Scams

Scams

by Mike Masnick




IRS Offers Up Stupid Redirect Links To Help Phishers Steal Money

from the our-tax-money-at-work dept

Too many sites that are trying to track what people click on when leaving a site offer up "open redirect links" which basically let's a site append an outside URL to the end of one of its own URLs and have traffic flow right through to that second site. This may be useful in easily tracking what links people click on to leave a site, but they're also perfect for phishing scammers, who use them to trick people into believing that they're going to a legitimate site. And, what better site to scam people than the IRS's site? Turns out that the IRS's special govbenefits.gov site uses open redirects that phishers are already using to steal money. They convince people they're going to the IRS site, when they're simply passing right through to the scammer's site. Our tax money at work. Update: Good point made in the comments. The site itself is not actually the IRS's but another government agency's. The scam, however, is about a tax refund.

10 Comments | Leave a Comment..

 
 

Reader Comments

(Flattened / Threaded)

    Nov 30th, 2005 @ 8:19pm
  • Finally!

    Finally our tax moneys doing some good!

    (reply to this comment) (link to this comment)

  • Nov 30th, 2005 @ 8:20pm
  • Heh

    by Testudo

    *scarcasm* At least its helping someone...

    (reply to this comment) (link to this comment)

  • Nov 30th, 2005 @ 9:41pm
  • No Subject Given

    by rizzel

    The IRS steals money anyway. Seams like they are just trying to expand their horizons.

    (reply to this comment) (link to this comment)

  • Nov 30th, 2005 @ 9:55pm
  • It doesn't look like this is the IRS' fault

    by Anonymous Coward

    The site with the open redirect is www.govbenefits.gov, not the IRS site (www.irs.gov). The article says the site is managed by the Department of Labor (of which the IRS is not part). I see nothing on the govbenefits site to contradict that. The "MEET THE MANAGEMENT TEAM" link introduces us to the "Assistant Secretary for Administration and Managemen1t at the Department of Labor".
    (I love the job titles. The head of an Administration (FAA, NASA, etc.) has the title of "Administrator". Somewhere in the federal government there's got to be an Administrative Assistant to the Assistant Administrator for Administration. . .)

    (reply to this comment) (link to this comment)

  • Nov 30th, 2005 @ 11:02pm
  • No Subject Given

    by discojohnson

    i know that sometimes we attack the wrong end of these things, but it's my turn. i don't think it's the technology's fault, but the random dumbass that clicks a link that says they have a tax refund they need to pick up. how dumb do you have to be? considering how mainstream the phishing idea is and how much plublicity it attains, do people really still click? i'd like to think that number is right next to zero.
    the flip side to that is trying to blame the IRS. maybe we should be more concerned with webmaster and not the content owner; after all, the webmaster decided to not use keywords or make the page smart enough not to accept external requests for the page

    (reply to this comment) (link to this comment)

  • Dec 1st, 2005 @ 5:57am
  • Something about a pot and a kettle

    by SB

    Isn't this a bit hypocritical?

    (reply to this comment) (link to this comment)

  • Jul 12th, 2006 @ 10:31am
  • by mojo

    ummm. this was a flaw on the govebenefits site not the irs.

    could you not see that in the link? by your definition, I could change the target and say "tech dirt offers up stupid redirect to help phishers steal money"

    (reply to this comment) (link to this comment)

Add Your Comment

Have a Techdirt Account? Sign in now.
Get Techdirt’s Daily Email
Plain Text HTML
Save me a cookie
  • Plain Text: A CRLF will be replaced by break <br> tag, all other allowable HTML is intact
  • HTML: No formatting of any kind is done without explicitly being written in
  • Allowed HTML Tags: <b> <i> <p> <a> <em> <br> <strong> <blockquote> <hr> <tt>
Close
Have a Techdirt Account? Sign in now.
Get Techdirt’s Daily Email
Plain Text HTML Save me a cookie

Search Techdirt
And now, a word from our Sponsors..



Subscribe to Techdirt's Daily Email Newsletter

Techdirt's Daily Email Newsletter

Related Stories
Close
E-mail It