Prepaid cash card is similar to debit card, with a card number, signature and company branding. It enables holder to purchase and make payment using an amount preloaded by the holder or someone else. However, it is not like debit card services which links to a bank account with an overdraft facility. Prepaid cash card users are only allowed to use the credit preloaded by them.
Group Members
Kam Pei Sun
Lim Wan Leng
Wong Ngan Teng
What is the time now?
Related Links
Blog Archive
-
▼
2009
(20)
-
▼
July
(8)
- Review a Local, Transactional E-Commerce Site.
- E-Goverment in Malaysia: Its Implementation so far...
- Corporate Blogging: A New Marketing Communication ...
- A Discussion on E-learning Offered in Malaysia Uni...
- Mobile Payment Systems in Malaysia: Its Potentials...
- Electronic Currency
- Credit Card Debts: Causes and Prevention
- The Application of Pre-Paid Cash Card for Consumers
-
▼
July
(8)
Other Blog Link in Tutorial 1
Labels
- WEEK 2: Introduction (4)
- WEEK 3 (4)
- WEEK 4 (4)
- WEEK 5 (4)
- WEEK 6 (4)
There are few categories of threat:
1. Accidental actions
This category encompasses problems arising from basic lack of knowledge about online security concepts and includes issues such as poor password choices, accidental or erroneous business transactions, accidental disclosure, and erroneous or outdated software.
Related problems occur as a result of misconfigured security products and information leakage resulting from insecure information transfers.
2.Malicious attacks
- Attack that specifically aims harm computers.
- Types of Malicious attacks:
a.Computer Virus:

-It is the most common form of malicious code.
-It is a program that attaches itself to other program.
-Major types of virus:
i. File Infectors
ii. System or boot-record infectors
iii. Macro Viruses
iv. Multi-part
-Example of computer virus:
I.

“Melissa” virus/worm - It will cause computer show down and face frequent failure.
II.

“I Love You” virus - A small piece of code attached to electronic mail which will cause an e-mail send to everyone in an address book, then damaging victims' machines.
III.Trojan horse - Personal information will be stolen as Trojan track into the computer.
b.Denial of Service Attacks (DoS)
- It is an attack on a web site that uses specialized software to send a flood of data packets to the target computer with the intention of overloading its resources and cause the network shut down.
c.Distributed denial-of-service attack (DDoS)
- A DoS attacks that gains illegal administrative access to as many computers on the internet as possible and uses these multiple computers to send a flood of data pockets to the target computer.
3.Online fraud
- It is a broad term covering Internet transactions that involve falsified information.
- Types of Online fraud:
a.Identity Theft
-Electronic commerce information can be intercepted as a result of vulnerabilities in computer security. Thieves can then take information such as credit card numbers and misuse on it.
b.Data Theft
-A term used to describe not only the theft of information but also unauthorized perusal or manipulation of private data.
Ways to help prevent Threats of online security:

- Use and update anti-virus software, anti spyware software and firewall frequently.
- Be aware of email attachments from unknown sources.
- Develop a strong password and change them frequently.
- Do not download free software unless you have verified that it is legitimate.
- Stay away from 'questionable' websites.
- Be cautious of pop-ups.
- Back up your data frequently.
- Always delete cookies in the computer to prevent track on the history/password.
In conclusion, we should prepare well before online to secure us being threat of online security.
Related Links: http://www.bsagovernment.com/downloads/MajorOnlineThreats.pdf http://www.vermontpcsolutions.com/articles/10-free-ways-to-help-prevent-malware-threats.html
Phishing is a new word produced from ‘fishing’, it refers to a new type of network attack where the attacker creates a replica of an existing Web page to fool users (e.g., by using specially designed e-mails or instant messages) into submitting personal, financial, or password by masquerading as a trustworthy person or business in an electronic communication. This information then can be used for future target advertisements or even identity theft attacks (e.g., transfer money from victims’ bank account).Example 1: Phishing email / Phishing website
A frequently used attack method is to send phishing e-mails to potential victims, which seemed to be sent by banks, online organizations, or ISPs. In these e-mails, they will makeup some causes such as password of your credit card had been mis-entered for many times, or they are providing upgrading services, to allure you visit their Web site to conform or modify your account number and password through the hyperlink provided in the e-mail. You will then be linked to a counterfeited Web site after clicking those links. Legitimate organizations would never request this information of you via email.

Example 2: JavaScript Obfuscation
There is a trend in phishing today to make an attempt to further fooling a victim in believing he/she is on a trusted page, at say, Netbank. Unmodified, a copied Netbank site will look like this on the phisher’s hosting server:

The location bar, which takes up approximately 2% of the screen height, accounts for virtually that all of the indication that a Web site is genuine. This is easily circumvented with a well known JavaScript vulnerability posted on the Bugtraq security mailing list in May of 2004, which uses a floating pop-up frame to change the address bar to the familiar:

The ability to produce “chromeless” frames outside the browser window using the window open JavaScript function continues to be available to Web developers, but thankfully, are now blocked by recent versions of Internet Explorer’s and Mozilla Firefox’s built-in “pop-up blockers,”.
Here is a quick checklist to bear in mind during our surfing, we should alert to the risks of phishing:
7. Never reveal your personal information to anyone; however although genuine or trustful requester may sound. Personal details should only know by you and is your personal asset. It is better to be careful a bite.
Related links:
http://internet.suite101.com/article.cfm/avoid_phishing_attempts
http://research.microsoft.com/en-us/um/people/chguo/phishing.pdf
http://y2u.co.uk/Knowledge_Information/Technology/RN_Computer_Phishing_Scam.htm
http://www.phishtank.com/what_is_phishing.php
http://www.planbsecurity.net/wp/503167001_PhishingDetectionandPrevention.pdf
There are some ways to safeguard our personal and financial data:
1. User ID
Avoid identifying information in user IDs, such as first initial and full last name. We should use a substitute name that avoids any reference to your name, job or other personal attributes can make tracking more difficult. Besides, we shall not use the same ID across multiple services.
2. Encryption and password security
Whenever we are transmitting data over private or public networks, we should assume that somebody could be eavesdropping on the packet data that we sent and receive. Therefore, when we transmitting sensitive data, we should use some form of encryption to protect our data. Besides, we should use stronger password to protect our access data. For example, use longer password or a combination of numeric and alphabet passwords. By using encryption and password security, we can ensure that no unauthorized people can view our data if they can physically access it.
3. Install and update antivirus and antispyware programs
Make sure antivirus and antispyware programs are well installed to protect our computer against viruses and Trojan horse from stealing or modifying our data on computer. In addition, we also need to keep our virus definitions up to date. Besides, we should regularly scan our computer system for spyware because spyware may affect performance of our computer.
4. Avoid accessing financial information in public
We should not access financial information and do any financial transaction in public such as coffee shop or cyber café that offers wireless access. It is because we do not know whether there have been installed spyware in their computer and hacker can easily get our information if there is no a strong firewall.
Related Links:
http://www.msisac.org/awareness/news/2007-03.cfm

