• TLS/SSL Certificate Brands
    • RapidSSL - simple site security for less. It provides basic level customer confidence with the https, closed padlock and a static trust mark.
    • A range of digital certificate and trust products enable organizations of all sizes to maximize the security of their digital transactions cost-effectively.
    • The ideal solution for enterprises and large organizations. The Internet most recognized and trusted SSL brand.
    • A quick, cost-efficient, and effective solution to build secure connection. PositiveSSL certificates show your customers you’re employing serious security measures to keep their transactions and data safe.
    • SECTIGO, formerly COMODO CA, Creating trust online for individuals, e-merchants, enterprise, with its robust SSL security.
    • i
      How organizations best manage their certificate lifecycle?


      Download E-book
  • Certificate Products
    • Single Domain SSL
      One for main domain with free 'www' coverage.
    • Wildcard SSL
      Protect unlimited sub domains under main website.
    • Multi-Domain SSL
      One certificate for multiple domain names.
    • Domain Validation SSL
      It is quick and cost-efficient, really. Basic protection.
    • Organization Validation SSL
      It gives your website an online idenity. For SMBs to strengthen web trust.
    • Extended Validation SSL
      Stand out your buiness entity, protect brand and transactions.
    • Email (Client) Certificate
      Encrypt and signed email, enable two-factor authentication, and implement strong digital trust practices throughout your organization.
    • Code Signing Certificate
      Boost Software Adoption and improve customer's trust with Code Signing. Digitally sign Code across popular platforms.
  • Domain & Email
    • Domain Name Registration
      Get your perfect domain name
    • Domain Reseller
      Reseller Pricing & TLDs
    • Transfer Domain
      Transfer domain into BestCert
    • Business Email
      Business Email builds customer trust
  • Site Builder
  • PKI Solutions
  • Partner
  • About Us
虚假弹窗收集用户数据 - 新型网络钓鱼攻击

近期,安全人员发现一种新型的网络钓鱼攻击事件,目前主要针对Facebook及Google用户,以诱骗用户在线账户为目的,即使非常警惕的用户也很可能会中招。


   

安全人员文森特发现,网络犯罪分子正在分发博客和服务链接,提示访问者使用Facebook或Google账户登录,以便“阅读独家文章或购买折扣产品”。

使用Facebook和其他社交媒体账号登录可以方便使用者快速注册第三方服务,目前已被大量网站采用。通常,当您点击任何网站上的“使用Facebook登录”按钮时,将被重定向到该网站或通过该网站提供的在线弹出式浏览窗口,输入自己的Facebook用户凭据进行身份验证,并允许服务访问您的个人资料等必要信息。

然而,文森特发现,恶意博客在用户点击登录按钮后,为用户提供了一个非常逼真的假的Facebook登录提示弹窗,该登录按钮旨在捕获用户输入的凭据,就像任何网络钓鱼站点一样。

虚假弹窗实际上是使用HTML和JavaScript创建的,看起来完全和合法的浏览器窗口一样,显示状态栏、导航栏、阴影和带有绿色锁的Facebook网站的URL。根据文森特的说法,保护自己免受此类网络钓鱼攻击的唯一方法是,“实际上是尝试将弹窗提示拖离当前显示的窗口。如果将其拖出失败(弹出窗口的一部分消失在边缘之外),这就明显表示弹出窗口是假的。”

网络钓鱼攻击仍然是用户和企业面临的最严重的安全威胁之一,黑客不断尝试更多创新性的方法诱骗用户敏感信息或在线账户,国内同样存在使用社交媒体账户登录第三方服务的模式,这类网络钓鱼攻击方式也可能被复制用于针对国内用户。


文章来源:互联网


厦门聚力诚信科技有限公司(BestCert.net)是网络安全领域的专业服务提供商,专注提供SSL证书,邮件安全证书,代码签名证书等国际、国密双算法的数字证书管理服务, 涵盖所有市场主流的SSL证书类型和品牌,从证书的申请,验证,安装,证书专家全程在线支持!公司同时为各行业客户提供电子签章,身份认证等电子认证服务解决方案。





Chat Now

Email Us

Email Address:

sales@bestcert.net

Top