Pagine

mercoledì 3 agosto 2011

How to Crack a Wi-Fi Network’s WEP Password with BackTrack !!!!




You already know that if you want to lock down your Wi-Fi network, you should opt for WPA encryption because WEP is easy to crack. But did you know how easy? Take a look.

Today we're going to run down, step-by-step, how to crack a Wi-Fi network with WEP security turned on. But first, a word: Knowledge is power, but power doesn't mean you should be a jerk, or do anything illegal. Knowing how to pick a lock doesn't make you a thief. Consider this post educational, or a proof-of-concept intellectual exercise.
Dozens of tutorials on how to crack WEP are already all over the internet using this method. Seriously—Google it. This ain't what you'd call "news." But what is surprising is that someone like me, with minimal networking experience, can get this done with free software and a cheap Wi-Fi adapter. Here's how it goes.

What You'll Need

How to Crack a Wi-Fi Network's WEP Password with BackTrackUnless you're a computer security and networking ninja, chances are you don't have all the tools on hand to get this job done. Here's what you'll need:
  • A compatible wireless adapter—This is the biggest requirement. You'll need a wireless adapter that's capable of packet injection, and chances are the one in your computer is not. After consulting with my friendly neighborhood security expert, I purchased an Alfa AWUS050NH USB adapter, pictured here, and it set me back about $50 on Amazon. Update: Don't do what I did. Get the Alfa AWUS036H, not the US050NH, instead. The guy in this videobelow is using a $12 model he bought on Ebay (and is even selling his router of choice). There are plenty of resources on getting aircrack-compatible adapters out there.
  • A BackTrack 3 Live CD. We already took you on a full screenshot tour of how to install and use BackTrack 3, the Linux Live CD that lets you do all sorts of security testing and tasks. Download yourself a copy of the CD and burn it, or load it up in VMware to get started. (I tried the BackTrack 4 pre-release, and it didn't work as well as BT3. Do yourself a favor and stick with BackTrack 3 for now.)
  • A nearby WEP-enabled Wi-Fi network. The signal should be strong and ideally people are using it, connecting and disconnecting their devices from it. The more use it gets while you collect the data you need to run your crack, the better your chances of success.
  • Patience with the command line. This is an ten-step process that requires typing in long, arcane commands and waiting around for your Wi-Fi card to collect data in order to crack the password. Like the doctor said to the short person, be a little patient.

Crack That WEP

To crack WEP, you'll need to launch Konsole, BackTrack's built-in command line. It's right there on the taskbar in the lower left corner, second button to the right. Now, the commands.
First run the following to get a list of your network interfaces:
airmon-ng
The only one I've got there is labeled ra0. Yours may be different; take note of the label and write it down. From here on in, substitute it in everywhere a command includes (interface).
Now, run the following four commands. See the output that I got for them in the screenshot below.

