5. When spear phishers strike
Posted on 17 Jun 2008 at 10:38
Gaffe rating: 311
Web 2.0 and Software as a Service (SaaS) have become the biggest buzzwords of the past couple of years, attracting attention from the media and the malicious alike. Indeed, the internet underworld is realising it's just too sweet a honeypot to ignore, as CRM vendor Salesforce.com discovered last year.
The company was snared by a classic spear phishing technique, where a highly targeted social engineering exploit is unleashed upon a single employee to gain further access to more profitable accounts. In the case of Salesforce.com, the profitable account was one that enabled the hacker to access and copy a customer contact database including first and last names, company names, email addresses and telephone numbers of Salesforce.com customers. It was all the ammunition required to launch a further phishing spree on those customers, this time with the added bonus of having all that personal data to add authority to the scam.
Remember that not all phishers are Nigerian princes with an urge to share their bounty with the residents of Croydon. Always question why someone who has your account information should be asking out of the blue for you to repeat, add or update it. Spear phishing exploits make it harder than ever to spot the bad guy, because they will have invested time and money in making you believe. Bottom line: follow company security policy and don't reveal login information to anyone outside of its remit.
Next: 4. Most wanted: FBI distributes worm
Author: Davey Winder
advertisement
- Q&A: Why Conficker was a victim of its own success
- App developers losing faith in Android
- Biz Stone: Murdoch's Google veto will "fail fast"
- Google adds automatic captions to YouTube
- China ramps up cyber spying
- Mozilla maintains dependence on Google
- Windows 7 flying off the shelves
- Google Chrome OS: full details unveiled
- AOL slashes 2,500 jobs
- YouTube begins streaming full-length shows
- Why Britain's watchdogs have fewer teeth than goldfish
- Tabbed documents: how to make Office 2010 great
- Outlook 2010 People Pane – does it spell death to Xobni
- Microsoft Outlook 2010 screenshots
- Co-Authoring in Word 2010 and SharePoint Foundation 2010
- Microsoft Outlook 2010 screenshots: Backstage view
- Flash 10.1: Developing for Desktop and Device
- Microsoft Office 2010 screenshots: Recover unsaved items
- Microsoft Word 2010 screenshots: Text Effects
- Microsoft Word 2010: inserting screenshots
- Getting to grips with Microsoft's IT Health Environment Scanner
- Virtualise your servers
- The changing face of travel gadgets
- Build your own distributed file system
- The bulletproof Dell that costs an arm and a leg
- Microsoft Office 2010 Technical Preview: Q&A
- Lawnmowers, the TyTN II and one odd insurance request
- There'll never be a bulletproof OS
- How far can we trust apps?
- Five nice touches in Outlook 2010
advertisement
Printed from www.pcpro.co.uk

