Offering low cost Internet service since 2004 Sign up here.
 ISP HOME   DIALUP PLANS   ACCESS NUMBERS   HELP & SUPPORT   CONTACT 

A New Security Threat - Pharming

©2005-2006 US Netizen

[ other US Netizen articles Phishing Firewalls Antivirus Antispyware]

What is Pharming?

Pharming
(pronounced farming) is a technique used by unsavory individuals and companies to obtain important personal and financial information without your knowledge. It is similar to Phishing, except the information is collected without you needing to click a link in an email. Even the most savvy netizens are subject to pharming because it does not require you to make a mistake.

As with Phishing, the ultimate purpose is to separate you from your money.

How does Pharming Work?

Pharmers have two main ways of operating: directly on users' computers or on domain name servers that resolve Web site addresses for users.

Similar to phishing, Pharmers send e-mails to users requesting that account information needs to be updated. The difference from phishing is that the email contains a virus that installs small software programs on users' computers. When a user tries to go to the bank's real Web site, the program redirects the browser to the pharmer's fake site. It then asks a user to update information such as logons, PIN codes or other sensitive information. Savvy users that do not click on the links in the email are still subject to this attack because it uses a virus to direct the browser to the scammers website.

The pharmers' second method takes advantage of the fact that Web sites have alphanumeric names but reside at numeric addresses on the Internet. When users type a Web site's name into their browsers, Domain Name System, or DNS, servers read the name, look up its numeric address and take users to the site.

Pharmers interfere with that process by changing the real site's numeric address to the fake site's numeric address within the DNS server.

This technique can only be stopped at the server and there is little that the end-user can do. Here are recent examples of pharming in action:  Hushmail gets Pharmed Online Bank gets Pharmed

A more recent example showed that a webserver running Apache was compromised. In this example, links to the website as shown in searches on Google, Yahoo, and MSN sometimes directed the user to a Russian website where they attempted to collect money from the user.

Pharming is like planting seeds of malicious viruses. As users are later directed to the fake site, the pharmers harvest the sensitive information.

How to Avoid Pharming

The virus-based method of pharming is stopped by maintaining up-to-date antivirus, antispyware, and firewalls on your computer. This will greatly reduce the possibility that a virus will redirect you to the malicious web site.

Additionally, be careful when entering sensitive information on a website. Look for the lock secureor key icon secureat the bottom of the browser. If the site has changed since your last visit, be suspicious. When in doubt, do not use the website.

A list of popular financial sites that use a secure page for logins is maintained on pharming.org. They also have a shocking list of financial sites that use an unsecure login page. To use this type of site, do not enter your username and password on the unsecure login page. Instead, just click login and you should get an error on a secure page telling you that you forgot your username or password. Verify that the error page is secure secureand log in from there.

Threat Assessment

Until recently, it appeared that the server-based portion of pharming affects only Windows servers. The main method of altering the DNS records if through "DNS Poisoning" that is a known vulnerability on Windows servers. A patch is available for Windows NT4 and Windows 2000 servers. Windows 2003 servers are not vulnerable. Server operators should refer to this Microsoft article on "DNS cache pollution."

The February 2006 example of cache poisoning on an Apache server indicates that the threat of Pharming could grow [pun not intended].

 

accelerated dialup internet service

Your Ad Here

Don't buy any Spyware software until you read this.

Call 1-866-350-9085

1-866-350-9085

Great Connections
Great Service
Great Prices

How can you go wrong?

Can't get DSL or cable? Don't want to pay those high fees? US Netizen Internet Service is faster with Overdrive


Surf up to 5x faster with Overdrive accelerated service. It really works. Testing on real web sites shows that Overdrive averages nearly three times as fast as standard 56k. Works with e-mail, too.
More Info on High Speed  

low cost internet

US Netizen has great prices on Internet service.


sign up here

Sign Up On-Line or by Telephone

FREE SETUP
FREE SUPPORT

Instant Account Activation

USNetizen offers discount Internet service in these states:
Alabama Internet Service Provider
Alaska Dialup
Arizona ISP
Arkansas Internet Access
California ISP
Colorado Internet Service Provider
Connecticut ISP
Delaware Internet Access
District of Columbia ISP
Florida Internet Service Provider
Georgia ISP
Hawaii Dialup
Idaho Internet Access
Illinois ISP
Indiana Internet Service Provider
Iowa Dialup
Kansas ISP
Kentucky Internet Service
Louisiana ISP
Maine ISP
Maryland Internet Access
Massachusetts ISP
Michigan Internet Service Provider
Minnesota ISP
Mississippi Internet Access
Missouri ISP
Montana Internet Service Provider
Nebraska ISP
Nevada Internet Access
New Hampshire ISP
New Jersey Internet Service Provider
New Mexico ISP
New York Internet Access
North Carolina ISP

North Dakota Internet Service Provider
Ohio Internet Access
Oklahoma ISP
Oregon Internet Service Provider
Pennsylvania ISP
Rhode Island Internet Access
South Carolina ISP
South Dakota Internet Service Provider
Tennessee ISP
Texas Internet Access
Utah ISP
Vermont Internet Service Provider
Virginia ISP
Washington Internet Access
West Virginia ISP
Wisconsin Internet Service Provider
Wyoming ISP
© 2004-2008 USNetizen, P.O. Box 1452, Helena, MT, 59624