airmon-ng stop (interface)
ifconfig (interface) down
macchanger --mac 00:11:22:33:44:55 (interface)
airmon-ng start (interface)
How to Crack a Wi-Fi Network's WEP Password with BackTrackIf you don't get the same results from these commands as pictured here, most likely your network adapter won't work with this particular crack. If you do, you've successfully "faked" a new MAC address on your network interface, 00:11:22:33:44:55.
Now it's time to pick your network. Run:
airodump-ng (interface)
To see a list of wireless networks around you. When you see the one you want, hit Ctrl+C to stop the list. Highlight the row pertaining to the network of interest, and take note of two things: its BSSID and its channel (in the column labeled CH), as pictured below. Obviously the network you want to crack should have WEP encryption (in the ENC) column, not WPA or anything else.
How to Crack a Wi-Fi Network's WEP Password with BackTrackLike I said, hit Ctrl+C to stop this listing. (I had to do this once or twice to find the network I was looking for.) Once you've got it, highlight the BSSID and copy it to your clipboard for reuse in the upcoming commands.
Now we're going to watch what's going on with that network you chose and capture that information to a file. Run:
airodump-ng -c (channel) -w (file name) --bssid (bssid) (interface)
Where (channel) is your network's channel, and (bssid) is the BSSID you just copied to clipboard. You can use the Shift+Insert key combination to paste it into the command. Enter anything descriptive for (file name). I chose "yoyo," which is the network's name I'm cracking.
How to Crack a Wi-Fi Network's WEP Password with BackTrack
You'll get output like what's in the window in the background pictured below. Leave that one be. Open a new Konsole window in the foreground, and enter this command:
aireplay-ng -1 0 -a (bssid) -h 00:11:22:33:44:55 -e (essid) (interface)
Here the ESSID is the access point's SSID name, which in my case is yoyo. What you want to get after this command is the reassuring "Association successful" message with that smiley face.
How to Crack a Wi-Fi Network's WEP Password with BackTrack
You're almost there. Now it's time for:
aireplay-ng -3 -b (bssid) -h 00:11:22:33:44:55 (interface)
Here we're creating router traffic to capture more throughput faster to speed up our crack. After a few minutes, that front window will start going crazy with read/write packets. (Also, I was unable to surf the web with the yoyo network on a separate computer while this was going on.) Here's the part where you might have to grab yourself a cup of coffee or take a walk. Basically you want to wait until enough data has been collected to run your crack. Watch the number in the "#Data" column—you want it to go above 10,000. (Pictured below it's only at 854.)
Depending on the power of your network (mine is inexplicably low at -32 in that screenshot, even though the yoyo AP was in the same room as my adapter), this process could take some time. Wait until that #Data goes over 10k, though—because the crack won't work if it doesn't. In fact, you may need more than 10k, though that seems to be a working threshold for many.
How to Crack a Wi-Fi Network's WEP Password with BackTrack
Once you've collected enough data, it's the moment of truth. Launch a third Konsole window and run the following to crack that data you've collected:
aircrack-ng -b (bssid) (file name-01.cap)
Here the filename should be whatever you entered above for (file name). You can browse to your Home directory to see it; it's the one with .cap as the extension.
If you didn't get enough data, aircrack will fail and tell you to try again with more. If it succeeds, it will look like this:
How to Crack a Wi-Fi Network's WEP Password with BackTrackThe WEP key appears next to "KEY FOUND." Drop the colons and enter it to log onto the network.

Problems Along the Way

With this article I set out to prove that cracking WEP is a relatively "easy" process for someone determined and willing to get the hardware and software going. I still think that's true, but unlike the guy in the video below, I had several difficulties along the way. In fact, you'll notice that the last screenshot up there doesn't look like the others—it's because it's not mine. Even though the AP which I was cracking was my own and in the same room as my Alfa, the power reading on the signal was always around -30, and so the data collection was very slow, and BackTrack would consistently crash before it was complete. After about half a dozen attempts (and trying BackTrack on both my Mac and PC, as a live CD and a virtual machine), I still haven't captured enough data for aircrack to decrypt the key.
So while this process is easy in theory, your mileage may vary depending on your hardware, proximity to the AP point, and the way the planets are aligned. Oh yeah, and if you're on deadline—Murphy's Law almost guarantees it won't work if you're on deadline.

To see the video version of these exact instructions, check out this dude's YouTube video.

Got any experience with the WEP cracking courtesy of BackTrack? What do you have to say about it? Give it up in the comments.

Cracking di reti wifi !!!!

Questo articolo non intende incoraggiare in alcun modo la pirateria informatica, l’uso di software “non genuino” privo di licenza o l’attuazione di quanto decritto se infrange in qualsiasi modo le leggi del proprio Stato.

Visto l’interessse suscitato da questo argomento, ho pensato di inserire una pagina statica apposita in cui convogliare tutte le infoormazioni che via via reperirò sull’argomento, invece di lasciare la questione sparpagliata in una miriade di post.


foto tratta da SparkBlog
——————————————————————–
Definizioni e termini di uso cumune nell’ambito del Wifi:
  • Wifi / Wireless – abbreviazione di Wireless Fidelity, è un termine che indica dispositivi che possono collegarsi a reti locali senza fili (WLAN) basate sulle specifiche IEEE 802.11;
  • Protocollo WPA – Wi-Fi Protected Access (WPA e WPA 2) è un programma di certificazione amministrato dall’alleanza del Wi-Fi come forma di protezione per le reti di computer wireless. Il protocollo è stato creato in risposta alle numerose falle che i ricercatori hanno trovato nel sistema precedente, Wired Equivalent Privacy (WEP), sebbene una ricerca condotta nel 2008 ha portato alla luce dei difetti nell’implementazione del WPA;
  • Protocollo WPE – Wired Equivalent Privacy (WEP) è parte dello standardIEEE 802.11 (ratificato nel 1999) e in particolare è quella parte dello standard che specifica il protocollo utilizzato per rendere sicure le trasmissioni radio delle reti Wi-Fi. WEP è stato progettato per fornire una sicurezza comparabile a quelle delle normali LAN basate su cavo;
——————————————————————–
Iniziamo con questo articolo un breve tour alla scoperta di tool per effettuare ilcracking di reti wireless, in particolare quelle protette con chiave WEP.

