An effective new phishing technique identified by researchers with Trend Micro allows attackers to go after information without having to spend as much time developing copies of websites. . The attack involves a phishing page containing a proxy program that acts as a relay to a legitimate website, according to a Wednesday post by Noriaki Hayashi, senior threat researcher with Trend Micro. From the user's perspective, they are just browsing the regular site, and the attackers do not have to modify anything until they are ready to steal information. The link for this article located at SC Magazine is no longer available. . The attack involves a phishing page containing a proxy program that acts as a relay to a legitimate . effective, phishing, technique, identified, researchers, trend, micro, allows, attackers. . LinuxSecurity.com Team
During a presentation at the Virus Bulletin Conference in Dallas, Fabio Assolini from Kaspersky Lab described how criminals in Brazil managed to compromise 4.5 million DSL routers for months without being noticed. . For their attack, the criminals first used two Bash scripts and a Cross-Site Request Forgery (CSRF) attack to change the admin password and then manipulated the router's DNS server entry. The CSRF attack even allowed them to bypass any existing password protection. Once compromised, the PCs were redirected to specially crafted phishing domains that mainly targeted users' online banking credentials; the attackers had set up 40 DNS servers to handle this redirection. The attack was limited to large parts of Brazil's IP address space. The link for this article located at H Security is no longer available. . For their attack, the criminals first used two Bash scripts and a Cross-Site Request Forgery (CSRF) . during, presentation, virus, bulletin, conference, dallas, fabio, assolini, kaspersky. . LinuxSecurity.com Team
Just as Internet surfers have gotten wise to the fine art of phishing, along comes a new scam utilizing a new technology. Creative thieves are now switching their efforts to "vishing," which uses Voice over Internet Protocol (VoIP) phones instead of a misdirected Web link to steal user information. . The link for this article located at E-Security Planet is no longer available. . Explore the growing threat of smishing, a text message phishing tactic that endangers personal information and online security.. Vishing Scam, VoIP Security Risks, Phishing Techniques, User Safety, Online Information Theft. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.