“All that is necessary for the triumph of evil is that good men do nothing.”
(Edmund Burke)

Monday, March 28, 2005

Phish Pharming

As the word spreads about the techniques used in phishing emails, identity thieves are devising new methods to steal personal information. The latest scheme is called pharming.

"...phishing without an accompanying e-mail "lure" is becoming more common. So called "pharming" attacks don't rely on legitimate-looking e-mails to lure users to fake Web sites, but automate that process by planting malicious code on vulnerable systems, then modifying the PC's HOSTS file to point to fraudulent sites rather than to the real deal."

The reference above to the "PC's HOSTS" file is simply stating that the malicious code overrides the normal routing to a legitimate web site by substituting a different web address in it's place.

So far, the new pharming schemes have shown up on some game web sites and, strangely enough, Monster.com. These attacks may just be proof-of-concept forays. Time will tell.

Read more here.