翻訳と辞書
Words near each other
・ Inaba Masakuni
・ Inaba Masami
・ Inaba Masamichi
・ Inaba Masamori
・ Inaba Masanari
・ Inaba Masanobu
・ Inaba Masanori
・ Inaba Masao
・ Inaba Masatake
・ In-place algorithm
・ In-place matrix transposition
・ In-product communication
・ In-Public
・ In-Q-Tel
・ In-Quest
In-session phishing
・ In-SHUCK-ch Nation
・ In-sik
・ In-soo (Korean name)
・ In-sook
・ In-space propulsion technologies
・ In-Step BLUE
・ In-store financial services
・ In-system programming
・ In-tango
・ In-target probe
・ In-text advertising
・ In-Training (magazine)
・ In-vehicle parking meter
・ In-vessel composting


Dictionary Lists
翻訳と辞書 辞書検索 [ 開発暫定版 ]
スポンサード リンク

In-session phishing : ウィキペディア英語版
In-session phishing
In-session phishing is a form of phishing attack which relies on one web browsing session being able to detect the presence of another session (such as a visit to an online banking website) on the same web browser, and to then launch a pop-up window that pretends to have been opened from the targeted session. This pop-up window, which the user now believes to be part of the targeted session, is then used to steal user data in the same way as with other phishing attacks.
The advantage of in-session phishing to the attacker is that it does not need the targeted website to be compromised in any way, relying instead on a combination of data leakage within the web browser, the capacity of web browsers to run active content, the ability of modern web browsers to support more than one session at a time, and social engineering of the user.
The technique was originally documented by Amit Klein, CTO of security vendor Trusteer, Ltd.〔http://www.trusteer.com/files/In-session-phishing-advisory-2.pdf〕
== Process ==
Initial process of how phishers prepare the ground for their attacks. Phishing attacks can be subdivided into three phases:〔http://www.sciencedirect.com/science/article/pii/S1353485809700558〕
* Creation of a bogus web site that mimics the website of the bank that is the target of the attack.
* Uploading of the web page onto one's own site or else the compromising of an existing site.
* Mass emailing to lure the unwary to the bogus site.
Using the combination of all three techniques allows the attacker to carry out his plan. The attack's success, however, depends on factors such as; credibility of the site, contents of the email message, and the user's critical analysis capacity and IT proficiency.

抄文引用元・出典: フリー百科事典『 ウィキペディア(Wikipedia)
ウィキペディアで「In-session phishing」の詳細全文を読む



スポンサード リンク
翻訳と辞書 : 翻訳のためのインターネットリソース

Copyright(C) kotoba.ne.jp 1997-2016. All Rights Reserved.