Find more Phishing Funda....

Loading
Showing posts with label phishing scams. Show all posts
Showing posts with label phishing scams. Show all posts

Saturday, April 12, 2008

7 Ways to Protect Yourself Online

Based on information provided on the Internet World Stats website, there are about 1.3 billion internet users worldwide. Some of these users are friendly people who want to enjoy entertaining themselves, communicating with friends and family, or researching and shopping. There are others who may be conducting business online and there are stil others who are there to harm your computer.

The Internet can be a great place to do a lot of great things, but special care should be taken to make sure conditions are as safe as possible.

Here they are:

1) Scan for viruses - It doesn't matter as much about what program you are using as it does how often you use it. Having the best virus software and never using it is about as bad as having no software at all. Computers can become infected in a number of different ways, so it makes sense to scan and scan often.

2) Scan for spyware - It's really not a great thing when someone can watch what you're doing from your home or business computer. Whether they are watching directly or indirecting, using software, caution should be taken to make sure spyware is removed.

3) Avoid internet scams - If it sounds too good to be true or if you're getting something for nothing, avoid it at all costs. There are probably scams being created every day that focus on people's emotions in order to persuade them to take some type of unwise action. If you fall for a scam, it can costs hundreds or thousands of dollars and can be hard to dispute if you try to prove that the actions were fraudulent.

4) Avoid hoaxes - Hoaxes play on people's emotions especially to forward emails that contain myths or folklore. Since the emails may sound like something that has actually occurred, people forward them and the process continues.

5) Report and Recognize Phishing - Phishing involves someone trying to obtain your personal information such as bank account information through cleverly designed emails and webpages. The best thing to do is to report these types of incidents to the necessary authorities. The key component is actually recognizing the phishing attempts. If you receive an email that asks for personal information or has a link to login to an account, avoid it 99% of the time. Most organizations will not ask for social security numbers, account numbers, or passwords from email.

6) Avoid pornography - The best solution for avoiding most pornography that exists on the web is to install a filter. One of the filters that I recommend can be found Bsafeonline.com.This will take care of most of the process. Inappropriate sites will be blocked and parents can take an active approach at controlling the internet use in their home.

7) Use caution when blogging - Blogging can be a great thing most of the time. It is great for search engine optimization and building communities online, but caution should be used when including information that is personal or when discussing details of other people's lives. In addition, to keep people from stalking you, I would not suggest chronicling every detail of your every day life.

Devin Dabney is a computer consultant, author, speaker, and entrepreneur who is the founder and CEO of DabneyWorks Computer Consulting. DabneyWorks provides remote and in-person computer assistance , website design and auditing, and business consultation.

Tuesday, April 1, 2008

Be Aware Of Phishing Scams

If you surf the web, purchase products over the web or use the many financial services offered by your credit card company, bank and even Paypal and Ebay, then you should be aware of Phishing scams and how they can affect you personally.
Phishing scams are when hackers or criminals masquerade as a legitimate entities in order to steal sensitive information such as credit card numbers, social security numbers, etc to commit fraud. Phishing scams are numerous on the web and can affect almost anyone. Here are some tips to easily spot phishing scams and what to do if you think your information has been compromised.
How to Spot Phishing Scams
A vast majority of phishing scams come in the form of email. Emails are sent to possibly millions of people stating that they are from a legitimate entity such as American Express, Chase Bank, Ebay, Paypal, etc. The email itself looks very convincing (in fact, it is usually an exact copy of official emails sent). Within the email it will usually state that your account information is not up to date and not updating this information could jeopardize your account. It will usually give you a hyperlink to click on to update your account information which will usually ask you for your full name, address, social security number and account number. Once you have given all your sensitive information to this web site, the hacker or criminal organization can now use this info to make purchase online using your credit card information, open up loans using your info and literally steal money from your bank account.
Three ways to spot phishing scams are to make sure that the email is addressed directly to you. Inside the email itself, it should state your full name. If it says "Dear member" or "Dear customer" it most likely is a phishing scam. Secondly, the email that you receive the message from should be the one that you have given to the company. If you have five email address and use only one email address for all your finance related business, any emails you receive on your other email addresses are likely phishing scams. Thirdly, the vast majority of financial companies will never ask you for your account information or other sensitive info through an email. Email is not privacy protected and legitimate companies will not harm their customers in such a way.
An Easy Way to Thwart All Phishing Scams
Whether you think an email is legitimate or not, never click on any hyperlink within the email, instead, simply open up a new browser window, type in the financial company's address and log into your account. If your account requires any kind of update, it will state it. Usually, most companies will send you a letter in the mail or call you directly if there is some kind of issue. But even over the phone, make sure you are talking with a representative of the company before giving out information. They should have the information themselves and not be asking you for it.

Monday, February 11, 2008

“Phishing” for Suckers: Two Things You Should Look For In An email

“For Your Immediate Attention! Don’t Lose Your Account! Update Immediately!”

