Home » Featured, Headline, Phishing

What is phishing?

29 January 2009 1 views 9 Comments

phishingSo, what is phishing? In a nutshell, phishing is the act of stealing one’s personal information by pretending to be a legitimate and trustworthy entity. Most commonly the target websites are E-Mail services and E-Commerce websites. According to www.phishtank.com,  in the month of December, 2008 the top targets for phishing attacks were:

Top 10 Identified Targets Valid Phishes
1 JPMorgan Chase and Co. 12,110
2 PayPal 7,369
3 eBay, Inc. 262
4 Bank of America Corporation 212
5 Sulake Corporation 199
6 Google 169
7 Poste Italiane 163
8 Internal Revenue Service 142
9 Capital One 128
10 Wells Fargo 73


Phishing attacks are most commonly executed through E-Mails. The E-Mails look like they come from trusted sources and ask for personal information like usernames, passwords, credit card numbers, and social security numbers.


To avoid falling for phishing attacks, never go to important websites through links in E-Mails. Also, when logging into a website like Yahoo.com, look at the site URL and make sure it says www.yahoo.com  or a subdomain like login.yahoo.com. If it doesn’t, you know that it is a fake.  For more information on avoiding phishing scams see antiphishing.org.


To learn how phishing sites are created and executed, see the Hacker’s Underground Handbook.”"

1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)
Loading ... Loading ...

9 Comments »

  • MrCracker.com - all things hacking » Blog Archive » Phishing attack techniques. said:

    [...] an attacker puts together a phishing website, how does he go about getting victims to go to it? The methods are unlimited, but for those [...]

  • MrCracker.com - all things hacking » Blog Archive » Fake login page said:

    [...] posted about phishing and the techniques attacker’s use to spread their phishing sites. Now, let’s look at [...]

  • MrCracker.com - all things hacking » Blog Archive » How to hack any email account. said:

    [...] Phishing – Phishing is by far the most used and easiest method. The attacker simply sets up a page that looks exactly like the real email login page and tricks people into entering their login information. Update: Check out the new post on how to create your own phishing page here. [...]

  • MrCracker.com - all things hacking » Blog Archive » SSL Basics said:

    [...] session. They do this by primarily attacking the insecure part of the system – http, through phishing or fake web pages since most users do not directly access the secure page. This is also somewhat [...]

  • MrCracker.com – all things hacking » Blog Archive » Botnet said:

    [...] How do you make zombies or drones with others computer? It still goes down to the basics of hacking and exploiting the network and all the computer vulnerabilities.  This includes human reverse engineering or email phishing expeditions. [...]

  • BloggersBase Internet said:

    Botnet…

    Ever wonder how hackers are able to do all the stuff they do?  Many expert hackers do not just log on to systems using manual processes.  They get help from robots.  Yes, that’s right – robots. ……

  • BloggersBase Internet said:

    CrackerCast Episode 03 – Phishing…

    CrackerCast Episode 03 covers the ever popular topic of Phishing. Like always, you can send your feedback and questions to comments[at]MrCracker.com or leave a comment on the blog. Let me know……

  • asoka said:

    I have tried it out and most of my mail go to spam of my victim’s account. How to deliver those mails safely in the victim’s account…??

  • David (author) said:

    @asoka, what are you sending and how are you sending it?

Leave your response!

Add your comment below, or trackback from your own site. You can also subscribe to these comments via RSS.

Be nice. Keep it clean. Stay on topic. No spam.

You can use these tags:
<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

This is a Gravatar-enabled weblog. To get your own globally-recognized-avatar, please register at Gravatar.