DUI Lawyers & DUI Attorneys - Driving Under the Influence of alcohol - DWI
TOLL FREE HELP LINES: Bankruptcy (866) 233-3092, Divorce (866) 233-3093, Injury (866) 233-3098, DUI (866) 233-3099, Criminal Defense (866) 233-3094
  FAQ: Bankruptcy Lawyer | Divorce Lawyer | Injury Lawyer | DUI Attorney | Criminal Defense Attorney

Identity Theft and Pharming - A New Twist on an Old Theme

Legal:Identity-Theft Article Guide
By: Michael Solomon

Identity theft is big business and, like it or not, the likelihood that you will become a victim is increasing. As the Internet and its popularity have grown, the number of unscrupulous operators out there has grown as well. There are so many scams and attack methods out there it is difficult to keep up with them.

One of the identity thief's more productive techniques is phishing. A phishing scam is one where an email message contains a link to a web site that asks for personal information. The scam uses social engineering to trick people to go to a web site they would not normally visit. A common scam is one in which an email that looks like it has come from a bank or credit card company asks you to "click on this link" to update your user information. There is generally a part of the email that tries to convey a sense of urgency to get you to "do it now". When you click on the link you are actually forwarded to a thief's web site that is designed to look like your bank or credit card company's web site. You are then asked to provide information, such as user id, password, and other identifying information. Identity thieves use this information to open or use credit accounts and steal money from unsuspecting consumers.

Phishing attacks are relatively easy the spot and avoid. Never follow links in email messages unless you know the link is valid. Compare the actual link address with the text you see. If you are expecting to go to PayPal.com, make sure the link really takes you there. You can view the hyperlink before you click on it buy pointing your mouse cursor at the link. Most email clients and web browsers will show you what the actual address is before you click on it. If the address doesn't match the web site address you expected to see, don't click on the link. Likewise, NEVER provide any personal information from an unsolicited source. You will also see the address you are visiting in your web browser's address bar. Make sure you are visiting the site you expect.

There is a new trend in identity theft, called pharming. Well, it is actually a fairly old type of attack put to a new and alarming use. The basic attack generally relies on DNS poisoning or domain spoofing. The difference between phishing and pharming is that while phishing targets individuals, pharming targets large groups of people. Before we get into a discussion of a pharming attack, let's look at a short primer on how Internet addresses work.

Anytime you type in an address in your web browser, such as http://www.somecompany.com, your computer needs to find the Internet Protocol (IP) address before sending any information. There are two main methods for finding IP addresses for web site addresses. The legacy method consists of a file, called the 'hosts' file, that lists all of the host names you may want to visit, along with their IP addresses. The other method is to send a name resolution request to a Dynamic Name Server (DNS). The DNS server looks up the address in its database and returns the corresponding IP address. Once your computer looks up the IP address for http://www.somecompany.com, it then uses the IP address for all further communication.

A pharming attack is one where the host file or DNS entry is modified to send users to a counterfeit web site. The slightly simpler of the two attacks is the host file modification. This can be accomplished with a virus or worm. It is generally harder to compromise DNS servers. With the phishing attack, a careful view of your web browser's address bar will show that you are visiting a site you did not expect. Pharming attacks are more difficult to detect since your web browser tells you that you are at the right site even when you really aren't.

The effect of a pharming attack is that all users who want to go to a particular site end up being redirected to a thief's site. While this might sound similar to a phishing attack, it can be much worse. There is no indication to the end user that a redirect has occurred. The web browser still shows the original web address. This behavior makes pharming attacks more difficult to detect. Also, if the thief is able to change DNS entries on a commonly used DNS server, all users who request IP addresses from the compromised server will be sent to the counterfeit site.

So, how do you protect yourself from a pharming attack? Much of the work in stopping pharming attacks is up to the DNS administrators. They will be responsible for ensuring any DNS entry changes are authentic. But, there are some steps you can take. Following these guidelines will reduce your chances of becoming a pharming victim:

Install and update a good anti-virus program. Since many attacks start as malicious software, protecting your system from viruses and other malicious software will go a long way toward stopping an attack before any information is changed. Protect your 'hosts' file. On Windows operating systems, the hosts file resides at: (assuming C:\Windows is where your OS installed) C:\Windows\system32\drivers\etc\hosts. On Unix systems, it resides at /etc/hosts. You can manually check your hosts file to ensure no unusual entries have been put there or you can install software shields that watch the hosts file for you (along with anti-virus software). Know the sites you visit and carefully protect any information you give out. Never divulge any information for any reason unless you are absolutely certain the information is necessary and you are providing it to the correct organization. If your bank web site, or any other web site, asks you to provide confidential information, call their customer service department to get confirmation that the information is needed. Don't call the number on the web site (it may be compromised). Look up the number in the phone book or use directory assistance. As more and more web sites start using digital certificates to authenticate their identities, you will begin to see more popup windows asking you to accept these certificates the first time you visit the web site. Always read the certificate details and ensure the web site really is the one you wanted to visit. If you are unsure, reject the certificate.
We will all hear more about pharming in the coming months. Its use is growing. This is just another opportunity to remind as many people as possible to be careful with the sites you visit and the information you give out. Protect your personal information. Not doing so can be very expensive.

Want more tips and information on how to recognize, prevent, and repair the effects of identity theft? Go to http://www.thesecurityguy.net right now and you’ll find eBooks and home study courses on identity theft and other security related topics.


Bookmark & Share Articles:


Leave a comment to Identity Theft and Pharming - A New Twist on an Old Theme

  • Name (required)
  • Mail (required but not published)
  • Comment / Rate this hotel
    Terrible
    Fair
    Okay
    Good
    Excellent
  • Please enter:  


No Responses to Identity Theft and Pharming - A New Twist on an Old Theme

Average Rating: (From 0 Votes)


Request a Case Evaluation with a Local Attorney

Regardless of your legal situation, a local attorney can help explain the legal process involved and answer any questions you have along the way. Fill out the form below for your case evaluation with a local attorney.

