Find more Phishing Funda....
Friday, August 8, 2008
New CipherSend Online Security Service Thwarts Email Address Theft And Soothes Password Fatigue
I founded CPAsites.com and made a life for myself and a few other employees by designing and managing websites for CPA firms across the country. We had no competition in the early, heady days of the late 90's and were able to quickly secure a name for ourselves by offering quality sites to quality firms.
Since 1997 however, the internet has grown from a pimply faced teenaged medium to a...well, goliath-sized pimply faced teenaged medium. I can recall getting my first spam messages in the early days of email and like everyone else, I thought they were "kinda' neat" in the way that my teenage daughters think college mail is "kinda' neat."
As a website developer in 2005 however, spam has become the bane of my existence. Invariably, once a week, we get a call or email from a CPA exasperated by the volume of spam email he or she is receiving and, also invariably, we - or the website we host for the accountant - gets the blame. "Please remove all of our email addresses off the site!" they proclaim with finality.
So much for the golden age of instant internet communication at your fingertips. Dutifully, we would comply with their requests and it wasn't until I endeavored to solve another common CPA complaint that I stumbled on the perfect solution for email theft.
For several years, the second most common complaint coming from my CPA clients was concerning an easy way to have clients email them securely from their website. After we explain to them the intricacies of password management and secure logins, they immediately dropped their security plans. They, like everyone else on the internet, suffer from "password fatigue" and weren't about to subject their clients to learning and remembering yet another password just to send their CPA some tax information.
About a year ago, we finally decided there SHOULD be an easy way to just click on a website or email link and download a person's encryption key so that you can email encrypted documents to the individual. We searched. There wasn't. Seeing a critical need not only for our CPA clients, but also for attorneys, physicians and other financial professionals, we called an encryption programmer, gave him our idea and said "do it."
The result is CipherSend.com which began selling in March of 2005 for $19.95. As the encryption programmers promised, it works perfectly for what we needed (click the button, encrypt anything and send it with no password), but imagine our surprise when we realized it also solved an even bigger problem - spambots stealing our clients' email addresses!
When our clients replace their email addresses with CipherSend buttons, spambot crawlers are stopped in their tracks. The button-owner's email address is stored on our secure server, not on his or her public website. Needless to say, both we and our clients were rather delighted that a "side effect" of the program was even better than the intended cure!
The service is ideally suited for professionals and physicians who can now quickly and easily receive secure documents from clients, associates and patients at their standard email address without the inconvenience of giving out passwords or secure logins, but it is also finding a huge market among millions of aggravated spam victims needing to replace an email address posted on a public website or included in the coding of a contact form.
CipherSend offers advantages over standard website email or contact forms with its spam-block security and double notification to site visitors when their email has been delivered and again when it is opened by the recipient. Despite the low price, CipherSend uses sophisticated 2048-bit RSA asymmetrical (two-key) encryption algorithms with maximum key length and meets government security regulations required in the healthcare industry for the transfer of patient medical information.
Since messages and documents are encrypted right on the sender's computer with a downloaded public key and decrypted by the recipient's private key, CipherSend represents true end-to-end security. A demo of the button can be found on the CipherSend.com website and the program has a 30 day free trial membership.
Generally, "the law of unintended consequences" is a nightmare scenario for people introducing a new product or service on the market, but for this fortunate CPA, "two birds with one stone" just took on new meaning and made my life a whole lot less stressful!
Monday, May 26, 2008
A New Era of Computer Security
Computer security for most can be described in 2 words, firewall and antivirus.
Until recently could one install a firewall and an antivirus program and feel quite secure. The risk of something “bad” succeeding with infecting your computer or a hacker to breach your firewall was not likely.
This as internet was filled with computer completely without protection. Easier to attack or infect the completely open computer then fight all installed counter measurements. The viruses spread quickly and if you had protection, you where protected.
The new era has come.
But look around. Read about all new versions of spam control software, software firewalls, antivirus software and similar products.
Of course are they still a good protection against all the normal threats on internet, but the new main focus is the protection they offer against new threats.
Yes, they actually all try to come up with more and more cleaver ways of protecting you from threats not even present!
And how can they do this?
The answer is quite simple.
Most attacks and viruses use variations of known methods to attack or infect. And the new technologies that are being invented all search for “how things are done” instead of “exactly this or that”.
How to find viruses.
The old way, a known virus can be found by using a signature, a known piece of code inside.
The new way, now they look for known actions certain viruses use to accomplish an infection or spreading.
How to recognize an attack.
The old way. Someone connecting to your computer in any way at all (stop them).
The new way, someone connecting via this protocol, to this port, more then 3 times per second and so on.
