Smishing Smackdown: Unraveling the Threads of USPS Smishing and Fighting Back

S1nn3r

DEF CON 32 Main Stage · Day 1 · Main Stage

Overview

In "Smishing Smackdown: Unraveling the Threads of USPS Smishing and Fighting Back," S1nn3r, a red team operator and bug bounty hunter, takes the audience on a journey through his personal investigation into a prevalent smishing (SMS phishing) campaign targeting United States Postal Service (USPS) customers. Motivated by his wife falling victim to such a scam and subsequently receiving a similar fraudulent text message himself, S1nn3r transformed a personal grievance into a deep technical dive, uncovering significant vulnerabilities and operational security (OpSec) flaws within the attackers' infrastructure.

Watch on YouTube

Visual summary for Smishing Smackdown: Unraveling the Threads of USPS Smishing and Fighting Back by S1nn3r
Visual summary for Smishing Smackdown: Unraveling the Threads of USPS Smishing and Fighting Back by S1nn3r

Key moments

  1. 0:00 Introduction and personal motivation for investigating smishing.
  2. 1:30 Analyzing the USPS smishing site with Burp Suite.
  3. 2:15 Uncovering path traversal via unexpected websocket traffic.
  4. 3:55 Technical explanation of path traversal vulnerabilities.
  5. 4:40 Discovering scammers' BT panel and geographic location.

Smishing Smackdown: Unraveling the Threads of USPS Smishing and Fighting Back

Speakers: S1nn3r

Conference: DEF CON 32

YouTube: https://www.youtube.com/watch?v=gLOv67LlIQs

Overview

In "Smishing Smackdown: Unraveling the Threads of USPS Smishing and Fighting Back," S1nn3r, a red team operator and bug bounty hunter, takes the audience on a journey through his personal investigation into a prevalent smishing (SMS phishing) campaign targeting United States Postal Service (USPS) customers. Motivated by his wife falling victim to such a scam and subsequently receiving a similar fraudulent text message himself, S1nn3r transformed a personal grievance into a deep technical dive, uncovering significant vulnerabilities and operational security (OpSec) flaws within the attackers' infrastructure.

This talk meticulously details the process of dissecting a live smishing campaign, from initial interaction with the phishing site to exploiting its underlying vulnerabilities. S1nn3r's research highlights how even seemingly sophisticated phishing operations can be built upon insecure foundations, offering valuable insights into attacker methodologies and providing actionable intelligence for both individual users and cybersecurity professionals. The presentation serves as a compelling case study demonstrating how curiosity, combined with technical expertise, can expose the inner workings of cybercriminal enterprises.

The importance of this research extends beyond mere curiosity; it provides a tangible understanding of the tactics, techniques, and procedures (TTPs) employed by smishing operators. By revealing the specific tools, vulnerabilities, and infrastructure choices made by these attackers, S1nn3r not only sheds light on a pervasive threat but also empowers defenders with the knowledge needed to counter such attacks more effectively. The findings underscore the critical need for robust web application security practices, even for platforms designed for illicit activities.

Background

▶ Watch: Introduction and personal motivation for investigating smishing. (0:00)

Smishing, or SMS phishing, has emerged as a particularly insidious form of social engineering, leveraging the ubiquity of mobile phones and the perceived trustworthiness of text messages. Unlike email phishing, which users are often more accustomed to scrutinizing, SMS messages can bypass traditional email security filters and often carry a greater sense of urgency or personal relevance. The United States Postal Service (USPS) has been a frequent target for brand impersonation in smishing campaigns, as package delivery notifications are a common and expected form of communication for many individuals. Scammers exploit this by sending fraudulent texts claiming issues with package deliveries, often prompting recipients to click a malicious link to "resolve" the problem.

The problem persists because these scams are often highly convincing. The initial text message typically mimics legitimate USPS notifications, and the linked websites are frequently designed to look remarkably similar to the official USPS portal. This verisimilitude is often achieved by loading legitimate resources (CSS, JavaScript, images) directly from the official usps.com domain, making it difficult for an unsuspecting user to distinguish the fake from the real. Once on the fake site, victims are coerced into entering personal information, credit card details, or other sensitive data under the guise of paying a small fee or updating delivery preferences.

