BS 7799/ISO 17799
Re: phishing threat Jul 27 2006 05:07AM
shakti velu (shaktivelu88 gmail com) (1 replies)
Re: phishing threat Jul 27 2006 05:58AM
Tim (pand0ra usa gmail com) (1 replies)
Re: phishing threat Jul 27 2006 06:34AM
shakti velu (shaktivelu88 gmail com) (2 replies)
Re: phishing threat Jul 27 2006 08:07AM
Domenico Rotondi (D Rotondi Computer Org) (1 replies)
RE: phishing threat Jul 27 2006 10:46AM
Omar A. Herrera (omar herrera oissg org) (1 replies)
Re: phishing threat Jul 29 2006 06:11AM
shakti velu (shaktivelu88 gmail com)
Re: phishing threat Jul 27 2006 06:47AM
Peter Boosten (peter boosten valid nl) (2 replies)
RE: phishing threat Jul 27 2006 07:33AM
Standen, Malcolm \(Griffin\) (malcolm standen-eds eds com)
Re: phishing threat Jul 27 2006 07:18AM
shakti velu (shaktivelu88 gmail com) (1 replies)
-------------------SANS Newsletter Extract---------------
Phishing Attack Defeats Two-Factor Authentication
(13 10 July 2006)
Phishers are targeting Citibank Citibusiness customers using a
man-in-the-middle attack to exploit people's trust in two-factor
authentication. The scheme, if successful, would provide the phishers
with Citibank Citibusiness customers' names and passwords in addition
to temporary passwords generated by security tokens. The scheme passes
on the customers' entered information to the legitimate site to see if
it authentic. In a real-time attack scenario, the temporary passwords
could be used before they expire. The phony site has reportedly been
shut down.
http://www.vnunet.com/vnunet/news/2160250/phishers-crack-two-factor
http://blog.washingtonpost.com/securityfix/2006/07/citibank_phish_spoofs
_2factor_1.html

On 7/27/06, Peter Boosten <peter.boosten (at) valid (dot) nl [email concealed]> wrote:
> I don't understand how you've implemented two-way authentication:
>
> Two-way means "something I know" (password) and "something I have" (token?).
>
> We use securID tokens from RSA which regenerate onetime passwords
> that only last for one minute maximum. I don't understand how this
> could be used in a phising attack.
>
> Could somebody explain this to me?
>
> TIA.
>
> Peter
>

[ reply ]
Re: phishing threat Jul 27 2006 07:48AM
Peter Boosten (peter boosten org)


 

Privacy Statement
Copyright 2010, SecurityFocus