Site Sponsor:

mcafee_logo.gif
line

Now Available:

Featured Resource:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Dan or post a comment to the blog.

« It's Still a Theory, but Hardware Errors Could Lead to Security Vulnerabilities | Main | Human Factors and Improving Application Security »

Hacking for the Holidays

The holiday spam and phishing lures are on the way. As sure as stores will open early on Friday and shoppers start their annual treks to the mall or Amazon.com, the scammers will be pushing wares. From ComputerWorld we get advice from Paul Henry of Secure Computing who warns:

A common scam is to pick the hot toy of the season and send out a spam e-mail blast offering it for much less than the typical price, Henry says. Victims end up entering credit card information on malicious sites designed to look like well-known, trusted ones. They might also unknowingly download a keylogger that can steal personal information people type in when making any kind of Internet transaction.
SC Magazine also has an article on the start of the holiday scams with Cyber Monday:
"The Monday after Thanksgiving is known as Cyber Monday and it's the biggest holiday shopping day of the year," said Ron Teixeira, executive director of the NCSA.

"Last year, Cyber Monday online sales generated a record $608m compared to $457.4m on Black Friday."

The article offers basic advice about install anti-virus software and checking for the SSL padlock in your address bar. Even better, look for vendors that use Extended Validation SSL Certificates, they'll display a green bar in the address line. Companies go through extra verification to ensure they are legitimate so it's harder for phishers to get those than conventional SSL certificates.

TrackBack

TrackBack URL for this entry:
http://www.realtime-websecurity.com/type/mt-tb.cgi/531

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Dan Sullivan's Bio:

Dan Sullivan is a systems architect with 20 years of IT experience that includes engagements in enterprise security, application design, and systems architecture. His experience includes a broad range of industries, including financial services, manufacturing, government, retail, gas and oil production, power generation, and education. Dan’s security-related project work has ranged from requirements analysis for enterprise information security to designing and implementing security for database applications and enterprise portals. Dan has written about information security and other enterprise information management topics for Business Security Advisor, DM Review, Intelligent Enterprise, and E-Business Advisor. You can contact Dan at: dan_sullivan@realtimepublishers.net