https://buy-zithromax.online buy kamagra usa https://antibiotics.top buy stromectol online https://deutschland-doxycycline.com https://ivermectin-apotheke.com kaufen cialis https://2-pharmaceuticals.com buy antibiotics online Online Pharmacy vermectin apotheke buy stromectol europe buy zithromax online https://kaufen-cialis.com levitra usa https://stromectol-apotheke.com buy doxycycline online https://buy-ivermectin.online https://stromectol-europe.com stromectol apotheke https://buyamoxil24x7.online deutschland doxycycline https://buy-stromectol.online https://doxycycline365.online https://levitra-usa.com buy ivermectin online buy amoxil online https://buykamagrausa.net

Spam, spam, spam and phish

Intersting — and alarming — note on how phishers are getting more sophisticated. “Phishing” is an attempt, usually through e-mail, to get you to reveal confidential account information. The most…

Intersting — and alarming — note on how phishers are getting more sophisticated. “Phishing” is an attempt, usually through e-mail, to get you to reveal confidential account information. The most common manifestation of this is an e-mail saying, “Hey, you need to update your account info at [fill in the name of the financial institution]. Click here.”

These sorts of attacks used to be (and, sometimes, still are) crude frauds, with typos and bad writing and all sorts of other tells that it wasn’t, in fact, Citibank trying to contact you. But the phishers are getting more sophisticated.

Phishing attacks have reached 57 million U.S. adults and have compromised at least 122 well-known brands so far, according to several estimates. At the end of 2004, nearly half of those attacks contained some sort of spyware or other malicious code, Trudeau said.

One attack, first documented last month by the Danish security firm Secunia, misdirects Web surfers by modifying a little-known directory in Microsoft Windows machines called a host file. When an Internet user types a Web address into a browser, he is directed instead to a fraudulent site. This technique has shown up in attacks spoofing several South American banks, said Scott Chasin, chief technology officer at MX Logic Inc., a security firm in Denver. The convergence of all of these threats means “we can expect to see some large attacks in the near term,” he said.

Another more ambitious attack targets the domain name servers that act as virtual telephone books, matching domain names with numerical addresses given to each computer on the Internet. If one of those computers is compromised, Internet users who type in www.bankofamerica.com, for example, could be directed to a look-alike site run by identity thieves.

Domain name servers are thought to be tougher to crack, but hackers can find a way in by posing as a company’s tech-support department and asking new employees for their passwords, Trudeau said. Domain-name hijacking is suspected in incidents involving Google Inc., Amazon.com Inc., eBay Germany and HSBC Bank of Brazil, Chasin said.

As a general rule, I ignore (in fact, flag as spam) any messages that come in with a subject line that indicates I have account info that needs updating. That’s because legitimate financial institutions and the like are well aware of this problem, and don’t use such messages.

If such a message does come in from an institution that I actually do business with, I’ll look at it. Anything that requires me to click through in the message to go to a web site, I consider to be a scam.

That all said, there’s not a lot that folks can do about DNS spoofing like the above passage mentions (any more than there’s much you can do about someone who works at a credit card company stealing your data). Just be vigilent, check your statements, and be careful before you click through on anything.

82 view(s)  

2 thoughts on “Spam, spam, spam and phish”

  1. I have seen a huge increase in phishing emails recently. They are very professionally done and would have fooled me, had I not kept a keen eye.

    One humorous thing is that I recently received a real “account needs updating” email from PayPal. My credit card on file had expired and they needed the new expiration date. The email was plain text and the reason I know it was legit is because they provided me with the last 4 digits and DIDN’T have any links to their website or attachements.

    All the provided was manual instructions for me to go to their website, navigate their links and update my CC expiration date.

    Of all the emails, the legit one had the least technical prowness.

  2. Interesting.

    The fact that they were able to validate some of your information was useful. An e-mail that says, “Dear Citibank customer …” or “Dear fred@maildomain.com … ” is probably less likely to be legit.

    And, as noted above, that the mail did not have a link for you to click on was, paradoxically, a sign it was more likely real.

    Hmmm.

Leave a Reply

Your email address will not be published. Required fields are marked *