In a world ripe with social networking sites such as Myspace, Facebook, LinkedIn, or any of the other 550,000 different sites allowing you to connect with people you are already friends with, there is bound to be a shady element. That underworld of exploitation, manipulation, and incredible social aptitude. Wait what?
Welcome to the world of the over-friendly and ‘single-minded' Trojan. Single-minded, as it seems to be inviting people to the site and start networking. A Trojan is a programme that appears to be desirable (like a free downloadable game or screen saver), but contains viruses or worms (self-replicating viruses) that can create havoc with the PC and the network.
However, in the case of these social networking sites, the Trojans that plant themselves on the users' computers and send invites to all mail IDs saved in the contact list, are harmless. The Trojan embeds itself in the user's computer when he/she logs on to a social networking site and sends invites to all listed in the contact list.
The receiver – believing it to be from a genuine friend – accepts the invitations and becomes a member of the social networking site. The sites use this to increase their membership, while hackers use the technique for their phishing attempts.
They do not crash the PC nor the network, an IT specialist with a leading BPO notes. But they sure can mar friendships, relationships or even lead to unwanted and unsolicited networking.
Internet Service Providers Association of India (ISPAI) president Rajesh Chharia says, "Even though these programmes only send spam and are quite harmless, at times it can lead to embarrassing situations".
"As most of these social networking sites are used for business networking and friendship, it is not possible for Internet Service Providers (ISPs) to block these sites. The best option is to put in good firewalls at the user's level," he said.
So the next time you log on to a social networking site, an invitation to join the site has gone to your super boss on your behalf. But without your knowledge!
My New Blog
June 8, 2008
The Social Butterfly
June 7, 2008
MICROSOFT SCAMS AGAIN!
Businesses that skip Windows Vista and upgrade their computers directly from the XP operating system to Windows 7 could expose themselves to security risks and other problems, Microsoft says in a new white paper.
Bypassing Vista could have "implications for security, support, and regulatory compliance and reduce flexibility in the face of changing business requirements," writes Microsoft VP Mike Nash, in the paper.Specifically, Nash says that businesses that wait for Windows 7 -- set for release in late 2009 or early 2010 -- to upgrade from XP could find themselves using outdated applications that don't employ proper security safeguards or are no longer supported.
They also won't get the advantage of new security technologies and other improvements that Microsoft embedded in Vista, Nash says. "By not deploying Windows Vista, it means missing out on the proven benefits such as better security, productivity, search, mobility, manageability and infrastructure optimization," Nash says in the paper, which is titled "The Business Value Of Windows Vista."
Do you remember any similar pushes with previous operating systems? This could possibly be because of the absolute travesty that is Vista security, that has kept so many large businesses from switching to the operating system. After such an outcry from the IT community and backlash against their prettiest operating system, Microsoft has decided to switch their tactics from marketing to George Bush-esque "strategertizing". Overheard in a consultation, "OH so you don't want to upgrade to Vista? If you don't You will never be able to Upgrade again!!!" Basically they are trying to tell you that if you don't upgrade to Vista, You can't upgrade to 7. And you can bet that the software of 7 wont allow a install from XP. And will most likely have a discount upgrade to Vista. 49.99 so that you can upgrade to vista so that you can upgrade to 7 (It's a steal!!!)
Posted by
Gillis57
at
1:56 PM
0
comments
Labels: Admin, Bill Gates, Expensive, Force, Gillis Jones, Hewlett Packard, IT, microsoft, Security, Social Engineer, Vista, Windows, Windows 7
British Beauty Queen Hijacked!
Am I being a little sensationalistic? I may be, however no one ever said that Beauty Queens were the brightest of the bunch. Cases like this are why I suggest that people be required to have a driver's license for the Internet.
Miss Scarborough has become the latest victim of online phishing fraudsters, with the the beauty contest winner having had £10,000 stolen from her bank account.
Jade Saunders, a 20-year-old student, was crowned Miss Scarborough in April this year, and is also a semi-finalist for Miss England 2008.
Saunders reportedly clicked on a link in an e-mail purporting to be from her bank, which took her to a genuine-looking, but fake, website. By entering her security log-in details on the fake site, Saunders provided the cybercriminals with all they needed to set up a standing order on her account for £10,000.
Alright, Here are a few checkpoints upon receiving an email from a seemingly legitimate source
[] IS IT FROM A LEGITIMATE SOURCE? LEGIT COMPANIES DO NOT USE FREE EMAIL ACCOUNTS
(Free Emails such as Yahoo, Hotmail, Gmail)
[] IS THE EMAIL GRAMMATICALLY INCORRECT
(Legit Companies typically don't spell words improperly)
[] IS THE EMAIL UNFORMATTED? (i.e No breaks, Paragraphs, Letterhead, Etc.)
(Companies will usually use some sort of professional formatting)
[] IS EMAIL STATING THAT YOU MUST ENTER PERSONAL INFORMATION?
(Companies do not ask for Passwords, SS #'s, or Bank Info)
[] DOES THE EMAIL STATE THAT CHARGES ARE BEING MADE TO YOUR ACCOUNT?
(If so, contact the companies customer support phone number immediately)
[] IS THERE A LINK? If you have checkmarks above, DO NOT CLICK!
(If so, hover your mouse over the link and a box will come up and say where it goes. If it Is not the company's website- Do Not Click!)
IF the email makes you feel uneasy at all, in general, don't click anything at all.
When you enter information on a phisher's website, he has all the information to take out a line of credit, transfer funds, or do any number of other unscrupulous things. Companies will not ask you to enter information in order to verify anything, and if you do recieve such an email- be sure to immediately contact the company in question on the phone support line.
BE SAFE ONLINE! IF NOT, YOU MAY SUFFER BIG LOSS IN THE REAL WORLD.
May 19, 2008
Dear God
Recently, I was browsing government websites to see if there were any new articles to read. However when I came to www.NSA.gov (National Security Agency), their website was offline. Baffled by this National Security Issue, seeing as how the NSA is supposed to be the pinnacle of Intelligence and Technology, I decided to do some digging.
So who was the "Super hacker" that executed such a technologically advanced, planning intensive attack upon the US government? Well, as it turns out the super hacker was a incompetent mole. No, not a double agent. Someone who was hired, because there was extra room in the Budget. DNS misconfiguration in my NSA? Its more likely than you think.
First, a web server was running on the same computer or the same IP address as one of the so-called authoritative name servers for nsa.gov. The authoritative name servers are the primary and secondary servers that translate the web addresses humans understand (i.e., NSA.gov) to machine-readable IP addresses (in the NSA.gov case, 189.182.93.126).
Moreover, the primary and secondary authoritative name servers were both downstream from the Qwest edge access router in Washington, D.C. They should have been separated topologically within the network infrastructure, according to McPherson.
Come On Guys, thats basic network design. If the Top Security Agency can't design a network properly- what does that say about our national network infrastructure.
Posted by
Gillis57
at
4:31 PM
0
comments
Labels: .Gov, DNS, Hub, NSA, Qwest, Router, Security, Social Engineer, Sql, Switch, topography, Tor, Washington
May 15, 2008
Hi, Im Here to fix your computer.
How Many of us work in a hectic, stressed environment- where deadlines and bottom-lines rule your workweek? In the course of a day, How many idiotic requests do you get to do seemly mundane chores? How Often has this happened?
You: {Bored and Seeking an excuse to take a break}
Phone Repairman: "Hi, Coorporate sent me over to do some work on your Phoneline"
You: "Oh, Alright- About How Long Will it take?"
PR: "Ten Minutes, Twenty Tops- I have some other stuff to do- so if your busy I can come back during lunch"
You: "Alright, Thanks!"
What happened here? You just gave a rival company full access to your office!
You: But he can't do anything! He doesn't Have My Password!
Me: *Hits You in the Head*
Lets go through this- He could (in Ten Minutes)
A. Steal A Hard Drive
B. Install a Hardware Keylogger
In twenty Minutes
A. Do a Stealth Boot Onto Your Computer
B. Install Software Keylogger and Screen Capture Device
C. Comb through trade secret documents, and walk out with them unquestioned.
D. Confiscate Hidden Bank documents, Client Credit cards, Even Blackmail.
Would You Give A Thief A Key? Would You Give a Murderer A Knife?
Would You Give A Meth Addict A Pipe?
You wouldn't do it with a Hacker either, 10% of Hacking is Intelligence: 89% is Persistence: And 1% Is Technological Prowess.
Hackers won't be the typical grungy teen whilst looking for information:
When in doubt, the best way to obtain information in a social engineering attack is just to be friendly. The idea here is that the average user wants to believe the colleague on the phone and wants to help, so the hacker really only needs to be basically believable. Beyond that, most employees respond in kind, especially to women. Slight flattery or flirtation might even help soften up the target employee to co-operate further, but the smart hacker knows when to stop pulling out information, just before the employee suspects anything odd. A smile, if in person, or a simple “thank you” clenches the deal. And if that’s not enough, the new user routine often works too: “I’m confused, (batting eyelashes) can you help me?”
Need More Info/ Training?
Let Me Secure Your Network!
Gillis57@gmail.com
Or, If for some god-awful reason you actually want to know what I'm doing
twitter.com/Gillis57
gillis57.googlepages.com