|
Drive-By Phishing in the Wild |
|
Monday, 28 January 2008 |
|
Last week Symantec reported an active exploit of Cross Site Request Forgery (CSRF) against residential ADSL routers in Mexico (WHID 2008-05).
In this attack, an e-mail with a malicious IMG tag was sent to victims.
By accessing the image referenced by the e-mail message, the user
initiated a router command which changed the DNS entry of a leading
Mexican bank, making any subsequent access by a user to the bank go
through the attacker's server. |
|
Last Updated ( Wednesday, 13 February 2008 )
|
|
Read more...
|