Pishing for credit

Internet Security tip :

Beware of links that have “webscr” contained within the link target. Pishing is a way of tricking a user to visit a fake version of a well trusted site, like PayPal in the hope of stealing their account login details and thus gaining control over their card numbers etc etc ……. Typically these are delivered by email, these are not viruses or worms, they appear on the surface to be as close to the branding of the original site they are attacking the users of.

This is what Pishing looks like to a text based email reader, that doesn’t render HTML, blatently you can see that the link doesn’t go to PayPal but in fact looks on the surface as if it will log you into PayPal, when infact it takes you off to a fake site known here as www.login-user1692.info :


<a
href="http://paypal.com.login-user1692.info/">
https://www.paypal.com/cgi-bin/webscr?</a>

Beware of such links and where possible check the source code before clicking that link, this can be done in a webpage too, where it’s slightly easier to detect because you can look in the status bar to see where the link will take you, if the status bar is blank or if it promises to take you to amazon.com but instead reads in the status bar as amazon.com.login.net, don’t click the link.

Firefox and Thunderbird to some extent figures this out for you in some cases doing the comparision and checking against blacklists … Internet Explorer however offers you no protection and neither does Outlook.

Leave a Reply

  1. :

Please note: Comment moderation is in use and may delay your comment's debut.
There's no need to post your comment twice if you don't see it right away.


Light up the night!: Globally Recognized Avatars (or: gravatars) are how some people make those little icons appear next to their names in replies here. Get one of your own for free today and use it everywhere you go!