Phishing Archives

Moderators: Moderator, Global Moderator

Post Reply
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Phishing Archives

Post by Tami »

[b]This thread contains important information in regards to Phishing & How To Protect Yourself, as well as an archives of Phishing alerts. [/b]


Phishy e-mails and Web sites: What's your responsibility?
Opinion by Larry Ponemon

Tom was an avid collector of antique train sets. One morning while scanning his e-mail, he noticed one from an online auction site from which he purchased a good part of his collection.

The e-mail had the familiar logos and graphics Tom was accustomed to seeing with a tempting message that he could purchase a 1938 Lionel caboose for less than $50. The message was irresistible. Tom provided his credit card number and shipping address. The site also asked for his Social Security number. Not thinking twice, Tom entered the nine digits. The next day, on his way to the grocery store, Tom stopped at his bank's ATM. To his horror, his balance was zero. He also found that his savings account was wiped out. A "phisherman" had hooked another victim.

The typical phishing experience starts with the receipt of a fake e-mail. The e-mail sender and subject line claims to be from a legitimate, trusted source such as an online auctioneer, bank, mortgage broker, credit card company or Web retailer.

A common message is a "customer service request" asking subjects to click onto a Web site, supposedly to resolve a glitch or problem within their account, perhaps to reset a password or personal identification number. As in the case above, it can also be an offer to purchase a product or service.

Because the fake e-mail often starts with a blast to millions of randomly selected e-mail addresses, most people don't respond because they don't have an existing business relationship. The goal for the criminal is to cast the net as wide as possible, luring in a few susceptible people who believe this is a legitimate request for information.

While the mere act of reading the e-mail advertisement or Web site can unleash a persistent cookie or Web beacon onto the user's computer system, the more serious security problem arises when the individual visits the spoofed Web site. The best spoofers do an excellent job of re-creating the real corporate Web site, making it almost impossible to detect the imposter. Once someone is on the site, more insidious technologies, such as spyware and Trojan horse programs, can be sent to the visitor's system. These technologies are used to tag someone as a gullible victim for a future scam.

More serious problems arise if users enter sensitive personal information onto the Web site page. Requested information often includes date of birth, Social Security number, credit card numbers, bank accounts, passwords and so forth.

Consumers aren't the only ones threatened by phishing and spoofing. Web retailers, banks and other online businesses risk losing customers' confidence, loyalty and valued relationships if they don't respond appropriately and quickly to customers who have been victimized.

Ponemon Institute just completed a study of one spoofing and phishing event that occurred in early May 2004 that victimized over 1 million customers of a major retail bank. We surveyed a random sample of 411 bank customers -- all of whom received the fake e-mail about an account security glitch. All of the selected customers claimed to have clicked to the spoofed Web site. In addition, all of the individuals contacted the bank's toll-free customer service help line for guidance or support. The following are the most salient findings:

Of the 411 customers, only 65 (16%) provided personal information on the spoofed Web site, which included their account numbers and confidential access codes for automated teller machines and check cashing. Of the 65 duped customers, only five experienced an unauthorized account penetration, and only one had a confirmed case of identity theft. The total estimated loss for this group of known victims was just under $50,000.

In total, 310 individuals felt that the bank didn't provide adequate guidance to them. Most of these people felt that the bank's customer service representatives weren't prepared to respond to the problem. Some of the bank employees suggested that this wasn't the bank's problem because it couldn't control spoofing. Of this group of dissatisfied bank customers, 243 (78%) decided to terminate their banking relationship as a result of their experience.

The remaining 101 bank customers felt that the bank did an adequate job in guiding them through the spoofing and phishing event. Only one person (1%) in this group suggested that he would terminate the banking relationship as a result of being spoofed.

Stop the Blame Game

In the case of Tom the train collector, who should be blamed? Is it the online auctioneer that was unaware of the fraudulent e-mail spam? Is it Tom? After all, shouldn't he know better than to provide his Social Security number?

Because the stakes are high for both consumers and businesses, we believe everyone should share the responsibility of cutting the phishing line. We recommend that organizations take the following actions:


Use enabling technologies to search or crawl the Internet and identify illegal domains and Web sites that contain your corporate logos or intellectual property. Many major brands have been targeted by cybercriminals. Unless you authenticate all the Web sites and domains that feature your brand, your customers are at risk.

Educate your customers about the dangers of phishing, spoofing and faked e-mails. Inform them that you are taking steps to address the problem. For example, eBay Inc. alerts customers on its Web site to spoofing messages. Consumers can also check with the online auction marketplace about any suspicious e-mails they receive under the guise of being from eBay.

Make sure your employees -- especially those in customer service -- understand the seriousness of the problem and can respond when customers contact your organization for help in resolving a phishing or spoofing attack.

