<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.expertiza.ncsu.edu/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Mbastan</id>
	<title>Expertiza_Wiki - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.expertiza.ncsu.edu/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Mbastan"/>
	<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=Special:Contributions/Mbastan"/>
	<updated>2026-08-14T23:08:15Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.41.0</generator>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379_SUM2008:Week_5,_Group_1&amp;diff=17006</id>
		<title>CSC 379 SUM2008:Week 5, Group 1</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379_SUM2008:Week_5,_Group_1&amp;diff=17006"/>
		<updated>2008-08-10T13:30:15Z</updated>

		<summary type="html">&lt;p&gt;Mbastan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Background ==&lt;br /&gt;
&lt;br /&gt;
Examine the ways an organization can help employees resolve concerns internally, and thereby avoid the need for external whistleblowing.  How do these practices, such as anonymous reporting hotlines, apply to the work environment of a software engineer?  &lt;br /&gt;
&lt;br /&gt;
Due to ineffective or nonexistent feedback processes within an organization, many important concerns never reach anyone who is willing or able to take action.  Employees may forgo making complaints due to processes that are hard to use, or because the company culture has no way to report anything, except to one’s immediate superior.&lt;br /&gt;
&lt;br /&gt;
What can be done to reduce the need for external whistleblowing?  Are there proven cultural fixes?  Technological fixes?  If someone has a less serious concern, which (s)he considers too insignificant to take the risk of external whistleblowing, how could this be actively addressed before problems arise?  Is there an ethical obligation on the part of organizations to adopt practices that encourage effective internal whistleblowing?  Please explain your answers.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Avoiding the Need for Whistleblowing ==&lt;br /&gt;
&lt;br /&gt;
Whistleblowing is a term used to denote an activity whereby an individual within a group (a company, a university, etc) presents a public report detailing a (typically) unethical action that has taken place within their group. The report is presented to the public because the individual has presumably already reported the violation via internal channels, and no action has taken place. By making the violation public, pressure is applied to the group to rectify the problem.&lt;br /&gt;
&lt;br /&gt;
== Problems With Conventional Whistleblowing ==&lt;br /&gt;
&lt;br /&gt;
Whistleblowing is not without its disadvantages, however. The primary problem with whistleblowing is that the whistleblower almost always faces retaliation. This can range anywhere from facing hostility at work to being sued by the company for breach of confidentiality. Whistleblowers may even face demotions, reassignments, or in the worst case may lose their jobs. In rare instances, threats to their well-being or families may also occur. There is therefore a strong disincentive to remain silent about an illicit activity, should it be discovered. While laws are in place to protect whistleblowers, knowledge of their existence is limited, and whistleblowers may only find out about them after the statute of limitations has expired.&lt;br /&gt;
&lt;br /&gt;
But preventing or stopping that illicit activity is the morally and ethically correct course of action, and steps to do so can only be taken after the knowledge can be communicated to the people with the power to take action. And if the severity of the problem is great enough that it may result in loss of life, the whistleblower would even have a moral obligation to report his or her findings, regardless of the consequences.&lt;br /&gt;
&lt;br /&gt;
To balance the simultaneous needs of allowing whistleblowers to file their grievances and protecting them from retribution, alternatives are necessary. The below sections attempt to list and explain these alternatives.&lt;br /&gt;
&lt;br /&gt;
==Whistle-blowing and codes of morality==&lt;br /&gt;
&lt;br /&gt;
Duty to the public is the first principle of the code of the National Society of professionals. Given that, a great deal of responsibility engineers are to carry. The fourth principle describes the duty of the employer as: ‘‘the health, safety, and welfare of the public are to be placed first’’ (Harris et al., 2005, p. 183). Therefore we can derive the conclusion that whistle blowing is mandatory in certain situations.&lt;br /&gt;
&lt;br /&gt;
====Duality of engineering ethics====&lt;br /&gt;
&lt;br /&gt;
The ethic courses that are being offered in the engineering school, usually discusses different cases and inquire what should an engineer do. The cases are usually a mixture of different issues such as scientific, humanistic, and social issues. Then they try to come up with a solution that covers all aspects of the case. However codes of conduct are principles that engineers pursue them as their duties. There are two different aspects to it; What should an engineer do from an ethical point of view that is his/her duty, and what should he/she do from a non-ethical point of view, that is technical concerns. Therefore the whistle blowing in many situation will be obligatory.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''Issues with heroism.'' Because of the whistleblower’s pure intention and the danger that they bring to themselves, one would conclude that this is heroism. But since whistleblowing is an ethical obligation, one can not be hero by living up to his/her duties. Whistleblowing has been referred to as a heroic act by so many people that it seems people have forgotten that it is an obligation by our morality.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Links ==&lt;br /&gt;
&lt;br /&gt;
* [http://www3.interscience.wiley.com/journal/119949153/abstract Whistleblowing at work: ingredients for an effective procedure]&lt;br /&gt;
* [http://www.springerlink.com/content/t61246w14l64k416/  Organizational Culture: A Framework and Strategies for Facilitating Employee Whistleblowing]&lt;br /&gt;
* [http://portal.acm.org/citation.cfm?doid=367211.367274 Blowing the whistle on troubled software projects]&lt;br /&gt;
* [http://courses.ncsu.edu/csc379/lec/001/lectures/wk15/lecture.html cture 15: Whistleblowing]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/basics/whistle/ Ethics in Computing]&lt;br /&gt;
* [http://www.springerlink.com.www.lib.ncsu.edu:2048/content/w2t5252050044180/fulltext.pdf Whistle-Blowing and Morality] Mathieu Bouville&lt;/div&gt;</summary>
		<author><name>Mbastan</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379_SUM2008:Week_5,_Group_1&amp;diff=17005</id>
		<title>CSC 379 SUM2008:Week 5, Group 1</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379_SUM2008:Week_5,_Group_1&amp;diff=17005"/>
		<updated>2008-08-10T13:29:33Z</updated>

		<summary type="html">&lt;p&gt;Mbastan: /* Assignment Description */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Avoiding the Need for Whistleblowing ==&lt;br /&gt;
&lt;br /&gt;
Whistleblowing is a term used to denote an activity whereby an individual within a group (a company, a university, etc) presents a public report detailing a (typically) unethical action that has taken place within their group. The report is presented to the public because the individual has presumably already reported the violation via internal channels, and no action has taken place. By making the violation public, pressure is applied to the group to rectify the problem.&lt;br /&gt;
&lt;br /&gt;
== Problems With Conventional Whistleblowing ==&lt;br /&gt;
&lt;br /&gt;
Whistleblowing is not without its disadvantages, however. The primary problem with whistleblowing is that the whistleblower almost always faces retaliation. This can range anywhere from facing hostility at work to being sued by the company for breach of confidentiality. Whistleblowers may even face demotions, reassignments, or in the worst case may lose their jobs. In rare instances, threats to their well-being or families may also occur. There is therefore a strong disincentive to remain silent about an illicit activity, should it be discovered. While laws are in place to protect whistleblowers, knowledge of their existence is limited, and whistleblowers may only find out about them after the statute of limitations has expired.&lt;br /&gt;
&lt;br /&gt;
But preventing or stopping that illicit activity is the morally and ethically correct course of action, and steps to do so can only be taken after the knowledge can be communicated to the people with the power to take action. And if the severity of the problem is great enough that it may result in loss of life, the whistleblower would even have a moral obligation to report his or her findings, regardless of the consequences.&lt;br /&gt;
&lt;br /&gt;
To balance the simultaneous needs of allowing whistleblowers to file their grievances and protecting them from retribution, alternatives are necessary. The below sections attempt to list and explain these alternatives.&lt;br /&gt;
&lt;br /&gt;
==Whistle-blowing and codes of morality==&lt;br /&gt;
&lt;br /&gt;
Duty to the public is the first principle of the code of the National Society of professionals. Given that, a great deal of responsibility engineers are to carry. The fourth principle describes the duty of the employer as: ‘‘the health, safety, and welfare of the public are to be placed first’’ (Harris et al., 2005, p. 183). Therefore we can derive the conclusion that whistle blowing is mandatory in certain situations.&lt;br /&gt;
&lt;br /&gt;
====Duality of engineering ethics====&lt;br /&gt;
&lt;br /&gt;
The ethic courses that are being offered in the engineering school, usually discusses different cases and inquire what should an engineer do. The cases are usually a mixture of different issues such as scientific, humanistic, and social issues. Then they try to come up with a solution that covers all aspects of the case. However codes of conduct are principles that engineers pursue them as their duties. There are two different aspects to it; What should an engineer do from an ethical point of view that is his/her duty, and what should he/she do from a non-ethical point of view, that is technical concerns. Therefore the whistle blowing in many situation will be obligatory.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''Issues with heroism.'' Because of the whistleblower’s pure intention and the danger that they bring to themselves, one would conclude that this is heroism. But since whistleblowing is an ethical obligation, one can not be hero by living up to his/her duties. Whistleblowing has been referred to as a heroic act by so many people that it seems people have forgotten that it is an obligation by our morality.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Assignment Description ==&lt;br /&gt;
&lt;br /&gt;
Examine the ways an organization can help employees resolve concerns internally, and thereby avoid the need for external whistleblowing.  How do these practices, such as anonymous reporting hotlines, apply to the work environment of a software engineer?  &lt;br /&gt;
&lt;br /&gt;
Due to ineffective or nonexistent feedback processes within an organization, many important concerns never reach anyone who is willing or able to take action.  Employees may forgo making complaints due to processes that are hard to use, or because the company culture has no way to report anything, except to one’s immediate superior.&lt;br /&gt;
&lt;br /&gt;
What can be done to reduce the need for external whistleblowing?  Are there proven cultural fixes?  Technological fixes?  If someone has a less serious concern, which (s)he considers too insignificant to take the risk of external whistleblowing, how could this be actively addressed before problems arise?  Is there an ethical obligation on the part of organizations to adopt practices that encourage effective internal whistleblowing?  Please explain your answers.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Links ==&lt;br /&gt;
&lt;br /&gt;
* [http://www3.interscience.wiley.com/journal/119949153/abstract Whistleblowing at work: ingredients for an effective procedure]&lt;br /&gt;
* [http://www.springerlink.com/content/t61246w14l64k416/  Organizational Culture: A Framework and Strategies for Facilitating Employee Whistleblowing]&lt;br /&gt;
* [http://portal.acm.org/citation.cfm?doid=367211.367274 Blowing the whistle on troubled software projects]&lt;br /&gt;
* [http://courses.ncsu.edu/csc379/lec/001/lectures/wk15/lecture.html cture 15: Whistleblowing]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/basics/whistle/ Ethics in Computing]&lt;br /&gt;
* [http://www.springerlink.com.www.lib.ncsu.edu:2048/content/w2t5252050044180/fulltext.pdf Whistle-Blowing and Morality] Mathieu Bouville&lt;/div&gt;</summary>
		<author><name>Mbastan</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379_SUM2008:Week_5,_Group_1&amp;diff=17004</id>
		<title>CSC 379 SUM2008:Week 5, Group 1</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379_SUM2008:Week_5,_Group_1&amp;diff=17004"/>
		<updated>2008-08-10T13:25:20Z</updated>

		<summary type="html">&lt;p&gt;Mbastan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Avoiding the Need for Whistleblowing ==&lt;br /&gt;
&lt;br /&gt;
Whistleblowing is a term used to denote an activity whereby an individual within a group (a company, a university, etc) presents a public report detailing a (typically) unethical action that has taken place within their group. The report is presented to the public because the individual has presumably already reported the violation via internal channels, and no action has taken place. By making the violation public, pressure is applied to the group to rectify the problem.&lt;br /&gt;
&lt;br /&gt;
== Problems With Conventional Whistleblowing ==&lt;br /&gt;
&lt;br /&gt;
Whistleblowing is not without its disadvantages, however. The primary problem with whistleblowing is that the whistleblower almost always faces retaliation. This can range anywhere from facing hostility at work to being sued by the company for breach of confidentiality. Whistleblowers may even face demotions, reassignments, or in the worst case may lose their jobs. In rare instances, threats to their well-being or families may also occur. There is therefore a strong disincentive to remain silent about an illicit activity, should it be discovered. While laws are in place to protect whistleblowers, knowledge of their existence is limited, and whistleblowers may only find out about them after the statute of limitations has expired.&lt;br /&gt;
&lt;br /&gt;
But preventing or stopping that illicit activity is the morally and ethically correct course of action, and steps to do so can only be taken after the knowledge can be communicated to the people with the power to take action. And if the severity of the problem is great enough that it may result in loss of life, the whistleblower would even have a moral obligation to report his or her findings, regardless of the consequences.&lt;br /&gt;
&lt;br /&gt;
To balance the simultaneous needs of allowing whistleblowers to file their grievances and protecting them from retribution, alternatives are necessary. The below sections attempt to list and explain these alternatives.&lt;br /&gt;
&lt;br /&gt;
==Whistle-blowing and codes of morality==&lt;br /&gt;
&lt;br /&gt;
Duty to the public is the first principle of the code of the National Society of professionals. Given that, a great deal of responsibility engineers are to carry. The fourth principle describes the duty of the employer as: ‘‘the health, safety, and welfare of the public are to be placed first’’ (Harris et al., 2005, p. 183). Therefore we can derive the conclusion that whistle blowing is mandatory in certain situations.&lt;br /&gt;
&lt;br /&gt;
====Duality of engineering ethics====&lt;br /&gt;
&lt;br /&gt;
The ethic courses that are being offered in the engineering school, usually discusses different cases and inquire what should an engineer do. The cases are usually a mixture of different issues such as scientific, humanistic, and social issues. Then they try to come up with a solution that covers all aspects of the case. However codes of conduct are principles that engineers pursue them as their duties. There are two different aspects to it; What should an engineer do from an ethical point of view that is his/her duty, and what should he/she do from a non-ethical point of view, that is technical concerns. Therefore the whistle blowing in many situation will be obligatory.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''Issues with heroism.'' Because of the whistleblower’s pure intention and the danger that they bring to themselves, one would conclude that this is heroism. But since whistleblowing is an ethical obligation, one can not be hero by living up to his/her duties. Whistleblowing has been referred to as a heroic act by so many people that it seems people have forgotten that it is an obligation by our morality.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Assignment Description ==&lt;br /&gt;
&lt;br /&gt;
Examine the ways an organization can help employees resolve concerns internally, and thereby avoid the need for external whistleblowing.  How do these practices, such as anonymous reporting hotlines, apply to the work environment of a software engineer?  &lt;br /&gt;
&lt;br /&gt;
Due to ineffective or nonexistent feedback processes within an organization, many important concerns never reach anyone who is willing or able to take action.  Employees may forgo making complaints due to processes that are hard to use, or because the company culture has no way to report anything, except to one’s immediate superior.&lt;br /&gt;
&lt;br /&gt;
What can be done to reduce the need for external whistleblowing?  Are there proven cultural fixes?  Technological fixes?  If someone has a less serious concern, which (s)he considers too insignificant to take the risk of external whistleblowing, how could this be actively addressed before problems arise?  Is there an ethical obligation on the part of organizations to adopt practices that encourage effective internal whistleblowing?  Please explain your answers.&lt;br /&gt;
&lt;br /&gt;
* [http://www3.interscience.wiley.com/journal/119949153/abstract Whistleblowing at work: ingredients for an effective procedure]&lt;br /&gt;
* [http://www.springerlink.com/content/t61246w14l64k416/  Organizational Culture: A Framework and Strategies for Facilitating Employee Whistleblowing]&lt;br /&gt;
* [http://portal.acm.org/citation.cfm?doid=367211.367274 Blowing the whistle on troubled software projects]&lt;br /&gt;
* [http://courses.ncsu.edu/csc379/lec/001/lectures/wk15/lecture.html cture 15: Whistleblowing]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/basics/whistle/ Ethics in Computing]&lt;br /&gt;
* [http://www.springerlink.com.www.lib.ncsu.edu:2048/content/w2t5252050044180/fulltext.pdf Whistle-Blowing and Morality] Mathieu Bouville&lt;/div&gt;</summary>
		<author><name>Mbastan</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379_SUM2008:Week_5,_Group_1&amp;diff=16984</id>
		<title>CSC 379 SUM2008:Week 5, Group 1</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379_SUM2008:Week_5,_Group_1&amp;diff=16984"/>
		<updated>2008-08-09T14:46:46Z</updated>

		<summary type="html">&lt;p&gt;Mbastan: /* Assignment Description */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Avoiding the Need for Whistleblowing ==&lt;br /&gt;
&lt;br /&gt;
Whistleblowing is a term used to denote an activity whereby an individual within a group (a company, a university, etc) presents a public report detailing a (typically) unethical action that has taken place within their group. The report is presented to the public because the individual has presumably already reported the violation via internal channels, and no action has taken place. By making the violation public, pressure is applied to the group to rectify the problem.&lt;br /&gt;
&lt;br /&gt;
== Problems With Conventional Whistleblowing ==&lt;br /&gt;
&lt;br /&gt;
Whistleblowing is not without its disadvantages, however. The primary problem with whistleblowing is that the whistleblower almost always faces retaliation. This can range anywhere from facing hostility at work to being sued by the company for breach of confidentiality. Whistleblowers may even face demotions, reassignments, or in the worst case may lose their jobs. In rare instances, threats to their well-being or families may also occur. There is therefore a strong disincentive to remain silent about an illicit activity, should it be discovered. While laws are in place to protect whistleblowers, knowledge of their existence is limited, and whistleblowers may only find out about them after the statute of limitations has expired.&lt;br /&gt;
&lt;br /&gt;
But preventing or stopping that illicit activity is the morally and ethically correct course of action, and steps to do so can only be taken after the knowledge can be communicated to the people with the power to take action. And if the severity of the problem is great enough that it may result in loss of life, the whistleblower would even have a moral obligation to report his or her findings, regardless of the consequences.&lt;br /&gt;
&lt;br /&gt;
To balance the simultaneous needs of allowing whistleblowers to file their grievances and protecting them from retribution, alternatives are necessary. The below sections attempt to list and explain these alternatives.&lt;br /&gt;
&lt;br /&gt;
==Whistle-blowing and codes of morality==&lt;br /&gt;
&lt;br /&gt;
Duty to the public is the first principle of the code of the National Society of professionals. Given that, a great deal of responsibility engineers are to carry. The fourth principle describes the duty of the employer as: ‘‘the health, safety, and welfare of the public are to be placed first’’ (Harris et al., 2005, p. 183). Therefore we can derive the conclusion that whistle blowing is mandatory in certain situations.&lt;br /&gt;
&lt;br /&gt;
====Duality of engineering ethics====&lt;br /&gt;
&lt;br /&gt;
The ethic courses that are being offered in the engineering school, usually discusses different cases and inquire what should an engineer do. The cases are usually a mixture of different issues such as scientific, humanistic, and social issues. Then they try to come up with a solution that covers all aspects of the case. However codes of conduct are principles that engineers pursue them as their duties. There are two different aspects to it; What should an engineer do from an ethical point of view that is his/her duty, and what should he/she do from a non-ethical point of view, that is technical concerns. Therefore the whistle blowing in many situation will be obligatory.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''Issues with heroism.'' Because of the whistleblower’s pure intention and the danger that they bring to themselves, one would conclude that this is heroism. But since whistleblowing is an ethical obligation, one can not be hero by living up to his/her duties. Whistleblowing has been referred to as a heroic act by so many people that it seems people have forgotten that it is an obligation by our morality.&lt;br /&gt;
&lt;br /&gt;
== Alternatives ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Assignment Description ==&lt;br /&gt;
&lt;br /&gt;
Examine the ways an organization can help employees resolve concerns internally, and thereby avoid the need for external whistleblowing.  How do these practices, such as anonymous reporting hotlines, apply to the work environment of a software engineer?  &lt;br /&gt;
&lt;br /&gt;
Due to ineffective or nonexistent feedback processes within an organization, many important concerns never reach anyone who is willing or able to take action.  Employees may forgo making complaints due to processes that are hard to use, or because the company culture has no way to report anything, except to one’s immediate superior.&lt;br /&gt;
&lt;br /&gt;
What can be done to reduce the need for external whistleblowing?  Are there proven cultural fixes?  Technological fixes?  If someone has a less serious concern, which (s)he considers too insignificant to take the risk of external whistleblowing, how could this be actively addressed before problems arise?  Is there an ethical obligation on the part of organizations to adopt practices that encourage effective internal whistleblowing?  Please explain your answers.&lt;br /&gt;
&lt;br /&gt;
* [http://www3.interscience.wiley.com/journal/119949153/abstract Whistleblowing at work: ingredients for an effective procedure]&lt;br /&gt;
* [http://www.springerlink.com/content/t61246w14l64k416/  Organizational Culture: A Framework and Strategies for Facilitating Employee Whistleblowing]&lt;br /&gt;
* [http://portal.acm.org/citation.cfm?doid=367211.367274 Blowing the whistle on troubled software projects]&lt;br /&gt;
* [http://courses.ncsu.edu/csc379/lec/001/lectures/wk15/lecture.html cture 15: Whistleblowing]&lt;br /&gt;
* [http://ethics.csc.ncsu.edu/basics/whistle/ Ethics in Computing]&lt;br /&gt;
* [http://www.springerlink.com.www.lib.ncsu.edu:2048/content/w2t5252050044180/fulltext.pdf Whistle-Blowing and Morality] Mathieu Bouville&lt;/div&gt;</summary>
		<author><name>Mbastan</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379_SUM2008:Week_5,_Group_1&amp;diff=16983</id>
		<title>CSC 379 SUM2008:Week 5, Group 1</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379_SUM2008:Week_5,_Group_1&amp;diff=16983"/>
		<updated>2008-08-09T14:37:40Z</updated>

		<summary type="html">&lt;p&gt;Mbastan: /* Assignment Description */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Avoiding the Need for Whistleblowing ==&lt;br /&gt;
&lt;br /&gt;
Whistleblowing is a term used to denote an activity whereby an individual within a group (a company, a university, etc) presents a public report detailing a (typically) unethical action that has taken place within their group. The report is presented to the public because the individual has presumably already reported the violation via internal channels, and no action has taken place. By making the violation public, pressure is applied to the group to rectify the problem.&lt;br /&gt;
&lt;br /&gt;
== Problems With Conventional Whistleblowing ==&lt;br /&gt;
&lt;br /&gt;
Whistleblowing is not without its disadvantages, however. The primary problem with whistleblowing is that the whistleblower almost always faces retaliation. This can range anywhere from facing hostility at work to being sued by the company for breach of confidentiality. Whistleblowers may even face demotions, reassignments, or in the worst case may lose their jobs. In rare instances, threats to their well-being or families may also occur. There is therefore a strong disincentive to remain silent about an illicit activity, should it be discovered. While laws are in place to protect whistleblowers, knowledge of their existence is limited, and whistleblowers may only find out about them after the statute of limitations has expired.&lt;br /&gt;
&lt;br /&gt;
But preventing or stopping that illicit activity is the morally and ethically correct course of action, and steps to do so can only be taken after the knowledge can be communicated to the people with the power to take action. And if the severity of the problem is great enough that it may result in loss of life, the whistleblower would even have a moral obligation to report his or her findings, regardless of the consequences.&lt;br /&gt;
&lt;br /&gt;
To balance the simultaneous needs of allowing whistleblowers to file their grievances and protecting them from retribution, alternatives are necessary. The below sections attempt to list and explain these alternatives.&lt;br /&gt;
&lt;br /&gt;
==Whistle-blowing and codes of morality==&lt;br /&gt;
&lt;br /&gt;
Duty to the public is the first principle of the code of the National Society of professionals. Given that, a great deal of responsibility engineers are to carry. The fourth principle describes the duty of the employer as: ‘‘the health, safety, and welfare of the public are to be placed first’’ (Harris et al., 2005, p. 183). Therefore we can derive the conclusion that whistle blowing is mandatory in certain situations.&lt;br /&gt;
&lt;br /&gt;
====Duality of engineering ethics====&lt;br /&gt;
&lt;br /&gt;
The ethic courses that are being offered in the engineering school, usually discusses different cases and inquire what should an engineer do. The cases are usually a mixture of different issues such as scientific, humanistic, and social issues. Then they try to come up with a solution that covers all aspects of the case. However codes of conduct are principles that engineers pursue them as their duties. There are two different aspects to it; What should an engineer do from an ethical point of view that is his/her duty, and what should he/she do from a non-ethical point of view, that is technical concerns. Therefore the whistle blowing in many situation will be obligatory.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''Issues with heroism.'' Because of the whistleblower’s pure intention and the danger that they bring to themselves, one would conclude that this is heroism. But since whistleblowing is an ethical obligation, one can not be hero by living up to his/her duties. Whistleblowing has been referred to as a heroic act by so many people that it seems people have forgotten that it is an obligation by our morality.&lt;br /&gt;
&lt;br /&gt;
== Alternatives ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Assignment Description ==&lt;br /&gt;
&lt;br /&gt;
Examine the ways an organization can help employees resolve concerns internally, and thereby avoid the need for external whistleblowing.  How do these practices, such as anonymous reporting hotlines, apply to the work environment of a software engineer?  &lt;br /&gt;
&lt;br /&gt;
Due to ineffective or nonexistent feedback processes within an organization, many important concerns never reach anyone who is willing or able to take action.  Employees may forgo making complaints due to processes that are hard to use, or because the company culture has no way to report anything, except to one’s immediate superior.&lt;br /&gt;
&lt;br /&gt;
What can be done to reduce the need for external whistleblowing?  Are there proven cultural fixes?  Technological fixes?  If someone has a less serious concern, which (s)he considers too insignificant to take the risk of external whistleblowing, how could this be actively addressed before problems arise?  Is there an ethical obligation on the part of organizations to adopt practices that encourage effective internal whistleblowing?  Please explain your answers.&lt;br /&gt;
&lt;br /&gt;
* http://www3.interscience.wiley.com/journal/119949153/abstract&lt;br /&gt;
* http://www.springerlink.com/content/t61246w14l64k416/&lt;br /&gt;
* http://portal.acm.org/citation.cfm?doid=367211.367274&lt;br /&gt;
* http://courses.ncsu.edu/csc379/lec/001/lectures/wk15/lecture.html&lt;br /&gt;
* http://ethics.csc.ncsu.edu/basics/whistle/&lt;br /&gt;
* [http://www.springerlink.com.www.lib.ncsu.edu:2048/content/w2t5252050044180/fulltext.pdf Whistle-Blowing and Morality] Mathieu Bouville&lt;/div&gt;</summary>
		<author><name>Mbastan</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379_SUM2008:Week_5,_Group_1&amp;diff=16982</id>
		<title>CSC 379 SUM2008:Week 5, Group 1</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379_SUM2008:Week_5,_Group_1&amp;diff=16982"/>
		<updated>2008-08-09T14:36:16Z</updated>

		<summary type="html">&lt;p&gt;Mbastan: /* Whistle-blowing and codes of morality */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Avoiding the Need for Whistleblowing ==&lt;br /&gt;
&lt;br /&gt;
Whistleblowing is a term used to denote an activity whereby an individual within a group (a company, a university, etc) presents a public report detailing a (typically) unethical action that has taken place within their group. The report is presented to the public because the individual has presumably already reported the violation via internal channels, and no action has taken place. By making the violation public, pressure is applied to the group to rectify the problem.&lt;br /&gt;
&lt;br /&gt;
== Problems With Conventional Whistleblowing ==&lt;br /&gt;
&lt;br /&gt;
Whistleblowing is not without its disadvantages, however. The primary problem with whistleblowing is that the whistleblower almost always faces retaliation. This can range anywhere from facing hostility at work to being sued by the company for breach of confidentiality. Whistleblowers may even face demotions, reassignments, or in the worst case may lose their jobs. In rare instances, threats to their well-being or families may also occur. There is therefore a strong disincentive to remain silent about an illicit activity, should it be discovered. While laws are in place to protect whistleblowers, knowledge of their existence is limited, and whistleblowers may only find out about them after the statute of limitations has expired.&lt;br /&gt;
&lt;br /&gt;
But preventing or stopping that illicit activity is the morally and ethically correct course of action, and steps to do so can only be taken after the knowledge can be communicated to the people with the power to take action. And if the severity of the problem is great enough that it may result in loss of life, the whistleblower would even have a moral obligation to report his or her findings, regardless of the consequences.&lt;br /&gt;
&lt;br /&gt;
To balance the simultaneous needs of allowing whistleblowers to file their grievances and protecting them from retribution, alternatives are necessary. The below sections attempt to list and explain these alternatives.&lt;br /&gt;
&lt;br /&gt;
==Whistle-blowing and codes of morality==&lt;br /&gt;
&lt;br /&gt;
Duty to the public is the first principle of the code of the National Society of professionals. Given that, a great deal of responsibility engineers are to carry. The fourth principle describes the duty of the employer as: ‘‘the health, safety, and welfare of the public are to be placed first’’ (Harris et al., 2005, p. 183). Therefore we can derive the conclusion that whistle blowing is mandatory in certain situations.&lt;br /&gt;
&lt;br /&gt;
====Duality of engineering ethics====&lt;br /&gt;
&lt;br /&gt;
The ethic courses that are being offered in the engineering school, usually discusses different cases and inquire what should an engineer do. The cases are usually a mixture of different issues such as scientific, humanistic, and social issues. Then they try to come up with a solution that covers all aspects of the case. However codes of conduct are principles that engineers pursue them as their duties. There are two different aspects to it; What should an engineer do from an ethical point of view that is his/her duty, and what should he/she do from a non-ethical point of view, that is technical concerns. Therefore the whistle blowing in many situation will be obligatory.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''Issues with heroism.'' Because of the whistleblower’s pure intention and the danger that they bring to themselves, one would conclude that this is heroism. But since whistleblowing is an ethical obligation, one can not be hero by living up to his/her duties. Whistleblowing has been referred to as a heroic act by so many people that it seems people have forgotten that it is an obligation by our morality.&lt;br /&gt;
&lt;br /&gt;
== Alternatives ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Assignment Description ==&lt;br /&gt;
&lt;br /&gt;
Examine the ways an organization can help employees resolve concerns internally, and thereby avoid the need for external whistleblowing.  How do these practices, such as anonymous reporting hotlines, apply to the work environment of a software engineer?  &lt;br /&gt;
&lt;br /&gt;
Due to ineffective or nonexistent feedback processes within an organization, many important concerns never reach anyone who is willing or able to take action.  Employees may forgo making complaints due to processes that are hard to use, or because the company culture has no way to report anything, except to one’s immediate superior.&lt;br /&gt;
&lt;br /&gt;
What can be done to reduce the need for external whistleblowing?  Are there proven cultural fixes?  Technological fixes?  If someone has a less serious concern, which (s)he considers too insignificant to take the risk of external whistleblowing, how could this be actively addressed before problems arise?  Is there an ethical obligation on the part of organizations to adopt practices that encourage effective internal whistleblowing?  Please explain your answers.&lt;br /&gt;
&lt;br /&gt;
* http://www3.interscience.wiley.com/journal/119949153/abstract&lt;br /&gt;
* http://www.springerlink.com/content/t61246w14l64k416/&lt;br /&gt;
* http://portal.acm.org/citation.cfm?doid=367211.367274&lt;br /&gt;
* http://courses.ncsu.edu/csc379/lec/001/lectures/wk15/lecture.html&lt;br /&gt;
* http://ethics.csc.ncsu.edu/basics/whistle/&lt;/div&gt;</summary>
		<author><name>Mbastan</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379_SUM2008:Week_5,_Group_1&amp;diff=16981</id>
		<title>CSC 379 SUM2008:Week 5, Group 1</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379_SUM2008:Week_5,_Group_1&amp;diff=16981"/>
		<updated>2008-08-09T14:35:57Z</updated>

		<summary type="html">&lt;p&gt;Mbastan: /* Whistle-blowing and codes of morality */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Avoiding the Need for Whistleblowing ==&lt;br /&gt;
&lt;br /&gt;
Whistleblowing is a term used to denote an activity whereby an individual within a group (a company, a university, etc) presents a public report detailing a (typically) unethical action that has taken place within their group. The report is presented to the public because the individual has presumably already reported the violation via internal channels, and no action has taken place. By making the violation public, pressure is applied to the group to rectify the problem.&lt;br /&gt;
&lt;br /&gt;
== Problems With Conventional Whistleblowing ==&lt;br /&gt;
&lt;br /&gt;
Whistleblowing is not without its disadvantages, however. The primary problem with whistleblowing is that the whistleblower almost always faces retaliation. This can range anywhere from facing hostility at work to being sued by the company for breach of confidentiality. Whistleblowers may even face demotions, reassignments, or in the worst case may lose their jobs. In rare instances, threats to their well-being or families may also occur. There is therefore a strong disincentive to remain silent about an illicit activity, should it be discovered. While laws are in place to protect whistleblowers, knowledge of their existence is limited, and whistleblowers may only find out about them after the statute of limitations has expired.&lt;br /&gt;
&lt;br /&gt;
But preventing or stopping that illicit activity is the morally and ethically correct course of action, and steps to do so can only be taken after the knowledge can be communicated to the people with the power to take action. And if the severity of the problem is great enough that it may result in loss of life, the whistleblower would even have a moral obligation to report his or her findings, regardless of the consequences.&lt;br /&gt;
&lt;br /&gt;
To balance the simultaneous needs of allowing whistleblowers to file their grievances and protecting them from retribution, alternatives are necessary. The below sections attempt to list and explain these alternatives.&lt;br /&gt;
&lt;br /&gt;
==Whistle-blowing and codes of morality==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;working...&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Duty to the public is the first principle of the code of the National Society of professionals. Given that, a great deal of responsibility engineers are to carry. The fourth principle describes the duty of the employer as: ‘‘the health, safety, and welfare of the public are to be placed first’’ (Harris et al., 2005, p. 183). Therefore we can derive the conclusion that whistle blowing is mandatory in certain situations.&lt;br /&gt;
&lt;br /&gt;
====Duality of engineering ethics====&lt;br /&gt;
&lt;br /&gt;
The ethic courses that are being offered in the engineering school, usually discusses different cases and inquire what should an engineer do. The cases are usually a mixture of different issues such as scientific, humanistic, and social issues. Then they try to come up with a solution that covers all aspects of the case. However codes of conduct are principles that engineers pursue them as their duties. There are two different aspects to it; What should an engineer do from an ethical point of view that is his/her duty, and what should he/she do from a non-ethical point of view, that is technical concerns. Therefore the whistle blowing in many situation will be obligatory.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''Issues with heroism.'' Because of the whistleblower’s pure intention and the danger that they bring to themselves, one would conclude that this is heroism. But since whistleblowing is an ethical obligation, one can not be hero by living up to his/her duties. Whistleblowing has been referred to as a heroic act by so many people that it seems people have forgotten that it is an obligation by our morality.&lt;br /&gt;
&lt;br /&gt;
== Alternatives ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Assignment Description ==&lt;br /&gt;
&lt;br /&gt;
Examine the ways an organization can help employees resolve concerns internally, and thereby avoid the need for external whistleblowing.  How do these practices, such as anonymous reporting hotlines, apply to the work environment of a software engineer?  &lt;br /&gt;
&lt;br /&gt;
Due to ineffective or nonexistent feedback processes within an organization, many important concerns never reach anyone who is willing or able to take action.  Employees may forgo making complaints due to processes that are hard to use, or because the company culture has no way to report anything, except to one’s immediate superior.&lt;br /&gt;
&lt;br /&gt;
What can be done to reduce the need for external whistleblowing?  Are there proven cultural fixes?  Technological fixes?  If someone has a less serious concern, which (s)he considers too insignificant to take the risk of external whistleblowing, how could this be actively addressed before problems arise?  Is there an ethical obligation on the part of organizations to adopt practices that encourage effective internal whistleblowing?  Please explain your answers.&lt;br /&gt;
&lt;br /&gt;
* http://www3.interscience.wiley.com/journal/119949153/abstract&lt;br /&gt;
* http://www.springerlink.com/content/t61246w14l64k416/&lt;br /&gt;
* http://portal.acm.org/citation.cfm?doid=367211.367274&lt;br /&gt;
* http://courses.ncsu.edu/csc379/lec/001/lectures/wk15/lecture.html&lt;br /&gt;
* http://ethics.csc.ncsu.edu/basics/whistle/&lt;/div&gt;</summary>
		<author><name>Mbastan</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379_SUM2008:Week_5,_Group_1&amp;diff=16977</id>
		<title>CSC 379 SUM2008:Week 5, Group 1</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379_SUM2008:Week_5,_Group_1&amp;diff=16977"/>
		<updated>2008-08-09T14:09:47Z</updated>

		<summary type="html">&lt;p&gt;Mbastan: /* Whistle-blowing and codes of morality */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Avoiding the Need for Whistleblowing ==&lt;br /&gt;
&lt;br /&gt;
Whistleblowing is a term used to denote an activity whereby an individual within a group (a company, a university, etc) presents a public report detailing a (typically) unethical action that has taken place within their group. The report is presented to the public because the individual has presumably already reported the violation via internal channels, and no action has taken place. By making the violation public, pressure is applied to the group to rectify the problem.&lt;br /&gt;
&lt;br /&gt;
== Problems With Conventional Whistleblowing ==&lt;br /&gt;
&lt;br /&gt;
Whistleblowing is not without its disadvantages, however. The primary problem with whistleblowing is that the whistleblower almost always faces retaliation. This can range anywhere from facing hostility at work to being sued by the company for breach of confidentiality. Whistleblowers may even face demotions, reassignments, or in the worst case may lose their jobs. In rare instances, threats to their well-being or families may also occur. There is therefore a strong disincentive to remain silent about an illicit activity, should it be discovered. While laws are in place to protect whistleblowers, knowledge of their existence is limited, and whistleblowers may only find out about them after the statute of limitations has expired.&lt;br /&gt;
&lt;br /&gt;
But preventing or stopping that illicit activity is the morally and ethically correct course of action, and steps to do so can only be taken after the knowledge can be communicated to the people with the power to take action. And if the severity of the problem is great enough that it may result in loss of life, the whistleblower would even have a moral obligation to report his or her findings, regardless of the consequences.&lt;br /&gt;
&lt;br /&gt;
To balance the simultaneous needs of allowing whistleblowers to file their grievances and protecting them from retribution, alternatives are necessary. The below sections attempt to list and explain these alternatives.&lt;br /&gt;
&lt;br /&gt;
==Whistle-blowing and codes of morality==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;working...&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Duty to the public is the first principle of the code of the National Society of professionals. Given that, a great deal of responsibility engineers are to carry. The fourth principle describes the duty of the employer as: ‘‘the health, safety, and welfare of the public are to be placed first’’ (Harris et al., 2005, p. 183). Therefore we can derive the conclusion that whistle blowing is mandatory in certain situations.&lt;br /&gt;
&lt;br /&gt;
====Duality of engineering ethics====&lt;br /&gt;
&lt;br /&gt;
The ethic courses that are being offered in the engineering school, usually discusses different cases and inquire what should an engineer do. The cases are usually a mixture of different issues such as scientific, humanistic, and social issues. Then they try to come up with a solution that covers all aspects of the case. However codes of conduct are principles that engineers pursue them as their duties. There are two different aspects to it; What should an engineer do from an ethical point of view that is his/her duty, and what should he/she do from a non-ethical point of view, that is technical concerns. Therefore the whistle blowing in many situation will be obligatory.&lt;br /&gt;
&lt;br /&gt;
== Alternatives ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Assignment Description ==&lt;br /&gt;
&lt;br /&gt;
Examine the ways an organization can help employees resolve concerns internally, and thereby avoid the need for external whistleblowing.  How do these practices, such as anonymous reporting hotlines, apply to the work environment of a software engineer?  &lt;br /&gt;
&lt;br /&gt;
Due to ineffective or nonexistent feedback processes within an organization, many important concerns never reach anyone who is willing or able to take action.  Employees may forgo making complaints due to processes that are hard to use, or because the company culture has no way to report anything, except to one’s immediate superior.&lt;br /&gt;
&lt;br /&gt;
What can be done to reduce the need for external whistleblowing?  Are there proven cultural fixes?  Technological fixes?  If someone has a less serious concern, which (s)he considers too insignificant to take the risk of external whistleblowing, how could this be actively addressed before problems arise?  Is there an ethical obligation on the part of organizations to adopt practices that encourage effective internal whistleblowing?  Please explain your answers.&lt;br /&gt;
&lt;br /&gt;
* http://www3.interscience.wiley.com/journal/119949153/abstract&lt;br /&gt;
* http://www.springerlink.com/content/t61246w14l64k416/&lt;br /&gt;
* http://portal.acm.org/citation.cfm?doid=367211.367274&lt;br /&gt;
* http://courses.ncsu.edu/csc379/lec/001/lectures/wk15/lecture.html&lt;br /&gt;
* http://ethics.csc.ncsu.edu/basics/whistle/&lt;/div&gt;</summary>
		<author><name>Mbastan</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379_SUM2008:Week_5,_Group_1&amp;diff=16976</id>
		<title>CSC 379 SUM2008:Week 5, Group 1</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379_SUM2008:Week_5,_Group_1&amp;diff=16976"/>
		<updated>2008-08-09T14:09:25Z</updated>

