Find more Phishing Funda....

Loading

Wednesday, March 19, 2008

Cyber Law : The Obstacles Facing Cyber Law Enforcement

The online community is cruel and ruthless leaving no margin of error for anyone. Once you make a bona fide mistake you get crucified immediately. It is because of this general attitude among many people in social communities, that people jump to unfair and unjustified conclusions. Most participants of these communities are used to this behaviour and are not bothered by it too much. Most of these unjustified remarks often cause embarrassment for the comment maker, which is well deserved, because you should take the consequences of your actions for speaking out loud without thinking. Where am I going with this? What does this have to do with fighting cyber crime?

Let me explain with an example: When a big company like Microsoft cause a security risk for users of Internet Explorer out of negligence, you can be sure that the press (including the online community) will throw some big stones at them. This response is justified because the safety of innocent users is put at risk because of the negligence of a respectful organisation. But when Microsoft makes a remark that is misunderstood by some people, without causing any security threats because of this ill formulated remark, why should they be crucified? Microsoft is run by people and people make mistakes. If the community wants to rant and rave about something, then find something that deserves some ranting and raving and stop wasting time on things that can be excused. The company has to waste valuable resources to put out the fires caused by this overreaction instead of using those resources to improve the security of their products. No, I am not a Microsoft prophet, I am simply using them as an example.

Investigating spam and determining the origin of a scam letter is not as simple as tracking an IP address. Most people think so, but that is because they never really tried to locate a spammer on their own after being spammed. It is very easy to forge an e-mail header and that makes it almost impossible to locate the real sender of the e-mail. Even if the header is not forged, you never know whether it is a case of identity theft. Computer criminals hack into e-mail accounts, they hijack web sites and use it to their advantage under the identity of an innocent victim. This enables them to operate undetectable by moving from one account to another. Jurisdictional constraints makes it is hard for federal organisations of one country to prosecute crimes committed in another crime, not even to speak of locating the criminal.

Abuse departments of hosting companies and service providers are so swamped with so many daily reports of spam and network abuse that it is impossible for them to respond to each and every spam report individually. It obviously creates the impression that they do not really take action against the guilty parties. Of course, some companies appear to have an abuse department, but it is only a front to make people believe that they take action against spammers. This discourages people from reporting cyber crime and it effectively allows cyber criminals to operate in the open without the risk of getting caught.

People take cyber crime lightly, cyber crime is being handled as crime committed in another dimension, a dimension not regulated by law. Cyber crime is just like any other crime committed in the normal world, the only difference comes in the methods of investigation. Cyber swindlers are real life criminals, they should never be underestimated. The fact that they operate behind a computer screen makes no difference. Law enforcement agencies do not really care about the person robbed from a couple of dollars, they only pursue the big fish. Unfortunately this is how most scammers operate. They steal a bit from one victim, they steal a bit from another victim, they steal a bit from hundreds of helpless victims and pocked thousands of dollars in the end. Law enforcement agencies will take this crime more serious if everyone starts to report it to their local police department. Sooner or later they will realise that something has to be done. Many police departments are also not equipped to handle digital evidence effectively and many police officers still do not have the skills to conduct proper cyber crime investigations.

Cyber crime is very volatile and cannot always be solved using conventional methods, so I appeal to the online community not to question the unconventional methods of cyber crime investigators. At least they are doing something about an epidemic that is ignored by many influential and powerful organisations.

Sunday, March 16, 2008

Phishing Attacks Reach New Level

The Georgia Institute of Technology has teamed up with Google to investigate how to counter new forms of phishing attacks by hackers. Hackers are able to control users' internet browsing by using the "open recursive" DNS (Domain Name System) server. This type of attack is not new, although hackers have developed a technique that makes it almost undetectable by anti-virus and anti-phishing software.

A DNS server is an internet service that translates domain names into a numerical internet protocol address. For example, users would type "google.com" into an internet browser and it would translate it to something that would look like this: "207.35.118,135". The internet browser would then direct the user to the site.

DNS servers work together in a network. If one DNS server can't find the address it would send it to another one until the address is found. Unlike other DNS servers, open recursive DNS servers answer all DNS look-up requests from any computer on the internet. It is this feature that hackers use.

