Phishing refers to the act of tricking people into revealing sensitive or private information. It is an e-mail fraud method in which the phisher sends out legitimate-looking email in an attempt to gather personal and financial information from recipients. Basically, phishing come from those well-known and trustworthy website such as PayPal, eBay, Yahoo, MSN, BestBuy, and America Online so that recipients would not suspect the incoming sources. Phishing attacks generally target on bank information, username, social security numbers, and password information.



Let's have a look on some of the phishing example:

This is an example of a phishing scam targeting Washington Mutual Bank customers. This phish claims that Washington Mutual Bank is adopting new security measures which require confirming ATM card details. As with other phishing scams, the victim is directed to visit a fraudulent site and any information entered on that site is sent to the attacker.

This is a phishing mail from the Charter One bank. This phishing email also pretends to be working to preserve the safety and integrity of online banking. The email also includes the Charter One logo in an attempt to gain reliability and trusty from customers.

Here is another example of a phishing scam targeting SunTrust bank customers. The email warns that the account may be suspended if customers failed to comply with the instructions stated in the statement. The phishers uses the SunTrust logo again which they can simply copied from the real banking site.




PayPal and eBay were two of the earliest targets of phishing scams. This PayPal phishing scams tries to trick recipients by claiming that someone 'from a foreign IP address' attempted to login to your PayPal account, the mail urges recipients to confirm their account details through the link provided at the bottom of the ststement. Once the recipients click on the link provided, it will actually takes the recipient to another unrelated website.

This is another phishing email from eBay website. It urges the eBay member to login and verify the charges due to a billing error that have been conducted previously. In order to make it more reliable, attacker attaches the eBay logo with it.


How To PREVENT Phishing?


In this technology era, phishing can occurs in different manner at anytime and at anywhere. Although complete prevention is impossible, there are several ways to prevent form it.



1) NEVER EVER Click on the hyperlinks provided within the email

You should never ever click on the links that is provided if you are doubt of the email sources. You can do it in an alternative way by directly type in the URL in the Internet browser address bar or call the company on a verified contact number.



2) Always look for "https" and a padlock on a site that requests personal information

Information entered on an Internet Web Site can be intercepted by a third party. Thus, when submitting sensitive financial and personal information through Internet, look for the locked padlock on the Internet browser's status bar or the “https://” at the start of the URL in the address bar. Although there is no absolute guarantee of the site's security, by not doing so, the site is definitely unsecure.




3) Use Anti-phishing software

Phishing Blaster is an Anti-Phishing software that monitors the incoming emails and web pages that might be phishing. Phishing Blaster provides one-step access to the security features that keep your computer safe and blocks phishing scams as it is being updated regularly in order to be more effective. The advantage of this anti software is that it is able to recognize phishing emails pretending to come from eBay, PayPal, Amazon and hundreds of other financial institutions. It benefits consumer from being tricked.

4) Educate Yourself on Fraudulent Activity on the Internet

The best way to avoid from becoming a phishing scam victim is to use your best judgement. None of the financial institution with any sense will email and ask you to input all your sensitive and private information. In fact, most institutions are keep on reminding and informing customers that “We will NEVER ask you for your personal information through phone or email” as the information is private and confidential. So, be SMART whenever you received a phishing mail, definitely you will not be attacked.

Related Links:

http://en.wikipedia.org/wiki/Phishing

antivirus.about.com/.../ss/phishing_6.htm

http://www.fraudwatchinternational.com/phishing-fraud/phishing-protection/

Prepared by Chong Hui Qi'

Threat of online security..


Nowadays, people rely on computer to create, store an manage critical information. Consequently, it is important for users to aware that computer security plays a major role in protecting their data from loss, damage, and misuse. Similarly, online security has been online trader's main concern in protecting their websites from potential threats, such as phishing, security hacking, information theft, virus, worms and etc.

However, the increasingly developed technologies sarcastically increase the risk every computer user faced. Everyone who owns a computer with internet connection is able to equip themselves with 'hacking' knowledge by making some research online. Internet provides the opportunities for users to share the knowledge without filtering the content. Therefore, everyone can learn skill that may jeopardize online security via internet and therefore increase the online security risk.

Nowadays, computer users are facing the threats of cybercrime, phishing, internet and network attacks such as computer viruses, worms, Trojan horses and back doors.

Cybercrime is defined as online internet-based illegal acts. Hackers, crackers and corporate spies is part of cybercrime, who have advanced computer and network skills that access into computers and networks illegally with the intention to destroy data, stealing proprietary data and information.

Phishing is a scam in which a perpetrator send an official looking email that attempts to obtain your personal information and financial information. In other words, this method is to collect information through fake websites. For example, some phishing email messages ask you to reply with your information, or a pop up window that looks like a website, that collects the information. The damages caused by phishing can be crucial. The following case illustrate potential thereat caused by phishing.

For example, in 21 June 2007, a spear phishing incident at the Office of the Secretary of Defense (OSD) stole sensitive U.S. defense information, leading to significant changes in identity and message-source verification at OSD. This incident has cost administrative disruptions and personal inconveniences, as well as huge financial loss in making system recovery. More info..

Internet and network attack that jeopardize security include macro virus, worm, and Trojan horse.

Macro virus is a piece of code that is secretly introduced into a system in order to corrupt it or destroy data. Macro virus such as Melissa and ILOVEYOU were propagated through Microsoft outlook email and whose payloads were delivered as Visual Basic for Application (VBA) programs attached to email messages. Virus attack can damage the operating system, causing the loss of data and other possible losses.

A worm is a program that runs independently, copies itself repeatedly and consuming the resources of its host in order to maintain itself which it is capable of propagating a complete version of itself onto another machine. The repeatedly copied files use up the available space and slow down a computer operating speed.

On the other hand, a Trojan horse is a program that appears to have a useful function but that contains a hidden function that presents a security risk. Trojan may arrive in the form of file that looks like an interesting game or program. When this program is run, the Trojan program is installed and executed every time the attacked computer is turned on. This particular Trojan horse enabled the perpetrator to capture user Ids and passwords, to display, delete messages and upload files on the affected computer.

A back door is a set of instruction in a program that allow users to bypass security control when accessing a program, computer, or network. Once perpetrators gain access to unsecured computers, they often install a back door or modify an existing program to include a back door, enabling them to continue access the computers remotely without user's knowledge.

In conclusion, risk exposed by computer users is increasing with the developed technology. therefore, safeguards developer must be always up to date to enhance the defenses against online security threats. In the same time, users must be educated and informed about the crucial damages and loss caused by imposing online online security threats.

Prepared by Wong Kai Lei

Reviewed post: Identity theft-Cases on stolen laptops, hacking and lost CD



I read a post which is about the identity theft and i reliased that how a grave consequance will happen if we do not get awareness of this issue. As identity theft is a crime of stealing someone's personal, identifying information for the purpose of using that information fraudulently. Those personal and identifying information are including social security numbers, credit card and banking account numbers, usernames, passwords and patient records. While these information have been stolen which helped the criminal do the fraudulent activities such as opening new credit accounts, taking out loans in the victim's name, stealing money from financial accounts, or using available credit. There are a lot of cases are happened around us as the victims were be in a huge debt but without applying any loan.



Trickier Methods that would use by Identity Theft
Hereby i would like to share with you some of the trickier methods which identity theft usually use and we should get to know more about their tactics as we can alert of not being one of the victims.

1. Pretexting

A trickier method that thieves fabricate false pretenses under which to obtain your sensitive financial information from banks or other financial institutions. For example, they will impersonate as your relative and obtain your information from a phone company or bank.

2. Direct Theft



It is an straight line method for stealing information directly from you. They can directly get your credit card information, bank statements, and the like by stealing your mail, swiping your purse or pickpocketing your wallet.