		<summary type="html">&lt;p&gt;Mbastan: /* Whistle-blowing and codes of morality */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Avoiding the Need for Whistleblowing ==&lt;br /&gt;
&lt;br /&gt;
Whistleblowing is a term used to denote an activity whereby an individual within a group (a company, a university, etc) presents a public report detailing a (typically) unethical action that has taken place within their group. The report is presented to the public because the individual has presumably already reported the violation via internal channels, and no action has taken place. By making the violation public, pressure is applied to the group to rectify the problem.&lt;br /&gt;
&lt;br /&gt;
== Problems With Conventional Whistleblowing ==&lt;br /&gt;
&lt;br /&gt;
Whistleblowing is not without its disadvantages, however. The primary problem with whistleblowing is that the whistleblower almost always faces retaliation. This can range anywhere from facing hostility at work to being sued by the company for breach of confidentiality. Whistleblowers may even face demotions, reassignments, or in the worst case may lose their jobs. In rare instances, threats to their well-being or families may also occur. There is therefore a strong disincentive to remain silent about an illicit activity, should it be discovered. While laws are in place to protect whistleblowers, knowledge of their existence is limited, and whistleblowers may only find out about them after the statute of limitations has expired.&lt;br /&gt;
&lt;br /&gt;
But preventing or stopping that illicit activity is the morally and ethically correct course of action, and steps to do so can only be taken after the knowledge can be communicated to the people with the power to take action. And if the severity of the problem is great enough that it may result in loss of life, the whistleblower would even have a moral obligation to report his or her findings, regardless of the consequences.&lt;br /&gt;
&lt;br /&gt;
To balance the simultaneous needs of allowing whistleblowers to file their grievances and protecting them from retribution, alternatives are necessary. The below sections attempt to list and explain these alternatives.&lt;br /&gt;
&lt;br /&gt;
==Whistle-blowing and codes of morality==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;working...&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Duty to the public is the first principle of the code of the National Society of professionals. Given that, a great deal of responsibility engineers are to carry. The fourth principle describes the duty of the employer as: ‘‘the health, safety, and welfare of the public are to be placed first’’ (Harris et al., 2005, p. 183). Therefore we can derive the conclusion that whistle blowing is mandatory in certain situations.&lt;br /&gt;
&lt;br /&gt;
*Duality of engineering ethics&lt;br /&gt;
&lt;br /&gt;
The ethic courses that are being offered in the engineering school, usually discusses different cases and inquire what should an engineer do. The cases are usually a mixture of different issues such as scientific, humanistic, and social issues. Then they try to come up with a solution that covers all aspects of the case. However codes of conduct are principles that engineers pursue them as their duties. There are two different aspects to it; What should an engineer do from an ethical point of view that is his/her duty, and what should he/she do from a non-ethical point of view, that is technical concerns. Therefore the whistle blowing in many situation will be obligatory.&lt;br /&gt;
&lt;br /&gt;
== Alternatives ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Assignment Description ==&lt;br /&gt;
&lt;br /&gt;
Examine the ways an organization can help employees resolve concerns internally, and thereby avoid the need for external whistleblowing.  How do these practices, such as anonymous reporting hotlines, apply to the work environment of a software engineer?  &lt;br /&gt;
&lt;br /&gt;
Due to ineffective or nonexistent feedback processes within an organization, many important concerns never reach anyone who is willing or able to take action.  Employees may forgo making complaints due to processes that are hard to use, or because the company culture has no way to report anything, except to one’s immediate superior.&lt;br /&gt;
&lt;br /&gt;
What can be done to reduce the need for external whistleblowing?  Are there proven cultural fixes?  Technological fixes?  If someone has a less serious concern, which (s)he considers too insignificant to take the risk of external whistleblowing, how could this be actively addressed before problems arise?  Is there an ethical obligation on the part of organizations to adopt practices that encourage effective internal whistleblowing?  Please explain your answers.&lt;br /&gt;
&lt;br /&gt;
* http://www3.interscience.wiley.com/journal/119949153/abstract&lt;br /&gt;
* http://www.springerlink.com/content/t61246w14l64k416/&lt;br /&gt;
* http://portal.acm.org/citation.cfm?doid=367211.367274&lt;br /&gt;
* http://courses.ncsu.edu/csc379/lec/001/lectures/wk15/lecture.html&lt;br /&gt;
* http://ethics.csc.ncsu.edu/basics/whistle/&lt;/div&gt;</summary>
		<author><name>Mbastan</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379_SUM2008:Week_5,_Group_1&amp;diff=16964</id>
		<title>CSC 379 SUM2008:Week 5, Group 1</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379_SUM2008:Week_5,_Group_1&amp;diff=16964"/>
		<updated>2008-08-09T13:11:53Z</updated>

		<summary type="html">&lt;p&gt;Mbastan: /* Whistle-blowing and codes of morality */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Avoiding the Need for Whistleblowing ==&lt;br /&gt;
&lt;br /&gt;
Whistleblowing is a term used to denote an activity whereby an individual within a group (a company, a university, etc) presents a public report detailing a (typically) unethical action that has taken place within their group. The report is presented to the public because the individual has presumably already reported the violation via internal channels, and no action has taken place. By making the violation public, pressure is applied to the group to rectify the problem.&lt;br /&gt;
&lt;br /&gt;
== Problems With Conventional Whistleblowing ==&lt;br /&gt;
&lt;br /&gt;
Whistleblowing is not without its disadvantages, however. The primary problem with whistleblowing is that the whistleblower almost always faces retaliation. This can range anywhere from facing hostility at work to being sued by the company for breach of confidentiality. Whistleblowers may even face demotions, reassignments, or in the worst case may lose their jobs. In rare instances, threats to their well-being or families may also occur. There is therefore a strong disincentive to remain silent about an illicit activity, should it be discovered. While laws are in place to protect whistleblowers, knowledge of their existence is limited, and whistleblowers may only find out about them after the statute of limitations has expired.&lt;br /&gt;
&lt;br /&gt;
But preventing or stopping that illicit activity is the morally and ethically correct course of action, and steps to do so can only be taken after the knowledge can be communicated to the people with the power to take action. And if the severity of the problem is great enough that it may result in loss of life, the whistleblower would even have a moral obligation to report his or her findings, regardless of the consequences.&lt;br /&gt;
&lt;br /&gt;
To balance the simultaneous needs of allowing whistleblowers to file their grievances and protecting them from retribution, alternatives are necessary. The below sections attempt to list and explain these alternatives.&lt;br /&gt;
&lt;br /&gt;
==Whistle-blowing and codes of morality==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;working...&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Duty to the public is the first principle of the code of the National Society of professionals. Given that, a great deal of responsibility engineers are to carry. The fourth principle describes the duty of the employer as: ‘‘the health, safety, and welfare of the public are to be placed first’’ (Harris et al., 2005, p. 183). Therefore we can derive the conclusion that whistle blowing is mandatory in certain situations.&lt;br /&gt;
&lt;br /&gt;
== Alternatives ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Assignment Description ==&lt;br /&gt;
&lt;br /&gt;
Examine the ways an organization can help employees resolve concerns internally, and thereby avoid the need for external whistleblowing.  How do these practices, such as anonymous reporting hotlines, apply to the work environment of a software engineer?  &lt;br /&gt;
&lt;br /&gt;
Due to ineffective or nonexistent feedback processes within an organization, many important concerns never reach anyone who is willing or able to take action.  Employees may forgo making complaints due to processes that are hard to use, or because the company culture has no way to report anything, except to one’s immediate superior.&lt;br /&gt;
&lt;br /&gt;
What can be done to reduce the need for external whistleblowing?  Are there proven cultural fixes?  Technological fixes?  If someone has a less serious concern, which (s)he considers too insignificant to take the risk of external whistleblowing, how could this be actively addressed before problems arise?  Is there an ethical obligation on the part of organizations to adopt practices that encourage effective internal whistleblowing?  Please explain your answers.&lt;br /&gt;
&lt;br /&gt;
* http://www3.interscience.wiley.com/journal/119949153/abstract&lt;br /&gt;
* http://www.springerlink.com/content/t61246w14l64k416/&lt;br /&gt;
* http://portal.acm.org/citation.cfm?doid=367211.367274&lt;br /&gt;
* http://courses.ncsu.edu/csc379/lec/001/lectures/wk15/lecture.html&lt;br /&gt;
* http://ethics.csc.ncsu.edu/basics/whistle/&lt;/div&gt;</summary>
		<author><name>Mbastan</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379_SUM2008:Week_5,_Group_1&amp;diff=16963</id>
		<title>CSC 379 SUM2008:Week 5, Group 1</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379_SUM2008:Week_5,_Group_1&amp;diff=16963"/>
		<updated>2008-08-09T13:11:34Z</updated>

		<summary type="html">&lt;p&gt;Mbastan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Avoiding the Need for Whistleblowing ==&lt;br /&gt;
&lt;br /&gt;
Whistleblowing is a term used to denote an activity whereby an individual within a group (a company, a university, etc) presents a public report detailing a (typically) unethical action that has taken place within their group. The report is presented to the public because the individual has presumably already reported the violation via internal channels, and no action has taken place. By making the violation public, pressure is applied to the group to rectify the problem.&lt;br /&gt;
&lt;br /&gt;
== Problems With Conventional Whistleblowing ==&lt;br /&gt;
&lt;br /&gt;
Whistleblowing is not without its disadvantages, however. The primary problem with whistleblowing is that the whistleblower almost always faces retaliation. This can range anywhere from facing hostility at work to being sued by the company for breach of confidentiality. Whistleblowers may even face demotions, reassignments, or in the worst case may lose their jobs. In rare instances, threats to their well-being or families may also occur. There is therefore a strong disincentive to remain silent about an illicit activity, should it be discovered. While laws are in place to protect whistleblowers, knowledge of their existence is limited, and whistleblowers may only find out about them after the statute of limitations has expired.&lt;br /&gt;
&lt;br /&gt;
But preventing or stopping that illicit activity is the morally and ethically correct course of action, and steps to do so can only be taken after the knowledge can be communicated to the people with the power to take action. And if the severity of the problem is great enough that it may result in loss of life, the whistleblower would even have a moral obligation to report his or her findings, regardless of the consequences.&lt;br /&gt;
&lt;br /&gt;
To balance the simultaneous needs of allowing whistleblowers to file their grievances and protecting them from retribution, alternatives are necessary. The below sections attempt to list and explain these alternatives.&lt;br /&gt;
&lt;br /&gt;
==Whistle-blowing and codes of morality==&lt;br /&gt;
&lt;br /&gt;
Duty to the public is the first principle of the code of the National Society of professionals. Given that, a great deal of responsibility engineers are to carry. The fourth principle describes the duty of the employer as: ‘‘the health, safety, and welfare of the public are to be placed first’’ (Harris et al., 2005, p. 183). Therefore we can derive the conclusion that whistle blowing is mandatory in certain situations. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Alternatives ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Assignment Description ==&lt;br /&gt;
&lt;br /&gt;
Examine the ways an organization can help employees resolve concerns internally, and thereby avoid the need for external whistleblowing.  How do these practices, such as anonymous reporting hotlines, apply to the work environment of a software engineer?  &lt;br /&gt;
&lt;br /&gt;
Due to ineffective or nonexistent feedback processes within an organization, many important concerns never reach anyone who is willing or able to take action.  Employees may forgo making complaints due to processes that are hard to use, or because the company culture has no way to report anything, except to one’s immediate superior.&lt;br /&gt;
&lt;br /&gt;
What can be done to reduce the need for external whistleblowing?  Are there proven cultural fixes?  Technological fixes?  If someone has a less serious concern, which (s)he considers too insignificant to take the risk of external whistleblowing, how could this be actively addressed before problems arise?  Is there an ethical obligation on the part of organizations to adopt practices that encourage effective internal whistleblowing?  Please explain your answers.&lt;br /&gt;
&lt;br /&gt;
* http://www3.interscience.wiley.com/journal/119949153/abstract&lt;br /&gt;
* http://www.springerlink.com/content/t61246w14l64k416/&lt;br /&gt;
* http://portal.acm.org/citation.cfm?doid=367211.367274&lt;br /&gt;
* http://courses.ncsu.edu/csc379/lec/001/lectures/wk15/lecture.html&lt;br /&gt;
* http://ethics.csc.ncsu.edu/basics/whistle/&lt;/div&gt;</summary>
		<author><name>Mbastan</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16803</id>
		<title>Phishing</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16803"/>
		<updated>2008-08-05T01:49:37Z</updated>

		<summary type="html">&lt;p&gt;Mbastan: /* What is phishing */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=[[Image:new.gif|New]]Study Guide=&lt;br /&gt;
==Why is phishing unethical?==&lt;br /&gt;
Phishing in computing is the process of acquiring private and sensitive information by pretending to be a trustworthy or a legitimate website through the online communications. Phishing is an example of fraudulent use of social engineering techniques to deceive an online service user. In this article some of the known attacks will be discussed following with some solutions to guard against these attacks.&lt;br /&gt;
&lt;br /&gt;
==Phishing attacks==&lt;br /&gt;
&lt;br /&gt;
As the technology advances and anti malware applications become more efficient, phishing attacks adopt new forms to stay away from detection. First different forms of attack will be discussed and then some of the solutions that one may prevent these attacks with will be presented. &lt;br /&gt;
&lt;br /&gt;
====Keyloggers====&lt;br /&gt;
&lt;br /&gt;
These are spywares that can get installed either into a web browser or as a device driver. They record the user’s input to the computer by recording the keyboard keystrokes or mouse click. This information will be then sent to the spyware owner. These spywares can cause severe data leak.&lt;br /&gt;
&lt;br /&gt;
===Torpig-family Trojan===&lt;br /&gt;
&lt;br /&gt;
These Trojans are using advanced technologies that help them to spread very fast and hide very well. They are designed to hijack sessions. These Trojans are constantly monitoring major banks’ websites throughout the world. They display a fake page when a user tries to log in to these websites, and in this way continue to steal the private information of their victims.&lt;br /&gt;
&lt;br /&gt;
===Session hijackers===&lt;br /&gt;
&lt;br /&gt;
These attacks can take place either from the malware that is installed on the victim’s computer or remotely. The attacks are triggered when users is trying to log into they account (usually bank accounts) or when they initiate a transaction. The malware then hijack the session for malicious purposes.&lt;br /&gt;
&lt;br /&gt;
===Content-injection phishing===&lt;br /&gt;
&lt;br /&gt;
This phishing refers to the situations when malicious or fake content gets injected into some legitimate Web sites. This content then can deceive the users of the Web site by redirecting them to other Web sites, install malware on their computers, or redirect the input that users is inputting to that Web site to the phishing server.&lt;br /&gt;
&lt;br /&gt;
===“Universal” man-in-the-middle phishing kit===&lt;br /&gt;
&lt;br /&gt;
There is only little effort required for the attackers to use this method to attack their victims. The attackers use a kit which is called MITM that includes several PHP files that get installed on the phishing server. This server then acts as a medium between the user and the legitimate website that he/she wants to access. These victims receive emails that include a purported link to their known website. Once they click on the link, they’ll be redirected to the phishing server which then will communicate with the original Web site on behalf of the user.&lt;br /&gt;
&lt;br /&gt;
===Search engine phishing===&lt;br /&gt;
&lt;br /&gt;
In this type pf phishing, phishers establish a webpage, and then get it indexed by the search engines to make it searchable. These pages are usually designed to include items and services at very low price to attract visitors to sign up or to enter their confidential information. The phisher then get the hold of the private information of the visitors.&lt;br /&gt;
&lt;br /&gt;
===Spear phishing===&lt;br /&gt;
&lt;br /&gt;
In this approach the phisher targets a particular person or a specific department in a company. The phisher then contacts the person by email and pretends to be from a legitimate department and is a trustworthy staff. The attacker then asks for the username and password with some fake reasons. Once the attacker get those information the can by pass the firewalls and break into the secured network.&lt;br /&gt;
&lt;br /&gt;
==Phishing solutions==&lt;br /&gt;
&lt;br /&gt;
To fight against the phishers, in the first place, the online service users should be educated. Once users know what phishing is and what methods phishers use, less people will fall for their tricks and many of their method then become useless. However some countermeasures have been developed and some of them are explained below.&lt;br /&gt;
&lt;br /&gt;
===Phishing blacklist===&lt;br /&gt;
&lt;br /&gt;
A server that is containing a list of all of the malicious websites and phishing servers should be established and be accessible by the internet browsers. The list should be updated on daily basis due to the lifetime of the phishing servers. The malicious URLs should be reported immediately.&lt;br /&gt;
&lt;br /&gt;
===Bookmarks or history===&lt;br /&gt;
&lt;br /&gt;
Using bookmarks and history to detect the list of the websites that the user uses. Then if a new website is visited randomly by the user that he/she did not visit before, chances are that this website is has malicious purposes. The down side of this method is that the history feature holds a history of the limited and short time.&lt;br /&gt;
&lt;br /&gt;
===Two-way authentication===&lt;br /&gt;
&lt;br /&gt;
In this method once a user signs up for an online service they receive and image in a secure way. Thereafter whenever the user visits the website and enters his/her username the website displays the image to prove its legitimacy. The user then can continue to enter his/her password.&lt;br /&gt;
&lt;br /&gt;
===VeriSign identity protection (VIP)===&lt;br /&gt;
&lt;br /&gt;
VIP has been design to protect the digital identities of the people who use online services. VIP provides number of rules that organizations should comply with if they want use VIP services. The VIP suite then provides a secure way for users to log into their account and transactions to take place.&lt;br /&gt;
&lt;br /&gt;
===Early alarm===&lt;br /&gt;
&lt;br /&gt;
This solution requires sort of add-on tool to be installed on Web browsers. This tool contains several rules and ways to check the authentication of the Web sites. The tool will notify the user if the Web site is legitimate and trusted.&lt;br /&gt;
&lt;br /&gt;
=[[Image:new.gif|New]]Bibliography=&lt;br /&gt;
&lt;br /&gt;
===What is phishing?===&lt;br /&gt;
[http://en.wikipedia.org/wiki/Phishing Phishing] ''Wikipedia''&lt;br /&gt;
&lt;br /&gt;
[http://www.identityprotection101.com/phishing/ Phishing Scams] ''identityprotection101.com''&lt;br /&gt;
&lt;br /&gt;
[http://delivery.acm.org.www.lib.ncsu.edu:2048/10.1145/1130000/1121968/p21-berghel.pdf?key1=1121968&amp;amp;key2=8870097121&amp;amp;coll=ACM&amp;amp;dl=ACM&amp;amp;CFID=72977&amp;amp;CFTOKEN=33062475  Phishing mongers and posers] Hal Berghel, ''Digital Village''&lt;br /&gt;
&lt;br /&gt;
===Privacy and ethical Issues===&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/xg41104w066612m7/fulltext.pdf Privacy and e-commerce: a consumer-centric perspective] Rhys Smith and Jianhua Shao, ''Electronic Commerce Research'', Volume 7, Number 2 / June, 2007 &lt;br /&gt;
&lt;br /&gt;
[http://www.mcgoverngreene.com/alerts/FA_pdfs/Oct-Nov_2004.pdf Phishers “net” unsuspecting consumers] ''fraud alert''  october/november 2004&lt;br /&gt;
&lt;br /&gt;
[http://delivery.acm.org.www.lib.ncsu.edu:2048/10.1145/1130000/1124861/p581-dhamija.pdf?key1=1124861&amp;amp;key2=4842557121&amp;amp;coll=ACM&amp;amp;dl=ACM&amp;amp;CFID=38796614&amp;amp;CFTOKEN=46500553 Why phishing works] Rachna Dhamija, J. D. Tygar, Marti Hearst&lt;br /&gt;
&lt;br /&gt;
[http://delivery.acm.org.www.lib.ncsu.edu:2048/10.1145/1080000/1073009/p77-dhamija.pdf?key1=1073009&amp;amp;key2=1444557121&amp;amp;coll=ACM&amp;amp;dl=ACM&amp;amp;CFID=38796614&amp;amp;CFTOKEN=46500553 The battle against phishing: Dynamic security skins] Rachna Dhamija,  J. D. Tygar&lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/d284629556533224/fulltext.pdf A Revocation scheme preserving privacy] Łukasz Krzywiecki, Przemysław Kubiak and Mirosław Kutyłowski &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/h62k448875177211/fulltext.pdf Security and privacy as market failures]L. Jean Camp,''Economics of Identity Theft: Avoidance, Causes and Possible Cures'' &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/q808084h875464v5/fulltext.pdf Protection or privacy? Data mining and personal data] David J. Hand&lt;br /&gt;
&lt;br /&gt;
===Protection against phishing attacks===&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/0p748n8766732770/fulltext.pdf Method for evaluating the security risk of a website against phishing attacks] Young-Gab Kim, Sanghyun Cho, Jun-Sub Lee, Min-Soo Lee, In Ho Kim and Sung Hoon Kim &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/307774n374w42854/fulltext.pdf An Intrusion detection system for detecting phishing attacks] Hasika Pamunuwa, Duminda Wijesekera and Csilla Farkas &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/50hln6j1b04ftbw1/fulltext.pdf Protection mechanisms against phishing attacks] Klaus Plössl, Hannes Federrath and Thomas Nowey &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/w833450106412039/fulltext.pdf On the effectiveness of techniques to detect phishing sites] Christian Ludl, Sean McAllister, Engin Kirda and Christopher Kruegel &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/bq4mj20enhm3ep0x/fulltext.pdf Effective protection against phishing and web spoofing] Rolf Oppliger and Sebastian Gajek &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/w81x1n840w231177/fulltext.pdf Usability evaluation of anti-phishing toolbars] Linfeng Li and Marko Helenius&lt;br /&gt;
&lt;br /&gt;
===Others===&lt;br /&gt;
[http://pg-server.csc.ncsu.edu/mediawiki/index.php/CSC_379_SUM2008:Topics#Phishing Topic page]&lt;br /&gt;
&lt;br /&gt;
[http://ethics.csc.ncsu.edu/abuse/spam/phishing/new.html Old phishing page]&lt;/div&gt;</summary>
		<author><name>Mbastan</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16801</id>
		<title>Phishing</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16801"/>
		<updated>2008-08-05T01:49:03Z</updated>

		<summary type="html">&lt;p&gt;Mbastan: /* What is phishing */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=[[Image:new.gif|New]]Study Guide=&lt;br /&gt;
==Why is phishing unethical?==&lt;br /&gt;
Phishing in computing is the process of acquiring private and sensitive information by pretending to be a trustworthy or a legitimate website through the online communications. Phishing is an example of fraudulent use of social engineering techniques to deceive an online service user. In this article some of the known attacks will be discussed following with some solutions to guard against these attacks.&lt;br /&gt;
&lt;br /&gt;
==Phishing attacks==&lt;br /&gt;
&lt;br /&gt;
As the technology advances and anti malware applications become more efficient, phishing attacks adopt new forms to stay away from detection. First different forms of attack will be discussed and then some of the solutions that one may prevent these attacks with will be presented. &lt;br /&gt;
&lt;br /&gt;
====Keyloggers====&lt;br /&gt;
&lt;br /&gt;
These are spywares that can get installed either into a web browser or as a device driver. They record the user’s input to the computer by recording the keyboard keystrokes or mouse click. This information will be then sent to the spyware owner. These spywares can cause severe data leak.&lt;br /&gt;
&lt;br /&gt;
===Torpig-family Trojan===&lt;br /&gt;
&lt;br /&gt;
These Trojans are using advanced technologies that help them to spread very fast and hide very well. They are designed to hijack sessions. These Trojans are constantly monitoring major banks’ websites throughout the world. They display a fake page when a user tries to log in to these websites, and in this way continue to steal the private information of their victims.&lt;br /&gt;
&lt;br /&gt;
===Session hijackers===&lt;br /&gt;
&lt;br /&gt;
These attacks can take place either from the malware that is installed on the victim’s computer or remotely. The attacks are triggered when users is trying to log into they account (usually bank accounts) or when they initiate a transaction. The malware then hijack the session for malicious purposes.&lt;br /&gt;
&lt;br /&gt;
===Content-injection phishing===&lt;br /&gt;
&lt;br /&gt;
This phishing refers to the situations when malicious or fake content gets injected into some legitimate Web sites. This content then can deceive the users of the Web site by redirecting them to other Web sites, install malware on their computers, or redirect the input that users is inputting to that Web site to the phishing server.&lt;br /&gt;
&lt;br /&gt;
===“Universal” man-in-the-middle phishing kit===&lt;br /&gt;
&lt;br /&gt;
There is only little effort required for the attackers to use this method to attack their victims. The attackers use a kit which is called MITM that includes several PHP files that get installed on the phishing server. This server then acts as a medium between the user and the legitimate website that he/she wants to access. These victims receive emails that include a purported link to their known website. Once they click on the link, they’ll be redirected to the phishing server which then will communicate with the original Web site on behalf of the user.&lt;br /&gt;
&lt;br /&gt;
===Search engine phishing===&lt;br /&gt;
&lt;br /&gt;
In this type pf phishing, phishers establish a webpage, and then get it indexed by the search engines to make it searchable. These pages are usually designed to include items and services at very low price to attract visitors to sign up or to enter their confidential information. The phisher then get the hold of the private information of the visitors.&lt;br /&gt;
&lt;br /&gt;
===Spear phishing===&lt;br /&gt;
&lt;br /&gt;
In this approach the phisher targets a particular person or a specific department in a company. The phisher then contacts the person by email and pretends to be from a legitimate department and is a trustworthy staff. The attacker then asks for the username and password with some fake reasons. Once the attacker get those information the can by pass the firewalls and break into the secured network.&lt;br /&gt;
&lt;br /&gt;
==Phishing solutions==&lt;br /&gt;
&lt;br /&gt;
To fight against the phishers, in the first place, the online service users should be educated. Once users know what phishing is and what methods phishers use, less people will fall for their tricks and many of their method then become useless. However some countermeasures have been developed and some of them are explained below.&lt;br /&gt;
&lt;br /&gt;
===Phishing blacklist===&lt;br /&gt;
&lt;br /&gt;
A server that is containing a list of all of the malicious websites and phishing servers should be established and be accessible by the internet browsers. The list should be updated on daily basis due to the lifetime of the phishing servers. The malicious URLs should be reported immediately.&lt;br /&gt;
&lt;br /&gt;
===Bookmarks or history===&lt;br /&gt;
&lt;br /&gt;
Using bookmarks and history to detect the list of the websites that the user uses. Then if a new website is visited randomly by the user that he/she did not visit before, chances are that this website is has malicious purposes. The down side of this method is that the history feature holds a history of the limited and short time.&lt;br /&gt;
&lt;br /&gt;
===Two-way authentication===&lt;br /&gt;
&lt;br /&gt;
In this method once a user signs up for an online service they receive and image in a secure way. Thereafter whenever the user visits the website and enters his/her username the website displays the image to prove its legitimacy. The user then can continue to enter his/her password.&lt;br /&gt;
&lt;br /&gt;
===VeriSign identity protection (VIP)===&lt;br /&gt;
&lt;br /&gt;
VIP has been design to protect the digital identities of the people who use online services. VIP provides number of rules that organizations should comply with if they want use VIP services. The VIP suite then provides a secure way for users to log into their account and transactions to take place.&lt;br /&gt;
&lt;br /&gt;
===Early alarm===&lt;br /&gt;
&lt;br /&gt;
This solution requires sort of add-on tool to be installed on Web browsers. This tool contains several rules and ways to check the authentication of the Web sites. The tool will notify the user if the Web site is legitimate and trusted.&lt;br /&gt;
&lt;br /&gt;
=[[Image:new.gif|New]]Bibliography=&lt;br /&gt;
&lt;br /&gt;
===What is phishing===&lt;br /&gt;
[http://en.wikipedia.org/wiki/Phishing Phishing] ''Wikipedia''&lt;br /&gt;
&lt;br /&gt;
[http://www.identityprotection101.com/phishing/ Phishing Scams] ''identityprotection101.com''&lt;br /&gt;
&lt;br /&gt;
[http://delivery.acm.org.www.lib.ncsu.edu:2048/10.1145/1130000/1121968/p21-berghel.pdf?key1=1121968&amp;amp;key2=8870097121&amp;amp;coll=ACM&amp;amp;dl=ACM&amp;amp;CFID=72977&amp;amp;CFTOKEN=33062475  Phishing mongers and posers] Hal Berghel, ''Digital Village''&lt;br /&gt;
&lt;br /&gt;
===Privacy and ethical Issues===&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/xg41104w066612m7/fulltext.pdf Privacy and e-commerce: a consumer-centric perspective] Rhys Smith and Jianhua Shao, ''Electronic Commerce Research'', Volume 7, Number 2 / June, 2007 &lt;br /&gt;
&lt;br /&gt;
[http://www.mcgoverngreene.com/alerts/FA_pdfs/Oct-Nov_2004.pdf Phishers “net” unsuspecting consumers] ''fraud alert''  october/november 2004&lt;br /&gt;
&lt;br /&gt;
[http://delivery.acm.org.www.lib.ncsu.edu:2048/10.1145/1130000/1124861/p581-dhamija.pdf?key1=1124861&amp;amp;key2=4842557121&amp;amp;coll=ACM&amp;amp;dl=ACM&amp;amp;CFID=38796614&amp;amp;CFTOKEN=46500553 Why phishing works] Rachna Dhamija, J. D. Tygar, Marti Hearst&lt;br /&gt;
&lt;br /&gt;
[http://delivery.acm.org.www.lib.ncsu.edu:2048/10.1145/1080000/1073009/p77-dhamija.pdf?key1=1073009&amp;amp;key2=1444557121&amp;amp;coll=ACM&amp;amp;dl=ACM&amp;amp;CFID=38796614&amp;amp;CFTOKEN=46500553 The battle against phishing: Dynamic security skins] Rachna Dhamija,  J. D. Tygar&lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/d284629556533224/fulltext.pdf A Revocation scheme preserving privacy] Łukasz Krzywiecki, Przemysław Kubiak and Mirosław Kutyłowski &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/h62k448875177211/fulltext.pdf Security and privacy as market failures]L. Jean Camp,''Economics of Identity Theft: Avoidance, Causes and Possible Cures'' &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/q808084h875464v5/fulltext.pdf Protection or privacy? Data mining and personal data] David J. Hand&lt;br /&gt;
&lt;br /&gt;
===Protection against phishing attacks===&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/0p748n8766732770/fulltext.pdf Method for evaluating the security risk of a website against phishing attacks] Young-Gab Kim, Sanghyun Cho, Jun-Sub Lee, Min-Soo Lee, In Ho Kim and Sung Hoon Kim &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/307774n374w42854/fulltext.pdf An Intrusion detection system for detecting phishing attacks] Hasika Pamunuwa, Duminda Wijesekera and Csilla Farkas &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/50hln6j1b04ftbw1/fulltext.pdf Protection mechanisms against phishing attacks] Klaus Plössl, Hannes Federrath and Thomas Nowey &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/w833450106412039/fulltext.pdf On the effectiveness of techniques to detect phishing sites] Christian Ludl, Sean McAllister, Engin Kirda and Christopher Kruegel &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/bq4mj20enhm3ep0x/fulltext.pdf Effective protection against phishing and web spoofing] Rolf Oppliger and Sebastian Gajek &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/w81x1n840w231177/fulltext.pdf Usability evaluation of anti-phishing toolbars] Linfeng Li and Marko Helenius&lt;br /&gt;
&lt;br /&gt;
===Others===&lt;br /&gt;
[http://pg-server.csc.ncsu.edu/mediawiki/index.php/CSC_379_SUM2008:Topics#Phishing Topic page]&lt;br /&gt;
&lt;br /&gt;
[http://ethics.csc.ncsu.edu/abuse/spam/phishing/new.html Old phishing page]&lt;/div&gt;</summary>
		<author><name>Mbastan</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16799</id>
		<title>Phishing</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16799"/>
		<updated>2008-08-05T01:48:42Z</updated>

		<summary type="html">&lt;p&gt;Mbastan: /* What is phishing */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=[[Image:new.gif|New]]Study Guide=&lt;br /&gt;
==Why is phishing unethical?==&lt;br /&gt;
Phishing in computing is the process of acquiring private and sensitive information by pretending to be a trustworthy or a legitimate website through the online communications. Phishing is an example of fraudulent use of social engineering techniques to deceive an online service user. In this article some of the known attacks will be discussed following with some solutions to guard against these attacks.&lt;br /&gt;
&lt;br /&gt;
==Phishing attacks==&lt;br /&gt;
&lt;br /&gt;
As the technology advances and anti malware applications become more efficient, phishing attacks adopt new forms to stay away from detection. First different forms of attack will be discussed and then some of the solutions that one may prevent these attacks with will be presented. &lt;br /&gt;
&lt;br /&gt;
====Keyloggers====&lt;br /&gt;
&lt;br /&gt;
These are spywares that can get installed either into a web browser or as a device driver. They record the user’s input to the computer by recording the keyboard keystrokes or mouse click. This information will be then sent to the spyware owner. These spywares can cause severe data leak.&lt;br /&gt;
&lt;br /&gt;
===Torpig-family Trojan===&lt;br /&gt;
&lt;br /&gt;
These Trojans are using advanced technologies that help them to spread very fast and hide very well. They are designed to hijack sessions. These Trojans are constantly monitoring major banks’ websites throughout the world. They display a fake page when a user tries to log in to these websites, and in this way continue to steal the private information of their victims.&lt;br /&gt;
&lt;br /&gt;
===Session hijackers===&lt;br /&gt;
&lt;br /&gt;
These attacks can take place either from the malware that is installed on the victim’s computer or remotely. The attacks are triggered when users is trying to log into they account (usually bank accounts) or when they initiate a transaction. The malware then hijack the session for malicious purposes.&lt;br /&gt;
&lt;br /&gt;
===Content-injection phishing===&lt;br /&gt;
&lt;br /&gt;
This phishing refers to the situations when malicious or fake content gets injected into some legitimate Web sites. This content then can deceive the users of the Web site by redirecting them to other Web sites, install malware on their computers, or redirect the input that users is inputting to that Web site to the phishing server.&lt;br /&gt;
&lt;br /&gt;
===“Universal” man-in-the-middle phishing kit===&lt;br /&gt;
&lt;br /&gt;
There is only little effort required for the attackers to use this method to attack their victims. The attackers use a kit which is called MITM that includes several PHP files that get installed on the phishing server. This server then acts as a medium between the user and the legitimate website that he/she wants to access. These victims receive emails that include a purported link to their known website. Once they click on the link, they’ll be redirected to the phishing server which then will communicate with the original Web site on behalf of the user.&lt;br /&gt;
&lt;br /&gt;
===Search engine phishing===&lt;br /&gt;
&lt;br /&gt;
In this type pf phishing, phishers establish a webpage, and then get it indexed by the search engines to make it searchable. These pages are usually designed to include items and services at very low price to attract visitors to sign up or to enter their confidential information. The phisher then get the hold of the private information of the visitors.&lt;br /&gt;
&lt;br /&gt;
===Spear phishing===&lt;br /&gt;
&lt;br /&gt;
In this approach the phisher targets a particular person or a specific department in a company. The phisher then contacts the person by email and pretends to be from a legitimate department and is a trustworthy staff. The attacker then asks for the username and password with some fake reasons. Once the attacker get those information the can by pass the firewalls and break into the secured network.&lt;br /&gt;
&lt;br /&gt;
==Phishing solutions==&lt;br /&gt;
&lt;br /&gt;
To fight against the phishers, in the first place, the online service users should be educated. Once users know what phishing is and what methods phishers use, less people will fall for their tricks and many of their method then become useless. However some countermeasures have been developed and some of them are explained below.&lt;br /&gt;
&lt;br /&gt;
===Phishing blacklist===&lt;br /&gt;
&lt;br /&gt;
A server that is containing a list of all of the malicious websites and phishing servers should be established and be accessible by the internet browsers. The list should be updated on daily basis due to the lifetime of the phishing servers. The malicious URLs should be reported immediately.&lt;br /&gt;
&lt;br /&gt;
===Bookmarks or history===&lt;br /&gt;
&lt;br /&gt;
Using bookmarks and history to detect the list of the websites that the user uses. Then if a new website is visited randomly by the user that he/she did not visit before, chances are that this website is has malicious purposes. The down side of this method is that the history feature holds a history of the limited and short time.&lt;br /&gt;
&lt;br /&gt;
===Two-way authentication===&lt;br /&gt;
&lt;br /&gt;
In this method once a user signs up for an online service they receive and image in a secure way. Thereafter whenever the user visits the website and enters his/her username the website displays the image to prove its legitimacy. The user then can continue to enter his/her password.&lt;br /&gt;
&lt;br /&gt;
===VeriSign identity protection (VIP)===&lt;br /&gt;
&lt;br /&gt;
VIP has been design to protect the digital identities of the people who use online services. VIP provides number of rules that organizations should comply with if they want use VIP services. The VIP suite then provides a secure way for users to log into their account and transactions to take place.&lt;br /&gt;
&lt;br /&gt;
===Early alarm===&lt;br /&gt;
&lt;br /&gt;
This solution requires sort of add-on tool to be installed on Web browsers. This tool contains several rules and ways to check the authentication of the Web sites. The tool will notify the user if the Web site is legitimate and trusted.&lt;br /&gt;
&lt;br /&gt;
=[[Image:new.gif|New]]Bibliography=&lt;br /&gt;
&lt;br /&gt;
===What is phishing===&lt;br /&gt;
[http://en.wikipedia.org/wiki/Phishing Phishing] ''Wikipedia''&lt;br /&gt;
&lt;br /&gt;
[http://www.identityprotection101.com/phishing/ Phishing Scams] ''identityprotection101.com''&lt;br /&gt;
&lt;br /&gt;
[http://delivery.acm.org.www.lib.ncsu.edu:2048/10.1145/1130000/1121968/p21-berghel.pdf?key1=1121968&amp;amp;key2=8870097121&amp;amp;coll=ACM&amp;amp;dl=ACM&amp;amp;CFID=72977&amp;amp;CFTOKEN=33062475  Phishing mongers and posers]Hal Berghel, ''Digital Village''&lt;br /&gt;
&lt;br /&gt;
===Privacy and ethical Issues===&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/xg41104w066612m7/fulltext.pdf Privacy and e-commerce: a consumer-centric perspective] Rhys Smith and Jianhua Shao, ''Electronic Commerce Research'', Volume 7, Number 2 / June, 2007 &lt;br /&gt;
&lt;br /&gt;
[http://www.mcgoverngreene.com/alerts/FA_pdfs/Oct-Nov_2004.pdf Phishers “net” unsuspecting consumers] ''fraud alert''  october/november 2004&lt;br /&gt;
&lt;br /&gt;
[http://delivery.acm.org.www.lib.ncsu.edu:2048/10.1145/1130000/1124861/p581-dhamija.pdf?key1=1124861&amp;amp;key2=4842557121&amp;amp;coll=ACM&amp;amp;dl=ACM&amp;amp;CFID=38796614&amp;amp;CFTOKEN=46500553 Why phishing works] Rachna Dhamija, J. D. Tygar, Marti Hearst&lt;br /&gt;
&lt;br /&gt;
[http://delivery.acm.org.www.lib.ncsu.edu:2048/10.1145/1080000/1073009/p77-dhamija.pdf?key1=1073009&amp;amp;key2=1444557121&amp;amp;coll=ACM&amp;amp;dl=ACM&amp;amp;CFID=38796614&amp;amp;CFTOKEN=46500553 The battle against phishing: Dynamic security skins] Rachna Dhamija,  J. D. Tygar&lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/d284629556533224/fulltext.pdf A Revocation scheme preserving privacy] Łukasz Krzywiecki, Przemysław Kubiak and Mirosław Kutyłowski &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/h62k448875177211/fulltext.pdf Security and privacy as market failures]L. Jean Camp,''Economics of Identity Theft: Avoidance, Causes and Possible Cures'' &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/q808084h875464v5/fulltext.pdf Protection or privacy? Data mining and personal data] David J. Hand&lt;br /&gt;
&lt;br /&gt;
===Protection against phishing attacks===&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/0p748n8766732770/fulltext.pdf Method for evaluating the security risk of a website against phishing attacks] Young-Gab Kim, Sanghyun Cho, Jun-Sub Lee, Min-Soo Lee, In Ho Kim and Sung Hoon Kim &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/307774n374w42854/fulltext.pdf An Intrusion detection system for detecting phishing attacks] Hasika Pamunuwa, Duminda Wijesekera and Csilla Farkas &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/50hln6j1b04ftbw1/fulltext.pdf Protection mechanisms against phishing attacks] Klaus Plössl, Hannes Federrath and Thomas Nowey &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/w833450106412039/fulltext.pdf On the effectiveness of techniques to detect phishing sites] Christian Ludl, Sean McAllister, Engin Kirda and Christopher Kruegel &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/bq4mj20enhm3ep0x/fulltext.pdf Effective protection against phishing and web spoofing] Rolf Oppliger and Sebastian Gajek &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/w81x1n840w231177/fulltext.pdf Usability evaluation of anti-phishing toolbars] Linfeng Li and Marko Helenius&lt;br /&gt;
&lt;br /&gt;
===Others===&lt;br /&gt;
[http://pg-server.csc.ncsu.edu/mediawiki/index.php/CSC_379_SUM2008:Topics#Phishing Topic page]&lt;br /&gt;
&lt;br /&gt;
[http://ethics.csc.ncsu.edu/abuse/spam/phishing/new.html Old phishing page]&lt;/div&gt;</summary>
		<author><name>Mbastan</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16795</id>
		<title>Phishing</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16795"/>
		<updated>2008-08-05T01:45:01Z</updated>

		<summary type="html">&lt;p&gt;Mbastan: /* What is phishing */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=[[Image:new.gif|New]]Study Guide=&lt;br /&gt;
==Why is phishing unethical?==&lt;br /&gt;
Phishing in computing is the process of acquiring private and sensitive information by pretending to be a trustworthy or a legitimate website through the online communications. Phishing is an example of fraudulent use of social engineering techniques to deceive an online service user. In this article some of the known attacks will be discussed following with some solutions to guard against these attacks.&lt;br /&gt;
&lt;br /&gt;
==Phishing attacks==&lt;br /&gt;
&lt;br /&gt;
As the technology advances and anti malware applications become more efficient, phishing attacks adopt new forms to stay away from detection. First different forms of attack will be discussed and then some of the solutions that one may prevent these attacks with will be presented. &lt;br /&gt;
&lt;br /&gt;
====Keyloggers====&lt;br /&gt;
&lt;br /&gt;
These are spywares that can get installed either into a web browser or as a device driver. They record the user’s input to the computer by recording the keyboard keystrokes or mouse click. This information will be then sent to the spyware owner. These spywares can cause severe data leak.&lt;br /&gt;
&lt;br /&gt;
===Torpig-family Trojan===&lt;br /&gt;
&lt;br /&gt;
These Trojans are using advanced technologies that help them to spread very fast and hide very well. They are designed to hijack sessions. These Trojans are constantly monitoring major banks’ websites throughout the world. They display a fake page when a user tries to log in to these websites, and in this way continue to steal the private information of their victims.&lt;br /&gt;
&lt;br /&gt;
===Session hijackers===&lt;br /&gt;
&lt;br /&gt;
These attacks can take place either from the malware that is installed on the victim’s computer or remotely. The attacks are triggered when users is trying to log into they account (usually bank accounts) or when they initiate a transaction. The malware then hijack the session for malicious purposes.&lt;br /&gt;
&lt;br /&gt;
===Content-injection phishing===&lt;br /&gt;
&lt;br /&gt;
This phishing refers to the situations when malicious or fake content gets injected into some legitimate Web sites. This content then can deceive the users of the Web site by redirecting them to other Web sites, install malware on their computers, or redirect the input that users is inputting to that Web site to the phishing server.&lt;br /&gt;
&lt;br /&gt;
===“Universal” man-in-the-middle phishing kit===&lt;br /&gt;
&lt;br /&gt;
There is only little effort required for the attackers to use this method to attack their victims. The attackers use a kit which is called MITM that includes several PHP files that get installed on the phishing server. This server then acts as a medium between the user and the legitimate website that he/she wants to access. These victims receive emails that include a purported link to their known website. Once they click on the link, they’ll be redirected to the phishing server which then will communicate with the original Web site on behalf of the user.&lt;br /&gt;
&lt;br /&gt;
===Search engine phishing===&lt;br /&gt;
&lt;br /&gt;
In this type pf phishing, phishers establish a webpage, and then get it indexed by the search engines to make it searchable. These pages are usually designed to include items and services at very low price to attract visitors to sign up or to enter their confidential information. The phisher then get the hold of the private information of the visitors.&lt;br /&gt;
&lt;br /&gt;
===Spear phishing===&lt;br /&gt;
&lt;br /&gt;
In this approach the phisher targets a particular person or a specific department in a company. The phisher then contacts the person by email and pretends to be from a legitimate department and is a trustworthy staff. The attacker then asks for the username and password with some fake reasons. Once the attacker get those information the can by pass the firewalls and break into the secured network.&lt;br /&gt;
&lt;br /&gt;
==Phishing solutions==&lt;br /&gt;
&lt;br /&gt;
To fight against the phishers, in the first place, the online service users should be educated. Once users know what phishing is and what methods phishers use, less people will fall for their tricks and many of their method then become useless. However some countermeasures have been developed and some of them are explained below.&lt;br /&gt;
&lt;br /&gt;
===Phishing blacklist===&lt;br /&gt;
&lt;br /&gt;
A server that is containing a list of all of the malicious websites and phishing servers should be established and be accessible by the internet browsers. The list should be updated on daily basis due to the lifetime of the phishing servers. The malicious URLs should be reported immediately.&lt;br /&gt;
&lt;br /&gt;
===Bookmarks or history===&lt;br /&gt;
&lt;br /&gt;
Using bookmarks and history to detect the list of the websites that the user uses. Then if a new website is visited randomly by the user that he/she did not visit before, chances are that this website is has malicious purposes. The down side of this method is that the history feature holds a history of the limited and short time.&lt;br /&gt;
&lt;br /&gt;
===Two-way authentication===&lt;br /&gt;
&lt;br /&gt;
In this method once a user signs up for an online service they receive and image in a secure way. Thereafter whenever the user visits the website and enters his/her username the website displays the image to prove its legitimacy. The user then can continue to enter his/her password.&lt;br /&gt;
&lt;br /&gt;
===VeriSign identity protection (VIP)===&lt;br /&gt;
&lt;br /&gt;
VIP has been design to protect the digital identities of the people who use online services. VIP provides number of rules that organizations should comply with if they want use VIP services. The VIP suite then provides a secure way for users to log into their account and transactions to take place.&lt;br /&gt;
&lt;br /&gt;
===Early alarm===&lt;br /&gt;
&lt;br /&gt;
This solution requires sort of add-on tool to be installed on Web browsers. This tool contains several rules and ways to check the authentication of the Web sites. The tool will notify the user if the Web site is legitimate and trusted.&lt;br /&gt;
&lt;br /&gt;
=[[Image:new.gif|New]]Bibliography=&lt;br /&gt;
&lt;br /&gt;
===What is phishing===&lt;br /&gt;
[http://en.wikipedia.org/wiki/Phishing Phishing] ''Wikipedia''&lt;br /&gt;
&lt;br /&gt;
[http://www.identityprotection101.com/phishing/ Phishing Scams] ''identityprotection101.com''&lt;br /&gt;
&lt;br /&gt;
===Privacy and ethical Issues===&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/xg41104w066612m7/fulltext.pdf Privacy and e-commerce: a consumer-centric perspective] Rhys Smith and Jianhua Shao, ''Electronic Commerce Research'', Volume 7, Number 2 / June, 2007 &lt;br /&gt;
&lt;br /&gt;
[http://www.mcgoverngreene.com/alerts/FA_pdfs/Oct-Nov_2004.pdf Phishers “net” unsuspecting consumers] ''fraud alert''  october/november 2004&lt;br /&gt;
&lt;br /&gt;
[http://delivery.acm.org.www.lib.ncsu.edu:2048/10.1145/1130000/1124861/p581-dhamija.pdf?key1=1124861&amp;amp;key2=4842557121&amp;amp;coll=ACM&amp;amp;dl=ACM&amp;amp;CFID=38796614&amp;amp;CFTOKEN=46500553 Why phishing works] Rachna Dhamija, J. D. Tygar, Marti Hearst&lt;br /&gt;
&lt;br /&gt;
[http://delivery.acm.org.www.lib.ncsu.edu:2048/10.1145/1080000/1073009/p77-dhamija.pdf?key1=1073009&amp;amp;key2=1444557121&amp;amp;coll=ACM&amp;amp;dl=ACM&amp;amp;CFID=38796614&amp;amp;CFTOKEN=46500553 The battle against phishing: Dynamic security skins] Rachna Dhamija,  J. D. Tygar&lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/d284629556533224/fulltext.pdf A Revocation scheme preserving privacy] Łukasz Krzywiecki, Przemysław Kubiak and Mirosław Kutyłowski &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/h62k448875177211/fulltext.pdf Security and privacy as market failures]L. Jean Camp,''Economics of Identity Theft: Avoidance, Causes and Possible Cures'' &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/q808084h875464v5/fulltext.pdf Protection or privacy? Data mining and personal data] David J. Hand&lt;br /&gt;
&lt;br /&gt;
===Protection against phishing attacks===&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/0p748n8766732770/fulltext.pdf Method for evaluating the security risk of a website against phishing attacks] Young-Gab Kim, Sanghyun Cho, Jun-Sub Lee, Min-Soo Lee, In Ho Kim and Sung Hoon Kim &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/307774n374w42854/fulltext.pdf An Intrusion detection system for detecting phishing attacks] Hasika Pamunuwa, Duminda Wijesekera and Csilla Farkas &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/50hln6j1b04ftbw1/fulltext.pdf Protection mechanisms against phishing attacks] Klaus Plössl, Hannes Federrath and Thomas Nowey &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/w833450106412039/fulltext.pdf On the effectiveness of techniques to detect phishing sites] Christian Ludl, Sean McAllister, Engin Kirda and Christopher Kruegel &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/bq4mj20enhm3ep0x/fulltext.pdf Effective protection against phishing and web spoofing] Rolf Oppliger and Sebastian Gajek &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/w81x1n840w231177/fulltext.pdf Usability evaluation of anti-phishing toolbars] Linfeng Li and Marko Helenius&lt;br /&gt;
&lt;br /&gt;
===Others===&lt;br /&gt;
[http://pg-server.csc.ncsu.edu/mediawiki/index.php/CSC_379_SUM2008:Topics#Phishing Topic page]&lt;br /&gt;
&lt;br /&gt;
[http://ethics.csc.ncsu.edu/abuse/spam/phishing/new.html Old phishing page]&lt;/div&gt;</summary>
		<author><name>Mbastan</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16792</id>
		<title>Phishing</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16792"/>
		<updated>2008-08-05T01:35:28Z</updated>

		<summary type="html">&lt;p&gt;Mbastan: /* NewBibliography */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=[[Image:new.gif|New]]Study Guide=&lt;br /&gt;
==Why is phishing unethical?==&lt;br /&gt;
Phishing in computing is the process of acquiring private and sensitive information by pretending to be a trustworthy or a legitimate website through the online communications. Phishing is an example of fraudulent use of social engineering techniques to deceive an online service user. In this article some of the known attacks will be discussed following with some solutions to guard against these attacks.&lt;br /&gt;
&lt;br /&gt;
==Phishing attacks==&lt;br /&gt;
&lt;br /&gt;
As the technology advances and anti malware applications become more efficient, phishing attacks adopt new forms to stay away from detection. First different forms of attack will be discussed and then some of the solutions that one may prevent these attacks with will be presented. &lt;br /&gt;
&lt;br /&gt;
====Keyloggers====&lt;br /&gt;
&lt;br /&gt;
These are spywares that can get installed either into a web browser or as a device driver. They record the user’s input to the computer by recording the keyboard keystrokes or mouse click. This information will be then sent to the spyware owner. These spywares can cause severe data leak.&lt;br /&gt;
&lt;br /&gt;
===Torpig-family Trojan===&lt;br /&gt;
&lt;br /&gt;
These Trojans are using advanced technologies that help them to spread very fast and hide very well. They are designed to hijack sessions. These Trojans are constantly monitoring major banks’ websites throughout the world. They display a fake page when a user tries to log in to these websites, and in this way continue to steal the private information of their victims.&lt;br /&gt;
&lt;br /&gt;
===Session hijackers===&lt;br /&gt;
&lt;br /&gt;
These attacks can take place either from the malware that is installed on the victim’s computer or remotely. The attacks are triggered when users is trying to log into they account (usually bank accounts) or when they initiate a transaction. The malware then hijack the session for malicious purposes.&lt;br /&gt;
&lt;br /&gt;
===Content-injection phishing===&lt;br /&gt;
&lt;br /&gt;
This phishing refers to the situations when malicious or fake content gets injected into some legitimate Web sites. This content then can deceive the users of the Web site by redirecting them to other Web sites, install malware on their computers, or redirect the input that users is inputting to that Web site to the phishing server.&lt;br /&gt;
&lt;br /&gt;
===“Universal” man-in-the-middle phishing kit===&lt;br /&gt;
&lt;br /&gt;
There is only little effort required for the attackers to use this method to attack their victims. The attackers use a kit which is called MITM that includes several PHP files that get installed on the phishing server. This server then acts as a medium between the user and the legitimate website that he/she wants to access. These victims receive emails that include a purported link to their known website. Once they click on the link, they’ll be redirected to the phishing server which then will communicate with the original Web site on behalf of the user.&lt;br /&gt;
&lt;br /&gt;
===Search engine phishing===&lt;br /&gt;
&lt;br /&gt;
In this type pf phishing, phishers establish a webpage, and then get it indexed by the search engines to make it searchable. These pages are usually designed to include items and services at very low price to attract visitors to sign up or to enter their confidential information. The phisher then get the hold of the private information of the visitors.&lt;br /&gt;
&lt;br /&gt;
===Spear phishing===&lt;br /&gt;
&lt;br /&gt;
In this approach the phisher targets a particular person or a specific department in a company. The phisher then contacts the person by email and pretends to be from a legitimate department and is a trustworthy staff. The attacker then asks for the username and password with some fake reasons. Once the attacker get those information the can by pass the firewalls and break into the secured network.&lt;br /&gt;
&lt;br /&gt;
==Phishing solutions==&lt;br /&gt;
&lt;br /&gt;
To fight against the phishers, in the first place, the online service users should be educated. Once users know what phishing is and what methods phishers use, less people will fall for their tricks and many of their method then become useless. However some countermeasures have been developed and some of them are explained below.&lt;br /&gt;
&lt;br /&gt;
===Phishing blacklist===&lt;br /&gt;
&lt;br /&gt;
A server that is containing a list of all of the malicious websites and phishing servers should be established and be accessible by the internet browsers. The list should be updated on daily basis due to the lifetime of the phishing servers. The malicious URLs should be reported immediately.&lt;br /&gt;
&lt;br /&gt;
===Bookmarks or history===&lt;br /&gt;
&lt;br /&gt;
Using bookmarks and history to detect the list of the websites that the user uses. Then if a new website is visited randomly by the user that he/she did not visit before, chances are that this website is has malicious purposes. The down side of this method is that the history feature holds a history of the limited and short time.&lt;br /&gt;
&lt;br /&gt;
===Two-way authentication===&lt;br /&gt;
&lt;br /&gt;
In this method once a user signs up for an online service they receive and image in a secure way. Thereafter whenever the user visits the website and enters his/her username the website displays the image to prove its legitimacy. The user then can continue to enter his/her password.&lt;br /&gt;
&lt;br /&gt;
===VeriSign identity protection (VIP)===&lt;br /&gt;
&lt;br /&gt;
VIP has been design to protect the digital identities of the people who use online services. VIP provides number of rules that organizations should comply with if they want use VIP services. The VIP suite then provides a secure way for users to log into their account and transactions to take place.&lt;br /&gt;
&lt;br /&gt;
===Early alarm===&lt;br /&gt;
&lt;br /&gt;
This solution requires sort of add-on tool to be installed on Web browsers. This tool contains several rules and ways to check the authentication of the Web sites. The tool will notify the user if the Web site is legitimate and trusted.&lt;br /&gt;
&lt;br /&gt;
=[[Image:new.gif|New]]Bibliography=&lt;br /&gt;
&lt;br /&gt;
===What is phishing===&lt;br /&gt;
[http://en.wikipedia.org/wiki/Phishing Phishing] ''Wikipedia''&lt;br /&gt;
&lt;br /&gt;
===Privacy and ethical Issues===&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/xg41104w066612m7/fulltext.pdf Privacy and e-commerce: a consumer-centric perspective] Rhys Smith and Jianhua Shao, ''Electronic Commerce Research'', Volume 7, Number 2 / June, 2007 &lt;br /&gt;
&lt;br /&gt;
[http://www.mcgoverngreene.com/alerts/FA_pdfs/Oct-Nov_2004.pdf Phishers “net” unsuspecting consumers] ''fraud alert''  october/november 2004&lt;br /&gt;
&lt;br /&gt;
[http://delivery.acm.org.www.lib.ncsu.edu:2048/10.1145/1130000/1124861/p581-dhamija.pdf?key1=1124861&amp;amp;key2=4842557121&amp;amp;coll=ACM&amp;amp;dl=ACM&amp;amp;CFID=38796614&amp;amp;CFTOKEN=46500553 Why phishing works] Rachna Dhamija, J. D. Tygar, Marti Hearst&lt;br /&gt;
&lt;br /&gt;
[http://delivery.acm.org.www.lib.ncsu.edu:2048/10.1145/1080000/1073009/p77-dhamija.pdf?key1=1073009&amp;amp;key2=1444557121&amp;amp;coll=ACM&amp;amp;dl=ACM&amp;amp;CFID=38796614&amp;amp;CFTOKEN=46500553 The battle against phishing: Dynamic security skins] Rachna Dhamija,  J. D. Tygar&lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/d284629556533224/fulltext.pdf A Revocation scheme preserving privacy] Łukasz Krzywiecki, Przemysław Kubiak and Mirosław Kutyłowski &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/h62k448875177211/fulltext.pdf Security and privacy as market failures]L. Jean Camp,''Economics of Identity Theft: Avoidance, Causes and Possible Cures'' &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/q808084h875464v5/fulltext.pdf Protection or privacy? Data mining and personal data] David J. Hand&lt;br /&gt;
&lt;br /&gt;
===Protection against phishing attacks===&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/0p748n8766732770/fulltext.pdf Method for evaluating the security risk of a website against phishing attacks] Young-Gab Kim, Sanghyun Cho, Jun-Sub Lee, Min-Soo Lee, In Ho Kim and Sung Hoon Kim &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/307774n374w42854/fulltext.pdf An Intrusion detection system for detecting phishing attacks] Hasika Pamunuwa, Duminda Wijesekera and Csilla Farkas &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/50hln6j1b04ftbw1/fulltext.pdf Protection mechanisms against phishing attacks] Klaus Plössl, Hannes Federrath and Thomas Nowey &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/w833450106412039/fulltext.pdf On the effectiveness of techniques to detect phishing sites] Christian Ludl, Sean McAllister, Engin Kirda and Christopher Kruegel &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/bq4mj20enhm3ep0x/fulltext.pdf Effective protection against phishing and web spoofing] Rolf Oppliger and Sebastian Gajek &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/w81x1n840w231177/fulltext.pdf Usability evaluation of anti-phishing toolbars] Linfeng Li and Marko Helenius&lt;br /&gt;
&lt;br /&gt;
===Others===&lt;br /&gt;
[http://pg-server.csc.ncsu.edu/mediawiki/index.php/CSC_379_SUM2008:Topics#Phishing Topic page]&lt;br /&gt;
&lt;br /&gt;
[http://ethics.csc.ncsu.edu/abuse/spam/phishing/new.html Old phishing page]&lt;/div&gt;</summary>
		<author><name>Mbastan</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16791</id>
		<title>Phishing</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16791"/>
		<updated>2008-08-05T01:31:22Z</updated>

		<summary type="html">&lt;p&gt;Mbastan: /* Others */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=[[Image:new.gif|New]]Study Guide=&lt;br /&gt;
==Why is phishing unethical?==&lt;br /&gt;
Phishing in computing is the process of acquiring private and sensitive information by pretending to be a trustworthy or a legitimate website through the online communications. Phishing is an example of fraudulent use of social engineering techniques to deceive an online service user. In this article some of the known attacks will be discussed following with some solutions to guard against these attacks.&lt;br /&gt;
&lt;br /&gt;
==Phishing attacks==&lt;br /&gt;
&lt;br /&gt;
As the technology advances and anti malware applications become more efficient, phishing attacks adopt new forms to stay away from detection. First different forms of attack will be discussed and then some of the solutions that one may prevent these attacks with will be presented. &lt;br /&gt;
&lt;br /&gt;
====Keyloggers====&lt;br /&gt;
&lt;br /&gt;
These are spywares that can get installed either into a web browser or as a device driver. They record the user’s input to the computer by recording the keyboard keystrokes or mouse click. This information will be then sent to the spyware owner. These spywares can cause severe data leak.&lt;br /&gt;
&lt;br /&gt;
===Torpig-family Trojan===&lt;br /&gt;
&lt;br /&gt;
These Trojans are using advanced technologies that help them to spread very fast and hide very well. They are designed to hijack sessions. These Trojans are constantly monitoring major banks’ websites throughout the world. They display a fake page when a user tries to log in to these websites, and in this way continue to steal the private information of their victims.&lt;br /&gt;
&lt;br /&gt;
===Session hijackers===&lt;br /&gt;
&lt;br /&gt;
These attacks can take place either from the malware that is installed on the victim’s computer or remotely. The attacks are triggered when users is trying to log into they account (usually bank accounts) or when they initiate a transaction. The malware then hijack the session for malicious purposes.&lt;br /&gt;
&lt;br /&gt;
===Content-injection phishing===&lt;br /&gt;
&lt;br /&gt;
This phishing refers to the situations when malicious or fake content gets injected into some legitimate Web sites. This content then can deceive the users of the Web site by redirecting them to other Web sites, install malware on their computers, or redirect the input that users is inputting to that Web site to the phishing server.&lt;br /&gt;
&lt;br /&gt;
===“Universal” man-in-the-middle phishing kit===&lt;br /&gt;
&lt;br /&gt;
There is only little effort required for the attackers to use this method to attack their victims. The attackers use a kit which is called MITM that includes several PHP files that get installed on the phishing server. This server then acts as a medium between the user and the legitimate website that he/she wants to access. These victims receive emails that include a purported link to their known website. Once they click on the link, they’ll be redirected to the phishing server which then will communicate with the original Web site on behalf of the user.&lt;br /&gt;
&lt;br /&gt;
===Search engine phishing===&lt;br /&gt;
&lt;br /&gt;
In this type pf phishing, phishers establish a webpage, and then get it indexed by the search engines to make it searchable. These pages are usually designed to include items and services at very low price to attract visitors to sign up or to enter their confidential information. The phisher then get the hold of the private information of the visitors.&lt;br /&gt;
&lt;br /&gt;
===Spear phishing===&lt;br /&gt;
&lt;br /&gt;
In this approach the phisher targets a particular person or a specific department in a company. The phisher then contacts the person by email and pretends to be from a legitimate department and is a trustworthy staff. The attacker then asks for the username and password with some fake reasons. Once the attacker get those information the can by pass the firewalls and break into the secured network.&lt;br /&gt;
&lt;br /&gt;
==Phishing solutions==&lt;br /&gt;
&lt;br /&gt;
To fight against the phishers, in the first place, the online service users should be educated. Once users know what phishing is and what methods phishers use, less people will fall for their tricks and many of their method then become useless. However some countermeasures have been developed and some of them are explained below.&lt;br /&gt;
&lt;br /&gt;
===Phishing blacklist===&lt;br /&gt;
&lt;br /&gt;
A server that is containing a list of all of the malicious websites and phishing servers should be established and be accessible by the internet browsers. The list should be updated on daily basis due to the lifetime of the phishing servers. The malicious URLs should be reported immediately.&lt;br /&gt;
&lt;br /&gt;
===Bookmarks or history===&lt;br /&gt;
&lt;br /&gt;
Using bookmarks and history to detect the list of the websites that the user uses. Then if a new website is visited randomly by the user that he/she did not visit before, chances are that this website is has malicious purposes. The down side of this method is that the history feature holds a history of the limited and short time.&lt;br /&gt;
&lt;br /&gt;
===Two-way authentication===&lt;br /&gt;
&lt;br /&gt;
In this method once a user signs up for an online service they receive and image in a secure way. Thereafter whenever the user visits the website and enters his/her username the website displays the image to prove its legitimacy. The user then can continue to enter his/her password.&lt;br /&gt;
&lt;br /&gt;
===VeriSign identity protection (VIP)===&lt;br /&gt;
&lt;br /&gt;
VIP has been design to protect the digital identities of the people who use online services. VIP provides number of rules that organizations should comply with if they want use VIP services. The VIP suite then provides a secure way for users to log into their account and transactions to take place.&lt;br /&gt;
&lt;br /&gt;
===Early alarm===&lt;br /&gt;
&lt;br /&gt;
This solution requires sort of add-on tool to be installed on Web browsers. This tool contains several rules and ways to check the authentication of the Web sites. The tool will notify the user if the Web site is legitimate and trusted.&lt;br /&gt;
&lt;br /&gt;
=[[Image:new.gif|New]]Bibliography=&lt;br /&gt;
===Privacy and ethical Issues===&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/xg41104w066612m7/fulltext.pdf Privacy and e-commerce: a consumer-centric perspective] Rhys Smith and Jianhua Shao, ''Electronic Commerce Research'', Volume 7, Number 2 / June, 2007 &lt;br /&gt;
&lt;br /&gt;
[http://www.mcgoverngreene.com/alerts/FA_pdfs/Oct-Nov_2004.pdf Phishers “net” unsuspecting consumers] ''fraud alert''  october/november 2004&lt;br /&gt;
&lt;br /&gt;
[http://delivery.acm.org.www.lib.ncsu.edu:2048/10.1145/1130000/1124861/p581-dhamija.pdf?key1=1124861&amp;amp;key2=4842557121&amp;amp;coll=ACM&amp;amp;dl=ACM&amp;amp;CFID=38796614&amp;amp;CFTOKEN=46500553 Why phishing works] Rachna Dhamija, J. D. Tygar, Marti Hearst&lt;br /&gt;
&lt;br /&gt;
[http://delivery.acm.org.www.lib.ncsu.edu:2048/10.1145/1080000/1073009/p77-dhamija.pdf?key1=1073009&amp;amp;key2=1444557121&amp;amp;coll=ACM&amp;amp;dl=ACM&amp;amp;CFID=38796614&amp;amp;CFTOKEN=46500553 The battle against phishing: Dynamic security skins] Rachna Dhamija,  J. D. Tygar&lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/d284629556533224/fulltext.pdf A Revocation scheme preserving privacy] Łukasz Krzywiecki, Przemysław Kubiak and Mirosław Kutyłowski &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/h62k448875177211/fulltext.pdf Security and privacy as market failures]L. Jean Camp,''Economics of Identity Theft: Avoidance, Causes and Possible Cures'' &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/q808084h875464v5/fulltext.pdf Protection or privacy? Data mining and personal data] David J. Hand&lt;br /&gt;
&lt;br /&gt;
===Protection against phishing attacks===&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/0p748n8766732770/fulltext.pdf Method for evaluating the security risk of a website against phishing attacks] Young-Gab Kim, Sanghyun Cho, Jun-Sub Lee, Min-Soo Lee, In Ho Kim and Sung Hoon Kim &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/307774n374w42854/fulltext.pdf An Intrusion detection system for detecting phishing attacks] Hasika Pamunuwa, Duminda Wijesekera and Csilla Farkas &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/50hln6j1b04ftbw1/fulltext.pdf Protection mechanisms against phishing attacks] Klaus Plössl, Hannes Federrath and Thomas Nowey &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/w833450106412039/fulltext.pdf On the effectiveness of techniques to detect phishing sites] Christian Ludl, Sean McAllister, Engin Kirda and Christopher Kruegel &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/bq4mj20enhm3ep0x/fulltext.pdf Effective protection against phishing and web spoofing] Rolf Oppliger and Sebastian Gajek &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/w81x1n840w231177/fulltext.pdf Usability evaluation of anti-phishing toolbars] Linfeng Li and Marko Helenius&lt;br /&gt;
&lt;br /&gt;
===Others===&lt;br /&gt;
[http://pg-server.csc.ncsu.edu/mediawiki/index.php/CSC_379_SUM2008:Topics#Phishing Topic page]&lt;br /&gt;
&lt;br /&gt;
[http://ethics.csc.ncsu.edu/abuse/spam/phishing/new.html Old phishing page]&lt;/div&gt;</summary>
		<author><name>Mbastan</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16789</id>
		<title>Phishing</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16789"/>
		<updated>2008-08-05T01:26:46Z</updated>

		<summary type="html">&lt;p&gt;Mbastan: /* Protection against phishing attacks */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=[[Image:new.gif|New]]Study Guide=&lt;br /&gt;
==Why is phishing unethical?==&lt;br /&gt;
Phishing in computing is the process of acquiring private and sensitive information by pretending to be a trustworthy or a legitimate website through the online communications. Phishing is an example of fraudulent use of social engineering techniques to deceive an online service user. In this article some of the known attacks will be discussed following with some solutions to guard against these attacks.&lt;br /&gt;
&lt;br /&gt;
==Phishing attacks==&lt;br /&gt;
&lt;br /&gt;
As the technology advances and anti malware applications become more efficient, phishing attacks adopt new forms to stay away from detection. First different forms of attack will be discussed and then some of the solutions that one may prevent these attacks with will be presented. &lt;br /&gt;
&lt;br /&gt;
====Keyloggers====&lt;br /&gt;
&lt;br /&gt;
These are spywares that can get installed either into a web browser or as a device driver. They record the user’s input to the computer by recording the keyboard keystrokes or mouse click. This information will be then sent to the spyware owner. These spywares can cause severe data leak.&lt;br /&gt;
&lt;br /&gt;
===Torpig-family Trojan===&lt;br /&gt;
&lt;br /&gt;
These Trojans are using advanced technologies that help them to spread very fast and hide very well. They are designed to hijack sessions. These Trojans are constantly monitoring major banks’ websites throughout the world. They display a fake page when a user tries to log in to these websites, and in this way continue to steal the private information of their victims.&lt;br /&gt;
&lt;br /&gt;
===Session hijackers===&lt;br /&gt;
&lt;br /&gt;
These attacks can take place either from the malware that is installed on the victim’s computer or remotely. The attacks are triggered when users is trying to log into they account (usually bank accounts) or when they initiate a transaction. The malware then hijack the session for malicious purposes.&lt;br /&gt;
&lt;br /&gt;
===Content-injection phishing===&lt;br /&gt;
&lt;br /&gt;
This phishing refers to the situations when malicious or fake content gets injected into some legitimate Web sites. This content then can deceive the users of the Web site by redirecting them to other Web sites, install malware on their computers, or redirect the input that users is inputting to that Web site to the phishing server.&lt;br /&gt;
&lt;br /&gt;
===“Universal” man-in-the-middle phishing kit===&lt;br /&gt;
&lt;br /&gt;
There is only little effort required for the attackers to use this method to attack their victims. The attackers use a kit which is called MITM that includes several PHP files that get installed on the phishing server. This server then acts as a medium between the user and the legitimate website that he/she wants to access. These victims receive emails that include a purported link to their known website. Once they click on the link, they’ll be redirected to the phishing server which then will communicate with the original Web site on behalf of the user.&lt;br /&gt;
&lt;br /&gt;
===Search engine phishing===&lt;br /&gt;
&lt;br /&gt;
In this type pf phishing, phishers establish a webpage, and then get it indexed by the search engines to make it searchable. These pages are usually designed to include items and services at very low price to attract visitors to sign up or to enter their confidential information. The phisher then get the hold of the private information of the visitors.&lt;br /&gt;
&lt;br /&gt;
===Spear phishing===&lt;br /&gt;
&lt;br /&gt;
In this approach the phisher targets a particular person or a specific department in a company. The phisher then contacts the person by email and pretends to be from a legitimate department and is a trustworthy staff. The attacker then asks for the username and password with some fake reasons. Once the attacker get those information the can by pass the firewalls and break into the secured network.&lt;br /&gt;
&lt;br /&gt;
==Phishing solutions==&lt;br /&gt;
&lt;br /&gt;
To fight against the phishers, in the first place, the online service users should be educated. Once users know what phishing is and what methods phishers use, less people will fall for their tricks and many of their method then become useless. However some countermeasures have been developed and some of them are explained below.&lt;br /&gt;
&lt;br /&gt;
===Phishing blacklist===&lt;br /&gt;
&lt;br /&gt;
A server that is containing a list of all of the malicious websites and phishing servers should be established and be accessible by the internet browsers. The list should be updated on daily basis due to the lifetime of the phishing servers. The malicious URLs should be reported immediately.&lt;br /&gt;
&lt;br /&gt;
===Bookmarks or history===&lt;br /&gt;
&lt;br /&gt;
Using bookmarks and history to detect the list of the websites that the user uses. Then if a new website is visited randomly by the user that he/she did not visit before, chances are that this website is has malicious purposes. The down side of this method is that the history feature holds a history of the limited and short time.&lt;br /&gt;
&lt;br /&gt;
===Two-way authentication===&lt;br /&gt;
&lt;br /&gt;
In this method once a user signs up for an online service they receive and image in a secure way. Thereafter whenever the user visits the website and enters his/her username the website displays the image to prove its legitimacy. The user then can continue to enter his/her password.&lt;br /&gt;
&lt;br /&gt;
===VeriSign identity protection (VIP)===&lt;br /&gt;
&lt;br /&gt;
VIP has been design to protect the digital identities of the people who use online services. VIP provides number of rules that organizations should comply with if they want use VIP services. The VIP suite then provides a secure way for users to log into their account and transactions to take place.&lt;br /&gt;
&lt;br /&gt;
===Early alarm===&lt;br /&gt;
&lt;br /&gt;
This solution requires sort of add-on tool to be installed on Web browsers. This tool contains several rules and ways to check the authentication of the Web sites. The tool will notify the user if the Web site is legitimate and trusted.&lt;br /&gt;
&lt;br /&gt;
=[[Image:new.gif|New]]Bibliography=&lt;br /&gt;
===Privacy and ethical Issues===&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/xg41104w066612m7/fulltext.pdf Privacy and e-commerce: a consumer-centric perspective] Rhys Smith and Jianhua Shao, ''Electronic Commerce Research'', Volume 7, Number 2 / June, 2007 &lt;br /&gt;
&lt;br /&gt;
[http://www.mcgoverngreene.com/alerts/FA_pdfs/Oct-Nov_2004.pdf Phishers “net” unsuspecting consumers] ''fraud alert''  october/november 2004&lt;br /&gt;
&lt;br /&gt;
[http://delivery.acm.org.www.lib.ncsu.edu:2048/10.1145/1130000/1124861/p581-dhamija.pdf?key1=1124861&amp;amp;key2=4842557121&amp;amp;coll=ACM&amp;amp;dl=ACM&amp;amp;CFID=38796614&amp;amp;CFTOKEN=46500553 Why phishing works] Rachna Dhamija, J. D. Tygar, Marti Hearst&lt;br /&gt;
&lt;br /&gt;
[http://delivery.acm.org.www.lib.ncsu.edu:2048/10.1145/1080000/1073009/p77-dhamija.pdf?key1=1073009&amp;amp;key2=1444557121&amp;amp;coll=ACM&amp;amp;dl=ACM&amp;amp;CFID=38796614&amp;amp;CFTOKEN=46500553 The battle against phishing: Dynamic security skins] Rachna Dhamija,  J. D. Tygar&lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/d284629556533224/fulltext.pdf A Revocation scheme preserving privacy] Łukasz Krzywiecki, Przemysław Kubiak and Mirosław Kutyłowski &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/h62k448875177211/fulltext.pdf Security and privacy as market failures]L. Jean Camp,''Economics of Identity Theft: Avoidance, Causes and Possible Cures'' &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/q808084h875464v5/fulltext.pdf Protection or privacy? Data mining and personal data] David J. Hand&lt;br /&gt;
&lt;br /&gt;
===Protection against phishing attacks===&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/0p748n8766732770/fulltext.pdf Method for evaluating the security risk of a website against phishing attacks] Young-Gab Kim, Sanghyun Cho, Jun-Sub Lee, Min-Soo Lee, In Ho Kim and Sung Hoon Kim &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/307774n374w42854/fulltext.pdf An Intrusion detection system for detecting phishing attacks] Hasika Pamunuwa, Duminda Wijesekera and Csilla Farkas &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/50hln6j1b04ftbw1/fulltext.pdf Protection mechanisms against phishing attacks] Klaus Plössl, Hannes Federrath and Thomas Nowey &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/w833450106412039/fulltext.pdf On the effectiveness of techniques to detect phishing sites] Christian Ludl, Sean McAllister, Engin Kirda and Christopher Kruegel &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/bq4mj20enhm3ep0x/fulltext.pdf Effective protection against phishing and web spoofing] Rolf Oppliger and Sebastian Gajek &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/w81x1n840w231177/fulltext.pdf Usability evaluation of anti-phishing toolbars] Linfeng Li and Marko Helenius&lt;br /&gt;
&lt;br /&gt;
===Others===&lt;br /&gt;
[http://pg-server.csc.ncsu.edu/mediawiki/index.php/CSC_379_SUM2008:Topics#Phishing Topic Page]&lt;/div&gt;</summary>
		<author><name>Mbastan</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16788</id>
		<title>Phishing</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16788"/>
		<updated>2008-08-05T01:25:01Z</updated>

		<summary type="html">&lt;p&gt;Mbastan: /* Privacy and ethical Issues */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=[[Image:new.gif|New]]Study Guide=&lt;br /&gt;
==Why is phishing unethical?==&lt;br /&gt;
Phishing in computing is the process of acquiring private and sensitive information by pretending to be a trustworthy or a legitimate website through the online communications. Phishing is an example of fraudulent use of social engineering techniques to deceive an online service user. In this article some of the known attacks will be discussed following with some solutions to guard against these attacks.&lt;br /&gt;
&lt;br /&gt;
==Phishing attacks==&lt;br /&gt;
&lt;br /&gt;
As the technology advances and anti malware applications become more efficient, phishing attacks adopt new forms to stay away from detection. First different forms of attack will be discussed and then some of the solutions that one may prevent these attacks with will be presented. &lt;br /&gt;
&lt;br /&gt;
====Keyloggers====&lt;br /&gt;
&lt;br /&gt;
These are spywares that can get installed either into a web browser or as a device driver. They record the user’s input to the computer by recording the keyboard keystrokes or mouse click. This information will be then sent to the spyware owner. These spywares can cause severe data leak.&lt;br /&gt;
&lt;br /&gt;
===Torpig-family Trojan===&lt;br /&gt;
&lt;br /&gt;
These Trojans are using advanced technologies that help them to spread very fast and hide very well. They are designed to hijack sessions. These Trojans are constantly monitoring major banks’ websites throughout the world. They display a fake page when a user tries to log in to these websites, and in this way continue to steal the private information of their victims.&lt;br /&gt;
&lt;br /&gt;
===Session hijackers===&lt;br /&gt;
&lt;br /&gt;
These attacks can take place either from the malware that is installed on the victim’s computer or remotely. The attacks are triggered when users is trying to log into they account (usually bank accounts) or when they initiate a transaction. The malware then hijack the session for malicious purposes.&lt;br /&gt;
&lt;br /&gt;
===Content-injection phishing===&lt;br /&gt;
&lt;br /&gt;
This phishing refers to the situations when malicious or fake content gets injected into some legitimate Web sites. This content then can deceive the users of the Web site by redirecting them to other Web sites, install malware on their computers, or redirect the input that users is inputting to that Web site to the phishing server.&lt;br /&gt;
&lt;br /&gt;
===“Universal” man-in-the-middle phishing kit===&lt;br /&gt;
&lt;br /&gt;
There is only little effort required for the attackers to use this method to attack their victims. The attackers use a kit which is called MITM that includes several PHP files that get installed on the phishing server. This server then acts as a medium between the user and the legitimate website that he/she wants to access. These victims receive emails that include a purported link to their known website. Once they click on the link, they’ll be redirected to the phishing server which then will communicate with the original Web site on behalf of the user.&lt;br /&gt;
&lt;br /&gt;
===Search engine phishing===&lt;br /&gt;
&lt;br /&gt;
In this type pf phishing, phishers establish a webpage, and then get it indexed by the search engines to make it searchable. These pages are usually designed to include items and services at very low price to attract visitors to sign up or to enter their confidential information. The phisher then get the hold of the private information of the visitors.&lt;br /&gt;
&lt;br /&gt;
===Spear phishing===&lt;br /&gt;
&lt;br /&gt;
In this approach the phisher targets a particular person or a specific department in a company. The phisher then contacts the person by email and pretends to be from a legitimate department and is a trustworthy staff. The attacker then asks for the username and password with some fake reasons. Once the attacker get those information the can by pass the firewalls and break into the secured network.&lt;br /&gt;
&lt;br /&gt;
==Phishing solutions==&lt;br /&gt;
&lt;br /&gt;
To fight against the phishers, in the first place, the online service users should be educated. Once users know what phishing is and what methods phishers use, less people will fall for their tricks and many of their method then become useless. However some countermeasures have been developed and some of them are explained below.&lt;br /&gt;
&lt;br /&gt;
===Phishing blacklist===&lt;br /&gt;
&lt;br /&gt;
A server that is containing a list of all of the malicious websites and phishing servers should be established and be accessible by the internet browsers. The list should be updated on daily basis due to the lifetime of the phishing servers. The malicious URLs should be reported immediately.&lt;br /&gt;
&lt;br /&gt;
===Bookmarks or history===&lt;br /&gt;
&lt;br /&gt;
Using bookmarks and history to detect the list of the websites that the user uses. Then if a new website is visited randomly by the user that he/she did not visit before, chances are that this website is has malicious purposes. The down side of this method is that the history feature holds a history of the limited and short time.&lt;br /&gt;
&lt;br /&gt;
===Two-way authentication===&lt;br /&gt;
&lt;br /&gt;
In this method once a user signs up for an online service they receive and image in a secure way. Thereafter whenever the user visits the website and enters his/her username the website displays the image to prove its legitimacy. The user then can continue to enter his/her password.&lt;br /&gt;
&lt;br /&gt;
===VeriSign identity protection (VIP)===&lt;br /&gt;
&lt;br /&gt;
VIP has been design to protect the digital identities of the people who use online services. VIP provides number of rules that organizations should comply with if they want use VIP services. The VIP suite then provides a secure way for users to log into their account and transactions to take place.&lt;br /&gt;
&lt;br /&gt;
===Early alarm===&lt;br /&gt;
&lt;br /&gt;
This solution requires sort of add-on tool to be installed on Web browsers. This tool contains several rules and ways to check the authentication of the Web sites. The tool will notify the user if the Web site is legitimate and trusted.&lt;br /&gt;
&lt;br /&gt;
=[[Image:new.gif|New]]Bibliography=&lt;br /&gt;
===Privacy and ethical Issues===&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/xg41104w066612m7/fulltext.pdf Privacy and e-commerce: a consumer-centric perspective] Rhys Smith and Jianhua Shao, ''Electronic Commerce Research'', Volume 7, Number 2 / June, 2007 &lt;br /&gt;
&lt;br /&gt;
[http://www.mcgoverngreene.com/alerts/FA_pdfs/Oct-Nov_2004.pdf Phishers “net” unsuspecting consumers] ''fraud alert''  october/november 2004&lt;br /&gt;
&lt;br /&gt;
[http://delivery.acm.org.www.lib.ncsu.edu:2048/10.1145/1130000/1124861/p581-dhamija.pdf?key1=1124861&amp;amp;key2=4842557121&amp;amp;coll=ACM&amp;amp;dl=ACM&amp;amp;CFID=38796614&amp;amp;CFTOKEN=46500553 Why phishing works] Rachna Dhamija, J. D. Tygar, Marti Hearst&lt;br /&gt;
&lt;br /&gt;
[http://delivery.acm.org.www.lib.ncsu.edu:2048/10.1145/1080000/1073009/p77-dhamija.pdf?key1=1073009&amp;amp;key2=1444557121&amp;amp;coll=ACM&amp;amp;dl=ACM&amp;amp;CFID=38796614&amp;amp;CFTOKEN=46500553 The battle against phishing: Dynamic security skins] Rachna Dhamija,  J. D. Tygar&lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/d284629556533224/fulltext.pdf A Revocation scheme preserving privacy] Łukasz Krzywiecki, Przemysław Kubiak and Mirosław Kutyłowski &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/h62k448875177211/fulltext.pdf Security and privacy as market failures]L. Jean Camp,''Economics of Identity Theft: Avoidance, Causes and Possible Cures'' &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/q808084h875464v5/fulltext.pdf Protection or privacy? Data mining and personal data] David J. Hand&lt;br /&gt;
&lt;br /&gt;
===Protection against phishing attacks===&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/0p748n8766732770/fulltext.pdf Method for Evaluating the Security Risk of a Website Against Phishing Attacks] Young-Gab Kim, Sanghyun Cho, Jun-Sub Lee, Min-Soo Lee, In Ho Kim and Sung Hoon Kim &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/307774n374w42854/fulltext.pdf An Intrusion Detection System for Detecting Phishing Attacks] Hasika Pamunuwa, Duminda Wijesekera and Csilla Farkas &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/50hln6j1b04ftbw1/fulltext.pdf Protection Mechanisms Against Phishing Attacks] Klaus Plössl, Hannes Federrath and Thomas Nowey &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/w833450106412039/fulltext.pdf On the Effectiveness of Techniques to Detect Phishing Sites] Christian Ludl, Sean McAllister, Engin Kirda and Christopher Kruegel &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/bq4mj20enhm3ep0x/fulltext.pdf Effective Protection Against Phishing and Web Spoofing] Rolf Oppliger and Sebastian Gajek &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/w81x1n840w231177/fulltext.pdf Usability evaluation of anti-phishing toolbars] Linfeng Li and Marko Helenius&lt;br /&gt;
&lt;br /&gt;
===Others===&lt;br /&gt;
[http://pg-server.csc.ncsu.edu/mediawiki/index.php/CSC_379_SUM2008:Topics#Phishing Topic Page]&lt;/div&gt;</summary>
		<author><name>Mbastan</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16774</id>
		<title>Phishing</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16774"/>
		<updated>2008-08-05T00:41:44Z</updated>

