Pharming
Term · Cybersecurity · MLC-T-CYB-003115
1. An attack in which an attacker causes the subscriber to be redirected to a fraudulent website, typically a fraudulent verifier/RP in the context of authentication. This could cause the subscriber to reveal sensitive information (e.g., a password) to the attacker, download harmful software, or contribute to a fraudulent act. This may be accomplished by corrupting an infrastructure service (e.g., the DNS) or the subscriber’s endpoint.
2. Using technical means to redirect users into accessing a fake Web site masquerading as a legitimate one and divulging personal information.
3. An attack in which an attacker corrupts an infrastructure service such as DNS (Domain Name System) causing the subscriber to be misdirected to a forged verifier/RP, which could cause the subscriber to reveal sensitive information, download harmful software, or contribute to a fraudulent act.
4. An attack in which an Attacker corrupts an infrastructure service such as DNS (Domain Name Service) causing the Subscriber to be misdirected to a forged Verifier/RP, which could cause the Subscriber to reveal sensitive information, download harmful software or contribute to a fraudulent act.
| Identifier | MLC-T-CYB-003115 |
|---|---|
| Field | Cybersecurity |
| References | NIST SP 800-63-4; NIST SP 800-44 Version 2; NIST SP 800-63-3 [Superseded]; NIST SP 800-63-2 [Superseded]; NIST CSRC Glossary |
Record as JSON
{
"id": "MLC-T-CYB-003115",
"term": "Pharming",
"field": "Cybersecurity",
"definition": "1. An attack in which an attacker causes the subscriber to be redirected to a fraudulent website, typically a fraudulent verifier/RP in the context of authentication. This could cause the subscriber to reveal sensitive information (e.g., a password) to the attacker, download harmful software, or contribute to a fraudulent act. This may be accomplished by corrupting an infrastructure service (e.g., the DNS) or the subscriber’s endpoint.\n\n2. Using technical means to redirect users into accessing a fake Web site masquerading as a legitimate one and divulging personal information.\n\n3. An attack in which an attacker corrupts an infrastructure service such as DNS (Domain Name System) causing the subscriber to be misdirected to a forged verifier/RP, which could cause the subscriber to reveal sensitive information, download harmful software, or contribute to a fraudulent act.\n\n4. An attack in which an Attacker corrupts an infrastructure service such as DNS (Domain Name Service) causing the Subscriber to be misdirected to a forged Verifier/RP, which could cause the Subscriber to reveal sensitive information, download harmful software or contribute to a fraudulent act.",
"references": [
"NIST SP 800-63-4",
"NIST SP 800-44 Version 2",
"NIST SP 800-63-3 [Superseded]",
"NIST SP 800-63-2 [Superseded]",
"NIST CSRC Glossary"
],
"url": "https://mlchart.com/terminology/cybersecurity/pharming/"
}
Record 3,115 of 4,693 in Cybersecurity terminology (MLC-0102). Request the full dataset.