Wednesday, June 24, 2009

eBay Phishing and Its Prevention Method

In these recent years, phishing is quite popular in e-commerce world. Many people lose their personal information due to "phishing". But, what is phishing? How does phishing actually happen? And, how to prevent it?

What is Phishing?

Phishing means that an intentional acquiring of other people's personal or sensitive information by acting as a business or individual. Usually, scammers will aim their target to obtain username and password on certain website such as bank, ebay and etc.

Phishing actually can be called a synonym to actual fishing. Why? Since scammers will acts as the representative of a company and send an email to try to get the personal and private information. This situation is quite similar with fishing. The scammers throw in the baits and you are the fish if you eat the baits by giving them your username and password.

How Do Scammers Phish?

PayPal and eBay were two of the earliest targets of phishing scams.

Scammers will phish for username and password to enter into the account. By using the ID, they sell fake or non-exist goods. They use the eBay's ID which have positive feedback to scam other people.

Message from member



The scammer will use message from eBay's member as masquerade. When you click respond, it will link to a faked website and when you enter your personal information into that website, they will be able to obtain it. This kind of message normally come in different style and writing.

Another method is using javascript to scam user's personal information. This method is the most clever scams. Scammers can manipulate the javascript and it is hard to recognize whether it is a scam. Normally, they use fake feedback to make buyers believe that they have high reputation in selling their goods. eBay does a lot of prevention to avoid scammers but they can still find their new way around it. So, do watch out when shopping in eBay.

Prevention

To prevent you get scammed in eBay, you must first:
  1. Check the goods the seller sold, if unrelated goods are now selling by his ID, he might be the victim of phishing.
  2. Remember, eBay or Bank will never acquire your personal information by send an email to you.
  3. Enter the email address manually, if eBay or Bank has sent you a important notice.

Besides that, for those who using the Firefox browser, there is an addon called "iTrustpage" which is an anti-phish tools that prevent users to access to a suspicious website.

At the end, I have to say that phishing is now all over e-commerce world, so be careful when buying something from the website. Don't make yourself become a fish by eating the bait that scammers throw in!

No comments:

Post a Comment