10.08.2013 Views

NESTA Crime Online - University of Brighton Repository

NESTA Crime Online - University of Brighton Repository

NESTA Crime Online - University of Brighton Repository

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Fraud on fraudster<br />

The most recent step in the commoditisation <strong>of</strong> phishing is the distribution <strong>of</strong> free<br />

phishing kits. These kits are actively advertised and distributed in underground IRCs at<br />

no charge. Free phishing kits hide backdoors through which the phished information is<br />

sent to recipients (probably the original kits’ authors) other than the intended ones<br />

(Cova et al, 2008).<br />

An example is a recent phish kit targeting the Bank <strong>of</strong> America, reported at Netcraft in<br />

2008, which contains an interesting insight into the intellectual hierarchy involved in<br />

Internet fraud. The phishing kit looks attractive to any fraudster – it is straightforward to<br />

deploy on any web server that supports PHP, 152 and a single configuration file makes it<br />

easy to specify an electronic mail address to receive captured financial details. In<br />

addition to requesting the credit card numbers and bank account details, a second form<br />

on the phishing site asks for the victim's SiteKey challenge questions and answers, 153<br />

which can help a fraudster gain access to the victim's Internet banking facilities.<br />

Sources: Marco Cova, Christopher Kruegel, and Giovanni Vigna: “There is No Free Phish:<br />

An Analysis <strong>of</strong> “Free” and Live Phishing Kits”, 2008; and NETCRAFT news at<br />

http://news.netcraft.com/.<br />

Recent research on underground forums has provided valuable information about the<br />

way cybercriminals form alliances, contact specialists in complementary techniques or<br />

find individuals who can extract cash for them. 154<br />

152 PHP (PHP Hypertext Preprocessor) is an open-source scripting language used to create dynamic web pages,<br />

PHP can also be used to connect to a database; to retrieve, add or update content.<br />

153 SiteKey questions and answers is a method <strong>of</strong> authentication to prevent unauthorised access to a person’s<br />

account. The questions are only shared between the financial institution and the customer. Their primary<br />

purpose is to deter phising.<br />

154 Symantec (2008), “Symantec Report on the Underground Economy”, July 2007–June 2008; Finjan (2008),<br />

Malicious Code Research Center, Web Security Trends Report Q2 2008.<br />

Page 51

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!