		<summary type="html">&lt;p&gt;Mbastan: /* Phishing attacks */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=[[Image:new.gif|New]]Study Guide=&lt;br /&gt;
==Why is phishing unethical?==&lt;br /&gt;
Phishing in computing is the process of acquiring private and sensitive information by pretending to be a trustworthy or a legitimate website through the online communications. Phishing is an example of fraudulent use of social engineering techniques to deceive an online service user. In this article some of the known attacks will be discussed following with some solutions to guard against these attacks.&lt;br /&gt;
&lt;br /&gt;
==Phishing attacks==&lt;br /&gt;
&lt;br /&gt;
As the technology advances and anti malware applications become more efficient, phishing attacks adopt new forms to stay away from detection. First different forms of attack will be discussed and then some of the solutions that one may prevent these attacks with will be presented. &lt;br /&gt;
&lt;br /&gt;
====Keyloggers====&lt;br /&gt;
&lt;br /&gt;
These are spywares that can get installed either into a web browser or as a device driver. They record the user’s input to the computer by recording the keyboard keystrokes or mouse click. This information will be then sent to the spyware owner. These spywares can cause severe data leak.&lt;br /&gt;
&lt;br /&gt;
===Torpig-family Trojan===&lt;br /&gt;
&lt;br /&gt;
These Trojans are using advanced technologies that help them to spread very fast and hide very well. They are designed to hijack sessions. These Trojans are constantly monitoring major banks’ websites throughout the world. They display a fake page when a user tries to log in to these websites, and in this way continue to steal the private information of their victims.&lt;br /&gt;
&lt;br /&gt;
===Session hijackers===&lt;br /&gt;
&lt;br /&gt;
These attacks can take place either from the malware that is installed on the victim’s computer or remotely. The attacks are triggered when users is trying to log into they account (usually bank accounts) or when they initiate a transaction. The malware then hijack the session for malicious purposes.&lt;br /&gt;
&lt;br /&gt;
===Content-injection phishing===&lt;br /&gt;
&lt;br /&gt;
This phishing refers to the situations when malicious or fake content gets injected into some legitimate Web sites. This content then can deceive the users of the Web site by redirecting them to other Web sites, install malware on their computers, or redirect the input that users is inputting to that Web site to the phishing server.&lt;br /&gt;
&lt;br /&gt;
===“Universal” man-in-the-middle phishing kit===&lt;br /&gt;
&lt;br /&gt;
There is only little effort required for the attackers to use this method to attack their victims. The attackers use a kit which is called MITM that includes several PHP files that get installed on the phishing server. This server then acts as a medium between the user and the legitimate website that he/she wants to access. These victims receive emails that include a purported link to their known website. Once they click on the link, they’ll be redirected to the phishing server which then will communicate with the original Web site on behalf of the user.&lt;br /&gt;
&lt;br /&gt;
===Search engine phishing===&lt;br /&gt;
&lt;br /&gt;
In this type pf phishing, phishers establish a webpage, and then get it indexed by the search engines to make it searchable. These pages are usually designed to include items and services at very low price to attract visitors to sign up or to enter their confidential information. The phisher then get the hold of the private information of the visitors.&lt;br /&gt;
&lt;br /&gt;
===Spear phishing===&lt;br /&gt;
&lt;br /&gt;
In this approach the phisher targets a particular person or a specific department in a company. The phisher then contacts the person by email and pretends to be from a legitimate department and is a trustworthy staff. The attacker then asks for the username and password with some fake reasons. Once the attacker get those information the can by pass the firewalls and break into the secured network.&lt;br /&gt;
&lt;br /&gt;
==Phishing solutions==&lt;br /&gt;
&lt;br /&gt;
To fight against the phishers, in the first place, the online service users should be educated. Once users know what phishing is and what methods phishers use, less people will fall for their tricks and many of their method then become useless. However some countermeasures have been developed and some of them are explained below.&lt;br /&gt;
&lt;br /&gt;
===Phishing blacklist===&lt;br /&gt;
&lt;br /&gt;
A server that is containing a list of all of the malicious websites and phishing servers should be established and be accessible by the internet browsers. The list should be updated on daily basis due to the lifetime of the phishing servers. The malicious URLs should be reported immediately.&lt;br /&gt;
&lt;br /&gt;
===Bookmarks or history===&lt;br /&gt;
&lt;br /&gt;
Using bookmarks and history to detect the list of the websites that the user uses. Then if a new website is visited randomly by the user that he/she did not visit before, chances are that this website is has malicious purposes. The down side of this method is that the history feature holds a history of the limited and short time.&lt;br /&gt;
&lt;br /&gt;
===Two-way authentication===&lt;br /&gt;
&lt;br /&gt;
In this method once a user signs up for an online service they receive and image in a secure way. Thereafter whenever the user visits the website and enters his/her username the website displays the image to prove its legitimacy. The user then can continue to enter his/her password.&lt;br /&gt;
&lt;br /&gt;
===VeriSign identity protection (VIP)===&lt;br /&gt;
&lt;br /&gt;
VIP has been design to protect the digital identities of the people who use online services. VIP provides number of rules that organizations should comply with if they want use VIP services. The VIP suite then provides a secure way for users to log into their account and transactions to take place.&lt;br /&gt;
&lt;br /&gt;
===Early alarm===&lt;br /&gt;
&lt;br /&gt;
This solution requires sort of add-on tool to be installed on Web browsers. This tool contains several rules and ways to check the authentication of the Web sites. The tool will notify the user if the Web site is legitimate and trusted.&lt;br /&gt;
&lt;br /&gt;
=[[Image:new.gif|New]]Bibliography=&lt;br /&gt;
===Privacy and ethical Issues===&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/xg41104w066612m7/fulltext.pdf Privacy and e-commerce: a consumer-centric perspective] Rhys Smith and Jianhua Shao, ''Electronic Commerce Research'', Volume 7, Number 2 / June, 2007 &lt;br /&gt;
&lt;br /&gt;
[http://www.mcgoverngreene.com/alerts/FA_pdfs/Oct-Nov_2004.pdf Phishers “net” unsuspecting consumers] ''fraud alert''  october/november 2004&lt;br /&gt;
&lt;br /&gt;
[http://delivery.acm.org.www.lib.ncsu.edu:2048/10.1145/1130000/1124861/p581-dhamija.pdf?key1=1124861&amp;amp;key2=4842557121&amp;amp;coll=ACM&amp;amp;dl=ACM&amp;amp;CFID=38796614&amp;amp;CFTOKEN=46500553 Why phishing works] Rachna Dhamija, J. D. Tygar, Marti Hearst&lt;br /&gt;
&lt;br /&gt;
[http://delivery.acm.org.www.lib.ncsu.edu:2048/10.1145/1080000/1073009/p77-dhamija.pdf?key1=1073009&amp;amp;key2=1444557121&amp;amp;coll=ACM&amp;amp;dl=ACM&amp;amp;CFID=38796614&amp;amp;CFTOKEN=46500553 The Battle Against Phishing: Dynamic Security Skins] Rachna Dhamija,  J. D. Tygar&lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/d284629556533224/fulltext.pdf A Revocation Scheme Preserving Privacy] Łukasz Krzywiecki, Przemysław Kubiak and Mirosław Kutyłowski &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/h62k448875177211/fulltext.pdf Security and Privacy as Market Failures]L. Jean Camp,''Economics of Identity Theft: Avoidance, Causes and Possible Cures'' &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/q808084h875464v5/fulltext.pdf Protection or Privacy? Data Mining and Personal Data] David J. Hand&lt;br /&gt;
&lt;br /&gt;
===Protection against phishing attacks===&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/0p748n8766732770/fulltext.pdf Method for Evaluating the Security Risk of a Website Against Phishing Attacks] Young-Gab Kim, Sanghyun Cho, Jun-Sub Lee, Min-Soo Lee, In Ho Kim and Sung Hoon Kim &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/307774n374w42854/fulltext.pdf An Intrusion Detection System for Detecting Phishing Attacks] Hasika Pamunuwa, Duminda Wijesekera and Csilla Farkas &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/50hln6j1b04ftbw1/fulltext.pdf Protection Mechanisms Against Phishing Attacks] Klaus Plössl, Hannes Federrath and Thomas Nowey &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/w833450106412039/fulltext.pdf On the Effectiveness of Techniques to Detect Phishing Sites] Christian Ludl, Sean McAllister, Engin Kirda and Christopher Kruegel &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/bq4mj20enhm3ep0x/fulltext.pdf Effective Protection Against Phishing and Web Spoofing] Rolf Oppliger and Sebastian Gajek &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/w81x1n840w231177/fulltext.pdf Usability evaluation of anti-phishing toolbars] Linfeng Li and Marko Helenius&lt;br /&gt;
&lt;br /&gt;
===Others===&lt;br /&gt;
[http://pg-server.csc.ncsu.edu/mediawiki/index.php/CSC_379_SUM2008:Topics#Phishing Topic Page]&lt;/div&gt;</summary>
		<author><name>Mbastan</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16773</id>
		<title>Phishing</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16773"/>
		<updated>2008-08-05T00:30:57Z</updated>

		<summary type="html">&lt;p&gt;Mbastan: /* NewStudy Guide */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=[[Image:new.gif|New]]Study Guide=&lt;br /&gt;
==Why is phishing unethical?==&lt;br /&gt;
Phishing in computing is the process of acquiring private and sensitive information by pretending to be a trustworthy or a legitimate website through the online communications. Phishing is an example of fraudulent use of social engineering techniques to deceive an online service user. In this article some of the known attacks will be discussed following with some solutions to guard against these attacks.&lt;br /&gt;
&lt;br /&gt;
==Phishing attacks==&lt;br /&gt;
&lt;br /&gt;
The following are some of the way that the phishing attacks are taking place.&lt;br /&gt;
&lt;br /&gt;
====Keyloggers====&lt;br /&gt;
&lt;br /&gt;
These are spywares that can get installed either into a web browser or as a device driver. They record the user’s input to the computer by recording the keyboard keystrokes or mouse click. This information will be then sent to the spyware owner. These spywares can cause severe data leak.&lt;br /&gt;
&lt;br /&gt;
===Torpig-family Trojan===&lt;br /&gt;
&lt;br /&gt;
These Trojans are using advanced technologies that help them to spread very fast and hide very well. They are designed to hijack sessions. These Trojans are constantly monitoring major banks’ websites throughout the world. They display a fake page when a user tries to log in to these websites, and in this way continue to steal the private information of their victims.&lt;br /&gt;
&lt;br /&gt;
===Session hijackers===&lt;br /&gt;
&lt;br /&gt;
These attacks can take place either from the malware that is installed on the victim’s computer or remotely. The attacks are triggered when users is trying to log into they account (usually bank accounts) or when they initiate a transaction. The malware then hijack the session for malicious purposes.&lt;br /&gt;
&lt;br /&gt;
===Content-injection phishing===&lt;br /&gt;
&lt;br /&gt;
This phishing refers to the situations when malicious or fake content gets injected into some legitimate Web sites. This content then can deceive the users of the Web site by redirecting them to other Web sites, install malware on their computers, or redirect the input that users is inputting to that Web site to the phishing server.&lt;br /&gt;
&lt;br /&gt;
===“Universal” man-in-the-middle phishing kit===&lt;br /&gt;
&lt;br /&gt;
There is only little effort required for the attackers to use this method to attack their victims. The attackers use a kit which is called MITM that includes several PHP files that get installed on the phishing server. This server then acts as a medium between the user and the legitimate website that he/she wants to access. These victims receive emails that include a purported link to their known website. Once they click on the link, they’ll be redirected to the phishing server which then will communicate with the original Web site on behalf of the user.&lt;br /&gt;
&lt;br /&gt;
===Search engine phishing===&lt;br /&gt;
&lt;br /&gt;
In this type pf phishing, phishers establish a webpage, and then get it indexed by the search engines to make it searchable. These pages are usually designed to include items and services at very low price to attract visitors to sign up or to enter their confidential information. The phisher then get the hold of the private information of the visitors.&lt;br /&gt;
&lt;br /&gt;
===Spear phishing===&lt;br /&gt;
&lt;br /&gt;
In this approach the phisher targets a particular person or a specific department in a company. The phisher then contacts the person by email and pretends to be from a legitimate department and is a trustworthy staff. The attacker then asks for the username and password with some fake reasons. Once the attacker get those information the can by pass the firewalls and break into the secured network.&lt;br /&gt;
&lt;br /&gt;
==Phishing solutions==&lt;br /&gt;
&lt;br /&gt;
To fight against the phishers, in the first place, the online service users should be educated. Once users know what phishing is and what methods phishers use, less people will fall for their tricks and many of their method then become useless. However some countermeasures have been developed and some of them are explained below.&lt;br /&gt;
&lt;br /&gt;
===Phishing blacklist===&lt;br /&gt;
&lt;br /&gt;
A server that is containing a list of all of the malicious websites and phishing servers should be established and be accessible by the internet browsers. The list should be updated on daily basis due to the lifetime of the phishing servers. The malicious URLs should be reported immediately.&lt;br /&gt;
&lt;br /&gt;
===Bookmarks or history===&lt;br /&gt;
&lt;br /&gt;
Using bookmarks and history to detect the list of the websites that the user uses. Then if a new website is visited randomly by the user that he/she did not visit before, chances are that this website is has malicious purposes. The down side of this method is that the history feature holds a history of the limited and short time.&lt;br /&gt;
&lt;br /&gt;
===Two-way authentication===&lt;br /&gt;
&lt;br /&gt;
In this method once a user signs up for an online service they receive and image in a secure way. Thereafter whenever the user visits the website and enters his/her username the website displays the image to prove its legitimacy. The user then can continue to enter his/her password.&lt;br /&gt;
&lt;br /&gt;
===VeriSign identity protection (VIP)===&lt;br /&gt;
&lt;br /&gt;
VIP has been design to protect the digital identities of the people who use online services. VIP provides number of rules that organizations should comply with if they want use VIP services. The VIP suite then provides a secure way for users to log into their account and transactions to take place.&lt;br /&gt;
&lt;br /&gt;
===Early alarm===&lt;br /&gt;
&lt;br /&gt;
This solution requires sort of add-on tool to be installed on Web browsers. This tool contains several rules and ways to check the authentication of the Web sites. The tool will notify the user if the Web site is legitimate and trusted.&lt;br /&gt;
&lt;br /&gt;
=[[Image:new.gif|New]]Bibliography=&lt;br /&gt;
===Privacy and ethical Issues===&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/xg41104w066612m7/fulltext.pdf Privacy and e-commerce: a consumer-centric perspective] Rhys Smith and Jianhua Shao, ''Electronic Commerce Research'', Volume 7, Number 2 / June, 2007 &lt;br /&gt;
&lt;br /&gt;
[http://www.mcgoverngreene.com/alerts/FA_pdfs/Oct-Nov_2004.pdf Phishers “net” unsuspecting consumers] ''fraud alert''  october/november 2004&lt;br /&gt;
&lt;br /&gt;
[http://delivery.acm.org.www.lib.ncsu.edu:2048/10.1145/1130000/1124861/p581-dhamija.pdf?key1=1124861&amp;amp;key2=4842557121&amp;amp;coll=ACM&amp;amp;dl=ACM&amp;amp;CFID=38796614&amp;amp;CFTOKEN=46500553 Why phishing works] Rachna Dhamija, J. D. Tygar, Marti Hearst&lt;br /&gt;
&lt;br /&gt;
[http://delivery.acm.org.www.lib.ncsu.edu:2048/10.1145/1080000/1073009/p77-dhamija.pdf?key1=1073009&amp;amp;key2=1444557121&amp;amp;coll=ACM&amp;amp;dl=ACM&amp;amp;CFID=38796614&amp;amp;CFTOKEN=46500553 The Battle Against Phishing: Dynamic Security Skins] Rachna Dhamija,  J. D. Tygar&lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/d284629556533224/fulltext.pdf A Revocation Scheme Preserving Privacy] Łukasz Krzywiecki, Przemysław Kubiak and Mirosław Kutyłowski &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/h62k448875177211/fulltext.pdf Security and Privacy as Market Failures]L. Jean Camp,''Economics of Identity Theft: Avoidance, Causes and Possible Cures'' &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/q808084h875464v5/fulltext.pdf Protection or Privacy? Data Mining and Personal Data] David J. Hand&lt;br /&gt;
&lt;br /&gt;
===Protection against phishing attacks===&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/0p748n8766732770/fulltext.pdf Method for Evaluating the Security Risk of a Website Against Phishing Attacks] Young-Gab Kim, Sanghyun Cho, Jun-Sub Lee, Min-Soo Lee, In Ho Kim and Sung Hoon Kim &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/307774n374w42854/fulltext.pdf An Intrusion Detection System for Detecting Phishing Attacks] Hasika Pamunuwa, Duminda Wijesekera and Csilla Farkas &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/50hln6j1b04ftbw1/fulltext.pdf Protection Mechanisms Against Phishing Attacks] Klaus Plössl, Hannes Federrath and Thomas Nowey &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/w833450106412039/fulltext.pdf On the Effectiveness of Techniques to Detect Phishing Sites] Christian Ludl, Sean McAllister, Engin Kirda and Christopher Kruegel &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/bq4mj20enhm3ep0x/fulltext.pdf Effective Protection Against Phishing and Web Spoofing] Rolf Oppliger and Sebastian Gajek &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/w81x1n840w231177/fulltext.pdf Usability evaluation of anti-phishing toolbars] Linfeng Li and Marko Helenius&lt;br /&gt;
&lt;br /&gt;
===Others===&lt;br /&gt;
[http://pg-server.csc.ncsu.edu/mediawiki/index.php/CSC_379_SUM2008:Topics#Phishing Topic Page]&lt;/div&gt;</summary>
		<author><name>Mbastan</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16772</id>
		<title>Phishing</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16772"/>
		<updated>2008-08-05T00:29:06Z</updated>

		<summary type="html">&lt;p&gt;Mbastan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=[[Image:new.gif|New]]Study Guide=&lt;br /&gt;
&lt;br /&gt;
Phishing in computing is the process of acquiring private and sensitive information by pretending to be a trustworthy or a legitimate website through the online communications. Phishing is an example of fraudulent use of social engineering techniques to deceive an online service user. In this article some of the known attacks will be discussed following with some solutions to guard against these attacks.&lt;br /&gt;
&lt;br /&gt;
==Phishing attacks==&lt;br /&gt;
&lt;br /&gt;
The following are some of the way that the phishing attacks are taking place.&lt;br /&gt;
&lt;br /&gt;
====Keyloggers====&lt;br /&gt;
&lt;br /&gt;
These are spywares that can get installed either into a web browser or as a device driver. They record the user’s input to the computer by recording the keyboard keystrokes or mouse click. This information will be then sent to the spyware owner. These spywares can cause severe data leak.&lt;br /&gt;
&lt;br /&gt;
===Torpig-family Trojan===&lt;br /&gt;
&lt;br /&gt;
These Trojans are using advanced technologies that help them to spread very fast and hide very well. They are designed to hijack sessions. These Trojans are constantly monitoring major banks’ websites throughout the world. They display a fake page when a user tries to log in to these websites, and in this way continue to steal the private information of their victims.&lt;br /&gt;
&lt;br /&gt;
===Session hijackers===&lt;br /&gt;
&lt;br /&gt;
These attacks can take place either from the malware that is installed on the victim’s computer or remotely. The attacks are triggered when users is trying to log into they account (usually bank accounts) or when they initiate a transaction. The malware then hijack the session for malicious purposes.&lt;br /&gt;
&lt;br /&gt;
===Content-injection phishing===&lt;br /&gt;
&lt;br /&gt;
This phishing refers to the situations when malicious or fake content gets injected into some legitimate Web sites. This content then can deceive the users of the Web site by redirecting them to other Web sites, install malware on their computers, or redirect the input that users is inputting to that Web site to the phishing server.&lt;br /&gt;
&lt;br /&gt;
===“Universal” man-in-the-middle phishing kit===&lt;br /&gt;
&lt;br /&gt;
There is only little effort required for the attackers to use this method to attack their victims. The attackers use a kit which is called MITM that includes several PHP files that get installed on the phishing server. This server then acts as a medium between the user and the legitimate website that he/she wants to access. These victims receive emails that include a purported link to their known website. Once they click on the link, they’ll be redirected to the phishing server which then will communicate with the original Web site on behalf of the user.&lt;br /&gt;
&lt;br /&gt;
===Search engine phishing===&lt;br /&gt;
&lt;br /&gt;
In this type pf phishing, phishers establish a webpage, and then get it indexed by the search engines to make it searchable. These pages are usually designed to include items and services at very low price to attract visitors to sign up or to enter their confidential information. The phisher then get the hold of the private information of the visitors.&lt;br /&gt;
&lt;br /&gt;
===Spear phishing===&lt;br /&gt;
&lt;br /&gt;
In this approach the phisher targets a particular person or a specific department in a company. The phisher then contacts the person by email and pretends to be from a legitimate department and is a trustworthy staff. The attacker then asks for the username and password with some fake reasons. Once the attacker get those information the can by pass the firewalls and break into the secured network.&lt;br /&gt;
&lt;br /&gt;
==Phishing solutions==&lt;br /&gt;
&lt;br /&gt;
To fight against the phishers, in the first place, the online service users should be educated. Once users know what phishing is and what methods phishers use, less people will fall for their tricks and many of their method then become useless. However some countermeasures have been developed and some of them are explained below.&lt;br /&gt;
&lt;br /&gt;
===Phishing blacklist===&lt;br /&gt;
&lt;br /&gt;
A server that is containing a list of all of the malicious websites and phishing servers should be established and be accessible by the internet browsers. The list should be updated on daily basis due to the lifetime of the phishing servers. The malicious URLs should be reported immediately.&lt;br /&gt;
&lt;br /&gt;
===Bookmarks or history===&lt;br /&gt;
&lt;br /&gt;
Using bookmarks and history to detect the list of the websites that the user uses. Then if a new website is visited randomly by the user that he/she did not visit before, chances are that this website is has malicious purposes. The down side of this method is that the history feature holds a history of the limited and short time.&lt;br /&gt;
&lt;br /&gt;
===Two-way authentication===&lt;br /&gt;
&lt;br /&gt;
In this method once a user signs up for an online service they receive and image in a secure way. Thereafter whenever the user visits the website and enters his/her username the website displays the image to prove its legitimacy. The user then can continue to enter his/her password.&lt;br /&gt;
&lt;br /&gt;
===VeriSign identity protection (VIP)===&lt;br /&gt;
&lt;br /&gt;
VIP has been design to protect the digital identities of the people who use online services. VIP provides number of rules that organizations should comply with if they want use VIP services. The VIP suite then provides a secure way for users to log into their account and transactions to take place.&lt;br /&gt;
&lt;br /&gt;
===Early alarm===&lt;br /&gt;
&lt;br /&gt;
This solution requires sort of add-on tool to be installed on Web browsers. This tool contains several rules and ways to check the authentication of the Web sites. The tool will notify the user if the Web site is legitimate and trusted.&lt;br /&gt;
&lt;br /&gt;
=[[Image:new.gif|New]]Bibliography=&lt;br /&gt;
===Privacy and ethical Issues===&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/xg41104w066612m7/fulltext.pdf Privacy and e-commerce: a consumer-centric perspective] Rhys Smith and Jianhua Shao, ''Electronic Commerce Research'', Volume 7, Number 2 / June, 2007 &lt;br /&gt;
&lt;br /&gt;
[http://www.mcgoverngreene.com/alerts/FA_pdfs/Oct-Nov_2004.pdf Phishers “net” unsuspecting consumers] ''fraud alert''  october/november 2004&lt;br /&gt;
&lt;br /&gt;
[http://delivery.acm.org.www.lib.ncsu.edu:2048/10.1145/1130000/1124861/p581-dhamija.pdf?key1=1124861&amp;amp;key2=4842557121&amp;amp;coll=ACM&amp;amp;dl=ACM&amp;amp;CFID=38796614&amp;amp;CFTOKEN=46500553 Why phishing works] Rachna Dhamija, J. D. Tygar, Marti Hearst&lt;br /&gt;
&lt;br /&gt;
[http://delivery.acm.org.www.lib.ncsu.edu:2048/10.1145/1080000/1073009/p77-dhamija.pdf?key1=1073009&amp;amp;key2=1444557121&amp;amp;coll=ACM&amp;amp;dl=ACM&amp;amp;CFID=38796614&amp;amp;CFTOKEN=46500553 The Battle Against Phishing: Dynamic Security Skins] Rachna Dhamija,  J. D. Tygar&lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/d284629556533224/fulltext.pdf A Revocation Scheme Preserving Privacy] Łukasz Krzywiecki, Przemysław Kubiak and Mirosław Kutyłowski &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/h62k448875177211/fulltext.pdf Security and Privacy as Market Failures]L. Jean Camp,''Economics of Identity Theft: Avoidance, Causes and Possible Cures'' &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/q808084h875464v5/fulltext.pdf Protection or Privacy? Data Mining and Personal Data] David J. Hand&lt;br /&gt;
&lt;br /&gt;
===Protection against phishing attacks===&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/0p748n8766732770/fulltext.pdf Method for Evaluating the Security Risk of a Website Against Phishing Attacks] Young-Gab Kim, Sanghyun Cho, Jun-Sub Lee, Min-Soo Lee, In Ho Kim and Sung Hoon Kim &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/307774n374w42854/fulltext.pdf An Intrusion Detection System for Detecting Phishing Attacks] Hasika Pamunuwa, Duminda Wijesekera and Csilla Farkas &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/50hln6j1b04ftbw1/fulltext.pdf Protection Mechanisms Against Phishing Attacks] Klaus Plössl, Hannes Federrath and Thomas Nowey &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/w833450106412039/fulltext.pdf On the Effectiveness of Techniques to Detect Phishing Sites] Christian Ludl, Sean McAllister, Engin Kirda and Christopher Kruegel &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/bq4mj20enhm3ep0x/fulltext.pdf Effective Protection Against Phishing and Web Spoofing] Rolf Oppliger and Sebastian Gajek &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/w81x1n840w231177/fulltext.pdf Usability evaluation of anti-phishing toolbars] Linfeng Li and Marko Helenius&lt;br /&gt;
&lt;br /&gt;
===Others===&lt;br /&gt;
[http://pg-server.csc.ncsu.edu/mediawiki/index.php/CSC_379_SUM2008:Topics#Phishing Topic Page]&lt;/div&gt;</summary>
		<author><name>Mbastan</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16769</id>
		<title>Phishing</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16769"/>
		<updated>2008-08-05T00:05:14Z</updated>

		<summary type="html">&lt;p&gt;Mbastan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=[[Image:new.gif|New]]Study Guide=&lt;br /&gt;
&lt;br /&gt;
Phishing in computing is the process of acquiring private and sensitive information by pretending to be a trustworthy or a legitimate website through the online communications. Phishing is an example of fraudulent use of social engineering techniques to deceive an online service user. In this article some of the known attacks will be discussed following with some solutions to guard against these attacks.&lt;br /&gt;
&lt;br /&gt;
==Phishing attacks==&lt;br /&gt;
&lt;br /&gt;
The following are some of the way that the phishing attacks are taking place.&lt;br /&gt;
&lt;br /&gt;
====Keyloggers====&lt;br /&gt;
&lt;br /&gt;
These are spywares that can get installed either into a web browser or as a device driver. They record the user’s input to the computer by recording the keyboard keystrokes or mouse click. This information will be then sent to the spyware owner. These spywares can cause severe data leak.&lt;br /&gt;
&lt;br /&gt;
===Torpig-Family Trojan===&lt;br /&gt;
&lt;br /&gt;
These Trojans are using advanced technologies that help them to spread very fast and hide very well. They are designed to hijack sessions. These Trojans are constantly monitoring major banks’ websites throughout the world. They display a fake page when a user tries to log in to these websites, and in this way continue to steal the private information of their victims.&lt;br /&gt;
&lt;br /&gt;
===Session hijackers===&lt;br /&gt;
&lt;br /&gt;
These attacks can take place either from the malware that is installed on the victim’s computer or remotely. The attacks are triggered when users is trying to log into they account (usually bank accounts) or when they initiate a transaction. The malware then hijack the session for malicious purposes.&lt;br /&gt;
&lt;br /&gt;
===Content-Injection phishing===&lt;br /&gt;
&lt;br /&gt;
This phishing refers to the situations when malicious or fake content gets injected into some legitimate Web sites. This content then can deceive the users of the Web site by redirecting them to other Web sites, install malware on their computers, or redirect the input that users is inputting to that Web site to the phishing server.&lt;br /&gt;
&lt;br /&gt;
===“Universal” man-in-the-middle phishing kit===&lt;br /&gt;
&lt;br /&gt;
There is only little effort required for the attackers to use this method to attack their victims. The attackers use a kit which is called MITM that includes several PHP files that get installed on the phishing server. This server then acts as a medium between the user and the legitimate website that he/she wants to access. These victims receive emails that include a purported link to their known website. Once they click on the link, they’ll be redirected to the phishing server which then will communicate with the original Web site on behalf of the user.&lt;br /&gt;
&lt;br /&gt;
===Search engine phishing===&lt;br /&gt;
&lt;br /&gt;
In this type pf phishing, phishers establish a webpage, and then get it indexed by the search engines to make it searchable. These pages are usually designed to include items and services at very low price to attract visitors to sign up or to enter their confidential information. The phisher then get the hold of the private information of the visitors.&lt;br /&gt;
&lt;br /&gt;
===Spear phishing===&lt;br /&gt;
&lt;br /&gt;
In this approach the phisher targets a particular person or a specific department in a company. The phisher then contacts the person by email and pretends to be from a legitimate department and is a trustworthy staff. The attacker then asks for the username and password with some fake reasons. Once the attacker get those information the can by pass the firewalls and break into the secured network.&lt;br /&gt;
&lt;br /&gt;
==Phishing solutions==&lt;br /&gt;
&lt;br /&gt;
To fight against the phishers, in the first place, the online service users should be educated. Once users know what phishing is and what methods phishers use, less people will fall for their tricks and many of their method then become useless. However some countermeasures have been developed and some of them are explained below.&lt;br /&gt;
&lt;br /&gt;
===Phishing blacklist===&lt;br /&gt;
&lt;br /&gt;
A server that is containing a list of all of the malicious websites and phishing servers should be established and be accessible by the internet browsers. The list should be updated on daily basis due to the lifetime of the phishing servers. The malicious URLs should be reported immediately.&lt;br /&gt;
&lt;br /&gt;
===Bookmarks or history===&lt;br /&gt;
&lt;br /&gt;
Using bookmarks and history to detect the list of the websites that the user uses. Then if a new website is visited randomly by the user that he/she did not visit before, chances are that this website is has malicious purposes. The down side of this method is that the history feature holds a history of the limited and short time.&lt;br /&gt;
&lt;br /&gt;
===Two-Way authentication===&lt;br /&gt;
&lt;br /&gt;
In this method once a user signs up for an online service they receive and image in a secure way. Thereafter whenever the user visits the website and enters his/her username the website displays the image to prove its legitimacy. The user then can continue to enter his/her password.&lt;br /&gt;
&lt;br /&gt;
===VeriSign Identity Protection (VIP)===&lt;br /&gt;
&lt;br /&gt;
VIP has been design to protect the digital identities of the people who use online services. VIP provides number of rules that organizations should comply with if they want use VIP services. The VIP suite then provides a secure way for users to log into their account and transactions to take place.&lt;br /&gt;
&lt;br /&gt;
===Early alarm===&lt;br /&gt;
&lt;br /&gt;
This solution requires sort of add-on tool to be installed on Web browsers. This tool contains several rules and ways to check the authentication of the Web sites. The tool will notify the user if the Web site is legitimate and trusted.&lt;br /&gt;
&lt;br /&gt;
=[[Image:new.gif|New]]Bibliography=&lt;br /&gt;
===Privacy and ethical Issues===&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/xg41104w066612m7/fulltext.pdf Privacy and e-commerce: a consumer-centric perspective] Rhys Smith and Jianhua Shao, ''Electronic Commerce Research'', Volume 7, Number 2 / June, 2007 &lt;br /&gt;
&lt;br /&gt;
[http://www.mcgoverngreene.com/alerts/FA_pdfs/Oct-Nov_2004.pdf Phishers “net” unsuspecting consumers] ''fraud alert''  october/november 2004&lt;br /&gt;
&lt;br /&gt;
[http://delivery.acm.org.www.lib.ncsu.edu:2048/10.1145/1130000/1124861/p581-dhamija.pdf?key1=1124861&amp;amp;key2=4842557121&amp;amp;coll=ACM&amp;amp;dl=ACM&amp;amp;CFID=38796614&amp;amp;CFTOKEN=46500553 Why phishing works] Rachna Dhamija, J. D. Tygar, Marti Hearst&lt;br /&gt;
&lt;br /&gt;
[http://delivery.acm.org.www.lib.ncsu.edu:2048/10.1145/1080000/1073009/p77-dhamija.pdf?key1=1073009&amp;amp;key2=1444557121&amp;amp;coll=ACM&amp;amp;dl=ACM&amp;amp;CFID=38796614&amp;amp;CFTOKEN=46500553 The Battle Against Phishing: Dynamic Security Skins] Rachna Dhamija,  J. D. Tygar&lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/d284629556533224/fulltext.pdf A Revocation Scheme Preserving Privacy] Łukasz Krzywiecki, Przemysław Kubiak and Mirosław Kutyłowski &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/h62k448875177211/fulltext.pdf Security and Privacy as Market Failures]L. Jean Camp,''Economics of Identity Theft: Avoidance, Causes and Possible Cures'' &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/q808084h875464v5/fulltext.pdf Protection or Privacy? Data Mining and Personal Data] David J. Hand&lt;br /&gt;
&lt;br /&gt;
===Protection against phishing attacks===&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/0p748n8766732770/fulltext.pdf Method for Evaluating the Security Risk of a Website Against Phishing Attacks] Young-Gab Kim, Sanghyun Cho, Jun-Sub Lee, Min-Soo Lee, In Ho Kim and Sung Hoon Kim &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/307774n374w42854/fulltext.pdf An Intrusion Detection System for Detecting Phishing Attacks] Hasika Pamunuwa, Duminda Wijesekera and Csilla Farkas &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/50hln6j1b04ftbw1/fulltext.pdf Protection Mechanisms Against Phishing Attacks] Klaus Plössl, Hannes Federrath and Thomas Nowey &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/w833450106412039/fulltext.pdf On the Effectiveness of Techniques to Detect Phishing Sites] Christian Ludl, Sean McAllister, Engin Kirda and Christopher Kruegel &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/bq4mj20enhm3ep0x/fulltext.pdf Effective Protection Against Phishing and Web Spoofing] Rolf Oppliger and Sebastian Gajek &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/w81x1n840w231177/fulltext.pdf Usability evaluation of anti-phishing toolbars] Linfeng Li and Marko Helenius&lt;br /&gt;
&lt;br /&gt;
===Others===&lt;br /&gt;
[http://pg-server.csc.ncsu.edu/mediawiki/index.php/CSC_379_SUM2008:Topics#Phishing Topic Page]&lt;/div&gt;</summary>
		<author><name>Mbastan</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16768</id>
		<title>Phishing</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16768"/>
		<updated>2008-08-04T23:55:59Z</updated>

		<summary type="html">&lt;p&gt;Mbastan: /* NewStudy Guide */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=[[Image:new.gif|New]]Study Guide=&lt;br /&gt;
&lt;br /&gt;
Phishing in computing is the process of acquiring private and sensitive information by pretending to be a trustworthy or a legitimate website through the online communications. Phishing is an example of fraudulent use of social engineering techniques to deceive an online service user. In this article some of the known attacks will be discussed following with some solutions to guard against these attacks.&lt;br /&gt;
&lt;br /&gt;
==Phishing Attacks==&lt;br /&gt;
&lt;br /&gt;
The following are some of the way that the phishing attacks are taking place.&lt;br /&gt;
&lt;br /&gt;
====Keyloggers====&lt;br /&gt;
&lt;br /&gt;
These are spywares that can get installed either into a web browser or as a device driver. They record the user’s input to the computer by recording the keyboard keystrokes or mouse click. This information will be then sent to the spyware owner. These spywares can cause severe data leak.&lt;br /&gt;
&lt;br /&gt;
===Torpig-Family Trojan===&lt;br /&gt;
&lt;br /&gt;
These Trojans are using advanced technologies that help them to spread very fast and hide very well. They are designed to hijack sessions. These Trojans are constantly monitoring major banks’ websites throughout the world. They display a fake page when a user tries to log in to these websites, and in this way continue to steal the private information of their victims.&lt;br /&gt;
&lt;br /&gt;
===Session Hijackers===&lt;br /&gt;
&lt;br /&gt;
These attacks can take place either from the malware that is installed on the victim’s computer or remotely. The attacks are triggered when users is trying to log into they account (usually bank accounts) or when they initiate a transaction. The malware then hijack the session for malicious purposes.&lt;br /&gt;
&lt;br /&gt;
===Content-Injection Phishing===&lt;br /&gt;
&lt;br /&gt;
This phishing refers to the situations when malicious or fake content gets injected into some legitimate Web sites. This content then can deceive the users of the Web site by redirecting them to other Web sites, install malware on their computers, or redirect the input that users is inputting to that Web site to the phishing server.&lt;br /&gt;
&lt;br /&gt;
===“Universal” Man-in-the-Middle Phishing Kit===&lt;br /&gt;
&lt;br /&gt;
There is only little effort required for the attackers to use this method to attack their victims. The attackers use a kit which is called MITM that includes several PHP files that get installed on the phishing server. This server then acts as a medium between the user and the legitimate website that he/she wants to access. These victims receive emails that include a purported link to their known website. Once they click on the link, they’ll be redirected to the phishing server which then will communicate with the original Web site on behalf of the user.&lt;br /&gt;
&lt;br /&gt;
===Search Engine Phishing===&lt;br /&gt;
&lt;br /&gt;
In this type pf phishing, phishers establish a webpage, and then get it indexed by the search engines to make it searchable. These pages are usually designed to include items and services at very low price to attract visitors to sign up or to enter their confidential information. The phisher then get the hold of the private information of the visitors.&lt;br /&gt;
&lt;br /&gt;
===Spear Phishing===&lt;br /&gt;
&lt;br /&gt;
In this approach the phisher targets a particular person or a specific department in a company. The phisher then contacts the person by email and pretends to be from a legitimate department and is a trustworthy staff. The attacker then asks for the username and password with some fake reasons. Once the attacker get those information the can by pass the firewalls and break into the secured network.&lt;br /&gt;
&lt;br /&gt;
==Phishing solutions==&lt;br /&gt;
&lt;br /&gt;
To fight against the phishers, in the first place, the online service users should be educated. Once users know what phishing is and what methods phishers use, less people will fall for their tricks and many of their method then become useless. However some countermeasures have been developed and some of them are explained below.&lt;br /&gt;
&lt;br /&gt;
===Phishing blacklist===&lt;br /&gt;
&lt;br /&gt;
A server that is containing a list of all of the malicious websites and phishing servers should be established and be accessible by the internet browsers. The list should be updated on daily basis due to the lifetime of the phishing servers. The malicious URLs should be reported immediately.&lt;br /&gt;
&lt;br /&gt;
===Bookmarks or history===&lt;br /&gt;
&lt;br /&gt;
Using bookmarks and history to detect the list of the websites that the user uses. Then if a new website is visited randomly by the user that he/she did not visit before, chances are that this website is has malicious purposes. The down side of this method is that the history feature holds a history of the limited and short time.&lt;br /&gt;
&lt;br /&gt;
===Two-Way Authentication===&lt;br /&gt;
&lt;br /&gt;
In this method once a user signs up for an online service they receive and image in a secure way. Thereafter whenever the user visits the website and enters his/her username the website displays the image to prove its legitimacy. The user then can continue to enter his/her password.&lt;br /&gt;
&lt;br /&gt;
===VeriSign Identity Protection (VIP)===&lt;br /&gt;
&lt;br /&gt;
VIP has been design to protect the digital identities of the people who use online services. VIP provides number of rules that organizations should comply with if they want use VIP services. The VIP suite then provides a secure way for users to log into their account and transactions to take place.&lt;br /&gt;
&lt;br /&gt;
===Early alarm===&lt;br /&gt;
&lt;br /&gt;
This solution requires sort of add-on tool to be installed on Web browsers. This tool contains several rules and ways to check the authentication of the Web sites. The tool will notify the user if the Web site is legitimate and trusted.&lt;br /&gt;
&lt;br /&gt;
=[[Image:new.gif|New]]Bibliography=&lt;br /&gt;
===Privacy and ethical Issues===&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/xg41104w066612m7/fulltext.pdf Privacy and e-commerce: a consumer-centric perspective] Rhys Smith and Jianhua Shao, ''Electronic Commerce Research'', Volume 7, Number 2 / June, 2007 &lt;br /&gt;
&lt;br /&gt;
[http://www.mcgoverngreene.com/alerts/FA_pdfs/Oct-Nov_2004.pdf Phishers “net” unsuspecting consumers] ''fraud alert''  october/november 2004&lt;br /&gt;
&lt;br /&gt;
[http://delivery.acm.org.www.lib.ncsu.edu:2048/10.1145/1130000/1124861/p581-dhamija.pdf?key1=1124861&amp;amp;key2=4842557121&amp;amp;coll=ACM&amp;amp;dl=ACM&amp;amp;CFID=38796614&amp;amp;CFTOKEN=46500553 Why phishing works] Rachna Dhamija, J. D. Tygar, Marti Hearst&lt;br /&gt;
&lt;br /&gt;
[http://delivery.acm.org.www.lib.ncsu.edu:2048/10.1145/1080000/1073009/p77-dhamija.pdf?key1=1073009&amp;amp;key2=1444557121&amp;amp;coll=ACM&amp;amp;dl=ACM&amp;amp;CFID=38796614&amp;amp;CFTOKEN=46500553 The Battle Against Phishing: Dynamic Security Skins] Rachna Dhamija,  J. D. Tygar&lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/d284629556533224/fulltext.pdf A Revocation Scheme Preserving Privacy] Łukasz Krzywiecki, Przemysław Kubiak and Mirosław Kutyłowski &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/h62k448875177211/fulltext.pdf Security and Privacy as Market Failures]L. Jean Camp,''Economics of Identity Theft: Avoidance, Causes and Possible Cures'' &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/q808084h875464v5/fulltext.pdf Protection or Privacy? Data Mining and Personal Data] David J. Hand&lt;br /&gt;
&lt;br /&gt;
===Protection against Phishing attacks===&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/0p748n8766732770/fulltext.pdf Method for Evaluating the Security Risk of a Website Against Phishing Attacks] Young-Gab Kim, Sanghyun Cho, Jun-Sub Lee, Min-Soo Lee, In Ho Kim and Sung Hoon Kim &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/307774n374w42854/fulltext.pdf An Intrusion Detection System for Detecting Phishing Attacks] Hasika Pamunuwa, Duminda Wijesekera and Csilla Farkas &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/50hln6j1b04ftbw1/fulltext.pdf Protection Mechanisms Against Phishing Attacks] Klaus Plössl, Hannes Federrath and Thomas Nowey &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/w833450106412039/fulltext.pdf On the Effectiveness of Techniques to Detect Phishing Sites] Christian Ludl, Sean McAllister, Engin Kirda and Christopher Kruegel &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/bq4mj20enhm3ep0x/fulltext.pdf Effective Protection Against Phishing and Web Spoofing] Rolf Oppliger and Sebastian Gajek &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/w81x1n840w231177/fulltext.pdf Usability evaluation of anti-phishing toolbars] Linfeng Li and Marko Helenius&lt;br /&gt;
&lt;br /&gt;
===Others===&lt;br /&gt;
[http://pg-server.csc.ncsu.edu/mediawiki/index.php/CSC_379_SUM2008:Topics#Phishing Topic Page]&lt;/div&gt;</summary>
		<author><name>Mbastan</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16767</id>
		<title>Phishing</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16767"/>
		<updated>2008-08-04T23:49:09Z</updated>

