Beware Phishing: Protect Your Passwords from Internet Fraud!
Phishing is Phucked: Internet Ph...Fraud for a New Ilk
Phishing? Come again? "Phishing?"
The last time I checked, the closest approximation to phishing I could have unearthed would have involved a hackey-sack, plenty of smoke, and endless jams that tested the patience of even the most diligent of Dave Matthews Band refugees. What could my IE have against phishing?
Perhaps I'd better check into this...
As it turns out, there is a little more to phishing for Internet users than I had imagined. Phishing, according to Wikipedia, is a criminal activity using social engineering techniques. More than your basic worm or virus, which usually rely on your willingness to click on a cryptic link from an unfamiliar email address, phishing actually masquerades as a trusted correspondence to gain your trust and fool you into providing protected information, like passwords or credit card numbers, to the phisherman.
Phishing is phucked, to be sure, and the likelihood that you could be a victim of phishing is gaining in likelihood. The best way you can protect yourself is to be aware.
Several weeks ago, I received an email from "PayPal" informing me that there had been a breach in the security of my account. Alarmed, I immediately logged into my PayPal account and could detect nothing amiss. Rather than respond to the email I had received, I chose to contact PayPal directly through the messaging service on the site (I have yet to hear back from them).
Upon beginning my research into phishing, I discovered an example of the technique via PayPal that looked remarkably similar to the email correspondence I received from "PayPal." Weeks have past, and there is still no discrepancy in my PayPal account. Not having previous knowledge about phishing, or the techniques used to commit phishing fraud, I am only grateful that I chose to respond directly to PayPal, and not to the sender of the email.
So, what should you watch out for to protect yourself from phishing? There is a list. According to Wikipedia, there are three common types of phishing: link manipulation, website forgery, and phone phishing.
Link manipulation is the most common form of phishing. It involves the creation of a spoof website- a website that mimics a known and trusted site- and them creating links to the spoofed site. Often, the spoofed websites will differ from the valid sites by subtle differences like small misspellings in the URLs, or by the use of subdomains. Although savvy Internet users may learn to spot evidence of phishing through link manipulation, for the more basic users like me, the best practice is to employ "universal precautions" when responding to unsolicited emails. Never respond to an unsolicited or confusing email from any organization responsible for any sort of financial dealings by replying to the email- message the organization in question directly from their website, describe the communication, and ask them to validate it.
Website forgery is particularly ominous form of phishing. This form of phishing scam uses JavaScript commands to alter the address bar, either by placing an image of the legitimate site's URL over the address bar, or by replacing the URL of the phishing site with that of the legitimate site, thereby masking the occurrence from the user.
Phone phishing is old school, simpler, and often leaves users as or more vulnerable to being phished than the higher tech methods. In phone phishing, users receive a message bank or other institution utilizing sensitive financial information of its members instructing them to call a customer service number regarding a problem with their account. When responding, users will be instructed to enter their account numbers and PINs in order to begin the process of resolving the problem.
While I acknowledge that I am not terribly tech savvy, I am suspicious by nature and generally think of myself as intelligent and open-minded to the insipid dealings of the far-too-bored-and-smart. My save on the "PayPal" email issue was due to this. However, ignorant of phishing techniques, it was only a matter of time before someone got me. I hope this simple article from a tech-deficient simpleton will help some of you.
Go phish? Not if I can help it!
Published by Suri Cruise
Yeah. Um... okay. View profile
- Just What is the Internet?A relatively short article detailing on the Internet works, how to connect to the Internet, and some of the more common uses of the Internet. Aimed at a non-technical audience.
- Book Review: Internet Scams...Exposed!Keep your personal information personal! Arm yourself with information that will protect you from identity thieves and Internet scammers.
Most Common Passwords & Ways to Fix ThemOnline identity theft is the modern break-in. Now, protect yourself by having an unhackable password. I provide a list of the most common passwords, as well as ways to secure...- EBay & Phishing: You Recognize It, Now What?EBay and Paypal seem to be operating under the belief that merely educating people about phishing attempts is their only responsibility whent he phishing bears their names. I've got a few mroe questions for them...
- New Anti-Phishing Technology InventedA new tool currently being designed will catch domains registered for phishing before they even go up.
- Beware of Fraud in Internet Cafes When Traveling
- Internet... BEWARE! (Part 1)
- What Services and Resources Can Be Found on the Internet?
- Why Mozilla Firefox is the Best Internet Browser Out Today
- How to Stay Out of Spyware Trouble on the Internet
- Children and the Internet: Do You Know What Your Child is Doing?
- Prudential California Realty Adding Internet "Zip"
- Wikipedia
- Link manipulation is a form of phishing that sends requests for sensitive information from websites that spoof other websites that you trust.
- Website forgery takes phishing to another technological level- actually masking phishing websites with trusted site information.
- Phone phishing lures the users to actually call into a phone site with their sensitive account and PIN numbers.





2 Comments
Post a CommentAnd you could have written this two weeks ago! LOL before my ebay account got hijacked.
I have been the victim of this on my Myspace account. I find that it is best to change my password once a week.