Find more Phishing Funda....

Loading
Showing posts with label online. Show all posts
Showing posts with label online. Show all posts

Saturday, June 14, 2008

Beware of the Newest Activity Online: Phishing

No. I’m not talking here about the outdoor activity enjoyed
by many. And no again; I did not misspell it. Phishing is
the name given to the latest online scam where millions of
unwary Americans are getting their identities stolen.

This fraudulent activity is considered the fastest growing
crime of modern times. The favorite target groups of
phishers seem to be very young children and senior citizens,
as they do not often ask for credit reports, fill out credit
card applications or solicit loans. This allows the thieves
to go undetected for longer periods of time; but still, be
careful. We all are potential targets.

Remember when throwing away unshredded documents with
personal information in the trash bin was considered a big
risk for identity theft? While this still happens, identity
thieves have become more sophisticated in recent times, and
this is how they do it…

Phishers create bogus e-mails that look as if they came from
large, well-known institutions and banks, such as eBay,
Paypal, Citibank, EarthLink, and Wells Fargo among others.
These e-mails claim that you are due for an account update,
or that the account number, password, social security number
or other confidential information needs to be verified. Then
they warn you, stating that if you do not do it within a
certain period of time, that your account will be closed,
terminated, the service discontinued, or something to that
effect.

They even provide you with links to websites that look
legitimate, because they hijack the real logos of these
well known banks, and trusted institutions and companies.
And that is the scary part… these e-mails look 100%
legitimate, but they are not.

In some cases it goes even further… some of these phishers
are installing spyware on your computer to monitor your
online activities. So… should you leave the online world for
good? Not necessarily.

These are a few things you can do to protect yourself from
these scammers:

1. Do not respond to any e-mail that asks for personal
information from you, such as account number, credit card
number, user names, passwords, etc. If you suspect that the
e-mail, indeed, be legitimate, contact your bank or
institution to verify this.

2. When in doubt, visit the Anti-Phishing Working Group for
an update of the latest scams, and tips to avoid becoming a
victim. The website’s URL is www.antiphishing.org

3. Websites like www.Paypal.com, www.citibank.com, and
www.ebay.com, offer security tips and tell you what
information they’d never ask for in an e-mail.

4. Get anti-virus software and keep it up-to-date.

5. If you suspect you have received a fraudulent e-mail, do
not click on any links within it, and forward it to the FTC
at uce@FTC.gov

Finally, if you suspect you’ve been a victim of this fraud,
get a copy of your credit report immediately to check for
unusual activity. If you discover that you’ve been a victim
of identity theft, close your account at once and…

- Call the Credit Bureau.

- File a police report.

- Call the FTC ID theft hotline at (877)IDTHEFT.

- Alert other financial institutions where you have accounts.

According to the Anti-Phishing Working Group, phishers send
millions of e-mails a day, getting about 5% response. Even
with this low response, it is estimated that about 150,000
Americans have fallen prey to these scams since May of 2004.
Get informed. Do not become a victim yourself.

Friday, May 2, 2008

Avoid Internet Theft, Fraud and Phishing

Since its birth, the Internet has grown and expanded to unprecedented, unmanageable proportions. Information, software, news, and much more flow freely through its twisted pathways. Online services such as Internet banking save time and money. However, from the depths of its vast expanse have come the dregs of society intent on preying on the new, the naïve, and the less informed.

Phishing is one of the main scams in the present moment. People set up phoney websites and email addresses. Then they spam Email inboxes with official-looking messages explaining that your account with Company X has encountered a problem and that they need you to login and confirm some details. The email addresses are masked to appear official and the links provided in the email all seem to check out. If you click on the link provided then you will usually be taken to a site that looks for all intents and purposes to be official. When you click 'submit' your details will be sent to a criminal somewhere who will do as they please with your information, such as withdrawing money from a bank account or purchasing things in your name.

The scam has been labelled 'Phishing' because the criminals engaging in the activity behave similarly to a fisherman throwing bait out in the hope that they'll receive just one bite from the millions of people that receive the email.

So how do you avoid these online scams? First and foremost, it is important to realise that no legitimate organisation should be sending you a request to fill out your personal details because of some server error or for any other reason. Your bank will never send you an email with content along the lines of "We've lost your bank account number and password... please supply them again for our records". You should also know that no bank is going to require your social security number, bank account number, and PIN number just to log in to your account or retrieve your password. Other sites such as Ebay, PayPal, and the like will not email you asking for these details either.

If you're a little unsure as to whether or not an email is official, scroll down a bit until you find the link that they are requesting you to click and simply hold your mouse pointer over the link text without clicking. Now take a look at the bottom left-hand corner of your browser window. The link text is often the address that the phisher wants you to think you will be heading to but the real address will be revealed in the bottom of the browser. This address will most likely not have anything whatsoever to do with the company that the email is attempting to imitate. It could be a dodgy web site or even just a page on someone's personal computer. If the address doesn't appear in the bottom left-hand corner then you can right-click on the link, select 'properties' from the pop-up menu and then read the address listed in the information box.

To avoid further scams make sure that you have updated firewall and anti-virus software active on your system at all times. This will make it harder for anyone to install key loggers, Trojans, spyware, or other similar devices intended to retrieve your information. Keep your operating system up to date with the latest security patches and updates and be careful where you enter your details. Always look into the reputability of the site that is requesting your details and keep an eye on the lower right-hand corner of your browser. If the page you are viewing has a little padlock symbol appear in the corner, then it means that your details are being secured by some encryption method. You can double click on the icon to get more details if you wish. Sites without the padlock icon don't have encryption, which means that your details are a lot easier for malicious crooks to get a hold of.

Even if you're sure the website is legitimate, it's not a good idea to send your details over an unsecured connection. By the way, email does not count as a secure connection, and neither does any instant messaging program, (such as MSN, ICQ, Yahoo Messenger, AIM etc.) so don't give out personal details that way either.

Another common scam very similar to phishing involves the emailing of promises of great wealth. Seriously, what do you think your chances are of winning the lottery, let alone one that you never even entered? Or of some obscure yet ridiculously rich person in Africa dying and you being legally allowed to pick up their money? Or of a foreign prince wishing to smuggle money out of his country using your account? These emails are all scams. I wish it were true that I won three different lotteries every single day, but if you get in contact with the people sending these messages they're going to do their utmost to clean out your pockets. Unfortunate as it may sound, the 'Please Donate to Charity' emails sent are usually also scams.

If you really want to donate money to a charity, look them up and send it the usual way, don't respond to a multi-recipient email that may or may not be real. You also shouldn't donate to some random charity that no one has ever heard of before. Some of the Internet lowlifes have started up fake charities, 'dedicated to helping Tsunami victims' or similar and are simply pocketing the donations.

Everything in this world can be used for either good or evil purposes and the Internet is no exception. Staying alert and having just a little bit of Internet know-how can keep you out of harm's way for the majority of the time, and allow you access to the wonderful online services available with relative safety.

Sunday, April 20, 2008

How To Improve Customer Trust In Your Online Shop Or Auction Website

Internet fraud is on the rise. As fraud becomes more profitable, it also becomes more sophisticated and difficult to detect. As a result, tech savvy web users are looking for trust worthy sites to shop at. But how trustworthy are the current solutions? Are they just superficial but ineffective against the ever technically improving internet-fraudsters?

Typically, a number of means are employed to improve the trustworthiness of a site. These include superficial approaches like designing a site that looks professional, using recognized payment processors like Paypal etc. While these measures do not improve the sites security they may improve customer confidence as a professional looking site must be operated by a professional reputable company. At least that is what some customers will think.

Certificates are used to further increase customer confidence. Many online users are becoming familiar with the use of certificates and the small padlock that appears near the address bar to signify that the site is secure. While certificates and SSL can increase the integrity of data flowing to and from the website, they do not guarantee that the site does not have a security hole. They do not guarantee that the company that purchased the certificate is reputable. Certificates give a false sense of security to customers as in themselves, they cannot secure a site.

Does the software platform you use improve security? Not many companies code their own online shop from the ground up. Even fewer do it well enough to be secure. Most companies buy a pre developed package like CubeCart etc. These packages often do not get upgraded to plug the latest security threats. While this approach offers customers a professional interface, it does not improve security.

