<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>KENNY.MY &#187; login</title>
	<atom:link href="http://www.kenny.my/blog/tag/login/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.kenny.my/blog</link>
	<description>Tidbits of Web and Internet</description>
	<lastBuildDate>Sun, 05 Feb 2012 11:08:14 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Password Management &#8211; Remembering Your IDs and Passwords</title>
		<link>http://www.kenny.my/blog/2008/password-management-remembering-your-ids-and-passwords/</link>
		<comments>http://www.kenny.my/blog/2008/password-management-remembering-your-ids-and-passwords/#comments</comments>
		<pubDate>Thu, 06 Nov 2008 11:02:26 +0000</pubDate>
		<dc:creator>Kenny</dc:creator>
				<category><![CDATA[Computer Resources]]></category>
		<category><![CDATA[comparison chart]]></category>
		<category><![CDATA[excel sheet]]></category>
		<category><![CDATA[login]]></category>
		<category><![CDATA[management software]]></category>
		<category><![CDATA[management tool]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[username]]></category>

		<guid isPermaLink="false">http://www.whoiskenny.com/blog/?p=93</guid>
		<description><![CDATA[With the online usage is getting common nowadays, many of us accessing the Internet not only for banking transaction or emailing. We do online booking, community, job and etc. However, physical remembering all these login IDs/username and password is not easy. There&#8217;s a list of Password Management software available on the Internet, and mostly chargeble: [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-0072150711132852";
/* 336x280, created 21/10/09 */
google_ad_slot = "9000186014";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p><a href="http://www.kenny.my/blog/wp-content/uploads/2008/11/2008-11-06-password-management01.gif"><img class="size-medium wp-image-141 alignright" title="Using Excel as Password Management Tool" src="http://www.kenny.my/blog/wp-content/uploads/2008/11/2008-11-06-password-management01-300x153.gif" alt="A very simple way to manage all your IDs &amp; Password with Microsoft Office Excel" /></a></p>
<p>With the online usage is getting common nowadays, many of us accessing the Internet not only for banking transaction or emailing. We do online booking, community, job and etc. However, physical remembering all these login IDs/username and password is not easy.</p>
<p>There&#8217;s a list of Password Management software available on the Internet, and mostly chargeble:</p>
<ol>
<li><a href="http://www.roboform.com">RoboForm Pro</a></li>
<li><a href="http://www.chapura.com/turbopasswords.php">TurboPasswords</a></li>
<li><a href="http://www.cp-lab.com">Password Manager XP</a></li>
<li><a href="http://www.handypassword.com">Handy Password Manager</a></li>
<li><a href="http://www.animabilis.com">Aurora Password Manager</a></li>
<li><a href="http://www.tk8.com/safe/">TK8 Safe</a></li>
<li><a href="http://www.moonsoftware.com/pwagent.asp">Password Agent</a></li>
<li><a href="http://www.mypasswordmanager.com">My Password Manager</a></li>
<li><a href="http://www.rayslab.com/password_manager/password_manager.html">Advanced Password Manager</a></li>
<li><a href="http://www.symantec.com/norton/macintosh/confidential">Norton Confidential for Macintosh</a></li>
</ol>
<p>Comparison Chart:<br />
<a href="http://password-management-software-review.toptenreviews.com/">http://password-management-software-review.toptenreviews.com/</a></p>
<p><strong>DIY Password Management</strong></p>
<p>However, buying the software tool above is not necessary. You can actually manage your login IDs and passwords by using Microsoft Office Excel Sheet as your Password Manager, and you can secured the file with the password protection feature in Microsoft Office Excel (under tools &gt; Protection &gt; Protect Sheet.)</p>
<p><strong>Why you need a Password Management tool?</strong></p>
<p>What will happened tomorrow is unpredictable, anything could be happended. You might be able to remember all the IDs and passwords by yourself, but how if one day you need your family to retrieve the details? A good organisation skill not benefit yourself, it will ease your family as well.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.kenny.my/blog/2008/password-management-remembering-your-ids-and-passwords/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Fake Phishing Email</title>
		<link>http://www.kenny.my/blog/2008/fake-phishing-email/</link>
		<comments>http://www.kenny.my/blog/2008/fake-phishing-email/#comments</comments>
		<pubDate>Mon, 27 Oct 2008 11:39:46 +0000</pubDate>
		<dc:creator>Kenny</dc:creator>
				<category><![CDATA[Computer Resources]]></category>
		<category><![CDATA[bank account]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[login]]></category>
		<category><![CDATA[Mayban]]></category>
		<category><![CDATA[Maybank]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[Paypal]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[scam]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[spy ware]]></category>
		<category><![CDATA[URL]]></category>
		<category><![CDATA[username]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.whoiskenny.com/blog/2008/fake-phishing-email/</guid>
