Wednesday, June 18, 2008

Phishing: Examples and its prevention methods

Phishing is a fraudulent attempt which acquires sensitive information such as credit card numbers, account usernames and passwords, social security numbers, etc. It is typically carried out by e-mail or instant messaging. The e-mail directs the user to enter details at a Web site where they are asked to update personal information, such as account usernames and passwords. Phishing can be called a synonym to actual fishing. Scammer throws in a bait by sending you an email, pretending to be a representative of the company he tries to get sensitive information. If you eat the bait, scammer has obtained your accounts username and password or credit card information, whatever you have sent him.

PayPal, eBay and online banks are common targets. Typically phishing emails point recipients to a bogus website which looks like the real PayPal or eBay site, but is designed to steal usernames and passwords. Once hackers have stolen login details they can use the information to commit crimes such as identity fraud, leaving victims with a financial burden.

PayPal scam e-mails normally involve a link on which the user must click. The link takes you to a server where you have to supply sensitive and private information including credit card numbers, your PayPal account number, pin numbers and passwords. The scam claims your account information needs to be updated because they found incompatible information during a billing information check. The real PayPal never sends such emails. eBay phishing scams have the same purpose and characteristics as
PayPal phishing scams.

Day after day, computer users are bombarded with an increasing number of phishing-based emails and attacks. However, there are ways to prevent them. User should be suspicious of any email with urgent request for financial, account, or email information. Phishers have been known to include upsetting or enticing (but false) statements in their e-mails to get people to reach immediately, a practice known as social engineering. The email typically asks for usernames and passwords, credit card numbers, social security numbers or other personal information.

Users should not click on any links that you're unsure of. Many times, phishers will include a link leading to a fake website, possibly with a similar name of the website that gives them full
access to your sensitive information. User should ensure that they are on a secure connection to a web server when submitting personal information across the Internet. A secure Web server designation can be found by checking the beginning of the Web address in your browser’s address bar. The address should begin “https://” rather than http://.
User should install antivirus and firewall software and ensure that the program is up to date using their Update features. An antivirus program is a program that prevents and removes viruses. A firewall is used to prevent unauthorized access from a remote computer system. Antivirus and firewall software are very important because there are millions of existing viruses and new ones created everyday.

No comments: