Skip to main content
Home
The Baheyeldin Dynasty
The journey for wisdom starts with knowledge
  • Home
  • About
  • Site Map
  • Contact

Fake Facebook site uses pharming to steal passwords

  1. Home

By Khalid on 2010/01/24 - 00:40, last updated 2010/01/24 - 00:40

A cousin of mine got a new laptop from his place of work. The laptop is a nice 14.4" HP with Windows XP on it.

He found that when he visited Facebook, the site looked a bit odd, and when he logged in, the URL was redirecting to various other URLs.

These include:

http://chips05.clanteam.com/

http://chips09.99k.org/pro.php

http://hosint.zymic.com/404/

After some digging, it was apparent that typing "www.facebook.com" or just "facebook.com" were redirecting to one of the fake sites above. He downloaded and ran several malware/spyware removal programs but none of them fixed the problem.

Further digging using the ping command showed that instead of the real Facebook site, the fake site was on an IP address of a residential ADSL in Tirana, Albania! The address is 79.106.2.131.

The way this site manages to fool people into thinking it is Facebook, is that somehow it got the hosts file in Windows changed, so the malicious IP address serves a fake copy of the login page for Facebook.

This technique used by criminals is called pharming.

In order to check if you are affected by this, make sure that your Windows XP, file at C:\Windows\System32\Drivers\etc\hosts file, has the following, and no entries for Facebook (or Paypal, eBay, or other popular sites requiring passwords):

127.0.0.1 localhost

On a computer affected by the attack, you will have entries that look like this:

79.106.2.131 localhost
79.106.2.131 facebook.com
79.106.2.131 www.facebook.com

The solution is to restore the "localhost" entry to 127.0.0.1 and remove all other entries in the file for any web sites.

The irony is that despite malware removal programs such as Spybot inserting many fake sites into the hosts file as 127.0.0.1 to protect from such hijacks, yet it left the fake IP address for Facebook in the file, and even the fake entry for localhost.

It could be that my cousin's place of work are using a master image of Window that was previously infected via another mean, whether it is an unpatched Windows installation put on the internet, visiting a site distributing malware via ads, or the many other means that malware is spread by ...

Contents: 
Technology in Society
  • Add comment

Comments

Anonymous (not verified)

This could be a maleware that

Sun, 2010/01/24 - 13:26

This could be a maleware that hijack locally cached DNS.

Antivirus like Kaspersky would recommend changing system configuration to disabling DNS caching during installation.

you can manually disable DNS cache be using the following command

>net stop dnscache

also you can download & use SmitfraudFix & from its main menu use option 5 to clean the DNS

  • reply

Brandon Eric Q.... (not verified)

how do you change the host file?

Tue, 2010/01/26 - 09:28

i have the same problem. will you please help me.

  • reply

Khalid

It depends

Tue, 2010/01/26 - 09:36

It depends on many things, such as the Windows version, how it is setup.

But the steps are generally like this:

1. Make sure that the hosts files is writable. Check its permissions.

2. Click on Start -> Run, then enter CMD.

3. Enter CD \Windows\system32\drivers\etc

4. Enter EDIT hosts

5. Change the file as mentioned above.

6. Save the file.

7. Check if you are now at the right Facebook site.

  • reply

hakov (not verified)

THANKS!

Wed, 2010/01/27 - 13:51

thank u so much! i fixed it!

  • reply

Current

Pandemic

  • COVID-19
  • Coronavirus

Search

Site map

Contents

  • Family
    • Khalid
    • Ancestry
    • Extended
  • Friends
  • Nokat نكت
  • Writings
    • Cooking
    • Culture
    • Science
    • History
    • Linguistics
    • Media
    • Literature
    • Politics
    • Humor
    • Terrorism
    • Business
    • Philosophy
    • Religion
    • Children
  • Technology
    • Linux
    • Arabization
    • Drupal
      • Association
    • Software
    • Internet
    • Technology in Society
    • Digital Archeology
    • NCR History
    • MidEast Internet
    • Programming
    • Saudi ISPs
    • Miscellaneous
  • Places
    • Canada
      • Weather
    • Egypt
      • Cuisine
      • Alexandria
      • E.G.C.
    • USA
    • Saudi Arabia
  • Interests
    • Astronomy
    • Fishing
    • Photography
    • Snorkeling
    • Nature
    • Photomicroscopy
  • Miscellany

In Depth

  • al-Hakim bi Amr Allah: Fatimid Caliph of Egypt الحاكم بأمر الله
  • Alexandria, Egypt
  • Arabic on the Internet
  • Articles on the history of Muslims and Arabs in the Iberian Peninsula تاريخ المسلمين و العرب في الأند
  • DIY GOTO Telescope Controller With Autoguiding and Periodic Error Correction
  • E.G.C. English Girls College in Alexandria, Egypt
  • Egyptian Cuisine, Food and Recipes مأكولات مصرية
  • George Saliba: Seeking the Origins of Modern Science?
  • Internet Scams and Fraud
  • Mistaken for an Arab or Muslim: Absurdities of being a victim in the War on Terror
  • Mistaken Identity: How some people confuse my site for others
  • One People's Terrorist Is Another People's Freedom Fighter
  • Overview of Google's Technologies
  • Photomicroscopy
  • Pseudoscience: Lots of it around ...
  • Resources for using Google Adsense with Drupal
  • Rockwood Conservation Area, Southern Ontario
  • Selected Symbolic Novels And Movies
  • Snorkeling the Red Sea near Jeddah
  • Updates and Thoughts on the Egyptian Revolution of 2011

Recent Content

Most recent articles on the site.

  • Origin Of COVID-19: Natural Spillover, Lab Leak Or Biological Weapon?
  • Kamal Salibi and the "Israel from Yemen" theory
  • How To Upgrade HomeAssistant Core In A Python Venv Using uv
  • Ancestry - Paternal Side
  • Review of Wait Water Saver For Whole House Humidifiers
more

Most Comments

Most commented on articles ...

  • Another scam via Craigslist: offering more than asking price
  • Warning to female tourists thinking of marrying Egyptians
  • Craigslist classified for used car: Cheque fraud scam
  • Winning the lottery scam email: World Cup South African lottery
  • Email Scam: BMW 5 Series car and lottery winning
more

About Khalid

Various little bits of information ...

  • Khalid Baheyeldin: brief biography
  • Presentations and Talks
  • Youtube Videos
  • GitHub Projects
  • Drupal.org Profile
  • Astrophotography @ Flickr

Sponsored Links

Your Link Ad Here

Tags

Android Mobile Ubuntu Sony OnStep OpenWRT Router Ericsson COVID-19 Rogers Coronavirus Arabic Kubuntu Home Assistant GSM Telescope tablet Spectrum Scam Python 419 Laptop Firefox DIY CPU Conspiracy Comet Balkanization backup App
More

© Copyright 1999-2025 The Baheyeldin Dynasty. All rights reserved.
You can use our content under the Terms of Use.
Please read our privacy policy before you post any information on this site.
All posted articles and comments are copyright by their owner, and reflect their own views and opinions, which may not necessarily be consistent with the views and opinions of the owners of The Baheyeldin Dynasty.

Web site developed by 2bits.com Inc.