Bob opened the email and was confronted by the logo of one of his major credit card companies. He had been carrying the card for some time, and had used it for a lot of online purchases.

Understandably he was concerned with the message under the logo: “Due to online identity theft, we need to verify that the information in your account is accurate, or we will be required by the FTC to suspend it”.

Below was an itemized list of the information he was required to verify: his old account number, name, address, telephone number, social security number, and mother’s maiden name. The also wanted him to change the password to his account.

Panicked, Bob hit the reply button and started filling in the information. He didn’t want to lose that account. He had set up several online accounts using that credit card number, and used it to buy and sell in online auctions…

THE “PHISHERMEN” AND THEIR HOOKS

“Phishing” is a technique used by identity thieves to stampede people into giving out their credit information online. The scam has been around for awhile, and, unlike Bob, most people are aware that they should never:

• Be intimidated by a message found in an “authentic looking” email

• Reply by giving vital information to the “phishers”

• Open up any links contained within the email, which can download “criminalware” onto their computer.

We all know these facts intellectually, but when confronted by an intimidating message, many of us react emotionally, not rationally. Maybe I’m more easily intimidated than most, but I’ve found myself opening an email and feeling compelled to fill out the information the message demands.

I have to confess an incident that occurred when I almost did that very thing. In my own defense, however, I have to say that it happened before I’d ever heard the term “phishing”. Fortunately I became suspicious before hitting the “Send” button.

But I almost did it. I almost sent it off and thereby hanged myself.

THE LAKE IS GETTING CROWDED

Although the public is becoming savvier to this scam, the “phishermen” must be experiencing success because the Anti-Phishing Working Group, http://www.antiphishing.org/ reports that phishing incidents are on the upswing.

They list 28,571 consumer reported incidents in June 2006, almost double the reported numbers in June 2005.

More suckers are being “phished” than ever before, and as every honest fisherman knows, there is no bag limit on suckers.

HOW TO IDENTIFY LEGITIMATE EMAILS

Of course, the best thing to do when asked for vital information by someone purporting to be a legitimate credit card company or other institution is to call the company on the telephone and ask if the email in question does indeed come from them. Then, if it has, go to that site to change your information.

But there are a couple of “quickie” things you can look for in the email itself, which you should do if you are alarmed by the message and tempted to jump.

1. Check the “From” Address to see if the address is correct. It should come from a top level domain, i.e. ebay.com, not a sub domain such as ebay.security.com. A sub level domain can be obtained on line for free, and is not something a legitimate company would do.

2. Make Sure the “digital signature” is valid.

KNOW YOUR DIGITAL SIGNATURE

I don’t know if you’re like me, but my eyes glaze over when somebody mentions the words “digital signature”.

Basically, it’s just an electronic means of verifying that the email you received:

• Has originated from the source it claims to come from

• Hasn’t been intercepted and repackaged on the way.

An email that is “digitally signed” has a little red icon down in the lower left hand corner in the ‘To…From” box.

Click on that icon and you can find information about the sender. Be sure your email client is “S/MIME” compliant. “S/MIME” compliancy is supported by over 350 million email clients, including Microsoft Outlook, Lotus, Novel, Netscape and MacMail.

As noted on the antiphishing site, this is unspoofable for two reasons:

• It is strongly encrypted.

• It is generated when you open the email, not at the source

The email client has validated four things on receiving this email:

1. The email address in the “From” field matches the one in the digital certificate.

2. The certificate was issued by a trusted authority.

3. The message wasn’t tampered with in transit.

4. The certificate itself has not expired.

To put it simply, the certificate makes sure the email has indeed come from who it says it has come from, and hasn’t been tampered along the way.

To see what the certificate looks like, check out:

http://www.antiphishing.org/smim-dig-sig.htm

THREE WAYS TO PROTECT YOURSELF.

There are three good ways you can protect yourself from “phishermen.”

1. Call the company they supposedly represent. Don’t respond to alarming statements demanding personal information online.

2. Don’t open any links in the email. They can download “criminal ware” that can start gathering vital information off your computer.

3. Don’t open suspicious emails unless you have an “S/MIME” compliant email client and can view and open that digital icon.

LOOKING FOR SUCKERS

The phishermen are out there and still looking for suckers. Based on the rise in reported incidents they are still finding them. Armed with a little knowledge and a healthy awareness, you won’t end up in their “game bag”.

You definitely don’t want that…because the next stop is the frying pan.

Copyright 2006 John Young

John Young is a writer with a scientific and programming background. At the age of 62, he lives in California with his wife and pet cat “Bear”. His new book “Protect Yourself Against Identity Theft” can be found at: http://www.youridentitystolen.com

 
Copyright 2009 Phishing : A Online Robbery.. Powered by Blogger Blogger Templates designed by Deluxe Templates