		<summary type="html">&lt;p&gt;Mbastan: /* Bibliography */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=[[Image:new.gif|New]]Study Guide=&lt;br /&gt;
&lt;br /&gt;
Phishing in computing is the process of acquiring private and sensitive information by pretending to be a trustworthy or a legitimate website through the online communications. Phishing is an example of fraudulent use of social engineering techniques to deceive an online service user. In this article some of the known attacks will be discussed following with some solutions to guard against these attackes.&lt;br /&gt;
&lt;br /&gt;
==Phishing Attacks==&lt;br /&gt;
&lt;br /&gt;
The following are some of the way that the phishing attacks are taking place.&lt;br /&gt;
&lt;br /&gt;
====Keyloggers====&lt;br /&gt;
&lt;br /&gt;
These are spywares that can get installed either into a web browser or as a device driver. They record the user’s input to the computer by recording the keyboard keystrokes or mouse click. This information will be then sent to the spyware owner. These spywares can cause severe data leak.&lt;br /&gt;
&lt;br /&gt;
===Torpig-Family Trojan===&lt;br /&gt;
&lt;br /&gt;
These Trojans are using advanced technologies that help them to spread very fast and hide very well. They are designed to hijack sessions. These Trojans are constantly monitoring major banks’ websites throughout the world. They display a fake page when a user tries to log in to these websites, and in this way continue to steal the private information of their victims.&lt;br /&gt;
&lt;br /&gt;
===Session Hijackers===&lt;br /&gt;
&lt;br /&gt;
These attacks can take place either from the malware that is installed on the victim’s computer or remotely. The attacks are triggered when users is trying to log into they account (usually bank accounts) or when they initiate a transaction. The malware then hijack the session for malicious purposes.&lt;br /&gt;
&lt;br /&gt;
===Content-Injection Phishing===&lt;br /&gt;
&lt;br /&gt;
This phishing refers to the situations when malicious or fake content gets injected into some legitimate Web sites. This content then can deceive the users of the Web site by redirecting them to other Web sites, install malware on their computers, or redirect the input that users is inputting to that Web site to the phishing server.&lt;br /&gt;
&lt;br /&gt;
===“Universal” Man-in-the-Middle Phishing Kit===&lt;br /&gt;
&lt;br /&gt;
There is only little effort required for the attackers to use this method to attack their victims. The attackers use a kit which is called MITM that includes several PHP files that get installed on the phishing server. This server then acts as a medium between the user and the legitimate website that he/she wants to access. These victims receive emails that include a purported link to their known website. Once they click on the link, they’ll be redirected to the phishing server which then will communicate with the original Web site on behalf of the user.&lt;br /&gt;
&lt;br /&gt;
===Search Engine Phishing===&lt;br /&gt;
&lt;br /&gt;
In this type pf phishing, phishers establish a webpage, and then get it indexed by the search engines to make it searchable. These pages are usually designed to include items and services at very low price to attract visitors to sign up or to enter their confidential information. The phisher then get the hold of the private information of the visitors.&lt;br /&gt;
&lt;br /&gt;
===Spear Phishing===&lt;br /&gt;
&lt;br /&gt;
In this approach the phisher targets a particular person or a specific department in a company. The phisher then contacts the person by email and pretends to be from a legitimate department and is a trustworthy staff. The attacker then asks for the username and password with some fake reasons. Once the attacker get those information the can by pass the firewalls and break into the secured network.&lt;br /&gt;
&lt;br /&gt;
==Phishing solutions==&lt;br /&gt;
&lt;br /&gt;
To fight against the phishers, in the first place, the online service users should be educated. Once users know what phishing is and what methods phishers use, less people will fall for their tricks and many of their method then become useless. However some countermeasures have been developed and some of them are explained below.&lt;br /&gt;
&lt;br /&gt;
===Phishing blacklist===&lt;br /&gt;
&lt;br /&gt;
A server that is containing a list of all of the malicious websites and phishing servers should be established and be accessible by the internet browsers. The list should be updated on daily basis due to the lifetime of the phishing servers. The malicious URLs should be reported immediately.&lt;br /&gt;
&lt;br /&gt;
===Bookmarks or history===&lt;br /&gt;
&lt;br /&gt;
Using bookmarks and history to detect the list of the websites that the user uses. Then if a new website is visited randomly by the user that he/she did not visit before, chances are that this website is has malicious purposes. The down side of this method is that the history feature holds a history of the limited and short time.&lt;br /&gt;
&lt;br /&gt;
===Two-Way Authentication===&lt;br /&gt;
&lt;br /&gt;
In this method once a user signs up for an online service they receive and image in a secure way. Thereafter whenever the user visits the website and enters his/her username the website displays the image to prove its legitimacy. The user then can continue to enter his/her password.&lt;br /&gt;
&lt;br /&gt;
===VeriSign Identity Protection (VIP)===&lt;br /&gt;
&lt;br /&gt;
VIP has been design to protect the digital identities of the people who use online services. VIP provides number of rules that organizations should comply with if they want use VIP services. The VIP suite then provides a secure way for users to log into their account and transactions to take place.&lt;br /&gt;
&lt;br /&gt;
===Early alarm===&lt;br /&gt;
&lt;br /&gt;
This solution requires sort of add-on tool to be installed on Web browsers. This tool contains several rules and ways to check the authentication of the Web sites. The tool will notify the user if the Web site is legitimate and trusted.&lt;br /&gt;
&lt;br /&gt;
=[[Image:new.gif|New]]Bibliography=&lt;br /&gt;
===Privacy and ethical Issues===&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/xg41104w066612m7/fulltext.pdf Privacy and e-commerce: a consumer-centric perspective] Rhys Smith and Jianhua Shao, ''Electronic Commerce Research'', Volume 7, Number 2 / June, 2007 &lt;br /&gt;
&lt;br /&gt;
[http://www.mcgoverngreene.com/alerts/FA_pdfs/Oct-Nov_2004.pdf Phishers “net” unsuspecting consumers] ''fraud alert''  october/november 2004&lt;br /&gt;
&lt;br /&gt;
[http://delivery.acm.org.www.lib.ncsu.edu:2048/10.1145/1130000/1124861/p581-dhamija.pdf?key1=1124861&amp;amp;key2=4842557121&amp;amp;coll=ACM&amp;amp;dl=ACM&amp;amp;CFID=38796614&amp;amp;CFTOKEN=46500553 Why phishing works] Rachna Dhamija, J. D. Tygar, Marti Hearst&lt;br /&gt;
&lt;br /&gt;
[http://delivery.acm.org.www.lib.ncsu.edu:2048/10.1145/1080000/1073009/p77-dhamija.pdf?key1=1073009&amp;amp;key2=1444557121&amp;amp;coll=ACM&amp;amp;dl=ACM&amp;amp;CFID=38796614&amp;amp;CFTOKEN=46500553 The Battle Against Phishing: Dynamic Security Skins] Rachna Dhamija,  J. D. Tygar&lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/d284629556533224/fulltext.pdf A Revocation Scheme Preserving Privacy] Łukasz Krzywiecki, Przemysław Kubiak and Mirosław Kutyłowski &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/h62k448875177211/fulltext.pdf Security and Privacy as Market Failures]L. Jean Camp,''Economics of Identity Theft: Avoidance, Causes and Possible Cures'' &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/q808084h875464v5/fulltext.pdf Protection or Privacy? Data Mining and Personal Data] David J. Hand&lt;br /&gt;
&lt;br /&gt;
===Protection against Phishing attacks===&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/0p748n8766732770/fulltext.pdf Method for Evaluating the Security Risk of a Website Against Phishing Attacks] Young-Gab Kim, Sanghyun Cho, Jun-Sub Lee, Min-Soo Lee, In Ho Kim and Sung Hoon Kim &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/307774n374w42854/fulltext.pdf An Intrusion Detection System for Detecting Phishing Attacks] Hasika Pamunuwa, Duminda Wijesekera and Csilla Farkas &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/50hln6j1b04ftbw1/fulltext.pdf Protection Mechanisms Against Phishing Attacks] Klaus Plössl, Hannes Federrath and Thomas Nowey &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/w833450106412039/fulltext.pdf On the Effectiveness of Techniques to Detect Phishing Sites] Christian Ludl, Sean McAllister, Engin Kirda and Christopher Kruegel &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/bq4mj20enhm3ep0x/fulltext.pdf Effective Protection Against Phishing and Web Spoofing] Rolf Oppliger and Sebastian Gajek &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/w81x1n840w231177/fulltext.pdf Usability evaluation of anti-phishing toolbars] Linfeng Li and Marko Helenius&lt;br /&gt;
&lt;br /&gt;
===Others===&lt;br /&gt;
[http://pg-server.csc.ncsu.edu/mediawiki/index.php/CSC_379_SUM2008:Topics#Phishing Topic Page]&lt;/div&gt;</summary>
		<author><name>Mbastan</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16766</id>
		<title>Phishing</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16766"/>
		<updated>2008-08-04T23:48:53Z</updated>

		<summary type="html">&lt;p&gt;Mbastan: /* Study Guide */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=[[Image:new.gif|New]]Study Guide=&lt;br /&gt;
&lt;br /&gt;
Phishing in computing is the process of acquiring private and sensitive information by pretending to be a trustworthy or a legitimate website through the online communications. Phishing is an example of fraudulent use of social engineering techniques to deceive an online service user. In this article some of the known attacks will be discussed following with some solutions to guard against these attackes.&lt;br /&gt;
&lt;br /&gt;
==Phishing Attacks==&lt;br /&gt;
&lt;br /&gt;
The following are some of the way that the phishing attacks are taking place.&lt;br /&gt;
&lt;br /&gt;
====Keyloggers====&lt;br /&gt;
&lt;br /&gt;
These are spywares that can get installed either into a web browser or as a device driver. They record the user’s input to the computer by recording the keyboard keystrokes or mouse click. This information will be then sent to the spyware owner. These spywares can cause severe data leak.&lt;br /&gt;
&lt;br /&gt;
===Torpig-Family Trojan===&lt;br /&gt;
&lt;br /&gt;
These Trojans are using advanced technologies that help them to spread very fast and hide very well. They are designed to hijack sessions. These Trojans are constantly monitoring major banks’ websites throughout the world. They display a fake page when a user tries to log in to these websites, and in this way continue to steal the private information of their victims.&lt;br /&gt;
&lt;br /&gt;
===Session Hijackers===&lt;br /&gt;
&lt;br /&gt;
These attacks can take place either from the malware that is installed on the victim’s computer or remotely. The attacks are triggered when users is trying to log into they account (usually bank accounts) or when they initiate a transaction. The malware then hijack the session for malicious purposes.&lt;br /&gt;
&lt;br /&gt;
===Content-Injection Phishing===&lt;br /&gt;
&lt;br /&gt;
This phishing refers to the situations when malicious or fake content gets injected into some legitimate Web sites. This content then can deceive the users of the Web site by redirecting them to other Web sites, install malware on their computers, or redirect the input that users is inputting to that Web site to the phishing server.&lt;br /&gt;
&lt;br /&gt;
===“Universal” Man-in-the-Middle Phishing Kit===&lt;br /&gt;
&lt;br /&gt;
There is only little effort required for the attackers to use this method to attack their victims. The attackers use a kit which is called MITM that includes several PHP files that get installed on the phishing server. This server then acts as a medium between the user and the legitimate website that he/she wants to access. These victims receive emails that include a purported link to their known website. Once they click on the link, they’ll be redirected to the phishing server which then will communicate with the original Web site on behalf of the user.&lt;br /&gt;
&lt;br /&gt;
===Search Engine Phishing===&lt;br /&gt;
&lt;br /&gt;
In this type pf phishing, phishers establish a webpage, and then get it indexed by the search engines to make it searchable. These pages are usually designed to include items and services at very low price to attract visitors to sign up or to enter their confidential information. The phisher then get the hold of the private information of the visitors.&lt;br /&gt;
&lt;br /&gt;
===Spear Phishing===&lt;br /&gt;
&lt;br /&gt;
In this approach the phisher targets a particular person or a specific department in a company. The phisher then contacts the person by email and pretends to be from a legitimate department and is a trustworthy staff. The attacker then asks for the username and password with some fake reasons. Once the attacker get those information the can by pass the firewalls and break into the secured network.&lt;br /&gt;
&lt;br /&gt;
==Phishing solutions==&lt;br /&gt;
&lt;br /&gt;
To fight against the phishers, in the first place, the online service users should be educated. Once users know what phishing is and what methods phishers use, less people will fall for their tricks and many of their method then become useless. However some countermeasures have been developed and some of them are explained below.&lt;br /&gt;
&lt;br /&gt;
===Phishing blacklist===&lt;br /&gt;
&lt;br /&gt;
A server that is containing a list of all of the malicious websites and phishing servers should be established and be accessible by the internet browsers. The list should be updated on daily basis due to the lifetime of the phishing servers. The malicious URLs should be reported immediately.&lt;br /&gt;
&lt;br /&gt;
===Bookmarks or history===&lt;br /&gt;
&lt;br /&gt;
Using bookmarks and history to detect the list of the websites that the user uses. Then if a new website is visited randomly by the user that he/she did not visit before, chances are that this website is has malicious purposes. The down side of this method is that the history feature holds a history of the limited and short time.&lt;br /&gt;
&lt;br /&gt;
===Two-Way Authentication===&lt;br /&gt;
&lt;br /&gt;
In this method once a user signs up for an online service they receive and image in a secure way. Thereafter whenever the user visits the website and enters his/her username the website displays the image to prove its legitimacy. The user then can continue to enter his/her password.&lt;br /&gt;
&lt;br /&gt;
===VeriSign Identity Protection (VIP)===&lt;br /&gt;
&lt;br /&gt;
VIP has been design to protect the digital identities of the people who use online services. VIP provides number of rules that organizations should comply with if they want use VIP services. The VIP suite then provides a secure way for users to log into their account and transactions to take place.&lt;br /&gt;
&lt;br /&gt;
===Early alarm===&lt;br /&gt;
&lt;br /&gt;
This solution requires sort of add-on tool to be installed on Web browsers. This tool contains several rules and ways to check the authentication of the Web sites. The tool will notify the user if the Web site is legitimate and trusted.&lt;br /&gt;
&lt;br /&gt;
=Bibliography=&lt;br /&gt;
===Privacy and ethical Issues===&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/xg41104w066612m7/fulltext.pdf Privacy and e-commerce: a consumer-centric perspective] Rhys Smith and Jianhua Shao, ''Electronic Commerce Research'', Volume 7, Number 2 / June, 2007 &lt;br /&gt;
&lt;br /&gt;
[http://www.mcgoverngreene.com/alerts/FA_pdfs/Oct-Nov_2004.pdf Phishers “net” unsuspecting consumers] ''fraud alert''  october/november 2004&lt;br /&gt;
&lt;br /&gt;
[http://delivery.acm.org.www.lib.ncsu.edu:2048/10.1145/1130000/1124861/p581-dhamija.pdf?key1=1124861&amp;amp;key2=4842557121&amp;amp;coll=ACM&amp;amp;dl=ACM&amp;amp;CFID=38796614&amp;amp;CFTOKEN=46500553 Why phishing works] Rachna Dhamija, J. D. Tygar, Marti Hearst&lt;br /&gt;
&lt;br /&gt;
[http://delivery.acm.org.www.lib.ncsu.edu:2048/10.1145/1080000/1073009/p77-dhamija.pdf?key1=1073009&amp;amp;key2=1444557121&amp;amp;coll=ACM&amp;amp;dl=ACM&amp;amp;CFID=38796614&amp;amp;CFTOKEN=46500553 The Battle Against Phishing: Dynamic Security Skins] Rachna Dhamija,  J. D. Tygar&lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/d284629556533224/fulltext.pdf A Revocation Scheme Preserving Privacy] Łukasz Krzywiecki, Przemysław Kubiak and Mirosław Kutyłowski &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/h62k448875177211/fulltext.pdf Security and Privacy as Market Failures]L. Jean Camp,''Economics of Identity Theft: Avoidance, Causes and Possible Cures'' &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/q808084h875464v5/fulltext.pdf Protection or Privacy? Data Mining and Personal Data] David J. Hand&lt;br /&gt;
&lt;br /&gt;
===Protection against Phishing attacks===&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/0p748n8766732770/fulltext.pdf Method for Evaluating the Security Risk of a Website Against Phishing Attacks] Young-Gab Kim, Sanghyun Cho, Jun-Sub Lee, Min-Soo Lee, In Ho Kim and Sung Hoon Kim &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/307774n374w42854/fulltext.pdf An Intrusion Detection System for Detecting Phishing Attacks] Hasika Pamunuwa, Duminda Wijesekera and Csilla Farkas &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/50hln6j1b04ftbw1/fulltext.pdf Protection Mechanisms Against Phishing Attacks] Klaus Plössl, Hannes Federrath and Thomas Nowey &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/w833450106412039/fulltext.pdf On the Effectiveness of Techniques to Detect Phishing Sites] Christian Ludl, Sean McAllister, Engin Kirda and Christopher Kruegel &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/bq4mj20enhm3ep0x/fulltext.pdf Effective Protection Against Phishing and Web Spoofing] Rolf Oppliger and Sebastian Gajek &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/w81x1n840w231177/fulltext.pdf Usability evaluation of anti-phishing toolbars] Linfeng Li and Marko Helenius&lt;br /&gt;
&lt;br /&gt;
===Others===&lt;br /&gt;
[http://pg-server.csc.ncsu.edu/mediawiki/index.php/CSC_379_SUM2008:Topics#Phishing Topic Page]&lt;/div&gt;</summary>
		<author><name>Mbastan</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16765</id>
		<title>Phishing</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16765"/>
		<updated>2008-08-04T23:45:08Z</updated>

		<summary type="html">&lt;p&gt;Mbastan: /* Bibliography */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Study Guide=&lt;br /&gt;
&lt;br /&gt;
Phishing in computing is the process of acquiring private and sensitive information by pretending to be a trustworthy or a legitimate website through the online communications. Phishing is an example of fraudulent use of social engineering techniques to deceive an online service user. In this article some of the known attacks will be discussed following with some solutions to guard against these attackes.&lt;br /&gt;
&lt;br /&gt;
==Phishing Attacks==&lt;br /&gt;
&lt;br /&gt;
The following are some of the way that the phishing attacks are taking place.&lt;br /&gt;
&lt;br /&gt;
====Keyloggers====&lt;br /&gt;
&lt;br /&gt;
These are spywares that can get installed either into a web browser or as a device driver. They record the user’s input to the computer by recording the keyboard keystrokes or mouse click. This information will be then sent to the spyware owner. These spywares can cause severe data leak.&lt;br /&gt;
&lt;br /&gt;
===Torpig-Family Trojan===&lt;br /&gt;
&lt;br /&gt;
These Trojans are using advanced technologies that help them to spread very fast and hide very well. They are designed to hijack sessions. These Trojans are constantly monitoring major banks’ websites throughout the world. They display a fake page when a user tries to log in to these websites, and in this way continue to steal the private information of their victims.&lt;br /&gt;
&lt;br /&gt;
===Session Hijackers===&lt;br /&gt;
&lt;br /&gt;
These attacks can take place either from the malware that is installed on the victim’s computer or remotely. The attacks are triggered when users is trying to log into they account (usually bank accounts) or when they initiate a transaction. The malware then hijack the session for malicious purposes.&lt;br /&gt;
&lt;br /&gt;
===Content-Injection Phishing===&lt;br /&gt;
&lt;br /&gt;
This phishing refers to the situations when malicious or fake content gets injected into some legitimate Web sites. This content then can deceive the users of the Web site by redirecting them to other Web sites, install malware on their computers, or redirect the input that users is inputting to that Web site to the phishing server.&lt;br /&gt;
&lt;br /&gt;
===“Universal” Man-in-the-Middle Phishing Kit===&lt;br /&gt;
&lt;br /&gt;
There is only little effort required for the attackers to use this method to attack their victims. The attackers use a kit which is called MITM that includes several PHP files that get installed on the phishing server. This server then acts as a medium between the user and the legitimate website that he/she wants to access. These victims receive emails that include a purported link to their known website. Once they click on the link, they’ll be redirected to the phishing server which then will communicate with the original Web site on behalf of the user.&lt;br /&gt;
&lt;br /&gt;
===Search Engine Phishing===&lt;br /&gt;
&lt;br /&gt;
In this type pf phishing, phishers establish a webpage, and then get it indexed by the search engines to make it searchable. These pages are usually designed to include items and services at very low price to attract visitors to sign up or to enter their confidential information. The phisher then get the hold of the private information of the visitors.&lt;br /&gt;
&lt;br /&gt;
===Spear Phishing===&lt;br /&gt;
&lt;br /&gt;
In this approach the phisher targets a particular person or a specific department in a company. The phisher then contacts the person by email and pretends to be from a legitimate department and is a trustworthy staff. The attacker then asks for the username and password with some fake reasons. Once the attacker get those information the can by pass the firewalls and break into the secured network.&lt;br /&gt;
&lt;br /&gt;
==Phishing solutions==&lt;br /&gt;
&lt;br /&gt;
To fight against the phishers, in the first place, the online service users should be educated. Once users know what phishing is and what methods phishers use, less people will fall for their tricks and many of their method then become useless. However some countermeasures have been developed and some of them are explained below.&lt;br /&gt;
&lt;br /&gt;
===Phishing blacklist===&lt;br /&gt;
&lt;br /&gt;
A server that is containing a list of all of the malicious websites and phishing servers should be established and be accessible by the internet browsers. The list should be updated on daily basis due to the lifetime of the phishing servers. The malicious URLs should be reported immediately.&lt;br /&gt;
&lt;br /&gt;
===Bookmarks or history===&lt;br /&gt;
&lt;br /&gt;
Using bookmarks and history to detect the list of the websites that the user uses. Then if a new website is visited randomly by the user that he/she did not visit before, chances are that this website is has malicious purposes. The down side of this method is that the history feature holds a history of the limited and short time.&lt;br /&gt;
&lt;br /&gt;
===Two-Way Authentication===&lt;br /&gt;
&lt;br /&gt;
In this method once a user signs up for an online service they receive and image in a secure way. Thereafter whenever the user visits the website and enters his/her username the website displays the image to prove its legitimacy. The user then can continue to enter his/her password.&lt;br /&gt;
&lt;br /&gt;
===VeriSign Identity Protection (VIP)===&lt;br /&gt;
&lt;br /&gt;
VIP has been design to protect the digital identities of the people who use online services. VIP provides number of rules that organizations should comply with if they want use VIP services. The VIP suite then provides a secure way for users to log into their account and transactions to take place.&lt;br /&gt;
&lt;br /&gt;
===Early alarm===&lt;br /&gt;
&lt;br /&gt;
This solution requires sort of add-on tool to be installed on Web browsers. This tool contains several rules and ways to check the authentication of the Web sites. The tool will notify the user if the Web site is legitimate and trusted.&lt;br /&gt;
&lt;br /&gt;
=Bibliography=&lt;br /&gt;
===Privacy and ethical Issues===&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/xg41104w066612m7/fulltext.pdf Privacy and e-commerce: a consumer-centric perspective] Rhys Smith and Jianhua Shao, ''Electronic Commerce Research'', Volume 7, Number 2 / June, 2007 &lt;br /&gt;
&lt;br /&gt;
[http://www.mcgoverngreene.com/alerts/FA_pdfs/Oct-Nov_2004.pdf Phishers “net” unsuspecting consumers] ''fraud alert''  october/november 2004&lt;br /&gt;
&lt;br /&gt;
[http://delivery.acm.org.www.lib.ncsu.edu:2048/10.1145/1130000/1124861/p581-dhamija.pdf?key1=1124861&amp;amp;key2=4842557121&amp;amp;coll=ACM&amp;amp;dl=ACM&amp;amp;CFID=38796614&amp;amp;CFTOKEN=46500553 Why phishing works] Rachna Dhamija, J. D. Tygar, Marti Hearst&lt;br /&gt;
&lt;br /&gt;
[http://delivery.acm.org.www.lib.ncsu.edu:2048/10.1145/1080000/1073009/p77-dhamija.pdf?key1=1073009&amp;amp;key2=1444557121&amp;amp;coll=ACM&amp;amp;dl=ACM&amp;amp;CFID=38796614&amp;amp;CFTOKEN=46500553 The Battle Against Phishing: Dynamic Security Skins] Rachna Dhamija,  J. D. Tygar&lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/d284629556533224/fulltext.pdf A Revocation Scheme Preserving Privacy] Łukasz Krzywiecki, Przemysław Kubiak and Mirosław Kutyłowski &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/h62k448875177211/fulltext.pdf Security and Privacy as Market Failures]L. Jean Camp,''Economics of Identity Theft: Avoidance, Causes and Possible Cures'' &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/q808084h875464v5/fulltext.pdf Protection or Privacy? Data Mining and Personal Data] David J. Hand&lt;br /&gt;
&lt;br /&gt;
===Protection against Phishing attacks===&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/0p748n8766732770/fulltext.pdf Method for Evaluating the Security Risk of a Website Against Phishing Attacks] Young-Gab Kim, Sanghyun Cho, Jun-Sub Lee, Min-Soo Lee, In Ho Kim and Sung Hoon Kim &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/307774n374w42854/fulltext.pdf An Intrusion Detection System for Detecting Phishing Attacks] Hasika Pamunuwa, Duminda Wijesekera and Csilla Farkas &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/50hln6j1b04ftbw1/fulltext.pdf Protection Mechanisms Against Phishing Attacks] Klaus Plössl, Hannes Federrath and Thomas Nowey &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/w833450106412039/fulltext.pdf On the Effectiveness of Techniques to Detect Phishing Sites] Christian Ludl, Sean McAllister, Engin Kirda and Christopher Kruegel &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/bq4mj20enhm3ep0x/fulltext.pdf Effective Protection Against Phishing and Web Spoofing] Rolf Oppliger and Sebastian Gajek &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/w81x1n840w231177/fulltext.pdf Usability evaluation of anti-phishing toolbars] Linfeng Li and Marko Helenius&lt;br /&gt;
&lt;br /&gt;
===Others===&lt;br /&gt;
[http://pg-server.csc.ncsu.edu/mediawiki/index.php/CSC_379_SUM2008:Topics#Phishing Topic Page]&lt;/div&gt;</summary>
		<author><name>Mbastan</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379_SUM2008:Week_4,_Group_3&amp;diff=16734</id>
		<title>CSC 379 SUM2008:Week 4, Group 3</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379_SUM2008:Week_4,_Group_3&amp;diff=16734"/>
		<updated>2008-08-02T14:28:44Z</updated>

		<summary type="html">&lt;p&gt;Mbastan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Many municipalities are beginning to provide free (taxpayer- or advertising-funded) citywide wireless Internet access.  Many municipalities are also considering filtering the connections, usually to stop pornography.  However, allowing the government to control information flow is fraught with danger to free speech, especially in the absence of any laws limiting the government's authority.  Examine the ethical considerations posed by filtering of municipal WAN connections.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Dangers of Internet Filtering==&lt;br /&gt;
* Who decides what is appropriate and what isn't?&lt;br /&gt;
** The first amendment guarantees the right to free speech, how can the government justify blocking certain webpages?&lt;br /&gt;
* What criteria are used to decide whether a website is obscene?&lt;br /&gt;
**[http://blogs.computerworld.com/censorship_with_your_free_wi_fi Example:] Denver airports block &amp;quot;racy&amp;quot; content&lt;br /&gt;
* Who is and isn't allowed to access certain material on public networks?&lt;br /&gt;
**[http://www.accessmylibrary.com/coms2/summary_0286-8139694_ITM Example:] Oregon County Libraries propose age-based internet filters&lt;br /&gt;
* Are there sufficient laws to protect user's rights?&lt;br /&gt;
**Most legislators are blissfully unaware of even the most basic computer/internet functions, who could possibly expect them to understand the complex legal issues involved with internet free speech?&lt;br /&gt;
&lt;br /&gt;
==Policy Issues==&lt;br /&gt;
&lt;br /&gt;
There has not been a clear answer to the question that whether governmental organization should get engaged with the creation of Municipal Wireless Networks (MWN) or not. Many Internet Service Providers have started a legal challenge against creating MWN. The main argument is that the creating MWN is considered unjust competition. MWNs are not only threat to telecommunications and Internet Service Providers but also to the traditional wired telephones, cellular services, and broadcast entertainment. MWN delivers the same service at much lower cost to the customers. Telecoms and ISPs particularly argue that since government entities have a total access to the public assets that can be used to deploy network infrastructure equipment is not a fair competition. So far telecoms and ISPs successfully convinced public officials to pass laws in 14 states that prohibit MWNs to be built by the government. One of these states was Pennsylvania that telecoms and ISPs lobbied to pass law that prohibits municipalities in most of the state from building MWN but only Philadelphia was able to receive an exemption from this law after going through lot of debates.&lt;br /&gt;
&lt;br /&gt;
MWN has some major legal implications and complexities. For example who is responsible for data security, and the related liabilities? Who is responsible for operational performance and customer service manager?  Also since Municipal Wireless Networks operate over the whole city, they need to comply with the governmental regulations and licensing requirement.&lt;br /&gt;
&lt;br /&gt;
Other important unresolved policy issues are:&lt;br /&gt;
&lt;br /&gt;
1. Isn’t the installation of the MWNs by the governmental entities implies that government is trying to win private businesses? &lt;br /&gt;
&lt;br /&gt;
2. Isn’t the free and the total access that government has to the public assets that enables them to install the network equipment cause an unfair competition with the private ISPs?&lt;br /&gt;
&lt;br /&gt;
3. Is that okay to spend the public funds to support MWN where the internet service providers are the city or state governments which do not have lot of experience in providing internet service?&lt;br /&gt;
&lt;br /&gt;
4. Maybe we need some new laws to handle the competing goals among MWN stakeholders. Implementers should first try to understand and evaluate the legislative landscape in their community before starting to create MWN.&lt;br /&gt;
&lt;br /&gt;
==Ethical Considerations==&lt;br /&gt;
Free municipal WiFi service offered by the City of Boston, for example, comes with mandatory content filtering that blocks all kinds of sites which are not even close to illegal nor are they sources of pornography that might be considered harmful to children. One the one hand it’s not hard to see why city officials want to avoid the headline: “Boston’s free network a conduit to porn for city’s children, foiling parents’ filtering software.” But does that mean that it’s either wise public policy or constitutionally-permissible for the city to offer wifi to the public with such sweeping and arbitrary constraints?&lt;br /&gt;
&lt;br /&gt;
==United States Policy==&lt;br /&gt;
As a constitutional matter, it’s not quite clear whether the government can require government-funded Internet service providers to filter content. In United States v. American Library Association, 539 U.S. 194 (2003), the US Supreme Court decided that the Congress could require libraries receiving federal Internet access subsidies (the e-rate) to filter out porn. However, it’s not clear whether this case applies to the municipal Wifi situation. The Supreme Court explained:&lt;br /&gt;
&lt;br /&gt;
&amp;quot;A public library does not acquire Internet terminals in order to &lt;br /&gt;
create a public forum for Web publishers to express themselves, &lt;br /&gt;
any more than it collects books in order to provide a public &lt;br /&gt;
forum for the authors of books to speak. It provides Internet &lt;br /&gt;
access, not to “encourage a diversity of views from private &lt;br /&gt;
speakers,” … but for the same reasons it offers other library &lt;br /&gt;
resources: to facilitate research, learning, and recreational &lt;br /&gt;
pursuits by furnishing materials of requisite and appropriate &lt;br /&gt;
quality.&lt;br /&gt;
&lt;br /&gt;
==Links and Resources==&lt;br /&gt;
*[http://blogs.computerworld.com/censorship_with_your_free_wi_fi Censorship with your Free Wifi?] ''Computer World''&lt;br /&gt;
*[http://www.csmonitor.com/2003/0305/p02s01-usju.html Should Libraries Censor Internet Access?] ''CSMonitor.com''&lt;br /&gt;
*[http://blog.librarylaw.com/librarylaw/2006/02/how_many_states.html How many states censor?] ''Librarylaw.com''&lt;br /&gt;
*[http://www.usatoday.com/tech/columnist/2002/06/27/sinrod.htm Ruling in library Internet filter case was correct] ''USAToday.com''&lt;br /&gt;
*[http://www.accessmylibrary.com/coms2/summary_0286-8139694_ITM Oregon Libraries propose age-based filters] ''Accessmylibrary.com''&lt;br /&gt;
* http://www.wifinetnews.com/archives/006299.html&lt;br /&gt;
* http://people.w3.org/~djweitzner/blog/?p=90&lt;/div&gt;</summary>
		<author><name>Mbastan</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379_SUM2008:Week_4,_Group_3&amp;diff=16733</id>
		<title>CSC 379 SUM2008:Week 4, Group 3</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379_SUM2008:Week_4,_Group_3&amp;diff=16733"/>
		<updated>2008-08-02T14:27:49Z</updated>

		<summary type="html">&lt;p&gt;Mbastan: /* Policy Issues */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Many municipalities are beginning to provide free (taxpayer- or advertising-funded) citywide wireless Internet access.  Many municipalities are also considering filtering the connections, usually to stop pornography.  However, allowing the government to control information flow is fraught with danger to free speech, especially in the absence of any laws limiting the government's authority.  Examine the ethical considerations posed by filtering of municipal WAN connections.&lt;br /&gt;
&lt;br /&gt;
* http://www.wifinetnews.com/archives/006299.html&lt;br /&gt;
* http://people.w3.org/~djweitzner/blog/?p=90&lt;br /&gt;
&lt;br /&gt;
==Dangers of Internet Filtering==&lt;br /&gt;
* Who decides what is appropriate and what isn't?&lt;br /&gt;
** The first amendment guarantees the right to free speech, how can the government justify blocking certain webpages?&lt;br /&gt;
* What criteria are used to decide whether a website is obscene?&lt;br /&gt;
**[http://blogs.computerworld.com/censorship_with_your_free_wi_fi Example:] Denver airports block &amp;quot;racy&amp;quot; content&lt;br /&gt;
* Who is and isn't allowed to access certain material on public networks?&lt;br /&gt;
**[http://www.accessmylibrary.com/coms2/summary_0286-8139694_ITM Example:] Oregon County Libraries propose age-based internet filters&lt;br /&gt;
* Are there sufficient laws to protect user's rights?&lt;br /&gt;
**Most legislators are blissfully unaware of even the most basic computer/internet functions, who could possibly expect them to understand the complex legal issues involved with internet free speech?&lt;br /&gt;
&lt;br /&gt;
==Policy Issues==&lt;br /&gt;
&lt;br /&gt;
There has not been a clear answer to the question that whether governmental organization should get engaged with the creation of Municipal Wireless Networks (MWN) or not. Many Internet Service Providers have started a legal challenge against creating MWN. The main argument is that the creating MWN is considered unjust competition. MWNs are not only threat to telecommunications and Internet Service Providers but also to the traditional wired telephones, cellular services, and broadcast entertainment. MWN delivers the same service at much lower cost to the customers. Telecoms and ISPs particularly argue that since government entities have a total access to the public assets that can be used to deploy network infrastructure equipment is not a fair competition. So far telecoms and ISPs successfully convinced public officials to pass laws in 14 states that prohibit MWNs to be built by the government. One of these states was Pennsylvania that telecoms and ISPs lobbied to pass law that prohibits municipalities in most of the state from building MWN but only Philadelphia was able to receive an exemption from this law after going through lot of debates.&lt;br /&gt;
&lt;br /&gt;
MWN has some major legal implications and complexities. For example who is responsible for data security, and the related liabilities? Who is responsible for operational performance and customer service manager?  Also since Municipal Wireless Networks operate over the whole city, they need to comply with the governmental regulations and licensing requirement.&lt;br /&gt;
&lt;br /&gt;
Other important unresolved policy issues are:&lt;br /&gt;
&lt;br /&gt;
1. Isn’t the installation of the MWNs by the governmental entities implies that government is trying to win private businesses? &lt;br /&gt;
&lt;br /&gt;
2. Isn’t the free and the total access that government has to the public assets that enables them to install the network equipment cause an unfair competition with the private ISPs?&lt;br /&gt;
&lt;br /&gt;
3. Is that okay to spend the public funds to support MWN where the internet service providers are the city or state governments which do not have lot of experience in providing internet service?&lt;br /&gt;
&lt;br /&gt;
4. Maybe we need some new laws to handle the competing goals among MWN stakeholders. Implementers should first try to understand and evaluate the legislative landscape in their community before starting to create MWN.&lt;br /&gt;
&lt;br /&gt;
==Ethical Considerations==&lt;br /&gt;
Free municipal WiFi service offered by the City of Boston, for example, comes with mandatory content filtering that blocks all kinds of sites which are not even close to illegal nor are they sources of pornography that might be considered harmful to children. One the one hand it’s not hard to see why city officials want to avoid the headline: “Boston’s free network a conduit to porn for city’s children, foiling parents’ filtering software.” But does that mean that it’s either wise public policy or constitutionally-permissible for the city to offer wifi to the public with such sweeping and arbitrary constraints?&lt;br /&gt;
&lt;br /&gt;
==United States Policy==&lt;br /&gt;
As a constitutional matter, it’s not quite clear whether the government can require government-funded Internet service providers to filter content. In United States v. American Library Association, 539 U.S. 194 (2003), the US Supreme Court decided that the Congress could require libraries receiving federal Internet access subsidies (the e-rate) to filter out porn. However, it’s not clear whether this case applies to the municipal Wifi situation. The Supreme Court explained:&lt;br /&gt;
&lt;br /&gt;
&amp;quot;A public library does not acquire Internet terminals in order to &lt;br /&gt;
create a public forum for Web publishers to express themselves, &lt;br /&gt;
any more than it collects books in order to provide a public &lt;br /&gt;
forum for the authors of books to speak. It provides Internet &lt;br /&gt;
access, not to “encourage a diversity of views from private &lt;br /&gt;
speakers,” … but for the same reasons it offers other library &lt;br /&gt;
resources: to facilitate research, learning, and recreational &lt;br /&gt;
pursuits by furnishing materials of requisite and appropriate &lt;br /&gt;
quality.&lt;br /&gt;
&lt;br /&gt;
==Links and Resources==&lt;br /&gt;
*[http://blogs.computerworld.com/censorship_with_your_free_wi_fi Censorship with your Free Wifi?] ''Computer World''&lt;br /&gt;
*[http://www.csmonitor.com/2003/0305/p02s01-usju.html Should Libraries Censor Internet Access?] ''CSMonitor.com''&lt;br /&gt;
*[http://blog.librarylaw.com/librarylaw/2006/02/how_many_states.html How many states censor?] ''Librarylaw.com''&lt;br /&gt;
*[http://www.usatoday.com/tech/columnist/2002/06/27/sinrod.htm Ruling in library Internet filter case was correct] ''USAToday.com''&lt;br /&gt;
*[http://www.accessmylibrary.com/coms2/summary_0286-8139694_ITM Oregon Libraries propose age-based filters] ''Accessmylibrary.com''&lt;/div&gt;</summary>
		<author><name>Mbastan</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379_SUM2008:Week_4,_Group_3&amp;diff=16732</id>
		<title>CSC 379 SUM2008:Week 4, Group 3</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379_SUM2008:Week_4,_Group_3&amp;diff=16732"/>
		<updated>2008-08-02T14:04:59Z</updated>

		<summary type="html">&lt;p&gt;Mbastan: /* Policy Issues */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Many municipalities are beginning to provide free (taxpayer- or advertising-funded) citywide wireless Internet access.  Many municipalities are also considering filtering the connections, usually to stop pornography.  However, allowing the government to control information flow is fraught with danger to free speech, especially in the absence of any laws limiting the government's authority.  Examine the ethical considerations posed by filtering of municipal WAN connections.&lt;br /&gt;
&lt;br /&gt;
* http://www.wifinetnews.com/archives/006299.html&lt;br /&gt;
* http://people.w3.org/~djweitzner/blog/?p=90&lt;br /&gt;
&lt;br /&gt;
==Dangers of Internet Filtering==&lt;br /&gt;
* Who decides what is appropriate and what isn't?&lt;br /&gt;
** The first amendment guarantees the right to free speech, how can the government justify blocking certain webpages?&lt;br /&gt;
* What criteria are used to decide whether a website is obscene?&lt;br /&gt;
**[http://blogs.computerworld.com/censorship_with_your_free_wi_fi Example:] Denver airports block &amp;quot;racy&amp;quot; content&lt;br /&gt;
* Who is and isn't allowed to access certain material on public networks?&lt;br /&gt;
**[http://www.accessmylibrary.com/coms2/summary_0286-8139694_ITM Example:] Oregon County Libraries propose age-based internet filters&lt;br /&gt;
* Are there sufficient laws to protect user's rights?&lt;br /&gt;
**Most legislators are blissfully unaware of even the most basic computer/internet functions, who could possibly expect them to understand the complex legal issues involved with internet free speech?&lt;br /&gt;
&lt;br /&gt;
==Policy Issues==&lt;br /&gt;
&lt;br /&gt;
There has not been a clear answer to the question that whether governmental organization should get engaged with the creation of Municipal Wireless Networks (MWN) or not. Many Internet Service Providers have started a legal challenge against creating MWN. The main argument is that the creating MWN is considered unjust competition. MWNs are not only threat to telecommunications and Internet Service Providers but also to the traditional wired telephones, cellular services, and broadcast entertainment. MWN delivers the same service at much lower cost to the customers. Telecoms and ISPs particularly argue that since government entities have a total access to the public assets that can be used to deploy network infrastructure network is not a fair competition. So far telecoms and ISPs successfully convinced public officials to pass laws in 14 states that prohibit MWNs to be built by the government. One of these states was Pennsylvania that telecoms and ISPs lobbied to pass law that prohibits municipalities in most of the state from building MWN but only Philadelphia was able to receive an exemption from this law after going through lot of debates.&lt;br /&gt;
&lt;br /&gt;
MWN has some major legal implications and complexities. For example who is responsible for data security, and the related liabilities? Who is responsible for operational performance and customer service manager?  Also since Municipal Wireless Networks operate over the whole city, they need to comply with the governmental regulations and licensing requirement.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
There remain fundamental unresolved policy questions such as:&lt;br /&gt;
&lt;br /&gt;
1. Are MWNs an example of the government competing with private business?&lt;br /&gt;
&lt;br /&gt;
2. Does free access to public facilities provide municipalities with an unfair advantage in competing with ISPs?&lt;br /&gt;
&lt;br /&gt;
3. Should public funds be used to support MWNs when the stakeholders are often entities such as state or city governments and other community groups that do not have experience in providing Internet service?&lt;br /&gt;
&lt;br /&gt;
4. Is there a need for new uniform legislation to handle the often-competing goals among MWN stakeholders? Clearly, implementers should first seek to understand and assess the legislative landscape in their community before embarking on the creation of a MWN.&lt;br /&gt;
&lt;br /&gt;
==Ethical Considerations==&lt;br /&gt;
Free municipal WiFi service offered by the City of Boston, for example, comes with mandatory content filtering that blocks all kinds of sites which are not even close to illegal nor are they sources of pornography that might be considered harmful to children. One the one hand it’s not hard to see why city officials want to avoid the headline: “Boston’s free network a conduit to porn for city’s children, foiling parents’ filtering software.” But does that mean that it’s either wise public policy or constitutionally-permissible for the city to offer wifi to the public with such sweeping and arbitrary constraints?&lt;br /&gt;
&lt;br /&gt;
==United States Policy==&lt;br /&gt;
As a constitutional matter, it’s not quite clear whether the government can require government-funded Internet service providers to filter content. In United States v. American Library Association, 539 U.S. 194 (2003), the US Supreme Court decided that the Congress could require libraries receiving federal Internet access subsidies (the e-rate) to filter out porn. However, it’s not clear whether this case applies to the municipal Wifi situation. The Supreme Court explained:&lt;br /&gt;
&lt;br /&gt;
&amp;quot;A public library does not acquire Internet terminals in order to &lt;br /&gt;
create a public forum for Web publishers to express themselves, &lt;br /&gt;
any more than it collects books in order to provide a public &lt;br /&gt;
forum for the authors of books to speak. It provides Internet &lt;br /&gt;
access, not to “encourage a diversity of views from private &lt;br /&gt;
speakers,” … but for the same reasons it offers other library &lt;br /&gt;
resources: to facilitate research, learning, and recreational &lt;br /&gt;
pursuits by furnishing materials of requisite and appropriate &lt;br /&gt;
quality.&lt;br /&gt;
&lt;br /&gt;
==Links and Resources==&lt;br /&gt;
*[http://blogs.computerworld.com/censorship_with_your_free_wi_fi Censorship with your Free Wifi?] ''Computer World''&lt;br /&gt;
*[http://www.csmonitor.com/2003/0305/p02s01-usju.html Should Libraries Censor Internet Access?] ''CSMonitor.com''&lt;br /&gt;
*[http://blog.librarylaw.com/librarylaw/2006/02/how_many_states.html How many states censor?] ''Librarylaw.com''&lt;br /&gt;
*[http://www.usatoday.com/tech/columnist/2002/06/27/sinrod.htm Ruling in library Internet filter case was correct] ''USAToday.com''&lt;br /&gt;
*[http://www.accessmylibrary.com/coms2/summary_0286-8139694_ITM Oregon Libraries propose age-based filters] ''Accessmylibrary.com''&lt;/div&gt;</summary>
		<author><name>Mbastan</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379_SUM2008:Week_4,_Group_3&amp;diff=16696</id>
		<title>CSC 379 SUM2008:Week 4, Group 3</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=CSC_379_SUM2008:Week_4,_Group_3&amp;diff=16696"/>
		<updated>2008-08-02T02:11:56Z</updated>

		<summary type="html">&lt;p&gt;Mbastan: /* Policy Issues */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Many municipalities are beginning to provide free (taxpayer- or advertising-funded) citywide wireless Internet access.  Many municipalities are also considering filtering the connections, usually to stop pornography.  However, allowing the government to control information flow is fraught with danger to free speech, especially in the absence of any laws limiting the government's authority.  Examine the ethical considerations posed by filtering of municipal WAN connections.&lt;br /&gt;
&lt;br /&gt;
* http://www.wifinetnews.com/archives/006299.html&lt;br /&gt;
* http://people.w3.org/~djweitzner/blog/?p=90&lt;br /&gt;
&lt;br /&gt;
==Dangers of Internet Filtering==&lt;br /&gt;
* Who decides what is appropriate and what isn't?&lt;br /&gt;
** The first amendment guarantees the right to free speech, how can the government justify blocking certain webpages?&lt;br /&gt;
* What criteria are used to decide whether a website is obscene?&lt;br /&gt;
**[http://blogs.computerworld.com/censorship_with_your_free_wi_fi Example:] Denver airports block &amp;quot;racy&amp;quot; content&lt;br /&gt;
* Who is and isn't allowed to access certain material on public networks?&lt;br /&gt;
**[http://www.accessmylibrary.com/coms2/summary_0286-8139694_ITM Example:] Oregon County Libraries propose age-based internet filters&lt;br /&gt;
* Are there sufficient laws to protect user's rights?&lt;br /&gt;
**Most legislators are blissfully unaware of even the most basic computer/internet functions, who could possibly expect them to understand the complex legal issues involved with internet free speech?&lt;br /&gt;
&lt;br /&gt;
==Policy Issues==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;Working...&amp;gt;&lt;br /&gt;
&lt;br /&gt;
There is a policy question about whether—and under what conditions—government entities should get involved in the creation of MWNs. Internet service providers have started mounting legal challenges. For example, in the state of Pennsylvania, telecommunication providers successfully lobbied for the establishment of a law that forbids municipalities in most of the state from creating a MWN. However, after considerable debate, the city government of Philadelphia was able to receive an exemption from this law. So far, telecoms (such as the Baby Bells) and ISPs have successfully lobbied 14 states in the U.S. to pass laws prohibiting municipalities from building wireless networks because they are considered unfair competition [3]. The threat to entrenched interests goes beyond telecoms and ISPs because wireless Internet is seen as a disruptive technology that can displace traditional wired telephony, cellular service, and broadcast entertainment by delivering equivalent services at a lower cost to the consumer [8]. The telecoms and ISPs may have a point because municipalities in general have an advantage over them as they have ready and free access to public assets that can be used to mount network infrastructure equipment.&lt;br /&gt;
&lt;br /&gt;
A major policy challenge for a municipality is that MWNs come with an assortment of legal implications, involving matters such as who bears the responsibility for data security, related liabilities, operational performance, and customer service management. Finally, since MWNs operate over the public radio spectrum, they may face governmental regulatory constraints and licensing requirements.&lt;br /&gt;
&lt;br /&gt;
There remain fundamental unresolved policy questions such as:&lt;br /&gt;
&lt;br /&gt;
1. Are MWNs an example of the government competing with private business?&lt;br /&gt;
&lt;br /&gt;
2. Does free access to public facilities provide municipalities with an unfair advantage in competing with ISPs?&lt;br /&gt;
&lt;br /&gt;
3. Should public funds be used to support MWNs when the stakeholders are often entities such as state or city governments and other community groups that do not have experience in providing Internet service?&lt;br /&gt;
&lt;br /&gt;
4. Is there a need for new uniform legislation to handle the often-competing goals among MWN stakeholders? Clearly, implementers should first seek to understand and assess the legislative landscape in their community before embarking on the creation of a MWN.&lt;br /&gt;
&lt;br /&gt;
==Ethical Considerations==&lt;br /&gt;
Free municipal WiFi service offered by the City of Boston, for example, comes with mandatory content filtering that blocks all kinds of sites which are not even close to illegal nor are they sources of pornography that might be considered harmful to children. One the one hand it’s not hard to see why city officials want to avoid the headline: “Boston’s free network a conduit to porn for city’s children, foiling parents’ filtering software.” But does that mean that it’s either wise public policy or constitutionally-permissible for the city to offer wifi to the public with such sweeping and arbitrary constraints?&lt;br /&gt;
&lt;br /&gt;
==United States Policy==&lt;br /&gt;
As a constitutional matter, it’s not quite clear whether the government can require government-funded Internet service providers to filter content. In United States v. American Library Association, 539 U.S. 194 (2003), the US Supreme Court decided that the Congress could require libraries receiving federal Internet access subsidies (the e-rate) to filter out porn. However, it’s not clear whether this case applies to the municipal Wifi situation. The Supreme Court explained:&lt;br /&gt;
&lt;br /&gt;
&amp;quot;A public library does not acquire Internet terminals in order to &lt;br /&gt;
create a public forum for Web publishers to express themselves, &lt;br /&gt;
any more than it collects books in order to provide a public &lt;br /&gt;
forum for the authors of books to speak. It provides Internet &lt;br /&gt;
access, not to “encourage a diversity of views from private &lt;br /&gt;
speakers,” … but for the same reasons it offers other library &lt;br /&gt;
resources: to facilitate research, learning, and recreational &lt;br /&gt;
pursuits by furnishing materials of requisite and appropriate &lt;br /&gt;
quality.&lt;br /&gt;
&lt;br /&gt;
==Links and Resources==&lt;br /&gt;
*[http://blogs.computerworld.com/censorship_with_your_free_wi_fi Censorship with your Free Wifi?] ''Computer World''&lt;br /&gt;
*[http://www.csmonitor.com/2003/0305/p02s01-usju.html Should Libraries Censor Internet Access?] ''CSMonitor.com''&lt;br /&gt;
*[http://blog.librarylaw.com/librarylaw/2006/02/how_many_states.html How many states censor?] ''Librarylaw.com''&lt;br /&gt;
*[http://www.usatoday.com/tech/columnist/2002/06/27/sinrod.htm Ruling in library Internet filter case was correct] ''USAToday.com''&lt;br /&gt;
*[http://www.accessmylibrary.com/coms2/summary_0286-8139694_ITM Oregon Libraries propose age-based filters] ''Accessmylibrary.com''&lt;/div&gt;</summary>
		<author><name>Mbastan</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16471</id>
		<title>Phishing</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16471"/>
		<updated>2008-08-01T01:38:28Z</updated>

		<summary type="html">&lt;p&gt;Mbastan: /* Protection against Phishing attacks */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Study Guide=&lt;br /&gt;
&lt;br /&gt;
Phishing in computing is the process of acquiring private and sensitive information by pretending to be a trustworthy or a legitimate website through the online communications. Phishing is an example of fraudulent use of social engineering techniques to deceive an online service user. In this article some of the known attacks will be discussed following with some solutions to guard against these attackes.&lt;br /&gt;
&lt;br /&gt;
==Phishing Attacks==&lt;br /&gt;
&lt;br /&gt;
The followings are some of the way that the phishing attacks are taking place.&lt;br /&gt;
&lt;br /&gt;
====Keyloggers====&lt;br /&gt;
&lt;br /&gt;
These are spywares that can get installed either into a web browser or as a device driver. They record the user’s input to the computer by recording the keyboard keystrokes or mouse click. This information will be then sent to the spyware owner. These spywares can cause severe data leak.&lt;br /&gt;
&lt;br /&gt;
===Torpig-family Trojan===&lt;br /&gt;
&lt;br /&gt;
These Trojans are using advanced technologies that help them to spread very fast and hide very well. They are designed to hijack sessions. These Trojans are constantly monitoring major banks’ websites throughout the world. They display a fake page when a user tries to log in to these websites, and in this way continue to steal the private information of their victims.&lt;br /&gt;
&lt;br /&gt;
===Session Hijackers===&lt;br /&gt;
&lt;br /&gt;
These attacks can take place either from the malware that is installed on the victim’s computer or remotely. The attacks are triggered when users is trying to log into they account (usually bank accounts) or when they initiate a transaction. The malware then hijack the session for malicious purposes.&lt;br /&gt;
&lt;br /&gt;
===Content-Injection Phishing===&lt;br /&gt;
&lt;br /&gt;
This phishing refers to the situations when malicious or fake content get injected into some legitimate websites. These content then can abuse the users of the website by redirecting them to other websites, install malware on their computers, or redirect the input that users is inputting in that website to the phishing server.&lt;br /&gt;
&lt;br /&gt;
===“Universal” Man-in-the-middle phishing kit===&lt;br /&gt;
&lt;br /&gt;
There is only little effort required for the attackers to use this method to attack their victims. The attackers use a kit which is called MITM that includes several PHP files that get installed on the phishing server. This sever then acts as a median between the user and the legitimate website that he/she wants to access. These victims receive emails that includes a link to their know website. Once they click on the link, they’ll be redirected to the phishing server which then will communicate with the original website on behalf of the user.&lt;br /&gt;
&lt;br /&gt;
===Search Engine Phishing===&lt;br /&gt;
&lt;br /&gt;
In this type pf phishing, phishers establish a webpage, and then get it indexed by the search engines to make it searchable. These pages are usually designed to include items and services at very low price to attract visitors to sign up or to enter their confidential information. The phisher then get the hold of the private information of the visitors.&lt;br /&gt;
&lt;br /&gt;
===Spear Phishing===&lt;br /&gt;
&lt;br /&gt;
In this approach the phisher targets a particular person or a specific department in a company. The phisher then contacts the person by email and pretends to be from a legitimate department and is a trustworthy staff. The attacker then asks for the username and password with some fake reasons. Once the attacker get those information the can by pass the firewalls and break into the secured network.&lt;br /&gt;
&lt;br /&gt;
==Phishing solutions==&lt;br /&gt;
&lt;br /&gt;
To fight against the phishers, in the first place, the online service users should be educated. Once users know what phishing is and what methods phishers use, less people will fall for their tricks and many of their method then become useless. However some countermeasures have been developed and some of them are explained below.&lt;br /&gt;
&lt;br /&gt;
===Phishing blacklist===&lt;br /&gt;
&lt;br /&gt;
A server that is containing a list of all of the malicious websites and phishing servers should be established and be accessible by the internet browsers. The list should be updated on daily basis due to the lifetime of the phishing servers. The malicious URLs should be reported immediately.&lt;br /&gt;
&lt;br /&gt;
===Bookmarks or history===&lt;br /&gt;
&lt;br /&gt;
Using bookmarks and history to detect the list of the websites that the user uses. Then if a new website is visited randomly by the user that he/she did not visit before, chances are that this website is has malicious purposes. The down side of this method is that the history feature holds a history of the limited and short time.&lt;br /&gt;
&lt;br /&gt;
===Two-Way Authentication===&lt;br /&gt;
&lt;br /&gt;
In this method once a user signs up for an online service they receive and image in a secure way. Thereafter whenever the user visits the website and enters his/her username the website displays the image to prove its legitimacy. The user then can continue to enter his/her password.&lt;br /&gt;
&lt;br /&gt;
===VeriSign Identity Protection (VIP)===&lt;br /&gt;
&lt;br /&gt;
VIP has been design to protect the digital identities of the people who use online services. VIP provides number of rules that organizations should comply with if they want use VIP services. The VIP suite then provides a secure way for users to log into their account and transactions to take place.&lt;br /&gt;
&lt;br /&gt;
===Early alarm===&lt;br /&gt;
&lt;br /&gt;
This solution requires sort of add on tool to be installed on the web browsers. This tool contains several rules and ways to check the authentication of the websites. The tool will notify the user if the website is legitimate and trusted.&lt;br /&gt;
&lt;br /&gt;
=Bibliography=&lt;br /&gt;
===Privacy and ethical Issues===&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/xg41104w066612m7/fulltext.pdf Privacy and e-commerce: a consumer-centric perspective] Rhys Smith and Jianhua Shao, ''Electronic Commerce Research'', Volume 7, Number 2 / June, 2007 &lt;br /&gt;
&lt;br /&gt;
[http://www.mcgoverngreene.com/alerts/FA_pdfs/Oct-Nov_2004.pdf Phishers “net” unsuspecting consumers] ''fraud alert''  october/november 2004&lt;br /&gt;
&lt;br /&gt;
[http://delivery.acm.org.www.lib.ncsu.edu:2048/10.1145/1130000/1124861/p581-dhamija.pdf?key1=1124861&amp;amp;key2=4842557121&amp;amp;coll=ACM&amp;amp;dl=ACM&amp;amp;CFID=38796614&amp;amp;CFTOKEN=46500553 Why phishing works] Rachna Dhamija, J. D. Tygar, Marti Hearst&lt;br /&gt;
&lt;br /&gt;
[http://delivery.acm.org.www.lib.ncsu.edu:2048/10.1145/1080000/1073009/p77-dhamija.pdf?key1=1073009&amp;amp;key2=1444557121&amp;amp;coll=ACM&amp;amp;dl=ACM&amp;amp;CFID=38796614&amp;amp;CFTOKEN=46500553 The Battle Against Phishing: Dynamic Security Skins] Rachna Dhamija,  J. D. Tygar&lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/d284629556533224/fulltext.pdf A Revocation Scheme Preserving Privacy] Łukasz Krzywiecki, Przemysław Kubiak and Mirosław Kutyłowski &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/h62k448875177211/fulltext.pdf Security and Privacy as Market Failures]L. Jean Camp,''Economics of Identity Theft: Avoidance, Causes and Possible Cures'' &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/q808084h875464v5/fulltext.pdf Protection or Privacy? Data Mining and Personal Data] David J. Hand&lt;br /&gt;
&lt;br /&gt;
===Protection against Phishing attacks===&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/0p748n8766732770/fulltext.pdf Method for Evaluating the Security Risk of a Website Against Phishing Attacks] Young-Gab Kim, Sanghyun Cho, Jun-Sub Lee, Min-Soo Lee, In Ho Kim and Sung Hoon Kim &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/307774n374w42854/fulltext.pdf An Intrusion Detection System for Detecting Phishing Attacks] Hasika Pamunuwa, Duminda Wijesekera and Csilla Farkas &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/50hln6j1b04ftbw1/fulltext.pdf Protection Mechanisms Against Phishing Attacks] Klaus Plössl, Hannes Federrath and Thomas Nowey &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/w833450106412039/fulltext.pdf On the Effectiveness of Techniques to Detect Phishing Sites] Christian Ludl, Sean McAllister, Engin Kirda and Christopher Kruegel &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/bq4mj20enhm3ep0x/fulltext.pdf Effective Protection Against Phishing and Web Spoofing] Rolf Oppliger and Sebastian Gajek &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/w81x1n840w231177/fulltext.pdf Usability evaluation of anti-phishing toolbars] Linfeng Li and Marko Helenius&lt;/div&gt;</summary>
		<author><name>Mbastan</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16468</id>
		<title>Phishing</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16468"/>
		<updated>2008-08-01T01:36:18Z</updated>

		<summary type="html">&lt;p&gt;Mbastan: /* Privacy and ethical Issues */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Study Guide=&lt;br /&gt;
&lt;br /&gt;
Phishing in computing is the process of acquiring private and sensitive information by pretending to be a trustworthy or a legitimate website through the online communications. Phishing is an example of fraudulent use of social engineering techniques to deceive an online service user. In this article some of the known attacks will be discussed following with some solutions to guard against these attackes.&lt;br /&gt;
&lt;br /&gt;
==Phishing Attacks==&lt;br /&gt;
&lt;br /&gt;
The followings are some of the way that the phishing attacks are taking place.&lt;br /&gt;
&lt;br /&gt;
====Keyloggers====&lt;br /&gt;
&lt;br /&gt;
These are spywares that can get installed either into a web browser or as a device driver. They record the user’s input to the computer by recording the keyboard keystrokes or mouse click. This information will be then sent to the spyware owner. These spywares can cause severe data leak.&lt;br /&gt;
&lt;br /&gt;
===Torpig-family Trojan===&lt;br /&gt;
&lt;br /&gt;
These Trojans are using advanced technologies that help them to spread very fast and hide very well. They are designed to hijack sessions. These Trojans are constantly monitoring major banks’ websites throughout the world. They display a fake page when a user tries to log in to these websites, and in this way continue to steal the private information of their victims.&lt;br /&gt;
&lt;br /&gt;
===Session Hijackers===&lt;br /&gt;
&lt;br /&gt;
These attacks can take place either from the malware that is installed on the victim’s computer or remotely. The attacks are triggered when users is trying to log into they account (usually bank accounts) or when they initiate a transaction. The malware then hijack the session for malicious purposes.&lt;br /&gt;
&lt;br /&gt;
===Content-Injection Phishing===&lt;br /&gt;
&lt;br /&gt;
This phishing refers to the situations when malicious or fake content get injected into some legitimate websites. These content then can abuse the users of the website by redirecting them to other websites, install malware on their computers, or redirect the input that users is inputting in that website to the phishing server.&lt;br /&gt;
&lt;br /&gt;
===“Universal” Man-in-the-middle phishing kit===&lt;br /&gt;
&lt;br /&gt;
There is only little effort required for the attackers to use this method to attack their victims. The attackers use a kit which is called MITM that includes several PHP files that get installed on the phishing server. This sever then acts as a median between the user and the legitimate website that he/she wants to access. These victims receive emails that includes a link to their know website. Once they click on the link, they’ll be redirected to the phishing server which then will communicate with the original website on behalf of the user.&lt;br /&gt;
&lt;br /&gt;
===Search Engine Phishing===&lt;br /&gt;
&lt;br /&gt;
In this type pf phishing, phishers establish a webpage, and then get it indexed by the search engines to make it searchable. These pages are usually designed to include items and services at very low price to attract visitors to sign up or to enter their confidential information. The phisher then get the hold of the private information of the visitors.&lt;br /&gt;
&lt;br /&gt;
===Spear Phishing===&lt;br /&gt;
&lt;br /&gt;
In this approach the phisher targets a particular person or a specific department in a company. The phisher then contacts the person by email and pretends to be from a legitimate department and is a trustworthy staff. The attacker then asks for the username and password with some fake reasons. Once the attacker get those information the can by pass the firewalls and break into the secured network.&lt;br /&gt;
&lt;br /&gt;
==Phishing solutions==&lt;br /&gt;
&lt;br /&gt;
To fight against the phishers, in the first place, the online service users should be educated. Once users know what phishing is and what methods phishers use, less people will fall for their tricks and many of their method then become useless. However some countermeasures have been developed and some of them are explained below.&lt;br /&gt;
&lt;br /&gt;
===Phishing blacklist===&lt;br /&gt;
&lt;br /&gt;
A server that is containing a list of all of the malicious websites and phishing servers should be established and be accessible by the internet browsers. The list should be updated on daily basis due to the lifetime of the phishing servers. The malicious URLs should be reported immediately.&lt;br /&gt;
&lt;br /&gt;
===Bookmarks or history===&lt;br /&gt;
&lt;br /&gt;
Using bookmarks and history to detect the list of the websites that the user uses. Then if a new website is visited randomly by the user that he/she did not visit before, chances are that this website is has malicious purposes. The down side of this method is that the history feature holds a history of the limited and short time.&lt;br /&gt;
&lt;br /&gt;
===Two-Way Authentication===&lt;br /&gt;
&lt;br /&gt;
In this method once a user signs up for an online service they receive and image in a secure way. Thereafter whenever the user visits the website and enters his/her username the website displays the image to prove its legitimacy. The user then can continue to enter his/her password.&lt;br /&gt;
&lt;br /&gt;
===VeriSign Identity Protection (VIP)===&lt;br /&gt;
&lt;br /&gt;
VIP has been design to protect the digital identities of the people who use online services. VIP provides number of rules that organizations should comply with if they want use VIP services. The VIP suite then provides a secure way for users to log into their account and transactions to take place.&lt;br /&gt;
&lt;br /&gt;
===Early alarm===&lt;br /&gt;
&lt;br /&gt;
This solution requires sort of add on tool to be installed on the web browsers. This tool contains several rules and ways to check the authentication of the websites. The tool will notify the user if the website is legitimate and trusted.&lt;br /&gt;
&lt;br /&gt;
=Bibliography=&lt;br /&gt;
===Privacy and ethical Issues===&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/xg41104w066612m7/fulltext.pdf Privacy and e-commerce: a consumer-centric perspective] Rhys Smith and Jianhua Shao, ''Electronic Commerce Research'', Volume 7, Number 2 / June, 2007 &lt;br /&gt;
&lt;br /&gt;
[http://www.mcgoverngreene.com/alerts/FA_pdfs/Oct-Nov_2004.pdf Phishers “net” unsuspecting consumers] ''fraud alert''  october/november 2004&lt;br /&gt;
&lt;br /&gt;
[http://delivery.acm.org.www.lib.ncsu.edu:2048/10.1145/1130000/1124861/p581-dhamija.pdf?key1=1124861&amp;amp;key2=4842557121&amp;amp;coll=ACM&amp;amp;dl=ACM&amp;amp;CFID=38796614&amp;amp;CFTOKEN=46500553 Why phishing works] Rachna Dhamija, J. D. Tygar, Marti Hearst&lt;br /&gt;
&lt;br /&gt;
[http://delivery.acm.org.www.lib.ncsu.edu:2048/10.1145/1080000/1073009/p77-dhamija.pdf?key1=1073009&amp;amp;key2=1444557121&amp;amp;coll=ACM&amp;amp;dl=ACM&amp;amp;CFID=38796614&amp;amp;CFTOKEN=46500553 The Battle Against Phishing: Dynamic Security Skins] Rachna Dhamija,  J. D. Tygar&lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/d284629556533224/fulltext.pdf A Revocation Scheme Preserving Privacy] Łukasz Krzywiecki, Przemysław Kubiak and Mirosław Kutyłowski &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/h62k448875177211/fulltext.pdf Security and Privacy as Market Failures]L. Jean Camp,''Economics of Identity Theft: Avoidance, Causes and Possible Cures'' &lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/q808084h875464v5/fulltext.pdf Protection or Privacy? Data Mining and Personal Data] David J. Hand&lt;br /&gt;
&lt;br /&gt;
===Protection against Phishing attacks===&lt;/div&gt;</summary>
		<author><name>Mbastan</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16467</id>
		<title>Phishing</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16467"/>
		<updated>2008-08-01T01:36:00Z</updated>

		<summary type="html">&lt;p&gt;Mbastan: /* Privacy and ethical Issues */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Study Guide=&lt;br /&gt;
&lt;br /&gt;
Phishing in computing is the process of acquiring private and sensitive information by pretending to be a trustworthy or a legitimate website through the online communications. Phishing is an example of fraudulent use of social engineering techniques to deceive an online service user. In this article some of the known attacks will be discussed following with some solutions to guard against these attackes.&lt;br /&gt;
&lt;br /&gt;
==Phishing Attacks==&lt;br /&gt;
&lt;br /&gt;
The followings are some of the way that the phishing attacks are taking place.&lt;br /&gt;
&lt;br /&gt;
====Keyloggers====&lt;br /&gt;
&lt;br /&gt;
These are spywares that can get installed either into a web browser or as a device driver. They record the user’s input to the computer by recording the keyboard keystrokes or mouse click. This information will be then sent to the spyware owner. These spywares can cause severe data leak.&lt;br /&gt;
&lt;br /&gt;
===Torpig-family Trojan===&lt;br /&gt;
&lt;br /&gt;
These Trojans are using advanced technologies that help them to spread very fast and hide very well. They are designed to hijack sessions. These Trojans are constantly monitoring major banks’ websites throughout the world. They display a fake page when a user tries to log in to these websites, and in this way continue to steal the private information of their victims.&lt;br /&gt;
&lt;br /&gt;
===Session Hijackers===&lt;br /&gt;
&lt;br /&gt;
These attacks can take place either from the malware that is installed on the victim’s computer or remotely. The attacks are triggered when users is trying to log into they account (usually bank accounts) or when they initiate a transaction. The malware then hijack the session for malicious purposes.&lt;br /&gt;
&lt;br /&gt;
===Content-Injection Phishing===&lt;br /&gt;
&lt;br /&gt;
This phishing refers to the situations when malicious or fake content get injected into some legitimate websites. These content then can abuse the users of the website by redirecting them to other websites, install malware on their computers, or redirect the input that users is inputting in that website to the phishing server.&lt;br /&gt;
&lt;br /&gt;
===“Universal” Man-in-the-middle phishing kit===&lt;br /&gt;
&lt;br /&gt;
There is only little effort required for the attackers to use this method to attack their victims. The attackers use a kit which is called MITM that includes several PHP files that get installed on the phishing server. This sever then acts as a median between the user and the legitimate website that he/she wants to access. These victims receive emails that includes a link to their know website. Once they click on the link, they’ll be redirected to the phishing server which then will communicate with the original website on behalf of the user.&lt;br /&gt;
&lt;br /&gt;
===Search Engine Phishing===&lt;br /&gt;
&lt;br /&gt;
In this type pf phishing, phishers establish a webpage, and then get it indexed by the search engines to make it searchable. These pages are usually designed to include items and services at very low price to attract visitors to sign up or to enter their confidential information. The phisher then get the hold of the private information of the visitors.&lt;br /&gt;
&lt;br /&gt;
===Spear Phishing===&lt;br /&gt;
&lt;br /&gt;
In this approach the phisher targets a particular person or a specific department in a company. The phisher then contacts the person by email and pretends to be from a legitimate department and is a trustworthy staff. The attacker then asks for the username and password with some fake reasons. Once the attacker get those information the can by pass the firewalls and break into the secured network.&lt;br /&gt;
&lt;br /&gt;
==Phishing solutions==&lt;br /&gt;
&lt;br /&gt;
To fight against the phishers, in the first place, the online service users should be educated. Once users know what phishing is and what methods phishers use, less people will fall for their tricks and many of their method then become useless. However some countermeasures have been developed and some of them are explained below.&lt;br /&gt;
&lt;br /&gt;
===Phishing blacklist===&lt;br /&gt;
&lt;br /&gt;
A server that is containing a list of all of the malicious websites and phishing servers should be established and be accessible by the internet browsers. The list should be updated on daily basis due to the lifetime of the phishing servers. The malicious URLs should be reported immediately.&lt;br /&gt;
&lt;br /&gt;
===Bookmarks or history===&lt;br /&gt;
&lt;br /&gt;
Using bookmarks and history to detect the list of the websites that the user uses. Then if a new website is visited randomly by the user that he/she did not visit before, chances are that this website is has malicious purposes. The down side of this method is that the history feature holds a history of the limited and short time.&lt;br /&gt;
&lt;br /&gt;
===Two-Way Authentication===&lt;br /&gt;
&lt;br /&gt;
In this method once a user signs up for an online service they receive and image in a secure way. Thereafter whenever the user visits the website and enters his/her username the website displays the image to prove its legitimacy. The user then can continue to enter his/her password.&lt;br /&gt;
&lt;br /&gt;
===VeriSign Identity Protection (VIP)===&lt;br /&gt;
&lt;br /&gt;
VIP has been design to protect the digital identities of the people who use online services. VIP provides number of rules that organizations should comply with if they want use VIP services. The VIP suite then provides a secure way for users to log into their account and transactions to take place.&lt;br /&gt;
&lt;br /&gt;
===Early alarm===&lt;br /&gt;
&lt;br /&gt;
This solution requires sort of add on tool to be installed on the web browsers. This tool contains several rules and ways to check the authentication of the websites. The tool will notify the user if the website is legitimate and trusted.&lt;br /&gt;
&lt;br /&gt;
=Bibliography=&lt;br /&gt;
===Privacy and ethical Issues===&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/xg41104w066612m7/fulltext.pdf Privacy and e-commerce: a consumer-centric perspective] Rhys Smith and Jianhua Shao, ''Electronic Commerce Research'', Volume 7, Number 2 / June, 2007 &lt;br /&gt;
&lt;br /&gt;
[http://www.mcgoverngreene.com/alerts/FA_pdfs/Oct-Nov_2004.pdf Phishers “net” unsuspecting consumers] ''fraud alert''  october/november 2004&lt;br /&gt;
&lt;br /&gt;
[http://delivery.acm.org.www.lib.ncsu.edu:2048/10.1145/1130000/1124861/p581-dhamija.pdf?key1=1124861&amp;amp;key2=4842557121&amp;amp;coll=ACM&amp;amp;dl=ACM&amp;amp;CFID=38796614&amp;amp;CFTOKEN=46500553 Why phishing works] Rachna Dhamija, J. D. Tygar, Marti Hearst&lt;br /&gt;
&lt;br /&gt;
[http://delivery.acm.org.www.lib.ncsu.edu:2048/10.1145/1080000/1073009/p77-dhamija.pdf?key1=1073009&amp;amp;key2=1444557121&amp;amp;coll=ACM&amp;amp;dl=ACM&amp;amp;CFID=38796614&amp;amp;CFTOKEN=46500553 The Battle Against Phishing: Dynamic Security Skins] Rachna Dhamija,  J. D. Tygar&lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/d284629556533224/fulltext.pdf A Revocation Scheme Preserving Privacy] Łukasz Krzywiecki, Przemysław Kubiak and Mirosław Kutyłowski &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/h62k448875177211/fulltext.pdf Security and Privacy as Market Failures]L. Jean Camp,''Economics of Identity Theft: Avoidance, Causes and Possible Cures'' &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/q808084h875464v5/fulltext.pdf Protection or Privacy? Data Mining and Personal Data] David J. Hand&lt;br /&gt;
&lt;br /&gt;
===Protection against Phishing attacks===&lt;/div&gt;</summary>
		<author><name>Mbastan</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16466</id>
		<title>Phishing</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16466"/>
		<updated>2008-08-01T01:34:42Z</updated>

		<summary type="html">&lt;p&gt;Mbastan: /* Privacy and ethical Issues */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Study Guide=&lt;br /&gt;
&lt;br /&gt;
Phishing in computing is the process of acquiring private and sensitive information by pretending to be a trustworthy or a legitimate website through the online communications. Phishing is an example of fraudulent use of social engineering techniques to deceive an online service user. In this article some of the known attacks will be discussed following with some solutions to guard against these attackes.&lt;br /&gt;
&lt;br /&gt;
==Phishing Attacks==&lt;br /&gt;
&lt;br /&gt;
The followings are some of the way that the phishing attacks are taking place.&lt;br /&gt;
&lt;br /&gt;
====Keyloggers====&lt;br /&gt;
&lt;br /&gt;
These are spywares that can get installed either into a web browser or as a device driver. They record the user’s input to the computer by recording the keyboard keystrokes or mouse click. This information will be then sent to the spyware owner. These spywares can cause severe data leak.&lt;br /&gt;
&lt;br /&gt;
===Torpig-family Trojan===&lt;br /&gt;
&lt;br /&gt;
These Trojans are using advanced technologies that help them to spread very fast and hide very well. They are designed to hijack sessions. These Trojans are constantly monitoring major banks’ websites throughout the world. They display a fake page when a user tries to log in to these websites, and in this way continue to steal the private information of their victims.&lt;br /&gt;
&lt;br /&gt;
===Session Hijackers===&lt;br /&gt;
&lt;br /&gt;
These attacks can take place either from the malware that is installed on the victim’s computer or remotely. The attacks are triggered when users is trying to log into they account (usually bank accounts) or when they initiate a transaction. The malware then hijack the session for malicious purposes.&lt;br /&gt;
&lt;br /&gt;
===Content-Injection Phishing===&lt;br /&gt;
&lt;br /&gt;
This phishing refers to the situations when malicious or fake content get injected into some legitimate websites. These content then can abuse the users of the website by redirecting them to other websites, install malware on their computers, or redirect the input that users is inputting in that website to the phishing server.&lt;br /&gt;
&lt;br /&gt;
===“Universal” Man-in-the-middle phishing kit===&lt;br /&gt;
&lt;br /&gt;
There is only little effort required for the attackers to use this method to attack their victims. The attackers use a kit which is called MITM that includes several PHP files that get installed on the phishing server. This sever then acts as a median between the user and the legitimate website that he/she wants to access. These victims receive emails that includes a link to their know website. Once they click on the link, they’ll be redirected to the phishing server which then will communicate with the original website on behalf of the user.&lt;br /&gt;
&lt;br /&gt;
===Search Engine Phishing===&lt;br /&gt;
&lt;br /&gt;
In this type pf phishing, phishers establish a webpage, and then get it indexed by the search engines to make it searchable. These pages are usually designed to include items and services at very low price to attract visitors to sign up or to enter their confidential information. The phisher then get the hold of the private information of the visitors.&lt;br /&gt;
&lt;br /&gt;
===Spear Phishing===&lt;br /&gt;
&lt;br /&gt;
In this approach the phisher targets a particular person or a specific department in a company. The phisher then contacts the person by email and pretends to be from a legitimate department and is a trustworthy staff. The attacker then asks for the username and password with some fake reasons. Once the attacker get those information the can by pass the firewalls and break into the secured network.&lt;br /&gt;
&lt;br /&gt;
==Phishing solutions==&lt;br /&gt;
&lt;br /&gt;
To fight against the phishers, in the first place, the online service users should be educated. Once users know what phishing is and what methods phishers use, less people will fall for their tricks and many of their method then become useless. However some countermeasures have been developed and some of them are explained below.&lt;br /&gt;
&lt;br /&gt;
===Phishing blacklist===&lt;br /&gt;
&lt;br /&gt;
A server that is containing a list of all of the malicious websites and phishing servers should be established and be accessible by the internet browsers. The list should be updated on daily basis due to the lifetime of the phishing servers. The malicious URLs should be reported immediately.&lt;br /&gt;
&lt;br /&gt;
===Bookmarks or history===&lt;br /&gt;
&lt;br /&gt;
Using bookmarks and history to detect the list of the websites that the user uses. Then if a new website is visited randomly by the user that he/she did not visit before, chances are that this website is has malicious purposes. The down side of this method is that the history feature holds a history of the limited and short time.&lt;br /&gt;
&lt;br /&gt;
===Two-Way Authentication===&lt;br /&gt;
&lt;br /&gt;
In this method once a user signs up for an online service they receive and image in a secure way. Thereafter whenever the user visits the website and enters his/her username the website displays the image to prove its legitimacy. The user then can continue to enter his/her password.&lt;br /&gt;
&lt;br /&gt;
===VeriSign Identity Protection (VIP)===&lt;br /&gt;
&lt;br /&gt;
VIP has been design to protect the digital identities of the people who use online services. VIP provides number of rules that organizations should comply with if they want use VIP services. The VIP suite then provides a secure way for users to log into their account and transactions to take place.&lt;br /&gt;
&lt;br /&gt;
===Early alarm===&lt;br /&gt;
&lt;br /&gt;
This solution requires sort of add on tool to be installed on the web browsers. This tool contains several rules and ways to check the authentication of the websites. The tool will notify the user if the website is legitimate and trusted.&lt;br /&gt;
&lt;br /&gt;
=Bibliography=&lt;br /&gt;
===Privacy and ethical Issues===&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/xg41104w066612m7/fulltext.pdf Privacy and e-commerce: a consumer-centric perspective] Rhys Smith and Jianhua Shao, ''Electronic Commerce Research'', Volume 7, Number 2 / June, 2007 &lt;br /&gt;
&lt;br /&gt;
[http://www.mcgoverngreene.com/alerts/FA_pdfs/Oct-Nov_2004.pdf Phishers “net” unsuspecting consumers] ''fraud alert''  october/november 2004&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://delivery.acm.org.www.lib.ncsu.edu:2048/10.1145/1130000/1124861/p581-dhamija.pdf?key1=1124861&amp;amp;key2=4842557121&amp;amp;coll=ACM&amp;amp;dl=ACM&amp;amp;CFID=38796614&amp;amp;CFTOKEN=46500553 Why phishing works] Rachna Dhamija, J. D. Tygar, Marti Hearst&lt;br /&gt;
&lt;br /&gt;
[http://delivery.acm.org.www.lib.ncsu.edu:2048/10.1145/1080000/1073009/p77-dhamija.pdf?key1=1073009&amp;amp;key2=1444557121&amp;amp;coll=ACM&amp;amp;dl=ACM&amp;amp;CFID=38796614&amp;amp;CFTOKEN=46500553 The Battle Against Phishing: Dynamic Security Skins] Rachna Dhamija,  J. D. Tygar&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
http://www.springerlink.com.www.lib.ncsu.edu:2048/content/d284629556533224/fulltext.pdf&lt;br /&gt;
A Revocation Scheme Preserving Privacy &lt;br /&gt;
Łukasz Krzywiecki, Przemysław Kubiak and Mirosław Kutyłowski &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
http://www.springerlink.com.www.lib.ncsu.edu:2048/content/h62k448875177211/fulltext.pdf&lt;br /&gt;
Security and Privacy as Market Failures &lt;br /&gt;
L. Jean Camp &lt;br /&gt;
Economics of Identity Theft: Avoidance, Causes and Possible Cures &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
http://www.springerlink.com.www.lib.ncsu.edu:2048/content/q808084h875464v5/fulltext.pdf&lt;br /&gt;
Protection or Privacy? Data Mining and Personal Data &lt;br /&gt;
David J. Hand&lt;br /&gt;
&lt;br /&gt;
===Protection against Phishing attacks===&lt;/div&gt;</summary>
		<author><name>Mbastan</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16465</id>
		<title>Phishing</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16465"/>
		<updated>2008-08-01T01:33:33Z</updated>