foto tratta da MediaKey
——————————————————————–
Corso WireShark:

foto tratta da ICD

martedì 2 agosto 2011

Rilevare i Virus invisibili!!! ( RootKit )

Questi software permettono di ottenere il controllo di un computer, sia da locale come un banale virus, sia da remoto come un trojan virus. I RootKit sono software largamente usati dagli hacker per nascondere le loro intrusioni . 

Essi agiscono in maniera completamente invisibile , rendendosi non rilevabili  sia dall’utente , sia dai programmi applicativi che da software di controllo come anti spyware e  antivirus. Le operazioni che permettono di svolgere in modalità stealth sono moltissime, possono ad esempio nascondere backdoor, trojan, virus  e malware in generale . Per mantenere questa invisibilità sui sistemi Unix usano i moduli del kernel e librerie, mentre in Microsoft Windows, gli sviluppatori dei rootkit utilizzano librerie dll e driver di sistema. La parola rootkit vuol dire appunto attrezzatura di amministrazione, quindi questi programmi non sono in realtà nocivi,  hanno solo nel loro kernel capacità avanzate di occultamento.
Spesso le tecniche usate dai rootkit vengono integrate da software di uso quotidiano quindi non dannosi, è famosa la vicenda della Sony che ha integrato in CD Audio come quelli di Celine Dion, (album: On ne Change-Pas), e Ricky Martin (album: Life )  ecc. tecnologie per limitare il numero di copie,  installando un rootkit sul computer . Il problema è che questo software di protezione può essere usato da malintenzionati per memorizzare dati privati degli utenti in maniera nascosta e permette intrusioni non autorizzate nel computer nascondendo trojan e virus in generale. 

Per loro natura i rootkit suscitano gli interessi di Hacker, Cracker, e Virus Writer , soprattutto di questi ultimi che sfruttano le capacità di questi software per rendere i loro virus immuni alla scansione di antivirus compromettendo la sicurezza di qualsiasi sistema. Esiste infatti  una tipologia di virus chiamatavirus stealth, che utilizza largamente queste caratteristiche. 

Come funzionano i rootkit
La prima operazione che compie un rootkit una volta installato, è quella di assicurarsi la sua esecuzione all’avvio del computer,  iniettando spesso un comando nel registro di configurazione del sistema e rendendolo invisibile. I rootkit per mantenere questa invisibilità, si installano come parte del Sistema Operativo spacciandosi per una libreria , un driver ecc. Riescono quindi a mettersi tra il Sistema Operativo e il programma permettendo di filtrare tutto ciò che si intende nascondere e riuscendo a rendere invisibile applicazioni base per qualsiasi sistema operativo , come chiavi di registro di configurazione,  processi di sistema  e addirittura riescono a rendere stealth porte di rete. 
Per questo motivo la loro rimozione è molto delicata e difficile. Si rischia infatti di compromettere l’inera integrità del sistema operativo. Una volta che il rootkit è installato, può aiutare i software come backdoors,  che si mettono in ascolto sulla rete in attesa di istruzioni esterne a  non essere intercettati. Può evitare l’identificazione  di keylogger che memorizzano tutto ciò che viene digitato e lo inviano al malintenzionato

Rootkit avanzati: rootkit LKM 

La minaccia più grave che un rootkit può portare alla sicurezza di un sistema è quella causata dai rootkit LKM ( Loadable Kernel Module ) è un meccanismo comodo e veloce per aggiungere nuove funzionalità al kernel del sistema operativo. I rootkit LKM non rimpiazzano gli eseguibili di sistema come visto in precedenza, ma ne alterano il funzionamento attraverso il kernel. 

Come difendersi dai rootkit e come trovarli

Riuscire a capire che il sistema sia stato Infettato da un rootkit è fondamentale per poterlo eliminare. Come per i virus, i primi segni di malfunzionamento dovrebbero insospettire l'utente. Una tipica anomalia causata dai rootkit è un forte utilizzo della banda di comunicazione in uscita, questa anomalia è causata potenzialmente da intrusi che usano il sistema per diffondere e distribuire software protetti, crack e materiali illeciti ( warez ). 

