Security Information

Phishing


Recently I have received email from my bank/credit Card Company, eBay & pay pal saying that my account has possibly been compromised and I need to confirm my details and password in order to get continued access.

Spam email now has a new and more frightening variant, it's called phishing and it has been made by criminals and hackers who aim at getting unwitting consumers to reveal account numbers and passwords.

Usually after getting an email like the ones mentioned above from reputable companies, most of us would race to respond as quickly as possible. However, in most cases you will find that you won't be helping anyone other then the criminal who wrote that email and who has nothing to do with the actual organizations.

What is Phishing?

It is when someone creates false email that pretends to be from a bank or other authority, but which is actually designed to collect sensitive information such as passwords. This process of stealing information used for fraudulent purposes is the latest problem to plague Internet users. It is a phenomenon know as phishing i.e. emails 'fishing' for important information.

Just like Spam, phishing mails are sent to the widest possible audience so it's not unusual to receive a message asking you to confirm account details from an organization you do not actually deal with. You may be asked to fix up your eBay account when you haven't even got one!

In addition to collecting sensitive information many phishing messages try to install spy ware, Trojans etc. allowing hackers to gain backdoor entry into computers.

Types of Phishing Emails:

Some phishing emails ask for a response by email.

Some emails include a form for collecting details that you are told to fill out.

Some even include a link to a web site that resembles the actual site you expect to visit, but is actually a clone of the original site.

Number of active phishing sites reported in March, 2005: 2870

Number of brands hijacked by phishing campaigns: 78

Contains some form of target name in URL: 31%

Country hosting the most number of phishing sites: United States of America

Source: http://www.antiphishing.org

Phishing attacks can be really sophisticated. Some time ago a flaw in Internet Explorer allowed hackers to display a false address while redirecting the user to an entirely different site making it almost impossible to distinguish a phishing attack from a legitimate email.

Possible solutions:

New technologies can provide a better means of countering phishers. One option being explored by a lot of banks is the use of a secure token, a small electronic gadget that generates a unique password to be entered each time a user logs onto the web site. This would make a phishing attack useless because without the physical possession of a token it is impossible to access the account. This approach is somewhat similar to what is used at Automated Teller Machines around the world where you need to have both the card and the Pin number in order to use the machine.

One option is to use a technology popularly knows as PassMarks that effectively acts as a second password. After entering the user name a unique image pre selected by the user is displayed before s/he is asked for the password. If the proper image is not displayed the user will come to know that s/he is not on the authentic site. Another option that a lot of organizations are exploring is using text messages instead of email messages. Text messages cost money to send, so Spammers are less likely to partake in the process making it easier to distinguish between legitimate messages and fakes.

Ashish Jain
M6.Net Web Helpers
http://www.m6.net


MORE RESOURCES:

Daily Nation

Kenyan security forces kill militia commander: police
AFP - 10 hours ago
NAIROBI (AFP) — Kenyan security forces killed a militia commander,one of the most wanted rebel figures in the country, and four other fighters in a gun ...
Charge top security men over torture, demands rights team Daily Nation
Kenya: Claims of Torture By Army And Militia, As Food Shortages ... AllAfrica.com
Rights commission requests torture probe United Press International
Voice of America - Daily Nation
all 53 news articles


KVEO-TV

Texas officials sue US over border fence
The Associated Press - 4 hours ago
WASHINGTON (AP) — Texas mayors and business leaders filed a class-action lawsuit Friday alleging Homeland Security Secretary Michael Chertoff hoodwinked ...
Texas mayors, business leaderss sue federal government over border ... International Herald Tribune
Texas cities sue to stop border fence Arizona Republic
Some worry about border fence's ecological impact Houston Chronicle
San Diego Union Tribune - guardian.co.uk
all 306 news articles


US. to triple grants for Md. port security
Baltimore Sun, United States - 4 hours ago
By Matthew Hay Brown and Laura McCandlish | Sun reporters The federal government will more than triple its grant funding this year for port security in ...
St. Louis City to manage $2.6M for port security Bizjournals.com
DHS announces IPA grants Middle East Times
all 11 news articles


DigitalJournal.com

Iowa: Lawsuit Filed Over Raid
New York Times, United States - 1 hour ago
The charges include accusations of aggravated identity theft, falsely using a Social Security number, illegally re-entering the United States after being ...
Video: ICE Agents Raid Meat Packing Plant AssociatedPress
Paying the Price of the Immigration Crackdown IRC's Americas Program
Lawsuit: Immigration raid violated workers' rights The Associated Press
The NarcoSphere - WHO-TV
all 927 news articles


MSN India

Major Powers Finish Nuclear Incentives Offer for Iran
Voice of America - 7 hours ago
Officials here say the permanent UN Security Council member countries and Germany, the P-5+1, have finished the details of a revised incentive package and ...
Tehran hands proposals to Russia, China on nuclear security - 2 RIA Novosti
Iran calls UN Security Council sanctions illegal, proposes new talks International Herald Tribune
Iran Calls UN Sanctions Illegal Fars News Agency
ISNA - United Press International
all 193 news articles


Gulf Times

Missing guards in Cabuyao bank heist under custody
ABS CBN News, Philippines - 12 hours ago
The two missing security guards employed at the bank where a deadly robbery incident occurred Friday are now under custody. Police said one of the security ...
Thieves loot Philippine bank after killing 7 bank employees and a ... RTT News
8 killed in Philippine bank robbery, mostly bank employees International Herald Tribune
9 executed in bank robbery Sun.Star
Scotsman - guardian.co.uk
all 264 news articles


TopNews

Security Council wants UN peacekeepers in Somalia
The Associated Press - May 15, 2008
UNITED NATIONS (AP) — The Security Council unanimously approved a resolution on Thursday calling for a UN political presence in conflict-wracked Somalia for ...
UN Security Council Supports Possible Peacekeepers for Somalia Voice of America
Security Council express strong support for Secretary-General's ... ReliefWeb (press release)
Resolution urges UN Somalia force Aljazeera.net
AFP - PR-Inside.com (Pressemitteilung)
all 91 news articles


Verizon wins Homeland Security contract
ZDNet - May 15, 2008
Verizon picked up a huge contract from the Department of Homeland Security: a $670 million deal to provide IP and security services over 10 years, ...
Verizon and AT&T Win Homeland Security Contract RedOrbit
Verizon land 10-year deal to unify DHS networks Register
Verizon to supply Homeland Security TeleGeography
FOXBusiness - Reuters
all 187 news articles


'Foolproof' security for Jaipur match
Hindustan Times, India - 1 hour ago
There will now be close to 3000 policemen in the stadium, alongside 500 security guards from a private agency. On the eve of the match, the only thing that ...


Hi-tech security system for crowded places soon
Times of India, India - 6 hours ago
The network would consist of a central command that would control the various subsystems assigned to a particular security parameter. ...
Kapil Sibal unveils new technology to sanitize public places from ... Press Information Bureau (press release)
all 5 news articles

Security - Google News

home | site map

Visit our other sites:
GamesBlog | GamingDepot | GimmeaRide | GimmeNetwork | Golf Biz | HotorNotGame | I Want Computers | I Want Games | I Want Hosting | I Want Music | I Want Security | JokeBox | ScriptShock | Wantedfonts | Webalize
© 2006