Security Information

Fishing for Fortunes. Scam!


Spelt phishing, but pronounced as above, this despicable act is an effort to batter your bankroll or commandeer your cash.

To put it simply, you can get emails from account administrators, which strongly urge you to update details attached to that account. The issue, though, is the pretence of such mail.

You may not even have such an account as referenced.

It doesn't come from the account provider.

It can use false S.S.L. references, to present an illusion of trust and security.

It can prompt for immediate action on your part, alleging false log-in's by persons unknown, and from countries unknown. If action is not taken, they can impress on you, that the account will be suspended or closed. Indeed, anything likely to work can be fabricated, to get you to the webpage suggested in the link or hyperlink. Note the word "suggested". Likenesses to company logos are used to re-enforce "credibility".

In fact, these phishing attempts actually look pretty good or realistic. So much so that any qualms of guilt or stupidity, experienced by a "conned party" are groundless.

Experience, specific education or forewarning, is all that prevents this type of charade from widening its base of "victims".

The goal is to get you to type in your details, complete with credit card number and the rest can be guessed.

Some damage is also absorbed by the organisation or company being misrepresented and they can do little about it but warn their customers what to watch out for, and issue security instructions. Indeed, it is from accounts at reputable companies that most passing trade learn the correct or most secure procedures. It is therefore important to read any material that they offer.

Generally though, reputable companies with a mind to preserve their integrity will tell you to log-in at their main page and proceed from there. Not through a link specific to your account!

Hyperlinks can mask the true domain that you'll be brought to, with the text linked to www.anydomaindotcom (example, only), a replica or fake page. Only going to secure pages where one believes that "https" will do it, will always help but wholly unreliable. The "s" is an indication of a secure page, but are you at the right domain?

Place your mouse over the link and the domain attached to such a link, should show itself. Viewing the source code is another way but some knowledge of it is necessary.

Another ploy, sometimes deliberate and sometimes "convenient", is inserting a reference to the "legitimate company" anywhere after the domain name. Ex. https://www.anydomaindotcom/ebay/aagle/. Unwary victims may overlook the fact that "ebay" is not the domain, but see it anyway as a directory or file name. Anyone, anywhere can have a file or directory named like that of a company.

To make matters somewhat worse from an "easy to identify" viewpoint, the source code of the link can be represented as an I.P. address rather than its named counterpart. There are some tools that you can use at http://centralops.net/co/ which you can use to type in the I.P. address and cross reference it with the official account domain presented in the e-mail, or web page for that matter. Opening a second window for investigative purposes and re-sizing both to be side by side can be revealing, and comparisons be made between the alleged source and that of the source code.

www.ebay.com can be put in one window and www.suspiciouslyspurious.com can be put in the other. NOTE; you should be checking domains and ignoring everything that comes after the forward slash at the end of the domain. A similar test can be done for email viruses, where suspicious email addresses can be searched for some degree of authenticity.

If you are phished, try to learn as much as possible about it as phishing attempts and email viruses have some aspects in common. Incorrect spelling is one of them. You must understand that the authors can be from anywhere and not necessarily have degrees in English. Legitimate companies can also be from anywhere, with different primary languages, but do perfect their spellings and general grammar.

Attention to upper and lower case can be another giveaway. This is especially true where particular portions of the text are the design of the author, and not just copied and pasted. Typically, these portions are customised to be customer specific in a general sense, and fonts may even be different or out of place. Such "special" additions are to strengthen the sense of urgency and call to action.

Should you be the recipient of "phishy mail", you can forward it to spam@uce.gov

Seamus Dolly and phising samples are at http://www.CountControl.com/phishy.html


MORE RESOURCES:

National Post

UN Security Council urges int'l action to fight Somalia piracy
Xinhua, China - 12 hours ago
UNITED NATIONS, Oct. 7 (Xinhua) -- The UN Security Council voted unanimously on Tuesday to urge states to deploy naval vessels and military aircraft to ...
UN chief sees obstacles to helping Darfur, Somalia The Associated Press
New Somalia piracy resolution adopted at UN AFP
Somalia: Security Council Asks Nations With Military Capacity In ... AllAfrica.com
ReliefWeb (press release) - Bloomberg
all 252 news articles


Homeland Security Capital Corporation Awarded $3.1 Million ...
WELT ONLINE, Germany - 10 hours ago
HSCC is an international provider of specialized technology-based radiological, nuclear, environmental, disaster relief, and security solutions to ...


Jerry L. Pettis Memorial VA Medical Center Awards $200000 Security ...
MarketWatch - 10 hours ago
By deploying BrightSite, the Jerry L. Pettis Memorial VA Medical Center will be able to unite more than 21 individual security systems into an integrated ...


Feds question Georgia’s checking of new voters
Atlanta Journal Constitution,  USA - 7 hours ago
Social Security Commissioner Michael Astrue said Georgia has asked the administration to verify the identities of nearly 2 million voters, more than any ...
Feds question new voter checks in 6 states The Associated Press
Feds question new voter checks in 6 states WTHI
Feds question 6 states' new voter checks, including Georgia NBC Augusta
Atlanta Journal Constitution
all 151 news articles


Vanguard Policy Manager Enhances RACF Security, Prevents Security ...
MarketWatch - 6 hours ago
This new software enables organizations to reduce security risks and meet regulatory compliance requirements while providing an immediate return on ...


Washington Post

Palin Rips Obama on Social Security 'Fear and Panic,' but Tangles ...
Washington Post, United States - 9 hours ago
John McCain's Social Security views, continuing her criticism of the Democratic nominee. "Beware! No presidential election cycle is complete without the ...
Video: Town Hall Debate - Humanitarian Deployments: Would you us... CSPAN
McCain-Obama Presidential Debate Analysis Dakota Voice
all 1,474 news articles


FaceTime Unified Security Gateway Named Best Anti-Malware Gateway ...
MarketWatch - 13 hours ago
has awarded FaceTime Communications' Unified Security Gateway (USG) top honors in its recent live testing and review of the secure Web gateway appliance. ...


McCain at his best talking national security
Chicago Sun-Times, United States - 1 hour ago
But it was in the area of national security that McCain became a clear choice and was at his most presidential. "My hero is a guy named Teddy Roosevelt," ...


PopMatters

Q&A: E-voting security results 'awful,' says Ohio secretary of state
Computerworld, MA - 3 hours ago
... Standards & Testing" analysis, otherwise known as EVEREST, in which "critical security failures" were found in every system tested by several teams of ...
Florida's No Match-No Vote Law Violates Equal Protection OpEdNews
Voting: Don't be thrown off Florida Times-Union
Red flags on voter records may lead to nothing Columbus Dispatch
Boston Herald
all 68 news articles


Six essential Apple iPhone security tips
NetworkWorld.com, MA - 11 hours ago
By Al Sacco , CIO , 10/07/2008 If you're an Apple iPhone user and security's not on your mind, you're at risk; at risk of having a Web mail account hacked; ...

Security - Google News

home | site map
© 2006