Keylogging Used To Catch Bank Crackers
An anonymous reader writes "BBC News is reporting that the British police National High Tech Crime Unit has foiled an attempted fraud by hackers using keylogging software. The London branch of the Sumitomo Mitsui bank of Japan was the target, and a person has been arrested in Israel after being identified as the recipient of an attempted electronic transfer of UKP13.9m."
The crooks were the ones using the keyloggers, not the people who caught them!!!!!!
How do you manage to get key-logging software onto a bank system without physical access?
Is this more examples of social engineering, or would this have required physical access to the computers? [ I'm assuming here that the general bank computers aren't all on the interweb ]
Scary as hell that someone (almost) managed to do this.
Lost at C:>. Found at C.
The ambiguous story description could be interpreted to mean either that the crackers installed the keylogger, or that they were caught by keyloggers. Any sensible reader would know that the crackers probably weren't caught by keyloggers, because they'd already have too much access by that point. But even just reading the story shows that their attack was by keylogger, not their capture.
Now it's obvious: Slashdot submission approvers (staff "authors" who vet the submission queue, to approve stories for publication) just read the text, and decide whether the story is interesting. They don't click the links, they don't think about whether anything makes sense. It really looks like Slashdot's submitters are higher quality than the editors who decide what to publish. And even worse, the editors seem to have the quality of a lower tier of Slashdot readers: grab the most inflammatory interpretation of a post, and run with it - without regard to the facts, or even just the story itself.
For all Slashdot's championing of the "open" community, we know very little of how the editorial process works. How many editors? Do they know each other? See each other, or work remotely? Is there an editorial policy, written or by "rolling consensus"? Are their criteria? What's the process like? With the published Slashcode so old, there's no way to know details about the queue process even by looking at "the" software. So what goes on there behind the curtain?
--
make install -not war