		<description><![CDATA[Phishing attacks have become a common method for stealing personal identification information, such as bank account numbers and passwords. It is the fastest growing method of fraud on the Internet. I have recently received a scam email from a well known airline, it claimed that I have bought an air ticket from their website and [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p><a href="http://www.kenny.my/blog/wp-content/uploads/2008/11/2008-10-27-fake-phishing-email.gif"><img class="size-medium wp-image-158 alignright" title="Fake Phishing Email" src="http://www.kenny.my/blog/wp-content/uploads/2008/11/2008-10-27-fake-phishing-email-300x177.gif" alt="Phish and Spam are Different. The purpose of Phishing - Stealing; The purpose of Spam - Selling." /></a></p>
<p><strong>Phishing attacks have become a common method for stealing personal identification information, such as bank account numbers and passwords. It is the fastest growing method of fraud on the Internet.</strong></p>
<p>I have recently received a scam email from a well known airline, it claimed that I have bought an air ticket from their website and my credit card has been charged for an amount. The message also provides the login username and password information and attached an e-ticket receipt for my record.</p>
<p>I know it is a fake phishing email and the attachment might have contains the virus or worm or something will harm my computer or steal my information. I believe many of you also have received this kind of fraudulent email messages, it is a common Internet confidence scam, the increasing number of email scam become our mentally challenge when filtering those unnecessary email from our mailbox, and worry when will accidentally open an email contain the &#8220;Boom&#8221;.</p>
<p>The people who create the phishing email using the psychology technique to attract people open their email such as attractive message subject and real/trustable email sender (ie. admin, support, person name), and email contain message that you will first feel desires or denied. For an example above email message, if I first think that I didn&#8217;t buy it and want to check the receipt whether it&#8217;s my information then I fell into their trapped.</p>
<p>There&#8217;s more way doing scam. Some would install the spy ware/worm/virus into your computer, some will ask you to click on the link on the email message to a website that will request to obtain your P&amp;C information. Anyhow their purpose and objective is to steal your information whether is worm resist in your computer or manually provide by you enter on a web page.</p>
<p>I used to study on a spam research, the results was turned out 3 out of 10 person was fell into spam trap. Below is the whole process:</p>
<p>Note: The name/company/website using here is just an example.</p>
<p><strong>A smart phishing email creator know how to protect and clean his/her backside:</strong></p>
<p>1. Register 2 Paypal accounts- one Paypal account with fake information and another one with real information which has your credit card details.<br />
2. Register 2 eBay accounts- one account (A) with a real Paypal account and one account (B) with fake Paypal account.<br />
3. Account (B) offer a product on ebay and let the account (B) win the auction bidding, then transfer the money from account A (real paypal account) to the account B (fake Paypal account). The amount of money as long as enough to buy a domain name and web hosting for one month.<br />
4. Close/terminate the real Paypal account.<br />
5. Ready to use the fake Paypal account money to register a domain name and web hosting. There are many third world / Europe countries offer no restriction hosting. Many illegal group host their website in Europe / Russia to avoid government tracked/banned/suspended.</p>
<p>Above is basically a money laundering process and cover backdoor-fire method, which using the Internet technology to perform illegal process that beyond government ability/boundary.</p>
<p><strong>Creating a website that you know:</strong></p>
<p>Those Malaysia well known e-commerce website simply to become the victim. Let say, Maybank2u.com, AirAsia.com, kwsp.gov.my and etc. For our example, Maybank2u.com- nearly 30% of Malaysian have accounts with Maybank, and those with Maybank accounts will usually activated their online banking.</p>
<p>See how can I create a Fake Maybank2u site:</p>
<p>1. Register a domain name &#8220;look&#8221; like Maybank2u.com or intentionally create a typo error domain name. For example: Mayban2u.com, Moybank2u.com, Maybak2u.com, Maybank2u.de, Maybank2u.asia, Maybank2uu.com or whatever similar.</p>
<p>2. Copy the Mayban2u.com website layout and duplicate it on the fake website. Let we use &#8220;Mayban2u.com&#8221; as for our fake website example.</p>
<p>3. A page on &#8220;Mayban2u.com&#8221; with the URL: http://www.mayban2u.com/mbb/scripts/mbb_login.jsp?do=Login. The reason for this is because it look like the actual login URL and also more text can confuse people visually overlook the domain names.</p>
<p>4. Create a web application behind that will capture username and password when user really enter the login information. Upon recorded the login information then forward to actual Maybank2u.com&#8217;s login page. (At this point, the fake phishing email creator has already achieve his/her objective. The account holders may think that the page at Maybank2u.com is not working and etc)</p>
<p>For process 2 &amp; 3, the creator need to have a little of web programming skills.</p>
<p><strong>Preparing and sending out the fake phishing email to anyone. </strong></p>
<p>1. Design a corporate and professional email newsletter with the actual logo. Attached the fake link mentioned above in the newsletters and mask it with the actual URL (the actual link is just the text and when you click on it, it will lead you to different page), and of cause, newsletter will not designed in the way of &#8220;I want your username and password&#8221; style. It must made the recipient either feel desire or denying, this is the psychology technique. For a sample:</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8211; Begin of sample: fake phishing email &#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
Dear Valued Customers,</p>
<p>Thank you for being a Maybank2u.com account user. We would like to inform you that your online account will be deactivated in 3 days (31st October 2008) due to following reason:</p>
<p>Status code: MI109947463-3<br />
Description: In-active account &#8211; 3 months.</p>
<p>Please take note that you will need to manually re-active your online account through Maybank2u.com&#8217;s <span style="text-decoration: underline;">Customer Account Control Panel (login required)</span> BEFORE the deactivation date.</p>
<p>Please ignore this notification if you do not wish to continue the online account.</p>
<p>For enquiries, please contact our customer care centre.</p>
<p>Thank you.</p>
<p>Regards,<br />
Customer Care Dept<br />
Maybank Berhad<br />
Address: bla blabla</p>
<p>Email:customercare@maybank2u.com<br />
Website: www.maybank2u.com<br />
Call centre hotline: blablabla<br />
Fax: blablabla</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8211; End of sample: fake phishing email &#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>The message &#8220;<span style="text-decoration: underline;">Customer Account Control Panel (login required)</span>&#8221; which is the link to the fake URL. When user click on it, it will lead you to a page that look exactly like the Maybank2u.com page.</p>
<p>2. Design an attractive email message subject that will make recipient desire to know more. For an example: &#8220;Maybank2u.com &#8211; Deactivate Account Notification&#8221; or &#8220;Important Notice: Your Maybank2u.com account will be deactivated&#8221;</p>
<p>3. Sending the email out by a common sender name. You can set this in your web hosting configuration for email account. For an example: &#8220;Cutomer Care&#8221;, Company Name, &#8220;Support&#8221;, &#8220;Admin&#8221;, &#8220;Billing&#8221;&#8230;</p>
<p>4. That&#8217;s it. The last process will be who do you want to send to? I believe those fake phishing email creator already has thousands or even millions of email address records on their hand. (See our junk mail box already know how many of them have our email address)</p>
<p><strong>Is Phishing Illegal?</strong></p>
<p>Yes and no. There is no crime in asking you to volunteer information. It isn&#8217;t a crime to send you an important-looking message. Its a copyright infringement if the originator of the message uses a copyrighted or trademarked logo (which are easy to steal) to make the message look more authentic, but that&#8217;s a crime against the owner of the logo not you. Identity theft is illegal but no crime is committed until the thief actually uses the information you unwittingly provide. Its attempted fraud of course but if it were easy to catch these people, Phishing wouldn&#8217;t be a problem.</p>
<p><strong>Phishing, Identity Theft and Bank Fraud Detection &#8211; </strong><strong>Netcraft Toolbar </strong></p>
<p>To protect your savings from Phishing attacks, there&#8217;s a freeware &#8216;Netcraft Toolbar&#8217; is available for download at <a href="http://toolbar.netcraft.com/">http://toolbar.netcraft.com/</a>, it is something like Google Toolbar / Yahoo Toolbar, it will integrated with your web browser once you installed. I am using this tool to gether the information from the website that I visited, lower the risk, browse in safety and check the reported phishing attack (and help defend the Internet community from fraudsters.)</p>
<p><a href="http://www.kenny.my/blog/wp-content/uploads/2008/11/2008-10-27-netcraft-toolbar01.png"><img class="alignnone size-full wp-image-146" title="Netcraft Toolbar - Protect your savings from Phishing attacks" src="http://www.kenny.my/blog/wp-content/uploads/2008/11/2008-10-27-netcraft-toolbar01.png" alt="" width="464" height="120" /></a></p>
<p>Beside the Netcraft Toolbar, you can also subscribe to their Netcraft Phishing Site Feed (RSS). More: <a href="http://news.netcraft.com/phishing-site-feed">http://news.netcraft.com/phishing-site-feed</a></p>
<p><strong>Tips on Phishing</strong></p>
<p>Know your senders</p>
<ul>
<li>Is this someone I do business with?</li>
<li>Is this something I was told I’d receive?</li>
<li>Look for other ways to respond</li>
</ul>
<p>Stay on guard</p>
<ul>
<li>Look for clues – improve your PhishingIQ</li>
<li>Don’t be afraid to ask</li>
<li>Know how your system is updated</li>
<li>Protect your system</li>
<li>Check your records</li>
</ul>
<p><span style="color: #ff6600;">Disclaimer: The name/company/website used above is for an example. It is not a real case.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.kenny.my/blog/2008/fake-phishing-email/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

