Slashdot Mirror


Phishing Scams Incorporate SSL Certificates

dettifoss writes "Netcraft reports: `Internet "phishing" scams are incorporating the use of SSL certificates in their efforts to trick users into divulging sensitive login information for financial accounts.' Perhaps more disturbingly: `Scammers can also configure their web server so that deceptive SSL certificates won't trigger an alert in the user's browser. "One of the SSL encoding methods is 'plain text'," Neal Krawetz from Secure Science Corporation noted in the SANS post on the issue. "Most SSL servers have this disabled by default, but most browsers support it. When plain text is used, no central certificate authority is consulted and the user never sees a message asking if a certificate should be accepted.'"

12 of 316 comments (clear)

  1. Offtopic: Slashdot tech jobs by britneys+9th+husband · · Score: -1, Offtopic

    Has anyone seen the banner ad for "Slashdot tech jobs"? Let's say you're a business, and you hire someone that found your listing through Slashdot. Are you going to act all surprised when they sit around all day... reading Slashdot? What genius thought of this?

    --
    Hear recorded Slashdot headlines on your phone! New service beta testing. Just call (248) 434-5508
    1. Re:Offtopic: Slashdot tech jobs by Anonymous Coward · · Score: -1, Offtopic

      The same fuckheads who thought up slashdot.

    2. Re:Offtopic: Slashdot tech jobs by Anonymous Coward · · Score: -1, Offtopic
      The same fuckheads who thought up slashdot.

      At least they had high enough IQs to suck you in.

  2. *The* question remains: by Anonymous Coward · · Score: -1, Offtopic

    Why is my hamster so nice? It can eat a lot and is so soft!

  3. Re:The short by Idealius · · Score: 0, Offtopic

    Flamebait +1

    For fun.

  4. Phish chicks smell bad by Anonymous Coward · · Score: -1, Offtopic

    The only time I got the clap was when I stuck it up a fucked up hippie chick in a van outside of a phish show a couple years ago. Never again.

  5. Re:SSL certificates in 2004 by normal_guy · · Score: -1, Offtopic

    What a horribly formatted post, and it got up to 5?

    --

    Linux: Free if your time is worthless.
  6. Re:FIRST POST! by Anonymous Coward · · Score: -1, Offtopic

    yeah, you missed it by a long shot, dumbass!

  7. Re:SSL certificates in 2004 by Anonymous Coward · · Score: -1, Offtopic
    At

    least

    I

    didn't

    post

    anonymous...

    it

    had to

    be

    said!

  8. GNAA Thanks You For Your Cooperation by Anonymous Coward · · Score: -1, Offtopic

    Props on the failed post.

  9. Re:Look for the cute little lock! by Anonymous Coward · · Score: -1, Offtopic

    I didn't think a euphonium could play the banjo .....

  10. Re:Interface issue by Anonymous Coward · · Score: -1, Offtopic

    There was evidence to prove that Overly Critical Guy is a lying cocksucker, but he deleted it. Think independently.