We all know that “Orkut” is vulnerable to problems related to phishing i.e. (stealing of user information) and this is done very easily these days.
What is phishing?(As per Wikipedia) In the field of computer security, phishing is the criminally fraudulent process of attempting to acquire sensitive information such as usernames, passwords and credit card details by masquerading as a trustworthy entity in an electronic communication. Communications purporting to be from popular social web sites, auction sites, online payment processors or IT administrators are commonly used to lure the unsuspecting public. Phishing is typically carried out by e-mail or instant messaging, and it often directs users to enter details at a fake website whose look and feel are almost identical to the legitimate one. Even when using server authentication, it may require tremendous skill to detect that the website is fake. Phishing is an example of social engineering techniques used to fool users, Attempts to deal with the growing number of reported phishing incidents include legislation, user training, public awareness, and technical security measures. and exploits the poor usability of current web security technologies .
Phishing in orkut? When we listen to the word “Phishing” the only thing that comes to our mind is, must be a “phishing mail”. Not necessarily, these days there are new techniques through which it is done, Posting a “Javascript” in a community, When a member pastes’s the javascript into the address bar, it re-directs to a “phishing page” which looks exactly as the login page of orkut. user is tempted to provide his username and password. and once when a user enters his orkut account details in that page, his username and password gets logged in with the “Phisher”. (Who created a fake phishing page) Some of the latest Phishing page pics This is a Javascript code when pasted re-directs you to a phishing page.
How does a Phishing page look like?
How to find out the difference between an original page and a fake page?The basic funda always is to check the Url(https) and a security certificate of website.
1. Https
2. Security certificate
Note: Remember, A fake page or a phishing page never provides you with these above features for identification.
Basic tips for all orkut users
Ways to report a phishing page. 1. To report a orkut page phishing page(reporting of all pages including blogspot),follow the link http://www.google.com/safebrowsing/report_phish/
2. You can also report it here. www.phishtank.com(Operated by Opendns)
On an ending note, if you come across any phishing, please report it so that other user’s do not face issues or fall prey onto it. The more number of user’s who report, the sooner action is to be taken. Spread awareness related to phishing
December 30, 2009 at 10:29 pm
I’m no using Orkut…But I’m sure this post will help a lot of users =)
[Reply]
December 31, 2009 at 1:29 pm
Nice Article Krish, keep up the good work
[Reply]
December 31, 2009 at 4:13 pm
Great article.
Users are recommended to use Firefox, which is more secure than IE. It has option of blocking the opening of reported web forgery(Active by default) and blocking attack sites(You have to enable it yourself). Also, it’s easier to report phishing sites to google. Just go to Help>Report Web Forgery.
Must read: http://www.antiphishing.org/consumer_recs.html
[Reply]
January 1, 2010 at 8:02 pm
Nice article for a orkut lover like me.
.-= Dinesh´s last blog ..Shashi Tharoor Tweets About Excellent Meet With S M Krishna =-.
[Reply]
January 2, 2010 at 11:10 pm
Hello you
Happy New Year
.-= SmashDesign´s last blog ..Hello world ! =-.
[Reply]
Kevin S Reply:
January 2nd, 2010 at 11:12 pm
Hi, Happy new year to you too.
[Reply]
January 19, 2010 at 9:21 pm
Now a days orkut is safe to use and they alow some java scripts to work with their interface and have strog sceaurity.always use firefox with update antivirus to be secuare.
Proxy Sites
.-= Free Proxy List´s last blog ..CupBox.info – Brand New Freedom Proxy =-.
[Reply]
February 1, 2010 at 1:31 pm
Orkut is safe now, It is maintain by google so dont get upset. Just secure your pwd, do not let it know to others directly
[Reply]