02:45 PM
Connect Directly

Anonymizer Offers Phishing Defense

Anonymizer 2005 defends against pharming, a particularly insidious form of phishing.

Internet privacy and security company Anonymizer Inc. has released an upgrade of its identity-protection software, Anonymizer 2005, to defend against a particularly insidious form of phishing that's been on the rise over the past few months.

"This kind of phishing is different from the kind you usually see," says Lance Cottrell, president and founder of Anonymizer. The Anti-Phishing Working Group, an association of businesses and law-enforcement organizations, calls it "pharming."

Phishing attacks traditionally rely on social-engineering techniques to dupe users into clicking on disguised links that take them to phony bank sites set up to capture sensitive information. Pharming, or "host-file phishing," relies on Trojans, worms, or viruses, some of which attack programs like Microsoft Outlook through E-mail. Once a machine is infected, the malware alters the computer's host file so that when a user types in the Web address for his or her bank, the browser sends the user to the phisher's fake bank site.

This technique takes advantage of the fact that banks have been telling customers to type their Web addresses into browsers manually rather than clicking on links to avoid a phishing scam.

Host-file phishing can usually, but not always, be prevented with antivirus or anti-spam software or hardware, which blocks the malware that alters the host file. Disabling Windows Scripting Host, a common procedure for security-conscious businesses, also offers some measure of protection by preventing potentially hostile Visual Basic Scripts sent as E-mail attachments from executing. But once a computer gets infected and its host file gets altered, defense can be difficult.

Anonymizer's software solves this problem by redirecting the user's Web traffic through its servers and resolving domain names there, rather than using a compromised host file. And, as its name suggests, Anonymizer 2005 encrypts the user's Web traffic and conceals the user's IP address so that advertisers and Web sites can't track the user.

The announcement of Anonymizer 2005 coincides with National Consumer Protection Week, as designated by the Federal Trade Commission.

Comment  | 
Print  | 
More Insights
Threaded  |  Newest First  |  Oldest First
How Enterprises Are Attacking the IT Security Enterprise
How Enterprises Are Attacking the IT Security Enterprise
To learn more about what organizations are doing to tackle attacks and threats we surveyed a group of 300 IT and infosec professionals to find out what their biggest IT security challenges are and what they're doing to defend against today's threats. Download the report to see what they're saying.
Register for InformationWeek Newsletters
White Papers
Current Issue
Top IT Trends to Watch in Financial Services
IT pros at banks, investment houses, insurance companies, and other financial services organizations are focused on a range of issues, from peer-to-peer lending to cybersecurity to performance, agility, and compliance. It all matters.
Twitter Feed
InformationWeek Radio
Archived InformationWeek Radio
Join us for a roundup of the top stories on for the week of October 23, 2016. We'll be talking with the editors and correspondents who brought you the top stories of the week to get the "story behind the story."
Sponsored Live Streaming Video
Everything You've Been Told About Mobility Is Wrong
Attend this video symposium with Sean Wisdom, Global Director of Mobility Solutions, and learn about how you can harness powerful new products to mobilize your business potential.
Flash Poll