Security Basics mailing list archives

RE: HOW TO PREVENT FHISHING ATTACKS


From: "Lynch, Gordon CTR NHRC" <Gordon.Lynch () med navy mil>
Date: Thu, 3 Feb 2011 08:41:19 -0800

Adam's right, client/user training is where some action should be
applied. Therefore, it might be useful to occasionally remind clients
that the bank will NEVER ask for personal information in an email or in
snail mail. After all, the bank should already have that information,
why would they ask for it? I work for the Navy, and we do annual
training about security and phishing and spear-phishing are both covered
in detail. You can't get bank clients in a training class, but you can
send them snail/emails reminding them to never give out personal
information
Regards,
Gordon Lynch

-----Original Message-----
From: listbounce () securityfocus com [mailto:listbounce () securityfocus com]
On Behalf Of Adam Pal
Sent: Wednesday, February 02, 2011 1:35 PM
To: mzcohen2682 () aim com
Cc: security-basics () securityfocus com
Subject: Re: HOW TO PREVENT FHISHING ATTACKS

Hello Mzcohen2682,

Phishing is a social engineering technique, so the only proficient way
to protect against is: training, security awareness, training...

If we take the scenario of withdraw administrator rights - whats the
benefit for phishing attack? Having no administrator privileges wont
stop the user entering whatever credentials the Email is asking for.

The weakest member member of the chain is the user.



Best regards,
 Adam Pal   

Friday, January 28, 2011, 12:44:06 AM, you wrote:

<==============Original message text===============
mac> Hi Guys,

mac> I am preparing a set of recommendation for a client of mine which
is a
mac> bank , a set of controls against fhisging attacks, besides of
telling 
mac> the bank to teach there customers how to protect against those
attacks
mac> ( not opening suspicious mails etc etc) what other recommendations
are
mac> good? are there some technological tools to prevent those attacks
that
mac> the bank can implement? I heard something about imperva radar
service 
mac> which should protect against fishing attack, some one has
experience 
mac> with that tool? what about other tools that the bank can implement?

mac> many thanks!

mac> Marco

mac>
------------------------------------------------------------------------
mac> Securing Apache Web Server with thawte Digital Certificate
mac> In this guide we examine the importance of Apache-SSL and who
mac> needs an SSL certificate.  We look at how SSL works, how it
mac> benefits your company and how your customers can tell if a site
mac> is secure. You will find out how to test, purchase, install and
mac> use a thawte Digital Certificate on your Apache web server.
mac> Throughout, best practices for set-up are highlighted to help you
mac> ensure efficient ongoing management of your encryption keys and
digital certificates.

mac>
http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442
f727d1
mac>
------------------------------------------------------------------------


<===========End of original message text===========



------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an
SSL certificate.  We look at how SSL works, how it benefits your company
and how your customers can tell if a site is secure. You will find out
how to test, purchase, install and use a thawte Digital Certificate on
your Apache web server. Throughout, best practices for set-up are
highlighted to help you ensure efficient ongoing management of your
encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442
f727d1
------------------------------------------------------------------------


------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how 
it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, 
install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are 
highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------


Current thread: