ISNow – Phishing

The following introduction was originally published in the BCS Information Security Now Magazine, Autumn 2007 issue (Volume 2, Issue 1), which was on the topic of Phishing:

“Although not about whiling away a lazy afternoon, and coming home with stories about the ones that got away, phishing is about hooking unwitting victims and reeling them in. With its etymological nod to phreaking, phishing is a criminal enterprise looking to subvert a user’s system, personal or financial details.

In its simplest form, a user would receive an email requiring them to confirm account details for an online service – from an ISP, through banks and now onto ecommerce and auction sites. Through the use of social engineering techniques (lying) the sender would hope to stumble across a gullible and compliant user.

Over time, techniques have developed, with the use of cleverly counterfeited websites masquerading as the official site of bank X, the use of malware to infect the user and install monitoring software, exploiting browser weaknesses (Unicode encoded URIs, Java overlays and actual vulnerabilities) and so on.

Advances in targeting have created a spin-off technique, which is specifically targeted, called spear-phishing. This targeting could be on an individual, organisational or sector basis and can very precise and convincing. Often the information required is available from online sources or compromised systems.

Company websites, online forums and social networking sites can provide a ready-made target list and all the necessary information required to execute a convincing social engineering attack. Posting your name, age, location, interests, company, holidays, family and friends can aid an attacker in targeting you.

Defence needs a sensible level of paranoia (as someone may be out to get you) –

  • challenge everything;
  • don’t respond if you are unsure;
  • repeat.”

A PDF version of the magazine is available online at:

http://www.bcs.org/upload/pdf/isnow-autumn07.pdf