Have you ever been a victim whose Instant messenger or email passwords have been stolen? Well if you have been, then I presume you are already taking precautions , however if you aren’t then read on you might be the next victim. Recently one of my net friends was locked out of her yahoo account which she had been maintaining since last eight years and even password recovering methods failed to recover her password , the hacker had taken care that she wasn’t able to recover her passwords. She had been accessing her accounts from her home, she even has a updated antivirus and even has turned on her windows firewall. So what went wrong? Hmm…
Well all she did was she clicked on a innocent looking hyperlink which was sent to her by one of her net friends asking her to see his photos on yahoo and looked something like http://photos.yahoo.au.tc... (this is the actual phishing link received by her so do not click on it unless you are very sure what you are doing )Did you notice that there is something wrong with this link? Well if you didn’t then let me tell you that it doesn’t end with yahoo.com it would have been okay if it ended with something like yahoo.au/… probably nobody wouldn’t have suspected it but it ends with yahoo.au.tc which does arouse suspicion but only when inspected minutely , nobody really observes so closely…More over this should followed by the user name like http://photos.yahoo.com/saurabh .Saurabh is the user. Any way so what does that link do and what can we do to protect ourselves? Well , as soon as you click on that link you got to yahoo photo webpage which asks you to login with your ID and password but here’s the catch that page is infact a fake one that looks like a yahoo’s login page and as soon as you login with your ID and password your password is received by the hacker and he can manipulate your account anyway he wants and if this is not enough the webpage can also contain some malicious html code which can run in background if your Internet explorer is not properly patched and, I am afraid to say even latest version of firefox 1.5.04 has some vulnerabilities, these malicious code can install spywares, trogan etc..
Remedy: Patch your internet explorer and windows with latest updates from Microsoft, Update your Antivirus regularly.
Well this is how my friend was locked out ,but there are still other ways by which your passwords can be stolen ,curious? Well read on…
Keyloggers
These are most easy and popular ways used by script kiddies (hackers who do not actually program and use ready made software to attack the victim) Keyloggers are software programs which are installed in the unsuspecting victim’s computer which monitors all the activities of the victim , these software actually run in background and are invisible even to windows task manager. These software continuously monitor the keyboard (some even monitor the mouse ) and save all the keys that are hit on your keyboard to a file .A clever software program can even send this file to the hacker who can view all that you have typed on your computer at his leisure this way not only your passwords but even your personal letters typed on computer or say your sensitive official documents can be viewed by the hacker…
Remedy : Use a keylogger scanner or software like Adaware or spybot search and destroy to scanner to scan your computer for malicious software like keylogger spywares adwares etc to find and remove these monitoring tools. Use a firewall software when you connect to the internet such as zone alarm ,kero, outpost or sygate , I used to have zone alarm which was free but after I installed the latest version of zone alarm it expired in 15 days and I had to switch to kero which is also a good firewall and for people who are aware with little bit of ports can try outpost which is a good firewall but a bit of a headache for newbies.
Well there is still another way the hacker can pounce on your sensitive data…. Want to know how?...
Network link snooping
Remedy: Encrypt the data , if you have a word or document file zip it and password protect it, it is simplest way you can encrypt the data without having to secure the complete link .
Well these are few things I think which might be useful to some people who surf the internet though there are lot of dark things which are lurking on the internet but these these few precautions can protect you to some extent.I hope this information helps somebody