Site security scanners are another way to improve customer confidence but do they improve site security (typically by displaying a hacker proof logo or something similar). In cases where shops use standard packages like CubeCart, these scans can detect versions and potentially spot problems. These scans cannot effectively cover all types of sites and may be ineffective on certain sites. Only one security vulnerability needs to be missed for a site to be insecure. While these scanners cannot detect all security vulnerabilities, they can produce a level of confidence for potential customers.

Website hosting providers. Many web traders place a lot of faith in their online hosting providers. There are however a lot of providers out there that do not secure their systems properly and leave their customers open to certain types of attacks. This is an area that your potential customers may not be able to see. While the hosting agent you choose may not help improve the trust of your customers, it may improve your site security.

A further way of improving site security and trust is to have the site/product/service recommended by customers that have used the site previously. This is how eBay gains the trust of potential buyers, by using their feedback system. The only way for this type of system to work for home grown sites is if the feedback system is managed by a trusted 3rd party. This type of feedback system is available free from Pubble Hill and can be integrated into any site using their free API. The API includes features that also allow your site to automatically upload products to the Pubble Hill directory. They also offer the worlds only independent search engine that allows customers to search for products based on the sellers reputation.

In conclusion, there is no real security measure that will make your site bulletproof. However, a combination of all the above will help increase your customers confidence and make your site more secure.

Sean has over 10 years R&D experience in high-tech industry. His strengths are spotting new ideas and technologies that have the potential to change the way business is done.

Saturday, April 12, 2008

7 Ways to Protect Yourself Online

Based on information provided on the Internet World Stats website, there are about 1.3 billion internet users worldwide. Some of these users are friendly people who want to enjoy entertaining themselves, communicating with friends and family, or researching and shopping. There are others who may be conducting business online and there are stil others who are there to harm your computer.

The Internet can be a great place to do a lot of great things, but special care should be taken to make sure conditions are as safe as possible.

Here they are:

1) Scan for viruses - It doesn't matter as much about what program you are using as it does how often you use it. Having the best virus software and never using it is about as bad as having no software at all. Computers can become infected in a number of different ways, so it makes sense to scan and scan often.

2) Scan for spyware - It's really not a great thing when someone can watch what you're doing from your home or business computer. Whether they are watching directly or indirecting, using software, caution should be taken to make sure spyware is removed.

3) Avoid internet scams - If it sounds too good to be true or if you're getting something for nothing, avoid it at all costs. There are probably scams being created every day that focus on people's emotions in order to persuade them to take some type of unwise action. If you fall for a scam, it can costs hundreds or thousands of dollars and can be hard to dispute if you try to prove that the actions were fraudulent.

4) Avoid hoaxes - Hoaxes play on people's emotions especially to forward emails that contain myths or folklore. Since the emails may sound like something that has actually occurred, people forward them and the process continues.

5) Report and Recognize Phishing - Phishing involves someone trying to obtain your personal information such as bank account information through cleverly designed emails and webpages. The best thing to do is to report these types of incidents to the necessary authorities. The key component is actually recognizing the phishing attempts. If you receive an email that asks for personal information or has a link to login to an account, avoid it 99% of the time. Most organizations will not ask for social security numbers, account numbers, or passwords from email.

6) Avoid pornography - The best solution for avoiding most pornography that exists on the web is to install a filter. One of the filters that I recommend can be found Bsafeonline.com.This will take care of most of the process. Inappropriate sites will be blocked and parents can take an active approach at controlling the internet use in their home.

7) Use caution when blogging - Blogging can be a great thing most of the time. It is great for search engine optimization and building communities online, but caution should be used when including information that is personal or when discussing details of other people's lives. In addition, to keep people from stalking you, I would not suggest chronicling every detail of your every day life.

Devin Dabney is a computer consultant, author, speaker, and entrepreneur who is the founder and CEO of DabneyWorks Computer Consulting. DabneyWorks provides remote and in-person computer assistance , website design and auditing, and business consultation.

 
Copyright 2009 Phishing : A Online Robbery.. Powered by Blogger Blogger Templates designed by Deluxe Templates