Showing posts with label scam. Show all posts
Showing posts with label scam. Show all posts

Tuesday, 24 April 2012

Zero Day: an upcoming documentary on cyber crime

Journalist Brian Krebs and few other reporters are to be featured in an upcoming documentary co-financed by BBC Storyville where viewer will be able to witness hands-on forensics that uncover the perpetrators and follow film makers as they film cases and investigations in real time. However, this project will only be funded if at least $20 000 is pledged by Saturday, June 2, 2012. For more information and to support the project please click here.

Saturday, 31 March 2012

How Windows pc and Mac systems get infected

Why Windows malware is not posing a threat to Linux system

In this post I will make an attempt to create a synopsis of usual ways malware makes its way into Windows or Mac system. I am referring specifically to Win/Mac because the vast majority of viruses and other malware is created for these two aforementioned Operating Systems, MS Windows being particular favourite of malware writers due to its large share of OS market (that is, if we are not talking mobile phones at this point).
Malware that has been created for Windows pc, is designed for Registry based OS, and neither Linux or Unix is one, therefore, cannot become affected by it (that is one of the few reasons why I absolutely love Linux). Even though malware can affect only OS it has been designed for, there are couple of things often shared by all three most popular computer Operating Systems (as well as those found in majority of mobile smartphones): Adobe Flash and Sun Java. (In case of Linux the use of Adobe product is less common though.) Even though HTML5+DOM coding in website development is expected to eventually make the use of Flash obsolete, currently that is not the case.

Top weaknesses that can cause infection

1. Unpatched security holes.

Operating system, software and its components are always a subject to exploitation because nothing is ever 100% perfect. If latest updates are not installed, the coding and design vulnerabilities in software applications and operating system are posing a risk of being abused by malware writers. Internet browsers, Adobe products, Sun Java, Windows Media Player, Apple Quicktime all have to be updated on regular basis.
Adobe products. Adobe Reader is usually installed with Speed launcher. This feature is loaded during Windows start-up thus prolonging the OS loading and storing the associated .exe file in Applications' folder where it may simply be another useless file which may be exploited during malware attack on the system. By reading this short article you can decide whether you really need this feature. More on Adobe Acrobat Reader related security issues here.
Adobe Flash is another subject to exploitation if not kept updated. Hackers are known to exploit Flash vulnerabilities which can lead to malware infection. When visiting a website that hosts a HTML page which requires a Flash script, users may encounter a malicious Flash redirector, or malicious script written to exploit vulnerability in the Flash Interpreter which causes it to execute automatically in order to infect the computer. Flash vulnerabilities are directly related to Web application and casual online gaming security. More extensive overview on this subject can be found here.
Java, if not kept updated, is the most common way of infecting computer with trojans while browser is rendering a HTML code at some dodgy adult or software cracking tools' website. It must be noted that most exploited vulnerability on such an occasion is previous Java version that has not been uninstalled after the new, updated one has been downloaded and installed. You can check whether you have two Java versions in your Windows pc by going to Control Panel and opening Add/Remove Programs. If you do have two Java updates listed, it is recommended that you uninstall the older one. You can check your system's Java status here.

2. Javascript enabled for all sites.

Regardless of the Web browser you are using, a Javascript can make your system less secure if enabled to run on all sites. The safe way of using Javascript is to enable it exclusively for trusted sites. Javascript is often the cause of malicious redirects to a site with either a malicious content or an intent to boost the incoming traffic.

3. Online game servers.

Because of the design of the online game architecture, firewalls and anti-malware software sometimes can't detect intrusions. That provides an opportunity for hackers to abuse the victim's machine by using online bots and rootkit-like techniques. More info on data and computer security threats related to online gaming can be found here.

4. Torrent, P2P (Peer-to-Peer) networks, File Sharing programs.

Connection to these networks is making the system susceptible to remote attacks and probability of downloading infected, malicious files. That in turn can lead to identity thefts. Malicious worms, backdoor Trojans, IRCBots and rootkits spread across P2P file sharing networks, gaming, dodgy adult and underground sites.

