Bookmark and Share

Phishing And Pharming Scams

Free PDF eBook!

Enter Your First Name
and Email Address to Download

eMail address:
First Name:

As soon as almost all computer users already got used to - or at least heard about - the word "phishing", another somewhat confusing word appeared. Pharming. Does it differ from phishing - if yes, how?

Actually, two completely different fields use the term "pharming" now. We can say there exist two separate "pharmings".

If genetics or businessmen from pharmaceutical industry are talking about pharming (spelled like that) it might have nothing to do with computers. This word has long been familiar to genetic engineers. For them, it's a merger of "farming" and "pharmaceutical" and means the genetic engineering technique - inserting extraneous genes into host animals or plants in order to make them produce some pharmaceutical product. Although it is very interesting matter, this article isn't about it.

As for PC users, the term "pharming" recently emerged to denote exploitation of a vulnerability in the DNS server software caused by malicious code. This code allows the cybercriminal who contaminated this PC with it to redirect traffic from one IP-address to the one he specified. In other words, a user who types in a URL goes to another web site, not the one he wanted to - and isn't supposed to notice the difference.

Usually such a website is disguised to look like a legitimate one - of a bank or a credit card company. Sites of this kind are used solely to steal users' confidential information such as passwords, PIN numbers, SSNs and account numbers.

A fake website that's what "traditional" phishing has in common with pharming. This scam can fool even an experienced computer user, and it makes pharming a grave threat. The danger here is that users don't click an email link to get to a counterfeit website.

Most people enter their personal information, unaware of possible fraud. Why should they suspect anything if they type the URL themselves, not following any links in a suspiciously-looking email?

Unfortunately, "ordinary" phishers are also getting smarter. They eagerly learn; there is too much money involved to make criminals earnest students. At first phishing consisted only of a social engineering scam in which phishers spammed consumer e-mail accounts with letters ostensibly from banks. The more people got aware of the scam, the less spelling mistakes these messages contained, and the more fraudulent websites looked like legitimate ones.

Since about November 2004 there has been a lot of publications of a scheme which at first was seen as a new kind of phishing. This technique includes contaminating a PC with a Trojan horse program. The problem is that this Trojan contains a keylogger which lurks at the background until the user of the infected PC visits one of the specified websites. Then the keylogger comes to life to do what it was created for - to steal information.

It seems that this technique is actually a separate scam aimed at stealing personal information and such attacks are on the rise. Security vendor Symantec warns about commercialisation of malware - cybercriminals prefer cash to fun, so various kinds of information-stealing software are used more actively.

Spy Audit survey made by ISP Earthlink and Webroot Software also shows disturbing figures - 33.17% PCs contaminated with some program with information stealing capability.

However, more sophisticated identity theft attempts coexist with "old-fashioned" phishing scams. That is why users should not forget the advice which they all are likely to have learned by heart:

-Never follow a link in an email, if it claims to be from a financial institution

-Never open an attachment if the email is from somebody you don't know

-Protect your PC from malware

-Stay on the alert



 

Identity Theft Videos and More Articles

Loading...

15 Easy Solutions To Avoid Identity Theft

... store them in a safe place and have it locked. It is also nice to store your unused checks, social security card and bank statement in a safe place. 4. You should also ensure to make credit card receipt copies when buying something. Moreover, confirm if your credit card was returned to you. 5. It is necessary ...

How To Create Safe Passwords For Online Accounts

... This makes the password weak and very capable of being hacked into. Lastly, do not use your login name or any part of your actual name to create a password. Criminals will always try your name, birthday, kid s names, and other personal information first so it is important to pick a password that has nothing ...

Notebook And WiFi Standards

... Even then, the security can be breached, albeit with difficulty. If you do not need Wi-Fi to implement your work, then stay switched off. If you need the Wi-Fi just to send and receive files, then stay connected for only that period. Rest of the time, stay offline. Precautions to take at a public Wi-Fi ...

10 Simple Reasons To Remove Spyware From Your Computer

... recognize programs that are now on your computer because they may have been installed there by a spyware related web site or program you loaded on your computer. In addition, you might be worried that: 4. Someone might be able to read your e-mails 5. Someone might be able to access your e-mail list 6. ...

Data Protection And Recycling Computer Hardware

... drive or remove it first. Professional services will ensure your old computer does not end up in landfill, but they usually don't guarantee that your data will be removed. If your used computer ends up on the Ivory coast, it's data will probably be accessed and your personal information stolen. Paying ...

 

Recommended Identity Theft Products









Home |  Free eBook |  Contact Us |  Privacy Policy |  Site Map