Phishing is a way of attempting to acquire information such as usernames,passwords, and credit card details by masquerading as a trustworthy entity in an electronic communication.(Wikipedia)
In a phishing attack,an attacker creates a dummy web site that appears to be identical to a legitimate web site in order to trick users into divulging private information.When a user visits the fake site,he is presented with a page that appears to be an authentication page for the legitimate site.On submitting their user name and password,however,the malicious site simply records the user’s now-stolen credentials,and hides his activity from the user either by redirecting him to the real site or presenting a notice that the site is “down for maintenance”.Most fishing attacks target the financial services industry,most likely due to the high value of phihshed information related to financial transactions.
Phishing typically relies on the fact that the user will not examine the fraudulent page carefully,since it is often difficult to recreate pages exactly.Also,unless the URL is falsified as a result of DNS cache poisoning,a simple glance at the address bar could provide clues that the site is fake.These attacks are often facilitated by spammers who send mass e-mails that claim to be from legitimate financial intitutions but which really contain links to phishing pages.See images below:
