Mark Murtagh
Mark Murtagh
R E L A T E D   C O N T E N T
ADVERTISEMENT

Bugwatch: Phishers target the network

The latest scams can affect far more people than the original recipient

Mark Murtagh, technical director, Websense, vnunet.com 01 Dec 2004
ADVERTISEMENT

Each week vnunet.com asks a different expert to give their views on recent virus and security issues, with advice, warnings and information on the latest threats.

This week Mark Murtagh, technical director at Websense, warns of the dangers to company networks when employees fall victim to phishing scams.

The number of phishing emails continues to rise at a shocking rate, with copycat websites opening as soon as one closes. So much so, that phishing now represents the biggest form of online identity theft.

Putting this into context, the Anti-Phishing Working Group, an industry body providing information on phishing and email fraud, reported over 1,900 unique phishing attacks in July alone, representing an increase of 19 per cent on the previous month.

In its most basic form, phishing works by using spoofed emails and fraudulent websites that appear to come from trusted institutions, such as e-commerce and financial sites, which are designed to dupe recipients into divulging confidential information such as credit card details or online banking passwords and Pins.

The rapid development and sophistication of such attacks means that the concept of phishing is no longer limited to simply using email as the attack tool. There have been many cases citing web browser hijacking, instant messaging and automatic pop-ups, through to mediums such as fax, phone calls and even regular post.

These 'next-generation' attacks are using blended methods that harness social engineering psychology (playing on people's fears and motivations) together with application and operating system vulnerabilities to run malicious code locally on users' PCs.

Key-loggers can now be programmed with behaviour mechanisms to wait until users access real websites to start logging keystrokes and take screen captures. To make matters worse, this is all conducted without users ever realising that they have been victims of phishing until they check their financial statements and receive an unpleasant surprise.

These new attacks have the potential to affect far more people than the original recipient. For example, an employee working at home on their company laptop receiving a phishing email clicks on a link, which could then infect other computers when the laptop is reconnected to the network.

If a large number of employees are accessing their bank details online, this offers potentially huge spending power for hackers. It also could compromise the company's finances and confidential information.

Seen in this light, phishing is a real security threat for businesses today and one that needs addressing quickly and efficiently. But the question is how?

Unfortunately, guaranteeing that an organisation is up to date with the latest security patches and antivirus signatures is not enough to prevent an attack.

Anti-spam software fails to offer a guaranteed method of protection, since the words and phrases used in the fake web address often appear to be from a normal bank and might escape through filters.

Companies need to enforce an internet usage policy that prevents unauthorised applications from launching on the employee desktop.

By blocking any unknown security threats, and only allowing approved applications to run on corporate PCs and servers, IT departments can customise policies based on existing user and group network definitions, enabling a system that offers protection without restricting employee productivity.

See also:

Phishers targeting smaller firms and non-financial institutionsFraudsters moving away from banks towards e-commerce sites  30 Mar 2005
Craig PollardStaff training is as vital to network security as the most cutting-edge patch or state-of-the-art email filter  30 Mar 2005
Latest phishing scams use sophisticated attacks via instant messagingHackers increasingly spreading malicious code via instant messaging  22 Mar 2005
Sites not fully protected, according to study  14 Mar 2005
Paul LawrenceHaving the best protection against attack makes the experience more tolerable  18 Feb 2005
Phishing attacks now viewed as a corporate threatAnalysts spell out challenges for the messaging industry  05 Jan 2005
Online banking scams reach epidemic proportionsPhishing, spam and viruses at record levels  22 Dec 2004
Dave MartinEmployees are the biggest threat to security, especially at Christmas  16 Dec 2004
Ken MunroIs that coffee-shop Wi-Fi connection the real thing?  08 Dec 2004
Criminal gangs now using professional programmersLock up your bank accounts  07 Dec 2004
Sexually explicit spam emailEmails in violation of the 'brown paper wrapper' rule  02 Dec 2004
Unchecked buffer in HTML processingUrgent enough to break the cycle  02 Dec 2004
Fake sites install malwareFake e-commerce sites use devious scam to steal banking details  30 Nov 2004
Gone phishingPhishing is becoming ever more prevalent and ever more dangerous  29 Nov 2004
Increasing automation and sophisticationAnti-Phishing Working Group reports 'disturbing' new trend  24 Nov 2004

All Hacking

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
Senior C# Agile Web Developer, Online Gaming, London My Client provides adult customers with high quality gambling and gaming services in an environment that is convenient, entertaining, fair, regulated and secure. My Client is one ... more >
| Aston Carter
EMC, NetApps, West London, Media • NetApps FAS ... more >
| Abraxas
Data Analyst / MI Analyst – Leading Online Gaming Company A Data Analyst / Trafficker is sought by a leading online gaming company. The role encompasses all aspects of online advertising including data handling, communicating ... more >
| JAM Recruitment
Field Applications Engineer Power Electronics/Supplies Europe/Based Surrey Permanent Position £35-45k Basic+Bonus 10-15%+Car/Car allowance A global organisation involved with the design and development of power supplies actively requires a Field Applications Engineer to strengthen it existing ... more >
More job opportunities