Advertisement
Promo

Security threats Toolkit in association with http://ad.doubleclick.net/clk;214682528;14505427;f?http://uk.blackberry.com/ataglance/security/

Hackers use Google to defeat anti-spam measures

Dan Ilet ZDNet.co.uk

Published: 26 Oct 2004 13:00 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Antivirus experts have discovered a phishing email that redirects users three times through Google to a fraudulent registration Web site in order to beat antispam technology.

The email purports to be from Yahoo administrators and attempts to dupe users into signing up for new email accounts with the company. But using a clever combination of Yahoo and their own home-made Web sites, the hackers are claiming the accounts as their own.

"No one is going to block Google," said Alex Shipp, senior antivirus technologist for MessageLabs. "The link is a very complex string that hides their URL behind Google. It redirects three times probably to try and defeat anti-spam measures. Basically, you create email accounts for the bad guys. It's a way of ensuring that they have loads of accounts, and these could be used for [sending] spam."

The fraudsters sent emails pretending to be from Yahoo asking users to complete a registration form for an email account. The link on the email directs users to a fake Yahoo Web site, but does so pointing browsers at Google three times first. At this point a legitimate Yahoo pop-up appears explaining the registration process. When the form is completed, users are prompted to fill in a legitimate verification number, at which point the hackers can take control of the account.

Shipp said that his team had discovered a similar scam that duped Citibank account holders into divulging their details and tricked them into handing over their PIN numbers, suggesting one group of fraudsters are responsible for both operations.

"The chances of two different gangs doing this are pretty small," said Shipp.

Hackers have also been using ZDNet and CNET redirects as means of hiding their Web sites, Shipp said.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
86 out of 191 people found this useful


Company/Topic Alerts

Create a new alert from the list below:








Video icon

Video

Sentry Posts Blog

Behind the Scenes: Next Gen Mobile Tec...

Behind the Scenes: Next Gen Mobile Technology Author: Eric Everson, Founder MyMobiSafe.com With infrastructure speeds continually improving at the network level of the world’s leading... More

Post a comment

Nasa hacker petition presented to Numb...

Sting's wife Trudie Styler and Janis Sharp have presented a petition to Number 10 calling for Nasa hacker Gary McKinnon not to be extradited to the US. Styler, and Sharp, who is... More

Post a comment

UK to appoint cyber-sec tsar?

The UK is to appoint a cyber security tsar along the lines of the US, according to a story in the Telegraph this morning. The story is similar to one that appeared in the Guardian... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters