January 16, 2008
Plishing attack on banking website appears legitimate
by Janine de Blois
Netcraft warns of new plishing attack that has taken place on an Italian banking website. Cross site scripting has made the attack very difficult to detect even with automated security filters.
Using an url which works on the JavaScipt function on the bank’s own Login page the url appear legitimate. The SSL certificate and secure page will appear normal; but the Iframe the attackers have inserted contains malicious code. The users’ personal data is transferred to Taiwan before redirecting the user to the banks actual page.
The site has been blocked in Netcraft’s anti-plishing toolbar as well as in Plishfeed.
Story link: Plishing attack on banking website appears legitimate
Discuss this in the Techwatch Forums
Related news to "Plishing attack on banking website appears legitimate"
No Comments »
No comments yet.
Leave a commentPrevious: « Norcent LT3250 LCD TV
Next: Mainstream publicity not good for criminal internet activities »
Visited 65 times, 1 so far today
IT Security News