Quote:
Now, phishing has taken a nasty new twist, according to Susan Larson, SurfControl's vice president of global content. "It's a hacking of the search technology on the sites," she said.
In this virulent new breed, the link in the e-mail takes those who click to a fraudulent page that's actually hosted on the bank's Web site. The spoof exploits a flaw in the banking sites' search servers. This flaw lets the crooks run a JavaScript page that displays their own phishing site instead of a legitimate Citibank or SunTrust Web page. Once the user enters the requested information and submits it, the data is whisked to an off-site server operated by the identity thieves.
Full article