For example, if a bank's DNS were changed, users could be redirected to a Web site that looks familiar. The bogus site could just collect usernames and passwords, or it could allow access to the site and, using some pretense, request financial information. Unlike phishing schemes that use e-mail to make people go to the phony site, pharming is more natural. Users are going to the site on their own and are certainly not suspicious because the pages look familiar. See phishing and DNS hijacking.
![]() | Reproduced with permission from Computer Desktop Encyclopedia. Copyright (c) 1981-2009 The Computer Language Company Inc. All rights reserved. |
Additional Resources
- Trend Micro Internet Security 2010
- Photo gallery:Trend Micro Internet Security 2010If you're looking for a robust feature set from your security suite, and you're looking for an affordable price, you could do worse than Trend Micro's 2010 products. Trend Micro has refreshed it Internet Security Pro, Internet Security, and the stripped-down AntiVirus plus AntiSpyware packages;...
- Product reviews 2009-08-28
- Anti-Phishing Based on Automated Individual White-List
- In phishing and pharming, users could be easily tricked into submitting their username/passwords into fraudulent web sites whose appearances look similar as the genuine ones. The traditional blacklist approach for anti-phishing is partially effective due to its partial list of global phishing sites. This paper presents a novel anti-phishing approach...
- White papers 2008-10-31
- Pharewell to Phishing: Secure Direction and Redirection Over the Web
- The conventional wisdom has always been that users should refrain from entering their sensitive data (such as usernames, passwords, and credit card numbers) into httpor white pages, but they can enter these data into https or yellow pages. Unfortunately, this assumption is not valid as it became clear recently that,...
- White papers 2008-10-13
- Cybercriminals syndicating Google Trends keywords to serve malware
- Cybercriminals syndicating Google Trends keywords to serve malwareLarge networks are increasingly...being used to comprimise the Internet. These commercial networks are too large to be managed by hands-on real people and are being managed by technology. Things are only going to get worse. If these networks can't be properly managed they...
- Discussion threads 2008-10-03
- Phishing, Pharming, and Vishing, Oh My! a Guide to the "INGs" and How to Remain Protected
- More recently, a New York Times article highlighted the flaw and the resulting leaks in the "Cobbled-together patch." The flaw in the DNS Domain Name System, which acts like the Internet's telephone book, could allow Internet traffic to be secretly redirected so thieves could, for example, hijack a bank's Web...
- Webcasts 2008-09-11
- Minimizing SSO Effort in Verifying SSL Anti-Phishing Indicators
- In an on-line transaction, a user sends her personal sensitive data (e.g., password) to a server for authentication. This process is known as Single Sign-On SSO. Subject to phishing and pharming attacks, the sensitive data may be disclosed to an adversary when the user is allured to visit a bogus...
- White papers 2008-09-05
- Does TraceMonkey kick Firefox into turbo mode?
- Does TraceMonkey kick Firefox into turbo mode?Wow, we are breaking down the barriers to web application adoption for allof our every day applications. The speed here will be so close to natively compiled code that it will not matter any more. But, we still need some kind of a sandboxed...
- Discussion threads 2008-08-26
- DNS cache poisoning attacks exploited in the wild
- UPDATE: Arbor Networks have provided more details in their "30 Days of DNS Attack Activity" analysis, SANS confirmed HD Moore's statement on DNS cache poisoned AT&T DNS servers. Numerous independent sources are starting to see evidence of DNS cache poisoning attempts on their local networks, in what appears to be...
- Blog posts 2008-07-29
- Understanding Pharming (Mobile)
- Brought to you by: Turn Key Technology Solutions, along with HOT LAVA SOFTWAREDo you know what pharmingis? Even if you've heard of it before, do you know how to protect yourself from it? With this comprehensive module you will understand pharming and how it's being prevented.You will learn:what pharming exactly...
- Software downloads 2008-07-14
- Protect Your Organization and Customers From a Wide Variety of Online Attacks Using Symantec Online Fraud Protection
- This webcast explains how Symantec Online Fraud Protection protects such organizations and their customers from losses that can result from online fraud. It helps protect against the threats of identity theft, phishing, pharming, and other varieties of online fraud to preserve the organization's brand, improve customer loyalty, minimize losses, and...
- Webcasts 2008-05-21
- Providing End-to-End Protection to Online Users
- With the rise of threats such as phishing, pharming and key stroke logging, strong authentication is essential to ensuring customers have a safe and secure online banking environment where they can transact. Even prior to the FFIEC guidance issued in October 2005, the Information Security IS team at Zions Bancorporation...
- Case studies 2008-01-01
- Getting hooked: Phishing, pharming and online threats
- Sponsored: There's no shortage of malicious code on the Internet. Agent Peterson of the Geek Squad offers some tips on how to protect yourself from viruses and spyware. The content for this video was sponsored and provided by Geek Squad.
- Whiteboards 2007-11-15
- Dynamic Pharming Attacks and Locked Same-Origin Policies for Web Browsers
- This paper describes a new attack against web authentication, which the paper calls dynamic pharming. Dynamic pharming works by hijacking DNS and sending the victim's browser malicious Javascript, which then exploits DNS rebinding vulnerabilities and the name-based same-origin policy to hijack a legitimate session after authentication has taken place. As...
- White papers 2007-11-02
- Information security by the numbers: It's not pretty
- A pair of security surveys were released Tuesday and the findings aren't pretty. First up, the Computing Technology Industry Association CompTIA released a survey on information security breaches. Among the findings: Among companies that reported a security breach in the last year, the...
- Blog posts 2007-09-18
- Unified Threat Management Appliances and Identity-Based Security: The Next Level in Network Security
- Enterprises, regardless of size, are increasingly realizing that their computer systems are vulnerable to as many security threats from within the company as from without. These insider threats lead to security loopholes created out of user ignorance and malicious intent with unauthorized access, leading to loss of data confidentiality, bandwidth...
- White papers 2007-09-01
- The Web Isn't Fun Anymore: How Websense Technology Protects Against Internet-Based Threats
- The Internet - with its wealth of information and features that are integrated into everyday lives - has become a necessary tool for business and provides a vast array of options for personal use. However, it does have a dark side. Over the past several years, the Internet has become...
- White papers 2007-08-01
- Catbird secures virtualized environments
- A short while ago, I had a wonderful conversation with Edmundo Costa, CEO, and Tamra Newberger, VP of marketing, of Catbird , about a new product they were launching. Since I've spoken with them many times in the past when they were associated with Tarantella and the Santa Cruz Operation,...
- Blog posts 2007-07-05
- RSA's Two-Factor Authentication Helps Forward-Thinking Specialty Banks Strengthen Protection for Online Customers
- The Internet has become an integral part of the overall business strategy for most financial institutions - it can help reduce costs and increase efficiency. Yet, with threats such as phishing, pharming and other types of fraud, financial institutions must provide their customers with a secure online environment to transact...
- Case studies 2007-06-01
- Remote vulnerability in high-profile Firefox extensions
- Today is Firefox Patch Day but even after you install the latest security updates from Mozilla, those browser extensions you use and love could put you at risk of code execution attacks.According to independent researcher Christopher Soghoian of boarding pass hacker fame, there's a remote vulnerability in the upgrade mechanism...
- Blog posts 2007-05-30
- I've got two free 'ID Vaults' for the members of ZDNet's audience who....
- Two Friday's ago, I announced ZDNet's Deputy Tester of the Week program. The following Monday, in search of our first deputy testers, I offered three free copies of PPTMinimizer 3.0 to the members of ZDNet's audience who needed a utility like that for compressing PowerPoint files into more manageable...
- Blog posts 2007-05-29
Neighboring Terms
Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
- Learn more about tools to grow your business
-
The Business Essentials Guide provides you useful tools and templates to help grow your business and save you time with automated shipping solutions.
- Save time with the UPS Business Essentials Guide
- The best support in the Linux business
-
If Linux is going to power your mission-critical applications, you'd better have the best support known to business. Novell was rated the top provider of Linux technical support.

- Learn more >>
- Microsoft Dynamics CRM Online - Free Six-Month Trial for Eligible Organizations
-
Microsoft Dynamics CRM Online provides fast online access, simple contact management and better sales performance for a low monthly cost - the best value on the market today.

- Learn more about the free, six-month trial offer>>
Enterprise Applications
- Check out some of the easiest and most powerful ways to boost productivity while saving money on your application infrastructure. See ZDNet's comprehensive Enterprise Application resource center, now!
- New Online Dashboard
- Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline








