[+] Wayc0de's Blog[+]

Tampilkan postingan dengan label Email. Tampilkan semua postingan
Tampilkan postingan dengan label Email. Tampilkan semua postingan

11/10/11

Lulzsec hacker: 'we still have Sun emails, stored in China

Sabu, the erstwhile leader of the hacking crew, says he is effectively on the run as he gives interview to Reddit readers about LulzSec's achievements, Facebook, sentencing and more


The LulzSec hacking group has said it is to disband
 
 
The LulzSec hacking group hit a number of sites in a spree in May and July 2011; now its leader Sabu has given an interview on Reddit. Photograph: Reuters
The hacker who styles himself "Sabu", erstwhile leader of the LulzSec hacking crew, claims to have a cache of emails copied from the Sun which are being stored on a Chinese server, along with data from a number of other hacks.

But he claimed this weekend that they will not be released yet: "there are a lot of interesting dumps we're sitting on due to timing," he wrote on his Twitter feed. He claims that hackers have broken into banks including HSBC and "a few others" but that they have found "no smoking guns yet" in the data there.

Sabu – who says his online handle is a tribute to the American professional wrestler – says that after the arrests in the UK and US of a number of people alleged to have been involved with the crew, he is effectively on the run. But his writing also suggests he is staying put where he lives.

"I'm past the point of no return. Not trying to sound like a bad ass, however, it's the truth," he wrote. Later he added: "The ironic twist will be that my own friends will take me down, and not these idiots who hide behind the patriot veil." He also says that "technically, I'm on the run, so there you go."

LulzSec was an offshoot of the Anonymous hacking collective which during a hacking spree in May and July 2011 broke into a number of sites, including Sony Pictures Europe, Fox.com, PBS and finally the News International site.

At the latter it altered the Sun's web page so that it redirected viewers first to a faked story about Rupert Murdoch's death, and then to their Twitter feed. The group also attacked the US Congress's web site, an FBI affiliate and brought down the web site for the UK's Serious Organised Crime Agency by using a "distributed denial of service" attack.

Sabu effectively acted as the leader of the group, maintaining discipline over what they did, as leaked chatroom logs published in June by the Guardian show.
At that time he told members of the crew not to give interviews – but says his willingness to do so now is because "that was during the height of LulzSec. We all agreed to do no interviews till the end if there was ever one."

LulzSec's achievements, he says, were that it "exposed the sad state of security across the media, social, government online environments".

After the Sun hack, Sabu claimed on his Twitter feed that he was looking at 4GB of emails from the company. The claim was never confirmed, although remote access to News International's systems had been compromised.

Sabu's revelations came in a long and sometimes detailed "Ask Me Anything" (AMA) thread on Reddit. Sabu responds to a number of questions and appears to reveal a number of details about himself, such as that he is married, studied social sciences and English, that his technical hacking skills are self-taught, and that he teaches "sometimes". He claims to speak three languages – English, Spanish and German – fluently, and to have "decent" Portuguese and Italian. He says he turned towards computer hacking in 2000, when the US government "ignored the peoples' please to stop bombing Vieques" – a part of Puerto Rico used by the US navy as a bombing range until 2003. He says he likes working on cars, playing music and spending time with his family: "I'm loving life a lot this year. I barely have time for ops [hacker operations] like I used to."

That confirms other details that have been collected by rival hackers about Sabu which suggest that he is of Puerto Rican extraction, aged about 30 and based in New York.

He insists that he had no knowledge of the identities of any of the other members of LulzSec. "I simply don't know anyone's identity at Anonymous." He says that when one alleged member was arrested in the Shetland Islands, north of Scotland, he had to go and look up its location: "I was a bit impressed, even." He vehemently denies the suggestions by some that he "snitched" on other LulzSec members to the authorities.

The breakup of LulzSec meant he has "lost too many friends. [I] will probably never talk to them ever again." But he thinks that it "has already achieved what it set out to achieve".

He suggests that one of the LulzSec members, called Avunit, who quit the group when it took aim at the FBI, "is relaxing somewhere on a boat".

Asked whether he is "safe", he replies: "no one can prove it's me anyway. The beauty of Anonymous." The closest that the authorities have come to him is when in September they arrested a hacker alleged to have gone by the online handle "Recursion", who was tracked down via logs held by the British company HideMyAss, which unwittingly provided a virtual private network (VPN) connection for the attack on Sony Pictures Europe.

That arrest was "probably the closest they ever got", Sabu says. He also makes a veiled threat against HideMyAss: he alleges it "turns out to be owned by some … people who are going around buying smaller VPN providers ... We should have a nice exposé for HMA and its mother computer/investors soon. Point is: research your VPN provider thoroughly."

He says he takes a number of precautions to evade law enforcement, using prepaid phones and BlackBerrys for calls and Twitter: "they're expendable. I don't ignore you, I simply don't know you." He trusts Twitter – to some extent: "believe it or not, Twitter has not been sleeping in bed with LEAs [law enforcement agencies]. In fact it's a process [for LEAs] to get account info."

He rails at the sentencing guidelines in place for computer activity: "The penalties for any cybercrime (with the exception of child pornography) is severely archaic. And enforced by non-computer users. A DDOS (distributed denial of service) should not [attract a sentence of] 10 years at all especially when rapists and murderers do LESS than time." (The Guardian's James Ball made a similar point earlier this year.)

He thinks a hacking attack against Facebook "is pointless unless some very courages [sic] individual go and burn down its datacenter containing DBs [databases]". But he calls Facebook "a serious global cancer … they have half a billion people's psychology and family down in a database".

LulzSec does not have a Google Plus account, he says: "We do NOT have a g+ account. So whoever is running it is more than likely posing and has no affiliation to us." (Other Reddit users said that files distributed from that account contain malware.) Google Plus was launched well after LulzSec apparently broke up.
His advice to would-be emulators: "Stick to yourselves. If you are in a crew – keep your opsec up 24/7. Friends will try to take you down if they have to."

Anonymous, he says, is "no leaders, no hierarchy, no cointelpro [counter-intelligence program] drama. And we are a living, moving mass of like-minded individuals." He says it is "pure democracy", though that can be anarchic. But he thinks it will spawn "many organisations and political parties". But he says that "you don't need to be 'anonymous' or need to hack to be Anonymous. It's an idea, not a job."

He says he hopes to give a talk at the next HOPE (Hackers on Planet Earth) conference in New York, expected to run in July 2012.
Read More...

08/10/11

Email fraud came close to wrecking my life – and the charity I run

On the last day of our summer holiday in my Dorset cottage, my son shouted down the stairs "Mum, you've been hacked".

That sunny day, 25 August, saw the beginning of the most gruelling, frustrating and miserable period of my recent life. It lasted nearly four weeks, when I felt totally isolated from all my contacts across the world, and work virtually stopped as I had no access to my Google Gmail account.

The phones, landlines and mobile, never stopped ringing as an endless list of people – friends, colleagues, civil servants (surely they should have recognised the money-seeking message as fraudulent?), people I had not spoken to for years – called to ask if I was in Spain, whether I had been robbed, or if it was a scam. Moreover, various elderly friends and relations (I am in my 80th year so it is not surprising that many on my list are as old or older) unwittingly fell for the trick, followed the instructions and sent off the requested money.

I lost all the contacts in my computer address book. It meant I almost had to close the charity I direct, Widows for Peace through Democracy, because I had missed so many deadlines and our work was badly compromised.

I am simply one of the many thousands of victims of the "mugged in Spain" scam. For Spain, substitute "Athens", "Cyprus", "Kuala Lumpur" or whatever destination the fraudsters care to use. Most of us, surely, can immediately recognise the message that urgently pleads for a loan of around £2,000 because I have been "attacked on my way back to my hotel …" as fraudulent.

But many people did not. As far as I know some £5,000 has been sent, as if to me, as a "loan to be repaid with interest". And during the month I was unable to use my Gmail account, I learned of at least six other cases where people had received similar emails as if from people they knew, and sent off large sums.

Yes, it is easy for us to express amazement that anyone could send off money without first doing a little bit of detective work – such as telephoning one's children to ask whether we really are abroad, or taking other advice. But the fact is, that in a contact list of maybe over 3,000 names, if just a handful of people fall for the scam, the fraudsters have won.

Google has no human helpline you can contact, unlike the paid-for providers, such as AOL and Virgin, and I feel its website is sadistically ambiguous in the instructions it gives on what to do if you cannot access your emails. But, eventually, we got back by changing the password to one very esoteric and surely uncrackable, and were able to message everyone on the contact list about what had happened.

For a whole week I worked hard to re-establish the work of our charity – the only NGO in the world that represents the needs of widows and wives of the missing in mainly conflict-afflicted countries. I was desperately concerned that I had let down my partner associations in Iraq, India, Afghanistan, Nepal, Sri Lanka, Congo, Nigeria, Southern Sudan (to name just a few on our network) since, due to the hack, I failed to meet UN deadlines to report specific human rights violations. I missed putting in project proposals and grant applications to various UN and other fund sources, and let down so many people vainly trying to contact me.

WPD operates from my home; has no core funding; no paid staff and all our work is done on the internet, using our Gmail address which is printed on all our publicity material and our website.

However, once reinstated in Gmail, I pulled myself together, buoyed up by the marvellously sympathetic Eddie Mair of Radio 4's PM programme, who gave me a slot to describe what these scams can do to one's work, and to one's life. And then … Boom, Crash, it happened again, this time back in my west London house.

On 29 September I got a call from Fiona Hodgson, on my advisory committee, who was preparing to chair the forthcoming Conservative Conference. "I am so sorry, Margaret. I know what you've been through in the last month but you have been hacked again."

I have to admit I nearly collapsed, since the horrors of the past month were so vivid and I knew I could not face a repetition of that saga. I would have to close down WPD and cease all work on the issue of widows' rights that I feel so passionate about and which is so neglected by the UN, the international community, and our UK International Development Department.

In Dorset, I had called the local police, but they admitted there were no resources to deal with these frauds since the priorities for a much-strapped police force are "burglary, violence and Asbo". When it happened again in London, we called the Met and they were rather more on the ball.

Their advice was to close down my Gmail account completely; transfer all the contact addresses to a private account I have with AOL, and to take a hard copy of the contacts so I would not be caught out should anything happen in the future. They also explained that my new password was easily decipherable once the fraudsters had my email address, for they have some device that browses every combination of letters and numbers until they get the magic mix. They advised: "Don't use any of the free internet providers like Google, Hotmail or Yahoo. None of these have help lines. Only use providers you pay for."

Although I have put the Met in touch with Dorset Police, and sent them all the evidence I have collected from other people's experiences of this hack, I fear nothing can be done. The police agree. They say the public must become more vigilant and aware of these frauds. This scam is on a vast global scale but neither Western Union, which is designated as the channel for these money transactions, nor Google itself, is prepared to bear any responsibility or help track down these criminals. Besides, the UK police are powerless to act since the fraudsters mostly operate from overseas.

There is much discussion in the media on cyber-crime, but it is mostly directed at gangs that hack into bank accounts, credit cards and big company or government computer systems. No one seems to pay any attention to the hacking of individuals' identity through their email accounts.

What is to be done? I feel wretched about the kind people who truly believed I was in dire need and sent money to these criminals; but I can hardly afford to repay them as I, too, am a pensioner trying to run my NGO with practically no financial support.

As hacking individual accounts is one of the most lucrative of all cyber-crimes, I hope that greater resources will be invested to raise awareness of this type of fraud among the public, especially the elderly. Given that this crime has no borders, information sharing between law enforcement officials internationally is vital. And I very much hope that the government will accommodate this type of fraud within its cyber-security strategy, to be presented shortly to parliament.
Read More...

27/09/11

‘Right-to-Left Override’ Aids Email Attacks

Computer crooks and spammers are abusing a little-known encoding method that makes it easy to disguise malicious executable files (.exe) as relatively harmless documents, such as text or Microsoft Word files.

The “right to left override” (RLO) character is a special character within unicode, an encoding system that allows computers to exchange information regardless of the language used. Unicode covers all the characters for all writing systems of the world, modern and ancient.

It also includes technical symbols, punctuations, and many other characters used in writing text. For example, a blank space between two letters, numbers or symbols is expressed in unicode as “U+0020″.

The RLO character (U+202e in unicode) is designed to support languages that are written right to left, such as Arabic and Hebrew. The problem is that this override character also can be used to make a malicious file look innocuous.

This threat is not new, and has been known for some time. But an increasing number of email based attacks are taking advantage of the RLO character to trick users who have been trained to be wary of clicking on random .exe files, according to Internet security firm Commtouch.

Take the following file, for example, which is encoded with the RLO character:
“CORP_INVOICE_08.14.2011_Pr.phylexe.doc”
Looks like a Microsoft Word document, right? This was the lure used in a recent attack that downloaded Bredolab malware. The malicious file, CORP_INVOICE_08.14.2011_Pr.phyldoc.exe, was made to display as CORP_INVOICE_08.14.2011_Pr.phylexe.doc by placing the unicode command for right to left override just before the “d” in “doc”.


I wanted to see this work on my Windows 7 system, but found that I had to enable a registry tweak to allow the insertion of unicode into file names. After a reboot, I was able to rename any executable by holding the ALT key, then pressing the “+” sign on the keypad and typing “202e” in front of the targeted area while renaming a file.

According to Commtouch, this technique is being used to conceal malicious files in an unusually aggressive series of spam blasts that have been ongoing since mid-August.

“The average outbreak during 2010 occurred every 10-14 days and consisted of 5-10 billion messages sent by botnets,” Commtouch co-founder Amir Lev said. “The outbreak distribution kept enough bots alive to manage [a] certain level of malicious activity.”

In contrast, Lev said, recent malware spam outbreaks have been far more frequent – sometimes three per day. The malware variants embedded in the spam include many password-stealing bots used in high-profile cyber heists, such as SpyEye and Zbot/ZeuS, in addition to Sasfis and fake antivirus. The lures used include UPS package notifications, credit card errors, inter-company invoices, and supposed notifications from NACHA, a not-for-profit group that develops operating rules for organizations that handle electronic payments, from payroll direct deposits to online bill pay services.

Some email applications and services that block executable files from being included in messages also block .exe programs that are obfuscated with this technique, albeit occasionally with interesting results. I copied the program that powers the Windows command prompt (cmd.exe) and successfully renamed it so that it appears as “evilexe.doc” in Windows. When I tried to attach the file to an outgoing Gmail message, Google sent me the usual warning that it doesn’t allow executable files, but the warning message itself was backwards:

“evil ‮”cod.exe is an executable file. For security reasons, Gmail does not allow you to send “this type of file.
Unfortunately, many mail applications don’t or can’t reliably scan archived and zipped documents, and according to Commtouch and others, the malicious files manipulated in this way are indeed being spammed out within zip archives.

This class of attack is a good reminder that there is no substitution for being careful with unbidden documents and attachments sent to you via email. If you receive a message with an attachment you weren’t expecting — even if it appears to come from someone you know — the safest option is to take a second and reply back to the person to verify the contents of the message and that they meant to send it.

I have not had an opportunity to test this on other operating systems or email clients (although my Mac happily displayed the cmd.exe file as evilexe.doc). I’d be interested in comments from readers who have broader experience with this approach in manipulating file types.

nb : krebsonsecurity
Read More...

Amstrad's retro E-m@iler, email privacy and data loss

Amstrad E-m@ilerThere have been two recent occasions on which my computing life has been influenced by Lord Sugar, the business mogul who founded Amstrad and the star of BBC One's reality TV show "The Apprentice".

The first was on a visit to the National Museum of Computing at Bletchley Park, where I got to use an old Amstrad computer. It was running a Tetris clone called Blox created - as was proudly proclaimed on the game screen - by an upstart programmer called "G Cluley".

The second was this weekend, when the device you see in the picture showed up in a charity shop. This is the Amstrad E-m@iler Plus, a sort of executive phone/internet thing released by Amstrad in 2002.
Being a fan of old computers, especially oddball ones like the E-m@iler, I bought it.

