
Many of my students commented in the Facebook, 'Sir, You really went and hack?' I am not sure whether this is hacking or not. But this how I did it.......
The attacker, I named him 'Mr Idiot.' Apparently, Mr Idiot has created a website with domain name 'www.myskyfruit.webs.com' and trying to phish away my customers. He has attempt to use my banner (myskyfruit.com) on his website. What He dis, is that he hard-coded his website to load the banner direct from my website - www.myskyfruit.com/iamges/banner.jpg Mr Idiot tried my people believe that they are our associate.
However, recently, a lot of people tried copying and downloading images from my website. So, I redesign my website and convert all the images from JPG to SWF (Flash). SWFs, unlike the JPGs are not easily downloaded. And, the banner in SWF is named as 'banner.jpg.swf' Normally in Windows, the extension is hidden. So, it cause the user to believe it is a JPG.
Since our banner is in SWF format, I created a fake JPG image with the same name but with extension JPG. After discussion with my son, we decided to put error messages in the JPG banner.
Since Mr Idiot links his website to my banner with JPG extension and guess what.... My fake JPG banner will displayed on his website.
The moral of the story are:
1. DON'T THINK THAT YOU ARE THE SMARTEST.
2. DO NOT LINK YOUR PROGRAM TO UNKNOWN EXTERNAL OBJECT.
