Home Page Add Favorite
 
Login To Site
Username :  
Password :  
   
   
Register
Forgot my password?
Pakistan Software Library » Security » What is phishing?
Main Menu
Home Page Site Stats
Add News Register
Last Comments New Articles
RSS 2.0 Contact Us
 
Support
Advanced Search
All the latest news
Category
Script Gen:0.00538s.
Site Info
Site Statistics
Top Author:
  1    admin 176
  2    Horlock 24
  3    autodilleryga 5


Membership:
  Total : 16   ( +0 )
  This month : 16
  This hour : 0
  Banned : 1


Articles:
  Total : 205  ( +5 )
  This Month : 205
  This hour : 0
  Awaiting validation : 5


Comments:
  Total : 0  ( +0 )
  This month : 0
  This hour : 0

Poll
Tracker

eXTReMe Tracker

Arshive
July 2010 (200)
Change Skin
 
 
 

Security : What is phishing?
 

What is phishing?

Phishing is a type of Internet fraud that seeks to acquire a user’s credentials by deception. It includes theft of passwords, credit card numbers, bank account details and other confidential information.

Phishing messages usually take the form of fake notifications from banks, providers, e-pay systems and other organizations. The notification will try to encourage a recipient, for one reason or another, to urgently enter/update their personal data. Such excuses usually relate to loss of data, system breakdown, etc.

Phishing attacks are becoming more advanced in their exploitation of social engineering techniques. In most cases, fraudsters try to frighten a recipient by providing a seemingly important reason that the recipient should divulge their personal data. Such messages usually contain threats to block an account if a recipient does not fulfill the requirements therein. For instance, “if you do not provide your personal data by the end of the week, your account will be blocked”. Ironically, it is not unknown for phishers to make reference to the necessity of improving anti-phishing systems as one of the reasons for the disclosure of confidential information. A typical ruse might be “if you want to secure yourself against phishing, click the link and enter your user name and password”.




Pic. 1. A sample of a phishing message, purportedly from the National Credit Union Administration,
containing a request to click the link and update the user’s data.


The average lifetime of a phishing site is 5 days. Anti-phishing filters receive information about a new threat very quickly and so phishers constantly have to register new sites that imitate the official sites of various different credible organizations.

In order to access a fake site the user has to enter their credentials. This information is exactly what the phishers are after. Once they get access to a user’s email box or bank account, the phishers then face the problem of removing cash from that victim’s account without leaving a trail, and that is not an easy thing to do. If a person involved in this illegal business gets caught by law enforcement authorities, they will surely be prosecuted. This is why phishers sell the stolen data to other fraudsters who already have proven schemes for the withdrawal of money from bank accounts in place.

Banks, e-pay systems and e-auctions are major targets for phishers. This indicates that fraudsters are most interested in personal data which provides access to money. The theft of email credentials is also popular however, because this information can be sold to those who distribute viruses or create zombie networks.

The ‘quality’ of phishing messages is usually very high. A fake site will generally look exactly like the original so that a user will not suspect anything is wrong when they enter their user name and password to access the site.

Another phishing trick is to use links that look similar to the URLs of credible sites. This trick is designed to ensnare less experienced users. A careful user will notice that a link in the browser command line is in fact different from that of the legitimate site. These links may begin with an IP address, though big companies do not commonly use links such as these any more.

As such, phishing URLs often closely resemble the genuine URL of a legitimate company. They may include the name of the original URL with some additional words (for example www.login-examplebank.com instead of www.examplebank.com). Another trick is to use dots instead of slashes (for example www.examplebank.com.personal.login or www.examplebank.com-personal.login instead of www.examplebank.com/personal/login).


Pic.2 A sample of a phishing message (imitation of an EBay notification)
containing several links with one of them leading to a phishing site.

The body of a message seemingly contains a link to a legitimate site, but the URL may be different. A user’s vigilance may be dimmed by a few additional links to the official site, but the main link, which requires the user to enter their name and password, leads to the fake site.

Sometimes a user is required to enter their confidential data on the same page as the message itself. Everyone should be alert to the fact that no legitimate bank or other similar organization would ever ask a user to do this.


Pic.3. A phishing message imitating a notification from Barclays Bank
asking the user to enter their login credentials on the same page as the message.

Phishers are constantly improving their technologies and this has resulted in the appearance of a new trend – ‘Pharming’. This type of Internet fraud also targets access credentials such as user names and passwords, but unlike phishers who use email to achieve their goals, pharmers obtain identities via official websites. They redirect users to bogus websites by changing legitimate digital website addresses on DNS servers to fake ones. Pharming is an even more serious threat because it is next to impossible for the user to spot the fact that they are being scammed.

The most popular phishing targets are Ebay and PayPal. Other targets include banks all over the world. Phishing attacks can be random or targeted. Random attacks are aimed at the most popular sites such as Ebay because there is a strong possibility that a recipient will have an account there. In the second case, fraudsters determine beforehand that the user has an account with a certain bank, e-pay system, provider etc. This method is more complicated and costly for the phishers, but the corresponding likelihood that a victim will be hooked is also higher.


Pic.4 A sample of a phishing message imitating a notification from the popular PayPal e-pay system.

Identity information theft is not the only threat presented by a phishing link. It may lead to spyware, a keylogger or a Trojan program. So even if a user does not have an account which can be targeted by fraudsters, they are never completely safe.

According to Gartner, in 2006, the average US phishing victim lost $1244, whilst in 2005 the figure did not exceed $257. These figures prove the phishers’ incredible success. However in Russia the situation is different. Systems that use e-pay are not as popular as they are in the West, thus the damage caused by phishing is not so great. When e-pay systems become more widespread in Russia the share of phishing emails compared to the total volume of email traffic will increase and this will result in correspondingly higher levels of fraud. This problem is not significant in Russia at present, but it is necessary to start preparing for it today.

The success of phishing is largely determined by the low levels of user-awareness regarding how the companies which fraudsters try to imitate, operate. Many legitimate sites contain special warnings saying that they never ask users to send confidential data in messages. However, users continue to send their passwords to phishers. That is why a few years ago an Anti-Phishing Working Group (APWG) was established which included both the companies that the phishers target, and anti-phishing/antispam software vendors. APWG holds information sessions to try to inform users about the problem. In addition APWG members inform each other about new phishing sites and threats. Currently APWG includes 2500 members. Big international banks and leading IT companies are among them. According to optimistic forecasts, in the near future, users will learn to be as wary of phishing sites as they have become of messages with attachments from unknown senders. Meanwhile spam filters remain the first line of defense against phishing.





 
 
 
 
   
 
 (Votes #: 0)
Comments (0)  Print Version
 
 
Add comments
   
 

 
 
Calendar    
«    July 2010    »
MoTuWeThFrSaSu
 
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
 
   Tag Cloud  
Aero, Author, Beta, Boot, Build, Change, Client, collections, Converter, Disable, Disk, Easy, Fighter, File, files, Free, from, Make, Manage, McAfee, Messenger, Mode, Online, other, Patch, Portable, Speed, Step, SuperDAT, System, Taskbar, Time, Unwanted, Update, Video, virus, Vista, Windows, with, your

Show all tags
   Last News  
» Unique wallpapers from Europe. Part 273
» Unique wallpapers from Europe. Part 272
» Unique wallpapers from Europe. Part 274
» Unique wallpapers from Europe. Part 270
» Unique wallpapers from Europe. Part 268
» Yahoo! Messenger 10 offline installer
» Download Yahoo Messenger 9 Full Setup
» Portable RightNote 1.7.5
» DVD slideshow GUI 0.9.3.8
» Mobile Atlas Creator (formerly TrekBuddy Atlas Creator) 1.8 Alpha 15 / 1.7
» Mission X 1.2
» La Tale Online Client 5.1
» Cross Fire Client 1049
» Priston Tale 2 Client 2.0.0
» SGIs Video Converter GUI v0.3.6
» Full Video Converter 6.0.5.18
» Total Video Converter 3.61
» DISK BOOT FAILURE, INSERT SYSTEM DISK AND PRESS ENTER
» Mozilla Firefox Portable 3.6
» Install Windows XP Step By Step
   Top News  
» Migrate XP to Windows 7 with Easy Transfer and a USB Drive
» Shin Megami Tensei: Imagine Patch 1.283U to 1.284U
» Talking Clipboard 2.9.0.0
» Advanced ETL Processor 3.1.0.8
» Trojan-Dropper.Win32.Agent.albv
» Children and the Internet
» 2005
» Who creates malware and why?
» 2004
» What if my computer is infected?
» DISK BOOT FAILURE, INSERT SYSTEM DISK AND PRESS ENTER
» Unique wallpapers from Europe. Part 213
» Backdoor.Win32.Clampi.a
» 1998
» 1988
» Unique wallpapers from Europe. Part 211
» Recognizing internal threats
» 2003
» 1993,1994
» 1989
   Random News  
» Mount and Blade: Warband 1.127
» Trojan-Dropper.Win32.Agent.albv
» TravianManager Bot 3.1.5
» Disable System Restore in Windows 7
» SunlitGreen PhotoEdit Portable 1.3.0 Build 421
» Access Frequently Used Items in Windows 7 with Jump Lists
» Unique wallpapers from Europe. Part 250
» 1998
» Unique wallpapers from Europe. Part 239
» TRIM Utility Script
» Customize Logon Screen Background
» Unique wallpapers from Europe. Part 270
» Full Video Converter 6.0.5.18
» Unique wallpapers from Europe. Part 213
» Children and the Internet
» Remove Fake Antivirus 1.67
» UltraSurf 9.97 Latest Version Portable
» 2004
» Mission X 1.2
» Types of spam