Wednesday, August 20, 2008

How to tell if an e-mail message is fraudulent



Here are a few phrases to look for if you think an e-mail message is a phishing scam.

"Verify your account."
Businesses should not ask you to send passwords, login names, Social Security numbers, or other personal information through e-mail.

If you receive an e-mail from Microsoft asking you to update your credit card information, do not respond: this is a phishing scam. To learn more, read Fraudulent e-mail that requests credit card information sent to Microsoft customers.


"If you don't respond within 48 hours, your account will be closed."
These messages convey a sense of urgency so that you'll respond immediately without thinking. Phishing e-mail message might even claim that your response is required because your account might have been compromised.


"Dear Valued Customer."
Phishing e-mail messages are usually sent out in bulk and often do not contain your first or last name.


"Click the link below to gain access to your account."
HTML-formatted messages can contain links or forms that you can fill out just as you'd fill out a form on a Web site.

The links that you are urged to click may contain all or part of a real company's name and are usually "masked," meaning that the link you see does not take you to that address but somewhere different, usually a phony Web site.

Notice in the following example that resting (but not clicking) the mouse pointer on the link reveals the real Web address, as shown in the box with the yellow background. The string of cryptic numbers looks nothing like the company's Web address, which is a suspicious sign.

Wednesday, August 13, 2008

Damage caused by phishing


The damage caused by phishing ranges from denial of access to e-mail to substantial financial loss. This style of identity theft is becoming more popular, because of the readiness with which unsuspecting people often divulge personal information to phishers, including credit card numbers, social security numbers, and mothers' maiden names. There are also fears that identity thieves can add such information to the knowledge they gain simply by accessing public records. Once this information is acquired, the phishers may use a person's details to create fake accounts in a victim's name. They can then ruin the victims' credit, or even deny the victims access to their own accounts.

It is estimated that between May 2004 and May 2005, approximately 1.2 million computer users in the United States suffered losses caused by phishing, totaling approximately US$929 million. United States businesses lose an estimated US$2 billion per year as their clients become victims. In 2007 phishing attacks escalated. 3.6 million adults lost US $ 3.2 billion in the 12 months ending in August 2007. In the United Kingdom losses from web banking fraud—mostly from phishing—almost doubled to £23.2m in 2005, from £12.2m in 2004, while 1 in 20 computer users claimed to have lost out to phishing in 2005.

The stance adopted by the UK banking body APACS is that "customers must also take sensible precautions ... so that they are not vulnerable to the criminal." Similarly, when the first spate of phishing attacks hit the Irish Republic's banking sector in September 2006, the Bank of Ireland initially refused to cover losses suffered by its customers (and it still insists that its policy is not to do so, although losses to the tune of €11,300 were made good.

Wednesday, August 6, 2008

Phishing techniques

Link manipulation

Most methods of phishing use some form of technical deception designed to make a link in an e-mail (and the spoofed website it leads to) appear to belong to the spoofed organization. Misspelled URLs or the use of subdomains are common tricks used by phishers. In the following example URL, http://www.yourbank.example.com/, it appears as though the URL will take you to the example section of the yourbank website; actually this URL points to the "yourbank" (i.e. phishing) section of the example website. Another common trick is to make the anchor text for a link appear to be valid, when the link actually goes to the phishers' site. The following example link, Genuine, appears to take you to an article entitled "Genuine"; clicking on it will in fact take you to the article entitled "Deception".

An old method of spoofing used links containing the '@' symbol, originally intended as a way to include a username and password (contrary to the standard).[23] For example, the link http://www.google.com@members.tripod.com/ might deceive a casual observer into believing that it will open a page on www.google.com, whereas it actually directs the browser to a page on members.tripod.com, using a username of www.google.com: the page opens normally, regardless of the username supplied. Such URLs were disabled in Internet Explorer,while Mozilla Firefox and Opera present a warning message and give the option of continuing to the site or cancelling.

A further problem with URLs has been found in the handling of Internationalized domain names (IDN) in web browsers, that might allow visually identical web addresses to lead to different, possibly malicious, websites. Despite the publicity surrounding the flaw, known as IDN spoofing or a homograph attack,no known phishing attacks have yet taken advantage of it.[citation needed] Phishers have taken advantage of a similar risk, using open URL redirectors on the websites of trusted organizations to disguise malicious URLs with a trusted domain.