A couple of examples.
Norton Antivirus 2005 ™ has, Internet Worm Protection. Panda Antivirus ™ has, Trueprevent.
Other companies will follow and this will expand into other areas like firewalls and spam protection.
What’s in it for you?
New protection will catch more virus, more attacks but they will most probably require more configuration from your side as well as a better understanding of how they work. And as always, a more complex system is more likely to give you problems.
So here you are, probably a bit more secure and with a bit more technical problems.
Friday, May 2, 2008
Avoid Internet Theft, Fraud and Phishing
Since its birth, the Internet has grown and expanded to unprecedented, unmanageable proportions. Information, software, news, and much more flow freely through its twisted pathways. Online services such as Internet banking save time and money. However, from the depths of its vast expanse have come the dregs of society intent on preying on the new, the naïve, and the less informed.
Phishing is one of the main scams in the present moment. People set up phoney websites and email addresses. Then they spam Email inboxes with official-looking messages explaining that your account with Company X has encountered a problem and that they need you to login and confirm some details. The email addresses are masked to appear official and the links provided in the email all seem to check out. If you click on the link provided then you will usually be taken to a site that looks for all intents and purposes to be official. When you click 'submit' your details will be sent to a criminal somewhere who will do as they please with your information, such as withdrawing money from a bank account or purchasing things in your name.
The scam has been labelled 'Phishing' because the criminals engaging in the activity behave similarly to a fisherman throwing bait out in the hope that they'll receive just one bite from the millions of people that receive the email.
So how do you avoid these online scams? First and foremost, it is important to realise that no legitimate organisation should be sending you a request to fill out your personal details because of some server error or for any other reason. Your bank will never send you an email with content along the lines of "We've lost your bank account number and password... please supply them again for our records". You should also know that no bank is going to require your social security number, bank account number, and PIN number just to log in to your account or retrieve your password. Other sites such as Ebay, PayPal, and the like will not email you asking for these details either.
If you're a little unsure as to whether or not an email is official, scroll down a bit until you find the link that they are requesting you to click and simply hold your mouse pointer over the link text without clicking. Now take a look at the bottom left-hand corner of your browser window. The link text is often the address that the phisher wants you to think you will be heading to but the real address will be revealed in the bottom of the browser. This address will most likely not have anything whatsoever to do with the company that the email is attempting to imitate. It could be a dodgy web site or even just a page on someone's personal computer. If the address doesn't appear in the bottom left-hand corner then you can right-click on the link, select 'properties' from the pop-up menu and then read the address listed in the information box.
To avoid further scams make sure that you have updated firewall and anti-virus software active on your system at all times. This will make it harder for anyone to install key loggers, Trojans, spyware, or other similar devices intended to retrieve your information. Keep your operating system up to date with the latest security patches and updates and be careful where you enter your details. Always look into the reputability of the site that is requesting your details and keep an eye on the lower right-hand corner of your browser. If the page you are viewing has a little padlock symbol appear in the corner, then it means that your details are being secured by some encryption method. You can double click on the icon to get more details if you wish. Sites without the padlock icon don't have encryption, which means that your details are a lot easier for malicious crooks to get a hold of.
Even if you're sure the website is legitimate, it's not a good idea to send your details over an unsecured connection. By the way, email does not count as a secure connection, and neither does any instant messaging program, (such as MSN, ICQ, Yahoo Messenger, AIM etc.) so don't give out personal details that way either.
Another common scam very similar to phishing involves the emailing of promises of great wealth. Seriously, what do you think your chances are of winning the lottery, let alone one that you never even entered? Or of some obscure yet ridiculously rich person in Africa dying and you being legally allowed to pick up their money? Or of a foreign prince wishing to smuggle money out of his country using your account? These emails are all scams. I wish it were true that I won three different lotteries every single day, but if you get in contact with the people sending these messages they're going to do their utmost to clean out your pockets. Unfortunate as it may sound, the 'Please Donate to Charity' emails sent are usually also scams.
If you really want to donate money to a charity, look them up and send it the usual way, don't respond to a multi-recipient email that may or may not be real. You also shouldn't donate to some random charity that no one has ever heard of before. Some of the Internet lowlifes have started up fake charities, 'dedicated to helping Tsunami victims' or similar and are simply pocketing the donations.
Everything in this world can be used for either good or evil purposes and the Internet is no exception. Staying alert and having just a little bit of Internet know-how can keep you out of harm's way for the majority of the time, and allow you access to the wonderful online services available with relative safety.
