
Phishing is a new Internet crime, that is flourishing day by day. To define Phishing lets say
“Phishing is a way to steal personnel data of Internet users such as credit card information, account information etc by make a malicious web site masquerade as a trust worthy entity.
“
According to antiphishing.org Phishing crime rose by 43% march this year as compared to last year
Phishing use social engineering skill to fool users. Most commonly by referring to malicious web site which is made to look like the authentic site of a bank or other financial institution. Differentiating the site from the original site require keen observation. However Phishing is not only done through email or IM even the original site may be wormed to refer the user to malicious pages as happened with myspace.com
Its important to know what Phishing is and how a user can avoid being phished and what steps can IT Security managers can take to deal with phishers, consider that more than $2 billion is lost my businesses annually on insurance covers relating to Phishing. Now even some banks are not providing insurance to claims due to Phishing. Their logic is that customer made the choice to enter the information in to the fake web site.
This article will deal with
How to spot phishing web sites
What to do after you've been phished
How can people protect themselves from becoming a victim of a phishing scam ?
By taking simple precautionary measures we can protect ourselves from phishers, and save ourselves
from on line fraud
Don’t click links within emails that ask for personal, financial, or account information. Go to main page of the organization instead.
Banks usually do not ask for information on the Internet they got nothing to do with your pin code, if still in doubt talk to the customer service of the bank, and instead of using the phone number in the email its better to look the number up.
A message being generally addressed instead of being specifically address to you is a sure way to tell, you are being phished.
Confirm the URL in the address bar if it spells right and is not a number, like IP adress. Normally phishers change a letter to redirect to their pages; like gogle.com instead of google.com.
Using book marks would be safer as it would lead you to the exact site, instead of entering every time, as a typo can lead you to a phishers site.
When replying to emails with sensitive, check the message headers. The ‘From:’ address and the ‘Return-path’ should be same, if they are different then the email address is spoofed.
Look at the expanded headers of the emails to trace the path of email, phishing emails use dubious mail servers, and anonymizing services.
Login sites of banks and other institutions dealing with private sensitive information use secure sites so in the address bar at the beginning of the address it should be HTTP not HTTPS; for secure HTTP.
Secure sites use a certificate and a certificate signing authority indicated by the padlock icon in the bottom bar of the explorer window, confirm its presence; it shows the site is validated by a certificate.
Most of the phishers are able to get a spoofed certificate now a days too, so click the padlock icon and confirm the company name of the certificate matches with the URL.
Most modern browsers check the certificate for expiry dates and validity instead of clicking through the certificate warning, pay attention to hem.
Use a phishing filter add ons for the browsers.
Phishing sites are usually like poor imitations of the originals, with spelling mistakes incorrect graphics etc, so be on the look out for the anomalies in the design.
Resist greed, like free money offers; if some thing is too good to be true then it must not be true.
If your friends account is compromised then the mail could come from his email address, confirm him by phone before giving out personnel information.
What action can people take if they discover that their private information has been stolen
Prevention is better than cure so the best policy is to avoid being phished, however if a negligence is already done, following measures could be taken to minimize the damage
Report to the organization whose site the phiser replicated, block your account.
Change your password immediately .
If you are unable to login use the hint service and change password and hint and contact the organization directly.
Check the transaction history, may be you are able to get insurance cover for fraudulent transactions
Several sites banking sites and Gmail offer log in and activity history keep, check the history frequently.
Report scam to your local law enforcement agency.

柔情聊天室 -
ReplyDelete玩美女人影音秀 mv -
aio交友愛情公寓館 -
免費下載a片 -
小褲褲ㄉ誘惑 -
美乳淫娃網 -
365色情電影下載網 -
洪爺影城 -
情人視訊樂園視訊聊天交友 -
免費美國棒球線上直播 -
色美媚部落格2站 -
丁字褲美女 -
日本色情網站 -
超G名模影音視訊聊天室 -
3cc流行音樂網 -
閃亮天使520聊天室 -
電話交友 -
美女寫真圖片區 -
愛戀中華美眉-交友中心 -
台灣無限貼圖區 -
後宮電影城 -
免費情色小電影 -
LIVE173影音視訊live秀-一對一免費視訊 -
包月視訊美女 -
一葉情貼圖片區 -
視訊辣妹影片直播 -
免費av18禁 -
情影片線上免費看 -
鐘點情人影音聊天室 -
美媚寫真104 -
小杜倩色文學 -
美女視訊免費看 -
脫衣辣妹部落格 -
學生妹自拍照 -
偏愛熟女人妻館 -
免費視訊辣妹 -
校園美女影音視訊網 -
波波情色貼圖 -
免費情色影片 -
休閒小站自拍寫真 -