Print | Send on Yahoo! | PDF version | Feed RSS | Filed Under: ALERTS

Lloyds TSB on-line credentials sought by phishers

Date: 06/24/2009
Author: Razvan Livintz

Simple and efficient fraudulent scheme

Lloyds TSB is challenging the Top ten most counterfeit bank identities described in our latest E-Threats Landscape Report. This time, with a not so flashy, yet nifty unsolicited message, that requires customers to follow a link and confirm their account information, after an alleged attack.

Phishing

The link does not lead to the e-banking portal, but to a collection of Web pages that employ several visual identification components of the original Web site, namely the bank logo (a bit blurry and disproportionately resized) and the general formatting elements.

Phishing 2

The e-thieves seem to be interested only in the User ID and password, which they pilfer via login.php script, and the memorable information, which they lift using login1.php script.

Even though all menu options are available, clicking any of them will return a "404 Page Not Found" message. Moreover, one can easily see that the Web page address mimicking the genuine Web site loads from a domain registered in Brazil (.br instead of .com).

And, as usual, there are no specific security elements, one could expect to find on an e-banking site, namely SSL encryption (Secure Socket Layer) and security authentication methods (no "https" prefix and locked padlock).

Phishing

Share our story:
DiggStumbleUpondel.icio.usYahooMyWebFurlGoogle

Comment on this:
Name:
Email:
Your email address will not be published!

Please enter the code from the image below.
The code is not case sensitive
Verification Image
Reload image
 
 
Calendar
March 2010
MoTuWeThFrSaSu
1234567
891011121314
15161718192021
22232425262728
293031    
« Feb March Apr »
Tag Claud
trojan omelette message virus malware canadian software word exploit data antivirus files microsoft pharmacy rogue system worm infected review bitdefender online downadup windows computer file conficker spam security messages twitter