Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

 Phishing Sites(Bank), How to protect yourself

views
     
TSnairud
post Sep 15 2006, 02:53 PM, updated 20y ago

One Leg Kick Ultra
Group Icon
Staff
7,529 posts

Joined: Jan 2003
Lately, have you been receiving emails from local banks informing you that your account has been suspended and in order to re-activate your account, you are required to click on a link provided in the email. Hence you are directed to a page where you can enter your login id and password so that you can use back your account again?

QUOTE(wikipedia@http://en.wikipedia.org/wiki/Phishing)
In computing, phishing is a criminal activity using social engineering techniques. Phishers attempt to fraudulently acquire sensitive information, such as passwords and credit card details, by masquerading as a trustworthy person or business in an electronic communication. Phishing is typically carried out using email or an instant message, although phone contact has been used as well[1]. Attempts to deal with the growing number of reported phishing incidents include legislation, user training, and technical measures.

The first recorded mention of phishing is on the alt.online-service.america-online Usenet newsgroup on January 2, 1996,[2] although the term may have appeared even earlier in the print edition of the hacker magazine 2600.[3] The term phishing is a variant of fishing[4], probably influenced by phreaking,[5][6] and alludes to the use of increasingly sophisticated lures to "fish" for users' financial information and passwords. The word may also be linked to leetspeak, in which ph is a common substitution for f.[7] The popular theory that it is a portmanteau of password harvesting[8] is an example of folk etymology. The name may also come from the popular rock group Phish.

Countless of times, people fell into this kind of attack which is also known as Phishing Attack. And how do you prevent yourself from being a victim? There is a toolbar for Internet Explorer and Mozilla Firefox where it will protect you from malicious phishing sites. It is called GRID Authenticator Toolbar

So far, GRID Authenticator toolbar only verify local banks. You can try out it's protection on phishing sites by clicking Maybank2u Phishing site How GRID Authenticator works for you is that when you enter a verified local bank, a GREEN frame will appear around your browser. This indicates that the website is a genuine one instead of a phishing site.

In the event that you received any mails from your so called "Bank", do visit GRID Center and report the phishing site. They will verify the url. Or you can simply pm me.

Let's make our local banking scene a safe place to go.

This post has been edited by nairud: Sep 15 2006, 02:58 PM
HMMaster
post Sep 15 2006, 04:24 PM

10K Club
Group Icon
Moderator
10,308 posts

Joined: Jan 2003
From: Kuala Lumpur


both IE7 and Firefox 2.0 will include phishing detector. smile.gif
WaCKy-Angel
post Sep 15 2006, 04:27 PM

PeACe~~
*********
All Stars
21,963 posts

Joined: Dec 2004
From: KL



Actually how does the Jaring grid authenticator works?
How does a softwares know which is real which is fake?
TSnairud
post Sep 15 2006, 04:31 PM

One Leg Kick Ultra
Group Icon
Staff
7,529 posts

Joined: Jan 2003
I guess this link would help you guys... me bz atm...no time to explain
https://www.elockgrid.com/gridcenter/help.htm
samurai1337
post Sep 16 2006, 07:10 PM

@_@
Group Icon
VIP
11,594 posts

Joined: Jan 2003
From: Area 51

Well, basically I never trust any email saying my account has been de-activated or shits like that. Will usually call the bank rightaway

Anyways, google also offers a Safe Browsing extension for firefox
http://www.google.com/tools/firefox/safebrowsing/
Not sure about how effective is it, though...

This post has been edited by samurai1337: Sep 16 2006, 07:14 PM
sotong168
post Sep 17 2006, 06:32 AM

in retiring mode
*******
Senior Member
5,291 posts

Joined: Dec 2004
From: I Luv Msia
yesterday i received an email disguised as PublicBank <Info@pbebank.com.my> with subjects "Update your information due to lots of fraudulent cases", pls note the the typo 'thorugh' and the grammar sweat.gif when i click on the links, it directs me to hxxp://www.archev.net/dotproject/classes/index.html (fraudulent site!!!)





Attached thumbnail(s)
Attached Image
TSnairud
post Sep 17 2006, 08:18 PM

One Leg Kick Ultra
Group Icon
Staff
7,529 posts

Joined: Jan 2003
Can you forward the email to me? I've pm you my email add
TSnairud
post Sep 21 2006, 09:26 AM

One Leg Kick Ultra
Group Icon
Staff
7,529 posts

Joined: Jan 2003
QUOTE(samurai1337 @ Sep 16 2006, 07:10 PM)
Anyways, google also offers a Safe Browsing extension for firefox
http://www.google.com/tools/firefox/safebrowsing/
Not sure about how effective is it, though...
*
I have encountered that also but it's only a mini icon on the url bar and also a popup reminding you that it might be a forged web only.

GRID authenticator will verify the site you are visiting (banks only: main page and login page) by showing a green frame over your IE/Firefox browser. Do you see Google Safe Browsing has anything that can really really get your attention that the site you're visiting is an actual site or not? When one enters the phishing site's url, GRID Authenticator will automatically block your access to that site instead of just informing you like Google Safe Browsing.

ding_dong
post Sep 22 2006, 12:55 PM

New Member
*
Junior Member
44 posts

Joined: Sep 2006
anyone has experience with this...
i means money transfer from international bank to our accc..
is it safe??
dopodplaya
post Sep 22 2006, 01:10 PM

Look at all my stars!!
*******
Senior Member
2,280 posts

Joined: Jun 2006
QUOTE(ding_dong @ Sep 22 2006, 12:55 PM)
anyone has experience with this...
i means money transfer from international bank to our accc..
is it safe??
*
Yes, most banks have Internet/electronic banking system nowadays. Ask your nearest bank branch today. Or surf the websites of your banks for more information.

The transactions are safe, most of the time. I never experience any fraud until today. Just becareful of three things, phishing, shoulder surfing and easy-to-crack passwords.

Tips
Avoid Phishing...
Avoid opening links from e-mail that claimed coming from bank representative. THEY DO NOT HAVE TO send you e-mail with links! Goto their websites and do transactions there. Type the URL exactly as the banks advertise. Do not reply to the e-mail claiming that they came from the bank representative. AGAIN, the bank DOES NOT NEED your reply via e-mail.

Please becareful of people next to you, even you Ah Ma! Make sure not to do transaction in public, but if you need to, be aware of people around you.

Most bank online system requires complex password. Do not create password that is easily remembered like, your birthday, dog, pet, girlfriend, etc... Use acronym or abbreviation or combination of both
ding_dong
post Sep 22 2006, 05:19 PM

New Member
*
Junior Member
44 posts

Joined: Sep 2006
thank yaa...
samurai1337
post Sep 25 2006, 04:30 PM

@_@
Group Icon
VIP
11,594 posts

Joined: Jan 2003
From: Area 51

QUOTE(ding_dong @ Sep 22 2006, 12:55 PM)
anyone has experience with this...
i means money transfer from international bank to our accc..
is it safe??
*
I've merged your thread into this one.
TSnairud
post Sep 25 2006, 04:37 PM

One Leg Kick Ultra
Group Icon
Staff
7,529 posts

Joined: Jan 2003
QUOTE(ding_dong @ Sep 22 2006, 12:55 PM)
anyone has experience with this...
i means money transfer from international bank to our accc..
is it safe??
*
Another way is to check the login page url. It should have HTTPS. Secure http. remember that.

then check the cert from that site. make sure it's a verified cert issued by a valid CA
AsenDURE
post Oct 5 2006, 04:17 PM

je suis desole. je n'y crois pas a ces conneries!!
Group Icon
VIP
2,496 posts

Joined: Jan 2003
From: LowYatDotNet Status:Agast
A central database of user-submitted and verified phishing sites.

http://www.phishtank.com/
TSnairud
post Oct 6 2006, 09:24 AM

One Leg Kick Ultra
Group Icon
Staff
7,529 posts

Joined: Jan 2003
Thanks mate... i did a mini search but phishing sites that target local banks are not listed.
nshady
post Oct 10 2006, 09:07 PM

Casual
***
Junior Member
354 posts

Joined: Jan 2006
I wonder , e-lockgrid belongs to which company ? A local bank ?

and Will this anti-phishing works along with built-in anti-pisher from internet browsers?
TSnairud
post Oct 11 2006, 08:35 AM

One Leg Kick Ultra
Group Icon
Staff
7,529 posts

Joined: Jan 2003
yes, it will work with the current google toolbar anti phisher (which i have tested on). But Google will only inform you that the site that you're entering might be a phishing site. iinm, this GRID toolbar will automatically block your access immediately along with a reminder that it's a phishing site.
samurai1337
post Nov 2 2006, 10:04 AM

@_@
Group Icon
VIP
11,594 posts

Joined: Jan 2003
From: Area 51

Online Security Tips quoted from maybank2u

QUOTE
Maybank2u.com Security Tips
With the recent report on online banking fraud, please take extra care when performing online banking. Simply follow these 3 important tips to ensure that your money is safe while you are on holiday.

.  Login name, Password/PIN Number
  Never disclose you Login Name, Password/PIN Number to anyone, including your family members. Most of the online banking fraud cases result from a "tidak apa" attitude. Be mindful.

Ensure that nobody is observing you when you perform financial transactions at a public Internet access point. A fair number of cases have been reported where the customer's account access data was obtained by just observing transactions performed at public Internet locations.

Don't use birthdays, wedding anniversary, house number, pet's names, children's names as your login name, password/PIN Number.
   
.  Phishing
  Phishing involves using fake emails and/or fake websites. You may receive emails that appear to be from your bank and if clicked will direct you to a fake website. This website "impersonates" your bank's website and prompts customers to reveal their account access data. Don't click and/or use any e-mail link or suspicious emails to update your account information. Always be on alert for these phony "look-alike" websites.  When in doubt, please contact your bank.
   
.  Trojan Horse
  Trojan Horse is a virus software which comes in the form of a legitimate e-mail from a family member, friend, colleague or someone in your email address list.  Once the email is opened, Trojans plant themselves into the keyboard driver and record keystrokes.

Later on when you open an online banking website, it captures the login name and password for fraudulent purposes.

At Maybank2u.com, we always have your best interest at heart. Gain tips and read articles at our special segment, Online Security Watch.

AsenDURE
post Nov 7 2006, 05:55 PM

je suis desole. je n'y crois pas a ces conneries!!
Group Icon
VIP
2,496 posts

Joined: Jan 2003
From: LowYatDotNet Status:Agast
QUOTE
OpenDNS can identify and stop sites trying to phish (steal) your personal information or money. The OpenDNS phishing protection works with all operating systems and browsers, and complements any other security measures already in use, such as a firewall and anti-virus software.


http://www.opendns.com/
TSnairud
post Dec 15 2006, 10:29 PM

One Leg Kick Ultra
Group Icon
Staff
7,529 posts

Joined: Jan 2003
GRID toolbar new version released!

2 Pages  1 2 >Top
 

Change to:
| Lo-Fi Version
0.0826sec    0.21    6 queries    GZIP Disabled
Time is now: 24th December 2025 - 09:42 AM