Phishers Defeat Citibank's 2-Factor Authentication

Started by TehBorken, Jul 11 06 12:13

Previous topic - Next topic

TehBorken

Crypto experts and U.S. Government regulations (FFIEC) have been pushing the need for financial Web sites to move beyond mere passwords and implement so-called "two-factor authentication" — the second factor being something the user has in their physical possession like a token — as the answer to protecting customers from phishing attacks that use phony e-mails and bogus Web sites to trick users into forking over their personal and financial data.

According to a Washington Post Blog, 'SecurityFix,' phishers have now started [a href="http://blog.washingtonpost.com/securityfix/2006/07/citibank_phish_spoofs_2factor_1.html"]phishing for the two-factor token ID[/a] from the user as well. The most interesting part is that these tokens only give you one minute to log in to the bank until that key will expire. The phishers employ a "[a href="http://en.wikipedia.org/wiki/Man_in_the_middle_attack"]man-in-the-middle[/a]" attack against the victim and Citibank to log in using an automated web script and then immediately conduct money transfers when logged in.  
The real trouble with reality is that there's no background music.

Quick Reply

Warning: this topic has not been posted in for at least 120 days.
Unless you're sure you want to reply, please consider starting a new topic.

Note: this post will not display until it has been approved by a moderator.

Name:
Email:
Verification:
Please leave this box empty:
Type the letters shown in the picture
Listen to the letters / Request another image

Type the letters shown in the picture:

Is your grandfather's Ford Escort orbiting Jupiter right now?:
If your father was named "Bob" and you're named "Jim", what's your dad's name?:
What's the opposite of "left"?:
Shortcuts: ALT+S post or ALT+P preview