Find more Phishing Funda....

Loading
Showing posts with label phishing. Show all posts
Showing posts with label phishing. Show all posts

Saturday, February 6, 2010

Tips For Creating Strong and Secure Passwords

Computer hacking happens when hackers who know your password do not have to resort to technological exploits, instead they can log on and do anything that you can do on the computer or network. Keeping your password secret is one of the most important things you can do to in information security to protect your computer against security breaches.

The first step in information security is creating strong passwords that cannot be easily guessed or deduced. Tips for creating strong passwords include the following: Do not use personal information for your password. Social security numbers, driver's license numbers, phone numbers, birth dates, spouse names, and pet names are all factual information that can be found out by others.

Saturday, June 14, 2008

Beware of the Newest Activity Online: Phishing

No. I’m not talking here about the outdoor activity enjoyed
by many. And no again; I did not misspell it. Phishing is
the name given to the latest online scam where millions of
unwary Americans are getting their identities stolen.

This fraudulent activity is considered the fastest growing
crime of modern times. The favorite target groups of
phishers seem to be very young children and senior citizens,
as they do not often ask for credit reports, fill out credit
card applications or solicit loans. This allows the thieves
to go undetected for longer periods of time; but still, be
careful. We all are potential targets.

Remember when throwing away unshredded documents with
personal information in the trash bin was considered a big
risk for identity theft? While this still happens, identity
thieves have become more sophisticated in recent times, and
this is how they do it…

Phishers create bogus e-mails that look as if they came from
large, well-known institutions and banks, such as eBay,
Paypal, Citibank, EarthLink, and Wells Fargo among others.
These e-mails claim that you are due for an account update,
or that the account number, password, social security number
or other confidential information needs to be verified. Then
they warn you, stating that if you do not do it within a
certain period of time, that your account will be closed,
terminated, the service discontinued, or something to that
effect.

They even provide you with links to websites that look
legitimate, because they hijack the real logos of these
well known banks, and trusted institutions and companies.
And that is the scary part… these e-mails look 100%
legitimate, but they are not.

In some cases it goes even further… some of these phishers
are installing spyware on your computer to monitor your
online activities. So… should you leave the online world for
good? Not necessarily.

These are a few things you can do to protect yourself from
these scammers:

1. Do not respond to any e-mail that asks for personal
information from you, such as account number, credit card
number, user names, passwords, etc. If you suspect that the
e-mail, indeed, be legitimate, contact your bank or
institution to verify this.

2. When in doubt, visit the Anti-Phishing Working Group for
an update of the latest scams, and tips to avoid becoming a
victim. The website’s URL is www.antiphishing.org

3. Websites like www.Paypal.com, www.citibank.com, and
www.ebay.com, offer security tips and tell you what
information they’d never ask for in an e-mail.

4. Get anti-virus software and keep it up-to-date.

5. If you suspect you have received a fraudulent e-mail, do
not click on any links within it, and forward it to the FTC
at uce@FTC.gov

Finally, if you suspect you’ve been a victim of this fraud,
get a copy of your credit report immediately to check for
unusual activity. If you discover that you’ve been a victim
of identity theft, close your account at once and…

- Call the Credit Bureau.

- File a police report.

- Call the FTC ID theft hotline at (877)IDTHEFT.

- Alert other financial institutions where you have accounts.

According to the Anti-Phishing Working Group, phishers send
millions of e-mails a day, getting about 5% response. Even
with this low response, it is estimated that about 150,000
Americans have fallen prey to these scams since May of 2004.
Get informed. Do not become a victim yourself.

Wednesday, May 28, 2008

Phishing: A Scary Way of Life

The Federal Bureau of Investigation has identified “phishing” as the “hottest and most troubling new scam on the Internet.”

What is Phishing?

Phishing is a scam initiated via e-mail. Messages are “fishing” for personal and financial information. Most often, e-mails appear to be from reputable companies (internet service providers, telephone companies, etc), banks, and other financial organizations. The e-mail message often gives a story of the bank needing to update its personal information database or a financial institution claiming your personal data had been lost.

Who Phishes?

Hackers and Scammers looking for personal and financial information use phishing as an effective method of gathering information. Phishers imitate legitimate companies in e-mails to entice people to share passwords or credit-card numbers. Recent victims include:

• Bank of America
• Best Buy
• America Online
• eBay
• PayPal
• Washington Mutual
• MSN (Microsoft Network)

History of Phishing

The term phishing comes from the fact that Internet scammers are using increasingly sophisticated lures as they "fish" for users' financial information and password data. The most common ploy is to copy the Web page code from a major site — such as AOL — and use that code to set up a replica page that appears to be part of the company's site. (This is why phishing is also called spoofing.) A fake e-mail is sent out with a link to this page, which solicits the user's credit card data or password. When the form is submitted, it sends the data to the scammer while leaving the user on the company's site so they don't suspect a thing.

Avoid Phishing

Fortunately, common sense can save you from giving away your personal information. For example, be aware for the company requesting information. I have received e-mails from banks I have never had business with. Know that your bank or ISP will never ask for your information out of the blue. Banks do not update their databases and misplace information.

