News
[PSUs]| Wednesday 3rd November 2004 |
UK security company MessageLabs says it has picked up on numbers of emails being spammed out which, if viewed, run a script that redirects visits to the websites of certain banks to dummy pages, where log in details can be harvested by the attackers.
Currently the emails are low in number - around 100 - and target Brazilian banks. However, the scam is a step forward in sophistication for phishes, as it doesn't require potential victims to follow a link in an email - every attempt to log on to the target bank site will be redirected to a fake one.
Alex Shipp, Senior
ADVERTISEMENT |
|
The current form of the email carries a subject line along the lines of 'Hi, please read this important information'.
The script will only run on Windows systems with Windows Scripting Host turned on. It is not disabled by default, so most users would be at risk to this kind of attack. To check the status of your machine and disable the service there are walkthroughs provided by Symantec and Sophos.
Submit to: Digg | Slashdot | Del.icio.us | Technorati


