Index arrow Internet Business arrow Security

Phishing and Pharming: Dangerous Scams PDF Print E-mail
Written by Alexandra Gamanenko   
As soon as almost all computer users already got used to -- or at least heard about -- the word "phishing", another somewhat confusing word appeared. Pharming. Does it differ from phishing -- if yes, how?

Two Pharmings

Actually, two completely different fields use the term "pharming" now. We can say there exist two separate "pharmings".

If genetics or businessmen from pharmaceutical industry are talking about pharming (spelled like that) it might have nothing to do with computers. This word has long been familiar to genetic engineers. For them, it's a merger of "farming" and "pharmaceutical" and means the genetic engineering technique -- inserting extraneous genes into host animals or plants in order to make them produce some pharmaceutical product. Although it is very interesting matter, this article isn't about it.

As for PC users, the term "pharming" recently emerged to denote exploitation of a vulnerability in the DNS server software caused by malicious code. This code allows the cybercriminal who contaminated this PC with it to redirect traffic from one IP-address to the one he specified. In other words, a user who types in a URL goes to another web site, not the one he wanted to--and isn't supposed to notice the difference.

Usually such a website is disguised to look like a legitimate one -- of a bank or a credit card company. Sites of this kind are used solely to steal users' confidential information such as passwords, PIN numbers, SSNs and account numbers.

Dangerous Scams

A fake website that's what "traditional" phishing has in common with pharming. This scam can fool even an experienced computer user, and it makes pharming a grave threat. The danger here is that users don't click an email link to get to a counterfeit website.

Most people enter their personal information, unaware of possible fraud. Why should they suspect anything if they type the URL themselves, not following any links in a suspiciously-looking email?

Unfortunately, "ordinary" phishers are also getting smarter. They eagerly learn; there is too much money involved to make criminals earnest students. At first phishing consisted only of a social engineering scam in which phishers spammed consumer e-mail accounts with letters ostensibly from banks. The more people got aware of the scam, the less spelling mistakes these messages contained, and the more fraudulent websites looked like legitimate ones.

Since about November 2004 there has been a lot of publications of a scheme which at first was seen as a new kind of phishing. This technique includes contaminating a PC with a Trojan horse program. The problem is that this Trojan contains a keylogger which lurks at the background until the user of the infected PC visits one of the specified websites. Then the keylogger comes to life to do what it was created for -- to steal information.

It seems that this technique is actually a separate scam aimed at stealing personal information and such attacks are on the rise. Security vendor Symantec warns about commercialisation of malware -- cybercriminals prefer cash to fun, so various kinds of information-stealing software are used more actively.

Spy Audit survey made by ISP Earthlink and Webroot Software also shows disturbing figures - 33.17% PCs contaminated with some program with information stealing capability.

However, more sophisticated identity theft attempts coexist with "old-fashioned" phishing scams. That is why users should not forget the advice which they all are likely to have learned by heart:

  • Never follow a link in an email, if it claims to be from a financial institution

  • Never open an attachment if the email is from somebody you don't know

  • Protect your PC from malware

  • Stay on the alert


  • Alexandra Gamanenko currently works at Raytown Corporation, LLC -- an independent software developing company that provides various solutions for information security. The company's R&D department created an innovative technology, which disables the very processes of information capturing -- keylogging, screenshoting, etc. It prevents keylogging programs or modules from stealing information. Learn more -- visit the company's website www.anti-keyloggers.com
 


128.jpg

129.jpg

18.jpg

140.jpg

Index arrow Internet Business arrow Security

Results 81 - 90 of 176


Identity Theft: Stop It Now! Author : Matthew C. Keegan
You may be a victim of identity theft and not even know it. Thieves may have secured important information about you and are using it without you knowing what they are doing. By the time you discover their nasty deeds, much damage may have already been done. While you may not be held responsible for their antics, the aggravation and recurring pain you will go through in restoring your good name can be intense. Let’s take a look at some ways you c...

Intrusion Prevention - IT Risk Management Author : Johnny Mayer
Intrusion Prevention solutions detect and eliminate content-based threats from email, viruses, worms, intrusions, etc. in real time without degrading network performance. They detect and eliminate the most damaging, content-based threats from email and Web traffic such as viruses, worms, intrusions, inappropriate Web content and more in real time - without degrading network performance. Today's global information infrastructure faces possible...

Application Security - IT Risk Management Author : Johnny Mayer
Application Security risk assessment and risk management are vital tasks for IT managers. Corporations face increased levels of Application Security risk from hackers and cyber crooks seeking intellectual property and customer information. A comprehensive application security risk assessment is a modern day corporate necessity. Application security risk management provides the optimal protection within the constraints of budget, law, ethics,...

Paypal Fraud, Paypal Email Scams and Avoiding Paypal Phishing Author : kaisilver
To access a Paypal account you need to have the username and password of the account. The username of a Paypal account is the main email address (primary email address) used to register the account. The owner of the account would also set up a password to be used along with the username to access the account. The security system is quite secure as long as the username and password of the Paypal account are known only to the actual owner of the ac...

CASE STUDY: How Website Monitoring Saved an Online Auto Parts Retailer Author : amabaie
PROBLEM: Customers complaining about site outages and slow site response times. Hosting company claiming that the problems had been resolved. Customers remaining dissatisfied. METHODOLOGY: External website monitoring on a page-by-page basis at one-minute intervals pinpointed the problems. SOLUTIONS: Realigning shared hosting, fixing database indexing, DNS server upgrade, altering the web host's BGP configuration and regular website...

Cyberspace Samurai's Art Of Hacking (via CobWeb/3.1 kupl1.ittc.ku.edu) Author : Mike Cliff
If you acknowledge the foe and recognize yourself, you need not fear the result of a hundred battles. If you recognise yourself merely not the foeman, for every victory gained you volition also suffer a defeat. If you cognize neither the opposition nor yourself, you testament succumb in every battle." - Sun Tzu, The Art of War. Take the immortal words of Sun Tzu, cognise yourself. Or here, experience your computer code. Do you live however your c...

Did I Hear You Say, Mama, Help Me! I Lost My Websites! (via CobWeb/3.1 kupl1.ittc.ku.edu) Author : Manny Jao II
This simple reminder is dedicated to all Webmasters (and Webslaves like me). Don't sleep tonight without reading this. Find out why below... Have you seen people cried out loud for help because they lost their websites? I have seen this many times in several forums and have personally experienced the same not long ago. I am a living testimony on this one. And so I cried out, "Mama help! I lost my websites!" But no one can help me....

Monitoring the International Web Author : amabaie
One of the top website monitoring services in the world has announced that it's industry-leading network and website monitoring services can now be accessed in French, Spanish and German, as well as in the original English. Why this sudden interest in other languages? "Many people in the English-speaking world think there is only one Internet – the English Internet," says Vadim Mazo, Chief Technology Officer for Dotcom-Monitor. "But there a...

Web Site and Network Stress Monitoring Author : amabaie
In today’s world, organizations are fast accepting the web and related applications as part of their overall business strategies. They understand that the Internet provides them with the potential to target a very focused set of customers spread across a very diverse geography. For a successful Internet presence, it is important that the web server and web applications are reliable, scalable and always available, irrespective of traffic volum...

Phishing and Pharming: Dangerous Scams Author : Alexandra Gamanenko
As soon as almost all computer users already got used to -- or at least heard about -- the word "phishing", another somewhat confusing word appeared. Pharming. Does it differ from phishing -- if yes, how? Two Pharmings Actually, two completely different fields use the term "pharming" now. We can say there exist two separate "pharmings". If genetics or businessmen from pharmaceutical industry are talking about pharming (spelled like tha...

  
Top
 
 
 
© 2008 mmakers.org
Joomla! is Free Software released under the GNU/GPL License.