Vol 7 #47

Paradigm Web Design Home Web Sm@rts header

Welcome! to all new subscribers this week. I hope you enjoy this publication and find it an integral part of your weekly reading!

This E-zine may have been forwarded to you by a friend or colleague.
If you would like to subscribe, please point your browser to paradigmwebdesign.net/subscribe.html

In This Issue

Please visit our sponsors. They offer some great products and services and they keep this publication coming to you for free.

Imagine your ad above! For rates click HERE

My 2¢ Worth


id you know that on average, 100 people choke to death on ball-point pens every year? Hmmm... How on Earth do you choke on a ball-point pen?

ell, regardless of how that happens, it does beg another question for me. They said way back when that computers would eliminate paperwork. If that was so, just what use would you have for a pen?

unny thing is, not only did computers fail eliminate paperwork; but paperwork seems to have increased and is on the rise. I can testify that in my case, this is true. I have more paperwork now than ever.

one-the-less, I shall remain a computer geek. I'll just be careful not to choke on my pen. :-)

ad box #1

Want a money-making website without all the work? Just read the sales stats from one site last quarter...

  • 24 Affiliate checks totaling $2,047.20 in commissions.
  • 25 direct sales for $3,725.00 more in profit.
  • 240 new sub-affiliates, and multiplying DAILY.

You can get a pre-designed site just like the one generating those stats, if you act quickly...

Click Now!

Imagine your ad above! For rates click HERE

Feature Article

"Phishing" on the "Pharm": How Thieves Combine Two Techniques to Steal Your Identity

by: John Young
Identity Theft Protection Prevention Resources

Bob squinted at the email and began to read:

"Dear eBay User, as part of our security measures, eBay Inc. has developed a security program against fraudulent attempts and account thefts. Therefore, our system requires further account verification..."

Security Measures. A threat to suspend his account to prevent "fraudulent activity". The email went on to say that there were "procedural safeguards with federal regulations to protect the information you provide for us."

Bob clicked the link and was confronted with an authentic looking logon page, just waiting for him to input his user name and password and confirm what ebay supposedly didn't know.

He almost did it. The page looked absolutely authentic, and he had already been "set up" by the email message. His fingers were poised over the keyboard when he happened to glance at the URL.

There was something very, very wrong with it.

"PHARMING" TO FLEECE SHEEP

The art of "pharming" involves setting up an illegitimate website that is identical with its legitimate prototype, for example the ebay page Bob was almost suckered into using, and redirecting traffic to it.

"Pharmers" can do it in two ways:

  1. By altering the "Hosts" file on your computer. The Hosts file stores the IP address of websites you have been accessing. By inserting a new IP address into the database field corresponding to a website, your own computer can be redirected to the pharmer's website. Any information you give the bogus site is immediately hijacked by the pharmer.
  2. Hijacking the DNS (Dynamic Name Server) itself. A DNS matches the names of address with their IP addresses. If this server can be coerced into assigning new IP addresses to traditional names, all computers using the name resolution provided by the DNS server will be redirected to the hijacker's web site.

ad box #2

Create 100 Killer Headlines in 17 Seconds — Guaranteed!

Amazing software lets you answer 4 simple questions and push 1 button to get 100 top notch headlines in 17 seconds or less. We guarantee increased ad response. Check this out:

Click Here!

Imagine your ad above! For rates click HERE

Article continues.

Once that happens, it's time to be fleeced.

DOWN ON THE PHARM

"Pharmers" hijack your "hosts" file or DNS servers using Spyware, Adware, Viruses or Trojans. One of the most dangerous things you can do is to run your computer without some form of Internet Security installed on it.

Your security software should be continually updating its virus definitions, and be capable of warning you if something has been downloaded from a web site or through email. It should be able to remove it, "quarantine it", or tell you where it is so that you can remove it by hand.

You should also have Spyware and Adware programs installed, and be aware of any change in Internet browsing patterns. If your home page suddenly changes, or you experience advertising pop ups (which may pop up even when you are not hooked up to the Internet), you should run a Virus, Spyware or Adware scan.

Thanks to the efficacy of these protection programs, pharming is a lot more difficult than it used to be. It isn't as easy to hijack a computer as it once was.

So, the "pharmers" have teamed up with the "phishermen" to get you to visit the bogus web page yourself, and enter all the information they need.

PHISHING TO CATCH YOU ON THE PHARM

As Bob discovered, the page he had been taken to by the bogus email message was identical to the ebay logon page. Identical in every way except for the URL.

Out of curiosity, he checked the URL for the ebay logon by accessing ebay directly and clicking on the logon link. The two URL's were nothing alike, except the bogus one did have the word "ebay" in it twice - just enough to make it look authentic.

Do you have an article for Web Sm@rts?
Send to


Placing your article in Web Sm@rts is a great way to gain exposure for you and/or your business!
Each article is published with your name and web site, plus a short 'resource box' at the end of the article.

Article continues.

By combining the two techniques, the phishermen/pharmers had avoided the high tech problems associated with downloading a Virus that could get past his protection software. They had gone straight for the throat.

Bob's throat.

YOUR ONLY REAL IDENTITY THEFT PREVENTION AND PROTECTION

The bottom line is that the only real protection against the pharmers and phishermen is YOU. There are three things you must consider when you read any email demanding information:

  • Why do they want it? Be extremely skeptical when they say they have to "update their records", "comply with federal regulations", or prevent fraud. They are the ones initiating the fraud.
  • Why can't this be done at the website? Why not invite you to access the website directly and provide this information? The answer is because the bonafide company doesn't need an update.
  • What does the URL look like? Is it a series of subdomains some of which have the name of the bonafide company? Most likely the subdomain is set up with a free hosting company.
  • Have they provided partial information about you as a guarantee that the email authentically comes from the legitimate source? Be very careful of this one. This technique is effective for "pretexting", impersonating a person or company, and was used in the Hewlett Packard scandal to collect information. Just because they know your first and last name (and any other information - known only to the legitimate source) doesn't mean the email is legitimate. They probably hijacked the information off the server.

THE BOTTOM LINE

The bottom line is: don't provide any information at the behest of an email, no matter how authentic it looks, or how authentic the page it directs you to looks. If you must log in, do so at the parent site itself.

Your Identity Theft prevention and protection is, in the final analysis, up to you.

Don't be the next sheep fleeced by the pharmers who caught you with the phisherman's hook. Being dropped naked into their frying pan is NOT a fate you want.

**************

John Young is a writer with a scientific and technical background living in California. At the age of 62, he is the father of four, grandfather of 13, and lives with his wife and cat "Bear". Please check out his latest book on Identity Theft at www.youridentitystolen.com.

**************

Rate This Article

As part of our ongoing commitment to provide quality content, we
would like you to take a moment to rate this article on a five point scale.
Not useful 1.   2.   3.    4.   5. Very useful
Too short 1.   2.   3.    4.   5. Too long
Additional comments:


ad box #3

ATTN: Webmasters

The Most Important Book Ever Written about staying out of trouble with your Internet business. Bulletproof Your Website In 60 Minutes Or Less. Fully licensed forms included! Authored by Shawn Casey, J.D. — one of the web’s most successful businessmen.

Click here

Imagine your ad above! For rates click HERE

This week's TIP
Describing tables using the SUMMARY attribute

Remember the ALT attribute in <img> tags? The SUMMARY attribute in <table> tags serve a similar purpose, in that it will provide a description of the table to users of non-visual browsers. Unlike the alt attribute, Explorer 4.x, Communicator 4.x and lower browsers do not use the SUMMARY attribute to display pop-up hints when the mouse is paused over the table

NOTE: You likely won't see a visual change by adding the SUMMARY attribute if you're using a graphical browser. However, HTML authors concerned about their content being accessible in different mediums and by users with disabilities are advised to provide a summary of their tables.

Example
<table summary="Red, green and blue rectangles">

ad box #4

Tips for Today's Woman

Recipes, fundraising tips and opportunities, child safety, tips on health and beauty, business opportunities, shopping and finance, home and family, food storage tips, women's devotional.

www.todaysmodernwoman.com/

Imagine your ad above! For rates click HERE

Second Article

Creating a Favicon


by: Meryl Evans
meryl's notes

Once, I attempted to create a favicon (the little graphic in the URL address box) for this Web site, but never did finish the work until now. I used a free program that allowed me to copy and paste an image to create an icon, but I believe it has spyware so I won't share its name. There are many icon creators out there.

In Photoshop (or whatever drawing program you have), I created a 16x16 pixel workspace. Added what I wanted in the icon (never could come up with a logo for the site, so I stuck with the m), select all (CTRL+A), copy (CTRL+C), and pasted it into the suspicious program. There, I saved it as “favicon.ico” and uploaded the file to my server.

It won't work yet. First, add a line to the <head> of the index page. Here's the line to add using XHTML standard formatting (if you're using HTML, leave off the / at the end of the line):

<link rel="Shortcut Icon" href="/images/favicon.ico" />

If you keep the ico file in the root, then use this instead:

<link rel="Shortcut Icon" href="favicon.ico" />

That's it. The first time you try it, nothing might happen. Give it a little bit to take effect as that's what happened with mine. You don't have to specifically create a 16 x 16 pixel image to make it into an icon with the program.

Other sites with favicons for inspiration:

**************

Meryl K. Evans is the Content Maven behind meryl's notes, eNewsletter Journal, and The Remediator Security Digest. She is also a PC Today columnist and a tour guide at InformIT. Meryl has written for The Dallas Morning News, AbsoluteWrite, O'Reilly, New Riders, and others. She is geared to tackle your editing, writing, content, and process needs. The native Texan resides in Plano, Texas, a heartbeat north of Dallas, and doesn't wear a 10-gallon hat or cowboy boots.

**************

Download of the Week

Here's a little "must have" game for those of you who like to drink and drive. If you are going to drink and drive, do it at home on the computer and drive a beer truck!

Beer Truck 1.1. You just stole a beer truck! Drive the beer truck over the road, avoiding the cars and cops. Stay inside the screen. You will need to collect the beer kegs or you will run out of gas.

Download Beer Truck 1.1.


Web Sm@rts is a publication of Paradigm Web Design.
All rights reserved.   ©2006