‹ முகப்புக்கு திரும்ப

Online Shopping-ல் Card Details திருடும் புதிய Malware! CSP Security-ஐயே Bypass பண்றது — இப்படி காத்துக்கோங்க

E-commerce sites-ல் card details type பண்ணும்போது அதை திருடும் புதிய malware கண்டுபிடிக்கப்பட்டிருக்கு. இது CSP என்ற main security protection-ஐ completely bypass பண்றது. Flipkart, Amazon-ல் மட்டும் இல்லை — smaller online shops-லயும் risk இருக்கு. UPI use பண்ணுங்க — அதுவே safe. Full explanation Tamil-ல்.

Keerthika 3 min read
Google-ல் Follow
அப்டேட் 5 மாதங்கள் முன்
Scam Alerts Online Shopping-ல் Card Details திருடும் புதிய Malware! CSP Security-ஐயே Bypass பண்றது — இப்படி காத்துக்கோங்க 3 நிமிடம் மீதம் Google-ல் Follow
Online Shopping-ல் Card Details திருடும் புதிய Malware! CSP Security-ஐயே Bypass பண்றது — இப்படி காத்துக்கோங்க

தமிழ்டெக் AI சுருக்கம்

Online shopping பண்ணும்போது card number, CVV, expiry date type பண்ணும் நேரத்துல background-ல run ஆகும் புதிய **WebRTC skimmer** malware உங்க card details-ஐ copy பண்ணி hacker server-க்கு அனுப்புது. முன்னாடி **CSP (Content Security Policy)** unauthorized connection-ஐ block பண்ணி காப்பாத்தும்; ஆனா WebRTC DataChannel-க்கு CSP apply ஆகாது, அதனால இந்த defense-ஐயே bypass பண்ணிடுது — அதனாலதான் இது serious news. Magento அல்லது Adobe Commerce use பண்ணும் sites-ல vulnerability மூலம் malicious code inject பண்ணி checkout page normal-ஆ தெரியும்போதே keystroke-ஐ intercept பண்ணுவாங்க; network tools-க்கும் இது video call traffic மாதிரி தெரியும். India-ல small e-commerce stores-லயும் risk இருக்கு, ஆனா **UPI** (GPay, PhonePe, Paytm) use பண்ணினா card details website form-ல type ஆகாது அதனால இந்த attack apply ஆகாது. Safe-ஆ இருக்க UPI-யை first choice வையுங்க, இல்லனா bank app-ல **virtual card** generate பண்ணுங்க, statement-ஐ weekly check பண்ணுங்க, unfamiliar sites-ல card save பண்ணாதீங்க.

  • WebRTC skimmer CSP security bypass பண்றது — browser's main script defense invisible-ஆ dodge பண்ணி card details steal; Magento/Adobe Commerce sites primary target
  • Detection extremely difficult — WebRTC encrypted UDP traffic legitimate video call-மாதிரி look ஆகும்; standard network security tools catch பண்றதில்லை
  • India shoppers best defense: UPI use பண்ணுங்க (card details form-ல் enter ஆகாது); virtual cards second option; bank statement weekly monitor பண்ணுங்க

AI உதவியுடன் தயாரான சுருக்கம் — தமிழ்டெக் எடிட்டர்ஸ் சரிபார்த்தது.

0:00
0:00
🔒 Listen வசதி subscribers-க்கு மட்டும். Subscribe செய்யுங்கள்

Card Details Type பண்ணும்போது யாரோ Copy எடுக்கிறாங்க — இது எப்படி நடக்குது?

Online shopping-ல் card details type பண்ணும்போது — card number, CVV, expiry date — அந்த நேரத்தில் background-ல் malicious code run ஆகி அதை copy பண்ணி hacker-கிட்ட அனுப்புது. இதை payment skimmer என்று சொல்வாங்க.

இது புதிய idea இல்லை. Security industry already CSP (Content Security Policy) என்ற defense build பண்ணியிருந்தது — இதை block பண்ண. ஆனா இப்போது கண்டுபிடிக்கப்பட்ட WebRTC skimmer அந்த defense-ஐயே bypass பண்றது. அது தான் இந்த news serious-ஆ இருக்கு.

CSP என்னன்னு ஒரு நிமிஷம் தெரிஞ்சுக்குவோம்

CSP (Content Security Policy) என்பது website உங்கள் browser-க்கு கொடுக்கும் ஒரு instruction. "இந்த website-ல் இந்த approved locations-லிருந்து மட்டும் code load ஆகலாம். வேற எங்கிருந்தாவது code வந்தா block பண்ணு" என்று சொல்லும்.

Skimmer உங்கள் card details steal பண்ணி hacker-ஓட server-க்கு அனுப்பணும். CSP அந்த unauthorized server connection block பண்ணும். இது years-ஆ நல்லா work ஆனது.

WebRTC skimmer இந்த rule-ஐ use பண்றதே இல்லை — வேற ஒரு road-ல் போகுது.

WebRTC என்னன்னு தெரியுமா?

WebRTC (வெப் ரியல்-டைம் கம்யூனிகேஷன்) என்பது browser-ல் video call பண்றதற்கு use ஆகும் technology. Google Meet browser-ல் use பண்றது, WhatsApp Web-ல் video call — எல்லாமே WebRTC-தான். இது browser-ல் இருந்து direct peer-to-peer connection பண்றது.

Critical point: Content Security Policy — WebRTC connections-க்கு apply ஆகாது. இது design decision — WebRTC legitimate real-time communication-க்கு build ஆனது, CSP rules-ல் include ஆகல.

Hacker-கள் இந்த gap-ஐ exploit பண்றாங்க. Normal web request-ல் card data அனுப்ப try பண்ணா — CSP block பண்ணும். WebRTC DataChannel (direct encrypted connection) மூலம் அனுப்பினா — CSP கேக்கவே மாட்டாது.

வேற problem: WebRTC encrypted UDP traffic use பண்றது — normal HTTP இல்லை. Network security tools-ல் பெரும்பாலானவை HTTP suspicious traffic watch பண்றது. WebRTC traffic legitimate video call-மாதிரி look ஆகும் — கண்டுபிடிக்கவே கஷ்டம்.

Attack எப்படி நடக்குது?

Hackers Magento அல்லது Adobe Commerce software-ல் vulnerability exploit பண்ணி website-ல் malicious file upload பண்றாங்க. Magento என்பது thousands of online shops globally — India-லயும் — use பண்றது.

நீங்க checkout page-க்கு வருவீங்க — normal-ஆ look ஆகும். Background-ல் malicious code quietly run ஆகுது.

Card number type பண்றீங்க — skimmer ஒவ்வொரு keystroke-ஐயும் intercept பண்றது. Complete card info memory-ல் assemble ஆகுது.

WebRTC DataChannel மூலம் — direct encrypted connection — hacker-ஓட server-க்கு உங்கள் card details போகுது. CSP block பண்றதில்லை, security tools கண்டுபிடிக்கல.

உங்கள் payment normal-ஆ process ஆகுது. Confirmation வருது. எல்லாமே okay-ஆ look ஆகும். ஆனா உங்கள் card details somewhere copy ஆகியிருக்கு.

India-ல் யாருக்கு Risk இருக்கு?

2025-ல் India-ஓட e-commerce $60 billion-க்கும் மேல் transactions process பண்ணியது. Card payments — credit card, debit card — UPI-உடன் சேர்த்து significant share. India-ல் many online stores Magento, WooCommerce use பண்றது — இவை common attack targets.

Large sites மட்டும் இல்லை — smaller regional e-commerce stores often more vulnerable. Dedicated security team இல்லை, code injection monitor பண்றதில்லை. Small clothing stores, electronics sites, specialty goods sites — இவற்றில் risk இருக்கு.

UPI payments-க்கு இந்த specific attack apply ஆகாது. ஏன்னா UPI-ல் (GPay, PhonePe, Paytm) உங்கள் card details website form-ல் type ஆகவே இல்லை. Payment உங்கள் UPI app-ல் நடக்குது. Skimmer steal பண்ண ஒன்னும் இல்லை. UPI-ஓட இது ஒரு genuine security advantage.