S1nn3r's personal encounter with this scam, where his wife unfortunately fell victim, served as the primary catalyst for his investigation. His subsequent receipt of an identical text message provided him with the perfect opportunity to turn the tables. Recognizing the malicious link as an entry point to a web application, S1nn3r, with his background in web application testing and bug bounty programs, saw it as an immediate target for analysis and exploitation. This personal connection to the problem highlights how real-world incidents can drive significant security research and contribute to a deeper understanding of prevalent threats.

Key Findings

▶ Watch: Analyzing the USPS smishing site with Burp Suite. (1:30)

S1nn3r's investigation into the USPS smishing campaign yielded several critical findings, exposing significant weaknesses in the attackers' operational security and infrastructure:

  1. Vulnerable Attacker Infrastructure: Despite the seemingly convincing front-end, the backend infrastructure used by the scammers was riddled with basic web application vulnerabilities, demonstrating a lack of fundamental security practices.
  2. Path Traversal Vulnerability: The most significant discovery was a Path Traversal vulnerability (also referred to as Local File Inclusion - LFI) within the web application, specifically through an unusual implementation of websockets. This flaw allowed S1nn3r to read arbitrary files from the server's file system.
  3. Exposure of Scammer Tools: By exploiting the Path Traversal vulnerability to access server access logs, S1nn3r uncovered that the scammers were utilizing BT panel, a Chinese web-based server administration software, and PHPMyAdmin for database management. The access logs even revealed the specific, randomized endpoint used for PHPMyAdmin.
  4. Identification of Scammer IP: The server access logs contained the IP address of the scammer actively interacting with their own infrastructure. This was identifiable through specific requests to the unique PHPMyAdmin endpoint with a 200 OK status code, distinguishing it from automated scans.
  5. Unusual and Insecure Service Configuration: An Nmap scan of the C2 server revealed not only the expected HTTPS (port 443) but also an open FTP (File Transfer Protocol) service on port 21. While S1nn3r was unable to exploit FTP directly, its presence signifies outdated and insecure practices.
  6. C2 Domain Identification: Initial traffic analysis with Burp Suite quickly revealed that the data collection was not occurring on the initial phishing domain but was being redirected to a separate Command and Control (C2) domain, which became the primary target for further investigation.

These findings collectively painted a detailed picture of the smishing operation, from the user-facing scam to the underlying vulnerable systems managed by the threat actors.

Technical Deep Dive

▶ Watch: Uncovering path traversal via unexpected websocket traffic. (2:15)

The technical investigation began with S1nn3r interacting with the malicious URL received via SMS. Upon loading the site in a browser, the initial observation was its high fidelity to the legitimate usps.com website. This deceptive appearance was achieved by dynamically loading most of the site's resources, such as CSS, JavaScript, and images, directly from the official USPS domain. This technique is a common tactic in phishing to enhance legitimacy and reduce the hosting burden on the attacker. The critical malicious component was a specific section designed to collect user data, ostensibly to resolve a "delivery failed" issue.

To gain deeper insight into the site's functionality and network interactions, S1nn3r employed Burp Suite Community Edition as his primary web proxy and analysis tool. The initial setup involved intercepting all HTTP/S traffic. A key observation during this phase was that while the initial page loaded from one domain, much of the subsequent data interaction, particularly the collection of user input, was directed to a different, albeit similar-looking, domain. This secondary domain was identified as the Command and Control (C2) server, serving as the central hub for the scam's operations and becoming the new focus of the investigation.

A peculiar finding during traffic analysis was the presence of websocket traffic. This was highly unusual for a web page primarily designed to be a static HTML form for data collection. Websockets are typically used for persistent, bidirectional communication, not for delivering a simple static page. This anomaly immediately flagged the websocket implementation as a potential point of weakness.

Further investigation into the websocket communication revealed a critical Path Traversal vulnerability. Path Traversal, also known as directory traversal or Local File Inclusion (LFI) when used to include local files, occurs when a web application uses user-supplied input to construct a file path without adequate sanitization. An attacker can manipulate this input with characters like ../ (dot-dot-slash) to navigate outside the intended directory structure and access arbitrary files on the server. S1nn3r demonstrated this by using a simple ../../etc/passwd payload, which is a common test for Path Traversal vulnerabilities, to read the /etc/passwd file, confirming the vulnerability. The speaker noted that while this LFI allowed reading of "basically everything," the server itself was a "bare image," meaning it contained minimal sensitive data like SSH keys or other login credentials beyond the web application itself.