Latest Legal Articles:

  • How To Stop Identity Theft
  • Identity Theft Protection
  • Living Will
  • How to Patent Your Invention
  • Ten Ways to Fight Identity Theft
  • Identity Theft Prevention
  • Injury Claim Lawyers
  • Identity Theft - When It Happens To You
  • How to Gain Custody of Children - What Makes You a Better Parent?
  • Identity Theft - Impacting Your Taxes?
  • New Jersey Family Lawyers
  • 7 Ways To Squash Identity Theft
  • Why Get an Adoption Attorney?
  • Los Angeles DUI Attorneys
  • Franchisee Rights Groups to Join
  • Fiancee Visa Process
  • The Probation Service in the United Kingdom
  • Garreth Westwood: What is Your Citizenship Strategy?
  • Employment Law: Time Limits for Bringing Employment Tribunal Claims
  • Protecting Your Leased or Consigned Photographs
  • Media: Privacy Rights - Publishing
  • Simple Ways to Help Avoid Identity Theft
  • Celebrex Law Suits Looking Like a Strong Case
  • 10 Ways to Keep Legal Fees Affordable
  • Small Claims Court -What's it All About?
  • Make Your Complaint Heard & Get Results
  • Work Injury Claim - Easy If You Make It!
  • Criminal Records Search
  • Bringing Your Fiance to America
  • Background Search – What to Look Out For
  • Criminal Defense Investigator
  • Steer Clear Of The Law When You Are Duplicating DVDs
  • Criminal Defense Attorneys
  • Future Proofing: Why You May Need An Enduring Power Of Attorney
  • Accident Compensation Claim On Automate!
  • Evictions in the City of Seattle
  • Know When To Get An Agreement In Writing
  • Requiem
  • Marketing Authorisation: Distinction Between Food Additives and Medicinal Products
  • Nude Notary Reveals the #1 Misunderstanding about Notaries
  • Successful Industrial Injury Claim Steps
  • Injury Attorneys
  • Other Documentary Evidence In Support Of Your Fiance Visa
  • Identity Theft
  • After the Revocable Living Trust is Signed... Now What?
  • Recalibrating Professional Service Provider Relationships
  • What You Need To Do If You Are In A Vehicle Accident
  • Home Refinancing Scam - Thieves Use Identity Theft to Steal Your Equity
  • New Jersey DWI Records
  • IRS Gives Away More Information on US Citizens than the Identity Thieves Even Need
  • Probate Research
  • Criminal Law: Should the Illegal Importation of Tobacco and Cigarettes be a Criminal Offense?
  • Fraud - Benefit Fraud
  • Estate Planning - Changing A Will
  • Lost or Stolen ATM Debit Cards - Your Liability
  • What is a Probate Court?
  • Junk Faxes - New California Law Challenged
  • Appellate Division Dismisses Claim After Plaintiff Failed To Name Company As Asbestos Supplier
  • How Do You Qualify For Legal Aid?
  • Why Opt for an Experienced Mesothelioma Attorney?
  • Identity Theft
  • Arizona DUI Defense
  • New Jersey DUI Fines
  • Bausch & Lomb Recall - ReNu Recall Lawyer & Fungal Keratitis Lawsuit Attorneys
  • You Bought A Lemon, Now What?
  • Mesothelioma Asbestos Lawyers
  • Destination India - A Legal Synopsis
  • Fraud - Identity Theft And Fraud
  • Master Franchise Agreements and the Royalties From Sale of Additional Franchises
  • Zyprexa Lawsuit Loan! No-Risk Legal Finance!
  • FTC Justification of FY 2007 is BS
  • Houston DWI Defense
  • 5 Things Banks Don't Tell You About ID Theft
  • Ohio Private Investigators
  • How Do You KNOW if Your Identity Has Been Stolen?
  • Pucker Up on the Latest Lemon Law
  • Identity Theft: Thieves no Longer Seek to Steal Your Possessions, They Seek to Steal YOU
  • Legal Efficiency
  • Florida DUI Schools
  • Pre-Settlement Lawsuit Funding
  • Stevens Johnson Syndrome Lawyer and SJS Lawsuit Litigation
  • Importance of Living Wills
  • Questions To Ask A Personal Injury Lawyer During Your Consultation
  • Post Divorce: A New Beginning
  • LPO For Insurance Litigation: A Few Insights
  • Is A Doctor's Past Legal History Admissibile In My Current Lawsuit?
  • Pierce the Corporate Veil
  • Lawsuit Loan Services
  • Help! Finding A Lawyer
  • Finding a Bankruptcy Attorney in New Hampshire
  • San Diego DUI Lawyers Report Breathalyzers Don't Measure Alcohol
  • Work Place Injury in Virginia: Can You Sue Your Employer for Your Injury?
  • More on Complexity and the Lemon Vehicle
  • Lawsuit Financing Companies
  • Los Angeles Criminal Defense Lawyers
  • How Well Do You Know The Constitution
  • Whiplash Compensation Claim - Take These Actions
  • Nursing Home Abuse Lawyers and Law Firm Attorney Lawsuit Information
  • Bail Bond Agents: The Good, Bad And Not-so-pretty
  • Protect Your Identity This Holiday Season

  • Latest Legal Guide

    TOLL FREE HELP LINES:

    - Bankruptcy (866) 233-3092
    - Divorce (866) 233-3093
    - Injury (866) 233-3098
    - DUI (866) 233-3099
    - Criminal Defense
      (866) 233-3094