ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Phishers pushing spyware through DNS holes

Published: 09 Mar 2005 09:25 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Online thieves looking for personal data may be moving to more active measures by redirecting people from legitimate sites to malicious ones, security experts said this week.

The warning follows reports Friday that some people's computers were being redirected from sites such as eBay and Google to malicious Web servers that attempted to install spyware. The compromises affected 30 to 40 networks, according to Jason Lam, incident handler for the Internet Storm Centre, which tracks network threats.

"It's hard to tell how many people were impacted by this, but it wasn't very widespread," Lam said Tuesday.

The attacks compromised DNS servers to replace the numeric addresses of popular Web sites with the addresses of malicious sites run by the attackers. Known as DNS poisoning, the scheme redirects Internet users to bogus sites where they may be asked for sensitive information or have spyware installed on their PCs.

The Internet Storm Centre, which represents a group of incident response professionals organised by the SANS Institute, a security training organisation, said that a recent flaw in Symantec's firewall and gateway security appliances likely allowed some of the DNS poisoning to occur. However, other sites that do not use Symantec products also were victims, Lam said.

"We haven't really determined what caused this," he said. "We don't have enough reported cases, so it is hard to draw a conclusion from that."

Symantec did not immediately respond to a request for comment.

Using DNS poisoning to redirect customers to sites that appear to be legitimate but actually steal sensitive information is a relatively new threat. Some security companies have called this technique pharming.

Lam warned that future attacks, if more adeptly executed, could be nearly undetectable. It's possible users would believe they are going to a legitimate site and would get no indication from their browsers that the site that actually appears is not official.

"In this case, the content of the site was different," he said. "But with DNS poisoning, if they intended to use it for phishing, it would have been very bad."

Lam said that the site certificates used by financial Web sites and other sensitive services would give users some warning that something was amiss.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
92 out of 156 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:








Related Jobs

Unix / Linux Redhat Systems Administrator- Market Leaders- London

Unix / Linux Redhat Systems Administrator Scripting, Oracle, MySql, DNS, DHCP, Apache, My client is a FSTE 100 blue chip organisation looking for ...

Firewalls Engineer Lead

Provide support of the hardware and software for the firewalls and switches from the outer border through to the CORNET gateway. On an operational ...

Junior Level Systems Admin(desktop,server,AD,DNS,DBA) BANKING

DNS, DHCP, TCP/IP & Database administration for Sybase, Oracle or MS SQL Servers. A market leading developer of trading & risk management systems ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment