Features
The mechanics of malware
More often than not, though, the technical modus operandi falls into a predictable routine. Link manipulation is almost always used to create a link within an email that appears to belong to the supposed sending organisation. Most commonly, this manipulation will take the form of the inclusion of a subdomain such as www.hsbc.com.somewhere-else.com, or simply using HTML anchor text to state one domain while the underlying URL points to another. Both are enough to fool all but the most security-savvy user, as indeed is the use of a similar-sounding domain such as paypal-security.com instead of paypal.com, for instance.
Proposed initiatives such as RFC 4871 - which uses cryptography signatures to verify the domain identity of
ADVERTISEMENT |
|
Keep it real
Although it isn't always possible to prevent malware attacks, you can still take sensible precautions. Ensure your computer and network is protected by regularly updated security software, and that your applications and operating system remain free of "in the wild" vulnerabilities by setting Windows to Auto Update. Also, avoid the temptation to link-click anything and everything or open unsolicited attachments. Steer clear of the dodgy underbelly of the internet, and don't download freeware without checking its reputation first. Unfortunately, it's the last of these basics that lets too many of us down.





