republican-creole
Search:  

 
 
   News
newer
story category What’s Your Phishing IQ?
Take the quiz; all of the cool kids are doing it.
(old news - 03:21PM Saturday Jul 28 2007)
tags: security · scam
Phishing scams are on the rise. Emails from scammers posing as IRS and other government agencies “attempt to trick consumers into divulging personal financial information.” Are you safe? McAfee is offering a ten-question quiz that you can take to see how well you know your phishing scams; the results show you why you were right or wrong on your responses. If you have a need to be at the top of the class, you can compare your score with some of our users here.

Related:
  1. Fortune 1000 Spam
  2. Phishing Scammers Pose As IRS
  3. DNS Hacks: 'Phishing 2.0'
  4. Vishing Identity Theft On The Rise
  5. Thursday Evening Links
  6. Tuesday Evening Links
  7. Wednesday Evening Links
  8. FoxNews.com Serving Up Infected Ads?
Forums » What’s Your Phishing IQ?
view: topics flat text 
Post a:
page: 1 · 2

Potaje
Premium
join:2002-07-28
Miami

9/10

Got 9/10

Missed the last one about SSL certificate or something.

hayabusa3303
Over 200 mph
Premium
join:2005-06-29
clubs:
·QuantumVoice
·AT&T Southeast
·RoadRunner Cable

Re: 9/10

said by Potaje See Profile :

Got 9/10

Missed the last one about SSL certificate or something.
Ditto. same here

trparky
Bite My Shiny Metal Ass
Premium,MVM
join:2000-05-24
Cleveland, OH
clubs:

Re: 9/10

Ditto.
--
Tom

Trimline
Premium
join:2004-10-24
Orlando, FL
·Callcentric
·AT&T Southeast
·RoadRunner Cable

Yippee.

YOU ANSWERED 10 OF 10 QUESTIONS CORRECTLY
Rating: Safety Guru

Nice work! Your practically clairvoyant knowledge of the Web allows you to spot even the most realistic looking spoofed sites. We're impressed!

That's the one's *we* know of. Always take caution.
--
FWD#537129

EdibleTarget
Real Gamers Dont Use Consoles

join:2004-12-02
Lowell, MA
I got 9/10, got confused on the amazon one

what gets to me, is the fact that once scammers learn to spell, were all screwed (according to this quiz) =P
xo

join:2007-06-15
Perry, FL

Re: 9/10

we're*

and i agree. ;]
MrBentor

join:2003-02-18
Seattle, WA
YOU ANSWERED 10 OF 10 QUESTIONS CORRECTLY
Rating: Safety Guru

I'd better go good on a test like that - or I would have to fire my self...
radougherty

join:1999-07-23
Austin, TX
·RoadRunner Cable

said by Potaje See Profile :

Got 9/10

Missed the last one about SSL certificate or something.
I was going to say false but blew it and said true.

Jameson
10-8
Premium
join:2004-05-28
Fallbrook, CA
clubs:
10/10

furlonium
Computer Over? Virus equals Very Yes?

join:2002-05-08
Bethlehem, PA

Yay!

YOU ANSWERED 10 OF 10 QUESTIONS CORRECTLY
Rating: Safety Guru

I like how the one site said "their have been" instead of "there"

Grammar is a good way to check, too.

dvd536
as Mr. Pink as they come
Premium
join:2001-04-27
Phoenix, AZ

Re: Yay!

said by furlonium See Profile :

YOU ANSWERED 10 OF 10 QUESTIONS CORRECTLY
Rating: Safety Guru

I like how the one site said "their have been" instead of "there"
I've seen alot of that here too
--
You can never be too rich, too thin or have too much Bandwidth

alg
Just a shot away
Premium
join:2001-04-10
Houston, TX
clubs:
·Earthlink Cable Mo..

Re: Yay!

said by dvd536 See Profile :

said by furlonium See Profile :

YOU ANSWERED 10 OF 10 QUESTIONS CORRECTLY
Rating: Safety Guru

I like how the one site said "their have been" instead of "there"
I've seen alot of that here too
Indeed.
--
Stop spamming the forums with Mafia games already.

Rob
In Deo speramus, God Bless the USA
Premium
join:2001-08-25
Kendall, FL
·Comcast


1 edit

Rating: Safety Guru

YOU ANSWERED 10 OF 10 QUESTIONS CORRECTLY
Rating: Safety Guru

Nice work! Your practically clairvoyant knowledge of the Web allows you to spot even the most realistic looking spoofed sites. We're impressed!

Here are all the examples, for those who didn't want to do the quiz.

»cache01.ae1.net/8c985935a22567f0···8fcc.jpg

wifi4milez
Big Russ, 1918 to 2008. Rest in Peace

join:2004-08-07
New York, NY

9 out of 10!

Some of those questions were difficult to figure out. Overall a very good test for those who use the web a lot!
--
я люблю Денди!

wee96
Your Local Confederate

join:2000-04-12
Clinton Township, MI

Neat

10 of 10 woo hoo.

ColorBASIC
8-bit Fun
Premium
join:2006-12-29
Corona, CA

8/10

I didn't think of checking for grammar and spelling mistakes so on a few I guessed. But those sites were 2 I don't have an account with so a phishing attack wouldn't have worked on me anyway.
--
Macintosh Users Group Serving the Inland Empire

Snickerdo
Premium
join:2001-02-28
Niagara Falls, ON

Re: 8/10

That's the first thing you've gotta check. Also checking for some obvious things, like credit card numbers and poor HTML coding helps too.

YOU ANSWERED 10 OF 10 QUESTIONS CORRECTLY
Rating: Safety Guru

BloodRoses
Gods lend wings to tainted hearts
Premium
join:2003-03-17
clubs:
I got 8/10 as well... I didn't think to check the address bar since the text was so funky and the Windows UI is a bit confusing to me.
--
Cheers,
Stephanie - www.GlitterFaerie.com

Transmaster
Don't Blame Me I Voted For Bill and Opus

join:2001-06-20
Cheyenne, WY
Ditto here did spot the bad grammar.

pokesph
It Is Almost Fast
Premium
join:2001-06-25
Sacramento, CA
clubs:
·Comcast

Phished!

hmmm 8/10

the Amazon site caught me off-guard. I'm not too sure on the last question.. it's pretty hard to spoof a legit SSL cert.. it does have to be verified through a 3rd party - so not sure why they say it can be spoofed (I assume it's not self-signed, and I DO look at the certs myself..)
ottawa_guy

join:2005-06-03
Ottawa, ON

Re: Phished!

Yep 9/10... The capital one site got me. The one I chose looks like the Canadian site, which I do have an account on.

Rogue Wolf
Ate The Last Of The Pumpkin Pie

join:2003-08-12
Troy, NY
·RoadRunner Cable

Re: Phished!

said by ottawa_guy See Profile :

Yep 9/10... The capital one site got me. The one I chose looks like the Canadian site, which I do have an account on.
Same one got me, only because the one I thought was a fake asked for the SSN number. That always throws up red flags for me. I guess I forgot to check the writing on the wall... err, I mean the page.
--
Let not the Demon in your thoughts.
Let not the Demon in your dreams.
Lest you should awake one morn,
And find the Demon within thee.
whoamIoramI

join:2004-05-17
Jersey City, NJ

6/10

Damn, I thought I did good and I find myself as being great at finding shit like this.

I had my mom do it and my dad. Both got 3/10

No wonder these shit heads make so much money.
BosstonesOwn

join:2002-12-15
Everett, MA
clubs:
·Comcast
·Comcast Formerly ..

Re: Phished!

said by pokesph See Profile :

hmmm 8/10

the Amazon site caught me off-guard. I'm not too sure on the last question.. it's pretty hard to spoof a legit SSL cert.. it does have to be verified through a 3rd party - so not sure why they say it can be spoofed (I assume it's not self-signed, and I DO look at the certs myself..)
Any one can generate ssl certs. I myself do it on servers. The major thing is that they will most times pop up a box saying hey the cert is signed but not by xxxxxx company would you like to proceed ? and most people click through.
If malware is on the machine it can and will put the site into the trusted zone and the ssl pop up never shows up.

I generate my own for most servers because I encrypt all traffic even on the lan.
--
"It's always funny until someone gets hurt......and then it's absolutely friggin' hysterical!"

jsimmons
Premium,MVM
join:2000-04-24
Falls Church, VA

Got 10 of 10.

Not a guru here... but very mindful of Phishing scams.

stomp357

join:2003-04-13
Lake Charles, LA
·Suddenlink

I got 10 of 10 right

I'm so "anal" about stuff dealing with my money. Last year my debit card number was lifted from somewhere, and $400.00 was withdrawn $40.00 at a time over a 2 day period (Saturday, & a Sunday) before I checked my account online, and seen the transactions. The money was being deposited into an Alipay.com account overseas. Have no idea how they got the number as the only online sites I use my debit card is with Amazon, Newegg, ComputerGeeks and HighTech (Aces High WWII multiplayer flight sim.).
I canceled that card, and the bank refunded all the charges a week, or so later. I now only do money order transactions with vendors, and pay my bills through my banks website.

swhx7
Premium
join:2006-07-23
Elbonia
·RoadRunner Cable


1 edit

Re: I got 10 of 10 right

If you have a credit card, it's a lot easier than money orders for online transactions, and safer than a debit card. There is theoretically a $50 risk, but in practice you can dispute transactions and get them taken off. And it won't expose your bank account.
pcnetworx1

join:2005-09-21
Bethel Park, PA

10/10

Would be funny if there was a bonus game at the end for a perfect score.

chakey
Premium
join:2004-06-14
Gladstone, NJ
clubs:

9/10

Amazon got me.

M A R K
St. Ides Heaven
Premium
join:2001-06-15
Long Island
clubs:

Re: 9/10

said by chakey See Profile :

Amazon got me.
Same, 9/10
--
Neturei Karta

swhx7
Premium
join:2006-07-23
Elbonia
·RoadRunner Cable

Is this a useful quiz?

Also discussed here: »Can You Identify Phishing?

I won't repeat my rant, but some legit sites have grammar/spelling errors, and you can't be expected to know exactly which variation of a logo a company uses, or that sort of thing. Look at the URL first, and then consider what info the page asks for and why you would give it.

And if some of the pics in the quiz still don't have URLs showing, it's a bogus quiz designed to sell you something.
old_wiz_60

join:2005-06-03
Bedford, MA

Re: Is this a useful quiz?

Not seeing the URL makes it more difficult; a close look at the URL is the first thing I would do. Still, got 10 of 10. If you don't, for example, use Amazon, you could get fooled. If the web site has spelling/grammar errors it's still a red flag.

jmn1207
Premium
join:2000-07-19
Reston, VA

Re: Is this a useful quiz?

I missed the Amazon site question, too. Of the few in the quiz that provided the URL, that was all that was needed to identify the phishing site from the legitimate version.

amdaz
Premium
join:2000-12-29
San Francisco, CA
·Comcast

said by swhx7 See Profile :

Also discussed here: »Can You Identify Phishing?

I won't repeat my rant, but some legit sites have grammar/spelling errors, and you can't be expected to know exactly which variation of a logo a company uses, or that sort of thing. Look at the URL first, and then consider what info the page asks for and why you would give it.

And if some of the pics in the quiz still don't have URLs showing, it's a bogus quiz designed to sell you something.
WORD !
CWO333

join:2005-02-24
Chicago, IL
·1and1

said by swhx7 See Profile :

And if some of the pics in the quiz still don't have URLs showing, it's a bogus quiz designed to sell you something.
well, it has a recommended download of McAfee SiteAdvisor which I've been using for a few months now. Its completely free and never asks you to buy, subscribe, or register it. So I'm still wondering what you think they're trying to sell...

retrogame

join:2003-04-14
Auburn, MA

It's my birthday

YOU ANSWERED 10 OF 10 QUESTIONS CORRECTLY
Rating: Safety Guru

TK Junk Mail
Go ahead, make my day

join:2006-07-30
Ocean Gate, NJ

Re: It's my birthday

10/10, only because I know what the login page for Amazon looks like.

Jim Gurd
Premium
join:2000-07-08
Plymouth, MI
·Comcast

8/10

Click for full size
This is allegedly the real site but look at the message I highlighted. That's why I suspected it was the fake.
I got this one wrong as well as the SSL one. The SSL question is kind of misleading though. Sure a fake site could have a certificate but the name wouldn't match the site they were impersonating so it's not really much of a threat.

Doctor Four
My other vehicle is a TARDIS
Premium
join:2000-09-05
Dallas, TX
·AT&T U-Verse

Re: 8/10

In my case, it helped that I was an Amazon customer. The
fake page didn't ask whether or not the viewer was an
Amazon customer already - it just asked for your email
address and password straight away. Also, there was no
option to sign in using the standard vs. secure server.
--
"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)

BloodRoses
Gods lend wings to tainted hearts
Premium
join:2003-03-17
clubs:

Re: 8/10

That's what gave it away for me as well.

Jim Gurd
Premium
join:2000-07-08
Plymouth, MI
·Comcast

The image I posted was from the legitimate site. Why would they post something like using the standard server if you were having problems with the secure one? Can't they fix the bugs with the secure site?