The key feature of this phone was that it also had email and web capabilities, albeit delivered via a premium rate number that lined Lord Sugar's pockets with every email check. Users could configure the phone to automatically fetch their mail to be read on the attached LCD screen.

And, indeed, someone had used this E-mailer for e-mail. Someone I shall call "Colin" had set up two accounts on the device. How do I know this? Because Colin hadn't deleted these accounts before taking his phone to the charity shop.
As I said, the E-m@iler relies on a dial-up service which was discontinued earlier this year by its ultimate owners, BSkyB. That means that I couldn't, should I want to, fetch Colin's new email messages.

But there were messages already stored on the phone that I could have read.

Email messages on Amstrad E-m@iler

More surprisingly, the configuration screens let me see passwords assigned to Colin's accounts: has he used the same passwords on any other services?
Hopefully you're aware of the need to ensure there's no sensitive information stored on old computers before you dispose of them, particularly if you're going to sell them on to other users. My new (or should I say Colin's old) E-m@iler shows that this goes for any device that stores or accesses your data, including phones both smart and retro.
Lord Sugar
I can just imagine the scene in Lord Sugar's office:
"Colin, you made a basic error. By failing to delete your accounts before giving away your phone, you put your e-mail messages and your passwords at risk. You compromised the privacy of your own and your company's data, and for that reason, you're fired."



nb : nakedsecurity.sophos
Read More...

23/09/11

'Lurid' malware hits Russia, CIS countries

Trend Micro says more than 1,400 computers in 61 countries were targeted

The latest espionage-related hacking campaign detailed by security vendor Trend Micro is most notable for the country it does not implicate: China.

Researchers from Trend wrote on Thursday that they discovered a series of hacking attacks targeting space-related government agencies, diplomatic missions, research institutions and companies located mostly in Russia but also Vietnam and Commonwealth of Independent States countries. In total, the attacks targeted 1,465 computers in 61 countries.

[ Also on InfoWorld: Security failures could erode public trust in the Internet.| Learn how to greatly reduce the threat of malicious attacks with InfoWorld's Insider Threat Deep Dive PDF special report. ]

The attacks, which Trend dubbed "Lurid," are not particularly unusual compared to other stealthy, long-range hacking campaigns publicized recently, said Rik Ferguson, director of security research and communication for Europe. Targeted e-mails were sent to employees that were engineered to attack unpatched software and sought to steal spreadsheets, Word documents and other information.

Those pilfered documents were then uploaded to Web sites hosted on command-and-control servers in the U.S and the U.K. Ferguson said. The location of the servers in these attacks shows that hackers can choose servers anywhere in the world to collect stolen information, which is not an indication of where the hackers may be located, he said.

China has endured frequent accusations that it is complicit in hacking since many high-profile attacks have originated from infrastructure within the country. But Ferguson said there are many tools ranging from VPNs (Virtual Private Networks) to e-mail spoofing techniques that can mislead hacking investigations.
"What do we do now?" Ferguson asked. "Point the finger at the U.S. and U.K.?"
Trend classified the Lurid attacks as an "advanced persistent threat" or APT, a relatively new term applied to hacking campaigns that endure for long periods of time undetected. Lurid has been active since at least August 2010.

Lurid uses a downloader program known as "Enfal" to steal documents. The downloader has been around since at least 2006, although it is not known to be sold on underground criminal forums, Ferguson said.

The e-mails sent to victims contained an attached file that looked for vulnerabilities in software on the computer. This particular series of attacks often exploited a vulnerability in Adobe Reader that dates back to 2009, Ferguson said. If the companies or organizations have not patched their software, they may be vulnerable: Security experts generally recommend patching as soon as a fix has been released.

Trend found that the hackers also assigned a special code to individual pieces of malware in order to identity their victims. Although the Lurid attacks touched on many organizations, most of the attacks were targeted at just three.

Ferguson said Trend identified 301 different campaign codes, with 115 campaigns focused on just one victim and 64 others hitting just two more organizations.

The information exfiltrated from compromised computers was sent encrypted to the command-and-control servers via HTTP POST requests. Since the stolen information was encrypted and appeared to be normal Web traffic, it can be difficult for organizations to detect that they may have been compromised, he said.

Ferguson said Trend had contacted Computer Emergency Response Teams in the affected countries and is also working with the U.K.'s Serious Organised Crime Agency, which includes hacking as part of its remit.

nb : infoworld Read More...

21/09/11

Spamvertised 'We are going to sue you' emails lead to malware

Summary: Security researchers from WebSense have intercepted a currently active and circulating malicious spam campaign.


Security researchers from WebSense have intercepted a currently active and circulating malicious spam campaign.

The spamvertised emails contain subjects and messages attempting to socially engineer users into thinking that spam is coming from their mailboxes, and that they face legal action:
In this campaign, emails are spoofed to appear as though they are sent from established companies. The emails even formally claims that legal action will be taken because of the spam you have sent. These emails with the fake warning even attach a ZIP file that contains a scanned copy of a document that is supposed evidence of your spam.
-Spamvertised subjects include:
  • We will be impelled to sue you
  • We are going to sue you
  • We are suing you
  • You are sending add messages
  • A message from our security service
- Spamvertised body of the message:
Hello. Your email is sending spam messages. If you don’t stop sending spam, we will be impelled to sue you! We’ve attached a scanned copy of the document assembled by our security service to this letter. Please care carefully read through the document and stop sending spam messages. This is the final warning.
-Detection rate for the spamvertised malware.

Users are advised not to interact with suspicious emails, or spam emails in general.

nb : zdnet Read More...

Malicious spam campaigns proliferating

Summary: In a recent blog post, researchers from Commtouch have summarized their observation status, and pointed out that someone is actively building crimeware-friendly botnets.


With spam continuing to represent the distribution vector of choice for the majority of cybercriminals, it shouldn’t be surprising that the volume of malicious spam campaigns is proliferating.

In a recent blog post, researchers from Commtouch have summarized their observation status on the malicious spam campaigns from last month, namely, UPS/FedEx, Map of love and Hotel charge error and pointed out that someone is actively building crimeware-friendly botnets:
“Pre-outbreak levels varied between a few hundred million emails to around 2 billion per day.  The peak outbreak included distribution of nearly 25 billion emails with attached malware in one day.”
Malware campaigns have cyclical pattern of distribution, namely, cybercriminals constantly rotate and introduce new topics, once the lifecycle of the previous campaign have reached the maturity stage. Meanwhile, users continue interacting with spam emails, clicking on links, downloading attachments and unsubscribing themselves, prompting the success of spam in general.

Now, that the cybercriminals have set up the foundations for their botnet aggregation practices by spamvertising billions of emails, it’s worth keeping an eye on the actual response rate of the command and control servers used in the campaigns in order to roughly estimate the damage caused by the campaigns.

nb : zdnet
Read More...

16/09/11

Bot army being assembled, awaiting orders

Waves of malicious email attachments have been sent out since August and millions of machines could be compromised, security firm warns

A mammoth army of infected computers is being assembled, but it's unclear yet what purpose they will be put to.

Wave after wave of malicious email attachments has been sent out since August, and with average success rates for such mailings, millions of machines could be compromised, says Internet security firm Commtouch.

[ Experts say the surge in attachment spam is a sign of desperation. | Also on InfoWorld: Nations with low malware rates have better ISPs. | Learn how to greatly reduce the threat of malicious attacks with InfoWorld's Insider Threat Deep Dive PDF special report. ]

BACKGROUND: Brace for email-attachment malware spree

Once infected, the computers can be loaded with additional malware that can perform a range of activities, including spamming, participating in DDoS attacks, stealing bank credentials and compromising email and social-network accounts, according to an upcoming Commtouch blog post.

But what this botnet will do remains a mystery. "The purpose of this vast computing force is still not clear," the blog says.

Since a record peak of 25 billion malicious attachments to emails being sent on a single day in mid-August, email-attached malware has peaked five times since, each spike smaller than the one before, says Commtouch. The company predicted this pattern in August just after the highest peak.

Each peak represents a surge in a particular scam used to dupe victims into opening the attack attachments. The first wave consisted mainly of phony notices from UPS or FedEx that a package has been misrouted. The second, called the Map of Love, is a PDF that purports to be a map of interesting destinations worldwide. The third is a false notice of an altered charge for a hotel room, the blog post says.

User forums indicate that the malware campaigns worked, with many users opening the attachments. While it doesn't have estimates of the number of machines compromised, Commtouch says that such campaigns have linear success, so the more attachments sent, the more opened.

If the purpose of the assembled botnet is to send spam, it hasn't had an impact on overall spam traffic, which has actually been trending a bit downward, Commtouch says.

nb : infoworld Read More...

15/09/11

Protect Yourself From Phishing

Most of us are familiar with the word Phishing.For those who are new to this term Phishing,i am going to first explain to you the concept of word phishing.

PHISHING:

Phishing is a technique that is used by some malicious hackers to acquire some sensitive information like Passwords,Bank Id’s and some very important login details of various accounts. This word sounds like the word “Fishing” and is quite similar to the technique of fishing,as in fishing the fisherman hooks a bait pretending to be a real food so that he can fool the fishes in the pond and as soon as the fish comes for the bait it gets hooked and gets caught.Same is the case with phishing that is used over internet by the users to trap people through fake login pages that are designed by them or are available on net.The attackers creates a fake or duplicate page of a genuine website like any social site or any bank account page,and then he will set the trap by sending a mail to the prey(user) and waits for the user to fall in that trap and as soon as the user enters his/her details they are caught i.e the login details are send to the attacker and he know has the access of their sensitive information,it may be an account of social networking site or any bank account details.

Phishing technique is basically done through Email spoofing(means sending anonymous mail) and also through instant messaging.Phishing requires social engineering skills i.e how you can pretend to be a genuine person to the user whom you want to attack.This technique has caused a lot of problem for users who are easily trapped in these types of Phishing attacks,it has caused real big damages to the user’s.

After all the problems that were caused by the Phishing attacks,came the concept of Anti-Phishing i.e how you can protect yourself from getting caught in these types of attacks.These are some simple techniques that you can easily remember and save yourself from getting attacked by the malicious users.

ANTI-PHISHING TECHNIQUES:

1.Social Awareness:

One of the important technique is to create social awareness among the people about these types of phishing techniques so that the users browsing the internet can know about these types of attacks that are being carried by some users and thus they will become more cautious while browsing.This is quite necessary because most of the users do not even know about these types of attacks and thus they can easily fell into the traps set by the malicious users.

2.Technical awareness:

Technical awareness includes the ability to identify between the fake website pages from the legit websites.If you are smart enough than you can easily differentiate between a legit and a fake website.The user can easily pick up the fake website page from the url itself,as most the urls that are used for phishing are different from the original url of a website,if you can recognize the legit page url ,than you will be easily able to differentiate between fake and legit pages.

But these days attackers have developed some new techniques through which they make the url so much complicated that it’s quite difficult to differentiate between the fake an legit site,but nowadays many browsers like internet explorer has developed a new technique in which the domain name is highlighted with black color and all other details with light brown color so that the user will be easily able to look into the domain name of the page and identify the page.

3. E-mail authentication:

This is quite an important technique if you want to save yourself from phishing.Most of the phishing technique rely on email systems i.e  the attacker will send you an email pretending to be a genuine company or a site administrator which will contain a link that will redirect you to a page that would look legit to you.Now how will you come to know that whether the email is secure or it’s fake.Some companies or websites have some special notations or signs that are not available to phishers and thus if you feel any difference in the email language then do not trust the email.There is always a contact information given in the email you can use it to authenticate the email,whether it’s legit or not.

Now most of you might be thinking that the fake Email’s are automatically send into the spam folder in your mail system,but this is not true.Today the users have developed so many new techniques that email the best email system will not be able to differentiate between the spam and regular email.So do not get fooled by this thing that fake email’s are send to the Spam folder. I am telling this you from my own personal experience and it’s 100% true.

If you follow these techniques then there is no chance of you falling in such traps.Do tell me about your views on this topic.

nb : techbugs Read More...