5. Infected files on USB and other storage media.

An Autorun.inf file can cause much trouble. More about this threat and how to avoid it you can read here.

6. Clicking unsolicited links in e-mail and Instant Messenger chats.

For more info as to why such links are being sent and what consequences such actions can have please see my previous posts here and here.

7. Rogue antivirus / antimalware software.

This includes clicking on pop-ups or banners that claim your computer is infected. All about rogues you can read in one of my previous posts here.

8. Backing up infected files.

A logical cause of re-infection.

9. Assuming that antivirus and/or firewall are not needed, or that they are providing 100% protection.

Two extreme assumptions that both can result in computer not being protected against cyber threats. On the first occasion, it is most likely that such a computer's owner won't even get that far as to visit this website to read this article, therefore, I am going to address the second assumption by saying that even protected machines get infected. Otherwise malware writers wouldn't waste their time on doing what they do. Here is an excerpt from Ivizsecurity.com blog:
Security products like anti-virus, firewalls, IDS/IPS and VPN have become of paramount importance to provide highest degree of confidentiality, availability and Integrity (CIA) to individuals and organizations. However, it is foolish to assume that security products are free from any vulnerability (security flaws). Security Products can also be of target of attacks from the attackers.
  By assuming that Anti-virus and Firewall will do the trick of fully protecting the machine, we risk to return to the beginning of this list, e.g. unpatched security holes.

Download and test these products for free for 30 days:
Internet Security Pack: AntiVirus+Firewall
Online Armor Premium Firewall

Monday, 13 February 2012

What is an online scam?

Before we proceed to recognizing the common phishing and scam patterns, let me tell you

Where to report phishing emails and websites?

Go to antiphishing.org website by clicking here, and follow instructions.

How to spot scam and phishing attempts?


In the picture above is a very simple example of what to look out for when you receive an email from a hot blonde with naughty videos online:
1. Spelling. I mean, waht series individuall or organizattion or website would send an email like that?
2. Do you know who is Micah Rafe and a website named cucougars.com?
3. What kind of a link is that anyway?

Speaking of links. Before clicking on any of them, at least hover your mouse cursor over each of them as to see where the link is supposed to take you. The address can usually be seen at the bottom left of the browser screen (and even then it might redirect the browser to another destination). The linked text can say Click Here, or it can look similar to one in the picture above, but in reality, can take you to a malicious website that is set up with an intent to collect personal or financial data (pharming), or to infect your machine with malware.
Even if the link looks legitimate at first sight (starting with www.paypal.com, for example), double-check that you read the link right (in other words, it's not www.paypalcom.com). Here's an excerpt from an article at scamdex.com website regarding links and DNS system:
  • Just because the domain name of a website mentions kitties and fluffy bunnies, it doesn't mean that it's not a porn site.
  • A mis-spelled bank domain name is probably a spoof website, trying to get you to enter your bank access details for a scammer.
  • The DNS system makes no decisions of any kind about the content of or suitability of or legality of websites - it is just a tool.
  • When your kids use google or any other search engine to search for stuff, the results returned may expose them to violent and/or sexual images which would horrify you.
Very simple and useful tips regarding to spotting the scam and phishing messages are provided in the following video (authors come up with an interesting fact that mobile users are receiving 3 times more scam messages than those using computers):


While we are at the subject of scamming, ladies, check out the Valentine's Day article on online dating scams by Ann Brenoff at Huffingtonpost.com website.
An extensive list and information on known scam patterns can be found at Consumer Fraud Reporting website.

Phishing and Identity theft

The essence of an Identity theft attempt looks like following:

Dear Sir,
I have 2 million dollars. I will give you 1,525 million dollars because I trust you. Please provide
Your Name:
Your Data of birth:
Your address:

In reality you would probably get more elaborate email message like this:
For your confidence,
Please consider to help me relocate this $2.5mUSD for establishing an industry in your country.
This fund was deposited in our bank by Mrs. Nina Wang from Hong Kong who died of cancer on April 3rd 2007 without a heir.
A routine notification was sent to her forwarding E-mail address but without responses.
She did not declare her next of kin in the bank
official papers including her real home contacts.
This money has been floating and if I do not remit it out urgently it will be confiscated by the government as unclaimed fund.
You will be compensated with 40% for your collaboration to receive this fund.
Click here
[link withdrawn]
I will give you all vital information and clarification so that you will contact my bank for the release of the money into your account as next of kin to the deceased depositor.
As one of the bank directors, I will play a role to make sure that the fund will be released to you.
Mr.Abdul .F. Umar
As you can tell straight away, should you decide to reply to the sender of the message, eventually you would be asked for your personal and financial details because, how would you otherwise be able to "help to relocate" the sender's "funds"..? My advice: don't reply to the message, blacklist the email address the message was sent from, and delete it.


In order to be aware of the seriousness of keeping your personal data safe, a list of methods (from Wikipedia) of obtaining data on other people will (hopefully) give you the idea of how much effort some people are ready to invest in obtaining data on other people:
  • Rummaging through rubbish for personal information (dumpster diving)
  • Retrieving personal data from redundant IT equipment and storage media including PCs, servers, PDAs, mobile phones, USB memory sticks and hard drives that have been disposed of carelessly at public dump sites, given away or sold on without having been properly sanitized
  • Using public records about individual citizens, published in official registers such as electoral rolls
  • Stealing bank or credit cards, identification cards, passports, authentication tokens ... typically by pickpocketing, housebreaking or mail theft
  • Skimming information from bank or credit cards using compromised or hand-held card readers, and creating clone cards
  • Using 'contactless' credit card readers to acquire data wirelessly from RFID-enabled passports
  • Observing users typing their login credentials, credit/calling card numbers etc. into IT equipment located in public places (shoulder surfing)
  • Stealing personal information from computers using malware, particularly Trojan horse keystroke logging programs or other forms of spyware
  • Hacking computer networks, systems and databases to obtain personal data, often in large quantities
  • Exploiting breaches that result in the publication or more limited disclosure of personal information such as names, addresses, Social Security number or credit card numbers
  • Advertising bogus job offers in order to accumulate resumes and applications typically disclosing applicants' names, home and email addresses, telephone numbers and sometimes their banking details
  • Exploiting insider access and abusing the rights of privileged IT users to access personal data on their employers' systems
  • Infiltrating organizations that store and process large amounts or particularly valuable personal information
  • Impersonating trusted organizations in emails, SMS text messages, phone calls or other forms of communication in order to dupe victims into disclosing their personal information or login credentials, typically on a fake corporate website or data collection form (phishing)
  • Brute-force attacking weak passwords and using inspired guesswork to compromise weak password reset questions
  • Obtaining castings of fingers for falsifying fingerprint identification.
  • Browsing social networking websites for personal details published by users, often using this information to appear more credible in subsequent social engineering activities
  • Diverting victims' email or post in order to obtain personal information and credentials such as credit cards, billing and bank/credit card statements, or to delay the discovery of new accounts and credit agreements opened by the identity thieves in the victims' names
  • Using false pretenses to trick individuals, customer service representatives and help desk workers into disclosing personal information and login details or changing user passwords/access rights (pretexting)
  • Stealing cheques (checks) to acquire banking information, including account numbers and bank routing numbers
  • Guessing Social Security numbers by using information found on Internet social networks such as Facebook and MySpace
  • Low security/privacy protection on photos that are easily clickable and downloaded on social networking sites.
  • Befriending strangers on social networks and taking advantage of their trust until private information are given. 
If you think that someone would write you an email wanting to pay you million dollars from the bank in Hong Kong or Africa, or that they are eagerly willing to pay you a jackpot that you have supposedly won in a lottery you have never taken a part in, better delete the email message and watch how some people have managed to scam the scammers (note: don't try this at home, might get you in trouble):

Download and test these products for free for 30 days:
Internet Security Pack: AntiVirus+Firewall
Online Armor Premium Firewall