Phishing : Examples And Its Prevention Methods

  1. What is phishing?

    The action of sending an e-mail to a user falsely claiming to be an established legitimate enterprise in an attempt to scam the user into surrendering private information that will be used for identity theft. The e-mail directs the user to visit a web site where they are asked to update personal information, such as passwords and credit card, social security, and bank account numbers, that the legitimate organization already has. The Web site, however, is bogus and set up only to steal the user’s information.

Example of phishing
For example, in year 2003 there is a proliferation of a phishing scam in which users received e-mails supposedly from eBay claiming that the user’s account was about to be suspended unless he clicked on the provided link and updated the credit card information that the genuine eBay already had. Because it is relatively simple to make a Web site look like a legitimate organizations site by mimicking the HTML code, the scam counted on people being tricked into thinking they were actually being contacted by eBay and were subsequently going to eBay’s site to update their account information. By spamming large groups of people, the “phisher” counted on the e-mail being read by a percentage of people who actually had listed credit card numbers with eBay legitimately.

Prevention method:

1.Regarding emails: DO NOT trust emails urgently requesting personal financial information !

2.Be sure not to call any number or use any link in the suspected email as this may put you in the hands of those responsible for the phishing attack.

3.Be suspicious of impersonal emails.

4.NEVER fill out forms in email messages that ask for personal financial information


5. Be suspicious of email links. Never trust it! There are ways to "spoof it" !

6. Always ensure that you're using a secure website when submitting credit card or other sensitive information via your Web browser

7. Regularly log into your online accounts

8. Ensure that your browser is up to date and security patches applied at http://www.microsoft.com/security/

9. Help stop phisching by reporting "phishing attacks" or “spoofed” e-mails to the following groups:


(i) Forward the email to reportphishing@antiphishing.com
(ii) Forward the email to the "abuse" email address at the company that is being spoofed (e.g. "spoof@ebay.com") when forwarding spoofed messages, always include the entire original email with its original header information intact.

The Threat of Online Security : How SAFE is our Data ?


Online security threats are one of the biggest challenges on the Internet. The problem is that every day there are new viruses and security threats that are launched all over the Internet, which means you need programs that can be updated continuously and don't just target one specific type of problem.

The best ways you can do if you get on the Internet at all is to use security software and hardware such as firewalls and authentication servers, as this is the most effective way to protect your computer and your personal information. It's best if you choose hardware and software that will update itself each time you are on the Internet, without you having to remember. It's also very important that you choose your passwords carefully, so that those that might want access to your information won't be able to guess as to what password you might use.

There are some of the main online security threats and the cautions of each :

1. Web servers and services ~ Default HTTP (Web) servers have had several vulnerabilities, and numerous patches have been issued over the past several years.
Cautions : Make sure all your patches are up to date, and do not use default configurations or default demonstration applications. These vulnerabilities may lead to denial-of-service attacks and other types of threats.


2. Windows authentication ~ Most Windows systems use passwords, but passwords can be easily guessed or stolen.
Cautions : Creating stronger, more difficult to guess passwords, not using default passwords, and following a recommended passwords policy will prevent password attacks.


3. Web browsers ~ Your window to the Internet, a Web browser contains many vulnerabilities. Common exploits may include disclosure of "cookies" with personal information, the execution of rogue code that could compromise a system, and exposure of locally-stored files.
Cautions : Configuring the browser's security settings for a setting higher than the default value will prevent most Web browser attacks.


4. Mail client ~ Attackers can use the mail client on a computer to spread worms or viruses, by including them as attachments in emails.
Cautions : Configuring the main servers appropriately, and blocking attachments such as .exe or .vbs files, will prevent most mail client attacks.


5. Instant messaging ~ Many corporations also block employees from using instant messaging, not only because of the technical threats but also because of the possibility of lost productivity.
Cautions : Configuring IM properly, applying all the latest patches, and taking control over any file transfers that occur over IM will prevent most attacks.

How to safeguard our personal and financial info?

How can we avoid "thefts" from the website? There are several ways to protect our personal and financial info, such as:

1) Password Protection
Strong passwords are hard for other members to guess with a combination of numbers and letters if possible. Do not write it down and carry in the wallet or briefcase.


2) Install and update antispyware and antivirus
The antivirus programs include Symantec, Norton Antivirus and AVG antivirus. This viruses may steal or modify the data on your own computer. Keep this programs up-to-date is necessary to have well protection.

3) Install a firewall
Most new computers come with firewall integrated into their operation systems in order to allow "good" people to access.



4) Regularly scan your computer for spyware
Spyware in the software programs may affect the performance of your computer and give attackers access to your data. Use a legitimate anti spyware to scan and remove any infected files.


5) Avoid access financial information in public
Cyber cafe, wireless access place are the venue that have to prevent from logging to check bank balance. Remember to close the browser window or log out before leaving as to prevent other users read the personal information.


6) Keep your credit cards carefully
Make sure waiter or waitress handle the card to you when shopping or eating out. Then take the card as well as the receipt and do not throw it away in a public place. Keep the card that you actually use only.

7) Avoid clicking on pop up advertisement and download information from unknown websites.



Wish all of us have a safe and secure journey when using internet!!!!