#15unit 1online security and payment system

Spoofing

Impersonating a trusted source or system.

5-mark Exam Answer

5-mark answer

Spoofing involves attempting to hide a true identity by using someone else's e-mail or IP address. Laudon and Traver describe several forms of spoofing and related threats such as pharming and spam (junk) websites.

  • 1.Definition: hide true identity
  • 2.Email spoofing: forged sender
  • 3.IP spoofing: forged source IP
  • 4.Pharming: redirects links to fake sites
  • 5.Spam websites: link farms of ads

Spoofing involves attempting to hide a true identity by using someone else's e-mail or IP address. For instance, a spoofed e-mail will have a forged sender e-mail address designed to mislead the receiver about who sent the e-mail. IP spoofing involves the creation of TCP/IP packets that use someone else's source IP address, indicating that the packets are coming from a trusted host. Most current routers and firewalls can offer protection against IP spoofing.

Spoofing a website sometimes involves pharming — automatically redirecting a web link to an address different from the intended one, with the site masquerading as the intended destination. Links designed to lead to one site can be reset to send users to a totally unrelated site — one that benefits the hacker.

Although spoofing and pharming do not directly damage files or network servers, they threaten the integrity of a site. If hackers redirect customers to a fake website that looks almost exactly like the true site, they can collect and process orders, effectively stealing business from the true site. Hackers can also alter orders — inflating them or changing products ordered — and then send them on to the true site.

In addition to threatening integrity, spoofing also threatens authenticity by making it difficult to discern the true sender of a message. Spam (junk) websites (also called link farms) are a related threat: sites that promise to offer some product or service but in fact are just collections of advertisements for other sites, some of which contain malicious code.

A customer clicks a link that looks like their bank's website, but pharming redirects them to a fake site that looks identical. The customer enters login details, which the attacker captures and uses to steal from the real account.

Spoofing, pharming, and spam websites threaten the integrity and authenticity of e-commerce sites, allowing attackers to mislead users, steal business, and deliver malicious code through deceptive identities.

spoofinge-mail spoofingIP spoofingpharmingspam websitelink farm

The exam interface follows the university paper pattern: Section A & B carry 5-mark questions; Section C carries objective questions.