Learn more about new technologies that will allow e-mail messages to be registered with a trusted identity and prevent counterfeit Web sites. The concept is similar to the watermarks created by the U.S. Mint to prevent the printing of counterfeit money. Also, Microsoft Corp. has announced its Sender ID technology to validate the server IP address of the sender to assure an e-mail recipient that a message claiming to be from a company or financial institution actually is.

Pretend you are a customer interested in more information about your company. Use a search engine such as Google to find what Web sites appear under your brand name or an approximation of your brand name. Sophisticated spoofers will create fraudulent Web sites that are very close to your name. For one well-known example, WhiteHouse.gov is the official site of the U.S. president. But, whitehouse.com takes you to a pornography Web site and unleashes a cookie.
In turn, when you're home as an online consumer instead of at work as an IT professional, you shouldn't be complacent. If you receive a suspicious e-mail from an organization you do business with, take the time to contact the organization and notify its customer service department about your concerns.

Counterfeit or fraudulent e-mails and Web sites are a growing and serious problem for everyone who uses the Internet. By luring unsuspecting Internet users to provide sensitive or confidential information, cybercriminals and terrorists have greatly enhanced their ability to steal identities and threaten people's assets. The best defense is for everyone to become proactive in stopping the phisherman's hook.

[url=\"http://www.computerworld.com/managementtopics/management/story/0,10801,95461p2,00.html\"]source[/url]
Last edited by Tami on Wed Oct 12, 2005 9:30 pm, edited 1 time in total.
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Phishing Archives

Post by Tami »

Phishing For Gmail Accounts

By Chris Richardson

It appears that there is a possible malicious email appearing in Gmail inboxes disguised as an invitation announcement. The mailing claims to be from the Gmail team and it "informs" the user that they have more invitations that can be given out.

This story was first reported by rustybrick at SearchEngineRoundTable.com, who discovered the email in his inbox. There are two reasons why the mailing, which looks like an official email from the Gmail Team, appears malacious. First, Gmail always puts new invite announcements in the mail console where users can easily see them.

The second reason for treating this mail as a fake is that it asks members to enter their Gmail user name and password in order "to claim their Gmail invitation package." Like rusty says, the fact that the mailing is asking for this information is reason enough for the alarms to go off. It certainly appears that someone is trying to acquire Gmail passwords.

Use this email at your own risk. A screenshot of the mailing, courtesy of rustybrick, follows.

[attachment=111:attachment]

[url=\"http://www.womensbiznews.com/womensbiznews-15-20040913PhishingForGmailAccounts.html\"]source[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
RuffRyders
Hero Member
Hero Member
Posts: 1138
Joined: Mon Jun 14, 2004 7:47 am

Phishing Archives

Post by RuffRyders »

[b]Caught in a phishing trap[/b]
[i]For Steve Krabill, a 33-year-old Oklahoma engineer, the answer to phishing scams is simple: Trust nobody.[/i]

Faced with an online test that presents him with 10 different e-mails, some of which are examples of phishing scams, his answer is to label every single one a fake. Three turn out to be the genuine article--but in the engineer's mind, he's passed the test either way.

"Companies I do business with online don't send me e-mails looking for my personal information, it's that easy," said Krabill, who works at Osborn Engineering, a Tulsa-based maker of metal recycling equipment. "I know that I'm not going to get scammed if I don't reply to any of them."

[img]http://www.killagraphix.com/uploads/111204phishing2_bchart.gif[/img]

Phishing is one of the fastest-growing forms of personal fraud in the world. While consumers are the most obvious victims, the damage spreads far wider--hurting companies' finances and reputation and potentially undermining consumer confidence in the safety of e-commerce.

"Phishers hijack brands for the purpose of fraud and degrade consumers' trust in those brands. That's what makes phishing so different than other types of online threats," Kim Legelis, director of industry solutions at security software maker Symantec, said.

The scammers typically send out an e-mail that appears to come from a trusted company such as a bank or an e-commerce Web site. The phishing messages attempt to lure people to a bogus Web site, where they're asked to divulge sensitive personal information. The attackers can then use those details to steal money from the victims' accounts.

According to a report from online privacy watchdog Truste, 7 out of 10 people who go online have received phishing e-mails, and 15 percent of those have successfully been duped into providing personal information.

The financial services industry has borne the brunt of those scams, an Anti-Phishing Working Group survey found, with Citibank leading the list of companies targeted. Online businesses such as eBay's Paypal online payment subsidiary and Google's Gmail "For many of these financial services companies, and undoubtedly for e-commerce providers, the Web is a very important channel for acquiring new business, growing revenue, and mitigating costs for customer service," Legelis said. "If consumers lose confidence in that channel, it will have a wide-ranging negative impact on these businesses."

