Pharming attacks

May 24, 2005, 8:57pm PDT | Length: 00:02:22
It's related to phishing, but even more sinister. Find out how pharming attacks hijack Internet domains and what you can do to protect yourself.

Transcript

Pharming attacks

'm Robert Vamosi, senior editor, CNET and today I'm talkingabout pharming attacks, which are related to phishing and what it is, is a wayof hijacking an Internet domain. What makes it insidious is you have no way ofknowing that it's going on.

What I've done here today is I mapped out how your typicalbrowser request a Web page to show up on your computer. So you start out liketyping in a common name for your bank. Your computer sends out a request towhat's called a Domain Name Service server that replies with an address on theInternet in numerical expression, which goes back to your computer and thengoes out to that address on the Internet and connects to the bank. The bankthen sends back the page that you want to see to connect.

Now, in a pharming attack, somebody has managed to rewritethe Domain Name server address. So when you send out the request for bank.comand it goes to the DNS server, it comes back with a fraudulent address andinstead of connecting to the bank you connect to a fraudulent server over here,which we all know from phishing experience can be very convincing when the Webpage comes back, it looks very similar to what you expected to find, exceptthere may be additional information that you didn't plan on giving your bank.

Is there anything that can be done about a pharming attack?Well, yes there is and something that the bank can do by turning on acertificate authority and what happens there is the request that you send outstill goes to the DNS server. The DNS server brings back the numerical address.It connects to the bank, but now the bank turns on an additional feature, whichsends out a message to a trusted authority, and the trusted authority says,yes, this is the numerical address that I show for the bank. This is in factthe bank that you are connecting to. You see on your screen a little pop-upmessage that says you are connecting to the bank you say, yes and there's theactual Web page. So here's one method in which you can fight a pharming attack.

Business class SaaS

Business class SaaS

Sponsored: The Software as a Service market is expected to double by 2012. Martin Capurro,...

Getting hooked: Phishing, pharming and online threats

Getting hooked: Phishing, pharming and online threats

Sponsored: There's no shortage of malicious code on the Internet. Agent Peterson of the Geek...

Vista: User account security

Vista: User account security

David Berlind, executive editor at ZDnet, explains how new security features in Windows Vista...

Protect privacy with encryption

Protect privacy with encryption

Sponsored: Paul Needham, director of product management for database security at Oracle,...

Vista: User account security

Vista: User account security

David Berlind, executive editor at ZDnet, explains how new security features in Windows Vista...

Security in a Web  2.0 world

Security in a Web 2.0 world

Malware is increasing with the popularity of social networking sites. Dan Nadir, vice president...

Two-factor authentication

Two-factor authentication

Dennis Hoffman, vice president of enterprise solutions at RSA, explains how a security process...

VoIP security: The real risks

VoIP security: The real risks

Like traditional data networks, voice networks carry their share of security risks. VOIP Watch's...

Talkback - Tell Us What You Think

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

White Papers, Webcasts, & Resources

Facebook Activity