The internet is a profoundly ‘open’ system and advanced internet users are cautious about either accepting or sending material from and to unknown sources and are careful in releasing information about themselves in any form. Conceptually, the internet challenges us to take greater responsibility for the protection of privacy and security than perhaps we are used to when dealing with the media.
The breadth and decentralisation of the internet allows a great deal of freedom for users, but unfortunately it also provides an excellent environment for fraudsters to commit crime. Internet users need to stay aware of online threats, and of the new technologies associated with them.
In the recent past a number of methods of online fraud have been developed. Experienced internet users have become very familiar with them, and it is natural now to place enforce strict security rules to your online profiles and firewalls. There are some frauds, however, that manage to pass through these controls and require a greater vigilance by the internet user.
Phishing, for example, can be performed in a number of ways. One example is for a fraudster to send an email that is mimics the website of a trusted institution, banks are common. The message will have some kind of scary subject such as the email below, I received yesterday, titled “Your HSBC Financial Group account has been violated!”
The link leads to a phoney site that records the information entered, which is then used for fraud activities. This might be considered old hat to the more experienced internet users, but in my work in a large bank I dealt with a complaint from a customer two weeks ago who had fallen victim to a phishing scam and had £9000 stolen from his credit card. Because he had voluntarily given his account details to an ‘unknown’ 3rd party, contravening the conditions of his bank account, he is required to repay the bank the full amount. Phishing is quite a lucrative industry for fraudsters, in Great Britain alone it is estimated that over £20 million is stolen annually.
Email security features and user training are proving effective in combating this kind of scam, but there are others in development that are much harder to recognise. XSS, or Cross-Site Scripting, is a new tool for internet fraud that is extremely hard to identify.
XSS can be used in a number of ways to defraud people. Essentially it is the process by which a fraudster inserts code into a webpage that can, invisibly, and without any indication of its presence, copy the users details and information being keyed. The result is that the fraudster can then assume the online identity of the user.
TJ Maxx, the clothing retailer, suffered from a XSS scam last year, where the fraudsters were able to access their systems and download hundreds of thousands of credit card numbers, the eventual cost to the business expected to be in excess of £100 million. XSS holes in websites are continually being found and fixed by developers, but not all sites are safe. Internet users can take security measures such as disabling scripts to help avoid XSS attacks.
Social Engineering is another form of attack, but unlike the two examples above, it relies purely on human error. The term covers a lot of different methods of attack, but one of them, and the favourite for the computer criminal Kevin Mitnick, is ‘pretexting’. This is often performed by calling an employee of a company posing as technical help. While ‘assisting’ the user with their query, the fraudster asks for their password or other security data which is then used to access the company’s computer systems.
Internet users need to keep updated with developments in website privacy and security, to ensure that they are communicating with websites and others in a secure way.
Email security features and user training are proving effective in combating this kind of scam, but there are others in development that are much harder to recognise. XSS, or Cross-Site Scripting, is a new tool for internet fraud that is extremely hard to identify.
XSS can be used in a number of ways to defraud people. Essentially it is the process by which a fraudster inserts code into a webpage that can, invisibly, and without any indication of its presence, copy the users details and information being keyed. The result is that the fraudster can then assume the online identity of the user.
TJ Maxx, the clothing retailer, suffered from a XSS scam last year, where the fraudsters were able to access their systems and download hundreds of thousands of credit card numbers, the eventual cost to the business expected to be in excess of £100 million. XSS holes in websites are continually being found and fixed by developers, but not all sites are safe. Internet users can take security measures such as disabling scripts to help avoid XSS attacks.
Social Engineering is another form of attack, but unlike the two examples above, it relies purely on human error. The term covers a lot of different methods of attack, but one of them, and the favourite for the computer criminal Kevin Mitnick, is ‘pretexting’. This is often performed by calling an employee of a company posing as technical help. While ‘assisting’ the user with their query, the fraudster asks for their password or other security data which is then used to access the company’s computer systems.
Internet users need to keep updated with developments in website privacy and security, to ensure that they are communicating with websites and others in a secure way.
Supporting Site 1:
Top Pagerank List - http://www.xssed.com/pagerank
This site provides a list of websites with known vulnerabilities to XSS attacks. They are listed according to Alexa page ranking – an organisation that measures traffic flow through websites. Users have the option of logging in to their email address or purchasing music through this Yahoo site, which is of a real concern to users as an XSS code in the page text can easily duplicate this information and send it to a fraudster.
I could not find a response from Yahoo regarding this vulnerability, it seems very strange that such a big company would allow this to continue.
Supporting Site 2:
Home Texts: Internet Security - http://elfguy.net/security.html
I have often referred to the presentations in this website to understand various issues dealing with the internet, I find the information very easy to read and digest.
I have chosen this site because it provides step by step instructions, in laymans terms, on how to secure your computer against general forms of internet fraud. Further information is also provided regarding the future of internet security, with clear explanations on some of the lesser known security issues in the general internet user community, such as social engineering and XSS. It’s a great resource.
Top Pagerank List - http://www.xssed.com/pagerank
This site provides a list of websites with known vulnerabilities to XSS attacks. They are listed according to Alexa page ranking – an organisation that measures traffic flow through websites. Users have the option of logging in to their email address or purchasing music through this Yahoo site, which is of a real concern to users as an XSS code in the page text can easily duplicate this information and send it to a fraudster.
I could not find a response from Yahoo regarding this vulnerability, it seems very strange that such a big company would allow this to continue.
Supporting Site 2:
Home Texts: Internet Security - http://elfguy.net/security.html
I have often referred to the presentations in this website to understand various issues dealing with the internet, I find the information very easy to read and digest.
I have chosen this site because it provides step by step instructions, in laymans terms, on how to secure your computer against general forms of internet fraud. Further information is also provided regarding the future of internet security, with clear explanations on some of the lesser known security issues in the general internet user community, such as social engineering and XSS. It’s a great resource.
No comments:
Post a Comment