Security Information

Phishing


Recently I have received email from my bank/credit Card Company, eBay & pay pal saying that my account has possibly been compromised and I need to confirm my details and password in order to get continued access.

Spam email now has a new and more frightening variant, it's called phishing and it has been made by criminals and hackers who aim at getting unwitting consumers to reveal account numbers and passwords.

Usually after getting an email like the ones mentioned above from reputable companies, most of us would race to respond as quickly as possible. However, in most cases you will find that you won't be helping anyone other then the criminal who wrote that email and who has nothing to do with the actual organizations.

What is Phishing?

It is when someone creates false email that pretends to be from a bank or other authority, but which is actually designed to collect sensitive information such as passwords. This process of stealing information used for fraudulent purposes is the latest problem to plague Internet users. It is a phenomenon know as phishing i.e. emails 'fishing' for important information.

Just like Spam, phishing mails are sent to the widest possible audience so it's not unusual to receive a message asking you to confirm account details from an organization you do not actually deal with. You may be asked to fix up your eBay account when you haven't even got one!

In addition to collecting sensitive information many phishing messages try to install spy ware, Trojans etc. allowing hackers to gain backdoor entry into computers.

Types of Phishing Emails:

Some phishing emails ask for a response by email.

Some emails include a form for collecting details that you are told to fill out.

Some even include a link to a web site that resembles the actual site you expect to visit, but is actually a clone of the original site.

Number of active phishing sites reported in March, 2005: 2870

Number of brands hijacked by phishing campaigns: 78

Contains some form of target name in URL: 31%

Country hosting the most number of phishing sites: United States of America

Source: http://www.antiphishing.org

Phishing attacks can be really sophisticated. Some time ago a flaw in Internet Explorer allowed hackers to display a false address while redirecting the user to an entirely different site making it almost impossible to distinguish a phishing attack from a legitimate email.

Possible solutions:

New technologies can provide a better means of countering phishers. One option being explored by a lot of banks is the use of a secure token, a small electronic gadget that generates a unique password to be entered each time a user logs onto the web site. This would make a phishing attack useless because without the physical possession of a token it is impossible to access the account. This approach is somewhat similar to what is used at Automated Teller Machines around the world where you need to have both the card and the Pin number in order to use the machine.

One option is to use a technology popularly knows as PassMarks that effectively acts as a second password. After entering the user name a unique image pre selected by the user is displayed before s/he is asked for the password. If the proper image is not displayed the user will come to know that s/he is not on the authentic site. Another option that a lot of organizations are exploring is using text messages instead of email messages. Text messages cost money to send, so Spammers are less likely to partake in the process making it easier to distinguish between legitimate messages and fakes.

Ashish Jain
M6.Net Web Helpers
http://www.m6.net


MORE RESOURCES:

'Special Report' Panel on Obama's National Security Team; Mumbai ...
FOXNews - 14 hours ago
BRET BAIER, GUEST HOST: President-elect Obama today rolling out his national security team. Among them, Hillary Clinton as secretary of state, Robert Gates ...
Video: Obama Picks Gates, Clinton for Foreign Policy AssociatedPress
A National Security Team That Looks Like the Nation Washington Post
Obama stresses diplomacy with new national security team Los Angeles Times
Austin American-Statesman - NewsOK.com
all 3,860 news articles


USA Today

Energy, Security and the New Administration
New York Times, United States - 15 hours ago
“President-elect Barack Obama’s choice for national security adviser, retired Marine Gen. Jim Jones, is giving hope to energy companies that backed ...
Obama names national security team including Clinton, Gates Dallas Morning News
Obama Turns to Marine Jones to Harness Veteran Security Team Bloomberg
Obama Selects Gen. James Jones for National Security Adviser ABC News
Voice of America - CNN
all 657 news articles


Washington Post

Obama Names Team to Face A Complex Security Picture
Washington Post, United States - 19 hours ago
President-elect Barack Obama announces his national security team, including naming Sen. Hillary Rodham Clinton as secretary of state. ...
Obama announces Clinton, rest of national security team Newsday
Obama's national security team Scripps News
Obama taps Clinton, Gates for US 'new dawn' abroad The Associated Press
Straits Times - Washington Post
all 550 news articles


ABC News

Napolitano tasked with Homeland Security overhaul
USA Today - Dec 1, 2008
At Homeland Security, Napolitano, 51, will be responsible for securing the nation's borders, ports and airports against terrorists, responding to natural ...
Napolitano Poised for Top Homeland Security Post Government Technology
Obama chooses Ariz. gov. for Homeland Security FOXNews
Nominee Would Lead ID Program She Opposed New York Times
SC Magazine US - Reuters
all 1,051 news articles


Times Online

International hotels seek mix between hospitality, security
USA Today - 23 hours ago
Security experts say the standard safety measures in place at most upscale hotels in international business centers could not have entirely prevented last ...
International hotels draw elites and terror threat The Associated Press
NSG commandos relive anti-terrorist operations Hindu
Security and hospitality can't go together, says Oberoi Times of India
The Statesman - Economic Times
all 2,282 news articles


Atheists want God out of Ky. homeland security
The Associated Press - 10 hours ago
(AP) — A group of atheists filed a lawsuit Tuesday seeking to remove part of a state anti-terrorism law that requires Kentucky's Office of Homeland Security ...
Kentucky security law violates Constitution, says Reform leader Jewish Telegraphic Agency
Atheists sue to get God out of homeland security WVLT
God and Homeland Security Christian Web News
Columbus Ledger-Enquirer - The Seeker - Chicago Tribune Blog
all 95 news articles


BBC News

Who Can Stop the Pirates?
FOXNews - 8 hours ago
If they start shooting… now you have an international incident," said Michael Lee, assistant vice president at Miami-based "non-lethal" security company ...
UN Security Council Extends Anti-Piracy Measures off Somali Coast Voice of America
UN Security Council supports anti-piracy mission Deutsche Welle
Pirates don't like loud noises Salon
The Associated Press - BBC News
all 211 news articles


Infonetics Research: Network security market up 4%; strong drivers ...
MarketWatch - 10 hours ago
Infonetics' latest report, Network Security Appliances and Software, shows that all world regions -- North America, Asia Pacific, EMEA, ...


India siege raises security concerns at US hotels
International Herald Tribune, France - 7 hours ago
Their mission: To quickly shore up security with a show of force outside the Waldorf Astoria, New York Palace and other marquee hotels. ...


Security California Announces Preliminary Approval for ...
MarketWatch - 6 hours ago
the holding company for Security Bank of California, announced that it received preliminary approval to participate in the US Department of Treasury's ...

Security - Google News

home | site map
© 2006