Subscribe to our e-mail newsletters
For more info on a specific newsletter, click the title. Details will be displayed in a new window.
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
More E-Mail Newsletters 
Computerworld 2007Subscribe to Computerworld
40 years of the most authoritative source of news and information for IT leaders.

Pharming for profits

Attacks are soaring at an alarming rate, security experts say
 

Sign up to receive Security Resource Alerts

June 02, 2005 (Computerworld) -- SAN JOSE -- Following Deep Throat's advice to "follow the money," hackers today are committing fraud at alarming rates, using sophisticated, multilayered "pharming" botnets that point to the need for new forms of authentication to secure e-mail originators as well as Web site destinations.
A four-member panel of cybercrime fighters dissected the ominous "phishing without a lure" pharming attacks in an "eCrime Calling" workshop at the InBox e-mail security conference here, co-sponsored by the Anti-Phishing Working Group.
Oliver Friedrichs, security manager at Symantec Corp.'s security response center, said the increase in pharming attacks has produced a steep rise in cybercrime statistics.The company's DeepSight global Internet sensor network recorded a 360% increase in phishing or pharming e-mails during the last half of 2004. DeepSight's 2 million honeypots and 4,000 devices recorded 9 million phishing e-mails for the last half of 2004, dwarfing the 2 million identified in last year's first six months. In a phishing scam, e-mail messages that look like they come from a legitimate Web site, such as a bank, are sent to users to lure them into entering sensitive information.
"It's a huge turn of events, from hacking for fun to hacking for profit," Friedrichs said. Phishers are taking advantage of "drive-by" installations, he said, injecting malware into some of the 21 vulnerabilities identified in Internet Explorer in the last half of 2004, as well as the 13 vulnerabilities identified in the Mozilla and Firefox browsers. The drive-by browser exploits place the infected machines into remote-controlled zombie botnets.
DeepSight analysis shows that 54% of all malware is designed to harvest confidential information from users, up from 44% in the second half of 2004 and 36% in the first half, Friedrichs said. Once infected, the top targets of the botnets are financial services companies followed by manufacturers.
"Phishers are sending e-mail with confidential information to multiple fake Web sites appearing to be an eBay or PayPal," said Jon Oliver, MailFrontier's director of research. "The sending botnets are being formed in many cases before the fake servers have been installed. The sophistication has grown tremendously."
Panelist Dan Hubbard, director of research at Websense Inc., said the "profit motive for phishing is very sizable. The hit rate is high, and the financial returns are quite good" as phishers develop more-sophisticated, "all-in-one" payloads that can proxy a server with a fake Web site, log keystrokes and redirect traffic.
Pharming attacks are the most ominous, said Scott Chasin, chief technology officer at MX Logic.

Continued...
1 | 2 | NEXT  



Print this Story Send Us Feedback E-mail this Story Digg! Digg this Story Slashdot this Story
"Apple fans have made much of the fact that the newest figures from Net Applications show that Apple's share of..." Read more...
"It's IT Blogwatch: in which Mozilla's Firefox Web browser continues to gain market share, smashing records as it does so...." Read more...
Read more Desktop Applications posts or See all Blogs
Microsoft promises four patches next week
Google gives away home-cooked Web application security scanner
Expect iPhone, Fourth of July scams, security firm says
More top stories...
Microsoft trumpets security additions in upcoming IE8
Apple cuts price of high-end SSD MacBook Air by $500
Ultrathin showdown: Apple MacBook Air vs. Lenovo ThinkPad X300 vs. Toshiba Portege R500
All it takes is a couple hours and about $125 to breathe new life into an old laptop. Here's how.
Is Microsoft's Golden Age over? What are Gates' most memorable quotes? Find out in Computerworld's complete coverage of the end of the Bill Gates era at Microsoft.
There are some things your CIO definitely doesn't want to hear. Also don't miss the flipside, Five things you should always tell your boss.
With its latest version, Mozilla's browser continues to raise the bar for what Web browsers should be.
Reviews, analyses, how-tos, visual tours, hot issues and predictions about Microsoft's new OS.
Four years from now, the IT field will be a vastly different place. Will you be ready?
All Zones
Application Performance Zone
Business Continuity Zone
Data Center Management Zone
Enterprise-Class Security Zone
The File Data Management Zone
Grid Computing on Windows Zone
Security Management Zone
ITIL Best Practices Zone
The SAS Zone
Storage Virtualization Zone
Business Intelligence and Analytics Zone

Ads by TechWords

See your link here
Computerworld Technology Briefing: An open-source path to optimal virtualization
Download this Technology Briefing now!
(Source: Novell/IBM/Intel) Virtualization is about a lot more than just lowering total cost of ownership. In fact users that have taken an open source path to virtualization have realized the additional, mission-critical benefit of markedly reduced IT complexity, as well as a more flexible infrastructure that is easier to change to meet shifting, often unpredictable business requirements.
Download this executive briefing download
Advance your BlackBerry(R) solution management know-how this July
Advance your BlackBerry(R) solution management know-how this July
BlackBerry Technical Seminar, register today!
Go to the webcast 
Adventist Health Improves Document Access with Single Supplier Solution
Download this white paper, free, compliments of Kodak!
(Source: Kodak) Until 2003, Adventist Health System- headquartered in Orlando, FL-relied on a paper-based filing system to manage medical records. The not-for-profit healthcare system, with over 45,000 employees, wanted to improve access to patient records at all of its 40 hospitals in 10 states. And when they transitioned to an electronic medical records system, the organization wanted to work with the best one-vendor solution for scanners.
Download this white paper go
White Papers
Read up on the latest ideas and technologies from companies that sell hardware, software and services.
Deploying Virtualized NetWare on Linux Whitepaper
Toward More Flexible, Next-Generation Collaboration Solutions
Driving Business Success Through Workgroup Choice and Flexibility
View more whitepapers