ARLINGTON, Va. – A new form of malicious software is being used by computer hackers to gain access to credit union or bank accounts without directly targeting or gaining access to a financial institution’s web site.
The malware, known as Cross-Site Scripting, or XXS, exploit a flaw in financial institution servers by adding extra characters to the URL line accessed by online banking users which create additional queries for users, such as credit card numbers, account numbers, passwords, PINs or mother’s maiden name–that the financial institution is not asking on its regular online banking login, according to Gregory Ogorek, anti-phishing manager for Cyveillance, which is alerting is clients of the emerging scheme today. "It’s additional fields that the hackers add to a legitimate login," Ogorek told The Credit Union Journal Friday.
The XXS takes advantage of a fault in most web servers, which recognize required URL addresses, but do not block against extra ULR characters that may be added to the end of a legitimate address, he said. As a result, Cyveillance is urging its credit union and bank customers to program their servers to only accept the required characters and to block the extra characters on the URL line. "This is easy to implement," said Ogorek.
While similar in concept to traditional phishing attacks that provide a spoofed login or input screen, XXS attacks are particularly dangerous because they occur only in the computer user’s browser. And they happen while visiting a legitimate website.









