Follow Us

New style of phishing attack discovered

Scammers target website frames to attempt fraud.

The rate of innovation in phishing has been underlined with the discovery of an attempt to hijack a website frame on a legitimate banking site.

The hack was revealed this week by UK security company
Netcraft
, which tracks such new forms of incursion using reports from its user community. The target in this instance was the online log-in of US-based Charter One Bank.

In contrast to established cross-scripting techniques where whole pages are hijacked by bogus sites, the new "cross-frame" scripting approach is able to inject content on to a real web page, making it extremely difficult to detect. The technique works by adding links to the frame further down in what otherwise appears to be the legitimate charterone.com website, without this being deemed invalid.

Anybody visiting the website while prey to the attack - after, say, following a phishing e-mail link - would have been presented with what looked like the real website, in which had been planted a fake "account update" form.

While there is no evidence that anyone fell for the ruse, entering log-in details on this form would have given the phishers enough information to attempt fraud. An attack such as this would have to be directed at a specific bank website and wouldn’t necessarily be possible on all banking websites.

Nevertheless, the ability to carry out such an audacious attack gives some insight into the level of creativity now being employed by phishers.
According to the security blog of Dow Jones columnist Jeremy Wagstaff, the website hole is believed to have been fixed by the bank in recent days.






Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

State of software security report volume 4

If your business has anything worth protecting, be it money, intellectual property or a trusted...

Download Whitepaper

New threats demand innovative responses

Financial institutions in the UK remain susceptible to further systemic problems, as challenging...

Download Whitepaper

Delivering a competitive advantage through IT

IT organisations share a common mission; to optimise investments and streamline operations to...

Download Whitepaper

6 tips to mobilise your existing ERP

Enterprise mobile users throughout the global business community will number 1.19 billion by...

Download Whitepaper

Techworld UK - Technology - Business

Techworld Awards

Techworld Awards Winners 2011


Learn who the winners of this year's Techworld Awards are. Video footage coming soon...

Find out more
Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...

Site Map

* *