ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Phishers target Yahoo IM users

Munir Kotadia ZDNet Australia

Published: 24 Mar 2005 10:40 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Yahoo's free instant-messaging (IM) service is being targeted by phishers in an attempt to steal usernames, passwords and other personal information.

Yahoo confirmed on Thursday its service was being targeted by a phishing scam. According to the search giant, attackers are sending members a message containing a link to a fake Web site that looks like an official Yahoo site and asks the user to log in by entering their Yahoo ID and password.

The scam is convincing because the original message seems to arrive from someone on the victim's friends list. Should the recipient of the phishing message enter their details, the attackers can gain access to any personal information stored in their profile and more importantly, the victim's contact lists.

A Yahoo spokesperson told ZDNet UK sister site ZDNet Australia on Thursday the attack was not very widespread but consumers should be aware it exists so they can protect themselves.

"Hackers have become very devious in their methods to obtain personal information. In this case, the hacker was able to trick the user into providing personal information by disguising their identity to make it appear that the message was coming from a trusted source," the spokesperson said.

Over the past month alone, Microsoft’s MSN Messenger service has been targeted by various malware, including a Trojan horse and a virus. In late February Microsoft forced millions of its MSN Messenger users to update their client software in order to stop one of the worms spreading around its network.

MSN Messenger was an obvious target because of its popularity, according to Graham Connolly, Websense manager, Australia and New Zealand.

"Hackers want to use IM as another attack vector to steal personal information. They hit MSN Messenger first because it is the most popular," said Connolly.

Connolly said as email filtering technology matures, attackers are looking for new ways to access confidential information.

"Content filtering, email filtering and antivirus are now mature technologies so the attackers need to find another way and IM is becoming one of those ways — like spyware," said Connolly.

In a survey published by Internet security specialists SurfControl on Thursday, the company found although 90 percent of the respondents had an Internet access policy, around half had no policy concerning the use of IM and peer-to-peer applications.

Charles Heunemann, managing director of SurfControl in Australia, said IM and peer-to-peer communications were rarely encrypted, making them susceptible to snooping, hijacking and impersonation attacks.

"Serious security vulnerabilities such as buffer overflows, denial-of-service attacks and encryption weaknesses continue to be found and exploited in all popular instant messaging clients," said Heunemann.

Heunemann said companies should protect themselves by enforcing strict policies regarding the use of IM and peer-to-peer applications in a corporate environment.

"Left ungoverned, instant messaging applications are an easy vehicle for accidental or malicious disclosure of sensitive corporate data, including company financials, personnel records and customer data," said Heunemann.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
79 out of 126 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

WeSphere Architect

You'll also work with both the business and IS to implement messaging solutions based on a SOA, taking responsibility for analysing business ...

Java Developer (Senior) Ecommerce, Java, J2EE, EJB, JSP, SQL

Hertfordshire and has offices in US, China and Australia. Excellent communication skills -Excellent delivery focus and commitment -Team players, able ...

Messaging Support Analyst (AD,TREND protection,Exchange) BANKING

Highly Prestigious Investment Bank is hiring a Senior Level Messaging Support Analyst to join a small team in supporting the global messaging & ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment