Lost Password? No account yet? Sign up! Why bother?
  • Narrow screen resolution
  • Wide screen resolution
  • Auto width resolution
  • Increase font size
  • Decrease font size
  • Default font size

SmallNetBuilder - Small Network Help

  
Home arrow Security arrow Security Features arrow Ignorance is Bliss? An Introduction to Internet Security - Part 2
Ignorance is Bliss? An Introduction to Internet Security - Part 2 Print E-mail
Pat McKenna   
March 27, 2006

Attacking The Login Page, Continued

Next, go to your Google page and enter 'screen scraper'. Now what you get is a listing of programs that grab an image of your desktop screen, like when you press the Print Screen button on your keyboard.

Attacking The Login Page, Continued

Now for the kicker - there are programs out there on the net that will do both of these tasks. Some of them come in the form of Trojan horse and spyware programs. These are downloaded onto your system, usually where you stumble across sites hosting pages where they are embedded - especially porn-related ones - or are perhaps received by email.

If you are infected with such a program, your confidential data will be captured as you enter it. At some time thereafter, your vital information will be appended to an email that reaches the hacker. Alternately, it may be silently 'piped' directly to a purpose-built server that harvests such information for later retrieval by the hacker.

You now know that these programs exist, and hopefully can understand that they are capable of recording and passing on vital information. In that light, it isn't difficult to see why the common logon box is such an easy target. Now think about those sites where you have submitted your credit card details, and where you have agreed to store that data for subsequent and convenient one-click purchasing...

But let's return to the attack on our login page. When the page is submitted, it passes typically with a POST or GET HTTP Request to its action target. Let us decipher some of this jargon.

HTTP stands for Hyper Text Transfer Protocol, and is the method by which pages of information are formed and transmitted across the Internet. A form can be passed in two ways: through a POST request or a GET request. Suffice to say that both are methods through which data is passed from a browser to a site. Each HTTP request can have a response, so when you submit a search for data from Google, the returning page is an HTTP Response.

Now there are two possible ways to have the data reach its intended target. It can either be encrypted using a mechanism such as Secure Sockets Layer (SSL, using a prefix of HTTPS://) or the information can be sent in the clear (HTTP://).

Either way it can be attacked, but to elaborate on how this can occur, we need to walk through a few concepts first.



Tags: Internet Security,

Related Articles:

They're Out to Get You - An Introduction to Internet Security
Factor Authentication in Online Banking
How To: Fixing DNS problems
How You Are About To Become Responsible For Credit Card Fraud
Privacy Policy
 

Most Read

 
 

Over At The Forums

Drobo vs NAS
Anyone knows of a NAS that works like a drobo? Im looking for a NAS that works a similar way. Data redundancy against HD failure...

Whazzup with DAP-1555? Has DLINK dropped it?
Im looking for a good wireless N access point and the 1522 intenna design got no connectivity for me. The 1555 has external antennas...

About the new Linksys mediahub
I was looking at the new Linksys media hub. It does look like everything I would need, with a simple clean interface. My big question...

what gigabit switch would be good for home use
I'm building a new house for the moment, and will need switch with at least 16 gigabit ports. My electrician proposed a switch of Allied...

6TB NAS for surveillance video
i am in the design phase for a fairly large ip surveillance camera project for a client. i am looking at three 24 port...

Slideshows

Linksys Media Hub LaCie 5big Network Jazinga IP PBX NETGEAR ReadyNAS Pro Western Digital ShareSpace QNAP TS-509 Pro More
Go Shopping with PriceGrabber

Get Email Updates

Enter your email address:

Delivered by FeedBurner once a day

 
 

Ldr:0.00171589851379, Rct:0.00718307495117, Sky:0.00887989997864, Tlink:0.323771953583, TopPG:0.323862075806, GQV:0.324027061462 seconds to load.