		<summary type="html">&lt;p&gt;Mbastan: /* Privacy and ethical Issues */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Study Guide=&lt;br /&gt;
&lt;br /&gt;
Phishing in computing is the process of acquiring private and sensitive information by pretending to be a trustworthy or a legitimate website through the online communications. Phishing is an example of fraudulent use of social engineering techniques to deceive an online service user. In this article some of the known attacks will be discussed following with some solutions to guard against these attackes.&lt;br /&gt;
&lt;br /&gt;
==Phishing Attacks==&lt;br /&gt;
&lt;br /&gt;
The followings are some of the way that the phishing attacks are taking place.&lt;br /&gt;
&lt;br /&gt;
====Keyloggers====&lt;br /&gt;
&lt;br /&gt;
These are spywares that can get installed either into a web browser or as a device driver. They record the user’s input to the computer by recording the keyboard keystrokes or mouse click. This information will be then sent to the spyware owner. These spywares can cause severe data leak.&lt;br /&gt;
&lt;br /&gt;
===Torpig-family Trojan===&lt;br /&gt;
&lt;br /&gt;
These Trojans are using advanced technologies that help them to spread very fast and hide very well. They are designed to hijack sessions. These Trojans are constantly monitoring major banks’ websites throughout the world. They display a fake page when a user tries to log in to these websites, and in this way continue to steal the private information of their victims.&lt;br /&gt;
&lt;br /&gt;
===Session Hijackers===&lt;br /&gt;
&lt;br /&gt;
These attacks can take place either from the malware that is installed on the victim’s computer or remotely. The attacks are triggered when users is trying to log into they account (usually bank accounts) or when they initiate a transaction. The malware then hijack the session for malicious purposes.&lt;br /&gt;
&lt;br /&gt;
===Content-Injection Phishing===&lt;br /&gt;
&lt;br /&gt;
This phishing refers to the situations when malicious or fake content get injected into some legitimate websites. These content then can abuse the users of the website by redirecting them to other websites, install malware on their computers, or redirect the input that users is inputting in that website to the phishing server.&lt;br /&gt;
&lt;br /&gt;
===“Universal” Man-in-the-middle phishing kit===&lt;br /&gt;
&lt;br /&gt;
There is only little effort required for the attackers to use this method to attack their victims. The attackers use a kit which is called MITM that includes several PHP files that get installed on the phishing server. This sever then acts as a median between the user and the legitimate website that he/she wants to access. These victims receive emails that includes a link to their know website. Once they click on the link, they’ll be redirected to the phishing server which then will communicate with the original website on behalf of the user.&lt;br /&gt;
&lt;br /&gt;
===Search Engine Phishing===&lt;br /&gt;
&lt;br /&gt;
In this type pf phishing, phishers establish a webpage, and then get it indexed by the search engines to make it searchable. These pages are usually designed to include items and services at very low price to attract visitors to sign up or to enter their confidential information. The phisher then get the hold of the private information of the visitors.&lt;br /&gt;
&lt;br /&gt;
===Spear Phishing===&lt;br /&gt;
&lt;br /&gt;
In this approach the phisher targets a particular person or a specific department in a company. The phisher then contacts the person by email and pretends to be from a legitimate department and is a trustworthy staff. The attacker then asks for the username and password with some fake reasons. Once the attacker get those information the can by pass the firewalls and break into the secured network.&lt;br /&gt;
&lt;br /&gt;
==Phishing solutions==&lt;br /&gt;
&lt;br /&gt;
To fight against the phishers, in the first place, the online service users should be educated. Once users know what phishing is and what methods phishers use, less people will fall for their tricks and many of their method then become useless. However some countermeasures have been developed and some of them are explained below.&lt;br /&gt;
&lt;br /&gt;
===Phishing blacklist===&lt;br /&gt;
&lt;br /&gt;
A server that is containing a list of all of the malicious websites and phishing servers should be established and be accessible by the internet browsers. The list should be updated on daily basis due to the lifetime of the phishing servers. The malicious URLs should be reported immediately.&lt;br /&gt;
&lt;br /&gt;
===Bookmarks or history===&lt;br /&gt;
&lt;br /&gt;
Using bookmarks and history to detect the list of the websites that the user uses. Then if a new website is visited randomly by the user that he/she did not visit before, chances are that this website is has malicious purposes. The down side of this method is that the history feature holds a history of the limited and short time.&lt;br /&gt;
&lt;br /&gt;
===Two-Way Authentication===&lt;br /&gt;
&lt;br /&gt;
In this method once a user signs up for an online service they receive and image in a secure way. Thereafter whenever the user visits the website and enters his/her username the website displays the image to prove its legitimacy. The user then can continue to enter his/her password.&lt;br /&gt;
&lt;br /&gt;
===VeriSign Identity Protection (VIP)===&lt;br /&gt;
&lt;br /&gt;
VIP has been design to protect the digital identities of the people who use online services. VIP provides number of rules that organizations should comply with if they want use VIP services. The VIP suite then provides a secure way for users to log into their account and transactions to take place.&lt;br /&gt;
&lt;br /&gt;
===Early alarm===&lt;br /&gt;
&lt;br /&gt;
This solution requires sort of add on tool to be installed on the web browsers. This tool contains several rules and ways to check the authentication of the websites. The tool will notify the user if the website is legitimate and trusted.&lt;br /&gt;
&lt;br /&gt;
=Bibliography=&lt;br /&gt;
===Privacy and ethical Issues===&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/xg41104w066612m7/fulltext.pdf Privacy and e-commerce: a consumer-centric perspective] Rhys Smith and Jianhua Shao, ''Electronic Commerce Research'', Volume 7, Number 2 / June, 2007 &lt;br /&gt;
&lt;br /&gt;
[http://www.mcgoverngreene.com/alerts/FA_pdfs/Oct-Nov_2004.pdf Phishers “net” unsuspecting consumers] ''fraud alert''  october/november 2004&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://delivery.acm.org.www.lib.ncsu.edu:2048/10.1145/1130000/1124861/p581-dhamija.pdf?key1=1124861&amp;amp;key2=4842557121&amp;amp;coll=ACM&amp;amp;dl=ACM&amp;amp;CFID=38796614&amp;amp;CFTOKEN=46500553 Why phishing works] Rachna Dhamija, J. D. Tygar, Marti Hearst&lt;br /&gt;
&lt;br /&gt;
The Battle Against Phishing: Dynamic Security Skins Rachna Dhamija,  J. D. Tygar&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
http://www.springerlink.com.www.lib.ncsu.edu:2048/content/d284629556533224/fulltext.pdf&lt;br /&gt;
A Revocation Scheme Preserving Privacy &lt;br /&gt;
Łukasz Krzywiecki, Przemysław Kubiak and Mirosław Kutyłowski &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
http://www.springerlink.com.www.lib.ncsu.edu:2048/content/h62k448875177211/fulltext.pdf&lt;br /&gt;
Security and Privacy as Market Failures &lt;br /&gt;
L. Jean Camp &lt;br /&gt;
Economics of Identity Theft: Avoidance, Causes and Possible Cures &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
http://www.springerlink.com.www.lib.ncsu.edu:2048/content/q808084h875464v5/fulltext.pdf&lt;br /&gt;
Protection or Privacy? Data Mining and Personal Data &lt;br /&gt;
David J. Hand&lt;br /&gt;
&lt;br /&gt;
===Protection against Phishing attacks===&lt;/div&gt;</summary>
		<author><name>Mbastan</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16464</id>
		<title>Phishing</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16464"/>
		<updated>2008-08-01T01:33:11Z</updated>

		<summary type="html">&lt;p&gt;Mbastan: /* Privacy and ethical Issues */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Study Guide=&lt;br /&gt;
&lt;br /&gt;
Phishing in computing is the process of acquiring private and sensitive information by pretending to be a trustworthy or a legitimate website through the online communications. Phishing is an example of fraudulent use of social engineering techniques to deceive an online service user. In this article some of the known attacks will be discussed following with some solutions to guard against these attackes.&lt;br /&gt;
&lt;br /&gt;
==Phishing Attacks==&lt;br /&gt;
&lt;br /&gt;
The followings are some of the way that the phishing attacks are taking place.&lt;br /&gt;
&lt;br /&gt;
====Keyloggers====&lt;br /&gt;
&lt;br /&gt;
These are spywares that can get installed either into a web browser or as a device driver. They record the user’s input to the computer by recording the keyboard keystrokes or mouse click. This information will be then sent to the spyware owner. These spywares can cause severe data leak.&lt;br /&gt;
&lt;br /&gt;
===Torpig-family Trojan===&lt;br /&gt;
&lt;br /&gt;
These Trojans are using advanced technologies that help them to spread very fast and hide very well. They are designed to hijack sessions. These Trojans are constantly monitoring major banks’ websites throughout the world. They display a fake page when a user tries to log in to these websites, and in this way continue to steal the private information of their victims.&lt;br /&gt;
&lt;br /&gt;
===Session Hijackers===&lt;br /&gt;
&lt;br /&gt;
These attacks can take place either from the malware that is installed on the victim’s computer or remotely. The attacks are triggered when users is trying to log into they account (usually bank accounts) or when they initiate a transaction. The malware then hijack the session for malicious purposes.&lt;br /&gt;
&lt;br /&gt;
===Content-Injection Phishing===&lt;br /&gt;
&lt;br /&gt;
This phishing refers to the situations when malicious or fake content get injected into some legitimate websites. These content then can abuse the users of the website by redirecting them to other websites, install malware on their computers, or redirect the input that users is inputting in that website to the phishing server.&lt;br /&gt;
&lt;br /&gt;
===“Universal” Man-in-the-middle phishing kit===&lt;br /&gt;
&lt;br /&gt;
There is only little effort required for the attackers to use this method to attack their victims. The attackers use a kit which is called MITM that includes several PHP files that get installed on the phishing server. This sever then acts as a median between the user and the legitimate website that he/she wants to access. These victims receive emails that includes a link to their know website. Once they click on the link, they’ll be redirected to the phishing server which then will communicate with the original website on behalf of the user.&lt;br /&gt;
&lt;br /&gt;
===Search Engine Phishing===&lt;br /&gt;
&lt;br /&gt;
In this type pf phishing, phishers establish a webpage, and then get it indexed by the search engines to make it searchable. These pages are usually designed to include items and services at very low price to attract visitors to sign up or to enter their confidential information. The phisher then get the hold of the private information of the visitors.&lt;br /&gt;
&lt;br /&gt;
===Spear Phishing===&lt;br /&gt;
&lt;br /&gt;
In this approach the phisher targets a particular person or a specific department in a company. The phisher then contacts the person by email and pretends to be from a legitimate department and is a trustworthy staff. The attacker then asks for the username and password with some fake reasons. Once the attacker get those information the can by pass the firewalls and break into the secured network.&lt;br /&gt;
&lt;br /&gt;
==Phishing solutions==&lt;br /&gt;
&lt;br /&gt;
To fight against the phishers, in the first place, the online service users should be educated. Once users know what phishing is and what methods phishers use, less people will fall for their tricks and many of their method then become useless. However some countermeasures have been developed and some of them are explained below.&lt;br /&gt;
&lt;br /&gt;
===Phishing blacklist===&lt;br /&gt;
&lt;br /&gt;
A server that is containing a list of all of the malicious websites and phishing servers should be established and be accessible by the internet browsers. The list should be updated on daily basis due to the lifetime of the phishing servers. The malicious URLs should be reported immediately.&lt;br /&gt;
&lt;br /&gt;
===Bookmarks or history===&lt;br /&gt;
&lt;br /&gt;
Using bookmarks and history to detect the list of the websites that the user uses. Then if a new website is visited randomly by the user that he/she did not visit before, chances are that this website is has malicious purposes. The down side of this method is that the history feature holds a history of the limited and short time.&lt;br /&gt;
&lt;br /&gt;
===Two-Way Authentication===&lt;br /&gt;
&lt;br /&gt;
In this method once a user signs up for an online service they receive and image in a secure way. Thereafter whenever the user visits the website and enters his/her username the website displays the image to prove its legitimacy. The user then can continue to enter his/her password.&lt;br /&gt;
&lt;br /&gt;
===VeriSign Identity Protection (VIP)===&lt;br /&gt;
&lt;br /&gt;
VIP has been design to protect the digital identities of the people who use online services. VIP provides number of rules that organizations should comply with if they want use VIP services. The VIP suite then provides a secure way for users to log into their account and transactions to take place.&lt;br /&gt;
&lt;br /&gt;
===Early alarm===&lt;br /&gt;
&lt;br /&gt;
This solution requires sort of add on tool to be installed on the web browsers. This tool contains several rules and ways to check the authentication of the websites. The tool will notify the user if the website is legitimate and trusted.&lt;br /&gt;
&lt;br /&gt;
=Bibliography=&lt;br /&gt;
===Privacy and ethical Issues===&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/xg41104w066612m7/fulltext.pdf Privacy and e-commerce: a consumer-centric perspective] Rhys Smith and Jianhua Shao, ''Electronic Commerce Research'', Volume 7, Number 2 / June, 2007 &lt;br /&gt;
&lt;br /&gt;
[http://www.mcgoverngreene.com/alerts/FA_pdfs/Oct-Nov_2004.pdf Phishers “net” unsuspecting consumers] ''fraud alert''  october/november 2004&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://delivery.acm.org.www.lib.ncsu.edu:2048/10.1145/1130000/1124861/p581-dhamija.pdf?key1=1124861&amp;amp;key2=4842557121&amp;amp;coll=ACM&amp;amp;dl=ACM&amp;amp;CFID=38796614&amp;amp;CFTOKEN=46500553&lt;br /&gt;
Why phishing works] Rachna Dhamija, J. D. Tygar, Marti Hearst&lt;br /&gt;
&lt;br /&gt;
The Battle Against Phishing: Dynamic Security Skins Rachna Dhamija,  J. D. Tygar&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
http://www.springerlink.com.www.lib.ncsu.edu:2048/content/d284629556533224/fulltext.pdf&lt;br /&gt;
A Revocation Scheme Preserving Privacy &lt;br /&gt;
Łukasz Krzywiecki, Przemysław Kubiak and Mirosław Kutyłowski &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
http://www.springerlink.com.www.lib.ncsu.edu:2048/content/h62k448875177211/fulltext.pdf&lt;br /&gt;
Security and Privacy as Market Failures &lt;br /&gt;
L. Jean Camp &lt;br /&gt;
Economics of Identity Theft: Avoidance, Causes and Possible Cures &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
http://www.springerlink.com.www.lib.ncsu.edu:2048/content/q808084h875464v5/fulltext.pdf&lt;br /&gt;
Protection or Privacy? Data Mining and Personal Data &lt;br /&gt;
David J. Hand&lt;br /&gt;
&lt;br /&gt;
===Protection against Phishing attacks===&lt;/div&gt;</summary>
		<author><name>Mbastan</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16462</id>
		<title>Phishing</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16462"/>
		<updated>2008-08-01T01:32:06Z</updated>

		<summary type="html">&lt;p&gt;Mbastan: /* Privacy and ethical Issues */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Study Guide=&lt;br /&gt;
&lt;br /&gt;
Phishing in computing is the process of acquiring private and sensitive information by pretending to be a trustworthy or a legitimate website through the online communications. Phishing is an example of fraudulent use of social engineering techniques to deceive an online service user. In this article some of the known attacks will be discussed following with some solutions to guard against these attackes.&lt;br /&gt;
&lt;br /&gt;
==Phishing Attacks==&lt;br /&gt;
&lt;br /&gt;
The followings are some of the way that the phishing attacks are taking place.&lt;br /&gt;
&lt;br /&gt;
====Keyloggers====&lt;br /&gt;
&lt;br /&gt;
These are spywares that can get installed either into a web browser or as a device driver. They record the user’s input to the computer by recording the keyboard keystrokes or mouse click. This information will be then sent to the spyware owner. These spywares can cause severe data leak.&lt;br /&gt;
&lt;br /&gt;
===Torpig-family Trojan===&lt;br /&gt;
&lt;br /&gt;
These Trojans are using advanced technologies that help them to spread very fast and hide very well. They are designed to hijack sessions. These Trojans are constantly monitoring major banks’ websites throughout the world. They display a fake page when a user tries to log in to these websites, and in this way continue to steal the private information of their victims.&lt;br /&gt;
&lt;br /&gt;
===Session Hijackers===&lt;br /&gt;
&lt;br /&gt;
These attacks can take place either from the malware that is installed on the victim’s computer or remotely. The attacks are triggered when users is trying to log into they account (usually bank accounts) or when they initiate a transaction. The malware then hijack the session for malicious purposes.&lt;br /&gt;
&lt;br /&gt;
===Content-Injection Phishing===&lt;br /&gt;
&lt;br /&gt;
This phishing refers to the situations when malicious or fake content get injected into some legitimate websites. These content then can abuse the users of the website by redirecting them to other websites, install malware on their computers, or redirect the input that users is inputting in that website to the phishing server.&lt;br /&gt;
&lt;br /&gt;
===“Universal” Man-in-the-middle phishing kit===&lt;br /&gt;
&lt;br /&gt;
There is only little effort required for the attackers to use this method to attack their victims. The attackers use a kit which is called MITM that includes several PHP files that get installed on the phishing server. This sever then acts as a median between the user and the legitimate website that he/she wants to access. These victims receive emails that includes a link to their know website. Once they click on the link, they’ll be redirected to the phishing server which then will communicate with the original website on behalf of the user.&lt;br /&gt;
&lt;br /&gt;
===Search Engine Phishing===&lt;br /&gt;
&lt;br /&gt;
In this type pf phishing, phishers establish a webpage, and then get it indexed by the search engines to make it searchable. These pages are usually designed to include items and services at very low price to attract visitors to sign up or to enter their confidential information. The phisher then get the hold of the private information of the visitors.&lt;br /&gt;
&lt;br /&gt;
===Spear Phishing===&lt;br /&gt;
&lt;br /&gt;
In this approach the phisher targets a particular person or a specific department in a company. The phisher then contacts the person by email and pretends to be from a legitimate department and is a trustworthy staff. The attacker then asks for the username and password with some fake reasons. Once the attacker get those information the can by pass the firewalls and break into the secured network.&lt;br /&gt;
&lt;br /&gt;
==Phishing solutions==&lt;br /&gt;
&lt;br /&gt;
To fight against the phishers, in the first place, the online service users should be educated. Once users know what phishing is and what methods phishers use, less people will fall for their tricks and many of their method then become useless. However some countermeasures have been developed and some of them are explained below.&lt;br /&gt;
&lt;br /&gt;
===Phishing blacklist===&lt;br /&gt;
&lt;br /&gt;
A server that is containing a list of all of the malicious websites and phishing servers should be established and be accessible by the internet browsers. The list should be updated on daily basis due to the lifetime of the phishing servers. The malicious URLs should be reported immediately.&lt;br /&gt;
&lt;br /&gt;
===Bookmarks or history===&lt;br /&gt;
&lt;br /&gt;
Using bookmarks and history to detect the list of the websites that the user uses. Then if a new website is visited randomly by the user that he/she did not visit before, chances are that this website is has malicious purposes. The down side of this method is that the history feature holds a history of the limited and short time.&lt;br /&gt;
&lt;br /&gt;
===Two-Way Authentication===&lt;br /&gt;
&lt;br /&gt;
In this method once a user signs up for an online service they receive and image in a secure way. Thereafter whenever the user visits the website and enters his/her username the website displays the image to prove its legitimacy. The user then can continue to enter his/her password.&lt;br /&gt;
&lt;br /&gt;
===VeriSign Identity Protection (VIP)===&lt;br /&gt;
&lt;br /&gt;
VIP has been design to protect the digital identities of the people who use online services. VIP provides number of rules that organizations should comply with if they want use VIP services. The VIP suite then provides a secure way for users to log into their account and transactions to take place.&lt;br /&gt;
&lt;br /&gt;
===Early alarm===&lt;br /&gt;
&lt;br /&gt;
This solution requires sort of add on tool to be installed on the web browsers. This tool contains several rules and ways to check the authentication of the websites. The tool will notify the user if the website is legitimate and trusted.&lt;br /&gt;
&lt;br /&gt;
=Bibliography=&lt;br /&gt;
===Privacy and ethical Issues===&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/xg41104w066612m7/fulltext.pdf Privacy and e-commerce: a consumer-centric perspective] Rhys Smith and Jianhua Shao ''Electronic Commerce Research'', Volume 7, Number 2 / June, 2007 &lt;br /&gt;
&lt;br /&gt;
http://www.mcgoverngreene.com/alerts/FA_pdfs/Oct-Nov_2004.pdf&lt;br /&gt;
Phishers “net” unsuspecting consumers fraud alert  october/november 2004&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
http://delivery.acm.org.www.lib.ncsu.edu:2048/10.1145/1130000/1124861/p581-dhamija.pdf?key1=1124861&amp;amp;key2=4842557121&amp;amp;coll=ACM&amp;amp;dl=ACM&amp;amp;CFID=38796614&amp;amp;CFTOKEN=46500553&lt;br /&gt;
Why phishing works Rachna Dhamija,  J. D. Tygar, Marti Hearst&lt;br /&gt;
&lt;br /&gt;
The Battle Against Phishing: Dynamic Security Skins Rachna Dhamija,  J. D. Tygar&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
http://www.springerlink.com.www.lib.ncsu.edu:2048/content/d284629556533224/fulltext.pdf&lt;br /&gt;
A Revocation Scheme Preserving Privacy &lt;br /&gt;
Łukasz Krzywiecki, Przemysław Kubiak and Mirosław Kutyłowski &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
http://www.springerlink.com.www.lib.ncsu.edu:2048/content/h62k448875177211/fulltext.pdf&lt;br /&gt;
Security and Privacy as Market Failures &lt;br /&gt;
L. Jean Camp &lt;br /&gt;
Economics of Identity Theft: Avoidance, Causes and Possible Cures &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
http://www.springerlink.com.www.lib.ncsu.edu:2048/content/q808084h875464v5/fulltext.pdf&lt;br /&gt;
Protection or Privacy? Data Mining and Personal Data &lt;br /&gt;
David J. Hand&lt;br /&gt;
&lt;br /&gt;
===Protection against Phishing attacks===&lt;/div&gt;</summary>
		<author><name>Mbastan</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16461</id>
		<title>Phishing</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16461"/>
		<updated>2008-08-01T01:31:28Z</updated>

		<summary type="html">&lt;p&gt;Mbastan: /* Bibliography */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Study Guide=&lt;br /&gt;
&lt;br /&gt;
Phishing in computing is the process of acquiring private and sensitive information by pretending to be a trustworthy or a legitimate website through the online communications. Phishing is an example of fraudulent use of social engineering techniques to deceive an online service user. In this article some of the known attacks will be discussed following with some solutions to guard against these attackes.&lt;br /&gt;
&lt;br /&gt;
==Phishing Attacks==&lt;br /&gt;
&lt;br /&gt;
The followings are some of the way that the phishing attacks are taking place.&lt;br /&gt;
&lt;br /&gt;
====Keyloggers====&lt;br /&gt;
&lt;br /&gt;
These are spywares that can get installed either into a web browser or as a device driver. They record the user’s input to the computer by recording the keyboard keystrokes or mouse click. This information will be then sent to the spyware owner. These spywares can cause severe data leak.&lt;br /&gt;
&lt;br /&gt;
===Torpig-family Trojan===&lt;br /&gt;
&lt;br /&gt;
These Trojans are using advanced technologies that help them to spread very fast and hide very well. They are designed to hijack sessions. These Trojans are constantly monitoring major banks’ websites throughout the world. They display a fake page when a user tries to log in to these websites, and in this way continue to steal the private information of their victims.&lt;br /&gt;
&lt;br /&gt;
===Session Hijackers===&lt;br /&gt;
&lt;br /&gt;
These attacks can take place either from the malware that is installed on the victim’s computer or remotely. The attacks are triggered when users is trying to log into they account (usually bank accounts) or when they initiate a transaction. The malware then hijack the session for malicious purposes.&lt;br /&gt;
&lt;br /&gt;
===Content-Injection Phishing===&lt;br /&gt;
&lt;br /&gt;
This phishing refers to the situations when malicious or fake content get injected into some legitimate websites. These content then can abuse the users of the website by redirecting them to other websites, install malware on their computers, or redirect the input that users is inputting in that website to the phishing server.&lt;br /&gt;
&lt;br /&gt;
===“Universal” Man-in-the-middle phishing kit===&lt;br /&gt;
&lt;br /&gt;
There is only little effort required for the attackers to use this method to attack their victims. The attackers use a kit which is called MITM that includes several PHP files that get installed on the phishing server. This sever then acts as a median between the user and the legitimate website that he/she wants to access. These victims receive emails that includes a link to their know website. Once they click on the link, they’ll be redirected to the phishing server which then will communicate with the original website on behalf of the user.&lt;br /&gt;
&lt;br /&gt;
===Search Engine Phishing===&lt;br /&gt;
&lt;br /&gt;
In this type pf phishing, phishers establish a webpage, and then get it indexed by the search engines to make it searchable. These pages are usually designed to include items and services at very low price to attract visitors to sign up or to enter their confidential information. The phisher then get the hold of the private information of the visitors.&lt;br /&gt;
&lt;br /&gt;
===Spear Phishing===&lt;br /&gt;
&lt;br /&gt;
In this approach the phisher targets a particular person or a specific department in a company. The phisher then contacts the person by email and pretends to be from a legitimate department and is a trustworthy staff. The attacker then asks for the username and password with some fake reasons. Once the attacker get those information the can by pass the firewalls and break into the secured network.&lt;br /&gt;
&lt;br /&gt;
==Phishing solutions==&lt;br /&gt;
&lt;br /&gt;
To fight against the phishers, in the first place, the online service users should be educated. Once users know what phishing is and what methods phishers use, less people will fall for their tricks and many of their method then become useless. However some countermeasures have been developed and some of them are explained below.&lt;br /&gt;
&lt;br /&gt;
===Phishing blacklist===&lt;br /&gt;
&lt;br /&gt;
A server that is containing a list of all of the malicious websites and phishing servers should be established and be accessible by the internet browsers. The list should be updated on daily basis due to the lifetime of the phishing servers. The malicious URLs should be reported immediately.&lt;br /&gt;
&lt;br /&gt;
===Bookmarks or history===&lt;br /&gt;
&lt;br /&gt;
Using bookmarks and history to detect the list of the websites that the user uses. Then if a new website is visited randomly by the user that he/she did not visit before, chances are that this website is has malicious purposes. The down side of this method is that the history feature holds a history of the limited and short time.&lt;br /&gt;
&lt;br /&gt;
===Two-Way Authentication===&lt;br /&gt;
&lt;br /&gt;
In this method once a user signs up for an online service they receive and image in a secure way. Thereafter whenever the user visits the website and enters his/her username the website displays the image to prove its legitimacy. The user then can continue to enter his/her password.&lt;br /&gt;
&lt;br /&gt;
===VeriSign Identity Protection (VIP)===&lt;br /&gt;
&lt;br /&gt;
VIP has been design to protect the digital identities of the people who use online services. VIP provides number of rules that organizations should comply with if they want use VIP services. The VIP suite then provides a secure way for users to log into their account and transactions to take place.&lt;br /&gt;
&lt;br /&gt;
===Early alarm===&lt;br /&gt;
&lt;br /&gt;
This solution requires sort of add on tool to be installed on the web browsers. This tool contains several rules and ways to check the authentication of the websites. The tool will notify the user if the website is legitimate and trusted.&lt;br /&gt;
&lt;br /&gt;
=Bibliography=&lt;br /&gt;
===Privacy and ethical Issues===&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/xg41104w066612m7/fulltext.pdf Privacy and e-commerce: a consumer-centric perspective] Rhys Smith and Jianhua Shao Electronic Commerce Research, Volume 7, Number 2 / June, 2007 &lt;br /&gt;
&lt;br /&gt;
http://www.mcgoverngreene.com/alerts/FA_pdfs/Oct-Nov_2004.pdf&lt;br /&gt;
Phishers “net” unsuspecting consumers fraud alert  october/november 2004&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
http://delivery.acm.org.www.lib.ncsu.edu:2048/10.1145/1130000/1124861/p581-dhamija.pdf?key1=1124861&amp;amp;key2=4842557121&amp;amp;coll=ACM&amp;amp;dl=ACM&amp;amp;CFID=38796614&amp;amp;CFTOKEN=46500553&lt;br /&gt;
Why phishing works Rachna Dhamija,  J. D. Tygar, Marti Hearst&lt;br /&gt;
&lt;br /&gt;
The Battle Against Phishing: Dynamic Security Skins Rachna Dhamija,  J. D. Tygar&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
http://www.springerlink.com.www.lib.ncsu.edu:2048/content/d284629556533224/fulltext.pdf&lt;br /&gt;
A Revocation Scheme Preserving Privacy &lt;br /&gt;
Łukasz Krzywiecki, Przemysław Kubiak and Mirosław Kutyłowski &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
http://www.springerlink.com.www.lib.ncsu.edu:2048/content/h62k448875177211/fulltext.pdf&lt;br /&gt;
Security and Privacy as Market Failures &lt;br /&gt;
L. Jean Camp &lt;br /&gt;
Economics of Identity Theft: Avoidance, Causes and Possible Cures &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
http://www.springerlink.com.www.lib.ncsu.edu:2048/content/q808084h875464v5/fulltext.pdf&lt;br /&gt;
Protection or Privacy? Data Mining and Personal Data &lt;br /&gt;
David J. Hand&lt;br /&gt;
&lt;br /&gt;
===Protection against Phishing attacks===&lt;/div&gt;</summary>
		<author><name>Mbastan</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16459</id>
		<title>Phishing</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16459"/>
		<updated>2008-08-01T01:30:59Z</updated>

		<summary type="html">&lt;p&gt;Mbastan: /* Privacy and ethical Issues */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Study Guide=&lt;br /&gt;
&lt;br /&gt;
Phishing in computing is the process of acquiring private and sensitive information by pretending to be a trustworthy or a legitimate website through the online communications. Phishing is an example of fraudulent use of social engineering techniques to deceive an online service user. In this article some of the known attacks will be discussed following with some solutions to guard against these attackes.&lt;br /&gt;
&lt;br /&gt;
==Phishing Attacks==&lt;br /&gt;
&lt;br /&gt;
The followings are some of the way that the phishing attacks are taking place.&lt;br /&gt;
&lt;br /&gt;
====Keyloggers====&lt;br /&gt;
&lt;br /&gt;
These are spywares that can get installed either into a web browser or as a device driver. They record the user’s input to the computer by recording the keyboard keystrokes or mouse click. This information will be then sent to the spyware owner. These spywares can cause severe data leak.&lt;br /&gt;
&lt;br /&gt;
===Torpig-family Trojan===&lt;br /&gt;
&lt;br /&gt;
These Trojans are using advanced technologies that help them to spread very fast and hide very well. They are designed to hijack sessions. These Trojans are constantly monitoring major banks’ websites throughout the world. They display a fake page when a user tries to log in to these websites, and in this way continue to steal the private information of their victims.&lt;br /&gt;
&lt;br /&gt;
===Session Hijackers===&lt;br /&gt;
&lt;br /&gt;
These attacks can take place either from the malware that is installed on the victim’s computer or remotely. The attacks are triggered when users is trying to log into they account (usually bank accounts) or when they initiate a transaction. The malware then hijack the session for malicious purposes.&lt;br /&gt;
&lt;br /&gt;
===Content-Injection Phishing===&lt;br /&gt;
&lt;br /&gt;
This phishing refers to the situations when malicious or fake content get injected into some legitimate websites. These content then can abuse the users of the website by redirecting them to other websites, install malware on their computers, or redirect the input that users is inputting in that website to the phishing server.&lt;br /&gt;
&lt;br /&gt;
===“Universal” Man-in-the-middle phishing kit===&lt;br /&gt;
&lt;br /&gt;
There is only little effort required for the attackers to use this method to attack their victims. The attackers use a kit which is called MITM that includes several PHP files that get installed on the phishing server. This sever then acts as a median between the user and the legitimate website that he/she wants to access. These victims receive emails that includes a link to their know website. Once they click on the link, they’ll be redirected to the phishing server which then will communicate with the original website on behalf of the user.&lt;br /&gt;
&lt;br /&gt;
===Search Engine Phishing===&lt;br /&gt;
&lt;br /&gt;
In this type pf phishing, phishers establish a webpage, and then get it indexed by the search engines to make it searchable. These pages are usually designed to include items and services at very low price to attract visitors to sign up or to enter their confidential information. The phisher then get the hold of the private information of the visitors.&lt;br /&gt;
&lt;br /&gt;
===Spear Phishing===&lt;br /&gt;
&lt;br /&gt;
In this approach the phisher targets a particular person or a specific department in a company. The phisher then contacts the person by email and pretends to be from a legitimate department and is a trustworthy staff. The attacker then asks for the username and password with some fake reasons. Once the attacker get those information the can by pass the firewalls and break into the secured network.&lt;br /&gt;
&lt;br /&gt;
==Phishing solutions==&lt;br /&gt;
&lt;br /&gt;
To fight against the phishers, in the first place, the online service users should be educated. Once users know what phishing is and what methods phishers use, less people will fall for their tricks and many of their method then become useless. However some countermeasures have been developed and some of them are explained below.&lt;br /&gt;
&lt;br /&gt;
===Phishing blacklist===&lt;br /&gt;
&lt;br /&gt;
A server that is containing a list of all of the malicious websites and phishing servers should be established and be accessible by the internet browsers. The list should be updated on daily basis due to the lifetime of the phishing servers. The malicious URLs should be reported immediately.&lt;br /&gt;
&lt;br /&gt;
===Bookmarks or history===&lt;br /&gt;
&lt;br /&gt;
Using bookmarks and history to detect the list of the websites that the user uses. Then if a new website is visited randomly by the user that he/she did not visit before, chances are that this website is has malicious purposes. The down side of this method is that the history feature holds a history of the limited and short time.&lt;br /&gt;
&lt;br /&gt;
===Two-Way Authentication===&lt;br /&gt;
&lt;br /&gt;
In this method once a user signs up for an online service they receive and image in a secure way. Thereafter whenever the user visits the website and enters his/her username the website displays the image to prove its legitimacy. The user then can continue to enter his/her password.&lt;br /&gt;
&lt;br /&gt;
===VeriSign Identity Protection (VIP)===&lt;br /&gt;
&lt;br /&gt;
VIP has been design to protect the digital identities of the people who use online services. VIP provides number of rules that organizations should comply with if they want use VIP services. The VIP suite then provides a secure way for users to log into their account and transactions to take place.&lt;br /&gt;
&lt;br /&gt;
===Early alarm===&lt;br /&gt;
&lt;br /&gt;
This solution requires sort of add on tool to be installed on the web browsers. This tool contains several rules and ways to check the authentication of the websites. The tool will notify the user if the website is legitimate and trusted.&lt;br /&gt;
&lt;br /&gt;
=Bibliography=&lt;br /&gt;
===Privacy and ethical Issues===&lt;br /&gt;
[http://www.springerlink.com.www.lib.ncsu.edu:2048/content/xg41104w066612m7/fulltext.pdf&lt;br /&gt;
Privacy and e-commerce: a consumer-centric perspective] Rhys Smith and Jianhua Shao Electronic Commerce Research, Volume 7, Number 2 / June, 2007 &lt;br /&gt;
&lt;br /&gt;
http://www.mcgoverngreene.com/alerts/FA_pdfs/Oct-Nov_2004.pdf&lt;br /&gt;
Phishers “net” unsuspecting consumers fraud alert  october/november 2004&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
http://delivery.acm.org.www.lib.ncsu.edu:2048/10.1145/1130000/1124861/p581-dhamija.pdf?key1=1124861&amp;amp;key2=4842557121&amp;amp;coll=ACM&amp;amp;dl=ACM&amp;amp;CFID=38796614&amp;amp;CFTOKEN=46500553&lt;br /&gt;
Why phishing works Rachna Dhamija,  J. D. Tygar, Marti Hearst&lt;br /&gt;
&lt;br /&gt;
The Battle Against Phishing: Dynamic Security Skins Rachna Dhamija,  J. D. Tygar&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
http://www.springerlink.com.www.lib.ncsu.edu:2048/content/d284629556533224/fulltext.pdf&lt;br /&gt;
A Revocation Scheme Preserving Privacy &lt;br /&gt;
Łukasz Krzywiecki, Przemysław Kubiak and Mirosław Kutyłowski &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
http://www.springerlink.com.www.lib.ncsu.edu:2048/content/h62k448875177211/fulltext.pdf&lt;br /&gt;
Security and Privacy as Market Failures &lt;br /&gt;
L. Jean Camp &lt;br /&gt;
Economics of Identity Theft: Avoidance, Causes and Possible Cures &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
http://www.springerlink.com.www.lib.ncsu.edu:2048/content/q808084h875464v5/fulltext.pdf&lt;br /&gt;
Protection or Privacy? Data Mining and Personal Data &lt;br /&gt;
David J. Hand&lt;br /&gt;
&lt;br /&gt;
===Protection against Phishing attacks===&lt;/div&gt;</summary>
		<author><name>Mbastan</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16458</id>
		<title>Phishing</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16458"/>
		<updated>2008-08-01T01:30:10Z</updated>

		<summary type="html">&lt;p&gt;Mbastan: /* Bibliography */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Study Guide=&lt;br /&gt;
&lt;br /&gt;
Phishing in computing is the process of acquiring private and sensitive information by pretending to be a trustworthy or a legitimate website through the online communications. Phishing is an example of fraudulent use of social engineering techniques to deceive an online service user. In this article some of the known attacks will be discussed following with some solutions to guard against these attackes.&lt;br /&gt;
&lt;br /&gt;
==Phishing Attacks==&lt;br /&gt;
&lt;br /&gt;
The followings are some of the way that the phishing attacks are taking place.&lt;br /&gt;
&lt;br /&gt;
====Keyloggers====&lt;br /&gt;
&lt;br /&gt;
These are spywares that can get installed either into a web browser or as a device driver. They record the user’s input to the computer by recording the keyboard keystrokes or mouse click. This information will be then sent to the spyware owner. These spywares can cause severe data leak.&lt;br /&gt;
&lt;br /&gt;
===Torpig-family Trojan===&lt;br /&gt;
&lt;br /&gt;
These Trojans are using advanced technologies that help them to spread very fast and hide very well. They are designed to hijack sessions. These Trojans are constantly monitoring major banks’ websites throughout the world. They display a fake page when a user tries to log in to these websites, and in this way continue to steal the private information of their victims.&lt;br /&gt;
&lt;br /&gt;
===Session Hijackers===&lt;br /&gt;
&lt;br /&gt;
These attacks can take place either from the malware that is installed on the victim’s computer or remotely. The attacks are triggered when users is trying to log into they account (usually bank accounts) or when they initiate a transaction. The malware then hijack the session for malicious purposes.&lt;br /&gt;
&lt;br /&gt;
===Content-Injection Phishing===&lt;br /&gt;
&lt;br /&gt;
This phishing refers to the situations when malicious or fake content get injected into some legitimate websites. These content then can abuse the users of the website by redirecting them to other websites, install malware on their computers, or redirect the input that users is inputting in that website to the phishing server.&lt;br /&gt;
&lt;br /&gt;
===“Universal” Man-in-the-middle phishing kit===&lt;br /&gt;
&lt;br /&gt;
There is only little effort required for the attackers to use this method to attack their victims. The attackers use a kit which is called MITM that includes several PHP files that get installed on the phishing server. This sever then acts as a median between the user and the legitimate website that he/she wants to access. These victims receive emails that includes a link to their know website. Once they click on the link, they’ll be redirected to the phishing server which then will communicate with the original website on behalf of the user.&lt;br /&gt;
&lt;br /&gt;
===Search Engine Phishing===&lt;br /&gt;
&lt;br /&gt;
In this type pf phishing, phishers establish a webpage, and then get it indexed by the search engines to make it searchable. These pages are usually designed to include items and services at very low price to attract visitors to sign up or to enter their confidential information. The phisher then get the hold of the private information of the visitors.&lt;br /&gt;
&lt;br /&gt;
===Spear Phishing===&lt;br /&gt;
&lt;br /&gt;
In this approach the phisher targets a particular person or a specific department in a company. The phisher then contacts the person by email and pretends to be from a legitimate department and is a trustworthy staff. The attacker then asks for the username and password with some fake reasons. Once the attacker get those information the can by pass the firewalls and break into the secured network.&lt;br /&gt;
&lt;br /&gt;
==Phishing solutions==&lt;br /&gt;
&lt;br /&gt;
To fight against the phishers, in the first place, the online service users should be educated. Once users know what phishing is and what methods phishers use, less people will fall for their tricks and many of their method then become useless. However some countermeasures have been developed and some of them are explained below.&lt;br /&gt;
&lt;br /&gt;
===Phishing blacklist===&lt;br /&gt;
&lt;br /&gt;
A server that is containing a list of all of the malicious websites and phishing servers should be established and be accessible by the internet browsers. The list should be updated on daily basis due to the lifetime of the phishing servers. The malicious URLs should be reported immediately.&lt;br /&gt;
&lt;br /&gt;
===Bookmarks or history===&lt;br /&gt;
&lt;br /&gt;
Using bookmarks and history to detect the list of the websites that the user uses. Then if a new website is visited randomly by the user that he/she did not visit before, chances are that this website is has malicious purposes. The down side of this method is that the history feature holds a history of the limited and short time.&lt;br /&gt;
&lt;br /&gt;
===Two-Way Authentication===&lt;br /&gt;
&lt;br /&gt;
In this method once a user signs up for an online service they receive and image in a secure way. Thereafter whenever the user visits the website and enters his/her username the website displays the image to prove its legitimacy. The user then can continue to enter his/her password.&lt;br /&gt;
&lt;br /&gt;
===VeriSign Identity Protection (VIP)===&lt;br /&gt;
&lt;br /&gt;
VIP has been design to protect the digital identities of the people who use online services. VIP provides number of rules that organizations should comply with if they want use VIP services. The VIP suite then provides a secure way for users to log into their account and transactions to take place.&lt;br /&gt;
&lt;br /&gt;
===Early alarm===&lt;br /&gt;
&lt;br /&gt;
This solution requires sort of add on tool to be installed on the web browsers. This tool contains several rules and ways to check the authentication of the websites. The tool will notify the user if the website is legitimate and trusted.&lt;br /&gt;
&lt;br /&gt;
=Bibliography=&lt;br /&gt;
===Privacy and ethical Issues===&lt;br /&gt;
===Protection against Phishing attacks===&lt;/div&gt;</summary>
		<author><name>Mbastan</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16457</id>
		<title>Phishing</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16457"/>
		<updated>2008-08-01T01:29:51Z</updated>

