Alert sounds alarm on phishing imposters

A new online service promises to send an e-mail alert when a Web site is copied and possibly used in a phishing scam.

The free service, dubbed PhishRegistry.org, is run by e-mail security company CipherTrust. Web site owners can use the service to monitor abuse of their brand, while consumers can submit URLs they use, such as a bank Web site, to the list of those monitored, CipherTrust said in a statement on Tuesday.

The Web addresses are submitted via forms on the PhishRegistry Web site. The system then analyses the legitimate site using CipherTrust's "Phisherprinting" technology, the company said. The technology essentially creates a "fingerprint" of the genuine pages using source code, images and text as markers.

After that, the system scans the Web and when it comes across a site, determines whether it is authentic by comparing the markers. It sends out an alert when attempts to duplicate the legitimate site have been detected. Site owners will receive weekly reports with information about suspect Web sites, the company said.

Phishing is a prevalent type of online scam in which attackers attempt to dupe Internet users into giving up sensitive data such as user names, passwords and credit card details. The attacks typically combine spam e-mail and fraudulent Web pages that look like legitimate sites.

A common method used to combat phishing is to blacklist known bad sites and to then prevent access to them.

"Blocking does not solve the problem. It's just a temporary fix," Paul Judge, chief technology officer at CipherTrust, said on Tuesday at a spam event hosted by the Massachusetts Institute of Technology. "Our main purpose is to give ammo to the companies being phished so that they can go and perform take-downs of the phishing sites."

The CipherTrust announcement comes on the heels of another effort to help fight phishing. On Monday, Sunbelt Software and online security community CastleCops launched the Phishing Incident Reporting and Termination squad, a volunteer effort to take down phishing Web sites.

Despite industry efforts, phishing is still on the rise. A record 9,715 phishing Web sites were spotted in January, according to a report from the Anti-Phishing Working Group.

CNET News.com's Candace Lombardi contributed to this report from Boston.

Advertisement

Talkback 0 comments


Latest Videos

ZDNet's CIO Vision Series

Department of Defence | Greg Farr, CIO (part two)

In the second part of his interview, Defence CIO Greg Farr talks about outsourcing, the skills crisis and reveals his most urgent IT priority.

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Jude Willis Why eBay tried to screw Aussie users
    Now that the bizarre ruckus over eBay's proposed PayPal monopoly appears totalled, it seems a good time to ponder why eBay chose Australia to risk its reputation on such a massively unpopular scheme.
  • Array The more things change…
    With all the excitement over the iPhone, few people have noticed that 1 July was the 11th anniversary of the deregulation of Australia's telecommunications market.
  • Array I'm a celebrity, don't back me up
    Celebrity comes with its perks — free alcohol, better-looking partners, lots of holiday time — and disadvantages — constant media intrusions, being forced to appear in films with Eddie Murphy for the long-term good of your career, and having to do mindless radio interviews with angry men who've been awake since 4am.
  • More blogs »

Tags

Back to top

Featured