Cyber Security Institute
§ Current Worries
Top 3 Worries
- Regulations
- Old Firewall Configurations
- Security Awareness
§ Listening
For the best information
- The underground
- Audible
- Executive Excellence
- Music (to keep me sane)
§ Watching
For early warnings
- 150 Security Websites
- AP Newsfeeds
- Vendors
Wednesday, March 08, 2006
Phishing fraudsters aim to outpace site shutdowns
In a move designed to ensure potential phishing victims always link to a live website, fraudsters have developed so-called “smart redirection” attacks. Smart redirection attacks involve creating a number of similar phishing websites based at different locations. Emails that form the basis of phishing attacks pose as security messages from online banks in an attempt to dupe a tiny proportion of recipients who happen to be customers of the bank, into visiting a bogus site and handing over account information. According to the Anti-Phishing Working Group, almost 50,000 phishing websites were created last year, with more than 7,000 appearing in December alone.
Bogus emails that form the basis of phishing attacks contain URLs that direct the victim to a single IP address, which hosts the so-called ‘smart redirector’. When the potential victim clicks on the link, the redirector checks all related phishing websites, identifying which sites are still live before redirecting the user to one of them.
RSA Cyota senior product manager Andrew Moloney said: “As anti-phishing vendors become more adept at shutting down phishing websites, inevitably the fraudsters are looking at ways to minimise the effect this has on their hit rates.
According to the Anti-Phishing Working Group, almost 50,000 phishing websites were created last year, with more than 7,000 appearing in December alone.
http://www.theregister.co.uk/2006/03/08/smart_redirect_phish_attack/