Phishers get personal

By Joris Evers, CNET News.com
Friday, May 27, 2005 08:52 AM

with their e-mail addresses as their login name, he said. They also require additional information for registration or password reminders, or use other security measures.

eBay is one online business that does not allow registration and password reminder attacks. The auction Web site stopped using e-mail addresses as user IDs before phishing became an issue, and it has taken other protective measures in its registration and password-reminder process, said Scott Shipman, senior counsel for eBay's global privacy practice.

"It is all designed to prevent the unauthorized disclosure of information, be it the simplest piece of information, such as whether or not that e-mail address or user id is actually a valid user ID on the site," Shipman said.

In eBay's case, the reminder feature for user IDs gives the same response, regardless of whether the e-mail address is registered with the site. "The language of the error message will not tell you whether or not it was a valid account," Shipman said.

What will foil an attack?

The technique works only if the site generates different responses for registered and unregistered e-mail addresses.

  • A registration feature can only be exploited if the Web site uses e-mail addresses to register users and does not require a hard-to-fake personal detail, such as a credit card number.
  • Other security features, such as requiring a new registrant to solve a graphical challenge, will also prevent an attempt.
  • A reminder feature can only be exploited if it does not require personal information in addition to an e-mail address.
  • A graphical challenge on a Web site also counters the approach used in these schemes.
  • Source: Blue Security

    Designing a Web site to not leak information about users is what all site operators should do, the eBay executive added. "It is an example of a type of practice that is a best practice," he said.

    Hostile profiling is only one way phishing messages are getting more targeted. Earlier this month, security researchers reported that stolen consumer data was used in phishing scams to rip off individual account holders at specific banks.

    Jevans at the Anti-Phishing Working Group said that Blue Security's study highlights an emerging phishing threat, and agreed that online organizations should take steps to eliminate vulnerable registration and password-reminder features.

    "I think the research is real. You can certainly code your site to not do that, and you probably should," he said.


     Previous 1 2 

    WORTHWHILE?

    0

    0 votes
    Blog

    Talkback 0 comments

    There are currently no comments for this post.


    Tech Jobs Now!

    Search for your ideal tech job:

    10 open source projects worth checking out

    Open Source

    The open source field is pretty crowded, but certain projects stand above the rest. Here are 10 tools and solutions you don't want to overlook.


    Read more »



    Do we need more delivery centers?

    Blog thumbnail

    As I wrote a while back in about "racing to subsidies", there certainly is an increased focus by governments to attract delivery centers to their region. To do that, many..... by Michael Rehkopf

    Read more »

    Tags

    1. attack
    2. authentication and encryption
    3. blog
    4. data security
    5. e - mail
    6. hacking
    7. internet
    8. malware
    9. microsoft corp.
    10. network
    11. network security
    12. pc security
    13. researcher
    14. security
    15. security management
    16. software
    17. spam and phishing
    18. symantec corp.
    19. viruses and worms
    20. web