Technology Review - Published By MIT
Advertisement

A Portal to Your Passwords

Continued from page 1

By Erica Naone

Tuesday, January 20, 2009

smaller text tool iconmedium text tool iconlarger text tool icon
Phishing 2.0: A vulnerability recently discovered by security company Trusteer would allow attackers to launch pop-ups matching those of a bank that a user is already logged in to, as shown above.
Credit: Trusteer

The core vulnerability discovered by the Israeli researchers is a Web browser flaw that lets the phisher see what other websites a person is visiting. Klein explains that a certain JavaScript function, commonly used by online retailers, financial institutions, and other sites, leaves a footprint revealing that the user is logged in to that site. Klein says that protections such as pop-up blockers wouldn't necessarily derail the attack because the hacked site could itself be altered to seem like a request to log in again.

"I think it is great that we are trying to identify additional venues of phishing attacks such as this," says Nitesh Dhanjani, an independent security researcher who studies phishing methods and trends. For the time being, Dhanjani says, this kind of attack is beyond the technical abilities of the average phisher. "The bar is far too low to enter the phishing game, so the phishers have no reason to evolve into a sophisticated community," he says. However, as users are better protected against the most basic types of attack, he says, the technical bar for phishers could start to rise: "Perhaps this is when we will see slightly more advanced techniques incorporated into phishing kits."

Klein says that Microsoft, Apple, and Mozilla have told him that they plan to issue fixes for the browser vulnerability discovered by Trusteer. He adds that users can protect themselves by being careful to log out of banking and e-commerce sites before visiting other websites.

Comments

  • new form of phishing
    The article outlines a new more sophisticated form of phishing involving using an open hijacked web site injecting a phishing attack into an open online banking page display.

    For the last couple of years I make it a matter of course to close all browsers, clear all personal data from the browser cache, open a pristine browser with only the banking tab open and then close and clear the browser when finished. I do this to prevent exactly this kind of attack.

    It may not guarantee perfect security but it does help. 
    Rate this comment: 12345

    arnetwork
    01/20/2009
    Posts:20
    Avg Rating:
    4/5
  • Whats new here?
    The article indicates this a new form of phishing, but if it requires the hacker to inject javascript into an existing site, then the site is alreayd vulernable to all kinds of attack.. the least of which is a pop up that acts people to login again.  You could simply hijack their session--and the user wouldnt even know...

    Perhaps a little more specifics (*without revealing the hack) would help here.
    Rate this comment: 12345

    wonderingwha...
    01/21/2009
    Posts:1
    • Re: Whats new here?
      I think the javascript doesn't need to be injected into the BANKING site.  So the phisher hacks into and corrupts some other, non-banking, less-protected site that the user just happens to have open while he is doing online banking.  The "hacked" site might even belong to the phisher.
      Rate this comment: 12345

      dmm
      01/22/2009
      Posts:193
      Avg Rating:
      3/5
  • scam alert
    report all such scams at http://www.allscamsforum.com
    Rate this comment: 12345

    scotty65
    08/24/2009
    Posts:1

Log In

Forgot your password?     Register »
Advertisement

Videos

The Marcellus Shale Gas Rush
Technology Review November/December 2009

Current Issue

Natural Gas Changes the Energy Map
The United States has vast supplies of this cleaner fossil fuel. But how should we use it?
Featured Content
Sponsored by:
White Papers

Twelve ways to reduce costs with SQL Server 2008
Find out how to reduce costs and get more efficient

Download

Total Economic Impact of SQL Server 2008 Upgrade
Forrester reports on increasing productivity and management capabilities

Download 

Achieving Cost and Resource Savings with UC
How Office Communications Server R2 and Exchange Server can make your business smarter and more efficient

Download 

The Compelling Case for Conferencing
Read how you can improve workload support and find IT efficiencies

Download

How Windows Server 2008 R2 Helps Optimize IT and Save you Money
Read how you can improve workload support and find IT efficiencies

Download

Windows Server 2008 R2 Hyper-V Live Migration
See how Windows Server 2008 R2 and Hyper-V enable virtualization and Live Migration

Download
Advertisement
Subscribe to Technology Review's daily e-mail update. Enter your e-mail address

TECHNOLOGY RESOURCES
Advertisement
MIT Massachusetts Institute of Technology © 2009 Technology Review. All Rights Reserved.