Find more Phishing Funda....

Loading
Showing posts with label theft. Show all posts
Showing posts with label theft. Show all posts

Monday, June 16, 2008

5 Simple Steps to Protect Your Digital Downloads

A couple of days ago, I was searching for a popular eBook online.

Now I'm not going to tell you the name of this eBook for reasons you'll understand in the next few minutes.

Okay, so here I was, opening Google, entering the name of the eBook - clicking search, and checking through the first few pages of search results.

-> Forward to Page 5 of Google

I saw a link that looked like a PDF document.

Right click -> open in new window

There, in full glory, was the eBook I was searching for!

The complete eBook, mind you, not a trial or demo - sitting there for the world to download.

And this is a product that sells for over $25 online!!

Obviously I'm not going to tell you the name of the eBook because it would not be fair to the reseller.

But it just made me realise that one of the reasons digital theft is so prevalent is simply because... its so EASY!

Don't get me wrong. I don't condone theft of any kind - digital or otherwise.

But would YOU shell out $25 for a product that everyone can 'legally' download off the 5th page of Google?

Most people would just shrug their shoulders, hit the save button and thank their lucky stars.

Result: The opposite of $ KA-CHING $ for the sellers

One of the problems with selling digital products online is that it is so SIMPLE to do. So now everyone and their grandmother wants to do it.

But most newbies have no idea that it requires only a few simple steps to ensure a moderate degree of security for your downloads.

So here I've outlined the five most BASIC security steps That anyone selling digital products online must take.

These will take you only a few minutes to do, and you do not need any special software or programming knowledge.

1. ZIP THAT FILE

The biggest problem arises when sellers store their downloads as PDF documents, as in my experience above.

Now you should know that Google, Altavista and many other search engines can read and list PDF files.

While this may not be a problem for those adding content to their sites in the form of PDF newsletters and reports, it also means that you must never store a product you want to SELL as a PDF file (unless it is in a password- protected folder).

It gets worse. Google also converts your PDF files into HTML documents. So ordinary browsers not only have access to your PDF file, but - horror of horrors - they can download your SOURCE FILE as well!!

The next logical step is for them to customize it with their own links, compile it and sell it or give it away.

Result: The opposite of $ KA-CHING $ for the sellers ...AND the author.

A simple way of keeping your files out of the reach of spiders is to upload them as a zip file. Search engines cannot look inside zip files (yet) and list their contents.

2. CREATE AN INDEX.HTML FILE

You MUST have an index.html file in EVERY folder. It acts like a curtain that keeps your files away from prying eyes.

A folder without an index file is like a house without walls. Everyone can enter and help themselves to the valuables.

The 'index.htm' file is the default file that opens when you click on the link here -

http://ebizwhizpublishing.com

If you don't create an index.htm or index.html file, you'd be allowing everyone to directly access the root directory of the folder where you store your downloads.

Here is a folder I uploaded to show you what happens when you DON'T have an index file.

http://ebizwhiz-publishing.com/test/

As you can see, all the files stored in it are clearly visible and ready to download.

And yes, feel free to help yourself - I won't accuse you of stealing :-)

3. SHOW PEEPING TOMS THE EXIT

You can use a simple script to redirect peeping Toms back to your home page.

Here's the easiest way to do it using what it called a "meta refresh tag." Add it between the Header tags like this.

<head > < META HTTP-EQUIV="refresh" content="0;URL=http://ebizwhizpublishing.com" > </head>

replace <br> < with < <br> > with ><br> " with "

Just replace my URL with your own in the example above and paste it into the head of your document (before your text).

You can see how it works by clicking on the test folder here.

http://ebizwhiz-publishing.com/redirect/

Now even though you click on the folder URL, you will be sent to my home page.

4. SPIDER-PROOF YOUR DOWNLOAD PAGES

To prevent search engine spiders from reading and listing the download pages that link to your eBooks add the tag below in the head of the document.

This "Robot" tag tells the spider that this page is not to be spidered or indexed. As a result it should never show up on a search.

<head> <META NAME="ROBOTS" CONTENT="NOINDEX, NOFOLLOW"> </head>

5. CHANGE YOUR DOWNLOAD LINKS OFTEN

To prevent unscrupulous people from posting your download links on forums or message boards, change the folder or file name where you store them from time to time, even if it means having to change the download links in your merchant account.

Using these methods will give you a good degree of satisfaction, knowing that you have taken the most basic steps to protect your digital valuables - and at absolutely no cost to you.

Friday, May 2, 2008

Avoid Internet Theft, Fraud and Phishing

Since its birth, the Internet has grown and expanded to unprecedented, unmanageable proportions. Information, software, news, and much more flow freely through its twisted pathways. Online services such as Internet banking save time and money. However, from the depths of its vast expanse have come the dregs of society intent on preying on the new, the naïve, and the less informed.

Phishing is one of the main scams in the present moment. People set up phoney websites and email addresses. Then they spam Email inboxes with official-looking messages explaining that your account with Company X has encountered a problem and that they need you to login and confirm some details. The email addresses are masked to appear official and the links provided in the email all seem to check out. If you click on the link provided then you will usually be taken to a site that looks for all intents and purposes to be official. When you click 'submit' your details will be sent to a criminal somewhere who will do as they please with your information, such as withdrawing money from a bank account or purchasing things in your name.

