| Home | Articles | Archive | Links |


- Misc
Phishing On The Pharm How Thieves...
The Latest On WordPress Themes
To Blog Or Not To Blog The Ups...
Trackback Spam Explained
Web 2 0 A Guide For Newbies
Ah The Joys Of Online Coupons
Web Marketing Its All About...
Why Online Coupons Are The Rage
Benefits Of Webmaster Toolkit...
What A htaccess File Is And How...
What You Should Know About Trackback...
What You Newbies Need To Know About...
The Exciting World Of Video Blogging...
com Not Listed In Regional Yahoo...
Cybersmear And The Job Seeking...
1stepsystem A One Step Internet...
3 Ideas That Made Internet...
3 Key Ingredients For Your Profit...
3 Legitimate Reasons For Getting An...
3 Must Read Books For Bloggers
3 Tips For Building Traffic To Your...
4 Common Mistakes New Affiliate...
4 Things Web Analytics Can Teach You...
4 Tips To Increase Your Blog...
4 Ways To Get Traffic To Your...
- SEO
Taguchi Method The Key In Ad...
1 Million In Google Adsense...
3 Steps To Getting Listed...
4 Key Ways To Keep Visitors Coming...
4 Steps To Law Firm Website Search...
4 Tips For Raising Your Search...
4 Tips To Build A Content Site With...
- Earning Money
Learning How To Bike The Right Way
Internet Business Myths The True...
2 Surefire Ways To Maximize Your...
3 Reasons Why Blogging Will Boost...
3 Simple Tips For Making Money...
- Hosting
3 Options For Hosting Multiple...
4 Tips To Find The Web Host That s...
- Linking
3 Way Links
Spoofing Phishing And Link Altering...

Phishing On The Pharm How Thieves Combine Two Techniques To Steal Your Identity



B


ob squinted at the email        email message. His fingers were   
and began to read:              poised over the keyboard when he  
                                happened to glance at the URL.    
"Dear eBay User, as part of our                                         
security measures, eBay Inc. has      There was something very, very    
developed a security program          wrong with it.                    
against fraudulent attempts and                                         
account thefts. Therefore, our        "PHARMING" TO FLEECE SHEEP        
system requires further account                                         
verification..."                      The art of "pharming" involves    
                                      setting up an illegitimate        
Security Measures. A threat to        website that is identical with    
suspend his account to prevent        its legitimate prototype, for     
"fraudulent activity". The email      example the ebay page Bob was     
went on to say that there were        almost suckered into using, and   
"procedural safeguards with           redirecting traffic to it.        
federal regulations to protect                                          
the information you provide for       "Pharmers" can do it in two ways: 
us."                                                                    
                                      1.By altering the "Hosts" file on 
Bob clicked the link and was          your computer. The Hosts file     
confronted with an authentic          stores the IP address of websites 
looking logon page, just waiting      you have been accessing. By       
for him to input his user name        inserting a new IP address into   
and password and confirm what         the database field corresponding  
ebay supposedly didn't know.          to a website, your own computer   
                                      can be redirected to the          
He almost did it. The page looked     pharmer's website. Any            
absolutely authentic, and he had      information you give the bogus    
already been "set up" by the          site is immediately hijacked by   



the pharmer.                          warning you if something has been 
                                      downloaded from a web site or     
2.Hijacking the DNS (Dynamic Name     through email. It should be able  
Server) itself. A DNS matches the     to remove it, "quarantine it", or 
names of address with their IP        tell you where it is so that you  
addresses. If this server can be      can remove it by hand.            
coerced into assigning new IP                                           
addresses to traditional names,       You should also have Spyware and  
all computers using the name          Adware programs installed, and be 
resolution provided by the DNS        aware of any change in Internet   
server will be redirected to the      browsing patterns. If your home   
hijacker's web site.                  page suddenly changes, or you     
                                      experience advertising pop ups    
Once that happens, it's time to       (which may pop up even when you   
be fleeced.                           are not hooked up to the          
                                      Internet), you should run a       
DOWN ON THE PHARM                     Virus, Spyware or Adware scan.    
                                                                        
"Pharmers" hijack your "hosts"        Thanks to the efficacy of these   
file or DNS servers using             protection programs, pharming is  
Spyware, Adware, Viruses or           a lot more difficult than it used 
Trojans. One of the most              to be. It isn't as easy to hijack 
dangerous things you can do is to     a computer as it once was.        
run your computer without some                                          
form of Internet Security             So, the "pharmers" have teamed up 
installed on it.                      with the "phishermen" to get you  
                                      to visit the bogus web page       
Your security software should be      yourself, and enter all the       
continually updating its virus        information they need.            
definitions, and be capable of                                          



PHISHING TO CATCH YOU ON THE                                            
PHARM                                 The only real protection against  
                                      the pharmers and phishermen is    
As Bob discovered, the page he        YOU. There are three things you   
had been taken to by the bogus        must consider when you read any   
email message was identical to        email demanding information:      
the ebay logon page. Identical in                                       
every way except for the URL.         â€¢ Why do they want it? Be       
                                      extremely skeptical when they say 
Out of curiosity, he checked the      they have to "update their        
URL for the ebay logon by             records", "comply with federal    
accessing ebay directly and           regulations", or prevent fraud.   
clicking on the logon link. The       They are the ones initiating the  
two URL's were nothing alike,         fraud.                            
except the bogus one did have the                                       
word "ebay" in it twice - just        â€¢ Why can't this be done at the 
enough to make it look authentic.     website? Why not invite you to    
                                      access the website directly and   
By combining the two techniques,      provide this information? The     
the phishermen/pharmers had           answer is because the bonafide    
avoided the high tech problems        company doesn't need an update.   
associated with downloading a                                           
Virus that could get past his         â€¢ What does the URL look like?  
protection software. They had         Is it a series of subdomains some 
gone straight for the throat.         of which have the name of the     
                                      bonafide company? Most likely the 
Bob's throat.                         subdomain is set up with a free   
                                      hosting company.                  
YOUR ONLY REAL IDENTITY THEFT                                           
PREVENTION AND PROTECTION             â€¢ Have they provided partial    



information about you as a                                              
guarantee that the email              The bottom line is: don't provide 
authentically comes from the          any information at the behest of  
legitimate source? Be very            an email, no matter how authentic 
careful of this one. This             it looks, or how authentic the    
technique is effective for            page it directs you to looks. If  
"pretexting", impersonating a         you must log in, do so at the     
person or company, and was used       parent site itself.               
in the Hewlett Packard scandal to                                       
collect information. Just because     Your Identity Theft prevention    
they know your first and last         and protection is, in the final   
name (and any other information -     analysis, up to you.              
known only to the legitimate                                            
source) doesn't mean the email is     Don't be the next sheep fleeced   
legitimate. They probably             by the pharmers who caught you    
hijacked the information off the      with the phisherman's hook. Being 
server.                               dropped naked into their frying   
                                      pan is NOT a fate you want.       
THE BOTTOM LINE                       

                              






About the Author:

John Young is a writer with a scientific and technical background living in California. At the age of 62, he is the father of four, grandfather of 13, and lives with his wife and cat "Bear". Please check out his latest book on Identity Theft http://www.youridentitystolen.com For some suggestions on Fire Walls, Virus, Spyware and Adware protection software visit his "California Software Shop" at http://www.pcreveal.com


Read more articles by: John Young

Article Source: www.iSnare.com


...Archive >>

Submit Your Site
Recent Articles
  • An Introduction To Website Analytics

    You recently revamped your firm’s website or are planning an online marketing campaign, but are not really sure what you’ll gain in return Website analytics is a science whose aim is to answer such questions In this piece, we’ll take a look at the benefits of web analytics and ways to optimize its tools...

  • Bring Good Results With Search Engine Optimization Help

    Search engine optimization help is no doubt becoming the most coveted option for the business entities that want to publicize their organization through the Internet It rewards the entrepreneurs with an immense number of clients or customers, increases the Internet traffic, and promises incremented sales as well SEO follows a proper protocol defining a set of methods that are crucial for the listings of search engines...

  • Free Myspace Layouts – Make Attractive Profile

    Are you on MySpace That must be the most popular question asked who roam the streets of America today Maybe you have asked, well, dive into convoy if you have because you can now say yes...

  • Myspace Layouts – Make Your Profile Attractive

    MySpace layouts If you want to create a little piece of your own on the Web, then perhaps you might consider MySpace This website has literally exploded one of the best websites on the Internet in general You will join fifty million users of all ages and interests, and we hope to win as many of them as you can to your new online friends...

    Copyright (c) 2008 Isnare.com. All rights reserved.

  • Google
    Phishing On The Pharm How Thieves Combine Two Techniques To Steal Your Identity