* Phishing gives way to pharming
endif; ?>Spam is nothing more than an attempt to bombard e-mail users with advertising for everything from mortgages to personal enhancement products. However, for spammers it’s not such a sweet deal in many cases – the response rate to spam is low and spam-blocking technology eliminates a lot of this stuff before it ever reaches the intended audience. Spamming evolved into phishing, in which a link in a spam message redirects you to a bogus site for a legitimate business and then asks for your account information. The next phase of this evolution – which asks you to do even less in order to get ripped off – is pharming.
Spam is nothing more than an attempt to bombard e-mail users with advertising for everything from mortgages to personal enhancement products. However, for spammers it’s not such a sweet deal in many cases – the response rate to spam is low and spam-blocking technology eliminates a lot of this stuff before it ever reaches the intended audience. Spamming evolved into phishing, in which a link in a spam message redirects you to a bogus site for a legitimate business and then asks for your account information. The next phase of this evolution – which asks you to do even less in order to get ripped off – is pharming.
Pharming is even more insidious than phishing. In a phishing attack, you at least have to click on a link in order to access a bogus Web site – even the most minimal sleuthing into the source code behind the link will usually reveal the true identity of the phisher. However, in a pharming attack, your browser gets hijacked through DNS cache poisoning, a Trojan horse or some other technique.
Even though you type a legitimate URL into the address bar of a browser, Web site redirection schemes will take you to a fake site without any clue that you’re being duped. In short, just as spoofing made the “From” lines suspect in e-mail, pharming now makes your browser’s address bar suspect. Pharming attacks can impact users of any Web browser or operating system. Companies whose Web sites were impacted by pharming during the last couple of years include eBay in Germany, HSBC Bank of Brazil and Al-Jazeera.
Combating pharming attacks can be accomplished in a number of ways, including multi-factor authentication, such as sending an authentication code to a user’s mobile phone or other device independent of the browser that may be compromised; browser plug-ins (e.g., one that Netcraft announced a couple of weeks ago); and publication of legitimate IP addresses for Web sites.
Many thanks to MX Logic for the information it supplied for this article.




