BetaONE will rise again!


Reply
  #1  
Old 15th Aug 06, 02:23 PM
Alpine's Avatar
Alpine Alpine is offline
Retired Crew
 
Join Date: Feb 2002
Location: Run Forest, RUN!!
Posts: 3,601
Alpine is on a distinguished road
Send a message via ICQ to Alpine Send a message via AIM to Alpine
Barclays scripting SNAFU exploited by phishers
Online scammers are exploiting a redirection script on Barclays' site to make fraudulent emails look more convincing. An alert Reg reader noticed the trick in scam emails he received.

We have yet to hear back from the bank, despite notifying Barclays of a potential problem last Tuesday (8 August). Meanwhile, the exploit (details of which we are withholding) remains open to abuse.

A similar attack, again ostensibly pointing to Barclays' website, but in reality directing surfers towards a phishing net, has been reported by other fraud watchers (see here). The other scams detailed by anti-phishing website MillerSmiles have a URL that more obviously points to something that's nothing to do with the targeted organisation (example here).

Our reader describes how the tactics used in the Barclays scam might trap the unwary: "Barclays Bank's website has a security flaw which will allow a phisher to provide a link which appears to be a legitimate Barclays URL, but actually redirects to fraudulent site. It seems very irresponsible to not do any checking that a URL is internal, or legitimate, before redirecting," he said.

eBay was the target of a similar attack last year. In that case, it took eBay some weeks to address the flaw. We can only hope that Barclays moves quickly to block off the possible route of attack.

Web security firm MessageLabs said redirection attacks that exploit security flaws on target websites are growing in prevalence. "Barclays is not the first. We have stopped several of these attacks in the past year," it said.

The REGister
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is On
Forum Jump


All times are GMT +1. The time now is 06:40 AM.


Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.