3. Skimming

Skimming is where the theft use sophisticated storage device to connect with a card reader and then access that information for malicious use. While this is a very perilous trick as such a device can directly be installed on any legitimate card reader without recognition the card reader is compromised.

4. Redirecting your mail

It is where those companies send a change of address form and from this, theft will divert your mail to a separate address and gain access to your account statements and other information. As another word, they will directly steal from your mailbox.

5. Phishing

It is using fraudulente-mail messages that appear to come from legitimate businesses in order to gain the personal information. Those personal data such as account numbers and passwords, credit card numbers may be abused by theft.





Does Encryption is useful for protecting your personal information?
It can't deny that encrytion will help us to protect our personal data but for me, this is a subjective question. For my opinion, eventhough there are a lot of high technology of encrytion to secure the data. However there are still a lot of hackers successful broke in to get those high confidential data.
Some of the cases happened were due to the people carelessness. Some of the businessmen send their notebooks for maintenance service but they did not store those customers confidential information in a secure location where it will give a chance to competitors stole their information.

Nomatterhow, we still have to prevent those identity theft. Here are some ways which i would like to share with you:
  • Protect your Social security number
  • Treat your trash and mail carefully
  • Be on guard when using the Internet
  • Select intricate passwords
  • Verify sources before sharing information
  • Safeguard your purse and wallet
  • Store information in secure locations
At last, i want to share my personal experience with you. It is a real life case.


During the time when i get hurry to search a good university or college to further my study, i received a private call. The person that talking on the phone is a China girl who speak with China accent. She promoted me to study at China and kept persuaded me with a lot of reasons. I asked her how she can get my phone number and she told me that may be when my friends applied for the China University form and give them my number.
Come on!!! This is a one of the trick as they have gained access to the school and obtain those student data. Therefore, we should always alert of this kind of phone call or email to avoid be trapped into a snare.

Reviewed post from:
Prepared by Wong Chuan Chi

Internet is a public network that connecting millions of computers throughout the world. Through telephone wires ans satellite links, internet users can share information in a variety of forms. It si very convenient as we do not need to use other traditional method anymore, but Internet is not a safe place anymore because hackers have te ability to intercept and use some information sch as credit card numbers and expiry dates to falsely do transactions. Data is sent back and forth through various servers which personal information and financial data are being housed. We need to take some precautions to increase internet security and decrease date stolen probability.

How we want to avoid the ttheft from the website? There are some suggestions stated below:

Use password that are hardly to guess

To protect information on the Internet and networks, variety of encryption techniques are being used to keep data secure and private. Encryption is a process of converting readable data into unreadable characters to prevent unauthorized access. Avoid using passwords that are easy for someone to guess such as, birth date or own name. If it is possible, use a combination of numbers and alphabets. Do not ever write down the password and put it into briefcase or wallet.

Do not give personal information to unknown parties

Avoid giving your personal information to unknown parties online, via e-mail and over the phone. Personal Financial Information such as name, date of birth, telephone and identity card number should not be given through online although the mail comes from the bank or other important management that handled by behalf of the institution or its affiliates.

Regularly scan computer

Do regularly scan computers using legitimate anti-spyware program to scan your computer and remove any infected files because spyware can be hidden in software programs that may affect the performance of your computer and give attacker access into the data.

Biometric fingerprints

Use a high technology security or any powerful tools which are easier and convenient for you to protect data. As technology is advancing, many system or parts are now provided with fingerprint access. Biometric fingerprint can be used to prevent unauthorized physical and logical access to factory, warehouse, office, laboratory, ATM machines, notebook PCs and any other computer network. Benefits of using this method are it wont lose although it is being stolen n which the theft will not be able to access into the private data .

Avoid accessing financial information in public

Prevent logging to check any bank balance or other private data when using a wireless access that provided by outside coffee shop or public. Although these systems are convenient, but you do not know how sturdy their firewalls are.

Additional informations:
1) Six ways to safeguard your online assets

2) Keep your financial data safe online

prepared by Wong Kai Lei