Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Phishing For Savvy Users
Scott Granneman, 2004-11-01

Recent "phishing" episodes, and two new browser vulnerabilities, show how the bad guys are tricking people into exposing their passwords and bank accounts. Couldn't happen to tech-savvy users, right? Unless you consider how entire nations have been fooled.

Comments Mode:
Phishing For Savvy Users 2004-11-02
Anonymous
Phishing For Savvy Users 2004-11-02
Anonymous
Phishing For Savvy Users 2004-11-02
sas (1 replies)
I disagree that most users always look at the form field as they type. Many people who can't touch type will look at the keyboard while typing, and if it's a site they're familiar with they may not bother to check their text entry before pressing return. In many login pages the cursor is automatically placed in the username field, so a user can simpy type username password - this might also catch out experienced users who don't pay proper attention to the page due to it's familiarity.

Even if they do check before submitting, presumably some javascript could be used to read the keystrokes as they're typed.

Admittedly this is only likely to work on a fairly simple form, like a simple login, but I think it's not as unlikely as you suggest.





[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/274/28944#28944
Phishing For Savvy Users 2004-11-02
Anonymous
Phishing For Savvy Users 2004-11-02
Anonymous (2 replies)
Phishing For Savvy Users 2004-11-04
Anonymous
Phishing For Savvy Users 2004-11-07
Anonymous
Phishing For Savvy Users 2004-11-03
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus