Nat west website - a warning?
Nat west website - a warning?
Author
Discussion

Davi

Original Poster:

17,153 posts

250 months

Tuesday 4th November 2008
quotequote all
I've not put this in computers as it obviously could have implications to people who don't give a monkeys / wouldn't have a clue if there hard drive is spinning or their ram is ramming.

Just had a call from a mate who's gone to log in to his Nat West account, only there was a subtle difference to his log in procedure - the site was asking him for ALL his account details, full password etc etc etc. Suspicious, he tried using a different PC, which gave the normal log in procedure, just a few details asked and parts of the password. A call to Nat West confirms that the site being visited via the first PC can't be the real one.

Just waiting for a screen shot to have a look at but after talking through with him on the phone I haven't yet identified any visual difference between the real one and the fake one - both appear to have the same URL, nothing instantly recognisable to distinguish it as a phishing site.

So, a possible word of warning to those who bank with Nat West, and also a request for thoughts on tracing how this computer is linking through the correct URL to a scam site?

fatboy b

9,665 posts

246 months

Tuesday 4th November 2008
quotequote all
Looks like he may have a virus. Site looks OK to me.

Davi

Original Poster:

17,153 posts

250 months

Tuesday 4th November 2008
quotequote all
running a lot of scans at the moment, so far all come up clean, still slightly odd that visually (including URL) there is no discrepancy surely?

illmonkey

19,822 posts

228 months

Tuesday 4th November 2008
quotequote all
possibly a DNS or LMhosts issue. There was also a fix for worldwide DNS issues that allowed people to change records when they shouldnt.

Get him to do a trace and see where it ends up.

Murdoc

364 posts

219 months

Tuesday 4th November 2008
quotequote all
The 'HOSTS' file may cause this. It can be used to direct an entered URL elsewhere. A google search may hold more info.

Stigmundfreud

22,454 posts

240 months

Tuesday 4th November 2008
quotequote all
torpig

carmonk

7,910 posts

217 months

Tuesday 4th November 2008
quotequote all
You know it's the real NatWest site when it takes 5 minutes to move between pages...

Must be a malicious programme on his PC or following a phishing link, no other possibilities.

HRG

72,863 posts

269 months

Tuesday 4th November 2008
quotequote all
carmonk said:
You know it's the real NatWest site when it takes 5 minutes to move between pages...

Must be a malicious programme on his PC or following a phishing link, no other possibilities.
Well apart from a hosts file hijack, probably. If he's non tecchie get him to try to ping www.natwest.com from a command prompt (it won't actually ping) and note the IP address it returns on both machines. The legit one is 155.136.80.213

Stig

11,823 posts

314 months

Tuesday 4th November 2008
quotequote all
Murdoc said:
The 'HOSTS' file may cause this. It can be used to direct an entered URL elsewhere. A google search may hold more info.
http://malektips.com/spyware_adware_0017.html

Read that.

HTH

Davi

Original Poster:

17,153 posts

250 months

Tuesday 4th November 2008
quotequote all
cheers guys, copied and pasted that lot into an email so should keep him busy for the next few hours smile

BRGBert

1,105 posts

255 months

Tuesday 4th November 2008
quotequote all
I would hazard a guess at it being

http://www.theregister.co.uk/2008/10/31/sinowal_tr...

It runs a HTML injection in to the browser and asks for extra information such as ATM Pin, Social security number, mothers maiden name Etc.


Strangely Brown

15,850 posts

261 months

Tuesday 4th November 2008
quotequote all
Errr... this is what SSL certificates are for. Check the SSL cert presented by the fake site, if there is one, and you'll see that it's not the right one.

The situation does sound like a man in the middle attack where a trojan has modified the hosts file so requests to the correct FQDN get directed to the incorrect website.

If you are in any doubt at all, ALWAYS check the ssl certificate.

Stigmundfreud

22,454 posts

240 months

Tuesday 4th November 2008
quotequote all
Strangely Brown said:
Errr... this is what SSL certificates are for. Check the SSL cert presented by the fake site, if there is one, and you'll see that it's not the right one.

The situation does sound like a man in the middle attack where a trojan has modified the hosts file so requests to the correct FQDN get directed to the incorrect website.

If you are in any doubt at all, ALWAYS check the ssl certificate.
awww bless its good to think you still believe that but it is always a good starting point ONLY it is still no guarantee

Davi

Original Poster:

17,153 posts

250 months

Tuesday 4th November 2008
quotequote all
Stigmundfreud said:
Strangely Brown said:
Errr... this is what SSL certificates are for. Check the SSL cert presented by the fake site, if there is one, and you'll see that it's not the right one.

The situation does sound like a man in the middle attack where a trojan has modified the hosts file so requests to the correct FQDN get directed to the incorrect website.

If you are in any doubt at all, ALWAYS check the ssl certificate.
awww bless its good to think you still believe that but it is always a good starting point ONLY it is still no guarantee
To the average technophobe they aren't exactly the most obvious of things to check either.

princeperch

8,277 posts

277 months

Tuesday 4th November 2008
quotequote all
Natwest never ask for your full password IIRC.

Strangely Brown

15,850 posts

261 months

Tuesday 4th November 2008
quotequote all
Stigmundfreud said:
Strangely Brown said:
Errr... this is what SSL certificates are for. Check the SSL cert presented by the fake site, if there is one, and you'll see that it's not the right one.

The situation does sound like a man in the middle attack where a trojan has modified the hosts file so requests to the correct FQDN get directed to the incorrect website.

If you are in any doubt at all, ALWAYS check the ssl certificate.
awww bless its good to think you still believe that but it is always a good starting point ONLY it is still no guarantee
OK, Mr. Condecending, please enlighten us as to how the attacker would forge an SSL certificate for Nat West and get it signed by Verisign, Thawte or any of the other major certificate issuers?

Strangely Brown

15,850 posts

261 months

Tuesday 4th November 2008
quotequote all
Davi said:
To the average technophobe they aren't exactly the most obvious of things to check either.
They may not be obvious but that is what they are there for. IMHO, if you can't be bothered to learn about the technology that you are using, i.e. basic stuff like checking that a site belongs to who it claims to belong to by looking at the certificate then perhaps you'd better stick to the high street.

Furthermore, I have little sympathy for people that blindly dismiss warnings from their browser about SSL certificate problems without understanding what they are doing. The warnings are there for a reason; they are to protect you from things like site SSL certs not matching the request and therefore quite possibly not belonging to whom it claims.

There are many things that we can do to protect ourselves. Sadly, unlike the OP's mate, too many people just blindly type their details into any old form that is presented to them.

hondafanatic

4,969 posts

231 months

Tuesday 4th November 2008
quotequote all
Strangely Brown said:
Stigmundfreud said:
Strangely Brown said:
Errr... this is what SSL certificates are for. Check the SSL cert presented by the fake site, if there is one, and you'll see that it's not the right one.

The situation does sound like a man in the middle attack where a trojan has modified the hosts file so requests to the correct FQDN get directed to the incorrect website.

If you are in any doubt at all, ALWAYS check the ssl certificate.
awww bless its good to think you still believe that but it is always a good starting point ONLY it is still no guarantee
OK, Mr. Condecending, please enlighten us as to how the attacker would forge an SSL certificate for Nat West and get it signed by Verisign, Thawte or any of the other major certificate issuers?
You don't need to forge one. Go Daddy.

tonyvid

9,889 posts

273 months

Tuesday 4th November 2008
quotequote all
Strangely Brown said:
Davi said:
To the average technophobe they aren't exactly the most obvious of things to check either.
They may not be obvious but that is what they are there for. IMHO, if you can't be bothered to learn about the technology that you are using, i.e. basic stuff like checking that a site belongs to who it claims to belong to by looking at the certificate then perhaps you'd better stick to the high street.

Furthermore, I have little sympathy for people that blindly dismiss warnings from their browser about SSL certificate problems without understanding what they are doing. The warnings are there for a reason; they are to protect you from things like site SSL certs not matching the request and therefore quite possibly not belonging to whom it claims.

There are many things that we can do to protect ourselves. Sadly, unlike the OP's mate, too many people just blindly type their details into any old form that is presented to them.
In fairness, being just an average punter, most of this thread is like a foreign language to me....which is why I try to avoid putting my financial stuff via my PC. Is it safer to use my work system and trust that they are wise to all this stuff? (C+W and CSC managed networks)

Strangely Brown

15,850 posts

261 months

Tuesday 4th November 2008
quotequote all
hondafanatic said:
Strangely Brown said:
OK, Mr. Condecending, please enlighten us as to how the attacker would forge an SSL certificate for Nat West and get it signed by Verisign, Thawte or any of the other major certificate issuers?
You don't need to forge one. Go Daddy.
OK, if not certificate forgery, how is the remote site going to present a valid, signed certificate that will be accepted by my browser (and me) as belonging to Nat West?

Please explain. This is clearly a gap in my understanding and I'd like to know.