Re: FT: Phishing, pharming and fraud

Mar 09, 2005 7 Replies

Presumably this is an IE only, MS Windows only problem?


wrote

Believe that at your peril!

I wasn't suggesting that I believe everything I see on my browser but as it appears that this 'phishing' exploit depends on installing some software on your PC to get information it follows that it will only work on a PC running some sort of Windows OS. I was just asking if this was the case.

The example in the situation is a Windows only problem, it won't be an IE only problem (since by my reading it works at the host level, not at the IE inteegration level) Of course though like everything there's nothing about other operating systems that protect them other than obscurity, not that isn't a pretty good defence of course.

Jim.

Jim: your ignorance is showing. . . :-)

Alec, your naivete' is showing... :-)

Bah. You don't need to infiltrate the client OS at all to pull off this kind of attack - the bad guys just need to attack the global DNS servers. They did that just recently so that queries to google, ebay were being redirected to a hacker site.

formatting link
They could just as easily have made it so that queries to citibank, wamu, etc. are redirected to a phishing site. No need to load a trojan onto the user's machine or depend on the user's gullibility in clicking your link.

Is this not one of the types of attack which SSL/TLS should protect against? Phishing attacks such as this are similar to a man-in-the-middle attack which SSL/TLS X.509 certificates should detect.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required