ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Phishing hole 'left open' by banks

Matt Hines CNET News.com

Published: 15 Mar 2005 08:55 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

An easily remedied Web site loophole may be leaving banks and other companies that do business online more susceptible to phishing attacks, according to Netcraft.

Online criminals are increasingly using cross-site scripting flaws to inject their own code into legitimate Web page URLs, the network security services company said in a note posted on its site Monday. With these sites, the attackers can try to dupe unsuspecting consumers into falling for phishing scams.

"The majority of phishing Web sites are only semibelievable, and end users are starting to see through those," said Paul Mutton, an Internet services developer at Netcraft. "But with cross-site scripting, people are more likely to fall for the scam, because the URL actually belongs to a real business. It just has content added by a third party."

According to Netcraft, cross-scripting vulnerabilities in the server applications that support many business sites cause some Web pages to ignore various kinds of data — specifically, JavaScript code. That creates an opening for criminals to push their own JavaScript programs onto legitimate Web pages.

Recently, customers of Citizens Financial Group were the targets of such an attack, Netscape said. The scam involved a phishing email that exploited a scripting program on the bank's Web site to build an imitation site that attempted to trick customers into sharing their personal data.

Citizens Bank representatives did not return calls seeking comment on the attack.

Mutton said companies should expect to see more of the scripting threats, unless businesses carefully review server applications to eliminate the scripting glitch. Doing so would be more time-consuming than complicated, he said.

Mutton also said banks, the most common targets of phishing threats, have done little to remedy the cross-site scripting problem.

"This is an opportunity that allows criminals to do a pretty good job at misleading consumers, and it's a large problem that the banks really don't seem to be tackling head-on," Mutton said.

Mutton said the scripting attacks differ from the URL-spoofing campaigns that have targeted companies such as online auctioneer eBay. Those ploys typically redirect people to sites that can be discovered as fraudulent with some poking around, he said. By contrast, scripting errors allow scammers to add content such as a fake password log-in system on top of a page that appears completely legitimate.

Cross-scripting flaws can also be used to construct sites that steal the cookies saved on Web browsers. Cookies typically contain private data such as Web site passwords or other Internet usage information.

Mutton said the lion's share of the attacks being created using the technology loophole target financial-services companies. The researcher believes that there is no reason to believe that scammers will change their methods any time soon.

"[Cross-site scripting] can happen on [almost] any Web site; banks are just a big target," he said. "But it's a pretty simple equation: Banks are where the money is, so that's where the criminals are looking for any opening they can find. And this is a big one."

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
39 out of 98 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

.Net/C# Developer (Gain Agile/Scrum & .Net 3) - C.London

ASP.Net web pages and Winforms using C# to support and develop existing applications. Due to expansion, .Net/C# developer is required by a market ...

VB.NET Developers For Milton Keynes Solution Provider - 40,000

The ideal candidate will be working within the development team and where required directly with customers to produce new (and changes to existing) ...

Project Manager, Network Acquisition - dark fiber, DWDM, SONET/SDH, Ethernet, and IP - London, South East

The role: Project Manager, Network Acquisition Google has an immediate opening for a seasoned technical project manager to plan, facilitate, and ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation