Pharming is an attack that manipulates name resolution so that users land on a forged site even though they typed the address correctly. Unlike phishing, it requires no click on a link.
At a glance
Pharming needs no click – the address is right, the destination is not.
The point of attack is name resolution, not the person.
A certificate warning is often the only visible signal.
Pharming attacks the infrastructure, not attention. Type the address yourself and you still end up in the wrong place.
Two routes to the wrong site
Either name resolution is manipulated on the device – through the hosts file or a substituted DNS server – or directly at the provider, by altering records in a DNS zone.
Real-world examples
- A manipulated home router redirects banking addresses to a rebuilt page.
- A hijacked domain account changes DNS records and intercepts all incoming mail.
Common misconception
Myth “If I type the address myself, nothing can happen.”
Reality That is exactly what pharming targets: the address is right, the resolution is not. Only the certificate gives certainty.
Frequently asked questions
How does pharming differ from phishing?
Phishing needs a message and a click; pharming manipulates name resolution. The BSI describes both methods.
Does HTTPS help against pharming?
Partly: the certificate then fails to match the address and the browser warns. ENISA covers the wider threat picture.