Please create an account to participate in the Slashdot moderation system

 



Forgot your password?
typodupeerror
×

Phishing Scams Incorporate SSL Certificates 316

dettifoss writes "Netcraft reports: `Internet "phishing" scams are incorporating the use of SSL certificates in their efforts to trick users into divulging sensitive login information for financial accounts.' Perhaps more disturbingly: `Scammers can also configure their web server so that deceptive SSL certificates won't trigger an alert in the user's browser. "One of the SSL encoding methods is 'plain text'," Neal Krawetz from Secure Science Corporation noted in the SANS post on the issue. "Most SSL servers have this disabled by default, but most browsers support it. When plain text is used, no central certificate authority is consulted and the user never sees a message asking if a certificate should be accepted.'"
This discussion has been archived. No new comments can be posted.

Phishing Scams Incorporate SSL Certificates

Comments Filter:

If you have a procedure with 10 parameters, you probably missed some.

Working...