Newsletter:

Skip Navigation LinksHome > News > Security > Cyber-crooks bank on free phishing kits

Cyber-crooks bank on free phishing kits

By Clement James
9 May 2008 07:39AM
Tags: cybercrooks | bank | free | phishing | kits

Security experts have discovered free phishing kits on the internet which allow cyber-crooks to send fraudulent emails..

Panda Security's PandaLabs said that the tools allow cyber-crooks to spoof bank pages, online pay platforms, Gmail and Yahoo Mail accounts, online games and blogs.

"The really amazing thing is that these kits are free," said Luis Corrons, technical director of PandaLabs.

"The number of phishing attacks increases due to the simplicity of the tools, causing companies and consumers large losses. A recent Gartner study found that phishing attacks caused US consumer losses of $3.2bn in 2007."

After accessing a URL that contains the kits, the criminal can obtain two files to create a fraudulent mail.

One file allows them to spoof emails from banks and pay platforms, and the other allows them to create a fraudulent page that resembles the original. The kit also includes a free PHP program to send emails from the spoofed page.

The rest of the process is similar to other phishing attacks. The false email is sent to several mail addresses with a link to a malicious page at which users are requested to enter personal data such as email addresses and banking passwords.

"Cyber-crooks buy lists of addresses on the internet, although some are free, " said Corrons. "If we add free hosting services, the result is that cyber-crooks can launch phishing attacks at no cost whatsoever."

Copyright © 2008 vnunet.com

   


Ads by Google


See web apps on the desktopDoes your security solution create work for you? Go Websense.
No hardware. No Software. No Fuss.
click here


Product Reviews

Star Rating
Niksun's NetDetector goes way beyond simple network-based forensics. This appliance features not only the...
Star Rating
This is a serious log analysis tool. It covers all the bases you need to cover for network forensics. The...
Star Rating
LogLogic's LX 2010 provides customers with a good feature set for network forensic investigations.
Star Rating
WetStone's LiveDiscover is an interesting proposition. It is designed as a first step in locating target...
Star Rating
This package from 8e6 Technologies offers high flexibility for the large enterprise. The bundle consists of...
ITNews NetSeminars
TopTopics
(29006) -  supercomputer
(21362) -  security
(12893) -  ibm
(10886) -  enterprise
(10667) -  supercomputers
(10261) -  microsoft
(6171) -  google
(5429) -  broadband
(5160) -  telstra
(4048) -  web
(3381) -  linux
(3234) -  internet
(3063) -  software
(2557) -  virtualisation
(2456) -  australia