Tips To Avoid Phishing

• If you receive an unexpected e-mail saying your account will be shut down unless you confirm your billing information, do not reply or click any links in the e-mail body.

• Look for words misspelled or other grammatical mistakes.

• Before submitting financial information through a Web site, look for the "lock" icon on the browser's status bar. It means your information is secure during transmission.

• If you are uncertain about the information, contact the company through an address or telephone number you know to be genuine.

• If you unknowingly supplied personal or financial information, contact your bank and credit card company immediately.

• Suspicious e-mail can be forwarded to uce@ftc.gov, and complaints should be filed with the state attorney general's office or through the FTC at www.ftc.gov.

Monday, April 28, 2008

Be Aware of Phishing Scams!

If you use emails actively in your communication, you must have received various messages claiming to be from Ebay, Paypal and a number of banks. A recent email as if from U.S. Bank Corporation that I received contains the subject "U.S. Bank Fraud Verification Process" and in the body of the mail it says "We recently reviewed your account, and suspect that your U.S. Bank Internet Banking account may have been accessed by an unauthorized third party. Protecting the security of your account and of the U.S. Bank network is our primary concern. Therefore, as a preventative measure, we have temporarily limited access to sensitive account features. To restore your account access, please take the following steps to ensure that your account has not been compromised:". It continues with a link to a webpage, which looks very similar to original web page of the bank.

The misleading web site appears authentic with familiar graphics and logos. The wordings are professional right down to the legal disclaimer at the bottom of the page.

If you happened to be holding an account of the claimed bank, followed the instructions of the email and input your account, pin, password, etc. you are doomed. You just have handed over access to your account to a con artist, who, in a matter of days, will drain off all the money available in that account.

This new scam, which is proliferating in a very rapid pace, is called "Phishing". Phishing is a form of identity theft, where a con artist with the help of official looking email containing link to phony web pages capable of harvesting information, tricks an unsuspecting victim into divulging sensitive personal data. Scammers use these data to bilk victims out of their savings.

One of the most common phishing campaigns being waged has targeted users of Web auction giant eBay and its PayPal division with financial services giant Citibank serving as another popular target. However, recently, every major bank has been hit with this scam. Crooks send out huge amounts of emails with an expectation that some of these email address owners may have online access to their accounts at the bank.

The term "Phishing" is a deviation of the word "Fishing". In hackers’ lexicon, in many words, "F" becomes "Ph". The term derives from the fact that scammers use sophisticated bait as they "fish" for users’ personal information.

According to Gartner, a research firm, illegal access to checking accounts gained via phishing has become into the fastest growing type of consumer theft in the United States. Roughly 1.98 million people reported that their checking account was breached in one way or another during the last year and US$ 2.4 billion were defrauded from the victims!

Gartner also estimated that 57 million U.S. Internet users have received phishing emails and 3 percent of them may have fooled into revealing their personal sensitive information.

The Anti-Phishing Working Group has also spotted a dramatic increase in reports of phishing attacks in recent months. Since November, 2003 phishing scams increase by about 110 percent each month. In April alone, the group identified 1125 unique phishing scams, a sharp lift of 178 percent from the previous month.

MessageLabs, a company that watches phishing scams closely, has noted an even more dramatic increase in number of phishing emails. It claims to see phishing messages jump from just 279 in September, 2003 to a staggering 215,643 in March of 2004.

The scammers also started to use more sophisticated technologies in recent months. The latest generation of phishing scammers uses several methods to trick users, including pop-up graphics to mast the true web URL of the phishing site and the installation of Spywares and Trojans on victim’s computer. The perpetrators also take advantage of security bugs in web browsers, in which the URL in the address bar appears to be for one site but is, in fact, a link to a totally different site.

A new Windows worm under the name "Korgo" is able to infiltrate into victim’s system with a key logging Trojan, steal information that the victim input in web forms and secretly transmit to designated server. There are a number of variants of this worm and they are spreading rapidly. However, Microsoft in April came up with a patch to seal this glitch. Many computers without the patch are still vulnerable to this potentially dangerous worm.

A U.S. Treasury report provides consumers with steps to prevent and report phishing scams:

  • Do not respond to or open any e-mail that warns that an account is about to be closed. Contact the company directly by phone and inquire of this e-mail.
  • Do not submit financial information unless there is a symbol for a locked padlock on the browser's status bar. Also look for the https:// at the beginning of the Web address. If both of these signs are absent, the Web site is not secure.
  • Always review your bank statement and credit card statements immediately upon receipt.
  • Verify the domestic telephone number listed on the Web site through directory assistance or other reliable sources and call the number. Many phishing attacks have originated outside the U.S. and don't have a domestic number.
  • Report suspicious activity or if you have been defrauded to the FTC and the FBI.
  • Phishing e-mails can be forwarded to uce@ftc.gov. Complaints can be filed at www.ftc.gov. Phishing attacks can also be reported to the Internet Fraud Complaint Center at www.ifccfbi.gov.

