Before starting with the topic one should be clear definition of Phishing. Phishing is a way of attempting to acquire sensitive information such as passwords,usernames, and credit card details by masquerading as a trustworthy entity in an electronic communication. This is similar as Fishing, where the fisherman puts a bait at the hook and pretend to be a genuine food for fish. But the hook inside it takes the complete fish out of the lake. Communications purporting to be from popular social web sites, auction sites, online payment processors or IT administrators are commonly used to lure the unsuspecting public. Phishing is typically carried out by e-mail spoofing or instant messaging, and it often directs users to enter details at a fake website whose look and feel are almost identical to the legitimate one. Phishing is an example of social engineering techniques used to deceive users, and exploits the poor usability of current web security technologies. Attempts to deal with the growing number of reported phishing incidents include legislation, user training, public awareness, and technical security measures.

Here in this post we will discus a little about what is phishing. Please note what we are covering is ways to protect yourself from phishing scams here is just basics and not a phishing tutorial. In phishing attack, an attacker creates a fake login page of a legitimate website and lures victim to login using it. The site under attack is known as phished site and the fake login page used for capturing or stealing information is known as phished page.To perform phishing attack an attacker performs following steps as given below: