Mark Murtagh
Mark Murtagh
R E L A T E D   C O N T E N T
ADVERTISEMENT

Bugwatch: Phishers target the network

The latest scams can affect far more people than the original recipient

Mark Murtagh, technical director, Websense, vnunet.com 01 Dec 2004
ADVERTISEMENT

Each week vnunet.com asks a different expert to give their views on recent virus and security issues, with advice, warnings and information on the latest threats.

This week Mark Murtagh, technical director at Websense, warns of the dangers to company networks when employees fall victim to phishing scams.

The number of phishing emails continues to rise at a shocking rate, with copycat websites opening as soon as one closes. So much so, that phishing now represents the biggest form of online identity theft.

Putting this into context, the Anti-Phishing Working Group, an industry body providing information on phishing and email fraud, reported over 1,900 unique phishing attacks in July alone, representing an increase of 19 per cent on the previous month.

In its most basic form, phishing works by using spoofed emails and fraudulent websites that appear to come from trusted institutions, such as e-commerce and financial sites, which are designed to dupe recipients into divulging confidential information such as credit card details or online banking passwords and Pins.

The rapid development and sophistication of such attacks means that the concept of phishing is no longer limited to simply using email as the attack tool. There have been many cases citing web browser hijacking, instant messaging and automatic pop-ups, through to mediums such as fax, phone calls and even regular post.

These 'next-generation' attacks are using blended methods that harness social engineering psychology (playing on people's fears and motivations) together with application and operating system vulnerabilities to run malicious code locally on users' PCs.

Key-loggers can now be programmed with behaviour mechanisms to wait until users access real websites to start logging keystrokes and take screen captures. To make matters worse, this is all conducted without users ever realising that they have been victims of phishing until they check their financial statements and receive an unpleasant surprise.

These new attacks have the potential to affect far more people than the original recipient. For example, an employee working at home on their company laptop receiving a phishing email clicks on a link, which could then infect other computers when the laptop is reconnected to the network.

If a large number of employees are accessing their bank details online, this offers potentially huge spending power for hackers. It also could compromise the company's finances and confidential information.

Seen in this light, phishing is a real security threat for businesses today and one that needs addressing quickly and efficiently. But the question is how?

Unfortunately, guaranteeing that an organisation is up to date with the latest security patches and antivirus signatures is not enough to prevent an attack.

Anti-spam software fails to offer a guaranteed method of protection, since the words and phrases used in the fake web address often appear to be from a normal bank and might escape through filters.

Companies need to enforce an internet usage policy that prevents unauthorised applications from launching on the employee desktop.

By blocking any unknown security threats, and only allowing approved applications to run on corporate PCs and servers, IT departments can customise policies based on existing user and group network definitions, enabling a system that offers protection without restricting employee productivity.

See also:

Phishers targeting smaller firms and non-financial institutionsFraudsters moving away from banks towards e-commerce sites  30 Mar 2005
Craig PollardStaff training is as vital to network security as the most cutting-edge patch or state-of-the-art email filter  30 Mar 2005
Latest phishing scams use sophisticated attacks via instant messagingHackers increasingly spreading malicious code via instant messaging  22 Mar 2005
Sites not fully protected, according to study  14 Mar 2005
Paul LawrenceHaving the best protection against attack makes the experience more tolerable  18 Feb 2005
Phishing attacks now viewed as a corporate threatAnalysts spell out challenges for the messaging industry  05 Jan 2005
Online banking scams reach epidemic proportionsPhishing, spam and viruses at record levels  22 Dec 2004
Dave MartinEmployees are the biggest threat to security, especially at Christmas  16 Dec 2004
Ken MunroIs that coffee-shop Wi-Fi connection the real thing?  08 Dec 2004
Criminal gangs now using professional programmersLock up your bank accounts  07 Dec 2004
Sexually explicit spam emailEmails in violation of the 'brown paper wrapper' rule  02 Dec 2004
Unchecked buffer in HTML processingUrgent enough to break the cycle  02 Dec 2004
Fake sites install malwareFake e-commerce sites use devious scam to steal banking details  30 Nov 2004
Gone phishingPhishing is becoming ever more prevalent and ever more dangerous  29 Nov 2004
Increasing automation and sophisticationAnti-Phishing Working Group reports 'disturbing' new trend  24 Nov 2004

All Hacking

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
C# Web Developer, Finance, London Financial Services Required: C#, ASP.NET, AJAX Fantastic opportunity not to be missed!! This is a great opportunity to work on a unique objectives that no other company is doing working ... more >
| JAM Recruitment
Senior Hardware Engineer Scotland/Edinburgh Communication Systems Permanent Position 40-45K+Benefits A leading organisation involved with the design and development of data acquisition systems and synthesis boards for a range of radar, signal intelligence and software radio ... more >
| JAM Recruitment
FPGA Engineer Defence/Safety Critical Buckinghamshire Permanent Position 45K+Benefits A leading UK defence organisation requires an experienced digital design engineer to strengthen its existing development team due to a number of long-term projects that have recently ... more >
| JAM Recruitment
DSP Engineer 3 Months Contract Hertfordshire £Excellent Rates£ This position requires you to have experience of measurement algorithms development for the generation and analysis of digital wireless communication standards including GSM, EDGE, UMTS, WLAN and ... more >
More job opportunities