Google and the Georgia Institute of Technology have discovered that there are over 17 million open recursive DNS servers. Most of these give accurate information, but 0.4% or 68,000 are giving users false addresses to phishing sites. The hackers are able to send users to phishing sites with the DNS.

Phishing sites are false sites set up by hackers. Hackers would create sites that look like the original and get users to give information such as usernames, passwords and pin numbers. For example, they could copy an online bank site and get users to register and log in. The login information is sent to the hacker and he or she is able to use it to gain access to the user's bank account. They trick users into entering their phishing site by sending a fake email. The email, for example, could be made to look as though it came from the user's bank, asking them to login and update their details. The e-mail would then contain a link to the phishing site.

Hackers are using the open DNS system by targeting the user's settings. The user would either open a virus infected attachment on an e-mail or a website with the virus embedded in it. The virus will exploit the user's computer by changing just one file in Windows registry setting. The changed setting will allow the hacker to have complete control over the user's browser.

If the virus is not stopped during the initial stages, it can go undetected for the rest of its existence. Users might believe that because they have anti-phishing software they can't be infected. However, because the hacker is operating at DNS level, the anti-phishing software is rendered useless. Hackers would allow the user to browse normally, but would re-direct them suddenly if they tried to use online banking.

Google and the Georgia Institute of Technology are looking into developing a type of software that will counteract the hackers. They are also trying to create more awareness among all administrations to change their DNS servers. There is no real benefit from having an open-server. The Georgia Institute has marked phishing attacks as one of the top threats for 2008.

Help Stop Phishing and Pharming

Technology has brought along with it some criminals too who have found many crooked ways to use the internet to deceive people. They do this by robbing them of their identity and their life savings too. Most people begin to react to phishing attacks slowly as they get completely devastated to find that they have lost everything they have got. This is why even though it may be difficult for most to handle phishing attacks at least we must be aware of how to stop phishing.

To stop phishing it is important that users report these phishing attacks to government agencies, banks and credit card companies. It is only when we report of such phishing emails to the respective banks, credit card companies etc that they will be aware that such fraudulent emails are making the rounds and they will quickly alert all their clients thus saving many innocent people from losing their money.

If you have been a victim of a phishing fraud, make sure that you have all the bank accounts in question closed immediately and inform your banks and credit card companies about your having been deceived into revealing all personal particulars. This is one of the best ways to stop phishing at its source itself.

Another way by which you can stop phishing is by installing anti phishing software in your system so that the software prevents any kind of fraud by scrutinising all the emails coming into your box and alerts you in case there is a suspicious email trying to phish. Once you are alerted, do not on any account open such emails.

Make sure you have an effective anti phishing software installed on your system, which will immediately alert you in case of suspicion. There are spyware programs that effectively detect scam mails and send them to junk.

Most of these phishing emails always play on your sentiments like your having won a lottery ticket etc. You will be naturally thrilled about this and would not think before you unwittingly provide all your personal information and financial information. If you have any suspicion immediately, inform any of the following groups. To stop phishing send the email you have received to the Internet Fraud Complaint centre of the FBI by filing a complaint on their website. You can also report to anti phishing groups. You can find the email addresses of anti phishing groups on the internet.

Sunday, February 24, 2008

An Alternative Method To Protecting Yourself From Phishing

Phishing is one of the leading trends in cyber crime. Basically, phishing occurs when websites that appear to be the one you are looking for are actually those belonging to people that want to steal your personal information. While some web browsers and internet security softwares will attempt to protect you from phishing attacks, they are not perfect. In many cases, the end goal of phishing is to obtain enough personal information to steal your credit cards numbers, or access to bank accounts.

Along with creating websites and emails that mimic legitimate businesses like paypal, phishing is also evolving into other trends. Basically, anything that will get you to transmit personal and financial information can be exploited for phishing purposes. This includes social websites, as well as those set up for the sale of merchandise.

One of the best things you can do is make sure that anything you enroll in online does not provide the same information that you gave to your banks and other lenders. This is especially important if you enjoy singing up for news forums, or other groups that ask identifying questions that you answered for your bank. As an example, the last four digits of your social security number, or mother's maiden name are very common questions. Unfortunately, in the hands of someone intent on phishing, this information can be used to obtain your credit card information.

Therefore, when it comes to online forums where you do not expect to engage in financial transfers, treat your password backups like a real password. This includes using a different backup for each site you enroll with. Also, you should use a "hardened password" that includes at least 8 letters, one number, and a non alpha-numeric character. Not only will this stymie phishing attempts, if they do try to use the information you gave them, you will know exactly what site the fraudulent activity came from.

If you find yourself wanting to open a financial account online, and need to provide information similar to what has been requested by your credit card company, or bank, the same advice applies. Simply treat your backup information like a secure password. With a legitimate bank or credit card institution, you can always call them later on and have these things reset if need be. This is far less troublesome than becoming the victim of a phishing attack.

Because cyber crime is only limited by the ideas that people get, many different schemes can be used to steal personal information. Over the years, phishing has evolved as the premier way to gain financial information and steal personal identities. Banks and many other financial institutions often utilize backup passwords or other information to help identify you. When enrolling in social groups, it is vital to treat this information like any other type of personal information. By using words or information different from what you would use with your bank, you may well help prevent a phishing attack, and also help investigators determine where it came from.

Sunday, February 17, 2008

Internet Security Suites

Installing the best Internet security software on one’s PC is an unwritten rule that many of us follow. We’ve heard countless horror stories of computer viruses and stolen identity; some making us swear we’ll never use the Internet again. But, let’s face it, the Web is essential to all of our lives and despite the risks, the benefits sure outweigh those detrimental aspects.

In order to fully protect your PC and find an Internet security software program you can stand hosting on your OS, it’s important to consider the following:

• Features-While most Internet security providers claim to ‘have it all,’ make sure you choose a software program with anti-virus and spyware protection, rootkit and spam protection, a firewall, and parental control functions, such as Security Shield 2008.

• Pricing-Everyone wants to save money and when choosing an Internet security software program, it’s vital to choose a great product with an affordable price tag. Security Shield 2008, for example, will run you $39.99 after mailing in their rebate.

• Ease of Use-Opt for a software program that is easy to install and doesn’t drain your system resources. CA Internet Security Suite Plus 2008, for example, provides an In-Product Tutorial if you run into any problems along your virus-scanning way.

• Customer Support-Make sure the Internet Security provider you go with has comprehensive customer support. Security Shield 2008 is covered by free technical support via email, phone and live chat. Many companies charge per-incident or by allotted time, so it’s wise to compare costs.

Most Internet security software programs run automatic updates and have real-time scanning capabilities, which are a must. Technology and Web-based threats aren’t static and in order to completely protect your PC, it’s crucial to choose a product that is both versatile and continuously updates itself.

Kelly Liyakasa is staff writer for 6StarReviews.com. Kelly Staller is site manager at 6StarReviews.com, a site dedicated to giving YOU, the consumer, the best product and service reviews around. If you like saving time and money by having someone else review leading sites and products, then Visit our site at 6StarReviews.com

