Fropper.com - no one's a stranger
Already a member? Login here  | Tour | Help  
in


Sharing knowledge enhances ones knowledge and happiness.



Posted on: Oct 19, '08


 WHAT IS PHISHING ?


Phishing is a common form of Internet piracy. It is deployed to steal users' personal and confidential information like bank account numbers, net banking passwords, credit card numbers, personal identity details etc. Later the perpetrators may use the information for siphoning money from the victim's account or run up bills on victim's credit cards. In the worst case one could also become the victim of identity theft. A few customers of some other Indian banks have been affected by the attempt of phishing during the early 2006. Even the most high-tech phishing scams work like old-fashioned con jobs, in which a phisher convinces his mark that he is reliable and trustworthy Since most people won't reveal their bank account, credit card number or password to just anyone, phishers are taking extra steps to trick their victims into giving up this information. This kind of deceptive attempt to get information is called social engineering. 

I  would like you to be aware of methodologies in a 'Phishing' attack, do's and don'ts in sharing of personal information and the action to be taken in case you fall prey to a phishing attempt.

Methodologies:

Phishing attacks use both social engineering and technical subterfuge to steal customers' personal identity data and financial account credentials.

1.Customer receives a fraudulent e-mail seemingly from a legitimate Internet address. 

2.The email invites the customer to click on a hyperlink provided in the mail.
3.Click on the hyperlink directs the customer to a fake web site that looks similar to the genuine site.
4.Usually the email will either promise a reward on compliance or warn of an impending penalty on non-compliance.
5.Customer is asked to update his personal information, such as login ID, passwords and credit card and bank account numbers etc.
6.Customer provides personal details in good faith. Clicks on 'submit' button.
He gets an error page or redirects to Bank’s genuine site after capturing the details given.
Customer falls prey to the phishing attempt. 

Don'ts:

1.Do not click on any link, which has come through e-mail. It may contain malicious code or could be an attempt to 'Phish'
2 If you get an e-mail that you believe is a phishing attempt, You do not reply to it .
3. Do not click on the links provided in the mail.
4. Do not provide your personal information.
5. Do not provide any information on a page, which might have come up as a pop-up window.
6. Never provide your password over the phone or in response to an unsolicited request over e-mail.
7. Always remember that information like password, PIN, TIN, etc are strictly confidential and are not known even to employees/service personnel of the Bank. You should therefore, never divulge such information even if asked for.
8. Avoid using cyber café / public PCs for logging into financial web sites. 

Do's:

Bookmark genuine web site and always logon to a site by selecting the saved bookmark.
Give your user Id and password only at the authenticated login page.
Before providing your user id and password please ensure that the page displayed is an https:// page and not an http:// page. Please also look for the lock sign ( ) at the right bottom of the browser and the certificate from the verification authorities.
Provide your personal details over phone/Internet only if you have initiated a call or session and the counter party has been duly authenticated by you.
Please remember that bank would never ask you to verify your account information through e-mail. 

What to do if you have accidentally revealed password/PIN/TIN etc:

If you feel that you have been phished or you have provided your personal information at a place you should not have, please carry out following immediately as a damage mitigation measure.
Change your password immediately from a secure desktop. If you use the same password at other sites, it is suggested you to change your passwords there, too.
Report to the bank/service provider by mailing them immediately at their address/website.
Check your account statement and ensure that it is correct in every respect.
Report any erroneous entries to Bank/service provider immediately. 

Only you can take care of your own interests. Please take care.



Tags:




Comments  [ 15 Comments ] [ Post your comment | Subscribe (?) ]


Send MessageOfflineScrap

deeepaksirohi said:
how can we change the password for fropper's account and how can i delete my account

December 29, '08


Send MessageOfflineScrap

sazzyme said:
informative stuff indeed! thanks CBji.

October 21, '08


Send MessageOfflineScrap

Gor123 said:
very important information my dear.

October 20, '08


Send MessageOfflineScrap

Priya5547 said:
Very informative. thanks for sharing

October 20, '08


Send MessageOfflineScrap

magsvir2000 said:
tnx 4 sharing

October 20, '08


Send MessageOfflineScrap

nisha264 said:
nice information.
thanks.

October 20, '08


Send MessageOfflineScrap

nandya said:
thanks for ur valuable info. friend


October 19, '08


Send MessageOfflineScrap

mikunal said:
nice information.
thanks.

October 19, '08


Send MessageOfflineScrap

ashokthakur said:
informative post
thanks for sharing

October 19, '08


Send MessageOfflineScrap

astrologychat said:
Oh.My incredible Vishu..You Hammered the nail on right spot.
yes Its become a global menace..and none is immune of this hazard.
Your information wil go a long way in imparting right education to fellow Buddies..
Great post.
Keep it up..


October 19, '08

Want to comment on this post?

Register now, its FREE, and share your views.
Already a member? Login now.