Phising. What is it and how to identify

nick_ro

Beta member
Messages
5
Phising is a technique used by hackers to steal your own private data like user accounts and passwords or card data. For example let's say you have purchased a premium account to a file-storing site like rapidshare or filesonic. The hacker will try to steal your login and password by creating a fake login page of that site. He copies the source code and changes it a little bit, then he is sending it to others or post on forums pretending that he shares with you a file. When you click the link you are redirected to the fake login page and it asks for you to introduce your login and password. These information are sent afterwards to a server which is hosted by the hacker.

So in order to protect yourself from these kind of attacks, always check the URL of your file that you are downloading. It must be turned green or display a lock for security purposes, if you suspect anything do not download.




The area that I slightly highlighted shows the name of the server where hacker is sending your login and password.
 
Well, your screen shows an extreme phishing case. Obviously looks that it's fake ;) Trusted websites should look this way:
pp_hwnepnn.jpg

We can see certificate near the address box. Also there is real address, not any strange domains etc.
 
That's why I always type the address in the URL box instead of going there by google search etc. as there are lots of malware results on search engines nowadays.
 
In some cases, even with the right domain address in the URL bar, you could still get phished...
The most popular way to do this is with XSS attack...
 
In some cases, even with the right domain address in the URL bar, you could still get phished...
The most popular way to do this is with XSS attack...

Yeah, that could also be.
But would that phishing site redirect you to your real account page after login or would it take you to a "dummy" page?
 
Back
Top Bottom