Hacked bank server hosts phishing sites
China Construction Bank may not know that a security vulnerability on its server has been exploited
IDG News Service - Criminals appear to have hacked a Chinese bank's server and are using it to host phishing sites to steal personal data from customers of eBay Inc. and a major U.S. bank., according to Internet services company Netcraft Ltd.
It may be the first scheme that uses one bank's infrastructure to exploit another bank, said Paul Mutton, an Internet services developer for Netcraft, based in Bath, England.
A user of Netcraft's free phishing toolbar reported receiving a suspicious e-mail, Mutton said. The e-mail led to phishing sites located in hidden directories on a server with IP addresses belonging to the Shanghai branch of China Construction Bank Corp., a state-owned bank with more than 14,000 branches.
One of the phishing sites offered customers of Chase Bank, part of JPMorgan Chase & Co., a chance to receive $20 for filling out a survey. The survey asked for the user's ID and password so the money could be deposited. Further, it requested the person's bank card number, PIN, card verification number, mother's maiden name and their U.S. Social Security number, Netcraft said.
The submitted data is then apparently sent to a form-processing server in India, Netcraft said.
The site pulls images and style sheets from Chase Bank's Web page. The method is known as "hot-linking" or "bandwidth leeching," Netcraft said. But it also leaves a trail, because the server where the images are pulled from retains of log of IP addresses of computers that requested the images, Mutton said.
There doesn't seem to be any advantage to the phishers in using a bank to host the fake page, which doesn't appear as a secure site to the browser. The URL of the site appears as an IP address rather than Chase Bank's domain name, another suspicious indicator.
On Saturday, Netcraft also found a fraudulent eBay log-in page with an IP address registered to the Chinese bank.
The fake eBay page carried a VeriSign seal, which is supposed to take visitors clicking on it to a page on Verisign Inc.'s site vouching for the security of the site. However, the seal vouches for the security of an entirely different site.
China Construction Bank may be unaware that someone has exploited a security vulnerability on its server, Mutton said. It's also possible that the server is infected with a worm that may be allowing unauthorized access, he said.
The scam could also be an inside job. "Anyone who has access to a server, either authorized or unauthorized, could have done it," Mutton said.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- X-Ray of the PCI Process-4 Proactive Steps
- This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into...
- Identity Governance: The Business Imperatives
- This white paper describes the business challenges and opportunities that are driving interest in Identity Governance while discussing considerations your organization should make... All Security White Papers
- Live Webcast
Playing Defense: Staying on Top of Your Disaster Recovery Game - When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
- Introduction to VMware vCenter Site Recovery Manager 5
- Traditional disaster recovery solutions are often too expensive, complex and unreliable to meet business requirements. As a result, IT departments are hesitant to...
- The Top Ten Secrets to Avoiding SAN Performance Problems
- Maintaining peak performance while simultaneously addressing the root cause of SAN errors is challenging. Learn the most common SAN problems and explore new...
- Deduplication Without Compromise
- Go inside Quantum's scalable, high-performance, multi-protocol new DXi deduplication appliances, designed to make backup much more effective. Discover how the new future-proof DXi6700...
- Director of Disk Products Discusses DXi6700
- Discover how the new DXi 6700 series of deduplication appliances provide investment protection and a future-proof feature set, all while delivering fast, scalable,...
- Playing Defense: Staying on Top of Your Disaster Recovery Game
- When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing... All Security Webcasts