Ads by TechWords

See your link here
Receive the latest technology news and information.
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

Pharming for profits

Attacks are soaring at an alarming rate, security experts say

June 2, 2005 12:00 PM ET

Computerworld - SAN JOSE -- Following Deep Throat's advice to "follow the money," hackers today are committing fraud at alarming rates, using sophisticated, multilayered "pharming" botnets that point to the need for new forms of authentication to secure e-mail originators as well as Web site destinations.
A four-member panel of cybercrime fighters dissected the ominous "phishing without a lure" pharming attacks in an "eCrime Calling" workshop at the InBox e-mail security conference here, co-sponsored by the Anti-Phishing Working Group.
Oliver Friedrichs, security manager at Symantec Corp.'s security response center, said the increase in pharming attacks has produced a steep rise in cybercrime statistics.The company's DeepSight global Internet sensor network recorded a 360% increase in phishing or pharming e-mails during the last half of 2004. DeepSight's 2 million honeypots and 4,000 devices recorded 9 million phishing e-mails for the last half of 2004, dwarfing the 2 million identified in last year's first six months. In a phishing scam, e-mail messages that look like they come from a legitimate Web site, such as a bank, are sent to users to lure them into entering sensitive information.
"It's a huge turn of events, from hacking for fun to hacking for profit," Friedrichs said. Phishers are taking advantage of "drive-by" installations, he said, injecting malware into some of the 21 vulnerabilities identified in Internet Explorer in the last half of 2004, as well as the 13 vulnerabilities identified in the Mozilla and Firefox browsers. The drive-by browser exploits place the infected machines into remote-controlled zombie botnets.
DeepSight analysis shows that 54% of all malware is designed to harvest confidential information from users, up from 44% in the second half of 2004 and 36% in the first half, Friedrichs said. Once infected, the top targets of the botnets are financial services companies followed by manufacturers.
"Phishers are sending e-mail with confidential information to multiple fake Web sites appearing to be an eBay or PayPal," said Jon Oliver, MailFrontier's director of research. "The sending botnets are being formed in many cases before the fake servers have been installed. The sophistication has grown tremendously."
Panelist Dan Hubbard, director of research at Websense Inc., said the "profit motive for phishing is very sizable. The hit rate is high, and the financial returns are quite good" as phishers develop more-sophisticated, "all-in-one" payloads that can proxy a server with a fake Web site, log keystrokes and redirect traffic.
Pharming attacks are the most ominous, said Scott Chasin, chief technology officer at MX Logic. Pharming, or maliciously redirecting a browser to a site



Jump to comments

Cybercrime/Hacking

Additional Resources

WHITE PAPER
Approximately 60 percent of data migration projects overrun time or budget, while some fail completely. Download this white paper, "Enhancing Your Chance for Successful Data Migration," to learn the critical steps you need to take to execute a data migration project with minimum cost and risk to your business.
WHITE PAPER
Read the Gartner research note to learn why the TCO of a server-based computing deployment used to deliver all applications to users is around 50% lower than that of an unmanaged desktop deployment.
WHITE PAPER
Economic downturns have a tendency to accelerate emerging technologies, boost the adoption of effective solutions, and punish solutions that are not cost competitive or that are out of synch with industry trends. This IDC White Paper presents the results of an IDC survey of 330 companies in Western Europe, Asia/Pacific and the Americas that measures the receptiveness to Linux and takes into consideration changing views driven by the disruptive economic environment that businesses face today.

White Papers & Webcasts

IBM Migration Factory: A smooth transition to new technology
Find out how to migrate your applications smoothly over to IBM.  

Effectively Implementing Datacenter Automation
Effectively select and deploy the best datacenter automation solution today!

Natural User Interface for Enterprise Applications
Download this Complimentary White Paper! Provided by Workday.  

Aligning IT to Business: The Rising Importance of Application Delivery Networks
Application Delivery Networking (ADN) will play a vital role in helping enterprises incorporate strategic technologies to achieve business initiatives.

Moving Beyond Monolithic - What's Next for Enterprise Application Architectures?
Download this Complimentary White Paper! Provided by Workday.  

Total Cost of Ownership of Server Computing Vs. PCs
Read the Gartner research note to learn why the TCO of a server-based computing deployment used to deliver all applications to users is...  

Mitigate Risk, Lower Costs and Improve Network Efficiency
Create a stable IP network that not only meets today's challenges, but is flexible enough to also meet future demands.