® Www.sssdirect.com

Sssdirect.com - "Phishing" On The "Pharm": How Thieves Combine Two Techniques To Steal Your Identity

Bob squinted at the email and began to read:

“Dear eBay User, as part of our security measures, eBay Inc. has developed a security program against fraudulent attempts and account thefts. Therefore, our system requires further account verification...”

Security Measures. A threat to suspend his account to prevent “fraudulent activity”. The email went on to say that there were “procedural safeguards with federal regulations to protect the information you provide for us.”

Bob clicked the link and was confronted with an authentic looking logon page, just waiting for him to input his user name and password and confirm what ebay supposedly didn't know.

He almost did it. The page looked absolutely authentic, and he had already been “set up” by the email message. His fingers were poised over the keyboard when he happened to glance at the URL.

There was something very, very wrong with it.

“PHARMING” TO FLEECE SHEEP

The art of “pharming” involves setting up an illegitimate website that is identical with its legitimate prototype, for example the ebay page Bob was almost suckered into using, and redirecting traffic to it.

“Pharmers” can do it in two ways:

1.By altering the “Hosts” file on your computer. The Hosts file stores the IP address of websites you have been accessing. By inserting a new IP address into the database field corresponding to a website, your own computer can be redirected to the pharmer's website. Any information you give the bogus site is immediately hijacked by the pharmer.

2.Hijacking the DNS (Dynamic Name Server) itself. A DNS matches the names of address with their IP addresses. If this server can be coerced into assigning new IP addresses to traditional names, all computers using the name resolution provided by the DNS server will be redirected to the hijacker's web site.

Once that happens, it's time to be fleeced.

DOWN ON THE PHARM

“Pharmers” hijack your “hosts” file or DNS servers using Spyware, Adware, Viruses or Trojans. One of the most dangerous things you can do is to run your computer without some form of Internet Security installed on it.

Your security software should be continually updating its virus definitions, and be capable of warning you if something has been downloaded from a web site or through email. It should be able to remove it, “quarantine it”, or tell you where it is so that you can remove it by hand.

You should also have Spyware and Adware programs installed, and be aware of any change in Internet browsing patterns. If your home page suddenly changes, or you experience advertising pop ups (which may pop up even when you are not hooked up to the Internet), you should run a Virus, Spyware or Adware scan.

Thanks to the efficacy of these protection programs, pharming is a lot more difficult than it used to be. It isn't as easy to hijack a computer as it once was.

So, the “pharmers” have teamed up with the “phishermen” to get you to visit the bogus web page yourself, and enter all the information they need.

PHISHING TO CATCH YOU ON THE PHARM

As Bob discovered, the page he had been taken to by the bogus email message was identical to the ebay logon page. Identical in every way except for the URL.

Out of curiosity, he checked the URL for the ebay logon by accessing ebay directly and clicking on the logon link. The two URL's were nothing alike, except the bogus one did have the word “ebay” in it twice – just enough to make it look authentic.

By combining the two techniques, the phishermen/pharmers had avoided the high tech problems associated with downloading a Virus that could get past his protection software. They had gone straight for the throat.

Bob's throat.

YOUR ONLY REAL IDENTITY THEFT PREVENTION AND PROTECTION

The only real protection against the pharmers and phishermen is YOU. There are three things you must consider when you read any email demanding information:

• Why do they want it? Be extremely skeptical when they say they have to “update their records”, “comply with federal regulations”, or prevent fraud. They are the ones initiating the fraud.

• Why can't this be done at the website? Why not invite you to access the website directly and provide this information? The answer is because the bonafide company doesn't need an update.

• What does the URL look like? Is it a series of subdomains some of which have the name of the bonafide company? Most likely the subdomain is set up with a free hosting company.

• Have they provided partial information about you as a guarantee that the email authentically comes from the legitimate source? Be very careful of this one. This technique is effective for “pretexting”, impersonating a person or company, and was used in the Hewlett Packard scandal to collect information. Just because they know your first and last name (and any other information – known only to the legitimate source) doesn't mean the email is legitimate. They probably hijacked the information off the server.

THE BOTTOM LINE

The bottom line is: don't provide any information at the behest of an email, no matter how authentic it looks, or how authentic the page it directs you to looks. If you must log in, do so at the parent site itself.

Your Identity Theft prevention and protection is, in the final analysis, up to you.

Don't be the next sheep fleeced by the pharmers who caught you with the phisherman's hook. Being dropped naked into their frying pan is NOT a fate you want.


Tags: Identity Theft, Phishing, Pharming, Identity Protection Theft, Identity Prevention Theft, Web-hosting

Will Your Business Be A Victim Of Identity Theft?

Identity theft is the world's fastest growing crime. In the US alone, there are 27,000 identity theft victims daily. It's likely that a high number of these victims include businesses of all sizes. If Microsoft or Wal-Mart loses customer data to identi

What You Need To Know About The Statistics On Identity Theft

There is actually much different information that you need to know about when it comes to the statistics on identity theft, and if you understand how big of an issue identity theft is nowadays, than you thus surely understand how important it is to know a

Retail News - Stopping Thieves In Their Tracks With 8 Easy Steps

Stopping thieves start with you and starts with me. As a retailer, you are responsible for also protecting your clients and consumers. Learn how to stop one of the quickest growing crimes in America – identity theft. According to a recent study complied

Protect Yourself From Identity Theft Online

When identity theft online happens, it can be several months before you are aware that anything has happened. This makes it much more dangerous than other types of theft. If someone steals your wallet, or your car, you notice it immediately, and can start

Protection Against Identity Theft

Identity theft is growing online and off. In fact, there are many types of identity theft. The most misused types are: • The fraudulent use of someone else's credit card • The fraudulent use of someone else's bank account • The fraudulent use of identi

Phone Verification Fights Phishing

Phishing (http://en.wikipedia.org/wiki/Phishing) is a kind of fraudulent activity focused on theft of private information. Such crimes are generally based on different methods of Social engineering (http://en.wikipedia.org/wiki/Social_engineering_(compute

Paypal Users: Don't Get Caught By Phishers

There is a rising trend in Paypal phishing scams. The latest Paypal spoof I received warns me that my Paypal account has been suspended. It asks me to restore full access to my account by logging in to Paypal. When I click on the link provided in the emai

Outsmart Fraudsters And Protect Your Identity

One of the most frustrating aspects of Internet Marketing is born in the WHOSITS database. This database, owned by Google, lets anyone see the information submitted when a small business owners purchases a domain name. Unfortunately, anyone can gain acc

More Identity Theft Solutions

Identity theft is on the increase. It is one of the more serious threats to internet users today. Keeping your internet security software updated, and following these common sense identity theft solutions will help you reduce the threat and keep you safe

Illegal Workers And Identity Theft

Identity theft is a growing problem throughout the United States and the world. As many as nine million people in this country will have their identities stolen every year. One source of identity theft, although not the only one, is the practice of illega

Identity Theft Website: Knowing Your Rights

Identity theft is a crime wherein another person obtains your personal data and uses this information in any act involving deception or fraud, such as shopping for online goods and other financial loses without your authorization. To know your rights and

Identity Theft Prevention

Once again, there have been more instances of Identity Theft, as a result of unsecured networks, greedy employees and contractors, and lost or stolen laptops. More people have had their personal information compromised, and now currently live in the possi

Identity Theft And The Internet: How Not To Be A Victim

Identity theft is a growing problem that has reached worldwide, astronomical proportions. Internet identity theft is on the rise and can have a huge, detrimental affect on your life by destroying your credit score and even leaving you open to criminal cha

Identity Protection Online - Seven Tips For Password Protection

There are thieves everywhere and the Internet has its fair share of bandits of all types. The most frightening and potentially dangerous thief is the identity thief. An identity thief can go beyond stealing the contents of your bank accounts or running up

How To Surf The Web Without A Trace

There are many reasons someone would want to surf the internet anonymously. Many people think that internet privacy is only for those trying to hide something, but that simply is not the case. Internet privacy is essential for normal people like you who v