Companies are paying a hefty amount to fix phishing damage. In many cases, they make good on their customers' losses. Money is also going to efforts to educate customers about fraud prevention, and the cost of polishing up a tarnished brand is hard to estimate.

The threat to business means that's money well spent. In a recent study by e-mail security company MailFrontier, 40 percent of American consumers surveyed said they would switch to a bank or credit card company that offers better protection from online identity theft. Ninety-four percent said it's the responsibility of their financial institution to shield them from phishing and similar scams, and 52 percent felt that their providers are not doing enough to safeguard their information.

The multiple problems caused by phishing do not have a simple solution. Some businesses hope education will lead to more wary customers like Krabill. Others are pinning their hopes on jointly looking for technical solutions, such as address-verification schemes and software filters to sort valid e-mail messages from scams.

Cooperation across the IT and e-commerce industries has led to a number of trade organizations being launched to combat phishing. One is the Anti-Phishing Working Group (APWG), made up of experts from a range of different organizations, including credit-trackers Experian, software giant Microsoft and credit card stalwart Visa.

Earlier this month, the group gave its endorsement to a global e-mail authentication strategy. It believes the project can help create technologies for Internet-protocol (IP) validation and digital signatures that will thwart spam and phishing attacks.

Peter Cassidy, secretary general of APWG, said the group is trying to balance the interests of consumers and businesses in finding a way to protect both. He believes lessons learned from earlier fraud efforts are key to discouraging phishing.

"The rate that we're seeing phishing attempts increase by is currently 50 percent per month, and it's moving to new platforms such as peer-to-peer computing, which is pretty spooky to think about," Cassidy said. "We have to take the same approach that credit companies took in the 1970s when fraud was crippling the catalogue business."

One of the main thrusts of the general antiphishing effort is consumer education. The MailFrontier phishing test completed by Krabill does make its point--in many cases, the phishing e-mails generated by online criminals are very hard to discern from the real thing.

"Consumers simply have to become savvier about phishing and other forms of fraud," said Mike Cunningham, senior vice president of fraud management at Chase Card Services, the credit card services division of JPMorgan Chase. Financial services companies "can do everything in our power to quickly identify these attacks and shut down the Web sites. But getting the customer to know what to expect from a credit card issuer, and what to expect from these criminals, is what's truly going to make a difference."

At online auction site eBay, customer awareness is starting to take root, company spokesman Hani Durzy said. On eBay's message boards for registered customers, people frequently post details of emerging phishing campaigns before the company has heard about them, he said. In addition, more and more members are reporting fraud activity and are talking among themselves about it.

"Our community has been very vigilant about passing around information, and asking for each others' advice and opinions whether things are legitimate or spoofs," Durzy said. "Over the last two years, phishing has really exploded, but people are becoming more aware of the threat."

On the technology side, eBay employs a complex system of software applications designed to flag any activity on its site that indicates one of its users' accounts has been hijacked. Much like the fraud prevention systems used by credit card companies, the tools look for irregularities such as a dramatic change in location or in the size of bids.

In addition, eBay and its PayPal billing unit share a fraud investigation team, whose full-time job is to track down illegitimate operations using the PayPal and eBay names.

Industry efforts such as these and cooperation with law enforcement agencies has resulted in high-profile arrests and the prosecution of fraudsters such as Zachary Hill, who was sent to prison for almost four years in connection with an eBay scam.

Despite these successes and the push to improve technology, experts agree that the best way to foil phishing campaigns is to encourage more cautious consumers. JPMorgan's Cunningham emphasizes that people need to delete suspicious messages and to resist the urge to ever transmit personal data.

"Just don't do it, don't reply," he said. "It's really that simple."

[url=\"http://news.com.com/Caught+in+a+phishing+trap/2100-1029_3-5453203.html?tag=st.num\"][Source][/url]
The bruises fade but memories are made.
RuffRyders
Hero Member
Hero Member
Posts: 1138
Joined: Mon Jun 14, 2004 7:47 am

Phishing Archives

Post by RuffRyders »

[b]Microsoft's answer to phishing: Two IDs[/b]
[i]Banks are looking to bring down the number of phishing attacks by adopting two-factor authentication, which would require people to produce two forms of identification, Microsoft said on Tuesday.[/i]

The software giant's chief security strategist, Scott Charney, said that companies had failed to adopt the technology as fast as he would have liked.

"We haven't had as much adoption as you would hope for," Charney said at the Microsoft IT Forum in Copenhagen. "A lot of solutions for two-factor authentication are for enterprise spaces. If you get two-factor authentication to the consumer level, you reduce the phishing threat."
Digital agenda

Phishing attacks are identity theft e-mails that are written to look as if they were sent from legitimate organizations. Companies such as eBay and PayPal, and some banks have seen their customers targeted by the fraudsters behind such scams.

Phishing fraud has cost U.S. consumers $500 million, according to a recent survey sponsored by Truste, a nonprofit privacy group, and NACHA, an electronic payments association.

"Banks are looking at (two-factor authentication)," Charney added. "The real issue is the consumer acceptance. This kind of security when implemented is not often viewed as friendly. There is a challenge in how you communicate this."

Earlier this month Howard Schmidt, former cybersecurity advisor to the White House, called for companies to implement two-factor authentication. He said that the technology was already available and that people had to supply more credentials for Internet transactions.

But the United Kingdom's Association for Payment Clearing Services (APACS), which represents the banking industry, said on Wednesday that no decisions have been taken to go ahead with two-factor authentication, despite the rise in phishing attacks.

"The fact is, it's a massive undertaking," said Tom Salmond, a managing consultant in the e-banking fraud liaison group at APACS. "It's under active consideration, but no decisions have been made at this time."

Richard Clarke, another former cybersecurity advisor to the White House, said earlier this month that online banking transactions cost just half of 1 percent of the cost of a physical transaction.

[url=\"http://news.com.com/Microsofts+answer+to+phishing+Two+IDs/2100-1029_3-5457381.html?tag=nefd.hed\"][Source][/url]
The bruises fade but memories are made.
RuffRyders
Hero Member
Hero Member
Posts: 1138
Joined: Mon Jun 14, 2004 7:47 am

Phishing Archives

Post by RuffRyders »

[b]New browser sniffs out phishy sites[/b]
[font=\"Arial\"][i]A browser launched on Wednesday with the promise to both detect "phishing" sites and nail an increasingly prevalent type of floating Web ad.[/i]

[size=1]By Paul Festa[/size]

Deepnet Explorer, a browser shell that uses Microsoft's Internet Explorer to render Web pages, analyzes Web addresses and combs through its own list of suspect sites to determine whether a site might be part of a phishing scam, in which fraudsters attempt to get personal and payment information from unsuspecting visitors.

Phishing scams have become more sophisticated and common, though a report released today suggests that the monetary cost of the trend has been exaggerated.

Version 1.3 of the browser, previously available in a test, or "beta" version, also takes aim at a new kind of Web advertisement that has been evading pop-up blocking software.

The ads, called "floating" or "overlay" ads, move around on the screen and are immune to the pop-up controls increasingly common in browsers and browser toolbars.

"We've seen a lot of these adverts recently," Deepnet CEO Yurong Lin said. "It's the new trend in advertising because the pop-up blockers are so popular."

Pop-up blockers generally work by detecting and foiling a Web script command to open a new window. But floating ads rely on a more involved scripting object that keeps the pixels moving in an existing window.

Deepnet Explorer 1.3 also introduces an application that lets Web surfers monitor cookies, or files that a Web site places on a visiting computer to keep track of preferences and other personal information. Another feature lets people create groups of browser tabs within a single window. Tabbed browsing has emerged as a must-have feature for Web browser software trying to compete with or expand on IE, which doesn't offer tabs.

For Version 1.3, Deepnet added content from news headline aggregator Moreover Technologies. For future versions, the company is in negotiations with Google to provide general search results.

Lin dismissed criticism that the Deepnet browser's phishing detector could lull users into unwarranted complacency. Critics have noted that some phishing schemes work on legitimate sites through code sneaked onto Web surfers' computers.

"Antivirus companies are looking for viruses, but phishing sites are not viruses, and you need something like Deepnet to find those sites," Lin said. "I think we complement each other."

Lin also defended his company's decision to stick with the IE rendering engine. IE has gotten criticism by some Web developers, who have rapped both its security and its standards support. Open-source options such as the Mozilla Foundation's Gecko software have won better security and standards reputations in recent years.

"Over the last several years, IE became the de facto standard browser, so most Web sites are designed to work with IE," Lin said. "If we chose something like Mozilla, it's going to not display a lot of Web pages properly."

But Lin said Deepnet has considered doing something like Netscape did yesterday with its release of a prototype browser that gives surfers the option of switching back and forth between browser engines.

"That's something we've been talking about internally," Lin said. "It's possible for us to support multiple engines. The only problem is engineering resources. To provide compatibility for Gecko would require a lot of development work."

[url=\"http://news.com.com/New+browser+sniffs+out+phishy+sites/2100-1029_3-5473252.html\"][Source][/url][/font]
The bruises fade but memories are made.
RuffRyders
Hero Member
Hero Member
Posts: 1138
Joined: Mon Jun 14, 2004 7:47 am

Phishing Archives

Post by RuffRyders »

[b]Microsoft rushes out critical IE fix[/b]
[i]Microsoft published a patch for Internet Explorer on Wednesday, aiming to close a month-old hole that has been used by viruses to spread and by an ad banner attack to compromise PCs.[/i]

[size=1]By Robert Lemos[/size]

The vulnerability, dubbed the Internet Explorer Elements flaw by Microsoft, had previously been called the iFrame vulnerability. The issue--which does not affect Microsoft's major Windows XP security update, Service Pack 2--could allow an attacker to take control of a victim's PC, if the user is logged on as an administrator. Most home users tend to log onto Windows as administrators.

A Microsoft representative said the software giant had released the update before its next scheduled patch day, Dec. 7, because it had already been used by malicious software to compromise Windows users' PCs.

"That's one of the things that we factor in--when the customers are affected or there are active attacks," said Stephen Toulouse, security program manager at Microsoft's security response center.

An attacker can use the vulnerability to gain control of a person's computer when the victim clicks on a simple Web link. The attacker would then have complete control of the system, and could install programs, view, modify or delete data and create new accounts.

The patch arrived more than a month after news of the vulnerability was first posted on public security mailing lists. The move garnered criticism from Microsoft, which has led a drive to convince security researchers to give software makers at least 30 days to fix issues before outing the problem in public forums.

The IE flaw underscores that online criminals are all too willing to use the latest vulnerabilities to take illicit control of users' PCs.

Digital agenda
Two computer viruses appeared on the Internet in early November, using the vulnerability in Microsoft's browser to infect PCs after their users clicked on a simple Web link. The viruses, called Bofra.A and Bofra.B by antivirus companies, were loosely based on the source code of MyDoom.

In addition, online intruders breached the security of at least one server at advertising host Falk last week and used the computer to distribute an attack to the service's clients, including The Register, a technology news and opinion site.

The IE Elements flaw affects PCs with IE version 6 installed, but does not affect computers that have been upgraded to Service Pack 2. The software, the latest version of Windows XP, has been downloaded more than 130 million times, Microsoft's Toulouse said.

The latest update for IE 6 can be downloaded from Microsoft's security site or through Windows Update.

-[url=\"http://dw.com.com/redir?destUrl=http%3A%2F%2Fwww.microsoft.com%2Fsecurity%2Fbulletins%2F200412_windows.mspx&siteId=3&oId=2100-7349-5473282&ontId=1009&lop=nl.ex\"]Link[/url]

[url=\"http://news.com.com/Microsoft+rushes+out+critical+IE+fix/2100-7349_3-5473282.html\"][Source][/url]
The bruises fade but memories are made.
RuffRyders
Hero Member
Hero Member
Posts: 1138
Joined: Mon Jun 14, 2004 7:47 am

Phishing Archives

Post by RuffRyders »

[b]Phishers lie in wait for Google searchers[/b]
[font=\"Arial\"][i]Phishers are setting up fraudulent e-commerce Web sites and simply waiting for victims using Google and other search engines to find them, a security company has warned.[/i]

Traditionally, phishing scammers have lured their victims to fraudulent Web sites by sending official-looking e-mails that are ostensibly from well-known companies asking users to 'verify' their user names and passwords. Now many are setting up legitimate looking e-commerce sites that disguise links to malicious software as pictures of goods on sale, CyberGuard said Wednesday.

Paul Henry, a senior vice president at CyberGuard, said that when Web shoppers search the Internet looking for products they want to buy, they could be directed to a plausible e-commerce site that instructs them to "Click here to download images" of the product.

Henry said that instead of linking to pictures of the advertised product, the links point to a self-extracting ZIP file that installs a Trojan horse on the victim's computer. The program could then steal personal and financial information.

"If it looks too good to be true, it probably is. Don't let the Grinch steal your Christmas," Henry said.

The warning comes a week after the Anti Phishing Work Group, or the APWG, said it suspected that a phishing tool kit, which could help create and automate phishing attacks, was being distributed on the Internet.

In early November, e-mail security company Messagelabs warned of a new phishing method that did not require the user to open an e-mail attachment or click a link.

Messagelabs said it had discovered some malicious e-mails that, when viewed, could run a script that manipulated certain files on the victim's computer. The next time that computer attempted to log on to a legitimate banking site it would automatically be redirected to a fraudulent Web site.

[size=1]Munir Kotadia of ZDNet Australia reported from Sydney.[/size]

[url=\"http://news.com.com/Phishers+lie+in+wait+for+Google+searchers/2100-7349_3-5473663.html\"][Source][/url][/font]
The bruises fade but memories are made.
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Phishing Archives

Post by Tami »

Phishing scams try new bait

By JACK KAPICA
Globe and Mail Update



Phishing attacks, designed to coax critical personal information from the recipient of a fraudulent e-mail, have a success rate of about 5 per cent, say security specialists at Proofpoint.

And phishing scams are beginning to use another technique designed to dupe an e-mail recipient into delivering the information: Make the recipient think the e-mail came from within his or her own company.

"Some of the most insidious new attacks we're seeing involve employees being sent phishing e-mails that appear to come from their employers," Proofpoint phishing expert Rami Habal said in a statement.

Proofpoint, based in Cupertino, Calif., said it has identified almost 100 new phishing attacks in November alone, an increase of 80 per cent over the previous month.

Analysts at another security company, Trend Micro, have reported a slow-down in the occurrence of viruses during the same month, which was 14 per cent lower than the previous month. But like Proofpoint, Trend Micro noticed an increase in "malware" — worms, viruses and phishing attacks already in circulation.

Trend Micro detected more than 1,500 malware detections for the month, which the company cited as proof that even during a "slow" period, corporations and consumers continue to battle worms and viruses.

Proofpoint believes the increase in phishing attacks is tied to the holiday season.

"The holidays are an especially dangerous period for consumers and employees, because the increased volume of legitimate commercial e-mail provides additional cover for the fraudulent e-mail, making it easier to deceive people into giving away their personal information," Mr. Habal said.

In November, holiday-themed spam increased more than 1,000 per cent, Mr. Habal said, and he expects to see a similar exponential increase in both holiday spam and holiday-themed phishing attacks during December.

Proofpoint gathered its data from about 1.2 million e-mail inboxes currently being protected by Proofpoint's security products.

Phishing attacks use "spoofed" e-mails and fraudulent websites designed to fool recipients into divulging personal financial data such as credit card numbers, account user names and passwords and social insurance numbers.

Proofpoint says it has five major warnings for Internet users. First, people should view any e-mail with urgent requests for personal identifying information, personal financial information, user names or passwords with suspicion; if you receive a suspicious e-mail, don't click the links in that e-mail to visit the website in question; when shopping on-line, entering important information such as credit-card numbers or updating personal information, make sure you're using a secure website (one with a Web address that begins with "https://" instead of the usual http://); don't fill out e-mail forms; and keep an eye on the accuracy of your credit-card and bank statements on a regular basis.

In worms and viruses, Trend Micro said that the Bagle worm continued to show persistence with the release of two new strains within hours of each other on Oct. 29.

The Sober worm, after five months of reasonable inactivity, has made a comeback, Trend said. The mass-mailing worm resurfaced on Nov. 19, infecting thousands of computers in Germany, Austria and France.


[url=\"http://www.globetechnology.com/servlet/story/RTGAM.20041213.gtphishdec13/BNStory/Technology/\"]source[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Phishing Archives

Post by Tami »

Phishers take aim at dot-ca name holders

By JACK KAPICA
Globe and Mail Update



The Canadian Internet Registration Authority is warning those who have registered a dot-ca domain name that an e-mail phishing scam is circulating, trying to get user account numbers and passwords from its victims.

The so-called phishing attack comes as a fraudulent notice purporting to come from CIRA, and requests a user's account number and passwords to validate registrant information and prevent domain name inactivation.

The e-mail originates from compliance@cira.cc — CIRA's real compliance e-mail address is compliance@cira.ca.

CIRA is responsible for setting policy and managing the 473,000 dot-ca domain name database as well as registering domain names through its network of certified registrars. It is asking people who have been victimized by this scam to notify their domain-name registrars as soon as possible. Users who have forgotten their registrar can identify them by entering the dot-ca domain name in the WHOIS field at [url=\"http://whois.cira.ca/public\"]http://whois.cira.ca/public[/url].

CIRA is also asking people who have received the phishing e-mail to forward a copy to security-advisory@cira.ca so the authority can estimate the extent of the fraud.

Most fraudulent e-mail schemes (called "phishing" or "spoofing") are designed to obtain credit-card numbers and Internet banking passwords. Getting information about domain names is a relatively new scam, CIRA said.

Armed with user account numbers and passwords, criminals can manage the victim's dot-ca domain names — such as renewing, transferring and updating the account.

CIRA says it has reported the current scam to police. Those seeking additional information are invited to call CIRA's customer support unit at 1-877-860-1411.


[url=\"http://www.globetechnology.com/servlet/story/RTGAM.20041214.gtphishdec14/BNStory/Technology/\"]source[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Endo
Hero Member
Hero Member
Posts: 1158
Joined: Wed May 05, 2004 9:05 am

Phishing Archives

Post by Endo »

Be careful when you receive e-mails from "MSN" claiming that "during one of our regular automatical verification procedures we've encountered a technical problem caused by the fact that we could not verify the information that you provided during registration." and urgently ask you to "submit your information so that we could fully verify your identity, otherwise an access to MSN services for your account will be deactivated until you pass verification process.".

Some of them even mention the recent .NET Messenger Service downtimes as the reason of the data loss. Do not click any link in these e-mails, let alone submit your information. This is an obvious case of phishing abusing the MSN brand.

[url=\"http://www.mess.be\"]Source[/url]
[align=center]

Image

[color=\"#333333\"]Last Blog:[/color][color=\"Green\"] SUMMER [/color][color=\"black\"](30/11/06)[/color]

[/align]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Phishing Archives

Post by Tami »

DNS-Based Phishing Attacks on The Rise
By Sean Michael Kerner

Phishing fraudsters are using a pair of DNS exploits to help give them the illusion of credible domains, the latest ploy to dupe people into handing over their sensitive information.

According to research firm Netcraft, phishers have begun to use wildcard DNS records to help trick unsuspecting users into giving up information about their identity.

Wildcard DNS help users arrive at their intended Web destination by redirecting mistyped and/or errant addresses. But wildcard DNS has been used against Barclays Banks in the U.K with e-mail using an additional sequence of characters that ultimately leads the user to a phisher's site.

A similar type of attack vector specific to Microsoft Internet Explorer was reported last month by security researcher Bitlance Winter. In that attack, an identifiable URL also has a string of characters or additional domain information added that directs a user to a different address than the one they see in the visible toolbar.

The technique, known as DNS cache poisoning, is also being utilized by phishers in an attack know known as "pharming" where a poisoned DNS server redirects users to the phisher's Web site. The "poison" is essentially false DNS information that is injected into a vulnerable DNS server.

According to Netcraft, an attack this past Saturday exploited a known vulnerability in Symantec's firewall product. The firewall vulnerability had not been patched by Symantec last year. The Saturday attack redirected user requests from eBay, Google and weather.com to a trio of phisher-directed sites.

Dave Jevans, chairman of the Anti-Phishing Working Group, told internetnews.com that he has seen an increase in Wildcard DNS and DNS pharming attacks with several new ones this year targeting North American institutions.

"UK has seen an increase since December 2004," Jevans said. "Some of these attempt to implement man-in-the-middle attacks too."

The DNS system itself has been the subject of proposed enhancements like DNSsec to guarantee better security for users. DNSsec is short for DNS Security Extensions, which are supposed to include integrity and authentication checks to DNS data.

"DNS-sec has been in the works for some time, but not really rolled out except maybe at the Verisign root. Recent events are going to spur something here, I think," Jevans said.

DNSsec however won't necessarily stop all pharming activity though.

"Most pharming is using DNS poisoning at the personal PC level (eg. add entries to the local hosts file). Fixing DNS servers won't prevent this," Jevans explained. "Mutual authentication (possibly two-factor) would be a big help, however."

The APWG recently reported that phishing attacks rose by 42 percent from December 2004 to January 2005.

[url=\"http://www.internetnews.com/ec-news/article.php/3488216\"]source: internet news[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Phishing Archives

Post by Tami »

New Phishing Attacks Offer Cash
by Dennis Fisher

A new kind of phishing attack made its debut over the weekend, and experts say this is the first time that online scammers have offered cash to entice recipients into responding to their ploys.

The new e-mail emerged in the last two days and is designed to look like a solicitation from Citizens Bank. The message asks recipients to complete an online survey, and in return, recipients will supposedly get $5 credited to their accounts.

But, in order to receive the credit, each user must enter his ATM card number and PIN, something that no legitimate bank mailing would ever require. Experts who have seen the messages and analyzed the code behind them say that the scam is being hosted by ISPs in England and the Netherlands.

The e-mail message, titled "Citizens Bank instant $5 reward survey," carries accurate logos and branding information for Citizens, but there are a number of grammatical errors in the text that mark it as a scam.

This attack is one of the few times that phishers have strayed from their tried-and-true method of trying to scare recipients into falling for their scams with messages saying that users' accounts have been compromised or need to be updated to avoid cancellation. Offering a cash incentive for responding to a message takes the scams to an entirely new level, and experts predict that such attacks will likely meet with tremendous success.

"This attack will have a very high capture rate as it changes the game and is a much better con. Five dollars is not a small amount. For a legitimate offer from my bank, I'd fill out a survey for $5," said Bill Franklin, president of Zero Spam Network Corp. in Coral Gables, Fla., a managed services provider that was able to stop the new attacks. "Once again the game keeps changing—this is a pretty bad development."

Most of the developments and advancements in phishing scams have been technical ones, as scammers have learned new coding tricks and ways to plant Trojans on recipients' machines. But some attacks also have been refining their social engineering repertoires.

[url=\"http://www.eweek.com/article2/0,1759,1777928,00.asp\"]source: eWeek[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Endo
Hero Member
Hero Member
Posts: 1158
Joined: Wed May 05, 2004 9:05 am

Phishing Archives

Post by Endo »

Phishing criminals are using a new technique to slip by the content filtering software some enterprises use to protect their workers from scams, a U.K.-based Web metrics and monitoring firm said Friday.

