Thread Rating:
  • 2 Vote(s) - 5 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Phishing Website - Possible Cookie Theft?
#1
Exclamation 
It has come to my attention that there is an impostor website linking to my website through a frame tag.

For example, blabla.XXX which is the imposter site will link to my legitimate blabla.YYY site.
And a GET data is extended with ?referrer=NUM.
Now I obviously undertand that they want to get many referrals, because I provide rewards for referrers.
BUT they also have a javascript with Google Analytics? It seems...

Question is, will they be able to obtain the cookies from the child frame?
#2
(2014-07-13, 11:48 AM)Jabberwock Wrote: Question is, will they be able to obtain the cookies from the child frame?
No.

You can prevent your website from being embedded in a frame: https://en.wikipedia.org/wiki/Clickjacking#Prevention
[Image: banner.png]
#3
(2014-07-13, 12:44 PM)StefanT Wrote:
(2014-07-13, 11:48 AM)Jabberwock Wrote: Question is, will they be able to obtain the cookies from the child frame?
No.

You can prevent your website from being embedded in a frame: https://en.wikipedia.org/wiki/Clickjacking#Prevention

As Stefan said their are couple of ways to block it.

One of them being Noscript(Client Side) and the other being Noframe(server side)

Goodluck Op.
Hey Everyone I am back! I will slowly be in progression of helping you all with your questions!


#4
I took the server side route, it's working great.
#5
Jabberwock,

how did you identify that someone was doing this?
#6
(2014-07-14, 12:49 PM)Dannymh Wrote: Jabberwock,

how did you identify that someone was doing this?

I think he's saying a parameter was holding it.

?refer=script here.
Hey Everyone I am back! I will slowly be in progression of helping you all with your questions!




Forum Jump:


Users browsing this thread: 2 Guest(s)