Instant Messages Carry Latest Phishing Scams


CRN logo By Dan Neel, ChannelWeb

11:00 AM EDT Thu. Jul. 22, 2004
Phishing schemes have moved into the realm of instant messaging.

Security experts on Thursday reported that instant message advertising links to malicious URLs have begun appearing, and that such URLs could be phony Web site fronts used for phishing scams.

Phishing is the act of recreating a clone of a commercial Web site--typically a banking, investment firm or retail Web site--then luring the customers of the legitimate sites to the clone with requests to update personal information like passwords. Once user names and passwords are obtained by the "phishers," victims of the scam risk having their accounts emptied.

One sample phishing scam sent an instant message pop-up reading "you have been sent a picture. To view it, Click here," wrote George Bakosto, an event handler at the Internet Storm Center, Bethesda, Md., in a statement on its Web site. "In this sample, "the From address is four random letters. However, a trusted name could be used."

Of this new form of phishing, Bakosto wrote, "It is important to understand that most instant messaging systems use only weak authentication schemes. Instant messaging is not a tool for exchanging confidential information. Only few instant messaging systems allow for encryption and sophisticated authentication. If you need instant messaging to communicate confidential information, use a system that allows you to control the server and provides for encryption and reasonable authentication. Jabber is an example of a free package [with these capabilities]."

Similar instant messaging schemes have been used a few times in the past to distribute viruses, according to Bakosto.

 
Channelweb : Promofinder
FEATURED PROMOTIONS
HES/HWS 30% End User Discount
HES/HWS 30% End User Discount
DLP Monitor 20% End User Discount
DLP Monitor 20% End User Discount
RELATED BLOG >>
Photo
SpamTitan offers comprehensive e-mail security, protecting against phishing attacks, viruses, malware and, yes, spam too.
ADVERTISEMENT




CHANNEL SERVICES >>

techcareers logo Search Jobs:


  

Post Resume|Employers

Recent Post:


Network Engineer
Lawrence Berkeley National Lab seeking Network Engineer in Berkeley, CA
spacer