Fraud protections of Firefox and Chrome are vulnerable to phishing

March 17, 2011 - 3:59am | Fraud | News |
| More
  
Fraud protections of Firefox and Chrome are vulnerable to phishing

According to a research conducted by a security group Firefox and Chrome browsers cannot detect new phishing attacks that targeted recently customers of Bank of America and PayPal. The phishing scam manages to bypass fraud protections built in to the Mozilla Firefox and Google Chrome by attaching an HTML file to the spam email.

According to M86 researcher Rodel Mendrez, the locally stored file opens a web form that collects the customers' login credentials, credit card numbers and other sensitive information and then uses a POST request to zap them to a PHP application on a legitimate website that's been compromised. By avoiding the use of more verbose GET requests and known phishing sites, the scam flies completely under the radar of the browsers' fraud protection features.

“While the POST request sends information to the phisher's remote web server, Google Chrome and Mozilla Firefox did not detect any malicious activity,” Mendrez writes. “Months-old phishing campaigns remain undetected, so it seems this tactic is quite effective.”

There's no technical reason why the browsers can't flag the URL that accepts the POST request. Mendrez posits that few PHP URLs get reported as abusive by most end users because of the technical expertise that's required. With not visible HTML accompanying them, there's little for the average user to go on.
 




RSS feed Subscribe to Ecommerce Journal RSS feed

Tags keywords: Chrome | Firefox | fraud | google | Mozilla | phishing | spam | web browser
0 points

   Tell us what topics you want to be covered in the Ecommerce Journal?  
Image CAPTCHA
  


Comments on Fraud protections of Firefox and Chrome are vulnerable to phishing




Similar Articles on Ecommerce Journal by sections

FIGURES
PAYMENT SYSTEMS
BANKS
PLASTIC CARDS
ECOMMERCE-CHECKED
INVESTMENT INDUSTRY
FRAUD
ANALYTICS
OTHER THEMES
INTERVIEWS
LAW ASPECTS