Technology Review - Published By MIT
Advertisement

A Portal to Your Passwords

A Web browser loophole could make it easier for crooks to scam the unwary.

By Erica Naone

Tuesday, January 20, 2009

smaller text tool iconmedium text tool iconlarger text tool icon

A thief wanting to make cash by stealing sensitive information online can break into the banking systems that store such data or grab it as it travels over an insecure connection. But these days, it's much easier to go "phishing" instead--in other words, to convince unwary Internet users to hand over such information themselves. To do this, phishers typically design fake versions of real websites--like a bank or an online retailer--and lure unwitting Web surfers into entering their login data or credit-card details. A common ploy is to sucker them in with an e-mail that claims to come from a real bank but actually contains links to one of the phishers' bogus sites.

Credit: Technology Review

Would-be victims are growing familiar with this basic phishing attack, however, and many e-mail and browser vendors have introduced countermeasures to protect them. So phishers are searching for new ways to sting the unwary, says Amit Klein, CTO of Trusteer, based in Tel Aviv, Israel. For example, the microblogging site Twitter is increasingly being used to distribute phishing links.

Story continues below

Nonetheless, Klein says that "the [basic] attack will not be as successful in the future as it has been up until now," and in an effort to prevent future phishing attacks, his company is looking for better ways to con people out of cash before the bad guys can. A worrying new tactic being explored by some phishers, says Klein, involves hacking into a legitimate website in order to inject malicious code that throws up a pop-up window requesting individuals' usernames and passwords for a banking site. This approach is of limited value, however, since most users will be suspicious of the sudden request.

A vulnerability in major browsers recently discovered by Trusteer could make this trick much more dangerous, by allowing for "in-session phishing" and a more tailored attack. Using this new vulnerability, a phisher could detect, via the hacked site, when a user was already logged in to a banking website. The hacked site could then launch a pop-up warning the user that her session has timed out and asking her to reenter her login details. This approach would be less likely to raise a red flag, says Klein, since the pop-up does not appear completely out of the blue.

Comments

  • new form of phishing
    The article outlines a new more sophisticated form of phishing involving using an open hijacked web site injecting a phishing attack into an open online banking page display.

    For the last couple of years I make it a matter of course to close all browsers, clear all personal data from the browser cache, open a pristine browser with only the banking tab open and then close and clear the browser when finished. I do this to prevent exactly this kind of attack.

    It may not guarantee perfect security but it does help. 
    Rate this comment: 12345

    arnetwork
    01/20/2009
    Posts:19
    Avg Rating:
    4/5
  • Whats new here?
    The article indicates this a new form of phishing, but if it requires the hacker to inject javascript into an existing site, then the site is alreayd vulernable to all kinds of attack.. the least of which is a pop up that acts people to login again.  You could simply hijack their session--and the user wouldnt even know...

    Perhaps a little more specifics (*without revealing the hack) would help here.
    Rate this comment: 12345

    wonderingwha...
    01/21/2009
    Posts:1
    • Re: Whats new here?
      I think the javascript doesn't need to be injected into the BANKING site.  So the phisher hacks into and corrupts some other, non-banking, less-protected site that the user just happens to have open while he is doing online banking.  The "hacked" site might even belong to the phisher.
      Rate this comment: 12345

      dmm
      01/22/2009
      Posts:192
      Avg Rating:
      3/5
  • scam alert
    report all such scams at http://www.allscamsforum.com
    Rate this comment: 12345

    scotty65
    08/24/2009
    Posts:1

Log In

Forgot your password?     Register »
Advertisement

Videos

Making 3D Maps on the Move
Technology Review November/December 2009

Current Issue

Natural Gas Changes the Energy Map
The United States has vast supplies of this cleaner fossil fuel. But how should we use it?
Featured Content
Sponsored by:
White Papers

Twelve ways to reduce costs with SQL Server 2008
Find out how to reduce costs and get more efficient

Download

Total Economic Impact of SQL Server 2008 Upgrade
Forrester reports on increasing productivity and management capabilities

Download 

Achieving Cost and Resource Savings with UC
How Office Communications Server R2 and Exchange Server can make your business smarter and more efficient

Download 

The Compelling Case for Conferencing
Read how you can improve workload support and find IT efficiencies

Download

How Windows Server 2008 R2 Helps Optimize IT and Save you Money
Read how you can improve workload support and find IT efficiencies

Download

Windows Server 2008 R2 Hyper-V Live Migration
See how Windows Server 2008 R2 and Hyper-V enable virtualization and Live Migration

Download
Advertisement
Subscribe to Technology Review's daily e-mail update. Enter your e-mail address

TECHNOLOGY RESOURCES
Advertisement
MIT Massachusetts Institute of Technology © 2009 Technology Review. All Rights Reserved.