mgu ni dpt b;jar byk benda coz we r dividi into 8 group to present bout security attack..mean ada 8 tjuk yg berkaitan..antaranya DOS D-DOS,hijacking, viruses n my group cover bout SPOOFING...
What is spoofing’?
- is a common phishing tactic
- is the creation of TCP/IP packets using somebody else's IP address. Routers use the "destination IP" address in order to forward packets through the Internet, but ignore the "source IP" address
Examples of spoofing:
- caller ID spoofing
- email spoofing
- man-in-the-middle
- routing redirect
- source routing
- blind spoofing
- flooding
Caller ID spoofing
the act of using a spoof card or other tool to call someone's phone under a false name.
is a service that allows a caller to masquerade as someone else by falsifying the number that appears on the recipient's caller ID display
Email Spoofing
a technique used by hackers to fraudulently send email messages in which the sender address and other parts of the email header are altered to appear as though the email originated from a source other than its actual source
The first step in spoofing
--determining the IP address of a host the intended target trusts.
--the attacker can change the headers of packets to make it seem like the transmissions are originating from the trusted machine.
Prevention of Caller ID Spoofing
1. Block spoofing calls. Services such as trapcall.com or safercall.com allow you to block calls that display false caller information. Such calls cannot go through unless the callers display their true identities.
2. Password protect your voicemail. Failure to password protect your voicemail allows criminals to hack into your voicemail and steal your personal information and contacts. Criminals can use this information to make spoof calls to your contacts and phish for sensitive information.
3. Avoid revealing sensitive information, such as your credit card or bank account number, via phone. Banks will never call you and request such information; they only request such information over phone when you initiate the contact. One of the main reasons that criminals spoof is to obtain your information. Hence, always be on guard, and do not assume the caller ID is always accurate.
Prevention of Email Spoofing
1. Safeguard your email address and avoid disclosing it. Spammers are one of the biggest perpetrators of spoofed emails. Use a spam filter, and always use an image to display your email online.
2. Distinguish real emails from spoofed ones. Look at the part of the email after the "@" sign. Make sure that this part fully matches the company's name.
3. Examine the email's language, tone and appearance, and note if it is different than usual. A sudden difference in tone or appearance as well as excessive grammar errors are warning signs
.
4. Do not disclose personal information. Many spoofing emails will request your Social Security number, date of birth or bank account number. Most legitimate financial institutions, however, will never request such information via email.
5. Report suspicious emails to the company being spoofed. Call the company, or find the email address for reporting suspicious activity on its website. Doing so encourages the company to alert other customers.