Article Source: http://EzineArticles.com/?expert=Kelly_Liyakasa

Saturday, February 16, 2008

Phishing - How to Avoid Getting Caught

What is Phishing?
With so many of us online nowadays, it's inevitable that criminals familiar with computer technology have found ways to take advantage of it to make money. The Internet is almost impossible to police, as it crosses so many international borders, and criminals can operate basically from anywhere there's power and an internet connection. Phishing is just one of many schemes thought up by criminal minds to part us from our money.
Phishing is simply the scam of sending out a fake email in order to try and get the recipient to respond with private or financial information. You've probably received plenty of these - they pretend to come from a well known bank, tell you that someone has changed your password or that your account will be terminated if you don't confirm your details, and give you a link to click on.
Of course if you do actually click on the link, you'll be taken to a false website where the information you enter will be recorded and used to log in to your bank account or credit card and steal your money. In extreme cases, where the phishing attempt also gets private information such as your social security number, your whole identity may be stolen and used to apply for fake loans. Your financial and credit history can be ruined in literally hours, before you have any idea there's something wrong.
How Do I Avoid Being Caught?
While this sounds terrible, there are things you can do to lessen the risk of your information being phished. The first, and most important, is to NEVER respond to an email that appears to come from your financial institution. It doesn't matter how legitimate it looks, or whether it has the right logos in it. These businesses are well aware of the rapid spread of phishing, and the last thing they would do is confuse things by sending an email requesting your login details or for you to confirm a password.
If in doubt, call your bank by looking up the phone number - don't use any phone numbers included in the email - and ask them if the email is legitimate. Never click on any links or URLs contained in the email, don't reply to the email, don't acknowledge that you've received it - just hit the delete button as fast as possible.
When you're visiting websites, always be wary of supplying too much private information. Only supply such information if you're sure it's a legitimate site that you've navigated to by yourself, and there should be a locked padlock logo in the bottom of the browser so you know the site is secure. Never enter this kind of information at a website you've reached by clinking on an email link.
What Type of Phishing Emails Can I get?
Phishing isn't just limited to financial institutions. Many phishing scams imitate emails from eBay and well-known stores. They may appear to be a special offer, suggesting you click on the link to get a great deal on that particular item. The problem is that you'll end up at a website designed to steal your information, not the store's website. If you're especially interested in the deal being offered, call the store and ask if it's a genuine offer before clicking on anything.
If you do receive a suspicious email that you think is a phishing scam, it's always helpful to notify the company that it appears to come from. Some businesses have specific addresses for receiving phishing notifications, but many simply use postmaster@theirURL. PayPal can be reached via spoof@paypal.com. You can also report the scam to the Internet Crime Complaint Center, although this mainly deals with the more threatening and widespread phishing scams.
The important thing to remember is that you should never click on an email link without checking with your bank first. It doesn't matter how dire the consequences sound if you don't do it - that's all part of the scam. The more vigilant we all are, the less people will fall for phishing scams, and the better the chance that one day these criminals will give up and leave our inboxes alone.
Steve Dolan is an IT professional with over 25 years experience in the industry. Find out how to protect yourself from phishing by clicking
Phishing Attacks and avoiding spam at Spam Attacks
Article Source: http://EzineArticles.com/?expert=Steve_Dolan

Monday, February 11, 2008

“Phishing” for Suckers: Two Things You Should Look For In An email

“For Your Immediate Attention! Don’t Lose Your Account! Update Immediately!”

Bob opened the email and was confronted by the logo of one of his major credit card companies. He had been carrying the card for some time, and had used it for a lot of online purchases.

Understandably he was concerned with the message under the logo: “Due to online identity theft, we need to verify that the information in your account is accurate, or we will be required by the FTC to suspend it”.

Below was an itemized list of the information he was required to verify: his old account number, name, address, telephone number, social security number, and mother’s maiden name. The also wanted him to change the password to his account.

Panicked, Bob hit the reply button and started filling in the information. He didn’t want to lose that account. He had set up several online accounts using that credit card number, and used it to buy and sell in online auctions…

THE “PHISHERMEN” AND THEIR HOOKS

“Phishing” is a technique used by identity thieves to stampede people into giving out their credit information online. The scam has been around for awhile, and, unlike Bob, most people are aware that they should never:

• Be intimidated by a message found in an “authentic looking” email

• Reply by giving vital information to the “phishers”

• Open up any links contained within the email, which can download “criminalware” onto their computer.

We all know these facts intellectually, but when confronted by an intimidating message, many of us react emotionally, not rationally. Maybe I’m more easily intimidated than most, but I’ve found myself opening an email and feeling compelled to fill out the information the message demands.

I have to confess an incident that occurred when I almost did that very thing. In my own defense, however, I have to say that it happened before I’d ever heard the term “phishing”. Fortunately I became suspicious before hitting the “Send” button.

But I almost did it. I almost sent it off and thereby hanged myself.

THE LAKE IS GETTING CROWDED

Although the public is becoming savvier to this scam, the “phishermen” must be experiencing success because the Anti-Phishing Working Group, http://www.antiphishing.org/ reports that phishing incidents are on the upswing.

They list 28,571 consumer reported incidents in June 2006, almost double the reported numbers in June 2005.

More suckers are being “phished” than ever before, and as every honest fisherman knows, there is no bag limit on suckers.

HOW TO IDENTIFY LEGITIMATE EMAILS

Of course, the best thing to do when asked for vital information by someone purporting to be a legitimate credit card company or other institution is to call the company on the telephone and ask if the email in question does indeed come from them. Then, if it has, go to that site to change your information.

But there are a couple of “quickie” things you can look for in the email itself, which you should do if you are alarmed by the message and tempted to jump.

1. Check the “From” Address to see if the address is correct. It should come from a top level domain, i.e. ebay.com, not a sub domain such as ebay.security.com. A sub level domain can be obtained on line for free, and is not something a legitimate company would do.

2. Make Sure the “digital signature” is valid.

KNOW YOUR DIGITAL SIGNATURE

I don’t know if you’re like me, but my eyes glaze over when somebody mentions the words “digital signature”.

Basically, it’s just an electronic means of verifying that the email you received:

• Has originated from the source it claims to come from

• Hasn’t been intercepted and repackaged on the way.

An email that is “digitally signed” has a little red icon down in the lower left hand corner in the ‘To…From” box.

Click on that icon and you can find information about the sender. Be sure your email client is “S/MIME” compliant. “S/MIME” compliancy is supported by over 350 million email clients, including Microsoft Outlook, Lotus, Novel, Netscape and MacMail.

As noted on the antiphishing site, this is unspoofable for two reasons:

• It is strongly encrypted.

• It is generated when you open the email, not at the source

The email client has validated four things on receiving this email:

1. The email address in the “From” field matches the one in the digital certificate.

2. The certificate was issued by a trusted authority.

3. The message wasn’t tampered with in transit.

4. The certificate itself has not expired.

To put it simply, the certificate makes sure the email has indeed come from who it says it has come from, and hasn’t been tampered along the way.

To see what the certificate looks like, check out:

http://www.antiphishing.org/smim-dig-sig.htm

THREE WAYS TO PROTECT YOURSELF.

There are three good ways you can protect yourself from “phishermen.”

1. Call the company they supposedly represent. Don’t respond to alarming statements demanding personal information online.

2. Don’t open any links in the email. They can download “criminal ware” that can start gathering vital information off your computer.

3. Don’t open suspicious emails unless you have an “S/MIME” compliant email client and can view and open that digital icon.

LOOKING FOR SUCKERS

The phishermen are out there and still looking for suckers. Based on the rise in reported incidents they are still finding them. Armed with a little knowledge and a healthy awareness, you won’t end up in their “game bag”.

You definitely don’t want that…because the next stop is the frying pan.

Copyright 2006 John Young

John Young is a writer with a scientific and programming background. At the age of 62, he lives in California with his wife and pet cat “Bear”. His new book “Protect Yourself Against Identity Theft” can be found at: http://www.youridentitystolen.com

Phishing Filter - How to Use Phishing Filters to Prevent Any Information Theft

A lot of people are actually still afraid of using computers due to the fact that they can have viruses and people can manipulate them in order to serve their purposes.

This argument actually holds true but there are actually different types of "manipulations" that people can do. This is where anti-viruses and viruses come into play and one of the most recent developments is creating phishing filters.

Phishing is the act of "fishing" information via the internet, there are a lot of ways to do this from emails to spywares, and people can access your computer and steal your information without you knowing it.

Normally the accounts that people try to phish are financial accounts that cannot be subjected to information trace - especially if they can keep you locked out long enough to get the money into a bank and run away with it.

The most common ones in the internet are Paypal and Ebay Accounts. Apart from the usual spyware tools, scammers are using simple emails targeted at unsuspecting users. These emails come with subject lines like: "Last Warning", "Password Change Required" or "Your account is suspended" and a whole lot more.

These e-mails would appear to have come from eBay or PayPal and provide a link to their own phishing page. Now these pages are designed just like the original pages and the unsuspecting user ends up providing his/her sensitive information like username/password or Credit Card Information to these duplicate pages.

That's why I would like to add one piece of advice to all users that you should always see where the link is taking you by seeing the tool tip and then if it takes you to your usual Paypal address, follow the link.

Now in order to avoid this e-mail to ever land in your inbox you need to use a phishing filter. One of the most common ones at the moment is the Bayesian Filter that allows you to blacklist or whitelist certain individuals. It also easily integrates to popular email clients such as MS outlook.

