New Phishing Tactic Uses Real URLs, Fake Pages   11/9/2004 - 2,441 views, 6 Comments

Summary: A new phishing tactic discovered by Internet security company SurfControl allows the phisher to take advantage of a weakness in a targeted company's website, permitting them to use the company's real URL, while serving up bogus look-alike content. According to Susan Larson of SurfControl, ...

Previous Article « Open Source Web Browsers Taking Bite Out of Windows IE
Read Next Article » Is BitTorrent Traffic Going to Bring Down the Internet?

A new phishing tactic discovered by Internet security company SurfControl allows the phisher to take advantage of a weakness in a targeted company’s website, permitting them to use the company’s real URL, while serving up bogus look-alike content.

According to Susan Larson of SurfControl, “This is definitely one of the most sophisticated phishing techniques we have ever seen. Up until now, an informed computer user stood a chance or being able to identify a suspicious URL if they were wary. This new technique demonstrates how computer criminals are engaged in a constantly evolving series of increasingly sophisticated efforts to defraud the public.”

The way that it works is that the phisher exploits a flaw in the search script native to the targeted site. This allows them to display their own content as a search result, thus leaving the legitimate URL intact in the address bar. Non-legitimate URLs are one of the ways that intended victims of phishers have typically been able to identify a potential scam before being taken in by it.

You can read more about this here.

Previous Article « Open Source Web Browsers Taking Bite Out of Windows IE
Read Next Article » Is BitTorrent Traffic Going to Bring Down the Internet?

Get a FREE summary of the week's articles every Friday!
(You can stop it any time!)
    *We never share your email address with anyone

Email Address:
Date of first visit:
How you found us:

Be sure to watch for the confirmation email!

Subscribe
to The Internet Patrol on your cell phone    Email the link for this page to a friend!

Read more:

»  Tax Refund Email from IRS at GovBenefits.gov is Fake! Don’t Get Caught by IRS Phishing Scam!

»  Phishers Use Wildcard DNS to Build Convincing Bait URLs - Spamfo

»  eBay Phishing Bug Allows Phishing Using Real eBay Web Addresses

»  Beware the Fake Microsoft Windows Update Patch W32.Pinfi!

For additional similar stories check out our archives on Everything Else

 

6 Comments »

  1. New Phishing Tactic Uses Real URLs, Fake Pages
    A new phishing tactic discovered by Internet security company SurfControl allows the phisher to take advantage of a weakness in a targeted company?s website, permitting them to use the company?s real URL, while serving up bogus look-alike content. Acco…

    Trackback by Lockergnome's Web Developers — 11/9/2004 @ 2:56 am

  2. Aunty Spam- this big orange box on the right
    covers part of the words in your articles.
    It would be nice to be able to read the whole
    thing.
    Thanks

    Comment by D. Scoggins — 11/9/2004 @ 6:27 am

  3. Dear Aunty Spam- this big orange box to the right
    covers part of your articles and it can’t be
    read. It would be nice to be able to read ALL your
    comments.
    Thanks

    Comment by D. Scoggins — 11/9/2004 @ 6:29 am

  4. i’m trying to subscribe to your newsletter the box link is dead please subsribe me

    THanks

    Comment by linda — 11/10/2004 @ 3:14 am

  5. Your right hand column covers most of the left. So I am unable to read this article or even be sure of what I am typing right now. Let’s go back to frames!

    I am using SlimBrowser v4.02 build 004.

    Comment by Allen Mulvey — 11/10/2004 @ 3:53 pm

  6. Well I thought it was just me and my antique IE 5.0 on Windows 98, but now I see other people have the same problem: this site is unreadable! Why does it have a horizontal scrollbar in this column with plenty of unused space on the right hand side of the screen?

    Comment by Roelof [The Netherlands] — 11/18/2004 @ 11:28 pm

RSS feed for comments on this post. TrackBack URI

Leave a comment

Warning! All comments which contain URLs and are clearly just spam to generate a link back to the URL will be deleted on sight. Don't bother wasting your time!

If you are going to include a URL in your comment,
please keep it under 25 characters in length,
or use TinyURL to shorten it before including it in your comment.

Line and paragraph breaks are automatic, your email address is never displayed.
HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

(required)

(required)


If you have not posted a comment here before, we apologize for having to ask you to enter the letters and numbers you see in the image above to validate your comment, but we are being attacked by thousands of comment form spams every day! You only need to do this once; once you have successfuly posted a comment here you will not be asked to do this again. Thank you for your understanding!

 
The Internet Patrol
Patrolling the Internet for You!