It will require the victim to login to their account, in addition to enter sensitive financial information such as their bank PIN number, credit card details, Social Security number and more. Normally, the email request the user to update their credit card information or else their account will be terminated. By other way, it will offer a service to protect their credit card from possible fraud. After that, the information that receives will sent to the attackers who then use it to create credit card and bank fraud.
The following are some example of phishing.
http://antivirus.about.com/od/emailscams/ss/phishing_2.htm

Figure 1(a) - Maybank 2U Portal
Figure 1 (b) Maybank 2U Login Page
Figure 2 (a)- Phishing Site
Figure 2(b)- Phising Site Login Page
http://www.ictsecurity.gov.my/readTxtFile.jsp?URLLINK=MaybankPhishing.pdf
The figure 1 is the real website of Maybank, while the figure 2 is the phishing website of Maybank. To differentiate these 2 website is to refer the address bar . (http:// is the correct URL prefix)
To prevent the phishing website and email. There are several prevention software or some tips when receiving the phishing website.
Phishing Detector v1.0 is a anti-phishing tool that detect phishings, email frauds and spoofed emails at the inbox with one click. It able to detect the phishing email that come from eBay, PayPal and others financial institute.
Tipping Point's Phishing Protection is using combination of vulnerability filters, signatures, and behaviour-based protection technique to detect and prevent phishing. TippingPoint anti-phishing filters block at every phase of phishing attack.
NETGATE Internet Security v2009 is a complete security protection software which can detect most of the serious Internet threat. It include spyware, viruses, torjans, phishing, spam and more. This protection will make the user more convenience since it consists all the features in one.
If receive an email or pop-up message that ask for personal or financial information, do not reply it and click on the link that provided. The legal financial institutes or website will not ask their customer to provide any confidential information via Internet. Normally, the Internet criminal will not type the receiver's name, this due to they will send the phishing email in bulk. Be careful when email with some attachment or downloading files, it might contain viruses or phishing.
It will easy to determine the phishing email and website. As a user, we need to always alert where there are suspicious of any email with urgent requests for personal financial data. They will make you to feel it is urgent and important. A phishing email is to trick you into providing the information. If you feel you might to reply on it, you better call for your financial institute to ensure the genuine of the website.
It also can prevent by using anti-virus and anti-phishing software. However, it will more effective with the software is update frequently. Beside that, we should not email our personal information to anyone or fill up form in email messaging. If have to do so, make sure the website is secure, look the security look and URL for a website that begins with "https", the "s" stand for secure. Furthermore, always review credit card and bank account statement to check any unauthorized charge. If anything that you do not recognize transaction, contact your bank immediately. Lastly, remember to report phishing email or phishing website to the respective organization.
In my opinion, we should always alert on the phishing website and email. We should not provide our personal information to any people via Internet. We must always aware the URL of the website, to ensure it is secure. If unfortunately that you have trick in phishing, you must report to http://www.antiphishing.org/ or visit to Government Security Web Portal(http://www.ictsecurity.gov.my/)
References:
http://www.cyberoam.com/phishing.html
http://en.wikipedia.org/wiki/Anti-phishing_software
http://www.antiphishing.org/consumer_recs.html
http://www.onguardonline.gov/topics/phishing.aspx
http://www.filebuzz.com/files/Phishing_Prevention/1.html
1 comments:
I think the user should always aware of this issue.It will bring a serious problem to the user once their personal information especially the financial information.The user need to paid for it although it is fraud transaction.The user can prevent phishing with the anti-software.
Post a Comment