Showing posts with label Spoofing. Show all posts
Showing posts with label Spoofing. Show all posts

Monday, November 2, 2009

Phising Definition, Concept and Techniques

What is phishing

Phishing, also known as "brand spoofing", is an elaborate form of data theft, targeting possible clients of ISP companies, banks, online banking services, government agencies etc.

When submitting your email address on the Internet, filling in online forms, accessing newsgroups or websites, your data can be stolen by Internet crawling spiders and then used without your permission to commit fraud or other crimes.

The Phishing Concept

Phishers develop counterfeit webpages, which imitate the corporate image of well-known, trusted service providers. Then, using collected or random generated email addresses, they "throw the bait".

Sunday, November 1, 2009

How the Web Spoofing Attack Works

URL Rewriting

STEP I
# A Phisher could insert a malicious script inside a product review to attack the user.

# The Script would modify the host site so that the user believes he/she is interacting with secure site. this technique is also called as “Cross-Scripting.”

STEP II
# This done by using encoded characters to hide the destination address of a link.
Ex-“abc” = "abc”

Web Spoofing Attack

Web Spoofing is Tricking Someone into visiting a Website other than one they intend to visit , by creating a similar website. Web Spoofing is a Phishing Scheme.

The attacker must somehow lure the victim into the attacker’s false web. there are several ways to do this.

# An attacker could put a link to false Web onto popular Web page.
# If the victim is using email, the attacker could email the victim a pointer to false Web.
# Finally, the attacker could trick a web search engine into indexing part of a false Web.

Wednesday, October 28, 2009

What is Email spoofing?

Email spoofing and what can be done about it. Examining solutions such as the Sender
Policy Framework (SPF) and Microsoft’s Sender ID, which is based on it are some of the solutions to this problem.

E-mail spoofing is forgery of an email header.(Header is the part of a message that
describes the originator, the addressee and other recipients, message priority level,
etc.) The message appears to have originated from someone or somewhere other than the
actual source. While spoofing can be used legitimately., using by anyone other than yourself is illegal in some jurisdictions.

Sunday, October 25, 2009

Computer crime - Forms of Attack

The growing economic value of information, products, and services accessible through computer systems has attracted increased attention from opportunistic criminals. In particular, the many potential vulnerabilities of online systems and the Internet have made computer crime attractive and pose significant challenges to professionals whose task it is to secure such systems.

The motivations of persons who use computer systems in unauthorized ways vary. Some hackers primarily seek detailed knowledge of systems, while others (often teenagers)
seek “bragging rights.” Other intruders have the more traditional criminal motive of gaining access to information such as credit card numbers and personal identities that can be used to make unauthorized purchases (see identity theft). Computer access can also be used to intimidate (see cyberstalking and harassment), as well as for extortion, espionage, sabotage, or terrorism (see cyberterr orism).