Advertisement
Promo

Security management Toolkit

Toxic phishers scam the unwary

David Berlind ZDNet.com

Published: 12 Jan 2004 15:55 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Users can achieve some success in shutting down suspect pages. When I contacted eBay's public relations department about one of the PayPal phishers that had come my way, the company asked me to file the report to the email address spoof@ebay.com , where it collects all reports of this nature. About two weeks passed between the time when I first received the email and when I finally forwarded the email and its header to that address. During that entire time, the page remained active. Within 24 hours of filing the report, I received a reply from eBay confirming that the page was fraudulent and that the company had taken action. To no avail, I tried to return to the offending page with my browser. EBay obviously has some clout. When I asked for more details about its process for handling my report and whether EBay would try to track down the bad guys, the company refused to comment. According to Jevans, this is not uncommon. Although the Anti-Phishing Work Group has a blue-blooded membership consisting of major financial institutions and Fortune 500 companies, most of them would just as well assume not be mentioned in stories that have to do with phishing.

"On the technology front, since phishing is spam, the same tools to combat spam such as Web and email filtering are one approach," Jevans said. "But we also recommend that companies regularly scan the DNS to see if domains with a close resemblance to their own are being registered. When Visa was targeted last month, the phisher used the domain visa-security.com. Also, banks are starting to digitally sign their emails, which in turn requires that end users be educated on how to discern between an email that's been legitimately signed and one that's not."

From a social perspective, education is key. For example, users need to be schooled on how to spot fraudulent mail and what to do about it. Whereas eBay has a process in place, other institutions may not. Jevans said anyone can file a phishing report at www.antiphishing.org.

Companies that are interested in developing an acute awareness of the phishing problem could benefit from joining antiphishing.org. The members share intelligence and ideas on how to deal with the problem. The organisation is also associated with several other prominent industry working groups. Jevans said membership is open to businesses that pass the organisation's litmus test (to keep phishers from getting inside), and that its next confab is in New York City on 29 January.

Oh, and if you go, be sure to hang a sign on your office door that reads "Gone Phishin'. " At the very least, your co-workers will ask what it means and thus, the education process within your company can begin.

Next

Previous

1 2 3


  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
229 out of 431 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:



Video icon

Video

Sentry Posts Blog

Official Organizations Losing Data

How does this article from earlier today make you feel? How many more government, health service, or military officials are going to lose pen drives, DVDs, USB hard disks and even entire... More

2 comments

Twitter hack was DNS redirect

Twitter has said an attack on Thursday which took the site offline for many users was the result of a DNS redirect. A group calling itself the Iranian Cyber Army redirected users... More

1 comment

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Win a Teufel Cinebar 50 system

Win a Teufel Cinebar 50 system

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters