IT Management articles: tips, advice, ideas, strategies & solutions

Subscribe to our IT Management Articles Feeds


Feeds

What's this?

Home > IT Management

Beware of Phishing

thumb it up Marvin Dreyer
Usually phishing starts with an email or an instant message, appearing to be from the genuine entity, asking you to furnish important details or to ‘verify' your account with the genuine entity to supposedly avoid a “disciplinary action” or on an “unforeseeable emergency.” The email will also have a link that points to a website copy of the genuine party's website.

On visiting this website, you will be amazed to find its thorough resemblance to the genuine entity's website; unsuspecting individuals may be fooled to believe that it is the original website. Unsuspecting users, thus, may provide the original user name and password in this website and make themselves victims of the phishing attack (and may still remain unsuspecting). Once given, the phishing entity has a direct door opened to your personal information and your identity. It can do anything with this information.

Online payment systems like PayPal, eBay, and online banking entities like Bank of America, Citibank are very common focus of the phishing attackers.

If you receive an email in your inbox, with subject line asking you to “confirm your email address,” “verify your login,” “log in to prevent disqualification,” etc., you should be wary. The spam detector of your email address may not catch these crooks all the time. If the genuine financial entity you depend on doesn't usually ask your password or ask you to confirm any personal information, then the email you received must be from fraudulent entity.

You should check the email address it comes from (not the header information alone, the exact email address). Latest phishing mails on PayPal actually come from an email address, support@paypal.com while the genuine PayPal email address may be different (like support@intl.paypal.com). So, you cannot rely even on the email addresses of the senders. However, so many attackers use public email addresses provided by Yahoo, GMail etc. The header may tell you something such as “Bank of America Online Banking System,” while the sender email address would be “bankspoof@yahoo.tk.” Smart people quickly see this anomaly.

Always make sure, when you log in to your financial institution website, that you open a new browser window, type in the address on the address bar, and log in. Never click on any links you get on your emails.

Spot Phishing

Most or all of the professional organizations do not ask for your private and personal information over an email. They won't ask you to “verify email” or “login to confirm” over an email anyway. So, any such mail you receive is phishing email and report it right away (see below to know how).

Look for promotional or intimidating diction in the emails you receive. If it tells you something like “We have no other means but to close down your account unless you verify now,” then remember it is most likely a phishing email.

Another type of phishing attack offers you large sums of money, telling you a short fiction about a bygone legacy (from which you get paid a percentage), asking your help to set records straight. On proceeding with the correspondence, you will be asked to submit bank account information, or even send small sums of money to enable successful funds transfer.

If the email contains image instead of text (to find out, try selecting the text on the email), then discern that it is an attempt to elude the spam filter of your email software.

Most of the phishing emails, owing to be from uneducated lot trying for quick bucks, may contain loads of grammatical and punctuation errors interspersed in awkward wording and spelling mistakes. Also, they would lack that quality and politeness of a polished professional email.

Another giveaway is the presence of attachments. Phishing emails may contain them while genuine entities never send attachments over emails. Make sure you don't open any of the attachments received. They can be such potential threats as adwares, malwares, keyloggers, etc.

If you don't find your name in the greeting in the mail, then it may be a phishing mail. Generic greetings like “Dear sir,” “Dear user,” “Dear subscriber,” etc., instead of “Dear Tom,” “Dear Sarah,” etc., clearly tells you that the sender knows not who you are. So, suspect such mails.

Check out the link provided. A link text of the URL of the genuine entity itself, like “Bank of America,” with underlying original hyperlink of the phishing website, may evade your eyes. So, always check which address it actually links to. Don't open the hyperlink unless you are sure. Deceptive URLs can take many forms. Some URLs will be subdomains with the subdomain name that of the genuine organization. Like “Paypal Spoof” Be wary of these addresses.

Fight Phishing

Legally fighting phishing is very easy for you. A way to report phishing attack is through US-CERT, the United States Computer Emergency Readiness Team. Report phishing to US-CERT through their email address, phishing-report (at) us-cert.gov. Report phishing with the Antiphishing Organization email, reportphishing (at) antiphishing.org. Spams may be forwarded to spam (at) uce.gov (Federal Trade Commission, FTC email address). Also, alert the Internet Crime Complaint Center of FBI (ic3.gov).

Most of the online entities have their own designated email addresses for you to report phishing. For instance, PayPal has spoof (at) paypal.com, eBay has spoof (at) ebay.com.

Conclusion

To be on the safe side, always make sure you have a current antivirus and firewall application in place. Do not give your personal information through any links you receive in emails. Email is not a safe medium of communication at all; do not communicate with anybody you don't know. Make sure you forward any spam or spoof you receive to the above-said entities. These simple steps will keep you secure in the cyberspace.
About the Author:
Marvin Dreyer is and entrepreneur, author. He has been involved in entrepreneurial activities for over 20 years. He founded Cheap Affordable Web Site Hosting for your web site hosting and check url to help web owners to check their site for viruses, check broken links and more online.
 

 

No. of Times this article has been viewed : 117
Date Published : Jun 30 2008

Most Recently Published IT Management Articles as of

Nov 7 2009    Business VoIP Solution .... What Does It Really Mean?

by Michael Lemm

No matter which direction your business goes with a business VoIP solution .... the key is understanding how you communicate and what you want to achieve. Simply put, a business Voip solution is an alternative to a traditional switched-voice service.

Nov 6 2009    Web Application Advantages in Today's World

by karel zeman

Web application development services have introduced ways to make the use of applications easier and safer for the consumer. The many advantages of going online to use your applications as opposed to using desktop applications are increasing steadily.

Nov 4 2009    Relax, Here Comes the USB Floppy Drive for You

by Tiel Holdstock

Who says you cannot use a floppy drive if you have a computer without a built in floppy disk drive? An external floppy disk drive has been devised especially for those with a computer like this, where in you can connect this device to the USB port and then go ahead with what you want with it.

Oct 30 2009    How to Connect Your PC to Your TV

by Charles Taylor

There are many people who do not know that they can connect their PC to a TV. This may look remedial to a lot of people, but it is simple. There are many reasons to connect a PC to TV.

Oct 21 2009    The Real Facts About MPLS Networks (Multi-Protocol Label Switching)

by Michael Lemm

MPLS... or Multi-Protocol Label Switching has fast become the solution of choice for connecting multiple network locations for businesses today. In order to make sure you're designing the right network solution you need to at least understand the basics.

Oct 21 2009    What is Expected of a Green-Minded CIO?

by Michael Lemm

"Going Green" is the phrase Dejour in business today...and the IT world is not immune to this movement. With that in mind CIO of every business should set the tone for what and how "going green" is accomplished from an IT perspective. Here's a tongue in cheek guide on just how that might look.

Oct 21 2009    EWaste - How Are CIO's Protecting the Environment?

by Michael Lemm

Going green .... or protecting the environment .... has become even more of focus in companies today then ever before. It's just plain the smart and responsible way to do business. One major segment of the overall effort is reducing and/or controlling E-waste.

Oct 21 2009    Hosted PBX - Good Business Choice?

by Michael Lemm

A hosted PBX solution may not be right for every business application. But if you do your due diligence you may find it's a good business choice for you. One key is that when you talk about hosted PBX (VoIP) .... it can mean different things to different people.

Oct 21 2009    Primer For Businesses Evaluating DS3 Bandwidth Costs

by Michael Lemm

Before deciding on a bandwidth solution for your business there's basic fundamental questions you must be aware of. Not just what they are but also how the answers will impact your network application(s)... and most importantly the impact on potential cost of implementing that network.

Oct 21 2009    VoIP PBX Solutions For Businesses - What to Look For

by Michael Lemm

The emergence of VoIP technology.... and specifically application to PBX systems via IP based protocols... has provided an enormous opportunity for companies to reap many benefits.

Oct 21 2009    Smart Business - How to Manage Bandwidth Requirements For Multi-Media Applications

by Michael Lemm

Take control of your Internet and WAN resources to optimize the performance of your business-critical applications, VoIP and video traffic. Ensure sufficient bandwidth in your network for near term and expansion needs....

Oct 21 2009    Should You Use Ethernet For Your Voice & Data Network?

by Michael Lemm

It seems that whenever you talk about an upgrade or new installation of a company's voice/data network these days you hear the buzz word "ethernet" sometime in the conversation. With all the buzz... should you seriously consider ethernet in the mix for your network solution?

Oct 21 2009    Describing DS3 Bandwidth in "Non-Technical" Terms

by Michael Lemm

Hhere's a non-technical description of DS3 Bandwidth and the different types of DS3 lines a business needing a voice and/or data network solution could opt for:

Oct 19 2009    The Basic Concepts of Cloud Computing

by Charles Taylor

Cloud Computing means accessing the hosted services over the Internet. That means, we can access our documents or interact with our application or develop applications that are stored at the service provider from any place.

Oct 7 2009    Anti-Spam: The Solution to All Your Unsolicited Email Problems

by Jon Harmer

Spam is a universal problem that every email user hates, and without an effective anti-spam solution, it can wreak havoc on companies, costing them money, time, and resources.

123456789
Search for ebooks on Management & Business