MSC Trustgate is a licensed Certification Authority (CA) in Malaysia since 1999. They offer security solutions that are needed by individuals, enterprises, government, and e-commerce service providers using digital certificates, digital signatures, encryption and decryption.
It’s very important for an organization to ensure the security of their confidential data. Therefore, they can use certificates to secure their data and manage identification credentials from users and computers within and outside your organization. Examples of the certificates are:
Public Key Infrastructure (PKI)
PKI is a combination of software, encryption technologies, processes and services which safeguard communications and business transaction. It is done by exchanging digital certificates between authenticated users and trusted resources. By using PKI, an organization can achieve its objective of Confidentiality, Integrity, Authenticity and Non-repudiation of data.
Digital ID
Everyday, there are millions of transactions being carried out over the unsecured network. These transactions normally contain information such as customer’s details, company’s pricing decision and other highly confidential information. Such information can be easily altered if not properly encrypted. Examples of Digital ID are CryptoSuite and Secured E-mail.
Therefore, Digital ID provides protection to this information so that such information remains private in its transferring process by signing and encrypting transaction. It uses private key and public key performs following operations that supplement PKI:
Authentication
- Verification of real identity of an individual, computer, computer program & E-Commerce websites.
- Assurance of confidential data remains private
Authorization
- Assurance that only authorized users have rights access to private data
Integrity
- Assurance that stored data have not been amended without authorization
Non-repudiation
- Assurance that online users cannot falsely deny or repudiate their transaction
VeriSign
Furthermore, VeriSign is also one of the programs used by organization in Malaysia. MSC Trustgate is the first company in Asia which appointed as VeriSign Authorized Training Centre. VeriSign provides various types of security products such as digital certificates, payment processing, managed firewalls to mobile call roaming, toll free call database queries and downloadable digital content for mobile devices.
MyKey 
Besides Organization, Malaysian Government is also applying 3rd party certification program in National Identity Card (MyKad) of every citizen. MyKey is the PKI solution that works with our MyKad which allows us to conduct several Internet activities such as online submission of tax return, online banking and digitally sign documents.
E-Commerce is also known as ecommerce, electronic commerce or E-Business. Unlike the traditional method of commerce, E-Commerce is the act and science of buying, selling or exchanging products, services and information over the internet. Internet shopping has become one of the popular activities around us. With E-commerce, everyone can shop at anytime they want.Evolution of ecommerce is a history of a new, virtual world which is evolving according to the customer advantage. It is a world which we are all building together brick by brick, laying a secure foundation for the future generations. I strongly believe that e-commerce will keep on developing popular stages until anyone can just buy thing and shop from home.
http://en.wikipedia.org/wiki/Electronic_commerce
http://www.flysyk02.netfirms.com/Ecommerce/History.htm
In my opinion, an example of e-commerce success is eBay which is a famous website visited by many people. The eBay was born over Labor Day weekend in 1995, when Pierre Omidyar, a computer programmer, wrote the code for an auction website that he ran from his home computer. Today, Omidyar's hobby is known as eBay, the world's largest online marketplace - where practically anyone can practically sell anything at any time. With a presence in 39 markets, including the U.S., and approximately 84 million active users worldwide, eBay has changed the face of Internet commerce.eBay might be the first example where a commerce site has actually been built around a community where people are exchanging information and exchanging goods, services and merchandise. It is a software program that allows people, in one spot, to list down items of various interest and various degrees. It also allows people to be able to come to that very same site and look at what are available for sale and bid and buy those items. It uses the auction process as the method for establishing how merchandise is valued and eventually how it is exchanged between buyer and seller.
All eBay users can browse through listed items in a fully autamated way. The items are arranged according to topics, where each type of auction has its own category. They are having both steamlined and globalised traditional person-to-person trading. Their facilities are easy for buyers to explore and enable sellers list item for sale immediately within minutes of registering, the binding contracts of the auction is between the winning bidder and the seller only.
Another factor to consider is, people enjoy with the experience of the shopping bazaar. They enjoy the hunt, looking around for merchandise and they really enjoy the competition of the bidding process. Everybody likes to get a bargain, I think, in some way, shape, or form, likes to haggle a little bit over the price. The eBay auction format allows users to do that. The other thing is that as it has grown, it has become a very practical place to buy and sell collectibles or commoditie.
Related links:
http://www.ecommercetimes.com/story/2127.html
http://www.ebay.com/
http://news.ebay.com/about.cfm
http://www.scribd.com/doc/1020018/Seven-Secrets-to-eBay-Success