Other cautionary measures you should take in order to protect yourself are:

  • Since most of the phishing emails come through spam, get a spam filter and install on your computer.
  • If you suspect a phishing attempt, report immediately to the bank. Every bank web site has a link or a toll-free number to report scams. Don't be ashamed if you were tricked into divulging account information. If you report it immediately, your account will be protected until you receive a new PIN.
  • Change your password and PINs regularly. Banks advise that you use separate PINs and passwords for different accounts, that way if one gets compromised, your entire financial life won’t be revealed. - If you are a frequent user of EBay, download its Web browser toolbar, a small program that runs with a user's Web browser. It flashes red when the user visits a possible spoof site. The toolbar uses a database of spoof site URLs, submitted by customers and is updated quite often.
  • Check your computer frequently for possible Trojan virus.

Sunday, April 27, 2008

Internet Security Basics 101

The explosive growth of the Internet has meant that thousands of people are today experiencing the joys of being online for the first time. With growth there always comes pain. Be it your growing pains as a child or the growth and development of this part of our culture called the Internet.

Firstly we need to quickly explain what the Internet is and where it came from. The Internet is the offspring of a military project called Arpanet. Arpanet was designed to provide reliable communication during global nuclear war. A vast network of interconnected computers was set up all over the world to allow the various branches of US and NATO forces to communicate with each other.

Nuclear war never came (thankfully) and the world was left with a massive network of computers all connected together with nothing to do. Colleges and universities started to use these computers for sharing research internationally. From there it grew and spread outside colleges to local homes and businesses. The World Wide Web was born and its father was a guy called Tim Berners Lee.

When you're connected to the Internet you're sharing a vast network with hundreds of millions of other users. This shared network provides resources that 15 years ago were never thought possible. Unfortunately when something is shared its open to abuse. On the Internet this abuse comes from hackers and virus creators. Their sole intent is to cause chaos and/or harm to your computer system and millions of other computer systems all over the world.

How do you combat this? You need an Internet security system. This might sound complicated but your Internet security system will be quite straigtforward being comprised of just 2 - 3 Internet security products. We'll look at each of these products in more detail now:

AntiVirus Software

The first and most critical element of your Internet security system is antivirus software. If you don't have up-to-date antivirus software on your PC you're asking for trouble. 300 new viruses appear each month and if you're not constantly protecting your system against this threat your computer will become infected with at least one virus - it's only a matter of time.

Antivirus software scans your PC for signatures of a virus. A virus signature is the unique part of that virus. It can be a a file name, how the virus behaves or the size of the virus file itself. Good antivirus software will find viruses that haven't yet infected your PC and eliminate the ones that have.

Antivirus software can only protect your computer from viruses trying to infect it via email, CD-Rom, floppy disk, Word documents or other types of computer files. Antivirus software alone will not keep your computer 100% safe. You also need to use firewall software.

Firewall Software

The use of firewall software by home computer users is a relatively new occurence. All Internet connections are a two way process. Data must be sent and received by your computer. This data is sent through something called ports. These are not physical things rather aspects of the way your computer communicates online.

Firewall software watches these ports to make sure that only safe communication is happening between your computer and other computers online. If it sees something dangerous happening it blocks that port on your computer to make sure your computer stays safe from the person who is trying to hack into your system.

An easier way to understand a firewall would be to picture your computer as an apartment complex. At the front door of this complex there is a security guard. Every person who enters the complex must pass this security guard. If the security guard recognizes the person entering as a resident he allows them to pass without saying anything. If, however, the person entering the complex is unknown to him then he will stop that person and ask for identification. If they have no business being at the apartment complex he escorts them from the building.

If you are not currently using firewall software your computer will get hacked into - that's a guarantee.

PopUp Blocker

You can get a good popup blocker at no cost. An easy way to do this is to install either the Google or Yahoo toolbar. Both of these come with popup blockers built in. Popups are not necessarily dangerous but are a nuisance and using either of these toolbars will make your life that bit easier.

A simple rule for practicing online security is: "If in doubt then don't". If you don't recognize the file, the email address, the website or if your gut feeling says "no" then don't click that button.

Sunday, March 16, 2008

Help Stop Phishing and Pharming

Technology has brought along with it some criminals too who have found many crooked ways to use the internet to deceive people. They do this by robbing them of their identity and their life savings too. Most people begin to react to phishing attacks slowly as they get completely devastated to find that they have lost everything they have got. This is why even though it may be difficult for most to handle phishing attacks at least we must be aware of how to stop phishing.

To stop phishing it is important that users report these phishing attacks to government agencies, banks and credit card companies. It is only when we report of such phishing emails to the respective banks, credit card companies etc that they will be aware that such fraudulent emails are making the rounds and they will quickly alert all their clients thus saving many innocent people from losing their money.

If you have been a victim of a phishing fraud, make sure that you have all the bank accounts in question closed immediately and inform your banks and credit card companies about your having been deceived into revealing all personal particulars. This is one of the best ways to stop phishing at its source itself.

Another way by which you can stop phishing is by installing anti phishing software in your system so that the software prevents any kind of fraud by scrutinising all the emails coming into your box and alerts you in case there is a suspicious email trying to phish. Once you are alerted, do not on any account open such emails.

