This is default featured slide 1 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions..

This is default featured slide 2 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions..

This is default featured slide 3 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions..

This is default featured slide 4 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions..

This is default featured slide 5 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions..

Showing posts with label scams. Show all posts
Showing posts with label scams. Show all posts

Wednesday, May 20, 2009

How To Recognize Ebay Scams

Shopping and selling on eBay can be one of the most rewarding experiences on the Internet. However you need to be careful of scam artists who will try to take advantage of you through various types of fraud. If you do get scammed on eBay there are ways you can get your money back. However, it is very difficult to ever catch the fraud artist and it is a lot simpler if you can recognize and avoid frauds from the beginning.

One of the scams that are very common today is fake e-mails that appear to originate from eBay or PayPal or even your bank. Keep in mind that anybody can spoof any e-mail address and send an e-mail that appears to be from somebody else. It is even possible to spoof an e-mail coming from the president of the United States. So when you see any e-mail in your inbox that comes from eBay or PayPal and asks you to log in to confirm your password the chances are that this is a scam. E-mails that you receive of this type will have eBay letterheads or PayPal letterheads and will direct you to a link that appears to be eBay or PayPal. However, if you look closely at the bottom of your browser you’ll generally see that the domain these links point to is not actually an eBay or PayPal domain. It just looks like eBay’s web site, but it is actually a scam site asking you to confirm your password. Once you put in your username and password the fraud artist has it. One of the more popular tactics being used right now is to send a fake payment notification from PayPal suggesting that you have paid for something which you did not buy. The e-mail and includes a link right in the center that says “dispute this charge”, and once you click on that link you are taken to a page that looks like PayPal but is actually a fraudulent web site designed to get you to enter your username and password.

One of the easiest ways to protect yourself on eBay is to use PayPal for all transactions. PayPal is a wholly-owned subsidiary of eBay, and so transactions that are paid for via PayPal can be easily disputed. Since it is in eBay’s interest to maintain a secure shopping environment they are generally very quick to resolve disputes that originate by PayPal. If you buy an item and are not satisfied with it and feel like the seller did not deliver what he promised, it is far easier to dispute that transaction fee with PayPal because eBay can reverse the funds themselves. If you purchased by money order or credit card or some other payment method, eBay does not have the opportunity to reverse charges without going through a third-party.

Whether you are buying or selling items is a good idea to stick with PayPal. If you are selling items it is a good idea to only except PayPal as a payment option. The last thing you need is to get a bad check, or have your buyer dispute his credit card charge. If you have fulfilled your end of the seller’s bargain, then all you’ll need to do is prove that to PayPal and eBay without involving a third-party. Generally speaking, if a buyer is unhappy with a product that you sold and does not consider the product to be in the condition advertised, then you should demand that the product be returned before you issue a refund.

In order to sell on eBay effectively you need to learn how to use reserve pricing. One of the most common schemes on eBay is for someone using multiple accounts to place a low bid and a high bid simultaneously under different aliases. This ties up your auction at the high bid price and allows of the fraud to be carried out when the high bid buyer declines to pay and you are confronted with a low second bid. This scam is effective because the seller feels obligated to sell the item to the second-highest bidder once the auction has fallen through with the top bidder. Placing a reserve is essential to avoid this kind of scam so be sure to set a reserve price at the point where you would not sell the product for any less.

It is worthwhile to note right on your auction page that you reserve the right to back out of selling an item if you suspect fraud. While it is easy to get scammed as a buyer it is even easier to get scammed as a seller. Sellers generally have more experience and can recognize these scams, but you should be aware of the pitfalls of selling upfront before you start selling items on eBay.

EBay is a very safe and secure way to shop if you use it wisely and remain aware of how fraud occurs. It is important to always report suspicious activity directly to the eBay or PayPal. Since they have a vested interest in assuring that reliable transactions occur without fraud you can be sure that they will do their best to prevent illegal fraudulent activity.

Thursday, March 19, 2009

Phishing, Fraudulent and Malicious Websites

Whether we like it or not, we are all living in the Information Age. We have nothing left but adapt to rapidly developing information technology, no matter who we are and what we do for living.

The Internet, in particular, means for us boundless opportunities in life and business – but also lots of dangers unheard of just a decade ago. We should be aware of these dangers if we want to use the huge potential of the Internet and to avoid the hazards it brings us.

Warning: There are Websites You'd Better Not Visit

Phishing websites

Thanks to authors of numerous articles on this topic, "classic" phishing technique is relatively well known. This scam involves setting bogus websites and luring people to visit them, as a rule, by links in emails. Phishing website is disguised to look like a legitimate one -- of a bank or a credit card company, and users are invited to provide their identifying information. Sites of this kind are used solely to steal users' passwords, PIN numbers, SSNs and other confidential information.

At first phishing consisted only of a social engineering scam in which phishers spammed consumer e-mail accounts with letters ostensibly from banks. The more people got aware of the scam, the less spelling mistakes these messages contained, and the more these fraudulent websites resembled legitimate ones. Phishers are getting smarter. They eagerly learn; there is enough money involved here to turn criminals into earnest students.

Since about November 2004 there has been a lot of publications of a scheme which at first was seen as a new kind of phishing. This technique includes contaminating a PC with a Trojan horse program. The problem is that this Trojan contains a keylogger which lurks at the background until the user of the infected PC visits one of the specified websites. Then the keylogger comes to life to do what it was created for -- to steal information.

It seems that this technique is actually a separate scam aimed at stealing personal information and such attacks are on the rise. Security experts warn about commercialisation of malware -- cybercriminals prefer cash to fun, so various kinds of information-stealing software are used more actively.

Fraudulent websites are on the rise

Websense Security Labs -- a well-known authority in information security -- noticed a dramatic rise in the number of fraudulent websites as far back as in the second half of 2004. These sites pose as ones for e-commerce; they encourage users to apply for a reward or purchase something, of course never delivering the product or paying money. The most popular areas for such fraud are online pharmacies, lottery scams, and loan / mortgage sites. Experts predict there will be more fake merchants in future and their scams will become more sophisticated.

Malicious websites are especially dangerous. Cybercriminals create them exclusively to execute malicious code on the visitors' computers. Sometimes hackers infect legitimate sites with malicious code.

Bad news for blog readers: blogs can be contaminated, too. Since January, Websense Security Labs has discovered hundreds of these "toxic" blogs set by hackers.

When unsuspecting users visit malicious sites, various nasty applications are downloaded and executed on their computers. Unfortunately, more and more often these applications contain keyloggers--software programs for intercepting data.

Keyloggers, as it is clear from the name of the program, log keystrokes --but that's not all. They capture everything the user is doing -- keystrokes, mouse clicks, files opened and closed, sites visited. A little more sophisticated programs of this kind also capture text from windows and make screenshots (record everything displayed on the screen) – so the information is captured even if the user doesn't type anything, just opens the views the file.

In February and March 2005, Websense Security Labs researched and identified about 8-10 new keylogger variants and more than 100 malicious websites which are hosting these keyloggers EACH WEEK. From November of 2004 through December 2004 these figures were much smaller: 1-2 new keylogger variants and 10-15 new malicious websites per week. There is by all means a disturbing tendency--the number of brand-new keyloggers and malicious website is growing, and growing rapidly.

What a user can do to avoid these sites?

As for phishing, the best advice is not to click any links in any email, especially if it claims to be from a bank.

Opening an attachment of a spam message can also trigger the execution of malicious program, for example a keylogger-containing Trojan horse.

As for fraudulent websites, maybe buying goods only from trusted vendors will help -- even if it is a bit more expensive.

As for malicious websites… "Malicious websites that host adult entertainment and shopping content can exploit Internet Explorer vulnerabilities to run code remotely without user interaction."(a quote from Websense's report). What can a user do about it? Not much, but avoiding adult sites and buying only from known and trusted online stores will reduce the risk.

Hackers also attract traffic to malicious websites by sending a link through spam or spim (the analog of spam for instant messaging (IM). So a good advice never follow links in spam is worth remembering once more.