Exploring Historical & Emerging Phishing Techniques

International Journal of Network Security & Its Applications (IJNSA), Vol.5, No.4, July 2013
DOI : 10.5121/ijnsa.2013.5402 23

Marc A. Rader1 and Syed (Shawon) M. Rahman2, *
1CapellaUniversity, Minneapolis, MN, USA and Associate Faculty, Cochise CollegeAZ, USA
Mrader3@CapellaUniversity.edu
Associate Professor of Computer Science at the University of Hawaii-Hilo, Hawaii,
USA and Part-time Faculty at Capella University, Minneapolis, USA
*SRahman@hawaii.edu
ABSTRACT
Organizations invest heavily in technical controls for their Information Assurance (IA) infrastructure.
These technical controls mitigate and reduce the risk of damage caused by outsider attacks. Most
organizations rely on training to mitigate and reduce risk of non-technical attacks such as social
engineering. Organizations lump IA training into small modules that personnel typically rush through
because the training programs lack enough depth and creativity to keep a trainee engaged. The key to
retaining knowledge is making the information memorable. This paper describes common and emerging
attack vectors and how to lower and mitigate the associated risks.
KEY WORDS
Security Risks, Phishing, Social Engineering, Cross Site Scripting, Emerging Attack Vectors, DNS poising.
1. INTRODUCTION
Phishing is a social engineering technique that is used to bypass technical controls implemented
to mitigate security risks in information systems. People are the weakest link in any security
program. Phishing capitalizes on this weakness and exploits human nature in order to gain access
to a system or to defraud a person of their assets.

The Scene News

news-logo

 

Monday 2st November (12:00pm GMT) – The Scene Really Sucks

The warez groups are nothing more than a bunch of anal licking faggots. All they do is make stupid mini bureaucracies which do nothing. The most important reason why the “scene” sucks is that the only people who actually can get a copy of the pirated software are members of the groups themselves.

Glue³.bas

— ——• Glue³.bas by méèh •—— — 'This is My Seventh Module 'The biggest bas ever made....1306 Subs and Functions '--If you make any programs with this please 'email them to me i would like to see them-- '--AND, If You Have Any Ideas For My Next Bas 'Or Suggestions, and Comments, or Errors Email Me-- '!-#* If you have a web site please post.....

Hacker defender v0.7.3====================== Main---- Hacker defender v0.7.3 byHoly_Father <holy_father@phreaker.net> & Ratter/29A <ratter@atlas.cz>Copyright (c) 2000,forever ExEwORxbirthday: 10.01.2003home: http://rootkit.host.skBetatesters:ch0pper <THEMASKDEMON@flashmail.com>phj34r (sandstorm99@ziplip.com)ierdna (ierdna@go.ro)UnixDied Hacker defender is rootkit for Windows NT 4.0, Windows 2000 and Windows XP.Main code was written in Delphi 6. New functions are written in assembler.Backdoor and redirector clients are coded mostly in Delphi 6. program uses adapted LDE32LDE32, Length-Disassembler Engine, 32-bit, (x) 1999-2000 Z0MBiEspecial edition.....

Standard by Gnome. This is the first program that I have made. This is the "beta" of the program meaning that it is still in it's trial phase and has some bugs and somethings are not enabled. They would in beta is the mooSock likes me, but I guess it doesn't. Thanks to: Louis, for teaching me how to use sockets and helped with the.....

ICON DROP v1.2   This is a good working punter. It only punts the user if they have the name you loged on, on ther buddylist. So if it isnt on ther list than this wont do shit.   www.aimtopics.tk www.n3k0de.com ¿DBN

Flood Assault v 1.1 This is version 1.1.This works with the up to date version of aim, maybe 4.7+. This logs in clones and floods the user you pick. The login is one at a time you can log alot on, i think around 100+ Well have fun as long as you dont flood me you will be tight ;). check out meh site.. www.aimtopics.tk.....

'''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''| | Thanks 4 using TaMEClone v4.15 The program is by Anphanax | | This program came from www.lenshell.com OR www.tameclones.tk | | if you got it any where else then AiM me at TaMEClone415 and let me know | ' | | ''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''

Idler by Gnome This program is perfect for the chatroom owner. Ever have the fear of a bot attack and that you will be lagged out eventually? Well, this simple program will let you idle in chatrooms without having another AIM Client running or cloning AIM! Things to be expected: Working about/help form, A hide feature that will enable you to hide the Idler window......

Chat Whore 2.5 By Peyton(r3l0ad) and Pixel(autojoin) www.solomofo.tk Solomofo Inc. ~~~~~~~~~~~NOTICE~~~~~~~~ tocsock.ocx and chat whore 2.5 should be in the same folder for this program to work Any suggestions for new updates/Ideas please email me at teh_hack@yahoo.com -reload