On CNET: CTIA Fall 2008: The hottest new phones
BNET Business Network:
BNET
TechRepublic
ZDNet

By Dawn Kawamoto, News.com
Posted on ZDNet News: Apr 12, 2005 3:27:00 PM

A new form of phishing is taking shape and riding on the growing popularity of blogs, security company Websense said Tuesday.

Malicious virus writers are attempting to lure people to malicious blogs using enticing e-mails and instant messages, according to a new report from Websense. Once a person arrives at the blog, which can be posted on a legitimate host site, the victim's computer becomes infected with software designed to steal sensitive information, such as passwords and bank account information.

"These aren't the kind of blog Web sites that someone would stumble upon and infect their machine accidentally," Dan Hubbard, Websense senior director of security and technology research, said in a statement. "The success of these attacks relies upon a certain level of social engineering to persuade the individual to click on the link."

In the past four months, Websense has detected hundreds of cases where blogs were used to store malicious code and infect users' computers. Malicious virus writers are attracted to blogs not only because the medium's popularity is growing, but also because of the free storage often provided by the host site and the lack of antivirus protection provided for these posted files.

Websense said that as of Tuesday, there are 210 active bogus blogs. The company also notes that the average lifespan of one of these blogs is three or four days.

In one recent case, Websense found a spoofed e-mail that tried to lure people to a malicious blog that would run a Trojan horse. The e-mail looked like it came from a popular instant-messaging service, and it tried to entice the recipient to click on a link to get a new version of its IM program. But when people clicked on the link, it directed them to a blog that hosted keystroke-logging software to steal their passwords when they accessed certain online banking sites.

The use of blogs is just the latest twist on phishing techniques. Other phishing offshoots include cross-site scripting and DNS poisoning.

  • Talkback
  • Most Recent of 12 Talkback(s)
Once again, Linux is immune of course ... the facts of life ...
You get an impressive looking email that invites you to check out something new which ...

Takes you to an impressive looking website which invites you to download a script which will 'blow you ... (Read the rest)
Posted by: George Mitchell Posted on: 04/12/05 You are currently: Logged In | Log out
The code trm1945   | 04/12/05
Try again Real World   | 04/12/05
And then? trm1945   | 04/12/05
MAC??? Ratherbfishing465   | 04/12/05
Everything. It's a general purpose Unix box rpmyers1   | 04/12/05
I'll go slower Real World   | 04/12/05
Doesn't sound entirely social rpmyers1   | 04/12/05
don't assume anything Power User   | 04/12/05
You presumed wrong. vdraken   | 04/12/05
Hardware Firewall, Linux with Firewall and Firefox andyhayes1   | 04/12/05
NAT router, Real World   | 04/12/05
Once again, Linux is immune of course ... the facts of life ... George Mitchell   | 04/12/05

What do you think?

advertisement
advertisement