วันอังคารที่ 15 กันยายน พ.ศ. 2552

What Everybody Needs To Know About Pharming

Pharming is a type of identity theft and once your private info is in the hands of miscreants it''s all over but the crying. The good news is that most anti-pharming techniques are quite simple.

Anti-virus, anti-spyware, firewalls and the like will not protect you against pharming. While you definitely SHOULD be using all of the above, they are for other matters.

Here are some things you can do to stop pharming before it grows.

1. Pay attention. Any site that you need to enter personal information must be a secure website. You can tell this by looking at the address bar for ''https'' at the address'' beginning. If that isn''t there, it''s not a secure site. You can also look for the small padlock icon in your browser''s status bar. Don''t ever enter personal information on an insecure site.

There are times when an operation will have stupid or lazy IT contractors who coded the lo gin page as non-secure, which then logs you into the secure site. This is just sloppy and stupid but there''s a workaround for it. Go ahead and press ''log in'' without entering a name or password. This will usually take you to the error page, which is on the secure side.

2. Speaking of your browser, switching to Mozilla Firefox and adding the ''petname'' plugin can help protect you as well. It works by letting you assign a pet name to sites you need. If an impostor site shows up, you will be prompted. This is also effective against phishing, giving you two for the same price (which, by the way, is free!) There are many other security-related benefits to using Firefox as well, making it a good choice even if you are not concerned with pharming.

3. Never Never Never accept an expired key certificate from a site you will be entering personal info. Just don''t do it! This same rule applies to certificates from ''unknown'' publishers and is really a common sense thing. You wouldn''t hand your wallet to a stranger on the street, would you? Accepting bogus certs isn''t much different. So, just say ''no.''

4. If you use a router, change the password to your own, not the factory default. Infecting a router is one way that pharming is accomplished. I shouldn''t have to explain why your password isn''t very useful when it is the same one as 27 million others who bought the same router, so I won''t. Make sure the password you choose is immune to dictionary attacks. (And it is not a bad idea to rethink all of your other passwords while you are at it).

5. Change your hosts file to read-only. 6. Flush your DNS cache.

(Steps six and seven will vary with the operating system you are using. An explanation of exactly how to do this is beyond the scope of this article, but is readily available elsewhere.)

These simple measures will make you far far safer from pharming. Do them and you can be better than the pharmer.

ไม่มีความคิดเห็น:

แสดงความคิดเห็น