Saturday, July 3, 2010

ICICI Phishing Alert

Dear Readers,

Today is really a challenging day for me at the same time a big lesson learnt by me. I am holding ICICI account for more than 5 yrs. I am very much satisfied with ICICI banking system. 

One fine day on June 29th 2010 i was busy in starting to my office where my calendar alerts me with few action items for the day. I was completing those task and in parallel i was checking my emails. I received the below email from Customer.care@icicibank.com which is the exact customer care ID of ICICI bank.

I thought they need some survey details and by seeing from address (in hurry) i just clicked on the link in the email which directed me to an another webpage which looks like ICICI bank webpage. It asked my Internet ID,Password,Card#,Grid#, Mobile# etc. I just entered all these details. When entering Grid# something stroked in my mind and i didn't bother. I also checked the URL(looked like an ftp site) on which i didn't felt it's a fake URL. I just submitted the information requested and left office.



After couple of days i received an sms to my mobile stating new payee added and that sms has an URN (Unique Registration Number). As i am out of town my sister saw the message and within 1 hr of that sms arrival, she receives a call to my mobile stating "We are from ICICI head office Mumbai and we have sent one URN please let us know the URN if you didn't say your online ID will be deactivated". As they said head office/deactivation of bank ID she also didn't try to think what is about she just gave the URN :(. When i called her casually she informed me on this and i called bank then deleted the registered payee, changed my online passwords and applied for new card by deactivating the existing card :(. 

When i click on the same link which they have sent me on June 29th 2010 i was redirected to some European website :(.  As everything happened in 1/2 hour i didn't loose any money. Thank God!

I just posted this to make sure this doesn't happen to anyone. I also visited all my email id's and changed my passwords for safety. Though i address on many security issues @ my work place and advise people on security, due to my hurry i have missed myself on some basic checks. We cannot raise a wall for ourself to everything. People are always running behind us to break the wall. 

I would like to thank ICICI bank for having many security measures in money transfers like sending URN,Grid#, PIN verifications etc which made some loop hold and strike us. But still it's our responsibility to keep our credentials safely.

The event which happened for me is known as PHISHING. It's nothing but an act of sending email that falsely claims to be from a legitimate organization. This is usually combined with a threat or request for information: for example, that an account will close, a balance is due, or information is missing from an account. 

How to avoid such things?

  1. Never enter/share your credentials with anyone/anywhere except by directly entering into bank URL's.
  2. Keep an track of your account activity on everyday basis as it wont take more than 2-4 mins daily.
  3. If your mobile is handled by any of your family members please ask them not to disclose any of your personal details/your current locations/any sms that sent to your mobile.
  4. Try to use KeyScrambler kind of add-ons to protect your key strokes
  5. Change the passwords every 45 days without fail. 
  6. Keep a track of your payee lists every one week at least.


Thursday, July 1, 2010

Why iPhone4 and why not HTC?

Tweet via e-mail

Creating Tweeter account and tweeting becomes a habit for many of us. Most of companies/colleges/organizations they restrict these kind of social networks to be accessed in their networks for security reasons. For this reason we wont be able to tweet our message to the world. But we have a cute solutions for this. 

We can tweet with our account by sending emails to a particular account. 

Yes, just sign up for a free account here and start sending emails to that account which will automatically tweet to the world.



Below are the list of features of this site.

  • Access to your tweeter account via email
  • Send/Receive tweets via email
  • Free to use
  • Add pictures to your tweeter home page.

Dictionary Disable/Enable in iOS4

Today i was discussing with my friend on some features of iOS4. He queried me stating his dictionary is not working for some reason, why so? I thought he didn't synchronize properly. Then finally we found the solution.

Step1: Goto Settings
Step2: Tap on General
Step3: Tap on KeyBoard
Step4: Make sure "Auto-Correction" is ON.

This way you will have dictionary and auto-fill words enabled. Follow the same step and OFF it for disabling.

Detect Suspicious Log ins

Dear Readers,

I know you all love Google as like me :). Yes, We all love you badly Google.

Mostly these hackers are targeting to access our email accounts to know our personal informations. Google has taken many steps to prevent these types of attacks and keep you secured. Few months back Google has launched a new features for Google account holders. Yes, this feature is to secure your Google account from hackers.

This feature will trace your login information and report to you on any suspicious activity on your account. What is suspicious here is  it will notify you with a message when someone log's on with your credentials in various locations. How does it works is as per the IP address provided by us the automated system @ Google tracks your login credentials in different location and alerts you incase of any suspicious activity.

For Eg: If you are have registered your IP address in New Jersey, then Google starts tracking your accessibility of account information in various location and if some one tries to login in with your credentials in another 30 mins in Canada obviously which is not possible then you will be notified with a message from Google. It will prompt us to report as an abuse and we can change the password immediately. 

If your spouse or any authorized person uses then you can skip it :).