How CAPTCHAs can cloak phishing URLs in emails
- Reference: 1647522011
- News link: https://www.theregister.co.uk/2022/03/17/captcha_phishinbg_url/
- Source link:
Security firm Avanan on Thursday published [1]its latest analysis of a phishing technique that builds on the internet community's familiarity with CAPTCHA challenges to amplify the effectiveness of deceptions designed to capture sensitive data.
Many companies employ secure email gateways (SEGs) to filter messages to prevent bad stuff, such as suspicious executables in attachments and links to phishing sites, from reaching users. Avanan, which sells an AI-based service that competes with traditional SEGs, unsurprisingly doesn't think much of these gateways and says it has new evidence to support its claims.
[2]
CAPTCHA puzzles, such as Google's reCAPTCHA, can act as a roadblock for these scanners because the filters can't solve the puzzles. When you beat a CAPTCHA, your browser can be directed someplace else, usually whatever it is you actually want to visit. If a SEG can't crack the riddle, it can't find out where a user would be ultimately taken, and is unable to make a decision on whether to filter out the email. It could default to blocking everything involving a CAPTCHA, but then that might be too much of a pain for users.
[3]
[4]
Crucially, what Avanan found, and shared [5]last year , is that miscreants have been deploying CAPTCHAs to conceal unsafe content from automated scans. If the scanner can't solve the puzzle, it potentially can't do its job properly.
For example, someone could get an email with an HTML attachment that when opened directs the user to a CAPTCHA, which if solved then eventually takes them to a phishing page that looks like a legit site's login screen but actually harvests any entered credentials. An automated scanner gets stopped at the puzzle.
[6]
As of February, Avanan researchers started seeing crooks using this technique used in conjunction with the compromised domain of a university as a way to capitalize on a trusted domain.
[7]Microsoft warns of widespread open redirection phishing attack – which Defender can block, coincidentally
[8]Cloudflare launches campaign to 'end the madness' of CAPTCHAs
[9]Who would cross the Bridge of Death? Answer me these questions three! Oh and you'll need two-factor authentication
[10]To CAPTCHA or not to CAPTCHA? Gartner analyst says OK — but don't be robotic about it
According to Jeremy Fuchs, a cybersecurity analyst at Avanan, victims received from the compromised university domain an email with an attached PDF file purporting to be a faxed document. The PDF, when opened, presents a URL – and instructions to visit the URL – that leads to a CAPTCHA form that shields the location of a phishing page. An automated scanner would need to get the URL out of the PDF, fetch it, and then solve the puzzle to get any further. It might even just trust the CAPTCHA URL.
Once the human victim solves the puzzle, they end up at a page that tries to trick the mark into entering their details supposedly for identity verification. Instead their information is sent off to fraudsters to exploit. The fact that a CAPTCHA is involved as some kind of security check may even convince some netizens that this really is a legit site. Attached documents could also be password protected, with the password in the message, to put another road block in the way of scanners; password-protected files may set them off, mind you.
"To the end-user, this doesn’t seem like phishing but more like a nuisance," explained Fuchs in research provided to The Register . "Given how often the average user fills out a CAPTCHA challenge, it’s not out of the ordinary. Neither are password-protected PDF documents."
For now, Avanan's advice is to tell people receiving these sorts of messages to supply the intelligence automated systems can't quite manage.
[11]
That means paying more attention to the URLs associated with CAPTCHA forms, making inquiries about whether attached PDFs should have been password-protected, and looking for potential red flags such as supposed faxed attachments that come from those known to be working at home (where fax machines are presumably as scarce as cassette tape players).
Good luck with that. ®
Get our [12]Tech Resources
[1] https://www.avanan.com/blog/using-captcha-forms-to-bypass-filters
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YjNpQV@88h-Gf6HWcnMYGQAAABU&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YjNpQV@88h-Gf6HWcnMYGQAAABU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YjNpQV@88h-Gf6HWcnMYGQAAABU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://www.avanan.com/blog/captcha-this-bypassing-segs-via-recaptcha
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YjNpQV@88h-Gf6HWcnMYGQAAABU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://www.theregister.com/2021/08/27/microsoft_phishing_defender/
[8] https://www.theregister.com/2021/05/14/cloudflare_cryptographic_attestation_of_personhood_captcha_killer/
[9] https://www.theregister.com/2021/06/25/something_for_the_weekend/
[10] https://www.theregister.com/2021/06/22/to_use_captcha_or_not/
[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YjNpQV@88h-Gf6HWcnMYGQAAABU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[12] https://whitepapers.theregister.com/
Re: An automated scanner gets stopped at the puzzle.
Also puzzled by this.
We use a 3rd party categorisation system at work, web sites are categorised by the 3rd party, and put into categories (Social media, news, vendors, dodgy (pirates etc), pr0n and so on).
The company decides what categories end users can get access to, rather than specific sites. (Although they can allow or block specific sites if needed).
Anything else, including anything not categorised yet, is blocked. So unless the target site, after the CAPTCHA, is an allowed site, uses wouldn't be able to get to it anyway.
So basically all sites are blocked by default, unless vetted and added to an allowed category.
Re: An automated scanner gets stopped at the puzzle.
So you have a white list.
Works a treat if you can guarantee the white listed sites are administered well and will never ever get compromised.
Can you guarantee that?
White lists are a good additional precaution but not too good on their own.
Re: An automated scanner gets stopped at the puzzle.
Dinosaur!
ITYM an ALLOW list
Lists of colours aren't the modern way.
Re: An automated scanner gets stopped at the puzzle.
So basically all sites are blocked by default, unless vetted
well , yes , that would avoid this problem.
Most companies find that technique too restrictive I'd have thought.
Re: An automated scanner gets stopped at the puzzle.
Given how frequently a computer can solve such items while it simultaneously causes Humans to fail to pass (Is that a tree? Telephone pole? skinny giraffe?) then it is *MORE* likely that an automated script to scan the initial URL could solve it, get past it, wind up on the real page, determine it's a scam, & then block the email as crap.
It's trivially easy for the computer to OCR a PDF for a URL, then follow the path; if the PDF is password locked then quarrentine the attachment as you would any other virus-posative email.
The idea that one computer can't figure out how to get past what another computer did is somehow not a very plausible one IMO...
Re: An automated scanner gets stopped at the puzzle.
"then it is *MORE* likely that an automated script to scan the initial URL could solve it"
huh?
"The idea that one computer can't figure out how to get past what another computer did is somehow not a very plausible one"
Sounds perfectly plausible to me - the first computer has been told the answer! *this* is a giraffe etc.
Also everytime a computer accepts or declines a password this has happened
Also when a computer encrypts something this has happened
Re: An automated scanner gets stopped at the puzzle.
"The idea that one computer can't figure out how to get past what another computer did is somehow not a very plausible one"
I've tried , I just really cant grasp any sort of logic in that statement from any direction.
It comes back to my opinion that HTML email is in itself a security hazard. My system is set up to display plain text and considers the presence of HTML to incline it to bounce a message. Stick to plain text, people, you know it makes sense.
HTML email is in itself a security hazard
from the article "someone could get an email with an HTML attachment that **when opened** directs the user to a CAPTCHA"
That's the problem right there. Don't open attachments, problem solved.
Re: HTML email is in itself a security hazard
couldnt someone also get a plain text email that says
Go to www capchasRus. com
they are giving away Massive Yachts!
"Given how often the average user fills out a CAPTCHA challenge..."
How often is this? The statement implies this is a regular thing for 'average' users, but for myself, I get a CAPTCHA very rarely!
And for ref, I use a lot of different sites and services, forums, gaming wiki's, news sites, banks, distro sites, retailers etc etc. I can't even remember the last time I saw a CAPTCHA, must be at least a couple of months back!
And I certainly never get them for anything work related.
Do some people get these a lot?
Re: "Given how often the average user fills out a CAPTCHA challenge..."
How often is this? The statement implies this is a regular thing for 'average' users, but for myself, I get a CAPTCHA very rarely!
Same here. Except for ID checks that I was expecting (new employers and so on) I can't recall ever jumping through such hoops for either personal or work email.
In fact asking me to do things like that is a good way to get ignored. The way I figure it is that it was you whom emailed me, so you want MY attention. I get more than enough email as it is so it you want my attention don't throw roadblocks in the way to getting it - that just gives me an excuse to ignore you.
Re: "Given how often the average user fills out a CAPTCHA challenge..."
Running Firefox with NoScript set fairly severely along with uMatrix and an unhelpful cookie policy, I see them all the time. There are a number of retailer's sites which simply tell me,
"Access Denied
You don't have permission to access "http://www.[our site].com/" on this server.
Reference #[alphanumeric soup]"
after I enable first-party Javascript in NoScript and reload the page.
Their loss.
Thunderbird set to show plain text only gives me a very interesting view of "modern" email messages. I still remember the first time I ran across a comment section inside the HTML in an "email" message.
Re: "Given how often the average user fills out a CAPTCHA challenge..."
Running Firefox with NoScript set fairly severely along with uMatrix and an unhelpful cookie policy, I see them all the time when browsing. There are a number of retailer's sites which simply tell me,
"Access Denied
You don't have permission to access "http://www.[our site].com/" on this server.
Reference #[alphanumeric soup]"
after I enable first-party Javascript in NoScript and reload the page.
Their loss.
Thunderbird set to show plain text only gives me a very interesting view of "modern" email messages. I still remember the first time I ran across a comment section inside the HTML in an "email" message.
To be more focused on captchas in email, I don't follow the links very often (less often now that I've read >this< article), I can't say I've seen that yet.
Re: "Given how often the average user fills out a CAPTCHA challenge..."
"Given how often the average user fills out a CAPTCHA challenge..."
True, also when they do - its not on the front page of a site , It'll be on the login page , behind the login button.
Any link sent in an email that goes straight to a capcha deserves to be blocked in my opinion
No legitimate site would send you to a link for their outsourced capcha rather than whatever precedes that on their site.
Re: "Given how often the average user fills out a CAPTCHA challenge..."
No legitimate site would send you to a link for their outsourced capcha rather than whatever precedes that on their site.
Google does that on their search page when you hit it from certain VPN endpoints. In their case the challenge is not outsourced, but that's just because they run their own CAPTCHA system.
Re: "Given how often the average user fills out a CAPTCHA challenge..."
If you don't get many CAPTCHAs that suggest you never block any trackers or 3rd party cookies etc. I do get them frequently, but figure its part of the downside of not letting big tech track me across every site I visit.
I even have to login to Elreg every time i come on to make a comment as it doesn't remember that I have been using this site for about 20 years.
Simpler just to block any CAPTCHA from email links. If that breaks the service then too bad, it is a shit service in the first place.
If it were for real security then it would have some form of 2FA, so no need for the CAPTCHA in the first place.
Given that an email link can be customised to identify an individual recipient's visit it strikes me that there's practically zero legitimate need for a CAPTCHA anyway for any well built system.
"Avanan, which sells an AI-based service that competes with traditional SEGs, unsurprisingly doesn't think much of these gateways and says it has new evidence to support its claims."
I have around an equal level of confidence in an AI-based system as a rules-based one: except with rules-based systems you can tell your users with confidence what sort of scams they are and aren't protected against, whereas with AI, it's a case of "most should be filtered out, but watch out for literally anything for those 1-2% of times where the AI doesn't work (yet)".
Timing
Every now and then when logging on to my account to tread 'The Guardian'* newspaper, I get asked to prove I'm not a robot with a 'captcha'. But that is after I have entered my log-on credentials. So maybe just be extra careful about when you are asked to enter your log in details.
*I suppose this makes me a 'leftie', but I do read the Financial Times occasionally and also the "i". And the BBC, and Astronomy Picture of the Day.
Paying attention may not be enough
" That means paying more attention to the URLs associated with CAPTCHA forms "
In a world where a high proportion of URLs include a path component that's utterly incomprehensible (commonly an apparently random string over 100 chars in length) or are 'shortened', it's largely impossible to identify potentially malicious content before accessing it.
As far as I'm aware, the only reasonably safe protection is for every request to be passed through an external specialist security proxy that checks its target for malicious content before forwarding it to the requester. And that would include both the request for the CAPTCHA, the request for submitting it and the request in the referral that results. So the automation would not have to compete the CAPTCHA as the user would do that. The automation would instead check the legitimacy of each step in the overall transaction.
The biggest problem we face on the web is unwitting and often unwarranted trust in content, so something between it and us has to check every request target dynamically for trustworthiness. But these checks must get much more sophisticated than at present. Particularly the tools that check emails are still too crude to avoid large numbers of both false positives and false negatives.
An automated scanner gets stopped at the puzzle.
Surely the correct behaviour is that content cannot be shown to be safe (for varying degrees of "safe"), then it is not . Teach the thing how to recognise a Captcha, so it'll understand that the link isn't the target, but rather an obfuscated step to the target.