What is pharming?

Pharming is a scamming practice in which malicious code is installed on a personal computer (PC) or server, misdirecting users to fraudulent websites. The cybercriminals are using this data to carry out various types of illegal activities.

How does pharming work?

The technique is used to target malicious machines and Internet content. The attackers rely on the hijacked DNS traffic

The DNS server translates domain names, such as google.com, to Internet Protocol (IP) addresses, such as If the IP address of a website in the DNS server is changed by a pharmer, then the computer will have the wrong — or corrupted — IP address when accessing that website. By causing the DNS server to give the user the incorrect answer, the pharmer can send users to a fake site for some nefarious purpose.

Pharming techniques

A pharming method called DNS hijacking is said to be causing lots of havoc. This method uses an email service that sends out requests for information that are mangled into requests for legit dataThe real site will show an alert to the user.

“Spyware is easily confused with legitimate software. Often, it can be found hiding in exactly the same positions, close enough together to be visible at the same time, with just one keystroke away from being activated on the system” In the event of a security breach even a novice user can literally take back control from someone with 20 years experience in the technology field

A third strategy is called DNS and IP and redirecting the traffic away from your primary IP address. Essentially, it tricks someone who thinks they are actually accessing a legitimate website into visiting an unofficial one instead In this method of pharming, individual PC host files don’t need to be corrupted. Instead, the problem occurs in the DNS server, which handles millions of internet users’ requests for URLs. Victims then end up at a bogus site without any visible indicator of a discrepancy.

Spyware removal programs cannot deal with this type of pharming because nothing is technically wrong with the end users’ computers.

What is the difference between pharming and phishing?

Pharmacy customers should be alert to the use of Pharming tactics, particularly because if they don’t pay attention then their medication can indeed get lost or stolen. Unscrupulous pharmacy salespeople may even start pressuring their patients to take generic medications so that they can bill them for an overpriced brand name drug.But, in pharming, larger numbers of computer users can be victimized because it is not necessary to target individuals one by one, and no conscious action is required on the part of the victim.

Phishing is an attempt to extract sensitive information, such as usernames, passwords and credit card details, by masquerading as a trustworthy entity in an electronic communication. Phishing is typically carried out by email spoofing or instant messaging (IM), and it often directs users to enter details at a fake website, whose look and feel are almost identical to the legitimate one.

The best way to avoid phishing is to remain vigilant and add it to your protection strategy. For example, a hacker may not get every bank password from a single phishing email, but if they can get one response out of 10,000 unsuspecting victims, their scam succeeded.

Pharming, on the other hand, is a form of phishing that uses a DNS system to send a user to a fake website. Instead of sending an email that looks like it’s from a user’s bank, pharming directs victims to a website that looks like their bank’s website.

Signs of pharming

While there are steps to take to protect a system against pharming, there are two significant signs that pharming may be taking place:

  • A slightly different site link and appearance. Pharming websites look slightly different than legitimate sites — using different colors, logos or graphics — but they attempt to trick a user into thinking the site is safe to visit. Sophisticated pharmers will try to convince users that they are on a legitimate site by using familiar logos and graphics to make users feel safe and secure. In addition, the website URL might be slightly different. For example, a pharming site might have minor spelling errors.

  • An unsecure connection. Although Hypertext Transfer Protocol Secure (HTTPS) is a widely adopted security measure to protect users and their data, pharming scams continue to prey on unsuspecting users by luring them to insecure, fake websites. Pharming sites use a variety of tricks to appear legitimate, including using well-known logos and URL redirects. However, one commonality among all of these sites is the use of http instead of https in their URLs.

Protecting against pharming

There are many steps that can be taken to prevent pharming and other malicious attacks from occurring:

  • Keep computers updated. Keeping a computer’s operating system (OS) and other software updated is important for protecting against pharming because the latest software patches fix the vulnerabilities that hackers use to attack computers.

  • Clear browser cache. While surfing the internet, browsers store information about the sites visited. If the same computer is used with a different internet connection, it is possible for a nefarious user to access the computer’s information. To avoid this problem, it’s a good idea to clear the cache before using a new internet connection.

  • Download antivirus and antimalware software. Using an antivirus program is a common and effective way to protect a computer from online threats and to protect against pharming. Malware is often used to exploit security vulnerabilities in OSes and browsers and usually spreads using malicious code or links to malicious websites.

  • Use HTTPS instead of HTTP. HTTPS is the secure communication protocol of the internet. “Secure HTTP” in the form of secure HTTPS is a better and more secure approach than HTTP and in theory makes it easier to use; however, in practice we do not see any real difference. And it has been proven that TLS 1.0 is fundamentally insecure against cipher suites with the known MD5 message-digest function. The protocol also does not come with strong

  • Use a virtual private network (VPN). A VPN hides your IP address from the Internet, making you immune from cyber-attacks. A VPN secures a connection between a remote location and a local network

  • Use bookmarks. Bookmarking frequently accessed sites and not clicking on links in emails or on social networking sites will reduce the chance of pharming

