NokiMo
JimBrowning
JimBrowning

patreon


Fake bank

So I've been playing with php and I've cloned the Barclays Bank website. Its only accessible from  within my Local Area Network. I was going to just it as part of a sting to capture scammers bank details... I'll create a fake 'Transfer' form and an appropriately large bank balance. The form will do nothing other than log the scammers bank details. 


I'm sure I can make this work, but I'd like your view on this... 

Comments

Setting up direct debit looks illegal and will get you in trouble.

Atul Gupta

Does my choice make me cruel at heart?

Perhaps_today

You had me worried for a moment. Two wrongs do not make a right. Beware not to break the law yourself, however tempting it may seem sometimes. Regards,

Actually, I'm ahead of you with this one. I have a friend who is quite advanced with just this. We will be using it to study scammer behaviour. Look out for this in a future video!

Jim Browning

Creating a fake bank website for a local bank definitely wouldn’t be a problem. Here in the US we have tons of tiny local banks, so you’d just have to build a believable mock up for a website, say, as a side scripting/html project. It’s on your own computer, you’re not trying to defraud anyone with it, it’s not published, it’s just a project! How is it your fault someone is poking around your computer and starts messing with your side projects? If anything, it would allow you to draw them in further and waste even more of their time. You could even use it to scare them. A few random links lead to pages that say “WARNING! SCAM ALERT!” In big red letters and see how they try to talk their way out of that, leaving them rattled for the next time they try to log into someone’s bank account.

Westly SpringLockedFoxy Roanoke

I was joking really. Its very tempting to remove the money from scammers, but it's still stolen money.

Jim Browning

I'm not sure but wouldn't the charity get in trouble for receiving stolen money?

True... Although scammers are already familiar with the big-name banks. I'm pretty sure I'm not contravening laws unless it's a real phishing scam. The fake website is only accessible from within my network, so the scammer has to do all of this while connected to my PC... I have every right to run a keylogger on my own machine and, as long as I'm not diverting real people's traffic to my website, I can't see the harm in trapping a scammer. My view is that if everyone did this, scammers would be scared enough never to attempt this sort of scam. Wishful thinking maybe.

Jim Browning

or Royal Bank of Windsor -London Branch (+ photo) or City Bank of Salford-New York or the Birmingham Agricultural Bank of South England England

Just thinking about this , Jim, we wouldn't want anything adverse happbning to you if you contravene the laws. But some of these scammers are so dumb I think you can get by with a few mispellings eg National Axminster Bank of Aberdeen ( with photo)

This phishing page is purely inside my network and can't be accessed from the Internet. Only a scammer who I allow to connect can see it. See the little video I posted.

Jim Browning

You're probably right... I don't think I'll go as far as using their details, but I would like to hand them over to the appropriate authorities.

Jim Browning

Are you in the US? I think not but even in the UK, copyright laws are tricky and the site is clearly copyrighted (I just checked, the notice is at the bottom). Theoretically, regardless of your motive, you may be breaking the law. Stealing from thieves is still illegal, even if they stole the money in the first place (Just ask OJ Simpson)...it's just safer because thieves are unlikely to call the cops. Personally, I think it's a great idea and it's certainly a good example of 'frontier justice' but please be careful.

Mary Jo DiBella

I'll post a little video later to show how it works...

Jim Browning

It's not a true phishing page. It won't be accessible from the Internet, but if a scammer connects to my PC, they will be able to see it. Its purely a honeypot. Only accessible if you're connected to my network.

Jim Browning

So you mean you'll set up a phishing page? :P If you try to host it with a web host, I doubt it'll stay up for long, as web hosts (and browsers) these days are pretty good at detecting and blocking phishing pages, since they're so common.

Daniel L


Related Creators