		<summary type="html">&lt;p&gt;Mbastan: /* Bibliography */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Study Guide=&lt;br /&gt;
&lt;br /&gt;
Phishing in computing is the process of acquiring private and sensitive information by pretending to be a trustworthy or a legitimate website through the online communications. Phishing is an example of fraudulent use of social engineering techniques to deceive an online service user. In this article some of the known attacks will be discussed following with some solutions to guard against these attackes.&lt;br /&gt;
&lt;br /&gt;
==Phishing Attacks==&lt;br /&gt;
&lt;br /&gt;
The followings are some of the way that the phishing attacks are taking place.&lt;br /&gt;
&lt;br /&gt;
====Keyloggers====&lt;br /&gt;
&lt;br /&gt;
These are spywares that can get installed either into a web browser or as a device driver. They record the user’s input to the computer by recording the keyboard keystrokes or mouse click. This information will be then sent to the spyware owner. These spywares can cause severe data leak.&lt;br /&gt;
&lt;br /&gt;
===Torpig-family Trojan===&lt;br /&gt;
&lt;br /&gt;
These Trojans are using advanced technologies that help them to spread very fast and hide very well. They are designed to hijack sessions. These Trojans are constantly monitoring major banks’ websites throughout the world. They display a fake page when a user tries to log in to these websites, and in this way continue to steal the private information of their victims.&lt;br /&gt;
&lt;br /&gt;
===Session Hijackers===&lt;br /&gt;
&lt;br /&gt;
These attacks can take place either from the malware that is installed on the victim’s computer or remotely. The attacks are triggered when users is trying to log into they account (usually bank accounts) or when they initiate a transaction. The malware then hijack the session for malicious purposes.&lt;br /&gt;
&lt;br /&gt;
===Content-Injection Phishing===&lt;br /&gt;
&lt;br /&gt;
This phishing refers to the situations when malicious or fake content get injected into some legitimate websites. These content then can abuse the users of the website by redirecting them to other websites, install malware on their computers, or redirect the input that users is inputting in that website to the phishing server.&lt;br /&gt;
&lt;br /&gt;
===“Universal” Man-in-the-middle phishing kit===&lt;br /&gt;
&lt;br /&gt;
There is only little effort required for the attackers to use this method to attack their victims. The attackers use a kit which is called MITM that includes several PHP files that get installed on the phishing server. This sever then acts as a median between the user and the legitimate website that he/she wants to access. These victims receive emails that includes a link to their know website. Once they click on the link, they’ll be redirected to the phishing server which then will communicate with the original website on behalf of the user.&lt;br /&gt;
&lt;br /&gt;
===Search Engine Phishing===&lt;br /&gt;
&lt;br /&gt;
In this type pf phishing, phishers establish a webpage, and then get it indexed by the search engines to make it searchable. These pages are usually designed to include items and services at very low price to attract visitors to sign up or to enter their confidential information. The phisher then get the hold of the private information of the visitors.&lt;br /&gt;
&lt;br /&gt;
===Spear Phishing===&lt;br /&gt;
&lt;br /&gt;
In this approach the phisher targets a particular person or a specific department in a company. The phisher then contacts the person by email and pretends to be from a legitimate department and is a trustworthy staff. The attacker then asks for the username and password with some fake reasons. Once the attacker get those information the can by pass the firewalls and break into the secured network.&lt;br /&gt;
&lt;br /&gt;
==Phishing solutions==&lt;br /&gt;
&lt;br /&gt;
To fight against the phishers, in the first place, the online service users should be educated. Once users know what phishing is and what methods phishers use, less people will fall for their tricks and many of their method then become useless. However some countermeasures have been developed and some of them are explained below.&lt;br /&gt;
&lt;br /&gt;
===Phishing blacklist===&lt;br /&gt;
&lt;br /&gt;
A server that is containing a list of all of the malicious websites and phishing servers should be established and be accessible by the internet browsers. The list should be updated on daily basis due to the lifetime of the phishing servers. The malicious URLs should be reported immediately.&lt;br /&gt;
&lt;br /&gt;
===Bookmarks or history===&lt;br /&gt;
&lt;br /&gt;
Using bookmarks and history to detect the list of the websites that the user uses. Then if a new website is visited randomly by the user that he/she did not visit before, chances are that this website is has malicious purposes. The down side of this method is that the history feature holds a history of the limited and short time.&lt;br /&gt;
&lt;br /&gt;
===Two-Way Authentication===&lt;br /&gt;
&lt;br /&gt;
In this method once a user signs up for an online service they receive and image in a secure way. Thereafter whenever the user visits the website and enters his/her username the website displays the image to prove its legitimacy. The user then can continue to enter his/her password.&lt;br /&gt;
&lt;br /&gt;
===VeriSign Identity Protection (VIP)===&lt;br /&gt;
&lt;br /&gt;
VIP has been design to protect the digital identities of the people who use online services. VIP provides number of rules that organizations should comply with if they want use VIP services. The VIP suite then provides a secure way for users to log into their account and transactions to take place.&lt;br /&gt;
&lt;br /&gt;
===Early alarm===&lt;br /&gt;
&lt;br /&gt;
This solution requires sort of add on tool to be installed on the web browsers. This tool contains several rules and ways to check the authentication of the websites. The tool will notify the user if the website is legitimate and trusted.&lt;br /&gt;
&lt;br /&gt;
=Bibliography=&lt;br /&gt;
==Privacy and ethical Issues==&lt;br /&gt;
==Protection against Phishing attacks==&lt;/div&gt;</summary>
		<author><name>Mbastan</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16411</id>
		<title>Phishing</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16411"/>
		<updated>2008-07-31T23:45:15Z</updated>

		<summary type="html">&lt;p&gt;Mbastan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Study Guide=&lt;br /&gt;
&lt;br /&gt;
Phishing in computing is the process of acquiring private and sensitive information by pretending to be a trustworthy or a legitimate website through the online communications. Phishing is an example of fraudulent use of social engineering techniques to deceive an online service user. In this article some of the known attacks will be discussed following with some solutions to guard against these attackes.&lt;br /&gt;
&lt;br /&gt;
==Phishing Attacks==&lt;br /&gt;
&lt;br /&gt;
The followings are some of the way that the phishing attacks are taking place.&lt;br /&gt;
&lt;br /&gt;
====Keyloggers====&lt;br /&gt;
&lt;br /&gt;
These are spywares that can get installed either into a web browser or as a device driver. They record the user’s input to the computer by recording the keyboard keystrokes or mouse click. This information will be then sent to the spyware owner. These spywares can cause severe data leak.&lt;br /&gt;
&lt;br /&gt;
===Torpig-family Trojan===&lt;br /&gt;
&lt;br /&gt;
These Trojans are using advanced technologies that help them to spread very fast and hide very well. They are designed to hijack sessions. These Trojans are constantly monitoring major banks’ websites throughout the world. They display a fake page when a user tries to log in to these websites, and in this way continue to steal the private information of their victims.&lt;br /&gt;
&lt;br /&gt;
===Session Hijackers===&lt;br /&gt;
&lt;br /&gt;
These attacks can take place either from the malware that is installed on the victim’s computer or remotely. The attacks are triggered when users is trying to log into they account (usually bank accounts) or when they initiate a transaction. The malware then hijack the session for malicious purposes.&lt;br /&gt;
&lt;br /&gt;
===Content-Injection Phishing===&lt;br /&gt;
&lt;br /&gt;
This phishing refers to the situations when malicious or fake content get injected into some legitimate websites. These content then can abuse the users of the website by redirecting them to other websites, install malware on their computers, or redirect the input that users is inputting in that website to the phishing server.&lt;br /&gt;
&lt;br /&gt;
===“Universal” Man-in-the-middle phishing kit===&lt;br /&gt;
&lt;br /&gt;
There is only little effort required for the attackers to use this method to attack their victims. The attackers use a kit which is called MITM that includes several PHP files that get installed on the phishing server. This sever then acts as a median between the user and the legitimate website that he/she wants to access. These victims receive emails that includes a link to their know website. Once they click on the link, they’ll be redirected to the phishing server which then will communicate with the original website on behalf of the user.&lt;br /&gt;
&lt;br /&gt;
===Search Engine Phishing===&lt;br /&gt;
&lt;br /&gt;
In this type pf phishing, phishers establish a webpage, and then get it indexed by the search engines to make it searchable. These pages are usually designed to include items and services at very low price to attract visitors to sign up or to enter their confidential information. The phisher then get the hold of the private information of the visitors.&lt;br /&gt;
&lt;br /&gt;
===Spear Phishing===&lt;br /&gt;
&lt;br /&gt;
In this approach the phisher targets a particular person or a specific department in a company. The phisher then contacts the person by email and pretends to be from a legitimate department and is a trustworthy staff. The attacker then asks for the username and password with some fake reasons. Once the attacker get those information the can by pass the firewalls and break into the secured network.&lt;br /&gt;
&lt;br /&gt;
==Phishing solutions==&lt;br /&gt;
&lt;br /&gt;
To fight against the phishers, in the first place, the online service users should be educated. Once users know what phishing is and what methods phishers use, less people will fall for their tricks and many of their method then become useless. However some countermeasures have been developed and some of them are explained below.&lt;br /&gt;
&lt;br /&gt;
===Phishing blacklist===&lt;br /&gt;
&lt;br /&gt;
A server that is containing a list of all of the malicious websites and phishing servers should be established and be accessible by the internet browsers. The list should be updated on daily basis due to the lifetime of the phishing servers. The malicious URLs should be reported immediately.&lt;br /&gt;
&lt;br /&gt;
===Bookmarks or history===&lt;br /&gt;
&lt;br /&gt;
Using bookmarks and history to detect the list of the websites that the user uses. Then if a new website is visited randomly by the user that he/she did not visit before, chances are that this website is has malicious purposes. The down side of this method is that the history feature holds a history of the limited and short time.&lt;br /&gt;
&lt;br /&gt;
===Two-Way Authentication===&lt;br /&gt;
&lt;br /&gt;
In this method once a user signs up for an online service they receive and image in a secure way. Thereafter whenever the user visits the website and enters his/her username the website displays the image to prove its legitimacy. The user then can continue to enter his/her password.&lt;br /&gt;
&lt;br /&gt;
===VeriSign Identity Protection (VIP)===&lt;br /&gt;
&lt;br /&gt;
VIP has been design to protect the digital identities of the people who use online services. VIP provides number of rules that organizations should comply with if they want use VIP services. The VIP suite then provides a secure way for users to log into their account and transactions to take place.&lt;br /&gt;
&lt;br /&gt;
===Early alarm===&lt;br /&gt;
&lt;br /&gt;
This solution requires sort of add on tool to be installed on the web browsers. This tool contains several rules and ways to check the authentication of the websites. The tool will notify the user if the website is legitimate and trusted.&lt;br /&gt;
&lt;br /&gt;
=Bibliography=&lt;/div&gt;</summary>
		<author><name>Mbastan</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16409</id>
		<title>Phishing</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16409"/>
		<updated>2008-07-31T23:44:08Z</updated>

		<summary type="html">&lt;p&gt;Mbastan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Study Guide=&lt;br /&gt;
&lt;br /&gt;
Phishing in computing is the process of acquiring private and sensitive information by pretending to be a trustworthy or a legitimate website through the online communications. Phishing is an example of fraudulent use of social engineering techniques to deceive an online service user. In this article some of the known attacks will be discussed following with some solutions to guard against phishing.&lt;br /&gt;
&lt;br /&gt;
==Phishing Attacks==&lt;br /&gt;
&lt;br /&gt;
The followings are some of the way that the phishing attacks are taking place.&lt;br /&gt;
&lt;br /&gt;
====Keyloggers====&lt;br /&gt;
&lt;br /&gt;
These are spywares that can get installed either into a web browser or as a device driver. They record the user’s input to the computer by recording the keyboard keystrokes or mouse click. This information will be then sent to the spyware owner. These spywares can cause severe data leak.&lt;br /&gt;
&lt;br /&gt;
===Torpig-family Trojan===&lt;br /&gt;
&lt;br /&gt;
These Trojans are using advanced technologies that help them to spread very fast and hide very well. They are designed to hijack sessions. These Trojans are constantly monitoring major banks’ websites throughout the world. They display a fake page when a user tries to log in to these websites, and in this way continue to steal the private information of their victims.&lt;br /&gt;
&lt;br /&gt;
===Session Hijackers===&lt;br /&gt;
&lt;br /&gt;
These attacks can take place either from the malware that is installed on the victim’s computer or remotely. The attacks are triggered when users is trying to log into they account (usually bank accounts) or when they initiate a transaction. The malware then hijack the session for malicious purposes.&lt;br /&gt;
&lt;br /&gt;
===Content-Injection Phishing===&lt;br /&gt;
&lt;br /&gt;
This phishing refers to the situations when malicious or fake content get injected into some legitimate websites. These content then can abuse the users of the website by redirecting them to other websites, install malware on their computers, or redirect the input that users is inputting in that website to the phishing server.&lt;br /&gt;
&lt;br /&gt;
===“Universal” Man-in-the-middle phishing kit===&lt;br /&gt;
&lt;br /&gt;
There is only little effort required for the attackers to use this method to attack their victims. The attackers use a kit which is called MITM that includes several PHP files that get installed on the phishing server. This sever then acts as a median between the user and the legitimate website that he/she wants to access. These victims receive emails that includes a link to their know website. Once they click on the link, they’ll be redirected to the phishing server which then will communicate with the original website on behalf of the user.&lt;br /&gt;
&lt;br /&gt;
===Search Engine Phishing===&lt;br /&gt;
&lt;br /&gt;
In this type pf phishing, phishers establish a webpage, and then get it indexed by the search engines to make it searchable. These pages are usually designed to include items and services at very low price to attract visitors to sign up or to enter their confidential information. The phisher then get the hold of the private information of the visitors.&lt;br /&gt;
&lt;br /&gt;
===Spear Phishing===&lt;br /&gt;
&lt;br /&gt;
In this approach the phisher targets a particular person or a specific department in a company. The phisher then contacts the person by email and pretends to be from a legitimate department and is a trustworthy staff. The attacker then asks for the username and password with some fake reasons. Once the attacker get those information the can by pass the firewalls and break into the secured network.&lt;br /&gt;
&lt;br /&gt;
==Phishing solutions==&lt;br /&gt;
&lt;br /&gt;
To fight against the phishers, in the first place, the online service users should be educated. Once users know what phishing is and what methods phishers use, less people will fall for their tricks and many of their method then become useless. However some countermeasures have been developed and some of them are explained below.&lt;br /&gt;
&lt;br /&gt;
===Phishing blacklist===&lt;br /&gt;
&lt;br /&gt;
A server that is containing a list of all of the malicious websites and phishing servers should be established and be accessible by the internet browsers. The list should be updated on daily basis due to the lifetime of the phishing servers. The malicious URLs should be reported immediately.&lt;br /&gt;
&lt;br /&gt;
===Bookmarks or history===&lt;br /&gt;
&lt;br /&gt;
Using bookmarks and history to detect the list of the websites that the user uses. Then if a new website is visited randomly by the user that he/she did not visit before, chances are that this website is has malicious purposes. The down side of this method is that the history feature holds a history of the limited and short time.&lt;br /&gt;
&lt;br /&gt;
===Two-Way Authentication===&lt;br /&gt;
&lt;br /&gt;
In this method once a user signs up for an online service they receive and image in a secure way. Thereafter whenever the user visits the website and enters his/her username the website displays the image to prove its legitimacy. The user then can continue to enter his/her password.&lt;br /&gt;
&lt;br /&gt;
===VeriSign Identity Protection (VIP)===&lt;br /&gt;
&lt;br /&gt;
VIP has been design to protect the digital identities of the people who use online services. VIP provides number of rules that organizations should comply with if they want use VIP services. The VIP suite then provides a secure way for users to log into their account and transactions to take place.&lt;br /&gt;
&lt;br /&gt;
===Early alarm===&lt;br /&gt;
&lt;br /&gt;
This solution requires sort of add on tool to be installed on the web browsers. This tool contains several rules and ways to check the authentication of the websites. The tool will notify the user if the website is legitimate and trusted.&lt;br /&gt;
&lt;br /&gt;
=Bibliography=&lt;/div&gt;</summary>
		<author><name>Mbastan</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16406</id>
		<title>Phishing</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16406"/>
		<updated>2008-07-31T23:41:31Z</updated>

		<summary type="html">&lt;p&gt;Mbastan: /* Background */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Study Guide=&lt;br /&gt;
&lt;br /&gt;
==Background==&lt;br /&gt;
&lt;br /&gt;
Phishing in computing is the process of acquiring private and sensitive information by pretending to be a trustworthy or a legitimate website through the online communications. Phishing is an example of fraudulent use of social engineering techniques to deceive an online service user.&lt;br /&gt;
&lt;br /&gt;
==Phishing Attacks==&lt;br /&gt;
&lt;br /&gt;
The followings are some of the way that the phishing attacks are taking place.&lt;br /&gt;
&lt;br /&gt;
====Keyloggers====&lt;br /&gt;
&lt;br /&gt;
These are spywares that can get installed either into a web browser or as a device driver. They record the user’s input to the computer by recording the keyboard keystrokes or mouse click. This information will be then sent to the spyware owner. These spywares can cause severe data leak.&lt;br /&gt;
&lt;br /&gt;
===Torpig-family Trojan===&lt;br /&gt;
&lt;br /&gt;
These Trojans are using advanced technologies that help them to spread very fast and hide very well. They are designed to hijack sessions. These Trojans are constantly monitoring major banks’ websites throughout the world. They display a fake page when a user tries to log in to these websites, and in this way continue to steal the private information of their victims.&lt;br /&gt;
&lt;br /&gt;
===Session Hijackers===&lt;br /&gt;
&lt;br /&gt;
These attacks can take place either from the malware that is installed on the victim’s computer or remotely. The attacks are triggered when users is trying to log into they account (usually bank accounts) or when they initiate a transaction. The malware then hijack the session for malicious purposes.&lt;br /&gt;
&lt;br /&gt;
===Content-Injection Phishing===&lt;br /&gt;
&lt;br /&gt;
This phishing refers to the situations when malicious or fake content get injected into some legitimate websites. These content then can abuse the users of the website by redirecting them to other websites, install malware on their computers, or redirect the input that users is inputting in that website to the phishing server.&lt;br /&gt;
&lt;br /&gt;
===“Universal” Man-in-the-middle phishing kit===&lt;br /&gt;
&lt;br /&gt;
There is only little effort required for the attackers to use this method to attack their victims. The attackers use a kit which is called MITM that includes several PHP files that get installed on the phishing server. This sever then acts as a median between the user and the legitimate website that he/she wants to access. These victims receive emails that includes a link to their know website. Once they click on the link, they’ll be redirected to the phishing server which then will communicate with the original website on behalf of the user.&lt;br /&gt;
&lt;br /&gt;
===Search Engine Phishing===&lt;br /&gt;
&lt;br /&gt;
In this type pf phishing, phishers establish a webpage, and then get it indexed by the search engines to make it searchable. These pages are usually designed to include items and services at very low price to attract visitors to sign up or to enter their confidential information. The phisher then get the hold of the private information of the visitors.&lt;br /&gt;
&lt;br /&gt;
===Spear Phishing===&lt;br /&gt;
&lt;br /&gt;
In this approach the phisher targets a particular person or a specific department in a company. The phisher then contacts the person by email and pretends to be from a legitimate department and is a trustworthy staff. The attacker then asks for the username and password with some fake reasons. Once the attacker get those information the can by pass the firewalls and break into the secured network.&lt;br /&gt;
&lt;br /&gt;
==Phishing solutions==&lt;br /&gt;
&lt;br /&gt;
To fight against the phishers, in the first place, the online service users should be educated. Once users know what phishing is and what methods phishers use, less people will fall for their tricks and many of their method then become useless. However some countermeasures have been developed and some of them are explained below.&lt;br /&gt;
&lt;br /&gt;
===Phishing blacklist===&lt;br /&gt;
&lt;br /&gt;
A server that is containing a list of all of the malicious websites and phishing servers should be established and be accessible by the internet browsers. The list should be updated on daily basis due to the lifetime of the phishing servers. The malicious URLs should be reported immediately.&lt;br /&gt;
&lt;br /&gt;
===Bookmarks or history===&lt;br /&gt;
&lt;br /&gt;
Using bookmarks and history to detect the list of the websites that the user uses. Then if a new website is visited randomly by the user that he/she did not visit before, chances are that this website is has malicious purposes. The down side of this method is that the history feature holds a history of the limited and short time.&lt;br /&gt;
&lt;br /&gt;
===Two-Way Authentication===&lt;br /&gt;
&lt;br /&gt;
In this method once a user signs up for an online service they receive and image in a secure way. Thereafter whenever the user visits the website and enters his/her username the website displays the image to prove its legitimacy. The user then can continue to enter his/her password.&lt;br /&gt;
&lt;br /&gt;
===VeriSign Identity Protection (VIP)===&lt;br /&gt;
&lt;br /&gt;
VIP has been design to protect the digital identities of the people who use online services. VIP provides number of rules that organizations should comply with if they want use VIP services. The VIP suite then provides a secure way for users to log into their account and transactions to take place.&lt;br /&gt;
&lt;br /&gt;
===Early alarm===&lt;br /&gt;
&lt;br /&gt;
This solution requires sort of add on tool to be installed on the web browsers. This tool contains several rules and ways to check the authentication of the websites. The tool will notify the user if the website is legitimate and trusted.&lt;br /&gt;
&lt;br /&gt;
=Bibliography=&lt;/div&gt;</summary>
		<author><name>Mbastan</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16404</id>
		<title>Phishing</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16404"/>
		<updated>2008-07-31T23:25:39Z</updated>

		<summary type="html">&lt;p&gt;Mbastan: /* Phishing Attacks */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Study Guide=&lt;br /&gt;
&lt;br /&gt;
==Background==&lt;br /&gt;
==Phishing Attacks==&lt;br /&gt;
&lt;br /&gt;
The followings are some of the way that the phishing attacks are taking place.&lt;br /&gt;
&lt;br /&gt;
====Keyloggers====&lt;br /&gt;
&lt;br /&gt;
These are spywares that can get installed either into a web browser or as a device driver. They record the user’s input to the computer by recording the keyboard keystrokes or mouse click. This information will be then sent to the spyware owner. These spywares can cause severe data leak.&lt;br /&gt;
&lt;br /&gt;
===Torpig-family Trojan===&lt;br /&gt;
&lt;br /&gt;
These Trojans are using advanced technologies that help them to spread very fast and hide very well. They are designed to hijack sessions. These Trojans are constantly monitoring major banks’ websites throughout the world. They display a fake page when a user tries to log in to these websites, and in this way continue to steal the private information of their victims.&lt;br /&gt;
&lt;br /&gt;
===Session Hijackers===&lt;br /&gt;
&lt;br /&gt;
These attacks can take place either from the malware that is installed on the victim’s computer or remotely. The attacks are triggered when users is trying to log into they account (usually bank accounts) or when they initiate a transaction. The malware then hijack the session for malicious purposes.&lt;br /&gt;
&lt;br /&gt;
===Content-Injection Phishing===&lt;br /&gt;
&lt;br /&gt;
This phishing refers to the situations when malicious or fake content get injected into some legitimate websites. These content then can abuse the users of the website by redirecting them to other websites, install malware on their computers, or redirect the input that users is inputting in that website to the phishing server.&lt;br /&gt;
&lt;br /&gt;
===“Universal” Man-in-the-middle phishing kit===&lt;br /&gt;
&lt;br /&gt;
There is only little effort required for the attackers to use this method to attack their victims. The attackers use a kit which is called MITM that includes several PHP files that get installed on the phishing server. This sever then acts as a median between the user and the legitimate website that he/she wants to access. These victims receive emails that includes a link to their know website. Once they click on the link, they’ll be redirected to the phishing server which then will communicate with the original website on behalf of the user.&lt;br /&gt;
&lt;br /&gt;
===Search Engine Phishing===&lt;br /&gt;
&lt;br /&gt;
In this type pf phishing, phishers establish a webpage, and then get it indexed by the search engines to make it searchable. These pages are usually designed to include items and services at very low price to attract visitors to sign up or to enter their confidential information. The phisher then get the hold of the private information of the visitors.&lt;br /&gt;
&lt;br /&gt;
===Spear Phishing===&lt;br /&gt;
&lt;br /&gt;
In this approach the phisher targets a particular person or a specific department in a company. The phisher then contacts the person by email and pretends to be from a legitimate department and is a trustworthy staff. The attacker then asks for the username and password with some fake reasons. Once the attacker get those information the can by pass the firewalls and break into the secured network.&lt;br /&gt;
&lt;br /&gt;
==Phishing solutions==&lt;br /&gt;
&lt;br /&gt;
To fight against the phishers, in the first place, the online service users should be educated. Once users know what phishing is and what methods phishers use, less people will fall for their tricks and many of their method then become useless. However some countermeasures have been developed and some of them are explained below.&lt;br /&gt;
&lt;br /&gt;
===Phishing blacklist===&lt;br /&gt;
&lt;br /&gt;
A server that is containing a list of all of the malicious websites and phishing servers should be established and be accessible by the internet browsers. The list should be updated on daily basis due to the lifetime of the phishing servers. The malicious URLs should be reported immediately.&lt;br /&gt;
&lt;br /&gt;
===Bookmarks or history===&lt;br /&gt;
&lt;br /&gt;
Using bookmarks and history to detect the list of the websites that the user uses. Then if a new website is visited randomly by the user that he/she did not visit before, chances are that this website is has malicious purposes. The down side of this method is that the history feature holds a history of the limited and short time.&lt;br /&gt;
&lt;br /&gt;
===Two-Way Authentication===&lt;br /&gt;
&lt;br /&gt;
In this method once a user signs up for an online service they receive and image in a secure way. Thereafter whenever the user visits the website and enters his/her username the website displays the image to prove its legitimacy. The user then can continue to enter his/her password.&lt;br /&gt;
&lt;br /&gt;
===VeriSign Identity Protection (VIP)===&lt;br /&gt;
&lt;br /&gt;
VIP has been design to protect the digital identities of the people who use online services. VIP provides number of rules that organizations should comply with if they want use VIP services. The VIP suite then provides a secure way for users to log into their account and transactions to take place.&lt;br /&gt;
&lt;br /&gt;
===Early alarm===&lt;br /&gt;
&lt;br /&gt;
This solution requires sort of add on tool to be installed on the web browsers. This tool contains several rules and ways to check the authentication of the websites. The tool will notify the user if the website is legitimate and trusted.&lt;br /&gt;
&lt;br /&gt;
=Bibliography=&lt;/div&gt;</summary>
		<author><name>Mbastan</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16403</id>
		<title>Phishing</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16403"/>
		<updated>2008-07-31T23:23:30Z</updated>

		<summary type="html">&lt;p&gt;Mbastan: /* Early alarm */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Study Guide=&lt;br /&gt;
&lt;br /&gt;
==Background==&lt;br /&gt;
==Phishing Attacks==&lt;br /&gt;
====Keyloggers====&lt;br /&gt;
&lt;br /&gt;
These are spywares that can get installed either into a web browser or as a device driver. They record the user’s input to the computer by recording the keyboard keystrokes or mouse click. This information will be then sent to the spyware owner. These spywares can cause severe data leak.&lt;br /&gt;
&lt;br /&gt;
===Torpig-family Trojan===&lt;br /&gt;
&lt;br /&gt;
These Trojans are using advanced technologies that help them to spread very fast and hide very well. They are designed to hijack sessions. These Trojans are constantly monitoring major banks’ websites throughout the world. They display a fake page when a user tries to log in to these websites, and in this way continue to steal the private information of their victims.&lt;br /&gt;
&lt;br /&gt;
===Session Hijackers===&lt;br /&gt;
&lt;br /&gt;
These attacks can take place either from the malware that is installed on the victim’s computer or remotely. The attacks are triggered when users is trying to log into they account (usually bank accounts) or when they initiate a transaction. The malware then hijack the session for malicious purposes.&lt;br /&gt;
&lt;br /&gt;
===Content-Injection Phishing===&lt;br /&gt;
&lt;br /&gt;
This phishing refers to the situations when malicious or fake content get injected into some legitimate websites. These content then can abuse the users of the website by redirecting them to other websites, install malware on their computers, or redirect the input that users is inputting in that website to the phishing server.&lt;br /&gt;
&lt;br /&gt;
===“Universal” Man-in-the-middle phishing kit===&lt;br /&gt;
&lt;br /&gt;
There is only little effort required for the attackers to use this method to attack their victims. The attackers use a kit which is called MITM that includes several PHP files that get installed on the phishing server. This sever then acts as a median between the user and the legitimate website that he/she wants to access. These victims receive emails that includes a link to their know website. Once they click on the link, they’ll be redirected to the phishing server which then will communicate with the original website on behalf of the user.&lt;br /&gt;
&lt;br /&gt;
===Search Engine Phishing===&lt;br /&gt;
&lt;br /&gt;
In this type pf phishing, phishers establish a webpage, and then get it indexed by the search engines to make it searchable. These pages are usually designed to include items and services at very low price to attract visitors to sign up or to enter their confidential information. The phisher then get the hold of the private information of the visitors.&lt;br /&gt;
&lt;br /&gt;
===Spear Phishing===&lt;br /&gt;
&lt;br /&gt;
In this approach the phisher targets a particular person or a specific department in a company. The phisher then contacts the person by email and pretends to be from a legitimate department and is a trustworthy staff. The attacker then asks for the username and password with some fake reasons. Once the attacker get those information the can by pass the firewalls and break into the secured network.&lt;br /&gt;
&lt;br /&gt;
==Phishing solutions==&lt;br /&gt;
&lt;br /&gt;
To fight against the phishers, in the first place, the online service users should be educated. Once users know what phishing is and what methods phishers use, less people will fall for their tricks and many of their method then become useless. However some countermeasures have been developed and some of them are explained below.&lt;br /&gt;
&lt;br /&gt;
===Phishing blacklist===&lt;br /&gt;
&lt;br /&gt;
A server that is containing a list of all of the malicious websites and phishing servers should be established and be accessible by the internet browsers. The list should be updated on daily basis due to the lifetime of the phishing servers. The malicious URLs should be reported immediately.&lt;br /&gt;
&lt;br /&gt;
===Bookmarks or history===&lt;br /&gt;
&lt;br /&gt;
Using bookmarks and history to detect the list of the websites that the user uses. Then if a new website is visited randomly by the user that he/she did not visit before, chances are that this website is has malicious purposes. The down side of this method is that the history feature holds a history of the limited and short time.&lt;br /&gt;
&lt;br /&gt;
===Two-Way Authentication===&lt;br /&gt;
&lt;br /&gt;
In this method once a user signs up for an online service they receive and image in a secure way. Thereafter whenever the user visits the website and enters his/her username the website displays the image to prove its legitimacy. The user then can continue to enter his/her password.&lt;br /&gt;
&lt;br /&gt;
===VeriSign Identity Protection (VIP)===&lt;br /&gt;
&lt;br /&gt;
VIP has been design to protect the digital identities of the people who use online services. VIP provides number of rules that organizations should comply with if they want use VIP services. The VIP suite then provides a secure way for users to log into their account and transactions to take place.&lt;br /&gt;
&lt;br /&gt;
===Early alarm===&lt;br /&gt;
&lt;br /&gt;
This solution requires sort of add on tool to be installed on the web browsers. This tool contains several rules and ways to check the authentication of the websites. The tool will notify the user if the website is legitimate and trusted.&lt;br /&gt;
&lt;br /&gt;
=Bibliography=&lt;/div&gt;</summary>
		<author><name>Mbastan</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16402</id>
		<title>Phishing</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16402"/>
		<updated>2008-07-31T23:23:13Z</updated>

		<summary type="html">&lt;p&gt;Mbastan: /* VeriSign Identity Protection (VIP) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Study Guide=&lt;br /&gt;
&lt;br /&gt;
==Background==&lt;br /&gt;
==Phishing Attacks==&lt;br /&gt;
====Keyloggers====&lt;br /&gt;
&lt;br /&gt;
These are spywares that can get installed either into a web browser or as a device driver. They record the user’s input to the computer by recording the keyboard keystrokes or mouse click. This information will be then sent to the spyware owner. These spywares can cause severe data leak.&lt;br /&gt;
&lt;br /&gt;
===Torpig-family Trojan===&lt;br /&gt;
&lt;br /&gt;
These Trojans are using advanced technologies that help them to spread very fast and hide very well. They are designed to hijack sessions. These Trojans are constantly monitoring major banks’ websites throughout the world. They display a fake page when a user tries to log in to these websites, and in this way continue to steal the private information of their victims.&lt;br /&gt;
&lt;br /&gt;
===Session Hijackers===&lt;br /&gt;
&lt;br /&gt;
These attacks can take place either from the malware that is installed on the victim’s computer or remotely. The attacks are triggered when users is trying to log into they account (usually bank accounts) or when they initiate a transaction. The malware then hijack the session for malicious purposes.&lt;br /&gt;
&lt;br /&gt;
===Content-Injection Phishing===&lt;br /&gt;
&lt;br /&gt;
This phishing refers to the situations when malicious or fake content get injected into some legitimate websites. These content then can abuse the users of the website by redirecting them to other websites, install malware on their computers, or redirect the input that users is inputting in that website to the phishing server.&lt;br /&gt;
&lt;br /&gt;
===“Universal” Man-in-the-middle phishing kit===&lt;br /&gt;
&lt;br /&gt;
There is only little effort required for the attackers to use this method to attack their victims. The attackers use a kit which is called MITM that includes several PHP files that get installed on the phishing server. This sever then acts as a median between the user and the legitimate website that he/she wants to access. These victims receive emails that includes a link to their know website. Once they click on the link, they’ll be redirected to the phishing server which then will communicate with the original website on behalf of the user.&lt;br /&gt;
&lt;br /&gt;
===Search Engine Phishing===&lt;br /&gt;
&lt;br /&gt;
In this type pf phishing, phishers establish a webpage, and then get it indexed by the search engines to make it searchable. These pages are usually designed to include items and services at very low price to attract visitors to sign up or to enter their confidential information. The phisher then get the hold of the private information of the visitors.&lt;br /&gt;
&lt;br /&gt;
===Spear Phishing===&lt;br /&gt;
&lt;br /&gt;
In this approach the phisher targets a particular person or a specific department in a company. The phisher then contacts the person by email and pretends to be from a legitimate department and is a trustworthy staff. The attacker then asks for the username and password with some fake reasons. Once the attacker get those information the can by pass the firewalls and break into the secured network.&lt;br /&gt;
&lt;br /&gt;
==Phishing solutions==&lt;br /&gt;
&lt;br /&gt;
To fight against the phishers, in the first place, the online service users should be educated. Once users know what phishing is and what methods phishers use, less people will fall for their tricks and many of their method then become useless. However some countermeasures have been developed and some of them are explained below.&lt;br /&gt;
&lt;br /&gt;
===Phishing blacklist===&lt;br /&gt;
&lt;br /&gt;
A server that is containing a list of all of the malicious websites and phishing servers should be established and be accessible by the internet browsers. The list should be updated on daily basis due to the lifetime of the phishing servers. The malicious URLs should be reported immediately.&lt;br /&gt;
&lt;br /&gt;
===Bookmarks or history===&lt;br /&gt;
&lt;br /&gt;
Using bookmarks and history to detect the list of the websites that the user uses. Then if a new website is visited randomly by the user that he/she did not visit before, chances are that this website is has malicious purposes. The down side of this method is that the history feature holds a history of the limited and short time.&lt;br /&gt;
&lt;br /&gt;
===Two-Way Authentication===&lt;br /&gt;
&lt;br /&gt;
In this method once a user signs up for an online service they receive and image in a secure way. Thereafter whenever the user visits the website and enters his/her username the website displays the image to prove its legitimacy. The user then can continue to enter his/her password.&lt;br /&gt;
&lt;br /&gt;
===VeriSign Identity Protection (VIP)===&lt;br /&gt;
&lt;br /&gt;
VIP has been design to protect the digital identities of the people who use online services. VIP provides number of rules that organizations should comply with if they want use VIP services. The VIP suite then provides a secure way for users to log into their account and transactions to take place.&lt;br /&gt;
&lt;br /&gt;
===Early alarm===&lt;br /&gt;
&lt;br /&gt;
=Bibliography=&lt;/div&gt;</summary>
		<author><name>Mbastan</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16390</id>
		<title>Phishing</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16390"/>
		<updated>2008-07-31T22:58:51Z</updated>

		<summary type="html">&lt;p&gt;Mbastan: /* Two-Way Authentication */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Study Guide=&lt;br /&gt;
&lt;br /&gt;
==Background==&lt;br /&gt;
==Phishing Attacks==&lt;br /&gt;
====Keyloggers====&lt;br /&gt;
&lt;br /&gt;
These are spywares that can get installed either into a web browser or as a device driver. They record the user’s input to the computer by recording the keyboard keystrokes or mouse click. This information will be then sent to the spyware owner. These spywares can cause severe data leak.&lt;br /&gt;
&lt;br /&gt;
===Torpig-family Trojan===&lt;br /&gt;
&lt;br /&gt;
These Trojans are using advanced technologies that help them to spread very fast and hide very well. They are designed to hijack sessions. These Trojans are constantly monitoring major banks’ websites throughout the world. They display a fake page when a user tries to log in to these websites, and in this way continue to steal the private information of their victims.&lt;br /&gt;
&lt;br /&gt;
===Session Hijackers===&lt;br /&gt;
&lt;br /&gt;
These attacks can take place either from the malware that is installed on the victim’s computer or remotely. The attacks are triggered when users is trying to log into they account (usually bank accounts) or when they initiate a transaction. The malware then hijack the session for malicious purposes.&lt;br /&gt;
&lt;br /&gt;
===Content-Injection Phishing===&lt;br /&gt;
&lt;br /&gt;
This phishing refers to the situations when malicious or fake content get injected into some legitimate websites. These content then can abuse the users of the website by redirecting them to other websites, install malware on their computers, or redirect the input that users is inputting in that website to the phishing server.&lt;br /&gt;
&lt;br /&gt;
===“Universal” Man-in-the-middle phishing kit===&lt;br /&gt;
&lt;br /&gt;
There is only little effort required for the attackers to use this method to attack their victims. The attackers use a kit which is called MITM that includes several PHP files that get installed on the phishing server. This sever then acts as a median between the user and the legitimate website that he/she wants to access. These victims receive emails that includes a link to their know website. Once they click on the link, they’ll be redirected to the phishing server which then will communicate with the original website on behalf of the user.&lt;br /&gt;
&lt;br /&gt;
===Search Engine Phishing===&lt;br /&gt;
&lt;br /&gt;
In this type pf phishing, phishers establish a webpage, and then get it indexed by the search engines to make it searchable. These pages are usually designed to include items and services at very low price to attract visitors to sign up or to enter their confidential information. The phisher then get the hold of the private information of the visitors.&lt;br /&gt;
&lt;br /&gt;
===Spear Phishing===&lt;br /&gt;
&lt;br /&gt;
In this approach the phisher targets a particular person or a specific department in a company. The phisher then contacts the person by email and pretends to be from a legitimate department and is a trustworthy staff. The attacker then asks for the username and password with some fake reasons. Once the attacker get those information the can by pass the firewalls and break into the secured network.&lt;br /&gt;
&lt;br /&gt;
==Phishing solutions==&lt;br /&gt;
&lt;br /&gt;
To fight against the phishers, in the first place, the online service users should be educated. Once users know what phishing is and what methods phishers use, less people will fall for their tricks and many of their method then become useless. However some countermeasures have been developed and some of them are explained below.&lt;br /&gt;
&lt;br /&gt;
===Phishing blacklist===&lt;br /&gt;
&lt;br /&gt;
A server that is containing a list of all of the malicious websites and phishing servers should be established and be accessible by the internet browsers. The list should be updated on daily basis due to the lifetime of the phishing servers. The malicious URLs should be reported immediately.&lt;br /&gt;
&lt;br /&gt;
===Bookmarks or history===&lt;br /&gt;
&lt;br /&gt;
Using bookmarks and history to detect the list of the websites that the user uses. Then if a new website is visited randomly by the user that he/she did not visit before, chances are that this website is has malicious purposes. The down side of this method is that the history feature holds a history of the limited and short time.&lt;br /&gt;
&lt;br /&gt;
===Two-Way Authentication===&lt;br /&gt;
&lt;br /&gt;
In this method once a user signs up for an online service they receive and image in a secure way. Thereafter whenever the user visits the website and enters his/her username the website displays the image to prove its legitimacy. The user then can continue to enter his/her password.&lt;br /&gt;
&lt;br /&gt;
===VeriSign Identity Protection (VIP)===&lt;br /&gt;
===Early alarm===&lt;br /&gt;
&lt;br /&gt;
=Bibliography=&lt;/div&gt;</summary>
		<author><name>Mbastan</name></author>
	</entry>
	<entry>
		<id>https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16388</id>
		<title>Phishing</title>
		<link rel="alternate" type="text/html" href="https://wiki.expertiza.ncsu.edu/index.php?title=Phishing&amp;diff=16388"/>
		<updated>2008-07-31T22:58:29Z</updated>

		<summary type="html">&lt;p&gt;Mbastan: /* Bookmarks or history */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Study Guide=&lt;br /&gt;
&lt;br /&gt;
==Background==&lt;br /&gt;
==Phishing Attacks==&lt;br /&gt;
====Keyloggers====&lt;br /&gt;
&lt;br /&gt;
These are spywares that can get installed either into a web browser or as a device driver. They record the user’s input to the computer by recording the keyboard keystrokes or mouse click. This information will be then sent to the spyware owner. These spywares can cause severe data leak.&lt;br /&gt;
&lt;br /&gt;
===Torpig-family Trojan===&lt;br /&gt;
&lt;br /&gt;
These Trojans are using advanced technologies that help them to spread very fast and hide very well. They are designed to hijack sessions. These Trojans are constantly monitoring major banks’ websites throughout the world. They display a fake page when a user tries to log in to these websites, and in this way continue to steal the private information of their victims.&lt;br /&gt;
&lt;br /&gt;
===Session Hijackers===&lt;br /&gt;
&lt;br /&gt;
These attacks can take place either from the malware that is installed on the victim’s computer or remotely. The attacks are triggered when users is trying to log into they account (usually bank accounts) or when they initiate a transaction. The malware then hijack the session for malicious purposes.&lt;br /&gt;
&lt;br /&gt;
===Content-Injection Phishing===&lt;br /&gt;
&lt;br /&gt;
This phishing refers to the situations when malicious or fake content get injected into some legitimate websites. These content then can abuse the users of the website by redirecting them to other websites, install malware on their computers, or redirect the input that users is inputting in that website to the phishing server.&lt;br /&gt;
&lt;br /&gt;
===“Universal” Man-in-the-middle phishing kit===&lt;br /&gt;
&lt;br /&gt;
There is only little effort required for the attackers to use this method to attack their victims. The attackers use a kit which is called MITM that includes several PHP files that get installed on the phishing server. This sever then acts as a median between the user and the legitimate website that he/she wants to access. These victims receive emails that includes a link to their know website. Once they click on the link, they’ll be redirected to the phishing server which then will communicate with the original website on behalf of the user.&lt;br /&gt;
&lt;br /&gt;
===Search Engine Phishing===&lt;br /&gt;
&lt;br /&gt;
In this type pf phishing, phishers establish a webpage, and then get it indexed by the search engines to make it searchable. These pages are usually designed to include items and services at very low price to attract visitors to sign up or to enter their confidential information. The phisher then get the hold of the private information of the visitors.&lt;br /&gt;
&lt;br /&gt;
===Spear Phishing===&lt;br /&gt;
&lt;br /&gt;
In this approach the phisher targets a particular person or a specific department in a company. The phisher then contacts the person by email and pretends to be from a legitimate department and is a trustworthy staff. The attacker then asks for the username and password with some fake reasons. Once the attacker get those information the can by pass the firewalls and break into the secured network.&lt;br /&gt;
&lt;br /&gt;
==Phishing solutions==&lt;br /&gt;
&lt;br /&gt;
To fight against the phishers, in the first place, the online service users should be educated. Once users know what phishing is and what methods phishers use, less people will fall for their tricks and many of their method then become useless. However some countermeasures have been developed and some of them are explained below.&lt;br /&gt;
&lt;br /&gt;
===Phishing blacklist===&lt;br /&gt;
&lt;br /&gt;
A server that is containing a list of all of the malicious websites and phishing servers should be established and be accessible by the internet browsers. The list should be updated on daily basis due to the lifetime of the phishing servers. The malicious URLs should be reported immediately.&lt;br /&gt;
&lt;br /&gt;
===Bookmarks or history===&lt;br /&gt;
&lt;br /&gt;
Using bookmarks and history to detect the list of the websites that the user uses. Then if a new website is visited randomly by the user that he/she did not visit before, chances are that this website is has malicious purposes. The down side of this method is that the history feature holds a history of the limited and short time.&lt;br /&gt;
&lt;br /&gt;
===Two-Way Authentication===&lt;br /&gt;
===VeriSign Identity Protection (VIP)===&lt;br /&gt;
===Early alarm===&lt;br /&gt;
&lt;br /&gt;
=Bibliography=&lt;/div&gt;</summary>
		<author><name>Mbastan</name></author>
	</entry>
</feed>