Per intercettare ed evitare l’installazione di queste applicazioni fantasma, si utilizzano programmi chiamati Anti Rootkit spesso si trovano in rete anche software con i nomi di rootkit revealer, rootkit removal e rootkit hunter . Questi software non sono infallibili perché basati soprattutto sul monitoraggio del filesystem . I rootkit, infatti rimpiazzano gli eseguibili di alcuni file di sistema con le relative versioni trojan, in modo da mantenere inalterata la funzionalità del file aggiungendo però le loro tecniche stealth per nascondere le azioni degli intrusi o i programmi da proteggere. E’ molto difficile identificarli perchè sono in grado di  imitare la data di creazione e la dimensione dei files  di sistema che rimpiazzano . Ovviamente un software AntiRootkit che tiene traccia unicamente di queste informazioni,  non è sufficiente a determinarne la presenza. 
Occorrerebbe quindi adottare l’utilizzo di un database dei files presenti nel sistema di cui calcolare e conservare il loro checksum. Questo database dovrebbe però essere conservato in un supporto di sola lettura ; nasce dunque il problema che questo database dovrebbe essere aggiornato e conservato ogni qualvolta si installino nuovi files. Un rootkit come abbiamo detto in precedenza non è progettato per danneggiare ma semplicemente per nascondere.

Per essere installato un rootkit dannoso, si devono spesso sfruttare le tecniche che usano i normali virus per installarsi e diffondersi , quindi valgono gli stessi consigli che si usano per i virus : installazione dipatch dei software, aggiornamenti continui del sistema operativo, installazione di firewall e antivirus.


link dove scaricare molti tool freeware per i rootkit. http://www.networkice.com/

Sicurezza Bluetooth !!!

Rappresenta una tecnologia di interconnessione wireless in grado di far comunicare fino ad un massimo di 16 dispositivi , con onde radio a basso raggio nella banda di frequenze ISM ( 2,45 Ghz - 2,56 Ghz ). Supporta fino a sette canali dati , con data rate di 57,6 Kbps in upstream , 721Kbps in dowstream e tre canali voce sincroni con data rate di 64 kbps. La velocità massima di trasferimento dati, nel suo complesso, è pari a 1Mbps fullduplex con una copertura dai 10 ai 100 metri .
Una rete Bluetooth si è soliti chiamarla piconet.


La tecnologia Bluetooth è disponibile su moltissimi dispositivi cellulari, palmari, computer, ecc. Durante la trasmissione di informazioni con questo metodo, è possibile essere esposti ad attacchi in linea come :

  • Sottrarre le informazioni memorizzate da elenchi , contatti, messaggi di posta elettronica e di testo;
  • Inviare messaggi o immagini non richiesti ad altri dispositivi dotati di tecnologia Bluetooth;
  • Accedere ai comandi del telefono cellulare utilizzando il telefono cellulare da remoto, con possibilità di inviare messaggi ,effettuare chiamate e installare un virus sul dispositivo provocando gli stessi danni di un virus su computer
Il telefono cellulare è il dispositivo su cui il bluetooth è maggiormente diffuso .Gli attacchi che è possibile  portare ad un cellulare con tecnologia Bluetooth  sono:

BlueJacking 
Equivale all’e-mail spam e rappresenta l'invio anonimo di un messaggio di un utente verso un altro .
Le contromisure che si possono adottare sono  l’impostazione della modalità invisibile. Questa tipologia diattacco non comporta alcuna modifica dei dati o controllo del dispositivo vittima.

BlueSnarfing
Si tratta di un vero è proprio attacco con tanto di violazione di sistema informatico . L’hacker riesce ad ottenere accesso ai dati presenti su un telefono cellulare come rubrica, messaggi, codice IMEI(International Mobile Equipment Identity) necessario per un eventuale clonazione del dispositivo, all'insaputa e senza il consenso dell'utente. Questo attacco è molto difficile da mettere in opera ,occorre infatti che il dispositivo della vittima sia  circa a 10metri ma con particolari dispositivi è possibile allargare questo raggio d’azione. L'unico modo per proteggere il cellulare , è quello di posizionare l'opzione Bluetooth sulla posizione off. e un telefonino con software aggiornato è protetto per questo bug.

BlueBugging
Consiste nel controllo remoto senza autorizzazione del telefono cellulare. Questo ovviamente ,permette a chi attacca ,di  effettuare chiamate o inviare messaggi, ascoltare di nascosto le conversazioni telefoniche e collegarsi a internet. Anche in questo caso, l'hacker deve trovarsi entro un raggio di 10 metri .

Come difendersi
Mantenere l'impostazione Bluetooth sulla modalità " non rilevabile o invisibile " ; installare un antivirus;utilizzare un codice pin complesso ;non associare mai dispositivi sconosciuti ed infine  disattivare le funzioni bluetooth se non utilizzate. 
Software
Per portare a compimento questi attacchi , si usano spesso computers dotati di software come
Bluestumbler, che può  monitorare tutte le attrezzature elettroniche con Bluetooth in un determinato perimetro. Questo programma permette di rilevare il nome, il modello, costruttore e le funzioni attive.
Bluebrowser. Questo software permette di rilevare tutti i servizi che è in grado di offrire un telefonino o un pc Bluetooth appena localizzato.
Redfang, è un software che prova a cercare dispositivi con Bluetooth attivo ma in modalità invisibile. Il software tenta tutte le possibili combinazioni dei sei byte dell'indirizzo logico dell'apparato. Una volta indovinata la sequenza corretta, chi attacca riesce ad  ottenere un varco.

Termini
War-nibbling: intercettazione di segnali Bluetooth per gli attacchi
Bluesniping: utilizzo di un laptop e di un'antenna potente per attaccare un utente con connessione bluetooth a distanza 

lunedì 1 agosto 2011

Cento motivi per passare a Linux




Che ormai io sia un fan sfegatato di Linux lo avrete capito tutti… Ci sono cento motivi per passare al sistema operativo del Pinguino: è gratuito, è completo, è stabile, è sicuro, è leggero, è veloce, è bello graficamente, è innovativo, è ricco di software liberamente scaricabile, è amico di tutti, è… Potrei andare avanti all’infinito. Ma il centounesimo motivo, l’ho scoperto solo ieri e credo sia quello che, se ci pensate, alla fine può bastare da solo per decidere di passare a Linux!

La storia: due settimane fa, improvvisamente, il mio amato pc di casa tira le cuoia.  Va bè, aveva sei anni, lo avevo assemblato io e in sei anni non mi ha mai dato un minimo problema; e devo dire che in sei anni l’ho usato veramente a fondo, per le attività più impegnative possibili, come la produzione di parecchi film… Morto. Allora, acquisto un pc nuovo, un Acer Extensa Core 2 Duo, 2GB di RAM, disco da 640GB e gli aggiungo subito una scheda video Asus con processore nVidia GeForce 8600, perché quella integrata sulla mb non mi offre l’uscita DVI e il mio monitor è digitale.
Ovviamente, il pc nuovo arriva con Windows Vista. Ovviamente, io NON voglio utilizzare Windows Vista.  Allora, prendo l’hard disk dal vecchio pc, sul quale ho due partizioni: una con Windows XP (lo avevo messo quando ancora usavo Windows XP…), l’altra con il mio amato Kubuntu 8.04. L’obiettivo è vedere se parte tutto. Il motivo è che se devo reinstallare da capo il SO (idem con patate se intendessi usare Vista), dovrei reinstallare da capo anche tutti i programmi e comunque perderei tutte le mie impostazioni personali: morale, dovrei perdere giorni per ritornare allo stato di prima!! 
Allora, per curiosità pura, prima faccio il boot da Windows XP, BEN sapendo a che cosa vado incontro. Infatti: 5 secondi netti dopo l’avvio, morto! Schermata blu, riavvio immediato. Ovvio, XP non ha mezzo driver per gestire la macchina nuova…
Secondo step: faccio il boot da Kubuntu, NON sapendo a che cosa vado incontro, ma immaginando problemi simili. INVECE NO!! A parte la scheda video, che non riconosce (ovvio, prima avevo una ATi; e comunque si avvia con i driver Vesa e tutto si vede), IL RESTO FUNZIONA DA SUBITO SENZA IL MINIMO PROBLEMA!!!  La macchina viene su che è un piacere, l’audio funziona, la rete funziona, le periferiche funzionano, è una scheggia, desktop e programmi sono esattamente come li avevo lasciati due settimane fa… Subito installo i driver nVidia ed ecco, parte anche Compiz e tornano gli effetti 3D. È TUTTO A POSTO!! E non devo reinstallare nulla…
Adesso ditemi: resta anche solo un motivo perché la gente debba ancora usare Windows?
Meditate, amici, meditate…

domenica 31 luglio 2011

applicazione attacco xss !!!!

La Tecnica xss - Cross Site Scripting 
Il motivo della sigla xss e non css , è proprio per evitare di far confondere i meno esperti con la sigla css che in gergo webmaster sta per “Cascading Style Sheets” L’attacco XSS appartiene alla tipologia injection, quindi si tratta di immissione di codice arbitrario in input alle pagine web. A differenza di sqlinjection ed altri attacchi alle web application trattati precedentemente a questo attacco , sono vulnerabili siti dinamici e non . L’attacco può essere portato a compimento su qualsiasi sito che presenti l’utilizzo di tecnologie come javascript, VBScript, actvex, html e Flash. Per chi non conosce queste tecnologie , basti pensare che si tratta di linguaggi e applicazioni che vengono eseguiti direttamente dal vostro webbroswer  (internet explorer, netscape, Mozilla Firefox, ecc.)


Come al solito, questa vulnerabilità è dovuta agli errori dei programmatori, che molto spesso trascurano completamente la validazione delle informazioni passate in input al sito dagli utenti. 

L’attacco Cross Site Scripting è quindi possibile d’attuazione, quando un sito web prende in input dati su cui effettua delle operazioni. Queste informazioni vengono inviate al sito solitamente tramite url. Questi dati, in siti non protetti, vengono visualizzati cosi’ come sono stati inseriti dagli utenti. Potenzialmente la vittima dell’attacco non è solo il sito, ma anche l’utente, proprio perché occorre un semplice link che porta ad una pagina di un sito non protetta per creare danni. Cliccando infatti incautamente su uno di questi link che si può trovare su un sito web o una mail , si può cadere vittima di questo attacco il cui fine è solitamente quello di raccogliere dati degli utenti , leggere i cookie, dirottare l’utente su un altro sito o visualizzare falsa pubblicità.


Analisi dell’attacco

Immaginate di essere su un forum o di scrivere su un guestbook
Nel testo scriveremo un cosa come:
<script>location='http://www.notrace.it/';</script>

Successivamente salviamo il nostro testo su un forum non protetto da questo attacco e  avremo come risultato che chi carica la pagina con il nostro messaggio , sarà reindirizzato al sito www.notrace.it

Detto così non sembra poi  tanto dannoso, ma pensate se sul sito su cui effettuo il reindirizzamento , creo pagine che permettono la raccolta dei dati , ottengo ad esempio il risultato di poter leggere i cookie rilasciati dal sito vittima e di inviarli ad una pagina appositamente creata . Se i cookie non sono crittografati , come succede spesso , si ha che l’attaccher otterrà user e password di tutte le persone che visitano la pagina del forum contenente il suo messaggio. Si può pensare anche ad un codice che faccia comparire qualche messaggio di alert come finestre di errore o che carichi all’interno della pagina attaccata un sito esterno.

È possibile ad esempio, manipolare il tag <img> che in html si occupa di visualizzare le immagini in modo che faccia comparire una finestra di alert
La stessa cosa per eludere eventuali filtri del web master potrebbe essere scritta informato Hex
Oppure in decimale:
Il codice cosi scritto, potrebbe essere inserito in una mail e magari codificato in modo da renderlo poco visibile. Potrebbe essere spacciato per un collegamento del sito e renderebbe gli utenti più vulnerabili ad attacchi di phisching. Inserendo ad esempio un redirect nel codice iniettato l’utente crede di andare sul sito http://www.sito-vittima.xx/  mentre si trova sul sito http://www.furbetto.xxx ,
che in caso di attacco phishing sarà sicuramente creato ad immagine e somiglianza del sito vittima rendendo quindi ulteriormente complesso il riconoscimento del phishing .

Come difendersiPer gli sviluppatori è opportuno controllare minuziosamente ogni informazione inserita in input dagli utenti prima di inoltrarla alle proprie applicazioni .
Per gli utenti è necessario cercare di tenere sempre aggiornato il proprio browser, i browser permettono di disabilitare l’utilizzo di linguaggi come javascript, vbscript, activix .