Monday, September 2, 2013

Protection from Phishing Attacks

When user receives an e-mail asking him to visit his bank’s web site, it signifies the beginning of a phishing fraud. The e-mail would usually provide a link to bank’s web site and ask the user to click the link. It would ask him to provide certain confidential banking information like his account number, credit card number etc., failing which his account would be doomed. There would be a sense of urgency and panic in the e-mail. This type of attack is called as phising attack.

Here is a checklist which helps to prevent this type of attack:
Check to see if the e-mail is indeed from the user’s bank and not from just any bank. If it isn’t, stop reading further and confirm the same from the by using other means like telephone. If the e-mail is not personally addressed to the user, it is most probably a fraud. Check the language and spelling of the text contained in the e-mail. If the user find misspelled words or substandard language, conclude that it is not from his bank.
If the e-mail urges the user to act immediately without delay, failing which his account will be closed down, stop reading it. It is not from user’s bank. If there is anything that even remotely feels wrong, stop. If something feels wrong, it is most probably wrong. Never click any link given inside the e-mail message. Instead, directly type the URL of the financial institution. If the user does not know the URL of his bank’s web site, take the time to call them immediately to find out. User should never provide personal information to anybody, come what may.
 
Do not visit untrusted websites
It is always recommended that the user should not visit the untrusted websites or download software’s, screensavers or games etc from those untrusted sites. There is a possibility that these types of application software install some kind of malicious code on the user’s system, which can be used to launch attack
on other computer systems without any consent of the user.