computerworld
By Georgia Weidman
Advice for meeting today’s demanding and evolving IT and cyber security challenges.
Close
Thank you
Your message has been sent.
Close
Sorry
There was an error emailing this page.
Credit:
Thinkstock
Advice for users on how to spot phishing emails
Computerworld |
Oct 8, 2014 6:40 AM
PT
Like this article?
thumbsup
thumbsdown
3
‘);//–“;
var adDivString = “”;
placementDiff = applyInsert($(this), adDivString);
if (debug) {
console.log(“Just placed an ad and the placementDiff is: ” + placementDiff);
}
placementTarget = cumulativeHeight + placementDiff + interModuleHeight + adHeightBuffer;
}
else {
var moduleDivString = “”;
var elementId = “drr-mod-“+moduleCounter;
moduleDivString = “”;
modules.push(elementId);
placementDiff = applyInsert($(this), moduleDivString);
if (debug) {
console.log(“Just placed a module and the placementDiff is: ” + placementDiff);
}
placementTarget = cumulativeHeight + placementDiff + interModuleHeight + moduleHeightBuffer;
moduleCounter++;
}
loopCounter++;
}
// Avoid placing elements too soon due to non-large figures inflating the cumulative height
if ($(this).is(“figure”) !$(this).is(“figure.large”)) {
cumulativeHeight += grafHeight;
}
else {
cumulativeHeight += $(this).height() + grafHeight;
}
}
});
// clone Related Stories module m-15 to come in after 2nd para in article body for mobile breakpoint display
var $relatedStories = $(‘.related-promo-wrapper’);
if ($relatedStories.length) {
var $relatedStoriesClone = $relatedStories.clone();
$relatedStoriesClone.insertAfter( “#drr-container p:eq(1)”);
}
var $insiderPromo = $(‘.insider-promo-wrapper’);
if ($insiderPromo.length) {
var $insiderPromoClone = $insiderPromo.clone();
$insiderPromoClone.insertAfter( “#drr-container p:eq(1)”);
}
//place left side element
cumulativeHeight = 0;
var leftPlacementTarget = tagHeight = leftPlacementTarget) {
if (debug) {
console.log(“congratulations… we’ve passed the initial start point”);
}
if (leftPlacementIndex == null) {
//it’s not good enough to not be a left avoid – it also shouldn’t be a
with an immediately preceding small or medium image left avoid.
if (!isLeftAvoid($(this)) noPrevFigures($(this)) ) {
leftPlacementIndex = $(this).index();
$leftPlacementElement = $(this);
leftPlacementLookaheadStart = cumulativeHeight;
if (debug) {
console.log(“is not a left avoid and no prev figures. ########## set placementIndex (“+leftPlacementIndex+”) and lookaheadStart (“+leftPlacementLookaheadStart+”) ##########”);
}
} else {
if (debug) {
console.log(“is a left avoid or has previous figures. continue”);
}
}
} else {
if (debug) {
console.log(“#### leftPlacementIndex already set to “+leftPlacementIndex+”. looking ahead…”);
}
//not null; has been set
if ((cumulativeHeight – leftPlacementLookaheadStart) leftIntervalHeight) {
if (debug) {
console.log(“###### THRESHOLD REACHED. LOOKAHEAD COMPLETE. END ###### (cumulativeHeight – leftPlacementLookaheadStart) (“+(cumulativeHeight-leftPlacementLookaheadStart)+”) leftIntervalHeight (“+leftIntervalHeight+”).”);
}
return false;
} else {
if (debug) {
console.log(“threshold not reached: (cumulativeHeight – leftPlacementLookaheadStart) (“+(cumulativeHeight-leftPlacementLookaheadStart)+”) tags
if (!(isLeftAvoid($(this)) ($(this).hasClass(‘small’) || $(this).hasClass(‘inline-small’) || $(this).hasClass(‘medium’) || $(this).hasClass(‘inline-medium’) || $(this).hasClass(‘apart’) ))) {
cumulativeHeight += $(this).height() + grafHeight;
}
if (debug) {
console.log(“——————– set cumulativeHeight(“+cumulativeHeight+”) —————“);
console.log(“”);
}
}
});
}
if (leftPlacementIndex != null elementNotNearEnd($leftPlacementElement, leftPixelWindow)) {
if (debug) {
console.log(” insert into index “+leftPlacementIndex);
}
$(“#drr-container”).children().eq(leftPlacementIndex).before(“
“);
}
IDG.GPT.trackOmniture();
// Add Right rail module content
for (var i=0; i= 0) {
var a = document.createElement(‘a’);
a.href = document.referrer;
var uriParts = a.pathname.split(‘/’);
a = ”;
if (typeof uriParts[3] == ‘undefined’) {
epoParams += “typeId=” + defaultTypeId + “referrer=home”; // default is ‘home’ behavior
}
else {
var refCatSlug = uriParts[3];
epoParams += “catSlug=” + refCatSlug + “referrer=article”;
}
}
// From SEARCH: Show article with catId same as current article
else if (document.referrer.indexOf(“google”) = 0 || document.referrer.indexOf(“yahoo”) = 0 || document.referrer.indexOf(“bing”) = 0) {
var categories = [3679];
if (categories instanceof Array categories.length 0) {
var primaryCatId = categories[0];
epoParams += “catId=” + primaryCatId + “referrer=search”;
}
else {
epoParams += “typeId=” + defaultTypeId + “referrer=home”; // default is ‘home’ behavior
}
}
// Default is to show like coming from homepage
else {
epoParams += “displayId=11referrer=home”;
// default is ‘home’ behavior
}
return epoParams;
}
/**
* @param jqo Original jquery object target
* @param divString The div to be inserted.
* @return Difference in height between original placement target and final target.
* Checks first 6 elements for an allowable placement (600 pixel window).
* If none, check nearby for elements that are not right avoids.
* If none, place element before current target.
*/
function applyInsert(jqo, divString) {
if (debug) {
console.log(“applyInsert at top and jqo index is: ” + jqo.index());
}
for (var i=0; i 0) {
children = $(“#drr-container”).children().slice(jqo.index(), allowElement.index() );
}
else {
children = $(“#drr-container”).children().slice(allowElement.index(), jqo.index());
}
if (children != null) {
children.each(function(i) {
if (debug) {
console.log(“About to add this element’s height to heigh diff offset”);
console.log($(this));
}
height += $(this).height() + grafHeight;
});
}
if (offset 300) {
if (debug) {
console.log(“isRightAvoid: found pre. return true”);
}
return true;
}
if (jqo.is(“figure”) jqo.hasClass(‘large’)) {
if (debug) {
console.log(“isRightAvoid: found figure.large return true”);
}
return true;
}
if (jqo.is(“figure”) jqo.hasClass(‘medium’) jqo.hasClass(‘inline’)) {
if (debug) {
console.log(“isRightAvoid: found figure has class medium and inline.”);
}
return true;
}
if (jqo.is(‘div’) jqo.hasClass(‘table-wrapper’)) {
if (debug) {
console.log(“isRightAvoid: found div with class table-wrapper”);
}
return true;
}
if (jqo.is(‘aside’)) {
if (jqo.hasClass(‘sidebar’) !jqo.hasClass(‘medium’)) {
if (debug) {
console.log(“isRightAvoid: found aside with class sidebar, without class medium”);
}
return true;
}
if (jqo.hasClass(‘statsTable’)) {
if (debug) {
console.log(“isRightAvoid: found aside with class statsTable”);
}
return true;
}
}
if (jqo.hasClass(‘download-asset’)) {
if (debug) {
console.log(“isRightAvoid: found class download-asset return true”);
}
return true;
}
if (jqo.hasClass(‘tableLarge’)) {
if (debug) {
console.log(“isRightAvoid: found class tableLarge return true”);
}
return true;
}
if (jqo.hasClass(‘reject’)) {
if (debug) {
console.log(“isRightAvoid: found class reject. return true”);
}
return true;
}
if (jqo.is(‘table’) jqo.hasClass(‘scorecard’)) {
if (debug) {
console.log(“isRightAvoid: found div with class scorecard”);
}
return true;
}
}
return false;
}
// Return true if element has class ‘reject’: will not place drr modules/ads next to these elements
function isRightReject(jqo) {
console.log(“in isRightReject”);
if (jqo != null) {
if (jqo.hasClass(“reject”)) {
if (debug) {
console.log(“isRightReject: found ‘reject’ class”);
}
return true;
}
return false;
}
return false;
}
// Returns true if height of all elements after this one is more than 500; false otherwise
function elementNotNearEnd(element, pixelWindow) {
if (pixelWindow == null) {
pixelWindow = 500;
}
if (element == null) {
return false;
}
var remainingHeight = 0;
var children = $(“#drr-container”).children().slice(element.index());
if (children == null) {
return false;
}
children.each(function(i){
remainingHeight += $(this).height();
});
if ( remainingHeight pixelWindow) {
return true;
}
else {
if (debug) {
console.log(“Element too close to end. Remaining height is: ” + remainingHeight + ” and window is ” + pixelWindow);
}
return false;
}
}
/**
* Return true if need to avoid this element when placing left module.
