internet.com
You are in the: Small Business Computing Channelarrow
Small Business Technology
» ECommerce-Guide | Small Business Computing | Webopedia | WinPlanet |Refer-It

WinPlanet Software Downloads and Reviews for Small Businesses
Search
Power Search | Tips
-
Navigate WinPlanet
WinPlanet Home Page

Software
Download Index
In-Depth Reviews
Tips & Tutorials
Updates
News

Software Categories
Browsers
Chat / Conferencing
Desktop Utilities
Development
Internet Apps
Multimedia
OS Service Packs
Productivity Tools

Software Glossary

WinPlanet Newsletter

internet.commerce
Partners & Affiliates













Small Business Computing
Small Business Computing
Ecommerce Guide
Webopedia
WinPlanet

WinPlanet / News

Download of the day
Internet Explorer 8

Most Popular Software Downloads
Mozilla Firefox 3.0
Ad-Aware 2008 Free
Internet Explorer 7
QuickTime for Windows
Paint Shop Pro
Mozilla Firefox Portable Edition 3
AVG Anti-Virus Free
Windows XP Service Pack 3
Ashampoo WinOptimizer
Adobe Flash Player
Windows Live Suite

Most Popular Software Articles
Windows Vista Tips & Tricks, Part 1
Windows Vista: Worthy of the Hype?
Windows Wireless Zero Configuration: Five Steps to Sanity


Software Reviews

Vishing Joins Phishing as Security Threat
Thieves Discover New Avenue for Scamming
Andy Patrizio

Just as Internet surfers have gotten wise to the fine art of phishing, along comes a new scam utilizing a new technology.

Creative thieves are now switching their efforts to "vishing," which uses Voice over Internet Protocol (VoIP) phones instead of a misdirected Web link to steal user information.

Phishing (define) is the sneaky art of sending an e-mail to people pretending to be from a bank or major online merchant, such as Amazon (Quote, Chart)or EBay (Quote, Chart), asking them to click on a link and verify their account information.

The user is then directed to a fake site that collects the login and password information.

Repeated efforts on the part of security firms have educated users to be cautious about clicking on links from unknown senders.

But now, the criminal element has shifted from asking people to click on links to placing a phone call instead. Only the number isn't to a bank or credit card, it's to a VoIP phone that can recognize telephone keystrokes.

The thieves don't even use an e-mail blast, they use a war dial over a VoIP system to blanket an area. A recorded message tells the person receiving the call that their credit card has been breached and to "call the following (regional) phone number immediately."

When the user calls the number, another message is played stating "this is account verification please enter your 16 digit account number." The rest is academic.

Secure Computing, which specializes in secure connections over networks, sent up the red flag over this new method. Secure Computing engineers have been tracking news group sites and open disclosure discussion groups discussing vishing.

"This is just a natural evolution of phishing itself," said Paul Henry, vice president of strategic accounts for Secure Computing.

"Simply put, people are becoming more aware of the fact that an e-mail containing a URL could be malicious in nature. So hackers are moving away from the URL and using something victims are more familiar with like calling a number."

Henry said Secure Computing raised the issue over a year ago, but the first recorded incident took place last month, involving a Santa Barbara bank, then a second incident in early July involving Paypal.

Henry said there is no real preventative technology solution. Caller ID spoofing is very simple, and VoIP providers like Skype allow customers to pick not only their area code but the prefix as well, so it's possible to pick a phone number in the same area code and prefix of a major bank.

To that end, Henry thinks the VoIP companies could help with the issue by being a little stricter in their signup process, but doesn't think they will.

"These VoIP companies are in the business of producing value for their shareholders, so they are trying to drive down transaction costs. They want establishment of a new account to be as fast and painless as possible," Henry said.

At this point, common sense is your best defense, said Henry. "If you receive an e-mail that would direct you to a telephone number, don't use that number. Contact your credit card provider or whoever with a known number that's good."

Daniel Hong, senior voice business analyst for Datamonitor, concurred that users need to be educated all over again.

"There's definitely vulnerability, because this is a completely new approach, especially in terms of customer behavior and customer psyche," Hong said.

There's been a lot of education on Internet scams, but there hasn't been a lot of awareness concerning the phone. So if there's an automated phone prompting you, it seems more credible than getting an e-mail blast from hackers out there."

More stringent measures for VoIP account activation could help, but in the end, education might be the best solution. "If the hacker is able to get to the consumer," said Hong, "then education will make the difference."

News courtesy of internetnews.com

July 11, 2006

View All Anti-Malware Tools

View All Anti-Virus Software

Contents:
1. Thieves Discover New Avenue for Scamming






JupiterOnlineMedia

internet.comearthweb.comDevx.commediabistro.comGraphics.com

Search:

Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

Jupitermedia Corporate Info


Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers

Solutions
Whitepapers and eBooks
IBM eBook: Planning a Service Oriented Architecture
IBM eBook: Choosing the Right Architecture--What It Means for You and Your Business
Microsoft Article: Will Hyper-V Make VMware This Decade's Netscape?
Avaya Article: Using Intelligent Presence to Create Smarter Business Applications
Intel Go Parallel Article: Getting Started with TBB on Windows
Microsoft Article: 7.0, Microsoft's Lucky Version?
Avaya Article: How to Feed Data into the Avaya Event Processor
IBM Article: Developing a Software Policy for Your Organization
Microsoft Article: Managing Virtual Machines with Microsoft System Center
Intel Go Parallel Article: Intel Threading Tools and OpenMP
HP eBook: Storage Networking , Part 1
Microsoft Article: Solving Data Center Complexity with Microsoft System Center Configuration Manager 2007
MORE WHITEPAPERS, EBOOKS, AND ARTICLES
Webcasts
HP Video: StorageWorks EVA4400 and Oracle
HP Webcast: Storage Is Changing Fast - Be Ready or Be Left Behind
Microsoft Silverlight Video: Creating Fading Controls with Expression Design and Expression Blend 2
MORE WEBCASTS, PODCASTS, AND VIDEOS
Downloads and eKits
Red Gate Download: SQL Toolbelt and free High-Performance SQL Code eBook
Iron Speed Designer Application Generator
MORE DOWNLOADS, EKITS, AND FREE TRIALS
Tutorials and Demos
Silverlight 2 App and Walkthrough: Leverage Silverlight 2 with SQL Server and XML
IBM Article: Enterprise Search--Do You Know What's Out There?
HP Demo: StorageWorks EVA4400
Microsoft Article: The Progress and Promise of Deep Zoom
Microsoft How-to Article: Get Going with Silverlight and Windows Live
MORE TUTORIALS, DEMOS AND STEP-BY-STEP GUIDES