New Phishing Technique Discovered. Learn How It Works...

It's a new year and — what do you know — there's a new tactic in the endless quest for new and improved phishing schemes from scammers.
Here's How It Works
Researchers at Trusteer recently released a security advisory detailing this new phishing technique. Rather than using email to lure unsuspecting victims into clicking over to a fake web site, this technique uses what Trusteer is calling "in-session" attacks. Here's a typical scenario:
- A user opens a browser and logs into their banking web site
- Leaving that browser session open, they open another browser window to check on their Webkinz or some other web pursuit.
- After a time, a pop-up window opens — supposedly from their bank web site — asking for them to re-enter their username and password.
- Since the user has recently logged in to the targeted web site, they are more likely to enter their info.
That's it! Their login credentials are now in the hands of the scammers.
What Makes It Possible?
A few things have to be in place for this to work. First, the scammers need a compromised web server in order to install the malware. Fortunately, there are lots of those around. Second, the malware has to be able to determine which other sites the user has visited. This is possible based on a vulnerability in the JavaScript engine used by Internet Explorer, Firefox, Safari, and Chrome.
From Trusteer:
The source of the vulnerability is a specific JavaScript function. When this function is called it leaves a temporary footprint on the computer and any other website can identify this footprint. Websites that use this function in a certain way are traceable. Many websites, including financial institutions, online retailers, social networking websites, gaming, and gambling websites use this function and can be traced.
How Can You Protect Yourself?
Well, the planets have to align a bit to pull this scam off and it's likely the JavaScript vulnerability will be patched in the near (hopefully) future.
Until then, Trusteer recommends the following preventative measures:
- Have an up-to-date anti-virus installed
- Be suspicious of any pop-ups asking you to login
- Log out of banking or other sensitive sites before heading over to Pogo.com for your bingo fix.
and most of all...
Learn more about this attack by downloading Trusteer's security advisory.
We invite you to become a fan of Fight Identity Theft or just join in the discussion. You can find us on Facebook or Twitter.
Fight Identity Theft Newsletter
Enter your email address and keep up to date. More info | Unsubscribe
Recent Blog Entries
- February, 2010 (1)
- January, 2010 (3)
- December, 2009 (1)
- November, 2009 (5)
- October, 2009 (6)
- September, 2009 (2)
- August, 2009 (3)
- April, 2009 (2)
- February, 2009 (3)
- January, 2009 (8)
- December, 2008 (8)
- March, 2008 (1)
- January, 2008 (1)
- December, 2007 (3)
- November, 2007 (2)
- October, 2007 (3)
- May, 2006 (1)
- March, 2006 (4)
- February, 2006 (4)
- January, 2006 (10)
- December, 2005 (7)
- July, 2005 (3)
- June, 2005 (4)
- May, 2005 (5)
- March, 2005 (1)
- Credit (12)
- Fraud (38)
- Government (21)
- Identity Theft (39)
- Junk Mail (5)
- Phishing (13)
- Privacy (19)
- Scam (32)
- Technology (52)
- Telemarketing (2)
- Viruses (11)
- Visitor Stories (1)
- Worms (11)




3 Comments
liz
I've been really worried about buying things online lately with all this identity theft going around. I've been trying to educate myself on the different ways people steel others identities. This website has been VERY helpful, for people out there like me who just want to educate themselves on the subject, i found the following website helpful as well:
http://www.e-personalfinance.com/article/How-to-Minimize-the-Risk-of-Identity-Theft.html
Hope this helps!!
Anonymous
~Kubic I love Press Release Writing
nice reading
Anonymous
I am geting hot at all of the phishing going on over my way. I have phishing lines rom all over the world dangling every where I turn. My e-mail is completely full of nothing but phishing emails , from lotteries to suspicious to good to be true offers. How do I get them to stop I feel like mr. limpit. This is getteing ridiculous. will someone assist or offer a suggestion for me?
Post new comment