*/
function isLeftAvoid(jqo) {
if (jqo.is(“figure”)) {
if (debug) {
console.log(“isLeftAvoid: found figure. return true”);
}
return true;
}
if (jqo.is(“aside.pullquote”)) {
if (debug) {
console.log(“isLeftAvoid: found pullquote. return true”);
}
return true;
}
if (jqo.is(“pre”)) {
if (debug) {
console.log(“isLeftAvoid: found pre. return true”);
}
return true;
}
if (jqo.is(“div.gist”)) {
if (debug) {
console.log(“isLeftAvoid: found github code block. return true”);
}
return true;
}
if (jqo.is(“aside”) jqo.hasClass(“sidebar”) jqo.hasClass(“medium”)) {
if (debug) {
console.log(“isLeftAvoid: found medium sidebar. return true”);
}
return true;
}
if (jqo.hasClass(“statsTable”)) {
if (debug) {
console.log(“isLeftAvoid: found class statsTable. return true”);
}
return true;
}
return false;
}
/**
* return true if there are no figures before the target placement that might bleed down into placement element
*/
function noPrevFigures($originalTarget) {
var targetIndex = $originalTarget.index();
var numElementsLookBack = 5;
var figureIndex = null;
var figureHeight = null;
var startIndex = targetIndex – numElementsLookBack
Phishing. It could happen to anyone, not paying attention after a long day at the office, or perhaps the attack is just a little too plausible to raise a red flag even among the security conscious. Phishing is using some electronic means to lure a target into giving up sensitive information such as credit card information or account credentials, or opening a malicious file on a device.
Although any electronic medium can be used as a conduit for phishing attacks — instant messaging programs such as IRC and AIM or SMS (text messages) on your cell phone for example — the most common attack vector remains email. From targeted attacks at large companies to basic catchall attempts sent to batch of gathered recipients, billions of phishing emails are sent every day.
Here is just one example of a phishing attack received recently by a colleague:
First of all, the recipient had not recently purchased a Bentley. This is a common phishing tactic, as the natural reaction is one of alarm. Someone else has compromised and used your information to buy something on your behalf. Perhaps your identity has been stolen, the worst nightmare of many in the digital age. Many such attacks are as simple as the one above, though more sophisticated attempts look like real receipts from stores such as Amazon complete with pictures of recommended products like the real Amazon receipts. Only further inspection would reveal that the email came from orders@amazone.com or amazon-reciepts@gmail.com, small matters that are easily missed, particularly when your heart is already racing from your potentially compromised credit card numbers.
Phishing attacks can either trick you into browsing to a dummy site, that looks and feels like the original, but instead sends your login to the attacker, or like in the case above can prompt you to open a file. By hovering over the link in the email above (or hold down the link to see a pop-up with the full URL on a phone or tablet), you can see it actually points to a link at dropbox.com instead of bentleyclassic.com, as one would expect if this were a legitimate receipt from a vendor. File sharing sites are a common resting place for malicious files or malware. Don’t download a suspicious file without taking the necessary precautions for malware analysis; in some case even just downloading the file is enough to infect your computer. You cannot rely solely on anti-virus software to protect you. While anti-virus is great at picking up threats it is familiar with, sophisticated malware is specifically crafted with bypassing anti-virus as a top priority. Generally speaking though, the end user should just leave a link unclicked if there is a doubt of its authenticity.
Of course it is perfectly normal for me to send a Dropbox link to one of my friends in an email. Context comes into play with phishing attacks; perhaps that is why they are such a difficult problem to solve. Very sophisticated phishing attacks are practically indistinguishable from legitimate email, and it only takes one mistake to give attackers access to your accounts or your internal network. Here are some key points to avoid becoming a victim of a phishing attack:
- Keep calm if you receive a strange email, such as a receipt for goods you have not purchased. Rather than a sign that your details have been compromised; this is often instead a phishing attack.
- Check the sender address on your received emails. Just because the sender name is Georgia Weidman make sure it is an address with which you have communicated with Georgia previously. If the sender is a business, make sure that the address for the domain is spelled correctly.
- Verify that links go where they say they do, and where you think they should. It is easy to make HTML links appear to point one place when they actually lead somewhere else entirely. Your email client should show you the actual link URL when you hover over it with a mouse or hold it down on a touch interface.
- If an email seems suspicious from someone you do know, follow up using a different medium (phone call, text message, instant message, etc.) to make sure the email is legitimate and not the result of your friend’s email account being compromised.
In these days when highly sophisticated attacks using unknown vulnerabilities are in high demand, it is sad that a simple attack that can be carried out for free and with little to no technical know how is still so successful. Education is the best way to combat phishing attacks, making end users aware of what to look for and how to react when they encounter this sort of attack.
This article is published as part of the IDG Contributor Network. Want to Join?
Apple’s new iPhone 6 hits the mark for technological excellence and stylish design, with a bigger
Get our daily newsletter
iPhone 6, or iPhone 6 Plus? It’s a conundrum, and with pre-orders starting on Friday, you have to
Scarlett Johansson, Jennifer Lawrence, Kate Upton… the sad list of naked celebs goes on. But what’s
Symantec’s board of directors unanimously approved a plan to break the company into two independent,
Hewlett-Packard’s plan to cut itself in two is being well-received by customers, though questions
Though it seems as if we’re sourrounded by innovative products, services and technologies, there’s a
Cisco, Sprint and Google all “collide” in the city’s plan to attract tech incubators, startups and
