Friday, June 26, 2009

Phishing: Examples and its prevention method

The webopedia define Phishing as the act of sending an e-mail to a user falsely
by claiming to be an established legitimate enterprise in an attempt to scam the user into surrendering private information that will be used for identity theft. The e-mail directs the user to visit a Web site where they are asked to update personal information, such as passwords and credit card, social security, and bank account numbers, that the legitimate organization already has. The Web site, however, is bogus and set up only to steal the use information.

Phishing can be called a synonym to actual fishing. Scammer throws in bait by sending you an email, pretending to be a representative of the company. He wastrying to get sensitive information from you. If you eat the bait, the scammer will obtain your username and password, credit card information or whatever you have sent him.

There are a several examples of phishing that have been identified.
Firstly, we are going to look at the example of ‘eBay phishing.’ Nowadays, sophisticated and clever scams are arising with javascript. eBay allows javascript, which is a programming language to be implemented into the templates of auctions, giving scammers opportunities to scam right on ebay.com! You may get scammed even in the original ebay site itself . The scammer uses a fake feedback in order to make buyers believe he has a reputation at eBay. Look at this:

A fake feedback score of 120, fake paypal buyer protection button and power seller!


The true feedback:


Bellow is also one of the example from ebay:

This genuine looking email is a masquerade. As soon as you clicked on “respond”, you were directed to an exact clone of eBay and your personal information was stolen. These messages come in different styles and writings.


The second example is phishing emails and scam attacks. In this example you are informed of a payment made by you. Though the email is very nicely formatted and looks quite like a legitimate Paypal email, it does not included your name. Besides that, if you mouse point over the "Item Title" link, the URL points to an I.P. address but not to the Paypal web site, which is http://www.paypal.com/.


The Third example would be Citizens Bank.The phish site looks like a simple ligitimate survey, except the demand for a debit card number.The debit card information is demanded with the explanation that 'this is where we will credit your $5 reward'. However, the real bank would normally send you a special page, linked to your account as they already know who you are, and not demand this information via an unsecured session


Many users are suffering from phishing attacks. The attacks of the Phishing are increasing day by day on to the computers. Prevention is the best approach and you can prevent yourself in many ways.

Keep Your Email and Instant Message Addresses Private
The best way to keep yourself from being tempted to respond to a phishing scam is to prevent them from landing in your email box in the first place. You may find it useful to have a separate email address for financial institutions, one for trusted friends and family, and one for general or public use. Many email providers will allow you to redirect emails from each of these different addresses to one account to minimize the inconvenience of checking each account. Do everything possible to keep the address you use for financial transactions as private as possible.

Password Privacy
The individuals will be able to get the services an information by rendering a trusted institution. Sometimes you might have received an email from back about the confirmation of your password. In this case you should verify from the email sender who they are. It might be some virus which will get your personal data by automatic installation.

Immediately Report Suspected Phishing Contacts
If you do receive a message you suspect to be a phishing scam, call the customer service phone number right away to confirm whether you've received an actual message or not. In addition, almost every bank and credit card lender has a website where you can report suspicious emails and instant messages. Typically, they will ask you to fill out a simple form that will give them enough information to trace the origin of the perpetrator.

Education
It is important for the computer users to recognize the phishing and other attacks in the form of fraudulent emails and websites. If you are receiving these email then you should report other as well to prevent from these emails. You can contact the Anti Phishing Working Group who can guide and you and recommend some suggestions for your help.

It is a good thing to monitor credit changes along with taking measure to prevent phishing attacks. You can save yourself from severity of problems with quick response to credit card response.


As a conclusion, we should act as the role of 'phisherman' to protect ourselves from being the victim.


References:
  1. http://onlinebusiness.about.com/od/onlinebusinessglossary/g/phishing.htm?rd=1
  2. http://www.webopedia.com/TERM/P/phishing.html
  3. http://www.bustathief.com/what-is-phishing-ebay-phishing-examples/Paypal
  4. http://www.webdevelopersnotes.com/
  5. http://www.antiphishing.org/
  6. http://security-antivirus-software.suite101.com/article.cfm/how_to_protect_yourself_from_phishing_attacks

No comments:

Post a Comment