{"id":857,"date":"2008-10-13T10:35:25","date_gmt":"2008-10-13T09:35:25","guid":{"rendered":"http:\/\/www.craigmurphy.com\/blog\/?p=857"},"modified":"2008-10-13T10:37:49","modified_gmt":"2008-10-13T09:37:49","slug":"spoofing-and-phishing-gentle-reminder-with-paypal-example","status":"publish","type":"post","link":"http:\/\/www.craigmurphy.com\/blog\/?p=857","title":{"rendered":"Spoofing and Phishing: gentle reminder with PayPal example"},"content":{"rendered":"<p>I meant to write about this when it first arrived in my inbox a few years ago (ahem, sorry!)  It has re-surfaced after a major inbox cleaning operation, so here it is now. <\/p>\n<p>With the economy taking a downturn, <a href=\"http:\/\/en.wikipedia.org\/wiki\/Spoofing\">spoofing<\/a> and <a href=\"http:\/\/en.wikipedia.org\/wiki\/Phishing\">phishing<\/a> are on the increase again.  Spoofing &#8211; web-sites are setup to look as identical to reputable web-sites thus inticing you to part with your financial details or login information for the site that is be emulated.  Phishing &#8211; you might receive e-mails that attempt to convince you to part with login details, personal data, etc.  Plenty has been written about spoofing and phishing, I won&#8217;t try to re-invent the wheel here.<\/p>\n<p>Anyway, here&#8217;s an example of a phishing e-mail that looks remarking like a real PayPal e-mail, including layout and graphics.  Whilst the hyperlinks in this e-mail look genuine enough, hovering the mouse over the links reveals that they don&#8217;t lead to the real PayPal web-site, but to the site of a scammer.  If you clicked on one of these links, you might not notice anything untoward as the scammer may well have done a good job spoofing the PayPal site look&#8217;n&#8217;feel.  <\/p>\n<p>Don&#8217;t be fooled &#8211; always check the ultimate destinations of links from e-mails.  Better still, open up a browser window and physically type in the URL of the web-site that the e-mail claims to be from &#8211; in this case PayPal&#8217;s web-site.  If the site in question really want to communicate with you, there will, more often than not, be a message waiting for you when you login using the correct channels.<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.craigmurphy.com\/blog\/wp-content\/uploads\/2008\/10\/PaypalSpoof.jpg\" style=\"border:none\" \/><\/p>\n<p>I realise that I&#8217;m probably teaching a lot of readers to suck eggs.  Sometimes these scams need concrete examples like this for demonstration purposes.  I&#8217;ve certainly used this screenshot to help folks understand the &#8220;how do you know?&#8221; process, as noted <a href=\"http:\/\/www.craigmurphy.com\/blog\/?p=470\">here<\/a> and <a href=\"http:\/\/www.craigmurphy.com\/blog\/?p=508\">here<\/a>.<\/p>\n<p>Technorati Tags: <a href=\"http:\/\/technorati.com\/tag\/spoof\" rel=\"tag\">spoof<\/a>, <a href=\"http:\/\/technorati.com\/tag\/spoofing\" rel=\"tag\">spoofing<\/a>, <a href=\"http:\/\/technorati.com\/tag\/security\" rel=\"tag\">security<\/a>, <a href=\"http:\/\/technorati.com\/tag\/phishing\" rel=\"tag\">phishing<\/a>, <a href=\"http:\/\/technorati.com\/tag\/confidence+tricks\" rel=\"tag\">confidence tricks<\/a>, <a href=\"http:\/\/technorati.com\/tag\/how+do+you+know\" rel=\"tag\">how do you know<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>I meant to write about this when it first arrived in my inbox a few years ago (ahem, sorry!) It has re-surfaced after a major inbox cleaning operation, so here it is now. With the economy taking a downturn, spoofing and phishing are on the increase again. Spoofing &#8211; web-sites are setup to look as &hellip; <a href=\"http:\/\/www.craigmurphy.com\/blog\/?p=857\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">Spoofing and Phishing: gentle reminder with PayPal example<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[21],"tags":[],"class_list":["post-857","post","type-post","status-publish","format-standard","hentry","category-security"],"_links":{"self":[{"href":"http:\/\/www.craigmurphy.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/857","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.craigmurphy.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.craigmurphy.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.craigmurphy.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/www.craigmurphy.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=857"}],"version-history":[{"count":0,"href":"http:\/\/www.craigmurphy.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/857\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.craigmurphy.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=857"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.craigmurphy.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=857"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.craigmurphy.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=857"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}