Make sure you have an effective anti phishing software installed on your system, which will immediately alert you in case of suspicion. There are spyware programs that effectively detect scam mails and send them to junk.

Most of these phishing emails always play on your sentiments like your having won a lottery ticket etc. You will be naturally thrilled about this and would not think before you unwittingly provide all your personal information and financial information. If you have any suspicion immediately, inform any of the following groups. To stop phishing send the email you have received to the Internet Fraud Complaint centre of the FBI by filing a complaint on their website. You can also report to anti phishing groups. You can find the email addresses of anti phishing groups on the internet.

Sunday, February 24, 2008

An Alternative Method To Protecting Yourself From Phishing

Phishing is one of the leading trends in cyber crime. Basically, phishing occurs when websites that appear to be the one you are looking for are actually those belonging to people that want to steal your personal information. While some web browsers and internet security softwares will attempt to protect you from phishing attacks, they are not perfect. In many cases, the end goal of phishing is to obtain enough personal information to steal your credit cards numbers, or access to bank accounts.

Along with creating websites and emails that mimic legitimate businesses like paypal, phishing is also evolving into other trends. Basically, anything that will get you to transmit personal and financial information can be exploited for phishing purposes. This includes social websites, as well as those set up for the sale of merchandise.

One of the best things you can do is make sure that anything you enroll in online does not provide the same information that you gave to your banks and other lenders. This is especially important if you enjoy singing up for news forums, or other groups that ask identifying questions that you answered for your bank. As an example, the last four digits of your social security number, or mother's maiden name are very common questions. Unfortunately, in the hands of someone intent on phishing, this information can be used to obtain your credit card information.

Therefore, when it comes to online forums where you do not expect to engage in financial transfers, treat your password backups like a real password. This includes using a different backup for each site you enroll with. Also, you should use a "hardened password" that includes at least 8 letters, one number, and a non alpha-numeric character. Not only will this stymie phishing attempts, if they do try to use the information you gave them, you will know exactly what site the fraudulent activity came from.

If you find yourself wanting to open a financial account online, and need to provide information similar to what has been requested by your credit card company, or bank, the same advice applies. Simply treat your backup information like a secure password. With a legitimate bank or credit card institution, you can always call them later on and have these things reset if need be. This is far less troublesome than becoming the victim of a phishing attack.

Because cyber crime is only limited by the ideas that people get, many different schemes can be used to steal personal information. Over the years, phishing has evolved as the premier way to gain financial information and steal personal identities. Banks and many other financial institutions often utilize backup passwords or other information to help identify you. When enrolling in social groups, it is vital to treat this information like any other type of personal information. By using words or information different from what you would use with your bank, you may well help prevent a phishing attack, and also help investigators determine where it came from.

Saturday, February 16, 2008

Phishing - How to Avoid Getting Caught

What is Phishing?
With so many of us online nowadays, it's inevitable that criminals familiar with computer technology have found ways to take advantage of it to make money. The Internet is almost impossible to police, as it crosses so many international borders, and criminals can operate basically from anywhere there's power and an internet connection. Phishing is just one of many schemes thought up by criminal minds to part us from our money.
Phishing is simply the scam of sending out a fake email in order to try and get the recipient to respond with private or financial information. You've probably received plenty of these - they pretend to come from a well known bank, tell you that someone has changed your password or that your account will be terminated if you don't confirm your details, and give you a link to click on.
Of course if you do actually click on the link, you'll be taken to a false website where the information you enter will be recorded and used to log in to your bank account or credit card and steal your money. In extreme cases, where the phishing attempt also gets private information such as your social security number, your whole identity may be stolen and used to apply for fake loans. Your financial and credit history can be ruined in literally hours, before you have any idea there's something wrong.
How Do I Avoid Being Caught?
While this sounds terrible, there are things you can do to lessen the risk of your information being phished. The first, and most important, is to NEVER respond to an email that appears to come from your financial institution. It doesn't matter how legitimate it looks, or whether it has the right logos in it. These businesses are well aware of the rapid spread of phishing, and the last thing they would do is confuse things by sending an email requesting your login details or for you to confirm a password.
If in doubt, call your bank by looking up the phone number - don't use any phone numbers included in the email - and ask them if the email is legitimate. Never click on any links or URLs contained in the email, don't reply to the email, don't acknowledge that you've received it - just hit the delete button as fast as possible.
When you're visiting websites, always be wary of supplying too much private information. Only supply such information if you're sure it's a legitimate site that you've navigated to by yourself, and there should be a locked padlock logo in the bottom of the browser so you know the site is secure. Never enter this kind of information at a website you've reached by clinking on an email link.
What Type of Phishing Emails Can I get?
Phishing isn't just limited to financial institutions. Many phishing scams imitate emails from eBay and well-known stores. They may appear to be a special offer, suggesting you click on the link to get a great deal on that particular item. The problem is that you'll end up at a website designed to steal your information, not the store's website. If you're especially interested in the deal being offered, call the store and ask if it's a genuine offer before clicking on anything.
If you do receive a suspicious email that you think is a phishing scam, it's always helpful to notify the company that it appears to come from. Some businesses have specific addresses for receiving phishing notifications, but many simply use postmaster@theirURL. PayPal can be reached via spoof@paypal.com. You can also report the scam to the Internet Crime Complaint Center, although this mainly deals with the more threatening and widespread phishing scams.
The important thing to remember is that you should never click on an email link without checking with your bank first. It doesn't matter how dire the consequences sound if you don't do it - that's all part of the scam. The more vigilant we all are, the less people will fall for phishing scams, and the better the chance that one day these criminals will give up and leave our inboxes alone.
Steve Dolan is an IT professional with over 25 years experience in the industry. Find out how to protect yourself from phishing by clicking
Phishing Attacks and avoiding spam at Spam Attacks
Article Source: http://EzineArticles.com/?expert=Steve_Dolan

Monday, February 11, 2008

“Phishing” for Suckers: Two Things You Should Look For In An email

“For Your Immediate Attention! Don’t Lose Your Account! Update Immediately!”

Bob opened the email and was confronted by the logo of one of his major credit card companies. He had been carrying the card for some time, and had used it for a lot of online purchases.

Understandably he was concerned with the message under the logo: “Due to online identity theft, we need to verify that the information in your account is accurate, or we will be required by the FTC to suspend it”.

Below was an itemized list of the information he was required to verify: his old account number, name, address, telephone number, social security number, and mother’s maiden name. The also wanted him to change the password to his account.

Panicked, Bob hit the reply button and started filling in the information. He didn’t want to lose that account. He had set up several online accounts using that credit card number, and used it to buy and sell in online auctions…

THE “PHISHERMEN” AND THEIR HOOKS

“Phishing” is a technique used by identity thieves to stampede people into giving out their credit information online. The scam has been around for awhile, and, unlike Bob, most people are aware that they should never:

• Be intimidated by a message found in an “authentic looking” email

• Reply by giving vital information to the “phishers”

• Open up any links contained within the email, which can download “criminalware” onto their computer.

We all know these facts intellectually, but when confronted by an intimidating message, many of us react emotionally, not rationally. Maybe I’m more easily intimidated than most, but I’ve found myself opening an email and feeling compelled to fill out the information the message demands.

I have to confess an incident that occurred when I almost did that very thing. In my own defense, however, I have to say that it happened before I’d ever heard the term “phishing”. Fortunately I became suspicious before hitting the “Send” button.

But I almost did it. I almost sent it off and thereby hanged myself.

THE LAKE IS GETTING CROWDED

Although the public is becoming savvier to this scam, the “phishermen” must be experiencing success because the Anti-Phishing Working Group, http://www.antiphishing.org/ reports that phishing incidents are on the upswing.

They list 28,571 consumer reported incidents in June 2006, almost double the reported numbers in June 2005.

More suckers are being “phished” than ever before, and as every honest fisherman knows, there is no bag limit on suckers.

HOW TO IDENTIFY LEGITIMATE EMAILS

Of course, the best thing to do when asked for vital information by someone purporting to be a legitimate credit card company or other institution is to call the company on the telephone and ask if the email in question does indeed come from them. Then, if it has, go to that site to change your information.

But there are a couple of “quickie” things you can look for in the email itself, which you should do if you are alarmed by the message and tempted to jump.

1. Check the “From” Address to see if the address is correct. It should come from a top level domain, i.e. ebay.com, not a sub domain such as ebay.security.com. A sub level domain can be obtained on line for free, and is not something a legitimate company would do.

2. Make Sure the “digital signature” is valid.

KNOW YOUR DIGITAL SIGNATURE

I don’t know if you’re like me, but my eyes glaze over when somebody mentions the words “digital signature”.

Basically, it’s just an electronic means of verifying that the email you received:

• Has originated from the source it claims to come from

• Hasn’t been intercepted and repackaged on the way.

An email that is “digitally signed” has a little red icon down in the lower left hand corner in the ‘To…From” box.

Click on that icon and you can find information about the sender. Be sure your email client is “S/MIME” compliant. “S/MIME” compliancy is supported by over 350 million email clients, including Microsoft Outlook, Lotus, Novel, Netscape and MacMail.

As noted on the antiphishing site, this is unspoofable for two reasons:

• It is strongly encrypted.

• It is generated when you open the email, not at the source

The email client has validated four things on receiving this email:

1. The email address in the “From” field matches the one in the digital certificate.

2. The certificate was issued by a trusted authority.

3. The message wasn’t tampered with in transit.

4. The certificate itself has not expired.

To put it simply, the certificate makes sure the email has indeed come from who it says it has come from, and hasn’t been tampered along the way.

To see what the certificate looks like, check out:

http://www.antiphishing.org/smim-dig-sig.htm

THREE WAYS TO PROTECT YOURSELF.

There are three good ways you can protect yourself from “phishermen.”

1. Call the company they supposedly represent. Don’t respond to alarming statements demanding personal information online.

2. Don’t open any links in the email. They can download “criminal ware” that can start gathering vital information off your computer.

3. Don’t open suspicious emails unless you have an “S/MIME” compliant email client and can view and open that digital icon.

LOOKING FOR SUCKERS

The phishermen are out there and still looking for suckers. Based on the rise in reported incidents they are still finding them. Armed with a little knowledge and a healthy awareness, you won’t end up in their “game bag”.

You definitely don’t want that…because the next stop is the frying pan.

Copyright 2006 John Young

John Young is a writer with a scientific and programming background. At the age of 62, he lives in California with his wife and pet cat “Bear”. His new book “Protect Yourself Against Identity Theft” can be found at: http://www.youridentitystolen.com

Phishing Filter - How to Use Phishing Filters to Prevent Any Information Theft

A lot of people are actually still afraid of using computers due to the fact that they can have viruses and people can manipulate them in order to serve their purposes.

This argument actually holds true but there are actually different types of "manipulations" that people can do. This is where anti-viruses and viruses come into play and one of the most recent developments is creating phishing filters.

Phishing is the act of "fishing" information via the internet, there are a lot of ways to do this from emails to spywares, and people can access your computer and steal your information without you knowing it.

Normally the accounts that people try to phish are financial accounts that cannot be subjected to information trace - especially if they can keep you locked out long enough to get the money into a bank and run away with it.

The most common ones in the internet are Paypal and Ebay Accounts. Apart from the usual spyware tools, scammers are using simple emails targeted at unsuspecting users. These emails come with subject lines like: "Last Warning", "Password Change Required" or "Your account is suspended" and a whole lot more.

These e-mails would appear to have come from eBay or PayPal and provide a link to their own phishing page. Now these pages are designed just like the original pages and the unsuspecting user ends up providing his/her sensitive information like username/password or Credit Card Information to these duplicate pages.

That's why I would like to add one piece of advice to all users that you should always see where the link is taking you by seeing the tool tip and then if it takes you to your usual Paypal address, follow the link.

Now in order to avoid this e-mail to ever land in your inbox you need to use a phishing filter. One of the most common ones at the moment is the Bayesian Filter that allows you to blacklist or whitelist certain individuals. It also easily integrates to popular email clients such as MS outlook.

By using this filter 90% of these types of messages will not arrive in your inbox, thus greatly increasing your phishing protection and it saves you a lot of time.

The next thing you need to use is anti-spyware software. One good program available in the market is called ad-aware by lavasoft. It is always updated and it is extremely simple to use. It runs through your computer like a virus scan - except that it only looks for spyware, which most of the time is not recognized by your virus scan as a threat to your system. Just download it and run it at least once a week and it will prevent any kind of phishing spywares to enter your system.

Now, all you need to do is just to keep these programs updated to protect your information and continuous awareness over phishing issues will also help you to be ahead of the curve and keep the scammers at bay.

Author and internet entrepreneur Bernard Pragides offers expert advice and tips regarding identity theft. Learn more about identity theft and fraud by visiting his identity theft blog and his website http://www.IdentityProtek.com for more helpful information.

Sunday, February 10, 2008

What is Phishing?

In the world of computers, phishing has become big business. Phishing, or attempting to gather information of a more sensitive nature such as logins, passwords, credit card or bank account details, has become far more prevalent today than it ever was.

Phishing is technically, just one more example of social engineering techniques that are used to trick a user into offering up their information to make it easier for the phisher to gather it.

The most recent attempts at phishing have been geared toward online banks and payment services consumers, and use emails which are purportedly from those services, or from the IRS (Internal Revenue Service) to gather information.

The emails now have begun to be targeted specifically at customers of a given bank or payment service and because they are more specific, have been given the new nomenclature-Spear Phishing.

One prevalent place that phishers will target are social networking sites, because such sites can be used to gather enough information to permit an identity theft. Nearly have of all phishing thefts between 2006 and 2007 appear to have initiated by groups doing business through the Russian Business Network which is based in St Petersburg.

There are several ways to combat phishing schemes, but the best way is education. Train the computer user, and particularly the novice user, to recognize phishing schemes for what they are and to avoid them.

Since most phishing is based to some degree on the impersonation of either a site, or a person who is in charge of that site, preventing it means finding some reliable method of determining a sites real identity.

One example is that some anti-phishing toolbars currently in use, show the domain name for the site you are currently visiting, permit you to add a nick name to it so that yo will know when you are visiting the same site again.

A general rule of thumb is that if an email comes with a banking or online payment site link, regardless of whether you believe that link is fraudulent or genuine, don't use it. Manually type in the url to the company that you use and investigate whether or not that site has asked for you to login or submit some survey or what have you, by checking your administrative messages once you are assured that you are on the genuine site.

Under no circumstances click on the link in the email, because having done so, there are times when your personal information is compromised simply by clicking the link.

If by some chance you do click the link and arrive at the suspect site, DO NOT enter information into the sites login, as those keystrokes are usually captured to permit the phisher to log into your genuine banking or online account site.

Abdul Hayi Mansoor, SEO Consultant Specialist, frequently writes informative articles about variety of topics including IT security issues.