Source - wikipedia

Monday, August 4, 2008

Phishing

In computing, phishing is the criminally fraudulent process of attempting to acquire sensitive information such as usernames, passwords and credit card details, by masquerading as a trustworthy entity in an electronic communication. Communications purporting to be from PayPal, eBay, Youtube or online banks are commonly used to lure the unsuspecting. Phishing is typically carried out by e-mail or instant messaging,[1] and it often directs users to enter details at a website. Phishing is an example of social engineering techniques used to fool users.[2] Attempts to deal with the growing number of reported phishing incidents include legislation, user training, public awareness, and technical security measures.

A phishing technique was described in detail in 1987, and the first recorded use of the term "phishing" was made in 1996. The term is a variant of fishing,[3] probably influenced by phreaking,[4][5] and alludes to baits used to "catch" financial information and passwords.

Recent phishing attempts

Phishers are targeting the customers of banks and online payment services. E-mails, supposedly from the Internal Revenue Service, have been used to glean sensitive data from U.S. taxpayers.[15] While the first such examples were sent indiscriminately in the expectation that some would be received by customers of a given bank or service, recent research has shown that phishers may in principle be able to determine which banks potential victims use, and target bogus e-mails accordingly.[16] Targeted versions of phishing have been termed spear phishing.[17] Several recent phishing attacks have been directed specifically at senior executives and other high profile targets within businesses, and the term whaling has been coined for these kinds of attacks.[18]

Social networking sites are a target of phishing, since the personal details in such sites can be used in identity theft;[19] in late 2006 a computer worm took over pages on MySpace and altered links to direct surfers to websites designed to steal login details.[20] Experiments show a success rate of over 70% for phishing attacks on social networks.[21]

Almost half of phishing thefts in 2006 were committed by groups operating through the Russian Business Network based in St. Petersburg.

...to be continued

Wednesday, July 30, 2008

It's mine and you can't have it!


By Matt Blackman

A well-known television show was conducting a story on the insurance industry in America and staged an intentional accident to demonstrate their point. A bus and a car were placed strategically to film the slow-motion crash. With television cameras rolling the bus was deliberately driven into the car. With cameras still rolling, surprised camera crews watched as bystanders who had witnessed the crash began piling on the bus. As word of the accident spread, the bus filled with more eager riders. Their sole purpose was to take part in the insurance windfall that would surely come their way. Most were not aware of the cameras that clearly documented the incident.

The unbridled increase of litigation in North America combined with growing complexity of tax codes has slowly but surely shifted the efforts of those with property. As a result less time is available for the pursuit of greater profits while more time and expense is required to keep what assets have been earned. With more than 100 million active lawsuits presently winding their way through the courts in the U.S. and more than 14 million new ones being launched every year, it is no wonder that those with property are getting apprehensive. Add the facts that half of all marriages end in divorce and 80% of all businesses fail within five years and one quickly realises the incredible challenge facing those with assets to protect.

In one recent survey conducted in the U.S., participants rated a lawsuit as the second best way to strike it rich behind winning a lottery and ahead of receiving an inheritance. It is a sad commentary on a system that once upon a time relied on risk- taking, initiative, ingenuity and plain hard work to get rich, slowly. Patience, it seems, has fallen out of favour. Let someone else take the risk, do the work and make the money - then sue them!

However, lest we slip into fainthearted despair, help is available. There are a growing number of options available to protect one's estate from the unrelenting onslaught of parasitic wannabe nouveau riche.

If you count yourself among those aspiring to own or haven't yet given any thought to protecting what you own, a new book entitled It's Mine and You Can't Have It by attorneys Robert V. Eberle and Frank Corcell should be at the top of your reading hit list. Written in plain English, it clearly presents a roadmap to follow and covers a variety of topics that will be of interest to the above groups.

The book begins with a "how to" on saving for retirement that explains how much money one needs to retire based on their earnings. It is a sobering reminder to the majority who are not putting away enough to retire in the style to which they have become accustomed. To begin with, retirement income should be 70% of working income. For example, if one earns $40,000 a year he or she will need a minimum $28,000 in yearly income to continue a similar lifestyle after leaving the work force. The average Social Security retirement benefit of $750 per month or just $9,000 a year isn't the answer unless the pre-retirement annual income was $12,850. This is prerequisite information for those in the early stages of a career but will prove shocking for the majority of Americans who are not adequately prepared for retirement. According to a Boston Globe survey, only 5 percent of American families with one spouse aged 70 years or greater are able to continue living the style to which they have become accustomed after they retire using Mr. Eberle's seventy-percent rule.

For this five percent, the challenge is keeping what they've got safe from the hoards that would scheme to take it from them. The book defines asset protection as "nothing more that the discipline of arranging the ownership of your assets or your property in such a way that your retain maximum control without any, or only minimal, direct ownership or your property." Why? Because whatever you own can be taken from you to satisfy a claim or judgement against you but if you own nothing, there is nothing to take.

As Mr. Eberle explains, giving up ownership is a frightening prospect for most of us. There are ways to satisfy this concern, however. "The key to asset protection is to arrange ownership in entities which permit you to control those assets without owning them directly." How that is accomplished while retaining peace of mind is the purpose the book.

Inside risk or that which emanates from the asset itself, and outside risk or that which results from simply owning the asset each require different types of protection. The first type can often be covered with insurance. Outside risk or the risk of lawsuit offers the greater challenge and requires a more complex strategy.

Trusts, a major tool in the battle against frivolous lawsuits, are explained in an easy to understand format. The differences between non-grantor and grantor, revocable and irrevocable, inter vivos (living) and testamentary (after death) trusts are all discussed in detail.

Offshore trusts and recent changes in legislation regarding offshore entities are covered along with some common dos and don'ts to prevent running afoul with the Internal Revenue Service. Offshore trusts should be irrevocable, discretionary, have a foreign trustee who limits the onshore trustee's control and should limit certain classes of persons from benefiting from the trust. This would include potential creditors or litigants of the grantor.

Various corporations, partnerships and other entities will be of interest to those who have wrestled with options on how best to conduct business while enjoying maximum asset protection. Mr. Eberle also discusses the advantages of different states to be used for incorporation when asset protection and tax minimisation are a prerequisite.

Sunday, July 27, 2008

The Rip Off Corporation


by Rolf Müller

The rip off corporation is one of the most common scams on the internet. Don't get short-changed on your Corporation. Most so-called offshore service providers sell 'hot cake,' corporations, that lack proper apostilles, proper stamps, have unpaid taxes, unpaid subscription taxes, and are merely 'shell documents,' not legal corporations. i.e. They sell you the document, but it is not legal in Panama. If you wish to do offshore banking, brokerage or eCommerce it will require that you have a fully legal Corporation that meets Panamanian law.

Panamanian fees & taxes must be paid from day one, not at the end of the year. (The fees are minuscule, consisting of only a few hundred dollars.) Many so-called Offshore Service Providers do not pay the taxes, even in subsequent years, although they will charge you for it. They don't care, they figure you'll never come to Panama, never investigate and therefor never know. This is part of what soured me to promoting offshore firms. Some firms go even beyond that level of dishonesty and run what are called Ponzi schemes, using other investors money to pay you high interest on your investments. (Like a chain letter.) Once they've collected enough money they disappear.

In eCommerce, (internet commerce,) the one area I am recommending, you control your own assets, you control your own website, you control your own bank account.

We are not interested in helping people evade taxes, our goal is to provide the legal means of doing legitimate offshore eCommerce, whether in international trade, import & export, online eCommerce, product sales, software sales, and/or any of the many forms of international online eCommerce that will benefit from the utilization of an offshore jurisdiction.

The most important tool, and the first tool one needs for offshore eCommerce is the IBC.

Wednesday, July 23, 2008

Seven tips for responsible use of debit cards

1. If your card is lost or stolen, report the loss immediately to your financial institution.

2. If you suspect your card is being fraudulently used, report it immediately to your financial institution.

3. Hold on to your receipts from your debit card transactions. A thief may get your name and debit card number from a receipt and order goods by mail or over the telephone. Your card does not have to be missing in order for it to be misused.

4. If you have a PIN number, memorize it. Do not keep your PIN number with your card. Also, don't choose a PIN number that a smart thief could figure out, such as your phone number or birthday.

5. Never give your PIN number to anyone. Keep your PIN private.

6. Always know how much money you have available in your account. Don't forget that your debit card may allow you to access money that you have set aside to cover a check which has not cleared your bank yet.
7. Keep your receipts in one place -- for easy retrieval and better oversight of your bank account.