Explorer

Cyber Security Agency CERT-In Warns Of Credit Card Skimming; Issues Advisory For Users

Cyber criminals in these kind of frauds add skimming code on online shopping websites to steal credit card information shared by customers.

New Delhi: India's Cyber security agency - Computer Emergency Response Team (CERT-In) has issued a warning against incidents of credit card skimming frauds on various e-commerce websites across world. ALSO READ | Oxford Scientists Optimistic About Covid-19 Vaccine, Could Be Out By September As quoted in various media reports, the CERT-In stated that "credit card skimming through various e-commerce sites are spreading worldwide. Attackers are typically targeting e-commerce sites because of their wide presence, popularity and the environment LAMP (Linux, Apache, MySQL, and PHP)." According to the experts, the cyber criminals in these kind of frauds add skimming code on online shopping websites to steal credit card information shared by customers. They remotely inject malicious code into one of their legitimate JavaScript libraries which is mainly designed to obtain credit card numbers as well as passwords of the user. As per the release, the cyber criminals are targeting the websites which are hosted on Microsoft’s IIS server running with the ASP.NET web application framework. These include sports organisations, health, shopping portal and e-commerce websites among others which are affected the most by such attacks. ALSO READ | Google Announces Major Redesign For Gmail; Know About New 'Rooms' Feature The government agency has shared a few names of skimmer hosting sites:
  • idpcdn-cloud[.]com
  • joblly[.]com
  • hixrq[.]net
  • cdn-xhr[.]com
  • rackxhr[.]com
  • thxrq[.]com
  • hivnd[.]net
CERT-In also issued an advisory for the users which can protect them from such attacks:
  • The agency advised the users to use only the latest version of ASP.NET web framework, IIS Web server and database server.
  • It further asked he users to apply new or the updated security patches on the OS and applications (when available) through OEM to prevent such attacks.
  • The users should be careful and must restrict or deny all and any kind of access by default. They should allow only the necessary access.
  • The users must also conduct complete and regular security checks of web application, web server and database server. After every major configuration, users may change and plug vulnerabilities if found any.
  • The users may also opt to apply Security Information and Event Management (SIEM) solutions.
 
View More
Advertisement
Advertisement
25°C
New Delhi
Rain: 100mm
Humidity: 97%
Wind: WNW 47km/h
See Today's Weather
powered by
Accu Weather
Advertisement

Top Headlines

Maha Kumbh's Third 'Amrit Snan' Begins On Basant Panchami — Watch
Maha Kumbh's Third 'Amrit Snan' Begins On Basant Panchami — Watch
Delhi Poll Official Responds To Kejriwal’s ‘Hooliganism’ Complaint As AAP, BJP Trade Charges Before Polls
Delhi Poll Official Responds To Kejriwal’s ‘Hooliganism’ Complaint As AAP, BJP Trade Charges Before Polls
‘Khambe Se Seedha Sheesh Mahal’: Rahul Gandhi Mocks Kejriwal, Dares Him To Drink Yamuna Water — WATCH
‘Khambe Se Seedha Sheesh Mahal’: Rahul Gandhi Mocks Kejriwal, Dares Him To Drink Yamuna Water — WATCH
Maha Kumbh: Top IAS Officers Roped In As UP Govt Aims For ‘Zero Error’ During Amrit Snan After Deadly Stampede
Maha Kumbh: Top IAS Officers Roped In As UP Govt Aims For ‘Zero Error’ During Amrit Snan After Deadly Stampede
Advertisement
ABP Premium

Videos

Delhi Election 2025: Raghav Chadha Discusses Economy, Education, and Infrastructure | ABP NEWSDelhi Election 2025: BJP Accuses AAP of Corruption, Highlights Sting on Somnath Bharti | ABP NEWSDelhi Election 2025: Arvind Kejriwal Warns Delhi Voters Against Fraud and BJP Threat to Slums | ABP NEWSDelhi Election 2025: Raghav Chadha Defends AAP's Welfare Policies in Exclusive Interview  | ABP NEWS

Photo Gallery

Embed widget