Financial web sites vulnerable to phishing attacks

27 Sep 2004

Be the first to comment

A Computing logo

Nine out of ten financial web sites contain security flaws that could expose them to phishing attacks, according to a study by Next Generation Security Software (NGS).

More than 90 per cent of web-based applications audited by NGS over the last year contained 'trivial security' or 'logic flaws' and approximately a third of the applications contained vulnerabilities that could be exploited to extract volumes of confidential customer information from back-end databases.

Further reading

The study also revealed that fraudsters were developing increasingly sophisticated forms of social-engineering to trick customers into giving away financially sensitive information.

A growth in trojan dropping viruses and spyware was also being used to solicit information for fraudulent purposes, NGS said.

'We were surprised at how naive many businesses are, and how poorly prepared they were for responding against phishing attacks targeting their own customers', said Gunter Ollmann, professional services director at NGS.

What do you think? Email feedback@computing.co.uk

If you want to be first with the news, visit Computing every day.

Reader comments

Have your say on this article

All fields required. Your email address will not be displayed on the site.

By submitting a comment you agree to abide by our Terms & Conditions

  • Digg
  • Tweet

Newsletters

Sign up for our FREE newsletters

Technology Patent Wars

Large companies such as Microsoft, Facebook and Google have been hoovering up technology patents recently. Is this stifling innovation?

87 %

5 %

8 %