Phishers Evolve to ‘Pharming’

LOS ANGELES — Phishers have recently begun to use at least three new types of attacks in order to convince Internet users to visit bogus sites, including DNS wildcard and poisoning attacks, and URL encoding.

Termed “pharming” by Internet research group Netcraft, the new combination of attacks allows perpetrators to redirect users to seemingly genuine sites that even bear what appear to be correct domain names.

“Phishing is throwing the bait out and hoping to get a bite,” MX Logic CTO Scott Chasin told Government Computer News. “Pharming is planting the seeds and not trusting to chance.”

A recent scam that involved misdirecting Barclays Bank users and stealing their financial information utilized DNS wildcards and URL encoding. Instead of pointing to the bank’s legitimate site, located at https://barclays.co.uk, the email pointed to sites like https://barclays.co.uk|YJ3EMOHOqljQ8J5oW2ZKyTaRMQOahSWazTrFTEQK919VVQj6jDtyq10d24r2h0bijh2, which actually points to a third-party redirection service that instead sent surfers to a spoofed Barclays page located in Moscow.

Netcraft has also warned that attackers are beginning to use DNS cache poisoning to subvert Internet users. The group pointed to an attack that occurred on Saturday, when a group of hackers managed to exploit a known vulnerability in Symantec firewalls to inject false information into DNS servers and reroute some traffic to Google.com, eBay.com and Weather.com to three sites that attempted to install spyware on visitors’ computers.

Luckily, most URL encoding attacks are specific to certain types of systems and don’t work overall. The address above, which features a pipe character, would work on Windows XP, for example, but not on Linux.

DNS poisoning is harder to detect. One of the few options is to trace the geographic location of the website using its IP address, but even that may not paint a whole picture. For example, if users encountered a U.S. bank site that was located in Russia, it might set off alarms, but if a user encountered a U.S. Bank site that was located in Pittsburgh instead of Pennsylvania, it might seem significantly less suspicious.

“We’re starting to see some movement in this, but it is slow,” Chasing said. “We’re not trying to hawk any of these solutions. But we live in the email defense world, and pharming is a tremendous threat to our world.”

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Proposed New Hampshire AV Bill Appears to Violate Constitution

A bill in the New Hampshire state legislature, aimed at requiring adult sites to age-verify users in that state, contains a provision that seemingly contradicts the Supremacy Clause in Article VI of the U.S. Constitution.

AEBN Publishes Report on Fetish Trends

AEBN has published a report on fetish categories from its straight and gay theaters.

Online Child Protection Hearing to Include Federal AV Bill

A House subcommittee will hold a hearing next week on a slate of bills aimed at protecting minors online, including the SCREEN Act, which would make site-based age verification of users seeking to access adult content federal law.

Industry Photographer, 'Payout' Founder Mike B Passes Away

Longtime industry photographer and publisher Michael Bartholomey, known widely as Mike B, passed away Saturday.

FSC Announces 2025 Board of Directors Election Nominees

The Free Speech Coalition (FSC) has announced the nominees for its 2025 Board of Directors election.

AdultHTML Launches Black Friday Web Design, Development Promo

AdultHTML has launched its annual Black Friday/Cyber Monday promo for web design and development, running through Dec. 5.

Canada Exempts Online Adult Content From 'CanCon' Quotas

The Canadian Radio-television and Telecommunications Commission (CRTC) has updated its broadcasting regulatory policies, exempting streaming adult content from “made in Canada” requirements that apply to other online material.

Creator Law Firm 'OnlyFirm' Launches

Entertainment attorney Alex Lonstein has officially launched OnlyFirm.com for creators.

German Court Puts Pornhub, YouPorn 'Network Ban' on Hold

The Administrative Court of Düsseldorf has temporarily blocked the State Media Authority of North Rhine-Westphalia (LfM) from forcing telecom providers to cut off access to Aylo-owned adult sites Pornhub and YouPorn.

FSC: NC Law Invalidating Model Contracts Takes Effect December 1

The Free Speech Coalition (FSC) has issued a notice that North Carolina's Prevent Exploitation of Women and Minors Act goes into effect on December 1.

Show More