IT Management articles: tips, advice, ideas, strategies & solutions

WOODRIDGE

IT Management Articles

Subscribe to our IT Management Articles Feeds


Feeds

What's this?

Home > IT Management

Beware of Phishing

by: Marvin Dreyer

Usually phishing starts with an email or an instant message, appearing to be from the genuine entity, asking you to furnish important details or to ‘verify' your account with the genuine entity to supposedly avoid a “disciplinary action” or on an “unforeseeable emergency.” The email will also have a link that points to a website copy of the genuine party's website.

On visiting this website, you will be amazed to find its thorough resemblance to the genuine entity's website; unsuspecting individuals may be fooled to believe that it is the original website. Unsuspecting users, thus, may provide the original user name and password in this website and make themselves victims of the phishing attack (and may still remain unsuspecting). Once given, the phishing entity has a direct door opened to your personal information and your identity. It can do anything with this information.

Online payment systems like PayPal, eBay, and online banking entities like Bank of America, Citibank are very common focus of the phishing attackers.

If you receive an email in your inbox, with subject line asking you to “confirm your email address,” “verify your login,” “log in to prevent disqualification,” etc., you should be wary. The spam detector of your email address may not catch these crooks all the time. If the genuine financial entity you depend on doesn't usually ask your password or ask you to confirm any personal information, then the email you received must be from fraudulent entity.

You should check the email address it comes from (not the header information alone, the exact email address). Latest phishing mails on PayPal actually come from an email address, support@paypal.com while the genuine PayPal email address may be different (like support@intl.paypal.com). So, you cannot rely even on the email addresses of the senders. However, so many attackers use public email addresses provided by Yahoo, GMail etc. The header may tell you something such as “Bank of America Online Banking System,” while the sender email address would be “bankspoof@yahoo.tk.” Smart people quickly see this anomaly.

Always make sure, when you log in to your financial institution website, that you open a new browser window, type in the address on the address bar, and log in. Never click on any links you get on your emails.

Spot Phishing

Most or all of the professional organizations do not ask for your private and personal information over an email. They won't ask you to “verify email” or “login to confirm” over an email anyway. So, any such mail you receive is phishing email and report it right away (see below to know how).

Look for promotional or intimidating diction in the emails you receive. If it tells you something like “We have no other means but to close down your account unless you verify now,” then remember it is most likely a phishing email.

Another type of phishing attack offers you large sums of money, telling you a short fiction about a bygone legacy (from which you get paid a percentage), asking your help to set records straight. On proceeding with the correspondence, you will be asked to submit bank account information, or even send small sums of money to enable successful funds transfer.

If the email contains image instead of text (to find out, try selecting the text on the email), then discern that it is an attempt to elude the spam filter of your email software.

Most of the phishing emails, owing to be from uneducated lot trying for quick bucks, may contain loads of grammatical and punctuation errors interspersed in awkward wording and spelling mistakes. Also, they would lack that quality and politeness of a polished professional email.

Another giveaway is the presence of attachments. Phishing emails may contain them while genuine entities never send attachments over emails. Make sure you don't open any of the attachments received. They can be such potential threats as adwares, malwares, keyloggers, etc.

If you don't find your name in the greeting in the mail, then it may be a phishing mail. Generic greetings like “Dear sir,” “Dear user,” “Dear subscriber,” etc., instead of “Dear Tom,” “Dear Sarah,” etc., clearly tells you that the sender knows not who you are. So, suspect such mails.

Check out the link provided. A link text of the URL of the genuine entity itself, like “Bank of America,” with underlying original hyperlink of the phishing website, may evade your eyes. So, always check which address it actually links to. Don't open the hyperlink unless you are sure. Deceptive URLs can take many forms. Some URLs will be subdomains with the subdomain name that of the genuine organization. Like “Paypal Spoof” Be wary of these addresses.

Fight Phishing

Legally fighting phishing is very easy for you. A way to report phishing attack is through US-CERT, the United States Computer Emergency Readiness Team. Report phishing to US-CERT through their email address, phishing-report (at) us-cert.gov. Report phishing with the Antiphishing Organization email, reportphishing (at) antiphishing.org. Spams may be forwarded to spam (at) uce.gov (Federal Trade Commission, FTC email address). Also, alert the Internet Crime Complaint Center of FBI (ic3.gov).

Most of the online entities have their own designated email addresses for you to report phishing. For instance, PayPal has spoof (at) paypal.com, eBay has spoof (at) ebay.com.

Conclusion

To be on the safe side, always make sure you have a current antivirus and firewall application in place. Do not give your personal information through any links you receive in emails. Email is not a safe medium of communication at all; do not communicate with anybody you don't know. Make sure you forward any spam or spoof you receive to the above-said entities. These simple steps will keep you secure in the cyberspace.
About the Author:
Marvin Dreyer is and entrepreneur, author. He has been involved in entrepreneurial activities for over 20 years. He founded Cheap Affordable Web Site Hosting for your web site hosting and check url to help web owners to check their site for viruses, check broken links and more online.
thumb it up
 

 

No. of Times this article has been viewed : 148
Date Published : Jun 30 2008

Most Recently Published IT Management Articles as of

Feb 9 2010    Tips on How to Migrate to a MPLS Network Architecture For Your Business

by Michael Lemm

The positives to your network reliability, performance, and cost make Multi-Protocol Label Switching seem to be a no brainer. But...you're not sure how to migrate from your existing traditional WAN (Wide Area Network) configuration to MPLS.

Feb 9 2010    Tips on a Router Solution For Any Size Business

by Michael Lemm

Your priority for designing a new or upgraded high bandwidth network is of course to deliver reliable internet connectivity .... but with a cost effective solution. Naturally the router configuration chosen is an important piece of the puzzle.

Jan 22 2010    How to Protect Against Denial-of-Service Attacks

by BMA Editorial Team B .

There are many critical steps to keeping your network and applications safe, but how do you protect against denial of service attacks? If an outside party is flooding your email with spam, you won't be able to receive new messages.

Jan 22 2010    What All Is Involved In Getting A T1 Line??

by Michael Lemm

You need a T1 line to meet the bandwidth requirements of your computer network. How do you get one?

Jan 22 2010    Bandwidth Requirements For Video Conferencing

by Michael Lemm

Most of today's companies are maximizing their travel budgets and communication requirements by making smart use of videoconferencing as an alternative to face-to-face meetings.

Jan 22 2010    What Is A MPLS Network?

by Michael Lemm

Nice breakdown and explanation of MPLS networks. What it is and what it can do for you.

Jan 20 2010    Elements of a Good List Building Formula

by BMA Editorial Team B .

If you want to be successful in your online business, it is important that you have a good list building formula. Having a formula for list building can be profitable as you can create an optimal opt-in list of subscribers and customers to whom you can offer and sell your products or services.

Jan 20 2010    IT Vulnerability Threat Concerns

by BMA Editorial Team B .

There are a variety of IT vulnerability threat concerns that businesses are forced to contend with, but by understanding what these risks are and forming a preventative plan of action to mitigate the damage, you can put your company in good stead to fend off and recover from an attack.

Jan 20 2010    Disaster Recovery Best Practices

by BMA Editorial Team B .

Implementing disaster recovery best practices in your business may seem like a time-consuming project, but it's an essential step to protect your resources and reputation in the event of a system failure.

Jan 20 2010    High Paying AdSense Keyword - A Strong Way To Increase AdSense Revenue`

by BMA Editorial Team B .

The AdWords prices are not, what the publishers get from the AdSense clicks, but they give a strong idea about the income chances from different keywords. So if an AdWords ad is expensive, it must also be a high paying AdSense keyword, i.e. it gives a higher income per click...

Jan 20 2010    Five Ways to Get Visitors to Bookmark your Website

by BMA Editorial Team B .

There are many factors to keeping someone's interest on your web page or site. It is not an easy task. Your ultimate goal is to get them to come back repeatedly. There is one precious commodity that most of us do not have much of - time.

Jan 20 2010    Getting The Best Identity Theft Protection

by BMA Editorial Team B .

Identity theft is a crime that occurs when one person steals another person's personal identification information and uses it fraudulently to obtain a service or credit account of some time.

Jan 19 2010    Discussing the Methods Used to Increase Page Rank

by BMA Editorial Team B .

When you are trying to rank a site, there are several levels to go through. First, when you have some content, you need to get the thing indexed and build up some initial links using social book marking and RSS submissions.

Jan 19 2010    Outsourcing Your Information Security Team Needs

by BMA Editorial Team B .

Outsourcing your information security team needs may not be something you've considered, but it can be a smart business move.

Jan 19 2010    5 Smart Ways to Make the Most of Your Call Accounting Software

by BMA Editorial Team B .

If you are looking for a savvy way to improve your business efficiency with a low input, learn 5 call accounting tips to increase your enterprise VoIP network ROI.

12345678910...
Search for ebooks on Management & Business