Posts Tagged ‘phishing’

Phishing = fishing + phreaking

I was reading this article Phishing ANZ customers and so I started to think more about phishing and doing a bit of research on the past “phishing classics”.
Now, I am not a security engineer, so dont expect me to give you all the security tips and tricks. When I was in my first days of college, I always wanted to become one. May be one day I will get there. I was very much impressed by firewalls. Infact I even did a tech-talk on that topic.

So, to keep ourselves restricted to the scope of this post ;) ‘phishing’ , which the term might have arised from fishing + phreaking, means impersonating something/someone else and tricking customers for financial advantages or to obtain user credentials.
Phishing
Phishing can be done in different ways, for example the news article that I have referred to in SMH speaks about a technique where the users get an email with some text and a link. The email content usually will give a legitimate impression to the user. The link will be to a site that impersonates the original site (in this case ANZ) and might request the user to login and thus can get the user credentials. In ANZ instance, the email went around to the bank customers and it contained a link to a site whose url, look and feel and content was very similar to the ANZ’s. It had login prompt where the users entered their customer number and their pin. So the phishers now got access to this sensitive data!!

Phishing techniques include using a seemingly legitimate link text or impersonating the look and feel of the site along with its url. After a few anti-phishing techniques have been developed to identify the most common phishing link text, many of the ‘phishers’ started using images to overcome them.

Read the rest of this entry »