website design company
123webguru, A sophisticated ID theft operation has caught out thousands of computer users, a security firm has found.

website designHomeSite MapContact usWe are the best website design and development company
Custom web designProfessional , custom , best website web design company

Professional  custom web site design company Ecommerce website design and development
Best in the web
Website design company
We are the Best
Custom website design

website design 123webguru News Desk

BBC News

ID theft spyware scam uncovered

Thousands of computer users have been caught out by a huge ID theft ring.

Security firm Sunbelt Software said it stumbled across a US-based server storing megabytes of data stolen from compromised computers while researching spyware infections.

The server held passwords for online accounts from 50 banks, Ebay and Paypal logins, hundreds of credit card numbers and reams of personal data.

The FBI has reportedly now started investigating the ring of ID thieves.

Hidden data

The bug that has stolen all the data is thought to be a variant of a family of trojans known as Dumaru or Nibu that exploit a vulnerability in Microsoft's Internet Explorer browser.

The trojan, a malicious piece of code, automatically downloaded itself on computers when people visited sites harbouring the program.

The way the data is laid out, the quality of it, it's very easy to go through and use it for nefarious purposes
Eric Sites, Sunbelt Software
The hidden payload in this bug is a keylogger that grabs a copy of everything a user types.

What made this bug so effective was its ability to grab text stored on the clipboard and by Internet Explorer, said Eric Sites, vice president of research and development at Sunbelt Software.

Microsoft's browser has a feature, called AutoComplete, that automatically populates boxes on web forms where people typically fill in names, addresses, e-mail addresses, credit card numbers and other biographical details.

The feature is supposed to make filling in forms on websites less of a chore. In this case, said Mr Sites, it helped the ID thieves get hold of enormously valuable data.

You can also check :
website design company Top News
website design company News of the Week

Typically a keylogger produces a file containing an unbroken string of characters, said Mr Sites.

"It's usually very hard to take that and do anything with it," he told the BBC News website.

By contrast, AutoComplete data is already labelled and sorted because the browser has to know where to put each item.

"The way the data is laid out, the quality of it, it's very easy to go through and use it for nefarious purposes," he said. "This is about getting money and stealing."

Megabytes of data

The BBC News website was shown the server and some of the files containing personal data that it was storing. Each file was full of login names, e-mail addresses, credit card details and everything needed to steal someone's identity or simply empty their bank account.

Analysis of information in the files revealed login details for online services at 50 banks as well as user details for many Ebay and Paypal accounts. One bank account had more than $380,000 in it.

Sunbelt has contacted some of the people identified in the files to warn them that they have fallen victim to the bug. Banks, credit card firms, Ebay and Paypal have been told about compromised accounts.

The server at the centre of the ID theft ring had many multi-megabyte sized files on it, said Mr Sites. The server, which was based in the US, was regularly cleaned out by the thieves who created the trojan.

Infected machines sent files back hourly or when the logs of data they were collecting had reached a certain size.

Browser danger

Mr Sites said that, so far, the trojan had been found on porn sites and websites offering cracks for pirated software. But, he said, the trojan was likely to be on many other websites as it had managed to infect so many users.

Sunbelt believes the trojan has been circulating for about three weeks and in that time has probably infected thousands of victims.

The vulnerability it exploits means that all a user has to do to fall victim is to visit the wrong site.

"Type in a web link and your machine is infected," said Mr Sites. "You do not have to click on anything, the website forces the installation."

Many victims may have no idea that they have been infected.

"This version of the trojan was very successful," he said. "It was very small, hard to detect, the file had a very innocuous name and did not cause any problems to the machine.

The size and sophistication of the ID theft ring led anti-virus and security companies to quickly produce tools that can spot if a machine has been compromised by the server and clean up infected machines.

The trojan was tricky to spot because the files being sent back to the server were disguised as data traffic generated by a user's browser.

The US-based security company has alerted the FBI to the online scam and it is reportedly investigating the matter.


Story from BBC NEWS:
http://news.bbc.co.uk/go/pr/fr/-/1/hi/technology/4173218.stm


website design Top News

website design News of the Week

website design All News

 

Website design company


Website design company

123webguru Articles

Screen resolutions for websites
Normally one would find that some webpages doesn`t fit well on the screen resolution that they are viewing. Problems like scroll bar might appear, graphics ...

Website Design project development
There is no specific rule for the website design project but usually a website design companies follows four steps of the Project Development Process. ...

Use ecommerce template
With the momentous achievement the Internet has attained, everyone needs a website for one purpose or the other, as with the help of none other than this, ...

Work at Home Business
So you've decided to become financially independent! You've chosen to work at home. Congratulations! I'm sure this is a decision that can turn your life ...

About Payment Gateway Services
The biggest advantage of internet technology is providing the ability to process transactions online. The biggest boon of the internet technology to the ...

why, what, where and how
We all know the facts, and we know the figures. The internet is the single most powerful tool that we have at our disposal. It provides us with an instant ...

Website design company

 

custom
123webguru.com :  Website design company

123webguru News

Toshiba to make Microsoft's Zune
Microsoft says Japanese firm Toshiba will make its Zune portable music player, due out later this year.

Bugged bins to promote recycling
Chips in bins which help councils charge for rubbish collections could be common across the UK within two years.

Stem cell 'wonder cures' warning
Patients should beware of so-called stem cell wonder cures as most have not been properly tested, experts say.

Google to target software market
Search engine Google is entering the software market, in a move that pits it against Microsoft.

Nasa moves shuttle indoors
Nasa decides to haul the Atlantis orbiter indoors to protect it from Tropical Storm Ernesto.

website design News of the Week

Website design company

 

Free Price Quotes



Are you looking for :

Ecommerce website | Real estate website | Database driven website | Web base Application | Full Flash website | Sitemap | Flash application | Logo design | SEO | Website design company | Web programming | Website redesign and redevelopment | Development of new website | Start a new website | Custom website design

123webguru.com, A new web division of Microsec Technologies Ltd.
© 2002-2005
Website design company, All Rights Reserved
Disclaimer | Privacy policy

Website design company