How could you protect yourself from phishing scams?
Now a days, Hacker are very active and they have a simplest way to reach you that is "Phishing". Today I will tell you how you can Secure from Phishing.
Hackers can reach you in many ways like email, personal messages, Facebook messages, Website ads etc. Clicking any links from these messages would lead you to a login page. Whenever you find an email that navigates you to a webpage, you should note only one thing which is URL because nobody can spoof URL except when there is any XSS zero-day vulnerability.
What is the URL you see in browser address bar? Is that really https://www.LEGITWEBSITE.com? Is there any Green color secure symbol (HTTPS) provided in the address bar? You can prevent hacking by remembering these questions. Also, see the below examples of Facebook phishing pages.
Perfect Phishing Pages
Most of the people won’t suspect this page (snapshot given above) since there is https prefix with the green color secure icon and no mistake in www.facebook.com. But this is a phishing page how? Recheck the URL. It is https://www.facebook.com.infoknown.com so www.facebook.com is a subdomain of infoknown.com.
Google Chrome doesn’t differentiate the sub-domain and domain, unlike Firefox does. SSL Certificates (HTTPS) can be obtained from many vendors, few vendors give SSL Certificate for Free for 1 year. It’s not a big deal for a novice to create a perfect phishing page like this. So beware of it.
This is a normal Facebook Phishing page with some modification in the word Facebook.
Phishing scams
Phishing scams are attempts by scammers/hackers/cybercriminals to trick you to enter your sensitive information like internet banking username & passwords, credit card details etc. As described above, phishing scams focus on retrieving monetary details indirectly.
Phishing Email
Most of the time phishing scams happens through email. Hackers spoof the email address of any legitimate website or authority to send phishing scam email, so the users are convinced to believe that the email is sent from a legit website.
An email address can be easily spoofed using email headers. Server scripting languages like PHP helps a commoner to spoof from email address easily. Popular email services like Gmail are smart enough to identify phishing email and route it to the spam folder. But still, there are some ways for a hacker to send phishing emails.