Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Security glitch aids IRS phishers
Macworld ^ | 12/01/2005 | Robert McMillan

Posted on 12/01/2005 4:43:38 AM PST by Panerai

The U.S. Department of Labor said Wednesday it is working to fix a programming glitch in a U.S. government Web portal that makes it easier for phishers to trick people into disclosing sensitive information. The flaw was first exploited by phishers who, earlier this week, began sending out bogus e-mail messages asking for personal information, including social security and credit card numbers.

The bug lets these phishers redirect URLs (Uniform Resource Locators) that use the GovBenefits.gov domain to fraudulent Web sites that are unconnected with the U.S. government.

This redirecting flaw was first exploited just days ago by phishers masquerading as the U.S. Internal Revenue Service (IRS), said Graham Cluley, a senior technology consultant with Sophos PLC, a U.K. security firm that has been researching the matter.

“The people behind GovBenefits.gov have implemented their software in such a way that leaves the Web site vulnerable to a phishing attack,” he said. The technique is particularly effective because the link that users click on is, in fact, a genuine GovBenefits.gov link, he added.

The fraudulent e-mail claims to require the sensitive information in order to process a tax refund, and claims to come from tax refunds@irs.gov, the IRS said.

The GovBenefits.gov Web site is used by 16 federal agencies, including the IRS, and is designed to help users determine their eligibility for government-funded benefit and assistance programs. It is maintained by the Department of Labor.

Though the site’s redirect glitch is not common, Sophos has seen it before, usually made by programmers looking for a flexible way to move users around their Web sites, Cluley said. “It’s a simple mistake to make, until you realize the consequences,” he said. “They probably didn’t see how it could be used.”

(Excerpt) Read more at macworld.com ...


TOPICS: Technical
KEYWORDS: irs; phishers; security

1 posted on 12/01/2005 4:43:39 AM PST by Panerai
[ Post Reply | Private Reply | View Replies]

To: Panerai

A similar problem occurs when applying for Social Security benefits


2 posted on 12/01/2005 5:00:44 AM PST by muawiyah (u)
[ Post Reply | Private Reply | To 1 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson