<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
> <channel><title>gHacks Technology News &#124; Latest Tech News, Software And Tutorials &#187; social-phishing</title> <atom:link href="http://www.ghacks.net/tag/social-phishing/feed/" rel="self" type="application/rss+xml" /><link>http://www.ghacks.net</link> <description>A technology news blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description> <lastBuildDate>Sat, 11 Feb 2012 17:32:23 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <atom:link rel="hub" href="http://pubsubhubbub.appspot.com"/><atom:link rel="hub" href="http://superfeedr.com/hubbub"/> <item><title>Help the fight against phishing with Phishtank</title><link>http://www.ghacks.net/2009/08/24/help-the-fight-against-phishing-with-phishtank/</link> <comments>http://www.ghacks.net/2009/08/24/help-the-fight-against-phishing-with-phishtank/#comments</comments> <pubDate>Sun, 23 Aug 2009 22:13:48 +0000</pubDate> <dc:creator>Joe</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[anti-phishing]]></category> <category><![CDATA[antiphishing]]></category> <category><![CDATA[phishing]]></category> <category><![CDATA[phishtank]]></category> <category><![CDATA[social-phishing]]></category> <category><![CDATA[web of trust]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=15598</guid> <description><![CDATA[For anti-phishing tools to work, phishing sites must be identified to analyse and to warn people about. Sites like Web of Trust allow users to share information about phishing sites, but scores of similar tools exist and as it would be counter-productive for each to maintain their own database of phishing sites. PhishTank centralises phishing [...]]]></description> <content:encoded><![CDATA[<p>For anti-phishing tools to work, phishing sites must be identified to analyse and to warn people about.</p><p>Sites like <a
href="http://www.ghacks.net/2008/12/02/web-of-trust-collaborative-online-security/">Web of Trust</a> allow users to share information about phishing sites, but scores of similar tools exist and as it would be counter-productive for each to maintain their own database of phishing sites.</p><p><a
href="http://www.phishtank.com/">PhishTank</a> centralises phishing reports and allows developers to use their data free-of-charge in their own applications, with manual or automatic download enabled (although the latter requires a free API key).</p><p>PhishTank offers a service a lot of web users will use without even realising it. Whilst certain tools might submit their data to PhishTank too, you can help your fellow web users and fight phishers through submitting data directly to PhishTank.</p><p><span
id="more-15598"></span>With a free registered account, reports can be submitted through a web interface or through email. It is extremely easy to send the next phishing attempt that manages to get through your spam filters to PhishTank. Providing you have that email address registered with them, all you have to do it forward it to phish (at) phishtank.com .</p><p>Whilst it might not directly benefit you to do so, you are helping users who might help you too. If nothing else, you are keeping your credit card interest rate down marginally, as your bank has to pay less out to compensate phishing victims!</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2009/08/24/help-the-fight-against-phishing-with-phishtank/feed/</wfw:commentRss> <slash:comments>1</slash:comments> </item> <item><title>Introduction to new phishing techniques</title><link>http://www.ghacks.net/2007/02/16/introduction-to-new-phishing-techniques/</link> <comments>http://www.ghacks.net/2007/02/16/introduction-to-new-phishing-techniques/#comments</comments> <pubDate>Fri, 16 Feb 2007 07:59:54 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Hacking]]></category> <category><![CDATA[The Web]]></category> <category><![CDATA[flash-phishing]]></category> <category><![CDATA[hacker]]></category> <category><![CDATA[phishing]]></category> <category><![CDATA[social-phishing]]></category> <guid
isPermaLink="false">http://www.ghacks.net/2007/02/16/introduction-to-new-phishing-techniques/</guid> <description><![CDATA[Many users are still unaware of the dangers that phishing could mean for their life's. They might now that hackers try to lure unsuspecting users to fake websites hoping that their victims would try to supply login information, credit card details or social security numbers while trying to use the service. Those users already have difficulties identifying those first generation phishing websites that undoubtedly look and feel more professional with every passing day.]]></description> <content:encoded><![CDATA[<p>Many users are still unaware of the dangers that phishing could mean for their life&#8217;s. They might now that hackers try to lure unsuspecting users to fake websites hoping that their victims would try to supply login information, credit card details or social security numbers while trying to use the service. Those users already have difficulties identifying those first generation phishing websites that undoubtedly look and feel more professional with every passing day.</p><p>Anti-Phishing toolbars and implementations in the major browsers are useful but can, as you will see, give the user a false sense of security. This can be attributed to the fact that databases that contain the information are not updated in real time. Someone has to report a phishing website before it will be added to the database, it would be more than difficulty to create a automatic solution for this problem.</p><p><span
id="more-1209"></span> A second difficulty are new techniques used by hackers that are not detected by ant-phishing toolbars and implementations.</p><p><strong>Flash Phishing</strong></p><p>Anti-Phishing toolbars do check the page content for signs of phishing but do not analyze flash objects at all. Hackers know this and tend to use this to their advantage by using flash to emulate the original website. Users tend to believe that the site is &#8220;clean&#8221; because their anti-phishing toolbar did not react to it.</p><p>It is however relatively easy to find out if the current website is fake.</p><ol><li>You need to take a look at the url in the address bar. If it is not the original address leave it immediately.</li><li>Check if it is using https instead of http. If it is using http leave the site immediately.</li><li>If it is using https check the certificate.</li><li>If the site is only using flash leave it.</li><li>Never follow links in emails (unless you know the person)</li><li>Never follow links in chats (unless you know the person)</li></ol><p>You should immediately contact the supposed owner of the website and ask for advice.</p><p><strong>Social Phishing</strong></p><p>Phishers use other means of getting sensitive data from users. We all know that we should contact the company if we have doubts about a website. What if you would receive a mail from your bank asking you to call them back because there was a security breach ? Would you call them back ?</p><p>What if the number was redirecting you to someone in China speaking fluent English ? Would you give him the information he would be asking for to verify´that you are the customer ? Sir, we need to make sure that you are indeed our customer. Could you please supply your credit card information so that I can verify your identity ?</p><p>This is not a huge market yet but it will grow over time.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2007/02/16/introduction-to-new-phishing-techniques/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> </channel> </rss>
