POP-UP PHISHING RISK POINTS TO WEB FRAUD EVOLUTION
Posted January 15, 2009
Taking the spam out of e-banking scams
Fraudsters have the potential to develop techniques for mounting phishing attacks using pop-up dialogue boxes instead of spoofed emails, security start up Trusteer warns. Although the firm isn’t able to cite example of the possible next-generation attack, which it describes as in-session phishing, that attack scenario is plausible enough to merit a closer look.
In-session phishing, like drive-by download attacks, first relies on planting malicious code on targeted web sites. But instead of redirecting surfers to maliciously constructed websites under the control of malware , where browser vulnerabilities might be used to load malware on poorly secured Windows PCs, the hostile code is used to generate rogue pop-up browser windows.
Keep reading “Pop-up phishing risk points to web fraud evolution” »
Popularity: 1% [?]