Safe-ஆ இருக்க என்ன பண்ணணும்?

UPI use பண்ணுங்க — GPay, PhonePe, Paytm. Website card form-ல் type பண்றதை avoid பண்ணுங்க. Especially unfamiliar smaller sites-ல்.

Virtual Card use பண்ணுங்க — HDFC, ICICI, SBI, Axis Bank apps-ல் one-time virtual card number generate ஆகும். அந்த number skimmer steal பண்ணினாலும் reuse பண்ண முடியாது.

Bank statement weekly check பண்ணுங்க — Skimmer fraud often ₹1 or ₹5 test charge-ல் start ஆகும். Early catch பண்றது larger loss prevent பண்ணும்.

Browser extension use பண்ணுங்க — uBlock Origin or Privacy Badger install பண்றது some WebRTC data leaks block பண்ணும். Perfect defense இல்லை — ஆனா extra layer.

Online shopping-ல் card save பண்ணாதீங்க — "Save card for future use" option avoid பண்ணுங்க unfamiliar sites-ல். One-time payment பண்ணுங்க.

Website owners என்ன பண்ணணும்?

Magento அல்லது WooCommerce-ல் online shop run பண்ற Tamil Nadu-ல் இருக்கும் business owners-க்கு:

Software updates regular-ஆ apply பண்ணுங்க — skimmers known vulnerabilities through enter ஆகுது, already fixed updates apply ஆகல.

File integrity monitoring setup பண்ணுங்க — server files unauthorized change ஆனா alert வரணும். Skimmer injection traces file modifications-ல் தெரியும்.

Web Application Firewall (WAF) use பண்ணுங்க — Cloudflare, Sucuri or Astra Security — Magento attack patterns specifically block பண்ணும்.

JavaScript files-க்கு Subresource Integrity (SRI) implement பண்ணுங்க — file modified ஆனா browser reject பண்ணும்.

TamilTech-ஓட கருத்து

WebRTC bypass technique security research-ல் known-ஆ இருந்தது. Real-world payment skimmers-ல் deployed ஆகியிருக்குன்னு கண்டுபிடிக்கப்படுறது — attackers' technical sophistication step up ஆகியிருக்கு என்று சொல்றது. Old skimmer code copy-paste பண்றவங்க இல்லை — novel attack vectors implement பண்ணுறாங்க.

India shoppers-க்கு genuinely simple defense: UPI use பண்ணுங்க. Card payments universally compromised-ன்னு இல்லை — ஆனா UPI skimmers exploit பண்ற specific attack surface-ஐயே remove பண்றது. Card details web form-ல் enter ஆகல — steal பண்ண ஒன்னும் இல்லை.

Online shopping-ல் maximum safety: UPI first choice, virtual card second choice, saved card last resort — especially unfamiliar sites-ல்.

நாளைய டெக் செய்திகள் உங்க WhatsApp-க்கே

தினமும் ஒரு சின்ன update, இலவசம். TamilTech channel-ஐ follow பண்ணுங்க.

What do you think?

people reacted

Keerthika

தமிழ்டெக் எடிட்டோரியல் டீம் · 3,344 கட்டுரைகள்

Keerthika is an editor at TamilTech, the Tamil and English technology publication founded by Praveen Kumar S. She covers AI, smartphones, gadgets, EVs, startups and cybersecurity i...

மேலும் Keerthika

WhatsApp-ல் TamilTech-ஐக் கேளுங்க

டெக் சந்தேகமா? தமிழிலோ ஆங்கிலத்திலோ கேளுங்க — எங்க WhatsApp அசிஸ்டன்ட் TamilTech கட்டுரைகளில் இருந்து சில நொடிகளில் பதில் சொல்லும்.

தொடர்புடைய செய்திகள்

கருத்துகள் (0)

| Supports **bold**, *italic*, `code`

Be the first to comment!

அடுத்த செய்தி Truecaller Scam Checker இப்போ Web-ல: App இல்லாம Check பண்ணலாம்
Tamiltech

Tamiltech

Install app for faster access

Earn XP 🏆
WhatsApp
Notifications