Rule 0: Be Skeptical
Please remember, your credit-card and other banking information such as login ID, passwords, ATM PIN, etc are very sensitive data. So always be skeptical when someone ask them to enter it. Don’t look at why they are asking your data, just care about what data they are asking!Rule 1: Always Look at Link URL before Clicking
Thanks to HTML, any text can point to any website. Ex: Britney Spears Naked. Don’t shout me if you led to Vatican Site…Rule 2: Check Email Headers for Actual Sender
Most people don’t know that FROM field in emails can be changed by sender. I can send you email from bill@microsoft.com. The technique is called email forging and is used in almost all phishing emails. So how to check if email you received is not forged? Most trusted method is to check email headers. But email headers are quite long and complex, so checking them manually is pain. Also technique differs slightly for each email service providers. I use Gmail and on Gmail things are always easy. So whenever you receive a mail on Gmail, look for show details option.Rule 3: Use Google Toolbar or any other anti-phishing technique/filter
Yes, Google Toolbar is not just for making your life easier while using Googles’ services. It comes with built-in anti-phishing filters which warns you whenever you open malicious sites. Following is screenshot of Google Toolbar warning when I opened site pointed by Get Verified text as discussed in Rule 1.Google Toolbar gave me almost 100% protection against phishing sites. Still if you just don’t like Google Toolbar, you can still use Google search to find a good anti-phishing filter for free!
Rule 4: Use a secure browser like Firefox
All major services authenticate users over secure channels. Even services which uses unsecure channels normally, process login pages via secure channels. Some famous examples, Gmail, Facebook, Orkut, Yahoo. While banking sites are normally use secure channels through-out the session. A small difference between secure and unsecure channels is, secure URL stats HTTPS while unsecure starts with HTTP. Note the missing ‘S’. (Read more on HTTPS) Now when you encounter a genuine login page in browser like Firefox, you can note following changes…- Navigation bar background changes to yellow. Also a lock icon is shown indicating a secure site. Here you should also check domain name, which we often overlook.
- Status bar also shows lock icon along with domain name for which digital certificate is issued.
Rule 5: Report Phishing…
Great you saved your ass. Its time to save others’ now…Its your responsibility to fight for yourself. Others at the most can help you. Don’t expect more!