By using this filter 90% of these types of messages will not arrive in your inbox, thus greatly increasing your phishing protection and it saves you a lot of time.

The next thing you need to use is anti-spyware software. One good program available in the market is called ad-aware by lavasoft. It is always updated and it is extremely simple to use. It runs through your computer like a virus scan - except that it only looks for spyware, which most of the time is not recognized by your virus scan as a threat to your system. Just download it and run it at least once a week and it will prevent any kind of phishing spywares to enter your system.

Now, all you need to do is just to keep these programs updated to protect your information and continuous awareness over phishing issues will also help you to be ahead of the curve and keep the scammers at bay.

Author and internet entrepreneur Bernard Pragides offers expert advice and tips regarding identity theft. Learn more about identity theft and fraud by visiting his identity theft blog and his website http://www.IdentityProtek.com for more helpful information.

Sunday, February 10, 2008

Phishing : How To Recognize A Phishing Email Message

Phishing is the practice of sending fraudulent email messages supposedly from a legitimate company or organization in order to trick someone into giving out personal and confidential information. This information could include a user ID, password, credit card number or even a Social Security number. At its most basic level, Phishing is a form of identity theft. It is one of the fastest growing cyber crimes, and there are estimates that 1 in 20 people who receive a Phishing email will respond to it with their personal information. Since the criminals who send out these Phishing messages are good at what they do, it’s important to be able to recognize a Phishing email so you won’t respond to their request and become a victim of identity theft. Here are a few signs that the message you have received might just be a Phishing expedition.

• The email message is generic. Phishing emails are sent out in bulk to thousands of people, so you’ll see a generic greeting like ‘Dear Valued Customer’ and not directly addressed to you by name.

• The message gives a false sense of urgency. Phishing emails are developed and designed specifically to push the recipient to immediate action. If there is no compelling reason to respond to the message, you won’t. But if there is a fear of some kind of consequence for not providing the requested information you might just be motivated to act quickly.

This fear, urgency or even panic created by a Phishing email begins right with the subject line. Here are a few examples from actual Phishing messages:

‘Online Alert: Online Account is Blocked’

’Fraud Report’

’Credit Card Declined Notice’

’Unauthorized Account Access’

The text of the message builds upon the initial sense of urgency. A message may state that your account will be closed within 24 hours if you don t verify your information. Sometimes the messages state that there has been suspicious activity on your bank account, or your credit card has been charged by an undesirable web site.

The criminals who send out Phishing emails have taken their scam to a new level. Now people are getting Phishing messages that offer a reward for responding to the message. The newest Phishing scam is a message that states you ve won a gift card somewhere (JC Penney, Circuit City and The Sports Authority have been recent ones), and you need to click the link in the email to provide the information where the gift can be sent. Other Phishing emails offer free enrollment in a fraud protection program by clicking the link and providing the requested information.

• The message states specifically “this is not a scam”. How does that saying go if it looks like a duck and quacks like a duck, it probably is a duck. Legitimate messages don’t need to state the obvious.

• A request is made to verify your information, and a link provided for you to do so. Phishing emails will use some tactic in order to trick the recipient into providing confidential information. This request is often tied in with the false sense of urgency created in the message. The link will take you to a very authentic looking site and ask you to fill in certain personal information. If you recognize you’ve made a mistake and you try to go back to a Phishing web site you probably won’t find it. The average lifespan of a Phishing web site in December 2004 was 6 days.

The link that is included in the email message for you to click and provide information might look legitimate, but it isn’t. Often the criminals will create a web site that has almost the same name as the original web site. They might add the word “verify” or use some other word along with the company name. You should never click a hyperlink in an email, especially if you don’t know who sent it to you.

Knowledge can be power when it comes to protecting yourself from identity theft and Phishing scams. Be aware of the tricks a criminal might do to steal your information, and don’t fall prey to them.

About The Author
Colleen Durkin writes about spyware protection. Learn more at http://spyware-removal.thrcomputer.com.

 
Copyright 2009 Phishing : A Online Robbery.. Powered by Blogger Blogger Templates designed by Deluxe Templates