According to Netcraft, some fraudsters are replacing text content on their phony sites with similar-looking images, "making it much more difficult for automated systems to detect the presence of keywords such as 'PayPal' and 'credit card.'"

In an online alert, Netcraft illustrated how a phisher could simply embed text within an image to hide it from filters. The text would still be readable by a possible victim, but not by a computer.

"Because the content filters may not detect this [sample page] as being a PayPal phishing scam, it could slip through undetected, allowing the fraudster to harvest the credentials of thousands of PayPal customers," Netcraft went on in its alert.

[url=\"http://www.informationweek.com/story/showArticle.jhtml?articleID=163102058\"][u][Source][/u][/url]
[align=center]

Image

[color=\"#333333\"]Last Blog:[/color][color=\"Green\"] SUMMER [/color][color=\"black\"](30/11/06)[/color]

[/align]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Phishing Archives

Post by Tami »

Anatomy of 'phishing' shows how thief was found
BY TED BRIDIS
Advertisement


WASHINGTON -- The illicit haul arrived each day by e-mail, the personal details of computer users tricked by an Internet thief: a victim's name, credit card number, date of birth, Social Security number, mother's maiden name.

One more Internet ''phishing'' scam was operating.

But this time, private sleuths soon were hot on the electronic trail of a thief whose online alias indicated an affinity for the dark side. The case moved ahead in part because of an underground tipster and the thief's penchant for repeatedly using the same two passwords -- ''syerwerz'' and ''r00tm3.''

Unraveling the scheme leapt across continents and ultimately pointed toward a neighborhood in Granby, Quebec. It offers an extraordinary glimpse behind an Internet fraud that targets the most trusting computer users.

''This is really lousy,'' said Johan Fabris of Holmes, Pa. The 82-year-old grandmother had her online bank account hijacked. Her teenage grandson set up the account for her to sell hand-sewn doll clothes in Internet auctions.

''This was my first foray into the modern computer world. These damn people, life is complicated enough,'' Fabris said.

In such phishing scams, victims are fooled by realistic-looking e-mails that appear to come from banks or other financial institutions. The messages direct recipients to verify their accounts by typing personal details -- credit card information, for example -- into a Web site disguised to appear legitimate.

Looked 'completely real'

Despite warnings from the government, banks and security experts, consumers fall victim with disturbing frequency.

One industry organization, the Anti-Phishing Working Group, estimated that thieves collectively launch more than 14,000 such schemes monthly and that about 5 percent of computer users respond to the fraudulent messages.

''They make it look completely real,'' said Jennifer Phillips, 25, of Martinsville, Ill. She was tricked into disclosing her card number, mother's maiden name, bank routing number and more. ''You wouldn't think this could happen to anybody living in the middle of cornfields,'' she said.

Internet sleuths from CardCops Inc. of Malibu, Calif., uncovered the latest plot.

A tipster pointed them to the thief's e-mail account and gave up the thief's favorite passwords, which the thief previously had shared with the informant, chief executive Dan Clements said.

Mounties won't investigate

CardCops monitors Internet chat rooms and other hacker communications for stolen credit card numbers, then notifies merchants and consumers to block bad purchases.

Clements said he logged into the thief's account -- despite concerns this could be illegal -- and found what he described as a ''den of treasure'' for identity crooks.

Clements said he discovered copies of victims' financial information plus tantalizing clues to the thief's real identity. They included an invoice for two Gamecube video games purchased with a stolen credit card. The person listed on the invoice as receiving the video games in Quebec denied any involvement in fraud, saying in a brief interview he did nothing wrong.

But shortly after the interview, the e-mail inbox used for the purchases was mysteriously emptied and the password changed, said Clements, who said he kept copies of everything he found.

The case showed how hard it can be to get the attention of police.

The Royal Canadian Mounted Police in Quebec said it does not investigate online financial crimes. A city detective in Granby referred the case to provincial police but cautioned that any investigation would take months.

''There's sort of a hole in enforcement,'' acknowledged Marc Gosselin, a cybercrimes investigator for the Mounties.

~~~

Sidenote: The RCMP does investigate online financial crimes. The problem lies in provinces which have a provincial police force. Some provinces, such as BC use the federal police force as a provincial police force, however some cities within the provinces also have their own police forces. As in other countries, it's all about jurisdiction.

[url=\"http://www.suntimes.com\"]source: Chicago Sun Times[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Phishing Archives

Post by Tami »

[url=\"http://www.antiphishing.org/\"]AntiPhising.org[/url] is probably *the* best resource site on the 'net for anti0phishing and pharming education.
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Post Reply

Return to “Security”