Win Sky+HD for a year and a trip to Barcelona


Wormwood,
I must confess that I was taken aback by your e-mail requesting that I share with you the secrets of my phishing success. But I am impressed with the audacity of your request, your ability to find a way to contact me and, perhaps most importantly, that you have discovered my real name. Given that fact, and that I have now made quite enough money to live on comfortably, I probably should pass on my knowledge to a successor and retire gracefully.
The first step on the road to becoming a master phisher is to pick a jurisdiction from which to operate. Sadly, given the requirement for a reasonable internet connection, there are fewer places where one can go to earn a decently dishonest living in peace. Current popular haunts include eastern Europe, Russia, and that old favourite, South America.
Once safely entrenched, it's time to pick your target. The traditional companies, such as Paypal and the major American banks, are now rather passé, and eBay phishes have become less effective with the introduction of countermeasures in the eBay toolbar; which blocks access to known spoof sites.
No, the way of the immediate future is micro-marketing - focusing on smaller financial institutions such as credit unions and local banks. They have fewer customers, but you only need to reach handful of gullible (although I like to call them "generous") ones to make it all worthwhile.
Another option is the "novelty phish", where one picks up on recent or upcoming events and plays on the sympathies of the general public. One associate of mine had great success "raising campaign funds for George Bush" at around the time of the last US Presidential election. Similar, more recent efforts have involved Hurricane Katrina. The key to success here is picking a subject where the heart will overrule the head. People are credulous creatures, eager to believe. You must make it easy.
So, once you have chosen your target, you must construct a convincing site. A quick and easy way is to save the real thing from your browser and tweak it to send the information back to yourself. Modern browsers make this particularly easy, as you can "Save Entire Page" to capture all of the associated images and style sheets.
Alternatively, and rather cheekily, you can copy the code from a site being used by another member of the community. After all, I'm sure you get as much phishing e-mail as I do, and many of the sites offered are rich sources of good quality material.
The next step is to register a convincing domain name. So, if your target is mybank.com, register something like mybank-online.com or mybankinc.com. Consumers usually don't know exactly which domains their bank operates from – and, in fact, many banks help us out by using multiple domains and redirecting between them seemingly at random, adding to a delicious feeling of confusion in the user's mind.
When you hit the big leagues, you'll be hosting multiple sites on networks of zombie computers, aka "botnets", made up from the home PCs of unsuspecting, ordinary people who haven't yet realised the need to use a firewall and to not run executable attachments sent to them by e-mail. At that point, you probably won't bother registering a domain for each site. Most people careless enough to fall for phishing scams are happy to put their credit card number into any form which asks for it politely, domain name or no domain name.
The same applies to SSL (that little padlock icon); as getting an SSL certificate usually requires revealing information about yourself, and as laudably many consumers don't bother themselves with the indicators put into browsers for their benefit, I wouldn't bother.
It's getting late, and I must retire to bed. However, that should have given you a great deal to think about. I must confess, I'm rather enjoying documenting my methods; its given me many opportunities to reminisce. When I next find the time, I will write to you of the steps required to attract "visitors" to your newly-minted site, and the safest ways to use the information obtained.
Yours cordially,
Screwtape
(With apologies to CS Lewis)
Read Screwtape's further missive here.
Gervase Markham works for the Mozilla Foundation, a non-profit organisation dedicated to promoting choice and innovation on the internet. His blog is Hacking for Christ
Explore your passion for food with the delights of Thai, Indian & Chinese cooking
In our new series, Tony Hawks takes a dry, wry look at modern life - junk mail, interminable meetings and snooty sales assistants
Read the training tips and advice that helped our London Triathletes
Read our exclusive 100 Years of Fleming and Bond interactive timeline, packed with original Times articles and reviews
The latest travel news plus the best hotels and gadgets for business travellers
Shortcuts to help you find sections and articles
2007
£30,000
2006
£14,337
2008
£39,937
Great car insurance deals online
c.£75,000
GlosFirstmeansbusiness
Gloucestershire
£32,795 - £41,545
Universitry of Southampton
Southampton
£
£32,795 - £41,545
Universitry of Southampton
Southampton
Competitive Package
Npower
West Midlands
1 & 2 Bed apartments
From £249,995
Great Investment, River Views
Great Dubai Investment Opportunities
from £89,950
low-cost ownership homes in London
Las Vegas SALE!
£POA
With Ramblers Worldwide Holidays!
£POA
List your property with two leading travel websites
£POA
Great travel insurance deals online
Contact our advertising team for advertising and sponsorship in Times Online, The Times and The Sunday Times. Globrix Property Search - find property for sale and rent in the UK. Milkround Job Search - for graduate careers in the UK. Visit our classified services and find jobs, used cars, property or holidays. Use our dating service, read our births, marriages and deaths announcements, or place your advertisement.
Copyright 2008 Times Newspapers Ltd.
This service is provided on Times Newspapers' standard Terms and Conditions. Please read our Privacy Policy.To inquire about a licence to reproduce material from Times Online, The Times or The Sunday Times, click here.This website is published by a member of the News International Group. News International Limited, 1 Virginia St, London E98 1XY, is the holding company for the News International group and is registered in England No 81701. VAT number GB 243 8054 69.