BleepingComputer.com: New Phish Deceives With Phony Certificates

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

New Phish Deceives With Phony Certificates

#1 User is offline   quietman7 

  • Bleepin' Janitor
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Global Moderator
  • Posts: 25,507
  • Joined: 09-July 05
  • Gender:Male
  • Location:Virginia, USA

Posted 23 September 2005 - 04:59 AM

Quote

September 22, 2005
New Phish Deceives With Phony Certificates
By Gregg Keizer

A new, advanced form a phishing dubbed "secured phishing" because it relies on self-signed digital certificates, can easily fool all but the most cautious consumers, a security firm warned Thursday...

The new phish blends traditional elements with the new twist of a self-signed digital certificate, said Larson. It starts the same as most phishing attacks, with spammed e-mails urging recipients to click on a link to update a financial account. The destination is a spoofed version of a real site which requests the consumer enter his or her username and password to verify the information (supposedly because unauthorized access has been detected from an overseas IP address)...But this campaign goes above and beyond the typical. The spoofed site uses the  HTTPS protocol so that the browser shows the standard "lock" icon designating a secure site...

securitypipeline.com/news
Microsoft MVP - Consumer Security 2007-2012 Posted Image
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users