Card Details Type பண்ணும்போது யாரோ Copy எடுக்கிறாங்க — இது எப்படி நடக்குது?
Online shopping-ல் card details type பண்ணும்போது — card number, CVV, expiry date — அந்த நேரத்தில் background-ல் malicious code run ஆகி அதை copy பண்ணி hacker-கிட்ட அனுப்புது. இதை payment skimmer என்று சொல்வாங்க.
இது புதிய idea இல்லை. Security industry already CSP (Content Security Policy) என்ற defense build பண்ணியிருந்தது — இதை block பண்ண. ஆனா இப்போது கண்டுபிடிக்கப்பட்ட WebRTC skimmer அந்த defense-ஐயே bypass பண்றது. அது தான் இந்த news serious-ஆ இருக்கு.
CSP என்னன்னு ஒரு நிமிஷம் தெரிஞ்சுக்குவோம்
CSP (Content Security Policy) என்பது website உங்கள் browser-க்கு கொடுக்கும் ஒரு instruction. "இந்த website-ல் இந்த approved locations-லிருந்து மட்டும் code load ஆகலாம். வேற எங்கிருந்தாவது code வந்தா block பண்ணு" என்று சொல்லும்.
Skimmer உங்கள் card details steal பண்ணி hacker-ஓட server-க்கு அனுப்பணும். CSP அந்த unauthorized server connection block பண்ணும். இது years-ஆ நல்லா work ஆனது.
WebRTC skimmer இந்த rule-ஐ use பண்றதே இல்லை — வேற ஒரு road-ல் போகுது.
WebRTC என்னன்னு தெரியுமா?
WebRTC (வெப் ரியல்-டைம் கம்யூனிகேஷன்) என்பது browser-ல் video call பண்றதற்கு use ஆகும் technology. Google Meet browser-ல் use பண்றது, WhatsApp Web-ல் video call — எல்லாமே WebRTC-தான். இது browser-ல் இருந்து direct peer-to-peer connection பண்றது.
Critical point: Content Security Policy — WebRTC connections-க்கு apply ஆகாது. இது design decision — WebRTC legitimate real-time communication-க்கு build ஆனது, CSP rules-ல் include ஆகல.
Hacker-கள் இந்த gap-ஐ exploit பண்றாங்க. Normal web request-ல் card data அனுப்ப try பண்ணா — CSP block பண்ணும். WebRTC DataChannel (direct encrypted connection) மூலம் அனுப்பினா — CSP கேக்கவே மாட்டாது.
வேற problem: WebRTC encrypted UDP traffic use பண்றது — normal HTTP இல்லை. Network security tools-ல் பெரும்பாலானவை HTTP suspicious traffic watch பண்றது. WebRTC traffic legitimate video call-மாதிரி look ஆகும் — கண்டுபிடிக்கவே கஷ்டம்.
Attack எப்படி நடக்குது?
Hackers Magento அல்லது Adobe Commerce software-ல் vulnerability exploit பண்ணி website-ல் malicious file upload பண்றாங்க. Magento என்பது thousands of online shops globally — India-லயும் — use பண்றது.
நீங்க checkout page-க்கு வருவீங்க — normal-ஆ look ஆகும். Background-ல் malicious code quietly run ஆகுது.
Card number type பண்றீங்க — skimmer ஒவ்வொரு keystroke-ஐயும் intercept பண்றது. Complete card info memory-ல் assemble ஆகுது.
WebRTC DataChannel மூலம் — direct encrypted connection — hacker-ஓட server-க்கு உங்கள் card details போகுது. CSP block பண்றதில்லை, security tools கண்டுபிடிக்கல.
உங்கள் payment normal-ஆ process ஆகுது. Confirmation வருது. எல்லாமே okay-ஆ look ஆகும். ஆனா உங்கள் card details somewhere copy ஆகியிருக்கு.
India-ல் யாருக்கு Risk இருக்கு?
2025-ல் India-ஓட e-commerce $60 billion-க்கும் மேல் transactions process பண்ணியது. Card payments — credit card, debit card — UPI-உடன் சேர்த்து significant share. India-ல் many online stores Magento, WooCommerce use பண்றது — இவை common attack targets.
Large sites மட்டும் இல்லை — smaller regional e-commerce stores often more vulnerable. Dedicated security team இல்லை, code injection monitor பண்றதில்லை. Small clothing stores, electronics sites, specialty goods sites — இவற்றில் risk இருக்கு.
UPI payments-க்கு இந்த specific attack apply ஆகாது. ஏன்னா UPI-ல் (GPay, PhonePe, Paytm) உங்கள் card details website form-ல் type ஆகவே இல்லை. Payment உங்கள் UPI app-ல் நடக்குது. Skimmer steal பண்ண ஒன்னும் இல்லை. UPI-ஓட இது ஒரு genuine security advantage.
Safe-ஆ இருக்க என்ன பண்ணணும்?
UPI use பண்ணுங்க — GPay, PhonePe, Paytm. Website card form-ல் type பண்றதை avoid பண்ணுங்க. Especially unfamiliar smaller sites-ல்.
Virtual Card use பண்ணுங்க — HDFC, ICICI, SBI, Axis Bank apps-ல் one-time virtual card number generate ஆகும். அந்த number skimmer steal பண்ணினாலும் reuse பண்ண முடியாது.
Bank statement weekly check பண்ணுங்க — Skimmer fraud often ₹1 or ₹5 test charge-ல் start ஆகும். Early catch பண்றது larger loss prevent பண்ணும்.
Browser extension use பண்ணுங்க — uBlock Origin or Privacy Badger install பண்றது some WebRTC data leaks block பண்ணும். Perfect defense இல்லை — ஆனா extra layer.
Online shopping-ல் card save பண்ணாதீங்க — "Save card for future use" option avoid பண்ணுங்க unfamiliar sites-ல். One-time payment பண்ணுங்க.
Website owners என்ன பண்ணணும்?
Magento அல்லது WooCommerce-ல் online shop run பண்ற Tamil Nadu-ல் இருக்கும் business owners-க்கு:
Software updates regular-ஆ apply பண்ணுங்க — skimmers known vulnerabilities through enter ஆகுது, already fixed updates apply ஆகல.
File integrity monitoring setup பண்ணுங்க — server files unauthorized change ஆனா alert வரணும். Skimmer injection traces file modifications-ல் தெரியும்.
Web Application Firewall (WAF) use பண்ணுங்க — Cloudflare, Sucuri or Astra Security — Magento attack patterns specifically block பண்ணும்.
JavaScript files-க்கு Subresource Integrity (SRI) implement பண்ணுங்க — file modified ஆனா browser reject பண்ணும்.
TamilTech-ஓட கருத்து
WebRTC bypass technique security research-ல் known-ஆ இருந்தது. Real-world payment skimmers-ல் deployed ஆகியிருக்குன்னு கண்டுபிடிக்கப்படுறது — attackers' technical sophistication step up ஆகியிருக்கு என்று சொல்றது. Old skimmer code copy-paste பண்றவங்க இல்லை — novel attack vectors implement பண்ணுறாங்க.
India shoppers-க்கு genuinely simple defense: UPI use பண்ணுங்க. Card payments universally compromised-ன்னு இல்லை — ஆனா UPI skimmers exploit பண்ற specific attack surface-ஐயே remove பண்றது. Card details web form-ல் enter ஆகல — steal பண்ண ஒன்னும் இல்லை.
Online shopping-ல் maximum safety: UPI first choice, virtual card second choice, saved card last resort — especially unfamiliar sites-ல்.




கருத்துகள் (0)
Be the first to comment!