Do-it-Yourself Phishing Kit Found Online
Anti-Fraud monitors discover a kit that eases normally difficult phishing attacks on bank and e-commerce websites.
John E. Dunn, Techworld.com
A software kit has been discovered for sale on the Internet that makes it possible for non-experts to set up and carry out sophisticated phishing attacks on large numbers of websites.
EMC's RSA division reports that its Anti-Fraud Detection Center (AFCC) found the 'universal man-in-the-middle phishing kit' being offered in a free demonstration version on a criminal forum monitored by the company.
User Friendly
The kit--said to have a user-friendly interface designed to help the nontechnical criminal--automates the programming needed to pull off a normally tricky man-in the middle attack on websites such as banks or e-commerce sites.
Typically, the attack generated by the kit would start by duping users into clicking on a link embedded within a phishing email. This would direct them to a fraudulent URL able to communicate with the genuine website in real time, retrieving content from that site to make the scam appear as convincing as possible.
Quick and Easy
Apart from the fact such attacks can be carried out quickly and simply on multiple websites, it offers the advantage of giving criminals access to all information exchanged with the attacked site, not just the basic login. According to RSA, the kit qualifies as 'universal' because it can be used on any website, and thus attacks don't need to be tailored for each site
"As institutions put additional online security measures in place, inevitably the fraudsters are looking at new ways of duping innocent victims and stealing their information and assets," said Marc Gaffan of RSA.
"While these types of attacks are still considered 'next generation,' we expect them to become more widespread over the course of the next 12-18 months," he said.
Working man-in-the-middle attacks are relatively rare but not unheard of by any means. Last year, the Sinowal Trojan was found circulating in Germany by Kaspersky Lab.
With HP wireless printers, you could have printed this from any room in the house. Live wirelessly. Print wirelessly.
Laptop Showcase
A Guide to Business IT
Related Security Articles
- Caution: Collaboration Can Spill Corporate Secrets Collaboration and mobility boost the opportunity for data leak dangers, a Cisco study reports.
- Don't Buy Antivirus Software, Vendor Says Threats today go far beyond viruses, so a standalone solution won't make it, Trend Micro manager says.
- IT Security Hinders Innovation, IDC Says Organizations struggle for balance between promoting innovations and ensuring security.
- Hong Kong Cracks Down on Piracy Business Software Alliance, in recognition of department's efforts in promoting the use of genuine software in businesses.
- 'Ransomware' Virus-Writer Identified When the alleged creator of an infamous virus tried to negotiate, security firm Kaspersky Lab helped track him down.
Best Prices on Security Software
Norton Internet Security 2008Price: $14.00
Internet Security 2008 - 3-User (Full Product, PC)Price: $12.99
Kaspersky Internet Security 2009Price: $29.95
Norton 360 2.0 ( PC)Price: $35.95
Internet Security Suite 2008 - 3-UserPrice: $16.95
Norton Internet Security 2009Price: $66.99
- Web Demo: Discover the Benefits of VoIP Is your company looking for a world class VoIP communications solution that will meet all of your business requirements? If so, join us for our Live Online Demo where you will receive a "guided tour" to the AltiGen Solution.
- PC World Webcast: Going Green Wondering how to make your business greener? These tips will help your business save money, and save the environment.
- A Windows Vista FAQ Corporate customers are deploying Windows Vista now, and Dell Services wants to help you understand the features of the new OS and how to plan your Windows Vista deployment.





"Do-it-Yourself Phishing Kit Found Online " Comments