How To Protect Yourself From Phishing

Protect yourself from Phishing scams that could lead to identity theft. I cannot stress this enough. Phishing scams are a hot topic lately that have grown with the popularity of online banking and social networking sites like MySpace, Facebook and Friendster.

The term Phishing comes from the analogy to fishing. The phisher uses a bait to lure victims into giving out personal information like passwords and credit card numbers. The bait is typically and urgent plea from one of the victims friends or trusted websites, asking for information to resolve some sort of problem with their account.

One of the popular Myspace phishing scams uses a domain name of RNyspace.com which shows up in the browser address bar as rnyspace.com, very similar to myspace. The site is designed to look very similar to myspace and tells you that you need to log in. You need to be very careful to check the address in the web browser whenever you are asked for login information or personal financial information.

Other typical targets for phishing include online banking sites, paypal, the internal revenue service and credit card companies. Internet users must be vigilant and always double check to make sure that the site you are giving your information to is actually the site you trust.

Phishing scams have a snowball effect. One the phisher has your login information it is very easy to contact your friends, pretending to be you, and get their information as well.

Anti-phishing software is a must for anyone that accesses the internet. Most of the internet service providers have some safety measures included as part of their online security software. Most web browsers also have add-ons that can detect most phishing scams. Unfortunately, these measures are not enough. Some of the more clever phishers have found ways to trick the anti-phishing software so you need to be cautious of suspicious emails and messages.

Phishing scams are not limited to the internet. Some phishers use the telephone to make requests for information. If you get a call from your banking institution asking for personal information, hang up and call your bank directly. Your bank will have your social security number and account information on file and should only ask you to verify a few digits.

If you feel that you have been targeted by a phishing scam it is very important that you report it to the company that the phisher is pretending to be. If you receive an email that you believe to be a phishing scam you should forward it to the FTC: "spam@uec.gov" so that others will not fall prey to these attacks.

You could also Phire back on Phishers by sending back false information that they will waste time actually trying to use.

Hobbyist writer/web developer. See more at http://www.how2life.com

Secret Tips To Prevent Phishing Attack

If you use your credit card online, then you're exposed to phishing attack. It's not just credit card users, but others who always entering their information through the Internet are also exposing themselves to this type of threat.

Phishing is define as stealing sensitive information using social engineering tactics. The phishers will attempt to duplicate trusted websites to retrieve your information.

Recently, researchers have found that the phishers can used a domain trusted by phishing filters to retrieve information from innocent users. This can become a headache because this attempt can bypass anti phishing filters and steal your information with the anti-phishing software installed.

How we can avoid this from happening? Nowadays, even trusted domain cannot be trusted.

I would like to suggest you to be very careful when entering your information to any website. Especially the websites that you do not trust.

If you're using the Internet Explorer 7, it has a built-in phishing filter. This built-in phishing filter can checks whether the website you're visiting is a suspicious website or not. But, don't rely on this filter too heavily.

Install a third-party anti-phishing software. It can help to protect you from phishing website. One anti-phishing software that I recommend is CallingID.

Remember to not click the link inside any emails you receive asking you to log in. If you receive an email asking you to update your banking information or something like that, type the URL directly to the web address. Do not click the link provided in the email. For example, if you receive an email from Paypal asking you to log in, type the Paypal URL directly to the web address instead of using the link provided in the email.

This can prevent phishers to steal your user name and password.

Everyday there will be attempt to steal our information and if we let our guard down, we might become their next victim. Before this happened, remember to take all the security measures that you know.

Even though we cannot have a water-tight security, but,it's best to take all the security measures that we can afford rather than have nothing against the phishers.

Azwan Asmat is the author of Chuang Computer Tips Want to know the secret of securing your PC from dangerous spyware, adware, and malware programs that can ruin your PC, your finances, and your sanity?!! Visit PC Safety 101 for more info.

Monday, February 4, 2008

Phishing 101 - How To Defend Yourself Against Phishing Attacks

What is Phishing?

Alarming numbers of Australians still do not know what the internet scam called 'phishing' (pronounced "fishing") is, nor are they adequately protected against it, a Galaxy survey has found.
Phishing is a type of fraud that tricks people into giving out their personal and banking information through hoax websites or phony emails which steal people's personal information, such as credit card numbers, account data, usernames and passwords. Many of the hoax/phishing emails may appear to come from legitimate and trusted business that you might have dealings with, such as, banks (eg. CBA) and online organisations (eg. eBay and PayPal), Internet service providers (eg. MSN and Google). The message may look quite authentic, featuring corporate logos and formats similar to the ones used for legitimate messages. Typically, these emails lead recipients to fake websites designed to trick the customer into entering their personal banking details. This information is then used to steal your money!

Because the emails look so official and convincing, they are very effective for criminals.

Criminals send out millions of these fraudulent e-mails to random e-mail addresses, whether or not they are a customer of the organisation, in the hope of luring unsuspecting innocent persons into providing their personal banking details.

If the link is followed, the victim often also downloads a malicious program which captures his/her keyboard strokes including any typed information, such as banking login details and sends them to a third party.

