<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Dave Hildebrand.com &#187; phishing</title>
	<atom:link href="http://www.davehildebrand.com/tag/phishing/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.davehildebrand.com</link>
	<description>The IT Crowd</description>
	<lastBuildDate>Fri, 25 Dec 2009 18:52:16 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Phishing: An Example</title>
		<link>http://www.davehildebrand.com/2006/09/01/phishing-an-example/</link>
		<comments>http://www.davehildebrand.com/2006/09/01/phishing-an-example/#comments</comments>
		<pubDate>Sat, 02 Sep 2006 01:20:58 +0000</pubDate>
		<dc:creator>Dave</dc:creator>
				<category><![CDATA[Tech Help]]></category>
		<category><![CDATA[email scams]]></category>
		<category><![CDATA[man in the middle]]></category>
		<category><![CDATA[phishing]]></category>

		<guid isPermaLink="false">http://www.davehildebrand.com/233/?p=20</guid>
		<description><![CDATA[Email scams have been around for almost as long as email has been widely used and the tricks these con artists use get more complex every day.&#160; Recently I had heard of a PayPal scam going around that is quite nasty. An email shows up in your inbox and asks you to confirm your account [...]]]></description>
			<content:encoded><![CDATA[<p>Email scams have been around for almost as long as email has been widely used and the tricks these con artists use get more complex every day.&nbsp; Recently I had heard of a PayPal scam going around that is quite nasty. An email shows up in your inbox and asks you to confirm your account details to secure your account and eliminate fraud on your account for good.&nbsp; To good to be true?&nbsp; I think so too.&nbsp; The scammer encourages you to click on a link within the email message that will take you to a website they have setup, that looks exactly like the PayPal login screen, where you enter your account user-name and password.&nbsp; Behind the scenes it copies your account info and logs you into PayPal so you think nothing is wrong.&nbsp; This is called a <a href="http://www.f-secure.com/weblog/archives/archive-082006.html#00000958" target="_blank">man-in-the-middle attack</a>.<span id="more-20"></span></p>
<p>Lets analyze an example of a phishing scam. The screen capture below shows the message in my inbox.</p>
<p><img src="http://www.davehildebrand.com/wp-content/uploads/2006/09/phishing01.JPG" alt="Phishing01" /></p>
<p>At first glance it looks like this could be a legit email, but look at the poor grammar (Account Informations !!!). This is hint #1 that this is a scam.</p>
<p><img src="http://www.davehildebrand.com/wp-content/uploads/2006/09/phishing04.JPG" alt="Phishing04" /></p>
<p>Next I hovered my mouse over the email address and it is not coming from PayPal but another, probable faked, email account.&nbsp; Hint #2.</p>
<p>I then opened the email and found a number of hints that this is a scam.&nbsp; I have highlighted them in red.</p>
<p><a href="http://www.davehildebrand.com/wp-content/uploads/2006/09/phishing02.JPG" title="Click to view the fullsized version" target="_blank"><img src="http://www.davehildebrand.com/wp-content/uploads/2006/09/phishing02.thumbnail.JPG" alt="Phishing02" /></a></p>
<p>Again you see that it is not from a PayPal address, the poor grammar, the extraordinary claims, a threat to cancel your account, another hint to a man-in-the-middle-attack, a helpful link to the account check page, and finally an errant bit of code (&nbsp;).</p>
<p>The final bit of evidence is the helpful link the scammer has provided.&nbsp; If you hover over it and look on the bottom Status bar (lower left of your browser) it will show the page that the link will take you.</p>
<p><img src="http://www.davehildebrand.com/wp-content/uploads/2006/09/phishing03.JPG" alt="Phishing03" /></p>
<p>It not even a page at PayPal. (Note: scammers will sometimes mask the location of their links, so beware)</p>
<p>As you can see this is one sneaky scam that could catch someone who does not take the time to scrutinize what they are reading.</p>
<p>My advice?&nbsp; Never, ever, under any circumstance click on a link from PayPal, eBay, banks, and any other financial institutions.&nbsp; Always type in the address into your browser or use a shortcut you have made and know is legit.&nbsp; It may take you a few extra seconds but it could save you thousands of dollars and hours of time in the future. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.davehildebrand.com/2006/09/01/phishing-an-example/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
