Pegasus InfoCorp: Web site design and web software development company
Home About Us Services Solutions Clientele Contact Us
Technology @ Pegasus InfoCorp
 
     
Ecommerce Web Site Development, Ecommerce Web Site Development USA, Ecommerce Web Site Development UK, Ecommerce Web Site Development Europe, Ecommerce Web Site Development Canada, Ecommerce Web Site Development Australia, Ecommerce Web Site Development Asia, Ecommerce Web Site Development India
Request a free quote!
Name :
Phone :
Email :
Comments :
     
Home
Clients
Contact Us

Dangerous game

Those running the study said website designers needed to re-think ways of flagging dangers to users.

The study looked at bogus websites created by phishing gangs and what made users believe that these sites were legitimate. Industry statistics suggest that, on average, 5% of those that get phishing e-mails visit an associated website and are conned into handing over data.

Although low, this figure is far more than the phishing gangs need to turn a healthy profit.

The study, carried out by post graduate student Rachna Dhamija of the Harvard Center for Research on Computation and Society, Professor Doug Tygar in the department of Computer Science at Berkeley and Professor Marti Hearst at Berkeley, suggests that on relatively sophisticated scams, many times more people are taken in.

SPOTTING PHISHING SITES
Check the address bar - fake sites are often hosted on domains that have nothing to do with their target. Although eBay owns www.ebay.com it may not own www.ebay-members-security.com.
Retype web links rather than click on them - legitimate-looking links in phishing e-mails often redirect you to fake sites.
Spelling test - some phishing gangs make their own webpages and often they are full of spelling and grammatical errors.
Site security - most online banks use weblinks starting "https" rather than "http".
Naked numbers - Few organisations use raw net addresses in e-mails and seeing one can flag a problem.
Use an anti-phishing toolbar - add-ons to browsers are produced by firms such as ebay, Netcraft, Geotrust, Cloudmark, Comodo and Phishing.net that can flag fake sites. Also worth using is the Site Advisor add-on for IE and Firefox.
The study presented real online banking and fake phishing sites to subjects to see if they could tell the two types apart.

On average, 40% of users failed to spot the phishing sites. The most sophisticated site caught out 90% of the 22 people participating.

The study revealed that people were caught out because they were generally ignorant about what did, and did not, indicate that a site was legitimate.

For instance, few of those participating looked at the domain name, such as bbc.co.uk, being displayed in a browser address bar.

Users generally did not look at the address bar, status bar or other security indicators that could flag if they had unwittingly strayed on to a phishing site.

The problem, said the researchers, was that "the indicators of trust presented by the browser are trivial to spoof".

Many participants also ignored more direct warnings contained in pop-up windows that a site may not be legitimate.

The researchers also said phishing gangs were being successful because many of the scams being mounted were very sophisticated and could catch out even seasoned users.

The academics said the results would help educate users about relevant dangers and to help those who create websites know which attacks succeed and why.

The researchers said: "These results illustrate that standard security indicators are not effective for a substantial fraction of users, and suggest that alternative approaches are needed."

The trio of researchers said the traditional security approach looks at what can be made secure rather than work out what humans do well and exploit that to make sites safer. The team is now working on ways to make fake sites far more obvious when reached by users likely to be caught out.

The researchers presented their results at the 2006 E-Crime Congress held in London.

 
Story from bbc.co.uk
 
 
Pegasus InfoCorp helps build customized web software and undertakes web development software solutions for clients internationally. We also build front end websites, and offline software that integrates with our web based software. Our services/ custom built software solutions include Ecommerce Web Site Development, web development, web software, small business web software development, ecommerce web site, mail order software and enterprise scale business software development on web technologies.
 
To know more about how we can meet your specific requirements, please drop us a message or mail us at 'contact [at] pegasusinfocorp.com'. Please click here to drop us a message.
 
Quick Links
 
web design, web development, software development, web software development, web site design, web site development, web site software development Home
web site development India, web site design and web site development, web site design company, web design company, software development company, web software development company, ecommerce web design company, ecommerce web site company Featured Clients
design development professional site web, web design, web development, software development, web software development, web site design, web site development, web site software development Why Choose Pegasus ?
offshore web site development, web site design company, web design company, software development company, web software development company, ecommerce web design company, ecommerce web site company Services
fashion designing web site, designing web site online Solutions
web site designing Mumbai, web site design company, web design company, software development company, web software development company, ecommerce web design company, ecommerce web site company Contact Us
designing good web site, designing optimization site web, web design, web development, software development, web software development, web site design, web site development, web site software development Site Map
 
Featured Clients
 
designing good web site, designing optimization site web Online Customer Relationship Management Software
designing good web site, designing optimization site web ICUIL (International)
designing good web site, designing optimization site web Smart Fashions (Dewsbury, UK)
designing good web site, designing optimization site web Aus RFID (Canberra, Australia)
designing good web site, designing optimization site web Marlex (Mumbai, India)
designing good web site, designing optimization site web Bonace Engineers
designing good web site, designing optimization site web Planet Bombay
designing good web site, designing optimization site web X-cessory
 
 
 
Home | About Us
 |  Services  |  Solutions  |  Clientele  |  Contact Us
 
Directory | Links
 |  Web Development  |  Web Services  |  Web Software  |  Website Programming
  Internet Applications  |  Website Development USA  |  Website Development UK  |  Website Development Canada
  International Web Development  |  Global Web Development  |  Outsource India  |  Website Design  |  Web Site Design Company
  Development Offshore 
;Outsource Software
 |  Ecommerce  |  Developer Offshore S
oftware
 |  Customized Software  |  Development
  Database Software Fo
r Palm
 |  Education  |  ERP  |  Database Software  |  Custom Software Deve
lopment Service