The scam has been labelled 'Phishing' because the criminals engaging in the activity behave similarly to a fisherman throwing bait out in the hope that they'll receive just one bite from the millions of people that receive the email.

So how do you avoid these online scams? First and foremost, it is important to realise that no legitimate organisation should be sending you a request to fill out your personal details because of some server error or for any other reason. Your bank will never send you an email with content along the lines of "We've lost your bank account number and password... please supply them again for our records". You should also know that no bank is going to require your social security number, bank account number, and PIN number just to log in to your account or retrieve your password. Other sites such as Ebay, PayPal, and the like will not email you asking for these details either.

If you're a little unsure as to whether or not an email is official, scroll down a bit until you find the link that they are requesting you to click and simply hold your mouse pointer over the link text without clicking. Now take a look at the bottom left-hand corner of your browser window. The link text is often the address that the phisher wants you to think you will be heading to but the real address will be revealed in the bottom of the browser. This address will most likely not have anything whatsoever to do with the company that the email is attempting to imitate. It could be a dodgy web site or even just a page on someone's personal computer. If the address doesn't appear in the bottom left-hand corner then you can right-click on the link, select 'properties' from the pop-up menu and then read the address listed in the information box.

To avoid further scams make sure that you have updated firewall and anti-virus software active on your system at all times. This will make it harder for anyone to install key loggers, Trojans, spyware, or other similar devices intended to retrieve your information. Keep your operating system up to date with the latest security patches and updates and be careful where you enter your details. Always look into the reputability of the site that is requesting your details and keep an eye on the lower right-hand corner of your browser. If the page you are viewing has a little padlock symbol appear in the corner, then it means that your details are being secured by some encryption method. You can double click on the icon to get more details if you wish. Sites without the padlock icon don't have encryption, which means that your details are a lot easier for malicious crooks to get a hold of.

Even if you're sure the website is legitimate, it's not a good idea to send your details over an unsecured connection. By the way, email does not count as a secure connection, and neither does any instant messaging program, (such as MSN, ICQ, Yahoo Messenger, AIM etc.) so don't give out personal details that way either.

Another common scam very similar to phishing involves the emailing of promises of great wealth. Seriously, what do you think your chances are of winning the lottery, let alone one that you never even entered? Or of some obscure yet ridiculously rich person in Africa dying and you being legally allowed to pick up their money? Or of a foreign prince wishing to smuggle money out of his country using your account? These emails are all scams. I wish it were true that I won three different lotteries every single day, but if you get in contact with the people sending these messages they're going to do their utmost to clean out your pockets. Unfortunate as it may sound, the 'Please Donate to Charity' emails sent are usually also scams.

If you really want to donate money to a charity, look them up and send it the usual way, don't respond to a multi-recipient email that may or may not be real. You also shouldn't donate to some random charity that no one has ever heard of before. Some of the Internet lowlifes have started up fake charities, 'dedicated to helping Tsunami victims' or similar and are simply pocketing the donations.

Everything in this world can be used for either good or evil purposes and the Internet is no exception. Staying alert and having just a little bit of Internet know-how can keep you out of harm's way for the majority of the time, and allow you access to the wonderful online services available with relative safety.

Sunday, February 10, 2008

How To Protect Yourself From Phishing

Protect yourself from Phishing scams that could lead to identity theft. I cannot stress this enough. Phishing scams are a hot topic lately that have grown with the popularity of online banking and social networking sites like MySpace, Facebook and Friendster.

The term Phishing comes from the analogy to fishing. The phisher uses a bait to lure victims into giving out personal information like passwords and credit card numbers. The bait is typically and urgent plea from one of the victims friends or trusted websites, asking for information to resolve some sort of problem with their account.

One of the popular Myspace phishing scams uses a domain name of RNyspace.com which shows up in the browser address bar as rnyspace.com, very similar to myspace. The site is designed to look very similar to myspace and tells you that you need to log in. You need to be very careful to check the address in the web browser whenever you are asked for login information or personal financial information.

Other typical targets for phishing include online banking sites, paypal, the internal revenue service and credit card companies. Internet users must be vigilant and always double check to make sure that the site you are giving your information to is actually the site you trust.

Phishing scams have a snowball effect. One the phisher has your login information it is very easy to contact your friends, pretending to be you, and get their information as well.

Anti-phishing software is a must for anyone that accesses the internet. Most of the internet service providers have some safety measures included as part of their online security software. Most web browsers also have add-ons that can detect most phishing scams. Unfortunately, these measures are not enough. Some of the more clever phishers have found ways to trick the anti-phishing software so you need to be cautious of suspicious emails and messages.

Phishing scams are not limited to the internet. Some phishers use the telephone to make requests for information. If you get a call from your banking institution asking for personal information, hang up and call your bank directly. Your bank will have your social security number and account information on file and should only ask you to verify a few digits.

If you feel that you have been targeted by a phishing scam it is very important that you report it to the company that the phisher is pretending to be. If you receive an email that you believe to be a phishing scam you should forward it to the FTC: "spam@uec.gov" so that others will not fall prey to these attacks.

You could also Phire back on Phishers by sending back false information that they will waste time actually trying to use.

Hobbyist writer/web developer. See more at http://www.how2life.com

 
Copyright 2009 Phishing : A Online Robbery.. Powered by Blogger Blogger Templates designed by Deluxe Templates