E-Card Remote Code Execution Scam

From: Jonathan A. Zdziarski (jonathan@networkdweebs.com)
Date: 09/28/02


From: "Jonathan A. Zdziarski" <jonathan@networkdweebs.com>
To: <incidents@securityfocus.com>
Date: Sat, 28 Sep 2002 05:25:12 -0400

This seems an aweful lot to me like a Remote Code Execution Scam...

I received an email addressed to "Undisclosed Recipients" notifying me
that I received an E-Card today, so I went to the site
http://www.surprisecards.net/viewcard.htm?id_num=[Undisclosed]&card=Pick
+up to view the card. Oddly, I received a security warning asking me if
I wanted to allow some code to run on my machine. Noticing the odd
choice of form variables as opposed to other e-card sites (not to
mention the fact that I could type in any number and get the same
screen), and with an eyebrow now raised I went to the main website
http://www.surprisecards.net to find "Welcome to the future home of
richardoliver.web.aplus.net". So I figure, if there's no way to send a
card from this website then chances are nobody sent me a valid card.

I took a look at the Thawte certificate for the card viewer "code" and
got www.cytron.com, some no-name development website with nothing more
than a phone number.

At the moment I'm not in front of any sacrificial machine to test the
card out on, but I suspect this email is being mailed out as a scam in
an attempt to run arbitrary code on the user's machine using a valid
Thawte certificate. What the code does when it loads I've no idea as
I'm not dumb enough to try it on my home machine.

In summary, my suspicion that this is the case is based on the
following:

1. The email was from egreetings@yahoo.com, yet was not redirecting me
to a yahoo site. (It was in fact coming from a yahoo mail server
though).

2. The email was NOT from surprisecard.net

3. The email was addressed to undisclosed recipients

4. There is no medium for sending cards from this site

5. www.cytron.com has no credible information about any card reader
product or even the company.

Perhaps someone in front of some extra hardware can take this and roll
with it.

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com



Relevant Pages

  • Re: The Saga continues: Possible scam?
    ... account and see what happened, which is not really your Pay Pal ... here's a scary scam for you. ... Both VISA and MasterCard told me ... This would be on your VISA card issued by 5/3 bank. ...
    (rec.equestrian)
  • Re: Free Sky TV Viewing Card
    ... This is a scam, please read on... ... Rue Des Capucins 22000 Guingamp France. ... work and a returns envelope for returning my card to be reprogrammed ... cash 13/03/03 via cheque, do you think there is anything I can do? ...
    (uk.media.tv.sky)
  • VISA/MASTERCARD SCAM
    ... VISA/MASTERCARD SCAM ... Fraud Department In Wiltshire Constabulary, ... By understanding how the VISA & MasterCard ... Telephone Credit Card Scam works, ...
    (uk.local.glasgow)
  • Re: OT-Credit Card Scam Warning/ Long
    ... Subject: Credit Card Scam Warning ... Security Number on Your Mc or Visa Card.. ... Will Be Issuing a Credit to Your Account. ...
    (rec.outdoors.rv-travel)
  • Re: Credit Card Scam Warning
    ... Subject: Credit Card Scam Warning ... Security Number on Your Mc or Visa Card.. ...
    (soc.retirement)