Movatterモバイル変換


[0]ホーム

URL:


Sign in / up
The Register

Channel

This article is more than1 year old

Barclays scripting SNAFU exploited by phishers

Read trawl about it

iconJohn Leyden
Tue 15 Aug 2006 //10:01 UTC

Online scammers are exploiting a redirection script on Barclays' site to make fraudulent emails look more convincing. An alertReg reader noticed the trick in scam emails he received.

We have yet to hear back from the bank, despite notifying Barclays of a potential problem last Tuesday (8 August). Meanwhile, the exploit (details of which we are withholding) remains open to abuse.

A similar attack, again ostensibly pointing to Barclays' website, but in reality directing surfers towards a phishing net, has been reported by other fraud watchers (seehere). The other scams detailed by anti-phishing website MillerSmiles have a URL that more obviously points to something that's nothing to do with the targeted organisation (examplehere).

Our reader describes how the tactics used in the Barclays scam might trap the unwary: "Barclays Bank's website has a security flaw which will allow a phisher to provide a link which appears to be a legitimate Barclays URL, but actually redirects to fraudulent site. It seems very irresponsible to not do any checking that a URL is internal, or legitimate, before redirecting," he said.

eBay was the target of a similar attack last year. In that case, it took eBay some weeks to address the flaw. We can only hope that Barclays moves quickly to block off the possible route of attack.

Web security firm MessageLabs said redirection attacks that exploit security flaws on target websites are growing in prevalence. "Barclays is not the first. We have stopped several of these attacks in the past year," it said. ®


More about


TIP US OFF

Send us news


Other stories you might like

Mobile industry warns patchwork cyber regs are driving up costs

GSMA says fragmented, poorly designed laws add burdens without making networks any safer
Security26 Nov 2025 |1

Doom hits KiCad as PCB traces become demons and doors

Engineer bends layout tool into vector renderer, then pushes frames through a MacBook's headphone jack
Software26 Nov 2025 |4

CodeRED emergency alert system CodeDEAD after INC ransomware attack

Regions across US affected, and one tore up its contract for the product
Cyber-crime26 Nov 2025 |3

Bring complexity under control with enterprise-grade Kubernetes

No, it'll probably never be a doddle – but you don't have to take the hard way when deploying Kubernetes, says Nutanix
Sponsored Feature

US Navy scuttles Constellation frigate program for being too slow for tomorrow's threats

Service limits 20-ship line to two hulls after redesigns and delays torpedo schedule
Offbeat26 Nov 2025 |15

Workday confronts existential threat as customers freeze hiring

HR software vendor pushes cross-selling as modest workforce growth exposes vulnerability of per-seat pricing
SaaS26 Nov 2025 |4

HSBC spies $207B crater in OpenAI's expansion goals

Gap threatens Oracle, Microsoft, and Amazon despite optimistic forecasts of 3 billion ChatGPT users by 2030
AI + ML26 Nov 2025 |18

Crocs get the Xbox treatment with sole-crushing price of $80

Time to test just how far fandom and taste will stretch
Offbeat26 Nov 2025 |13

The exascale offensive: America's race to rule AI HPC

Feature From nuclear weapons testing to climate modeling, nine new machines will give the US unprecedented computing firepower
Supercomputing Month26 Nov 2025 |3

London councils probe cyber incident as shared IT systems knocked offline

Three boroughs confirm investigation amid service outages, disrupted phone lines, and limited online access
Cyber-crime26 Nov 2025 |4

Tuxedo Computers slams lid on Arm Linux laptop after 18 months of pain

Planned Snapdragon goes puff and disappears, but the code will survive
Personal Tech26 Nov 2025 |18

Seven years later, Airbus is still trying to kick its Microsoft habit

Exclusive Google Workspace switch drags on amid Excel dependencies, compliance requirements, and compatibility issues
SaaS26 Nov 2025 |26

[8]ページ先頭

©2009-2025 Movatter.jp