New whitepaper "The Phishing Guide"

From: Gunter Ollmann (NGS) (gunter_at_ngssoftware.com)
Date: 09/22/04

  • Next message: Marc Ruef: "Pinnacle ShowCenter Skin Denial of Service"
    To: <bugtraq@securityfocus.com>
    Date: Wed, 22 Sep 2004 17:38:29 +0100
    
    

    Hi List,

    I'd like to point out that NGS have just released a new whitepaper. The
    whitepaper "The Phishing Guide" can be downloaded from:
    http://www.ngssoftware.com/papers/NISR-WP-Phishing.pdf

    Abstract

    Phishing is the new 21st century crime. The global media runs stories on an
    almost daily basis covering the latest organisation to have their customers
    targeted and how many victims succumbed to the attack. While the Phishers
    develop evermore sophisticated attack vectors, businesses flounder to
    protect their customers' personal data and look to external experts for
    improving email security. Customers too have become wary of "official"
    email, and organisations struggle to install confidence in their
    communications.
    While various governments and industry groups battle their way in preventing
    Spam, organisations can in the meantime take a proactive approach in
    combating the phishing threat. By understanding the tools and techniques
    used by professional criminals, and analysing flaws in their own perimeter
    security or applications, organisations can prevent many of the most popular
    and successful phishing attack vectors.
    This paper covers the technologies and security flaws Phishers exploit to
    conduct their attacks, and provides detailed vendor-neutral advice on what
    organisations can do to prevent future attacks. Security professionals and
    customers can use this comprehensive analysis to arm themselves against the
    next phishing scam to reach their in-tray.

    The official press release can be found on:
    http://www.nextgenss.com/pressrel.htm

    Cheers,

    Gunter
    ------------------------------------------------------
    G u n t e r O l l m a n n, MSc(Hons), BSc
    Professional Services Director
                                                          
    Next Generation Security Software Ltd.
    First Floor, 52 Throwley Way Tel: +44 (0)208 401 0070
    Sutton, Surrey, SM1 4BF, UK Fax: +44 (0)208 401 0076
    http://www.nextgenss.com
    ------------------------------------------------------


  • Next message: Marc Ruef: "Pinnacle ShowCenter Skin Denial of Service"

    Relevant Pages

    • [REVS] Understanding and Preventing DNS-related Attacks by Phishers
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... This paper, extending the original material of "The Phishing Guide", ... Internet-based customers are dependent upon, and how they can be exploited ... This paper focuses upon a recent group of attack vectors used by criminals ...
      (Securiteam)
    • Re: PayPal and Ebay scams
      ... And phishing would sink them just how? ... It ain't their security under attack ...
      (alt.marketing.online.ebay)
    • Re: PayPal and Ebay scams
      ... >>attack on their security. ... > And phishing would sink them just how? ... It ain't their security under ...
      (alt.marketing.online.ebay)
    • Re: hidden files
      ... themselves by phishing you immediately after you made a purchase? ... would even HAVE to attack you, let alone want to, in stead of skipping ... If one rules out 1 on the basis that its the first amazon phising ... One instance does not a pattern make. ...
      (alt.computer.security)
    • Re: Phishing
      ... Phishing is not really all that new. ... Other than warning it's customers, an online banking site could also ... >network analyzers. ... PGP / XML GATEWAY APPLIANCE ...
      (Security-Basics)