How to Identify E-mail Fraud

So, how do you know if the email you received is fraudulent? Here are a few things you should know:

  • Your bank will NEVER send you an email, or call you on the phone, asking you to disclose personal information such as your credit card number, online banking password or your mother's maiden name.
  • Be suspicious of unsolicited emails that have a sense of urgency and warnings that your accounts will be closed or your access limited if you do not reply.
  • The email might claim that your details are needed for a security and maintenance upgrade, to ‘verify’ your account or to protect you from a fraud threat. The email might even state that you are due to receive a refund for a bill or other fee that it claims you have been charged.
  • Does the email look professional? While some fraudulent emails may look professional at first glance, if you look more closely you may notice spelling and bad grammar, unusual language or branding that is not quite right. Fraudulent emails are not personalised and, instead, are addressed in general terms, such as 'Dear valued customer'.
  • If you receive an email notifying you that an email money transfer is being sent from a person you do not know, delete the email as it is likely fraudulent.

How to Avoid E-mail Fraud

There are some simple steps you can take to avoid becoming the victim of phishing scams:

  • Be skeptical. Fraudulent emails can look like they come from a real bank and organisation email address. If you have any doubts about an email that looks like it is from your bank or a reputable company, contact them before responding to ensure that it is legitimate. But do not use the toll-free number, email address or website address provided in the email: they may link you to the criminals rather than the bank. Use a phone number, email address or website address that you know is correct.
  • NEVER send your personal, credit card or online account details through an email.
  • NEVER send money, or give credit card or online account details to anyone you do not know and trust.
  • Do not give out your personal, credit card or online account details over the phone unless you made the call and the phone number came from a trusted source.
  • Always enter your bank or organisations website using the website address (URL) that you know is accurate - use a bookmarked link or type the address in yourself: NEVER follow a link in an email.
  • Review credit card and bank account statements as soon as you receive them to check for unauthorised charges.
  • Check your credit report at least once a year by contacting the Australian credit reporting agency Veda - Tel: 1300 762 207.
  • If the email links to a website, check the website address carefully. It's easy to disguise a link to a site. Scammers often set up fake websites with very similar addresses (eg. substituting similar-looking characters, so that paypal.com could be (and has been) spoofed as paypaI.com or paypa1.com. Similarly, a zero can be substituted for the letter O within a URL.) The longer the URL, the easier it is to conceal the true destination address.
  • Do NOT cut and paste a link from the message into your Web browser — as mentioned above, phishers can make links look like they go one place, but that actually send you to a different site. Some scammers send an email that appears to be from a legitimate business and ask you to call a phone number to update your account or access a 'refund'. Because they use VoIP (Voice over Internet Protocol technology), the area code you call does not reflect where the scammers really are. If you need to reach an organisation you do business with, call the number on your financial statements or on the back of your credit card, or type in the web address yourself.
  • NEVER enter your personal, credit card or online account information on a website that you are not certain is genuine.
  • On the Internet, whenever entering personal information, ensure that you are using a secure website. Look for https:// rather than just http:// in the address bar of your Web browser as well as a closed padlock in the bottom right corner of your browser.
  • Make sure that your computer is protected. Install anti-spam, anti-spyware and anti-virus software and make sure they are always up-to-date. You should also install a personal TWO-WAY firewall to act as a barrier to viruses and other external attacks and check for operating system patches and upgrades on a regular basis.
  • Do NOT open suspicious or unsolicited emails (spam): delete them.
  • Be cautious about opening any attachment or downloading any files from emails you receive, regardless of who sent them.
  • Update your browser.
  • NEVER use public computers to access private information. Internet kiosks at hotels and other businesses are convenient but often have Trojans and keyloggers installed that collect and transmit your information to the criminals.

What Should You Do If You Receive a Fraudulent E-mail?

If you suspect that you have received a hoax email, you should take the following action:

  • Axiom suggests that you treat phishing emails as spam and delete the email immediately from your Inbox and Deleted Items folder without opening.
  • Do NOT reply to the email, and do NOT click on any links in the email, or open any files attached to them. Never call a telephone number that you see in a spam email.
  • Spam emails are a proven method for distributing viruses and other unwanted programs. If you have clicked on the link within the email, complete a full security scan of your computer (to check for computer viruses, trojans and spyware).
  • If you have responded to any email by providing your confidential information, or believe you are a victim and have lost money as a result of phishing activities, please contact your financial institution and the local police immediately.

Final thoughts

Criminals have learned that they do not need to pull a gun on you to get your wallet or purse. They're using the Internet to steal your money and identity! Take a few simple steps to stop them, and don't become an identity theft statistic.

David Furlong is a qualified and experienced IT specialist and Technical Trainer. His list of credentials includes MCSE, MCSA, Dip IT, and a Masters in Networking and Systems Administration.

As manager of a computer consultancy firm, Axiom Networking Solutions, he recommends AVG Internet Security to his clients as a solid and reliable choice. For more information or to download your FREE 30 day AVG trial, please visit http://www.avg-antivirus.com.au

 
Copyright 2009 Phishing : A Online Robbery.. Powered by Blogger Blogger Templates designed by Deluxe Templates