UC Home Maps     A-Z Index Web Search People Search UC Tools  
UCit Home UCit Home   UC Home

 

 

Phishing Scams Grow More Sophisticated

by Lisa Padget

Phishing criminals constantly seek to deceive Internet users into divulging usernames, passwords, credit card numbers, and other account information. Their treacherous new tactic, "secured phishing," employs phony digital certificates to allay users' suspicions about spoofed sites.

Most phishing attacks begin with a spammed e-mail message that urges the recipient to click on a link to update account information. The link points to a spoofed version of a real site, which requests username, password, or credit card information.

The new element of the phishing attack is a self-signed digital certificate, exploiting users' faith that Secure Sockets Layer digital certificates have been issued by a certificate authority. The spoofed web site uses HTTPS protocol, so the browser displays the "padlock icon" that designates a secure site. The site looks legitimate.

To protect against this scam, set your browser security setting to high, always type a web site address in the address bar, and avoid clicking on any link supplied in an email message to access a web site.

The following web site provides information and practical tips to ensure safer computing:

http://onguardonline.gov/stopthinkclick.html

For more information on IT security, please see Security Matters, the Summer 2005 issue of UCit now.

 

previous article | next article

Return to the Fall 2005 index.



Print-Friendly version


  Footer rule line

Office of Information Technologies
University of Cincinnati
400 University Hall
University of Cincinnati
P.O. Box 210658
Cincinnati, OH 45221-0658
Phone: 513-556-HELP(4357); Fax 513-556-1006
E-mail: helpdesk@uc.edu 
UCit Site Map

Copyright Information © University of Cincinnati