<?xml version="1.0" encoding="UTF-8"?><xml><records><record><source-app name="Biblio" version="7.x">Drupal-Biblio</source-app><ref-type>17</ref-type><contributors><authors><author><style face="normal" font="default" size="100%">Sandeep K. Sood</style></author></authors></contributors><titles><title><style face="normal" font="default" size="100%">Phishing Attacks: A Challenge Ahead</style></title><secondary-title><style face="normal" font="default" size="100%">Information &amp; Security: An International Journal</style></secondary-title></titles><keywords><keyword><style  face="normal" font="default" size="100%">Browser Indicators</style></keyword><keyword><style  face="normal" font="default" size="100%">Cookies</style></keyword><keyword><style  face="normal" font="default" size="100%">Dynamic Identity</style></keyword><keyword><style  face="normal" font="default" size="100%">Password Authentication</style></keyword><keyword><style  face="normal" font="default" size="100%">Phishing</style></keyword></keywords><dates><year><style  face="normal" font="default" size="100%">2011</style></year><pub-dates><date><style  face="normal" font="default" size="100%">2011</style></date></pub-dates></dates><volume><style face="normal" font="default" size="100%">26</style></volume><pages><style face="normal" font="default" size="100%">12-26</style></pages><language><style face="normal" font="default" size="100%">eng</style></language><abstract><style face="normal" font="default" size="100%">&lt;p&gt;Password based authentication is used in online web applications due to its simplicity and convenience. Main advantage of passwords is that users can memorize them easily without needing any hardware to store them. Efficient password based authentication schemes are required to authenticate legitimacy of remote users or data origin authentication over an insecure communication channel. Password based authentication schemes are highly susceptible to phishing attacks. The phishing attacks are becoming more and more sophisticated and therefore require strong countermeasures. It is important to detect the phishing sites early because most of them are short-lived and cause the damage in the short time span between going online and vanishing. Phishing is doing direct damage to the financial industry and is also affecting the expansion of e-commerce. In this paper, we present the survey of different anti-phishing techniques based on several crucial criteria. This study will help in developing different password based anti-phishing authentication techniques for web applications. Financial transactions in web applications require highly secure authentication protocols. Phishing is the biggest problem financial organizations are facing to provide online transaction services. Most threatening phishing attacks require countermeasures to make online transactions reliable and secure.&lt;/p&gt;</style></abstract><issue><style face="normal" font="default" size="100%">1</style></issue><section><style face="normal" font="default" size="100%">12</style></section></record><record><source-app name="Biblio" version="7.x">Drupal-Biblio</source-app><ref-type>17</ref-type><contributors><authors><author><style face="normal" font="default" size="100%">Ya-Fen Chang</style></author><author><style face="normal" font="default" size="100%">Chin-Chen Chang</style></author></authors></contributors><titles><title><style face="normal" font="default" size="100%">An Efficient and Practical Remote User Authentication Scheme</style></title><secondary-title><style face="normal" font="default" size="100%">Information &amp; Security: An International Journal</style></secondary-title></titles><keywords><keyword><style  face="normal" font="default" size="100%">Password Authentication</style></keyword><keyword><style  face="normal" font="default" size="100%">Password Guessing Attacks.</style></keyword></keywords><dates><year><style  face="normal" font="default" size="100%">2004</style></year><pub-dates><date><style  face="normal" font="default" size="100%">2004</style></date></pub-dates></dates><volume><style face="normal" font="default" size="100%">15</style></volume><pages><style face="normal" font="default" size="100%">75-88</style></pages><language><style face="normal" font="default" size="100%">eng</style></language><abstract><style face="normal" font="default" size="100%">In 2000, Peyravian and Zunic proposed a simple and efficient password authentication scheme based on the collision-resistant hash function. Later, Hwang and Yeh indicated that Peyravian and Zunic’s scheme is insecure and proposed an improvement by using the server’s public key. Nevertheless, in practice, services that do not use public keys are quite often superior to PKIs. At the same time, Lee, Li and Hwang indicated that Peyravian and Zunic’s scheme suffers from off-line password guessing attacks and presented an improved version. However, Lee-Li-Hwang’s proposed scheme is still vulnerable to the same attacks and denial-of-service attacks. Therefore, this article presents a secure and efficient improvement.</style></abstract><issue><style face="normal" font="default" size="100%">1</style></issue></record></records></xml>