Saturday, February 16, 2008
Phishing - How to Avoid Getting Caught
With so many of us online nowadays, it's inevitable that criminals familiar with computer technology have found ways to take advantage of it to make money. The Internet is almost impossible to police, as it crosses so many international borders, and criminals can operate basically from anywhere there's power and an internet connection. Phishing is just one of many schemes thought up by criminal minds to part us from our money.
Phishing is simply the scam of sending out a fake email in order to try and get the recipient to respond with private or financial information. You've probably received plenty of these - they pretend to come from a well known bank, tell you that someone has changed your password or that your account will be terminated if you don't confirm your details, and give you a link to click on.
Of course if you do actually click on the link, you'll be taken to a false website where the information you enter will be recorded and used to log in to your bank account or credit card and steal your money. In extreme cases, where the phishing attempt also gets private information such as your social security number, your whole identity may be stolen and used to apply for fake loans. Your financial and credit history can be ruined in literally hours, before you have any idea there's something wrong.
How Do I Avoid Being Caught?
While this sounds terrible, there are things you can do to lessen the risk of your information being phished. The first, and most important, is to NEVER respond to an email that appears to come from your financial institution. It doesn't matter how legitimate it looks, or whether it has the right logos in it. These businesses are well aware of the rapid spread of phishing, and the last thing they would do is confuse things by sending an email requesting your login details or for you to confirm a password.
If in doubt, call your bank by looking up the phone number - don't use any phone numbers included in the email - and ask them if the email is legitimate. Never click on any links or URLs contained in the email, don't reply to the email, don't acknowledge that you've received it - just hit the delete button as fast as possible.
When you're visiting websites, always be wary of supplying too much private information. Only supply such information if you're sure it's a legitimate site that you've navigated to by yourself, and there should be a locked padlock logo in the bottom of the browser so you know the site is secure. Never enter this kind of information at a website you've reached by clinking on an email link.
What Type of Phishing Emails Can I get?
Phishing isn't just limited to financial institutions. Many phishing scams imitate emails from eBay and well-known stores. They may appear to be a special offer, suggesting you click on the link to get a great deal on that particular item. The problem is that you'll end up at a website designed to steal your information, not the store's website. If you're especially interested in the deal being offered, call the store and ask if it's a genuine offer before clicking on anything.
If you do receive a suspicious email that you think is a phishing scam, it's always helpful to notify the company that it appears to come from. Some businesses have specific addresses for receiving phishing notifications, but many simply use postmaster@theirURL. PayPal can be reached via spoof@paypal.com. You can also report the scam to the Internet Crime Complaint Center, although this mainly deals with the more threatening and widespread phishing scams.
The important thing to remember is that you should never click on an email link without checking with your bank first. It doesn't matter how dire the consequences sound if you don't do it - that's all part of the scam. The more vigilant we all are, the less people will fall for phishing scams, and the better the chance that one day these criminals will give up and leave our inboxes alone.
Steve Dolan is an IT professional with over 25 years experience in the industry. Find out how to protect yourself from phishing by clicking Phishing Attacks and avoiding spam at Spam Attacks
Article Source: http://EzineArticles.com/?expert=Steve_Dolan
Monday, February 4, 2008
Phishing 101 - How To Defend Yourself Against Phishing Attacks
What is Phishing?
Alarming numbers of Australians still do not know what the internet scam called 'phishing' (pronounced "fishing") is, nor are they adequately protected against it, a Galaxy survey has found.Phishing is a type of fraud that tricks people into giving out their personal and banking information through hoax websites or phony emails which steal people's personal information, such as credit card numbers, account data, usernames and passwords. Many of the hoax/phishing emails may appear to come from legitimate and trusted business that you might have dealings with, such as, banks (eg. CBA) and online organisations (eg. eBay and PayPal), Internet service providers (eg. MSN and Google). The message may look quite authentic, featuring corporate logos and formats similar to the ones used for legitimate messages. Typically, these emails lead recipients to fake websites designed to trick the customer into entering their personal banking details. This information is then used to steal your money!
Because the emails look so official and convincing, they are very effective for criminals.
Criminals send out millions of these fraudulent e-mails to random e-mail addresses, whether or not they are a customer of the organisation, in the hope of luring unsuspecting innocent persons into providing their personal banking details.
If the link is followed, the victim often also downloads a malicious program which captures his/her keyboard strokes including any typed information, such as banking login details and sends them to a third party.
How to Identify E-mail Fraud
So, how do you know if the email you received is fraudulent? Here are a few things you should know:
- Your bank will NEVER send you an email, or call you on the phone, asking you to disclose personal information such as your credit card number, online banking password or your mother's maiden name.
- Be suspicious of unsolicited emails that have a sense of urgency and warnings that your accounts will be closed or your access limited if you do not reply.
