Index arrow Internet Business arrow Security

“Phishing” for Suckers: Two Things You Should Look For In An email PDF Print E-mail
Written by John Young   
Copyright 2006 John Young

“For Your Immediate Attention! Don’t Lose Your Account! Update Immediately!”

Bob opened the email and was confronted by the logo of one of his major credit card companies. He had been carrying the card for some time, and had used it for a lot of online purchases.

Understandably he was concerned with the message under the logo: “Due to online identity theft, we need to verify that the information in your account is accurate, or we will be required by the FTC to suspend it”.

Below was an itemized list of the information he was required to verify: his old account number, name, address, telephone number, social security number, and mother’s maiden name. The also wanted him to change the password to his account.

Panicked, Bob hit the reply button and started filling in the information. He didn’t want to lose that account. He had set up several online accounts using that credit card number, and used it to buy and sell in online auctions…

THE “PHISHERMEN” AND THEIR HOOKS

“Phishing” is a technique used by identity thieves to stampede people into giving out their credit information online. The scam has been around for awhile, and, unlike Bob, most people are aware that they should never:

• Be intimidated by a message found in an “authentic looking” email

• Reply by giving vital information to the “phishers”

• Open up any links contained within the email, which can download “criminalware” onto their computer.

We all know these facts intellectually, but when confronted by an intimidating message, many of us react emotionally, not rationally. Maybe I’m more easily intimidated than most, but I’ve found myself opening an email and feeling compelled to fill out the information the message demands.

I have to confess an incident that occurred when I almost did that very thing. In my own defense, however, I have to say that it happened before I’d ever heard the term “phishing”. Fortunately I became suspicious before hitting the “Send” button.

But I almost did it. I almost sent it off and thereby hanged myself.

THE LAKE IS GETTING CROWDED

Although the public is becoming savvier to this scam, the “phishermen” must be experiencing success because the Anti-Phishing Working Group, http://www.antiphishing.org/ reports that phishing incidents are on the upswing.

They list 28,571 consumer reported incidents in June 2006, almost double the reported numbers in June 2005.

More suckers are being “phished” than ever before, and as every honest fisherman knows, there is no bag limit on suckers.

HOW TO IDENTIFY LEGITIMATE EMAILS

Of course, the best thing to do when asked for vital information by someone purporting to be a legitimate credit card company or other institution is to call the company on the telephone and ask if the email in question does indeed come from them. Then, if it has, go to that site to change your information.

But there are a couple of “quickie” things you can look for in the email itself, which you should do if you are alarmed by the message and tempted to jump.

1. Check the “From” Address to see if the address is correct. It should come from a top level domain, i.e. ebay.com, not a sub domain such as ebay.security.com. A sub level domain can be obtained on line for free, and is not something a legitimate company would do.

2. Make Sure the “digital signature” is valid.

KNOW YOUR DIGITAL SIGNATURE

I don’t know if you’re like me, but my eyes glaze over when somebody mentions the words “digital signature”.

Basically, it’s just an electronic means of verifying that the email you received:

• Has originated from the source it claims to come from

• Hasn’t been intercepted and repackaged on the way.

An email that is “digitally signed” has a little red icon down in the lower left hand corner in the ‘To…From” box.

Click on that icon and you can find information about the sender. Be sure your email client is “S/MIME” compliant. “S/MIME” compliancy is supported by over 350 million email clients, including Microsoft Outlook, Lotus, Novel, Netscape and MacMail.

As noted on the antiphishing site, this is unspoofable for two reasons:

• It is strongly encrypted.

• It is generated when you open the email, not at the source

The email client has validated four things on receiving this email:

1. The email address in the “From” field matches the one in the digital certificate.

2. The certificate was issued by a trusted authority.

3. The message wasn’t tampered with in transit.

4. The certificate itself has not expired.

To put it simply, the certificate makes sure the email has indeed come from who it says it has come from, and hasn’t been tampered along the way.

To see what the certificate looks like, check out:

http://www.antiphishing.org/smim-dig-sig.htm

THREE WAYS TO PROTECT YOURSELF.

There are three good ways you can protect yourself from “phishermen.”

1. Call the company they supposedly represent. Don’t respond to alarming statements demanding personal information online.

2. Don’t open any links in the email. They can download “criminal ware” that can start gathering vital information off your computer.

3. Don’t open suspicious emails unless you have an “S/MIME” compliant email client and can view and open that digital icon.

LOOKING FOR SUCKERS

The phishermen are out there and still looking for suckers. Based on the rise in reported incidents they are still finding them. Armed with a little knowledge and a healthy awareness, you won’t end up in their “game bag”.

You definitely don’t want that…because the next stop is the frying pan.

John Young is a writer with a scientific and programming background. At the age of 62, he lives in California with his wife and pet cat “Bear”. His new book “Protect Yourself Against Identity Theft” can be found at: http://www.youridentitystolen.com
 


62.jpg

73.jpg

154.jpg

177.jpg

Index arrow Internet Business arrow Security

Results 11 - 20 of 176


Avoiding A New Identity-Theft Scam Author : Stacey Moore
Consumers should be on the lookout for a new type of scam that uses Internet phone services. The scam, known as "vishing," involves criminals using Internet phone services (called VoIP) to trick consumers into revealing information about their bank accounts and credit card numbers over the phone. Here's how it works: A criminal calls you at home or sends an e-mail that asks you to call a local number. In either case, the criminal pretends...

Security is the Number One Issue Online. Author : Terry Ward
It should be a legal requirement for your ISP to protect every surfer, provide spam filtering that actually works and a defence against phishing that is more than a warning letter reminding you that emails asking for passwords should be deleted, but its not. If you surf it is your responsibility to protect your online security. Especially if your connection is a wireless one. You have no more important tasks before attaching yourself to the...

Are ActiveX Controls Safe? Author : A Singh
At the outset of understanding the link between ActiveX Controls and Registry cleaner, let us try to understand what ActiveX actually is and how it is meant to help in the running of the computer. Contrary to the belief of many computer amateurs, ActiveX is not a programming language but sets of rules that guide the way applications run on windows. Notice, we said ‘applications’ not ‘programs’. This is because all programs that run on Windows ope...

Internet Scams | Work At Home Scams Author : ttcinc
It makes no difference if you are thinking about starting a business, shopping or just looking for a new job online, you can protect yourself from some of the cleverest scams online if you just follow the simple steps below. (1) You can always find out information on a company or person by doing a quick search online. Go to Goggle or Yahoo and type in the company or person name and then type in the word scam after. Follow all leads. If no lea...

The Ins and Outs of IPS - Intrusion Prevention System Author : Ariel R
When it comes to protecting your network from attacks a good IPS (intruder prevention system) is needed. Be warned that many intrusion detection systems will try to pass them selves off as an IPS, even when they do not offer all the services of the IPS. Intrusion Detection Systems were the precursors to today’s IPS’s. Often old intrusion detection systems are exploited by attackers because they rely on out of date network technology. IPS is b...

“Phishing” for Suckers: Two Things You Should Look For In An email Author : John Young
Copyright 2006 John Young “For Your Immediate Attention! Don’t Lose Your Account! Update Immediately!” Bob opened the email and was confronted by the logo of one of his major credit card companies. He had been carrying the card for some time, and had used it for a lot of online purchases. Understandably he was concerned with the message under the logo: “Due to online identity theft, we need to verify that the information in your accou...

Spyware- Are you safe online? Author : Dave Jones
Arguably one of the greatest inventions the world has ever known. The internet has opened up the business world; it allows people to communicate across vast distances, cheaper and easier than ever before. There is a world of information at your finger tips. More and more people are getting connected and taking advantage of the great wealth afforded by the net. There are however some fairly serious down sides, identity theft is one of the fastest ...

Computer Viruses, Worms And Trojans Explained Author : Internet Security Squad
Fighting viruses and getting rid of them is big business right now. The first step is knowing just what the enemy is. THE ENEMY - Hackers and Crackers Computer geeks say that there is a difference between hackers and crackers. Crackers do damage to systems they break into while hackers just want to see how everything works. We'll use the more common term of hacker. Originally the term hacker was someone who made furniture with the use of ...

‘Why SSL & 6 In 1?’ Author : 101domainames.com
Why an SSL certificate and 6 in 1? The 6 is six domain names SSL with 1 certificate, like .com, .net, .org, .info and .biz. And ‘Saves’ money! All six in one. The SSL certificate encrypts the information and is a digital certificate that confirms genuineness or truth that the identity of a Web site and what information is sent to the server uses Secure Sockets Layer (SSL) technology. This secure process encrypts by scrambling data into an...

E-mail Tracking -The Truth Is Revealed. Author : Bruno Ligutti
Have you ever wondered whether your boss, coworkers or family read your e-mails? Well, now you can track your sent e-mails. In fact, there are many approaches to e-mail tracking. We all know the "read-receipt" system, in which you send an e-mail requesting a read confirmation. When the recipient reads your e-mail, he or she is asked by the software, "Would you like to confirm you received this e-mail?" Then the recipient may choose "No", and w...

  
Top
 
 
 
© 2008 mmakers.org
Joomla! is Free Software released under the GNU/GPL License.