Despite the server's minimal configuration, the Path Traversal vulnerability proved invaluable for accessing the server's access logs. These logs, typically found in /var/log/apache2/access.log or similar locations, record every request made to the web server. By carefully examining these logs, S1nn3r was able to reconstruct the scammers' activities. Crucially, the logs revealed entries indicating the use of BT panel, a popular web-based server administration software, particularly in China. The logs also showed requests to a PHPMyAdmin endpoint, which is a web interface for managing MySQL databases. What made these entries stand out was the highly randomized nature of the PHPMyAdmin path (e.g., PHPMyAdmin_a_long_string_of_characters), indicating it was a specific, intentionally obscured endpoint not easily discoverable by generic web scanners. The presence of a 200 OK status code for these requests, originating from a consistent external IP address, strongly suggested direct interaction by the scammer. S1nn3r utilized an "IP location" service to identify the geographical origin of this IP, though the specific country was not disclosed in the transcript, only hinted at.

To further profile the C2 server, an Nmap scan was performed. This revealed two open ports: 443 for HTTPS, which was expected for secure web communication, and 21 for FTP (File Transfer Protocol). The presence of an open FTP port was noted as an antiquated and generally insecure practice, especially for public-facing servers. S1nn3r attempted to exploit the FTP service through various means, including brute-forcing and checking for known CVEs, but was ultimately unsuccessful in gaining access via this vector. Nonetheless, its existence underscored the overall lax security posture of the scammer's infrastructure.

Demo / Proof of Concept

▶ Watch: Technical explanation of path traversal vulnerabilities. (3:55)

While the talk did not feature a live, real-time demonstration in the traditional sense, S1nn3r meticulously walked the audience through the entire process of his investigation, effectively serving as a detailed proof of concept for his findings. The step-by-step breakdown of how he uncovered and exploited the vulnerabilities clearly illustrated the practical application of his research.

The "demo" began with S1nn3r explaining the initial interaction with the phishing site and observing its deceptive use of legitimate usps.com resources. He then detailed the process of setting up Burp Suite to intercept and analyze the HTTP/S traffic, which was crucial for identifying the shift from the initial phishing domain to the Command and Control (C2) server.

The core of the proof of concept revolved around the Path Traversal vulnerability. S1nn3r described how the unexpected presence of websocket traffic for a static page led him to investigate this communication channel. He then explained the concept of Path Traversal, using the common ../../etc/passwd payload as an example to illustrate how he was able to read arbitrary files from the server. This explanation effectively demonstrated the vulnerability's existence and exploitability.

Finally, S1nn3r detailed how he leveraged this vulnerability to pull down the server's access logs. He showed how careful examination of these logs revealed the scammers' use of BT panel and the specific, randomized endpoint for PHPMyAdmin. The identification of the scammer's IP address within these logs, based on their unique interactions with the PHPMyAdmin interface, completed the proof of concept, showcasing how a single vulnerability could unravel significant details about the attacker's operations. The Nmap scan and its findings regarding open ports (HTTPS and FTP) further solidified the technical profiling of the C2 infrastructure.

Defensive Implications

▶ Watch: Discovering scammers' BT panel and geographic location. (4:40)

S1nn3r's detailed analysis of the USPS smishing campaign provides crucial defensive implications for various stakeholders, from individual users to cybersecurity professionals and organizations.

For individual users, the primary takeaway is enhanced awareness and vigilance. Users should:

  • Be Skeptical of Unsolicited Messages: Treat all unsolicited SMS messages, especially those claiming urgent package delivery issues, with extreme caution.
  • Verify URLs Independently: Never click links in suspicious texts. Instead, navigate directly to the official website (e.g., usps.com) or use the official mobile app to check package status or resolve issues.
  • Look for Red Flags: While phishing sites can be highly convincing, subtle discrepancies in URLs (e.g., usps.delivery.com instead of usps.com), grammatical errors, or unusual requests for personal data should raise suspicion.
  • Report Smishing: Forward suspicious SMS messages to 7726 (SPAM) to help carriers and authorities identify and block these campaigns.

For organizations, particularly those frequently impersonated like USPS, the implications are about brand protection and proactive threat intelligence:

  • Active Monitoring for Brand Impersonation: Implement robust systems to monitor for phishing domains impersonating their brand. This includes domain squatting detection and certificate transparency logs.
  • Public Awareness Campaigns: Regularly educate customers about common smishing tactics and how to identify legitimate communications.
  • Collaboration with Security Researchers: Foster environments where researchers can safely report findings, as S1nn3r's work demonstrates invaluable intelligence can be gained from such investigations.

For web administrators and security teams, the technical findings highlight critical web application security best practices:

  • Input Sanitization and Validation: Absolutely essential to prevent vulnerabilities like Path Traversal/LFI. All user-supplied input used in file paths, database queries, or command executions must be rigorously sanitized and validated against a whitelist of allowed characters and patterns.
  • Secure Web Server Configuration:
  • Disable Unnecessary Services: As seen with the open FTP port, unnecessary services increase the attack surface. Regularly audit and disable any services not critical for operation.
  • Secure Administration Interfaces: Web-based administration panels like BT panel and PHPMyAdmin should never be exposed directly to the internet. If remote access is required, it should be behind a VPN, restricted by IP whitelisting, and protected with strong, multi-factor authentication. Randomized URLs, while an attempt at obscurity, are not a substitute for proper access controls.
  • Principle of Least Privilege: Configure server processes and applications to run with the minimum necessary privileges to perform their functions.
  • Robust Logging and Monitoring: Comprehensive access logs are invaluable for incident response and threat intelligence. Logs should be collected, stored securely, and actively monitored for suspicious activities, such as access to administrative interfaces from unusual IPs or attempts to access sensitive files like /etc/passwd.
  • Regular Vulnerability Scanning and Penetration Testing: Proactively scan web applications and infrastructure for common vulnerabilities. Tools like Burp Suite (professional edition for automated scanning) and Nmap are essential for this.
  • Web Application Firewalls (WAFs): Deploying a WAF can help detect and block common web attacks, including Path Traversal attempts, before they reach the application.
  • Secure Development Lifecycle (SDL): Integrate security considerations throughout the entire software development lifecycle to build secure applications from the ground up.

By addressing these defensive implications, organizations can significantly reduce their susceptibility to being exploited by similar smishing campaigns, both as victims of impersonation and as hosts of vulnerable infrastructure.

Key Takeaways

  • Smishing campaigns often rely on vulnerable infrastructure: Even seemingly sophisticated phishing sites can be built on systems with fundamental security flaws, offering opportunities for defenders to turn the tables.
  • Path Traversal is a critical vulnerability: This flaw, often stemming from inadequate input sanitization, can expose sensitive server files (like access logs) and provide deep insights into attacker operations.
  • Attackers' OpSec flaws are exploitable: The use of easily identifiable admin tools like BT panel and PHPMyAdmin on internet-facing servers, coupled with an open FTP port, reveals a lack of robust operational security that can be leveraged by researchers.
  • Unusual network behavior signals vulnerabilities: The unexpected presence of websocket traffic for a static HTML page was a crucial indicator that led to the discovery of the Path Traversal vulnerability.
  • Leveraging common security tools yields significant intelligence: Tools like Burp Suite for traffic interception and Nmap for network scanning are invaluable for dissecting attacker infrastructure and identifying weaknesses.
  • Personal motivation can drive impactful security research: S1nn3r's personal experience with the scam highlights how real-world incidents can inspire deep dives that benefit the broader security community.

About the Speaker(s)

S1nn3r is a dedicated cybersecurity professional currently working full-time as a Red Team Operator. He is a recent university graduate who quickly established himself in the security field, having found approximately $10,000 in various bug bounty programs. This extensive experience in web application testing provided him with the foundational skills to conduct the detailed investigation into the USPS smishing campaign. S1nn3r is also the co-founder of Phantom Security Group, a company he established with a friend, further demonstrating his entrepreneurial spirit and commitment to the security industry.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

S1nn3r's dive into USPS smishing, spurred by personal experience, provides a robust case study in turning the tables on attackers. He leveraged a path traversal vulnerability in the scammer's websocket implementation to access server logs, revealing their use of BT panel, PHPMyAdmin, and even pinpointing their operational IP. This research delivers high practical impact by exposing common attacker OpSec failures and offering actionable intelligence for both individual users and security professionals.

Heather Calloway (CISO) — STRONG ACCEPT

This talk delivers a highly credible and actionable dissection of a prevalent smishing campaign, rooted in a personal experience. The speaker meticulously uncovers fundamental operational security flaws within the attacker's infrastructure, providing invaluable intelligence on their tactics, techniques, and procedures. It offers concrete defensive implications for individual users, brand-owning organizations, and web application security teams, effectively bridging the gap between technical discovery and practical, institutional action.

→ Top-rated talks at DEF CON 32 Main Stage

All talks from DEF CON 32 Main Stage