- The email might claim that your details are needed for a security and maintenance upgrade, to ‘verify’ your account or to protect you from a fraud threat. The email might even state that you are due to receive a refund for a bill or other fee that it claims you have been charged.
- Does the email look professional? While some fraudulent emails may look professional at first glance, if you look more closely you may notice spelling and bad grammar, unusual language or branding that is not quite right. Fraudulent emails are not personalised and, instead, are addressed in general terms, such as 'Dear valued customer'.
- If you receive an email notifying you that an email money transfer is being sent from a person you do not know, delete the email as it is likely fraudulent.
How to Avoid E-mail Fraud
There are some simple steps you can take to avoid becoming the victim of phishing scams:
- Be skeptical. Fraudulent emails can look like they come from a real bank and organisation email address. If you have any doubts about an email that looks like it is from your bank or a reputable company, contact them before responding to ensure that it is legitimate. But do not use the toll-free number, email address or website address provided in the email: they may link you to the criminals rather than the bank. Use a phone number, email address or website address that you know is correct.
- NEVER send your personal, credit card or online account details through an email.
- NEVER send money, or give credit card or online account details to anyone you do not know and trust.
- Do not give out your personal, credit card or online account details over the phone unless you made the call and the phone number came from a trusted source.
- Always enter your bank or organisations website using the website address (URL) that you know is accurate - use a bookmarked link or type the address in yourself: NEVER follow a link in an email.
- Review credit card and bank account statements as soon as you receive them to check for unauthorised charges.
- Check your credit report at least once a year by contacting the Australian credit reporting agency Veda - Tel: 1300 762 207.
- If the email links to a website, check the website address carefully. It's easy to disguise a link to a site. Scammers often set up fake websites with very similar addresses (eg. substituting similar-looking characters, so that paypal.com could be (and has been) spoofed as paypaI.com or paypa1.com. Similarly, a zero can be substituted for the letter O within a URL.) The longer the URL, the easier it is to conceal the true destination address.
- Do NOT cut and paste a link from the message into your Web browser — as mentioned above, phishers can make links look like they go one place, but that actually send you to a different site. Some scammers send an email that appears to be from a legitimate business and ask you to call a phone number to update your account or access a 'refund'. Because they use VoIP (Voice over Internet Protocol technology), the area code you call does not reflect where the scammers really are. If you need to reach an organisation you do business with, call the number on your financial statements or on the back of your credit card, or type in the web address yourself.
- NEVER enter your personal, credit card or online account information on a website that you are not certain is genuine.
- On the Internet, whenever entering personal information, ensure that you are using a secure website. Look for https:// rather than just http:// in the address bar of your Web browser as well as a closed padlock in the bottom right corner of your browser.
- Make sure that your computer is protected. Install anti-spam, anti-spyware and anti-virus software and make sure they are always up-to-date. You should also install a personal TWO-WAY firewall to act as a barrier to viruses and other external attacks and check for operating system patches and upgrades on a regular basis.
- Do NOT open suspicious or unsolicited emails (spam): delete them.
- Be cautious about opening any attachment or downloading any files from emails you receive, regardless of who sent them.
- Update your browser.
- NEVER use public computers to access private information. Internet kiosks at hotels and other businesses are convenient but often have Trojans and keyloggers installed that collect and transmit your information to the criminals.
What Should You Do If You Receive a Fraudulent E-mail?
If you suspect that you have received a hoax email, you should take the following action:
- Axiom suggests that you treat phishing emails as spam and delete the email immediately from your Inbox and Deleted Items folder without opening.
- Do NOT reply to the email, and do NOT click on any links in the email, or open any files attached to them. Never call a telephone number that you see in a spam email.
- Spam emails are a proven method for distributing viruses and other unwanted programs. If you have clicked on the link within the email, complete a full security scan of your computer (to check for computer viruses, trojans and spyware).
- If you have responded to any email by providing your confidential information, or believe you are a victim and have lost money as a result of phishing activities, please contact your financial institution and the local police immediately.
Final thoughts
Criminals have learned that they do not need to pull a gun on you to get your wallet or purse. They're using the Internet to steal your money and identity! Take a few simple steps to stop them, and don't become an identity theft statistic.
David Furlong is a qualified and experienced IT specialist and Technical Trainer. His list of credentials includes MCSE, MCSA, Dip IT, and a Masters in Networking and Systems Administration.
As manager of a computer consultancy firm, Axiom Networking Solutions, he recommends AVG Internet Security to his clients as a solid and reliable choice. For more information or to download your FREE 30 day AVG trial, please visit http://www.avg-antivirus.com.au
Article Source: http://EzineArticles.com/?expert=David_Furlong