I thought it was the fake because of that message. To me putting such a message on their website is very unprofessional and a perfect example of poor design.

DrModem
Premium
join:2006-10-19
USA
The amazon site was easy to spot for me. cause I know they have 41 product categorys instead of 40. plus on the fake there are two arrow buttons next to the "Your Lists" link.

Quiglag
God is Love
Premium
join:2004-09-19
Ontario, CA
·SharkSpace

10/10 here

I got a 10 out of 10, but my common practice is to never click on any link in an email if it is something i have to login to use. I will just type in the address myself. Places like ebay or paypal will also have the message listed when you log in.
--
\o/ My Website | Check Out My Gallery

stomp357

join:2003-04-13
Lake Charles, LA
·Suddenlink

Re: 10/10 here

said by Quiglag See Profile :

I got a 10 out of 10, but my common practice is to never click on any link in an email if it is something i have to login to use. I will just type in the address myself. Places like ebay or paypal will also have the message listed when you log in.
Yeah. The last time I clicked an email link was a few years back. I ended up with some spyware, and formatted, and reinstalled OS to get rid of it as Adaware, & Spybot S&D couldn't get rid of it.
jkb246

join:2000-03-18
Newark, NJ

10 out of 10, but that Amazon ? was really hard

Had to look at that Amazon site for a min before I selected the right one. Good quiz. I'm going to send it to my mom before she is caught in the net
Zoly

join:2004-01-04
Houston, TX

10 out of 10

Yeh, I have passed the test but it doesn't mean anything though...
2 years ago my CC was charged online for $5000, right 1 month after lexus nexus lost a big portion of their database.

Capital One called me to ask about suspicious charges around 2 am and I said I never ordered those things...

All I had to do is to destroy my CC and they sent me a new one...
oonja

join:2007-04-25
Wilsonville, OR

Bad Question

I got 8 out of 10 but the check who the email is from is a bad question. Looking for a bad sender name or domain is a legit way of finding a phishing scam. True good scammers can fake that, but it is still one of the first things you look for.

strfox18
Nothing To See Here
Premium
join:2001-08-15
Lake Havasu City, AZ
clubs:

Re: Bad Question

You don't have to be a good scammer to change the sender name. Changing the sender name is very easy.
thehinge

join:2005-11-07

Spelling:

I think I see why one should be suspicious about spelling and grammar. Some guy spoofing a website can't or won't get like thirty people to check out the site to be sure it's professional. An organization like an online bank would probably proofread for a couple of days before posting, I think.
OCP
Premium
join:2004-10-11
USA

9/10

I did not notice the grammar errors. Good tip though. I expected it to be easier.
MmmPancakes

join:2007-05-29
Toronto, ON
·TekSavvy Solutions..

Re: 9/10

I just got the SSL one wrong. I agree with previous poster's reasoning, kinda hard to fake SSL..

The Amazon one was hard, lol. I ended up going by the one with the "!" as being fake, haha.

Why do phishers not know how to spell ?
BosstonesOwn

join:2002-12-15
Everett, MA
clubs:

Re: 9/10

Because a majority are not from the US and "engrish" is not their primary language.

menumorut
BE an American.

join:2005-07-04
Queens Village, NY

Re: 9/10

said by BosstonesOwn See Profile :

Because a majority are not from the US and "engrish" is not their primary language.
Its not only the spelling, is the context of the words and the professional wording format that is used (on web pages) in US, to which Americans got so accustomed and is hard to fool them.

A foreigner that lived in the US long enough, payed attention and learned form the American way of life can scam 90% of the Internet users in to oblivion.
--
Give the world changes at a pace it can absorb.

supergirl

join:2007-03-20
Pensacola, FL
·Cox VOIP
·Skype
·Cox HSI
·AT&T Southeast
·magicjack.com

Re: 9/10

I thought both Amazons were fake (the URLs looked weird) but went totally by the login screen so got 10/10.

Personally, I think PayPal itself is a scam. Well, just another EBay rip-off.

Anyone sending me email with weird stuff, I delete. The Nigerian one has been around forever.

MySpace has made it difficult to check scams since everything starts with a "mslinks..." url. Their ads have all kinds of scams themselves.

The tip: never login to a site unless you personally typed the URL yourself. I do have a personal page with all my finance links on my computer (a local webpage) so it's done for me.
--
Saving the world keeps me busy. However, I find Earth very primitive from my home planet of Krypton.
-Supergirl
Forums » What’s Your Phishing IQ?page: 1 · 2


Sunday, 08-Nov 20:51:11 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole