Stirpes  

Go Back   Stirpes > Technology > Technology, Computer Science & Robotics > Computers & Internet Security and Privacy

Computers & Internet Security and Privacy Computer machines and components.
News and updates on latest security related advisories, threads, software, open source, etc.

Reply
 
Thread Tools Display Modes
  #1 (permalink)     Quote this post in a PM
Old Thursday, March 17th, 2005
Menydh's Avatar
Southern Charm,
Western Passion
 
Join Date: Dec 2004
Posts: 16,270
Menydh is a deity.Menydh is a deity.Menydh is a deity.Menydh is a deity.Menydh is a deity.Menydh is a deity.Menydh is a deity.Menydh is a deity.Menydh is a deity.Menydh is a deity.Menydh is a deity.
Exclamation Pharming - a new technique for Internet fraud

Pharming - a new technique for Internet fraud

Author: Fernando de la Cuadra, Panda Software
Monday, 07 March 2005, 18:34 GMT


Hackers appear to have an increasing interest in reaping financial reward from their actions and creations. If until now, phishing - using emails to lure users into entering data into spoofed online banking websites - was one of the most widespread fraud techniques, 'pharming' now poses an even greater threat.

Basically, pharming involves interfering with the name resolution process on the Internet. When a user enters an address (such as www.pandasoftware.com) this needs to be converted into a numeric IP address as 62.14.63.187. This is known as name resolution, and the task is performed by DNS (Domain Name System) servers. These servers store tables with the IP address of each domain name. On a smaller scale, in each computer connected to the Internet there is a file that stores a table with the names of servers and IP addresses so that it is not necessary to access the DNS servers for certain server names.

Pharming consists in the name resolution system modification, so that when a user thinks he or she is accessing to bank's web page, he or she is actually accessing the IP of a spoofed site.
Phishing owed its success to social engineering techniques, despite that not all users take the phishing bait, and so this success was limited. Also, each phishing attack was aimed at one specific type of banking service, further reducing the chances of success. Pharming on the other hand, can affect a far greater number of online banking users.

In addition, pharming isn't just a one-off attack, as is the case with phishing emails, but remains present on the computer waiting for the user to access the banking services.

The solution against this new kind of fraud lies, as ever, in antivirus security solutions. Pharming attacks depend on an application in the compromised system (this could be an exe file, a script, etc). But before this application can run, obviously it needs to reach the operating system. Code can enter the system through numerous channels, in fact, in as many ways as information can enter the system: el e-mail (the most frequent), Internet downloads, copied directly from CD or floppy, etc. In each of these information entry points, the antivirus has to detect the file with the malicious code and eliminate it, provided that is, it is registered as a dangerous application in the antivirus signature file.

Unfortunately, the propagation speed of malware today is head-spinning, and there more malicious creators and offering their source code to the rest of the hacker community to create new variants and propagate even more attacks. The virus laboratories don't have enough time to prepare the malware detection and elimination routines for new malicious code before they start spreading to a few PCs. Despite the efforts and improvements from virus labs, it is physically impossible for them to prepare an adequate solution in time against some of these threats that can spread in just a few minutes.


[source]
__________________
'Dardanidae duri, quae uos a stirpe parentum
prima tulit tellus, eadem uos ubere laeto
accipiet reduces. Antiquam exquirite matrem:
hic domus Aeneae cunctis dominabitur oris,
et nati natorum, et qui nascentur ab illis.'



We can easily forgive a child who is afraid of the dark; the real tragedy of life is when men are afraid of the light.

–Plato–

'Many people, I believe, wish for a society where faith, decency, pro-life convictions and national self-determination within Europe can flourish; and not be swallowed up in a dictatorial EU bureaucracy.'

Gerry McGeough, Irish Nationalist and POW–

Reply With Quote
Reply

Bookmarks

Tags
None


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Fraud, intimidation and bribery as Putin prepares for victory Sifjar The Tabloid 1 Saturday, December 1st, 2007 11:12
Cleared of rape and fraud and set to be South Africa’s next president Breogan World News 2 Saturday, September 29th, 2007 19:09
A Comparison of French and Italian Singing in the Seventeenth Century Ferran The Classics 0 Monday, July 17th, 2006 14:31
Millionaire Briton arrested in Majorca for fraud Ferran Immigration & Crime 0 Saturday, April 22nd, 2006 11:13
New Georgia Tech micro-CT imaging technique to help tissue engineers improve bone regeneration Ekhi Biology 0 Tuesday, February 22nd, 2005 05:00

Locations of visitors to this page

All times are GMT. The time now is 01:22.

Page generated in 0.2162690 seconds with 14 queries.


Powered by vBulletin® Version 3.7.0
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.1.0