|
Visit Our E2 Forums |
Education |
Financial Services |
Government |
Healthcare |
Manufacturing |
Retail
New! Focus on: End User Computing
|
||||||
Avoid Falling Victim to a Registrar Phishing AttackDave Piscitello, Internet Security Skeptic | 8/2/2011 |
In my last blog, "Phishers Are Casting Nets for Your Domain Names & DNS," I explained that even though security experts routinely warn Internet users to watch out for email notices from banks or e-merchants, these are not the only online businesses exploited by scammers.
Phishers also use emails from domain name registrars in phishing scams to gain control over legitimate domain names. Often, the attacker's objective is to change the IP addresses of your name servers in order to control name resolution for your domain. An attacker who can gain control over your name servers can inflict reputation harm -- directly, through Web defacement or email interception, or indirectly, by using your domain as a source for spam or other criminal activities. Basic phishing avoidance and awareness are a big part of the vigilance your organization needs to maintain to avoid falling victim to registrar attacks. Beyond these -- especially if your organization cannot afford the embarrassment of a defacement or a disruption of online presence of any length or kind -- you may want to consider measures recommended by ICANN’s Security and Stability Advisory Committee (SSAC), described below.
You may ask why your organization, and not your registrar, should have to put this kind of effort into protecting domain name assets. You could very easily ask the same of the online banking and e-merchant services your organization uses. Though these are different assets, the issue is the same. Phishers thrive on deception and social engineering. They study the security measures that banks, e-merchants, and registrars implement, so they can subvert them. You can’t rely on these security measures exclusively. Ultimately, the responsibility to avoid falling victim to scams of any kind is yours. The blogs and comments posted on EnterpriseEfficiency.com do not reflect the views of TechWeb, EnterpriseEfficiency.com, or its sponsors. EnterpriseEfficiency.com, TechWeb, and its sponsors do not assume responsibility for any comments, claims, or opinions made by authors and bloggers. They are no substitute for your own research and should not be relied upon for trading or any other purpose. |
More Blogs from Dave Piscitello
Dave Piscitello 8/18/2011
We've witnessed a steady stream of attacks against corporate, government, military, and controversial targets. The victims continue to conduct postmortems to assess damage and mitigate ...
Dave Piscitello 7/26/2011
We all know how traditional phishing works, where email is sent to users in an attempt to steal login or credit card information. But there is another, less known attack that is becoming ...
Dave Piscitello 5/20/2011
Yesterday, in Top 10 Advanced Persistent Threats, Part 1, I shared the observation that attacks used by Advanced Persistent Threat (APT) intruders are not that different from those used by ...
Dave Piscitello 5/19/2011
The cyber version of Advanced Persistent Threats (APTs) shares many of the characteristics we attribute to spy wars: continual surveillance of and intelligence gathering on a particular ...
Latest Archived Broadcast
Data visualization can make complex data easier to grasp. Our expert guest will talk about the hows, whys, and whats of bringing the big picture to your enterprise.
On-demand Video with Chat
NBA CIO Michael Gliedman will tell us why the NBA decided to create NBA.com/stats
6/18/2013 -
Please join us for the "IT Convergence Strategies: Why, When and How " to learn more about:
• 5 truths about infrastructure convergence today that go beyond the hype
• How to exploit the 4 phases of convergence maximum efficiency and agility
• Key milestones to plan for on the convergence journey
• Why integrated management is a critical component of convergence plans
• The importance of an open, modular approach, such as Dell’s active infrastructure, to building a converged data center
E2 IT Migration Zones
Get Modern Apps on the Windows 8 Desktop
Application Audits Simplify Migration
Hardware Refresh Cycles Are Outdated
BrandCache sous Windows Server 2012
Windows Blue attendu en juin
Comment profiter d’une nouvelle expérience User Virtualization
Leap Motion zeigt Gestensteuerung für Windows 8
Microsofts Surface Pro kommt nach Deutschland
Like Us on Facebook
Dell IT Insights
![]() ![]() Site Moderators Wanted
Enterprise Efficiency is looking for engaged readers to moderate the message boards on this site. Engage in high-IQ conversations with IT industry leaders; earn kudos and perks. Interested? E-mail:
moderators@enterpriseefficiency.com The major problem facing the CIO is how to measure the effectiveness of the IT department. Learn how Dell’s Efficiency Modeling Tool gives the CIO two clear, powerful numbers: Efficiency Quotient and Impact Quotient. These numbers can be transforma¬tive not only to the department, but to the entire enterprise. Read the full report Virtualization is a presence in nearly all enterprise data centers. But not all companies are using it to its best effect. Learn the common characteristics of success, what barriers companies face, and how to get the most from your efforts. Read the full report Cut through the VDI hype and get the full picture -- including ROI and the impact on your Data Center -- to make an informed decision about your virtual desktop infrastructure deployments. Read the full report SPONSORED BY DELL
BRIEFINGS
CASE STUDIES
EBOOKS
PUBLIC SECTOR RESOURCES
VIDEOS
WHITE PAPERS
A Video Case Study – Translational Genomics Research Institute e2 Video
|
|||||
|
|
||||||