Security Information

Phishing and Pharming: Dangerous Scams


As soon as almost all computer users already got used to -- or at least heard about -- the word "phishing", another somewhat confusing word appeared not long ago. Pharming. Does it differ from phishing -- and if yes, how?

Two Pharmings

Actually, two completely different fields use the term "pharming" now. We can say there exist two separate "pharmings".

If genetics or businessmen from pharmaceutical industry are talking about pharming (spelled like that) it might have nothing to do with computers. This word has long been familiar to genetic engineers. For them, it's a merger of "farming" and "pharmaceutical" and means the genetic engineering technique -- inserting extraneous genes into host animals or plants in order to make them produce some pharmaceutical product. Although it is a very interesting matter, this article is not about it.

As for PC users, the term "phishing" recently emerged to denote exploitation of a vulnerability in the DNS server software caused by malicious code. This code allows the cybercriminal who contaminated this PC with it to redirect traffic from one IP-address to the one he specified. In other words, a user who types in a URL goes to another web site, not the one he wanted to--and isn't supposed to notice the difference.

Usually such a website is disguised to look like a legitimate one -- of a bank or a credit card company. Sites of this kind are used solely to steal users' confidential information such as passwords, PIN numbers, SSNs and account numbers.

Dangerous Scams

A fake website that's what "traditional" phishing has in common with pharming. This scam can fool even an experienced computer user, and it makes pharming a grave threat. The danger here is that users don't click an email link to get to a counterfeit website.

Most people enter their personal information, unaware of possible fraud. Why should they suspect anything if they type the URL themselves, not following any links in a suspiciously-looking email? Unfortunately, "ordinary" phishers are also getting smarter. They eagerly learn; there is too much money involved to make criminals earnest students. At first phishing consisted only of a social engineering scam in which phishers spammed consumer e-mail accounts with letters ostensibly from banks. The more people got aware of the scam, the less spelling mistakes these messages contained, and the more fraudulent websites looked like legitimate ones.

Since about November 2004 there has been a lot of publications of a scheme which at first was seen as a new kind of phishing. This technique includes contaminating a PC with a Trojan horse program. The problem is that this Trojan contains a keylogger which lurks at the background until the user of the infected PC visits one of the specified websites. Then the keylogger comes to life to do what it was created for -- to steal information.

It seems that this technique is actually a separate scam aimed at stealing personal information and such attacks are on the rise. Security vendor Symantec warns about commercialisation of malware -- cybercriminals prefer cash to fun, so various kinds of information-stealing software are used more actively.

Spy Audit survey made by ISP Earthlink and Webroot Software also shows disturbing figures - 33.17% PCs contaminated with some program with information stealing capability.

However, more sophisticated identity theft attempts coexist with "old-fashioned" phishing scams. That is why users should not forget the advice which they all are likely to have learned by heart:

  • Never follow a link in an email, if it claims to be from a financial institution
  • Never open an attachment if the email is from somebody you don't know
  • Protect your PC from malware
  • Stay on the alert

Alexandra Gamanenko currently works at Raytown Corporation, LLC -- an independent software developing company that provides various solutions for information security.

The company's R&D department created an innovative technology, which disables information-stealing programs. Learn more -- visit the company's website http://www.anti-keyloggers.com


MORE RESOURCES:

Daily Mail

Commentary: a deep embarrassment to security services
Times Online, UK - 1 hour ago
Although it would take only the most devoted conspiracy enthusiast to imagine that the Security Service, with only 3500 staff members at its disposal, ...
Max Mosley orgy revelation forces M15 agent to quit Telegraph.co.uk
Motor racing-British spy agency link to Mosley sex scandal Reuters UK
The Mosley Scandal gets more complicated GrandPrix
autosport.com - TheOnlinewire
all 87 news articles


ICC security delegation arrives in Pakistan
Hindu, India - 2 hours ago
Karachi, (PTI): Two security experts of British origin have arrived in Karachi with International Cricket Council (ICC) officials to carry out a ...
Security is a vital factor to attract foreign teams Daily Times
Pakistan keen to convince ICC security panel CricInfo.com
PCB desperate to get security clearance from ICC Press Trust of India
The News - International
all 14 news articles


Gulf Times

Execs, police set Monday meeting on bank security
GMA news.tv, Philippines - 11 hours ago
MANILA, Philippines - Bank security officials are scheduled to meet with the Philippine National Police on Monday to discuss enhanced security cooperation ...
(UPDATE) 10th victim in deadly RCBC heist dies ABS CBN News
(UPDATE) Cabuyao police chief relieved Inquirer.net
P2-M reward offered Philippine Star
International Herald Tribune - Inquirer.net
all 289 news articles


Security officer stabbed at club
NEWS.com.au, Australia - 6 hours ago
A NIGHTCLUB security officer is in hospital after being stabbed on the Sunshine Coast early this morning. Police allege a 31-year-old woman went to the ...


Canada.com

Netherlands, Japan, Croatia welcome Iran’s package of proposals
Tehran Times, Iran - 17 hours ago
They stated that the package is meant to promote peace, security, and justice in the world. The ambassadors highlighted the eight percent increase in the ...
Major Powers Finish N. Incentives Offer for Iran Fars News Agency
Tehran sees no need to receive security guarantee: Iran’s ambassador ISNA
Major Powers Finish Nuclear Incentives Offer for Iran Voice of America
International Herald Tribune - RIA Novosti
all 225 news articles


Sea-Tac's security: Are they serious?
Seattle Times, United States - 5 hours ago
Greg Alderete has more than a passing interest in homeland security. A retired lieutenant colonel in the Army, he has devoted most of his life to it. ...


Topsgrup buys 51% stake in UK-based security solutions co
Sify, India - 7 hours ago
Bangalore: Topsgrup has acquired a 51-per cent stake in a security solutions company in the UK. The Mumbai-based company, however, did not disclose details ...


Philippine military chief says communists no security threat
Radio Australia, Australia - 4 hours ago
"Armed Forces Chief of Staff General Alexander Yano says security forces shall have reduced the communist insurgency to ineffectiveness by 2010. ...


Jamaica Gleaner

MacMillan takes charge as security minister
Jamaica Gleaner, Jamaica - 8 hours ago
Former police chief, Colonel Trevor MacMillan, last week spent his first three days as minister of national security after Prime Minister Bruce Golding ...
Previous changes in Golding's Cabinet Jamaica Gleaner
all 2 news articles


Cyber security plans assailed
Baltimore Sun, United States - 5 hours ago
Creating a secure operating system for government computers, and also a computer-monitoring system called "Einstein" designed to look for potential security ...

Security - Google News

home | site map

Visit our other sites:
GamesBlog | GamingDepot | GimmeaRide | GimmeNetwork | Golf Biz | HotorNotGame | I Want Computers | I Want Games | I Want Hosting | I Want Music | I Want Security | JokeBox | ScriptShock | Wantedfonts | Webalize
© 2006