Welcome to the EZIB Network
Home  - Item Index  - Identity Theft Site Map  - Contact Us  - Dummy Proof Investing
 



Identity Theft And Pharming - A New Twist On An Old Theme


                                                                               



Identity Theft And Pharming - A New Twist On An Old Theme

Identity theft is big business and, like it or not, the likelihood that you will become a victim is increasing. As the Internet and its popularity have grown, the number of unscrupulous operators out there has grown as well. There are so many scams and attack methods out there it is difficult to keep up with them.

One of the identity thief's more productive techniques is phishing. A phishing scam is one where an email message contains a link to a web site that asks for personal information. The scam uses social engineering to trick people to go to a web site they would not normally visit. A common scam is one in which an email that looks like it has come from a bank or credit card company asks you to "click on this link" to update your user information. There is generally a part of the email that tries to convey a sense of urgency to get you to "do it now". When you click on the link you are actually forwarded to a thief's web site that is designed to look like your bank or credit card company's web site. You are then asked to provide information, such as user id, password, and other identifying information. Identity thieves use this information to open or use credit accounts and steal money from unsuspecting consumers.

Phishing attacks are relatively easy the spot and avoid. Never follow links in email messages unless you know the link is valid. Compare the actual link address with the text you see. If you are expecting to go to PayPal.com, make sure the link really takes you there. You can view the hyperlink before you click on it buy pointing your mouse cursor at the link. Most email clients and web browsers will show you what the actual address is before you click on it. If the address doesn't match the web site address you expected to see, don't click on the link. Likewise, NEVER provide any personal information from an unsolicited source. You will also see the address you are visiting in your web browser's address bar. Make sure you are visiting the site you expect.

There is a new trend in identity theft, called pharming. Well, it is actually a fairly old type of attack put to a new and alarming use. The basic attack generally relies on DNS poisoning or domain spoofing. The difference between phishing and pharming is that while phishing targets individuals, pharming targets large groups of people. Before we get into a discussion of a pharming attack, let's look at a short primer on how Internet addresses work.

Anytime you type in an address in your web browser, such as http://www.somecompany.com, your computer needs to find the Internet Protocol (IP) address before sending any information. There are two main methods for finding IP addresses for web site addresses. The legacy method consists of a file, called the 'hosts' file, that lists all of the host names you may want to visit, along with their IP addresses. The other method is to send a name resolution request to a Dynamic Name Server (DNS). The DNS server looks up the address in its database and returns the corresponding IP address. Once your computer looks up the IP address for http://www.somecompany.com, it then uses the IP address for all further communication.

A pharming attack is one where the host file or DNS entry is modified to send users to a counterfeit web site. The slightly simpler of the two attacks is the host file modification. This can be accomplished with a virus or worm. It is generally harder to compromise DNS servers. With the phishing attack, a careful view of your web browser's address bar will show that you are visiting a site you did not expect. Pharming attacks are more difficult to detect since your web browser tells you that you are at the right site even when you really aren't.

The effect of a pharming attack is that all users who want to go to a particular site end up being redirected to a thief's site. While this might sound similar to a phishing attack, it can be much worse. There is no indication to the end user that a redirect has occurred. The web browser still shows the original web address. This behavior makes pharming attacks more difficult to detect. Also, if the thief is able to change DNS entries on a commonly used DNS server, all users who request IP addresses from the compromised server will be sent to the counterfeit site.

So, how do you protect yourself from a pharming attack? Much of the work in stopping pharming attacks is up to the DNS administrators. They will be responsible for ensuring any DNS entry changes are authentic. But, there are some steps you can take. Following these guidelines will reduce your chances of becoming a pharming victim:

Install and update a good anti-virus program. Since many attacks start as malicious software, protecting your system from viruses and other malicious software will go a long way toward stopping an attack before any information is changed.

Protect your 'hosts' file. On Windows operating systems, the hosts file resides at: (assuming C:\Windows is where your OS installed) C:\Windows\system32\drivers\etc\hosts. On Unix systems, it resides at /etc/hosts. You can manually check your hosts file to ensure no unusual entries have been put there or you can install software shields that watch the hosts file for you (along with anti-virus software).

Know the sites you visit and carefully protect any information you give out. Never divulge any information for any reason unless you are absolutely certain the information is necessary and you are providing it to the correct organization. If your bank web site, or any other web site, asks you to provide confidential information, call their customer service department to get confirmation that the information is needed. Don't call the number on the web site (it may be compromised). Look up the number in the phone book or use directory assistance.

As more and more web sites start using digital certificates to authenticate their identities, you will begin to see more popup windows asking you to accept these certificates the first time you visit the web site. Always read the certificate details and ensure the web site really is the one you wanted to visit. If you are unsure, reject the certificate.

We will all hear more about pharming in the coming months. Its use is growing. This is just another opportunity to remind as many people as possible to be careful with the sites you visit and the information you give out. Protect your personal information. Not doing so can be very expensive.


About the Author: Michael G. Solomon is a security speaker, consultant and author who specializes in assessing and fixing security vulnerabilities. Michael has written several security certification, security education, and project management books and offers more educational materials at http://www.thesecurityguy.net.

Source: www.isnare.com



Other Identity Theft Items of Interest:

Prevent Identity Theft - Itna Yeknom
Preventing Identity Theft Alas, it's not possible to prevent identity theft and credit fraud entirely. However, by managing your personal information carefully, and with a full understanding of its importance, you can substantially reduce the...
Identity Theft: Count The Ways - Daryl Campbell
I received an e-mail message from "Paypal" not to long ago. The e-mail stated that PayPal needed me to update and verify my security information for their database. I didn't. One of the sentences in the e-mail read: "Complete the necessary...
Identity Theft Scams Exposed - James Dimmitt
none Identity Theft Scams Exposed, Part I by James H. Dimmitt FACT: It takes 14 months, on average, before an Identity theft victim realizes their identity has been stolen. Therefore it’s important that you be aware of scam artists...
New Bankruptcy Law Will Not Protect You from Identity Theft - Charles Essmeier
Recently passed by Congress with overwhelming support, the oddly-named Bankruptcy Abuse Prevention and Consumer Protection Act was designed to eliminate “bankruptcy of convenience.” The perceived problem is that many compulsive gamblers, shoppers...
9 Sensible Steps To Prevent Identity Theft BEFORE It Happens - Marige O Brien
Unfortunately, identity theft has become the crime of the new millenium. Though credit card companies and various agencies work to prevent it, it is, ultimately, the responsibility of each individual to take their own precautionary measures...
Fighting Identity Theft - James H Dimmitt
Chances are good that you know someone who has been victimized by the fastest growing crime - identity theft. The Federal Trade Commission (FTC) reported that there were 10 million cases of identity theft in 2002 alone. It’s estimated that...
Identity Theft - Is your business at risk? - Juditnh A Wentzel
More and more business owners are purchasing document shredders then ever before. Why?... Identity theft for starters. A new law is going into effect in the summer of 2005 which states that if you employ anyone for any reason and have personal...
Phishing - What It Is and How to Avoid Identity Theft. - Angela Daley
Phishing is a term used to describe a type of spam that aims to steal your identity. It can be attempted through email, instant messages, or pop-up windows. Phishers seek to convince their potential victims to provide personal data such as credit...
Protect Yourself Again Identity Theft - Yvon Marier
1. Only print your initials and last name on your personal cheques. If you prefer, put your cell number instead of your home phone, and P.O. Box instead of your street address. Your bank has all your information and knows how you sign your cheques....
Identity Theft...Will It Destroy Your Business? - Steve Graham
"Wow, I never charged $8,000.00 for 10 lbs of Beluga Caviar." That's right pal, someone else did. Hey, did they nail you for wine to go with the caviar? One of the fastest growing crimes in America is Identity Theft. Victims come from a...
Identity Theft: Dont Be A Victim! - Nathan Dawson
Moments after stepping out of the taxi, Rachel plunged through the entranceway of the hotel lobby eager to put behind what had been a terribly exhausting day. Flight delays due to weather had caused her LAX-MDW-BWI trip to take nearly eleven...
Identity Theft - Don't Blame The Web - Hamish Hayward
Identity theft - also known as ID theft, identity fraud and ID fraud - describes a type of fraud where a criminal adopts someone else's identity in order to profit illegally. It is one of the fastest growing forms of fraud in many developed...
Identity Theft: It Can Happen to You! - Stephen Bucaro
---------------------------------------------------------- Permission is granted for the below article to forward, reprint, distribute, use for ezine, newsletter, website, offer as free bonus or part of a product for sale as long as no changes are...
Consumer Advice What is identity theft? - NC
(NC)—Identity theft occurs when someone uses your personal information without your knowledge or consent to commit a crime, such as fraud or theft. Once they steal the information and manipulate it, identity thieves can invade your...
Identity Theft and You - Rosanne Dausilio Ph D
ľ Do you supply personal information over the internet? ľ Do you use your credit card online? ľ Do you hand your credit card to servers at restaurants? ľ Do you carry your social security card in your wallet? According to the F.B.I. and...
Security Issues And Ways To Prevent Identity Theft - Julian Pereira
Everybody should be concerned about identity theft, which is a growing concern, that society has to face with the growth of the internet and related criminal activities. Find out how Identity Theft can be Prevented. Identity theft, is a...
How To Protect Yourself Against Identity Theft - Mike Nalbone
Identity theft is a serious crime that continues to grow. If you become a victim of identity theft, you may spend months, or years, trying to repair the damage. A compromised credit report can ruin your chances of getting a new job, a loan,...
Identity Theft Problem Solution - Mark Freink
We live in an information-oriented society. Technology allows us to do business and make transactions literally in a matter of seconds. This abundance of information has given rise to a new crime - identity theft. In fact, according to a 2003...
10 Tips To Reduce Your Exposure And Prevent Identity Theft - G L Bycz
Identity theft is the country's fastest-growing financial crime. The Federal Trade Commission estimates that 27.3 million Americans have been victims of identity theft in the past 5 years, including 9.9 million people last year alone. Some...
Identity Theft – Who Would Want Mine? - Steve Mueller
With all my bills who would possibly want my credit? Let them steal my identity and pay my bills! Unfortunately, that’s not the way it works. Many of us mistakenly believe that identity thieves hit only the wealthy. Nothing could be farther...
Identity Theft - Your Prevention Guide - Debbie Pettitt
Identity theft occurs when someone illegally obtains your personal information (social security number, credit card numbers or some other personal information) and uses that information to apply for loans or credit cards under your name or to make...
Identity Theft Exploding: Here’s How you can Avoid Becoming a Victim - Plus, Tips if you do Become a Victim - Steven Presar
Americans are more concerned about identity theft than unemployment or corporate fraud, according to a survey of 2,000 people conducted by Star Systems. Nine out of ten Americans demand new federal legislation, while two-thirds say the...
Identity Theft - Don't blame The Internet - Hamish hayward
Identity theft – also known as ID theft, identity fraud and ID fraud – describes a type of fraud where a criminal adopts someone else’s identity in order to profit illegally. It is one of the fastest growing forms of fraud in many developed...
How to identify Spoof/Phishing emails - Protect yourself from identity theft. - Dan Thompson
What is a spoof email? Spoof emails (sometimes also called "Phishing") are emails that pretend to be from a company or bank. The most common often come from eBay, PayPal, Barclays Bank etc. These emails will then contain a web link, if you click...
STOP Thief!: 10 Practical tips to avoid credit card identity theft. - Gunnar Berglund
Identity thieves are your modern-day robbers. They take your personal information and use it for their personal gains. It's shocking to know, that although there is a federal law against it, some states do not have a local law. Consequently, it is...
How You Can Avoid Becoming A Victim Of Identity Theft - Alex Katz
To reduce or minimize the risk of becoming a victim of identity theft or fraud, there are some basic steps you can take. The most important one is to ask periodically for a copy of your credit report. This is crucial because it is the surest...
Credit cards and identity theft - Gunnar Berglund
As more and more Americans become reliant on credit cards in their daily life, identity theft is growing. Identity theft is when someone uses your personal information without permission. They can obtain credit or use your existing credit to put you...
Identity Theft - Straightening Out Your Credit In The Aftermath - Debbie Pettitt
FBI statistics reveal that identity theft is one of the fastest-growing crimes in the United States, with about 1 in 5 families in the U.S. being a victim of identity theft. Identity theft is obtaining another person's personal information...
19,178 Identity Theft Victims Per Day - Are You One Of Them? - Andrew Obremski
Identity theft statistics are shocking. And we are told that it will only become worse, before it gets any better. Are you likely to be affected? According to recent studies, up to 7,000,000 people become identity theft victims each year, in...
Identity Theft. You are not Immune. - David Wilding
As identity theft becomes more prevalent, the need to regularly check your credit report is very easy to see and understand. Two big headlines in the news recently point to how closely tied your credit report and identity theft are. First, we hear...
Minimize your Risk for Identity Theft - Jeffrey Broobin
Identity theft is the fastest growing crime in America. According to the Federal Trade Commission, the number of identity theft incidents reached 9.9 million in 2003. These crimes are estimated to have taken the average victim $500 and 30 hours...
The Business of Identity Theft - Tim Knox
Q: I use PayPal to accept credit cards for my online collectibles business. I recently received an email that my PayPal account was going to expire in five days if I didn't click a link in the email and give them my PayPal account information....
Surviving Website Identity Theft - Greg Scowen
Every now and then you read about identity theft. I am not talking about the theft of you personal identity, sure that happens too, I am talking about the theft of a website’s identity. The big question is: What should you do if somebody with deeper...
How To Protect Yourself From Identity Theft - Gary Gresham
While nothing is ever foolproof you can learn how to protect yourself from identity theft. Identity theft is the fastest growing crime in America today with victims reporting new cases to authorities at an alarming rate. Last year alone in 2004,...
Home Refinancing Scam – Thieves Use Identity Theft to Steal Your Equity - Charles Essmeier
Since the demise of the stock market in 2000, the real estate market has been booming. Investors who are justifiably cautious about investing in stocks have been investing in homes. This has driven the prices of homes in the United States to record...
Protect Yourself From Identity Theft As An Online Degree Candidate - Joyce Jackson
As degree candidates in standard programs there is campus training every semester on personal safety and how to get around campus at night. As an online degree candidate you do not have those concerns but you do have identity theft. Identity theft...
Identity Theft - Protect Yourself - Chris N Fernando
First things first—be responsible and act fast! Don’t just sit there with your head buried into your hands as if the world just ended. Protecting yourself from identity theft takes proactive effort. Also, don’t be under the impression that Identity...
Identity Theft – Monitor Your Credit Report - Charles Essmeier
The recent security breach at credit card processor CardSystems Solutions has many consumers worried. Thanks to a well-placed computer virus, nearly forty million credit card numbers were stolen, and cardholders nationwide are justifiably concerned...
Sole-Proprietors, Prevent Identity Theft - Ellen Zucker
Obtaining an EIN or employer identification number is a good idea if you are a sole-proprietor. From time to time, you'll be asked to provide your social security number or employer ID to clients or governmental agencies. Once you do that you have...
10 Steps to take if you are a Victim of Identity Theft - Michelle Dunn
What can I do if I am already a victim of ID theft? • Contact the fraud departments of the three major credit bureaus, to place a fraud alert on your credit file. • Close all accounts that have been affected and request copies of fraud-dispute...



5 Simple Steps To Protect Yourself Against Identity Theft
Preventing Online Identity Theft
Protect Yourself From Identity Theft As An Online Degree Candidate
Identity Theft Protection Prevention Prevent ID Internet Fraud
Identity Theft A crime too personal
Identity Theft The Perfect Victim Your Child
How To Protect Yourself Against Identity Theft
Identity Theft The Internet
Identity Theft Is your business at risk
How did a Thief get my Name Don t be a Victim of Identity Theft
Identity Theft Oh No Not Them
Credit Repair for Identity Theft Victims
Identity Theft Scams
Surviving Website Identity Theft
Identity Theft Protect Yourself
15 Ways of reducing the risk of identity theft
Identity Theft Prevention
Identity Theft Is The Internet A Major Factor
Identity Theft Monitor Your Credit Report
How To Avoid Becoming A Victim of Identity Theft
19 178 Identity Theft Victims Per Day Are You One Of Them
Small Business Q A Don t Fall For The Latest Internet Identity Theft Scam
Identity Theft OR Will The REAL Me Please Stand Up
Identity Theft R R
Identity Theft Part 1
Identity Theft 10 Simple Ways to Protect Your Good Name
Fighting Identity Theft
Identity Theft
Identity Theft And The Internet
Identity Theft Scams Exposed
Home Refinancing Scam Thieves Use Identity Theft to Steal Your Equity
Identity Theft Is Investigated By The Department Of Justice
A Personal Experience with Identity Theft
Identity Theft Scams Exposed Part II
Identity Theft Shield
Identity Theft Exploding Here s How you can Avoid Becoming a Victim Plus Tips if you do Become a Victim
40 Million People Hacked YOU as Identity Theft Victim
10 Tips To Reduce Your Exposure And Prevent Identity Theft
Identity Theft Even After You Die
Identity Theft Don t blame The Internet


 
 
 
© 2012  EZ - Internet-Business Network.  All Rights Reserved
Home | Item Index | Identity Theft Site Map | Contact Us | Dummy Proof Investing