computerprobleen oplossen the Helpdesk .nl

Info Rubrieken
Wat te doen vóórdat
Wat te doen bij?
Waarschuwingen Praktijk
Windows migratie naar Linux
Nieuwe Dreigingen

Nieuws
UrgentBeveiligingsAdviezen
Laatste Nieuws
Uitbreiding Dienstverlening
Onderzoek en Technologie
BlackList-GreenList
 

'Make your own man-in-the-middle attack' online kit found

 

Dan Kaplan Jan 10 2007 18:04

Fraudsters are hawking free trials of "universal" man-in-the-middle phishing kits through an online forum, security researchers said today.

RSA's Anti-Fraud Command Center (AFCC) discovered an internet forum populated by fraudsters that is offering a set of tools to create a man-in-the-middle scheme, according to a company news release.

The kit allows would-be attackers to create a bogus URL that communicates with both the end user and the legitimate website in real time, the release said. The scammer must first dupe the user into visiting the spoofed site.

These so-called universal phishing kits allow users to configure their attacks to take advantage of any target website, according to the release.

What makes man-in-the-middle attacks so troubling to security experts is that they allow hackers to continue to steal credentials even after the account holder has logged in, thus permitting the attacker to make an immediate financial transaction. In addition, because the fake site is communicating with the real one, it will alert users when they have incorrectly entered in their login details - thus enhancing the legitimacy of the scam.

Experts have said mutual authentication - in which both the client browser and the website must validate themselves - needs to be implemented to prevent against this new style of attack. Two-factor authentication won't cut it.

"As institutions put additional online security measures in place, inevitably the fraudsters are looking at new ways of duping innocent victims and stealing their information and assets," said Marc Gaffan, director of marketing in the Consumer Solutions division at RSA. "While these types of attacks are still considered ‘next generation,' we expect them to become more widespread over the course of the next 12 to 18 months."

Amazon.com and Citibank have become recent man-in-the-middle victims.

Bron: SC Magazine

 

theHelpdesk.nl, onDemandSupport.nl, theHelpdesk.eu en onDemandSupport.eu are trademarks of I.S.P. International B.V. and/or Robert A. van Donkelaar. Nieuws.theHelpdesk.nl (de NieuwsDesk) is een sub-domain van theHelpdesk.nl. All other products mentioned are registered trademarks or trademarks of their respective companies; "World Community Grid, the name and the logo, are trademarks of International Business Machines Corporation in the U.S., other countries, or both, and are used under license.

Sponsored Initiatives: openDemocracy, WorldCommunityGrid of (onze WCG pagina), BitsOfFreedom, VSO, Warchild

This site is dedicated to Titus Livius!

Questions or problems regarding this web site should be directed to webmaster@theHelpdesk.nl.
Copyright © 1995 I.S.P. International B.V.. All rights reserved.
Last modified: May, 2006.

Colofon.
Concept & Design: theHelpdesk.nl; SEO Design & Development: I.S.P. International B.V.; Co-Development: 2tp-hosting (Harvliet Dalgety)