Showing posts with label Spam. Show all posts
Showing posts with label Spam. Show all posts

July 5, 2008

LinkedIn Scamming Customers?

Anyone who is active in the professional world loves LinkedIn. (In my opinion) it is an absolutely flawless way to network, get your name out there, and build up on online resume that is able to be referenced on websites,blogs, or emails. It allows companies seeking employees an easy venue to find qualified personnel, helps skilled labor to find a company looking for someone just like them, and rekindles old flames left to die. Okay, so maybe isn't the hotbed of romantic activity on the internet, but its great for business. Especially LinkedIn's bottom line.


"How can LinkedIn benefit from networking?"


When you sign up for LinkedIn, you are asked to complete a resume of sorts. This initial information includes your name, date of birth, field of business,location and interests. Then you of course have the option of adding where you have worked, gone to school, and clubs/associations you are a part of. After all these personally identifiable things, you are then given the option of Joining Linkedin "Groups". These are generally trade groups or groups that allow a person to further network their profile. In short, LinkedIn has developed a complete advertiser's dream scenario. A company can buy your profile information from LinkedIn, and are provided with all of your information, along with means of contact for you. In general, LinkedIn has a full demographical breakdown of you and anyone you "Invite" to LinkedIn. And whereas the majority of LinkedIn users are over 40 and have incomes of over $100,000 dollars- they are the ideal targets of marketers, both legitimate and not. Recently LinkedIn decided to advertise merchandise to its users, but in a selective manner. For example, if Mercedes decided to advertise its new model, it would go to LinkedIn and they would choose from the member database the ones that fitted the marketing campaign. Then, LinkedIn decided to make a little more money by offering Premium Business and Premium Business Plus. With a regular membership you couldn't just send someone an e-mail, you had to be introduced first; with the new types of membership, this was no longer an issue. HR companies saw a great opportunity in this and for good reason. All they had to do was pay and they had access to all sorts of potential job candidates.

Their new Enterprise Corporate Solution gives access to all 23 million users of LinkedIn.

July 1, 2008

Mcafee's Spam Project.

Have you ever pondered to yourself, "What would happen if I left my computer without anti-virus, routine maintenance, or any care to be taken of it?" Do you imagine a zombie computer, revving its engine repeatedly in disgust of your lack of decent ownership?Well,Mcafee has released the results of its Spammed Persistently All Month campaign- So you do not have to wonder anymore.

The project asked a group of 70 users from 10 countries to surf the web unprotected and gather as much spam as possible.

The guinea pigs were able to amass a total of 104,000 spam messages, an average of 2,096 messages per person and 70 messages per day for each user.

Americans topped the spam haul, amassing 23,233 spam messages between five users. Brazil finished a distant second with 15,856 messages, and the UK was fifth with 11,965.

Participants in the study also noticed significant system slowdowns from unwanted software installations.

"In just 30 days there was quite a noticeable change in the performance of their computers," said McAfee Avert Labs senior vice president Jeff Green.

"This showed just how much malware was being installed without their knowledge, and that spam is much more than a nuisance. It is a very real threat. "

The US also led the study in the number of adult-oriented spam messages, while the UK received the highest number of Nigerian '419' messages. Brits received more than 23 per cent of the infamous money transfer scam attempts.

Financial services messages were the most popular spam topics, followed by advertisements and health and medicine messages. Adult emails were the fourth most-popular, while offers for free items were fifth and 419 scams tenth.

McAfee also noted an increasing number of location- and language-specific spam, particularly in France and Germany. The large spam loads in Brazil and Mexico also suggest a new focus on emerging economies.

"Our participants came from all walks of life, from all over the world and, given their interest to take part in the experiment, they were well aware of the problem," said McAfee chief executive Dave DeWalt.

"Despite this, they were all shocked by the sheer amount of spam they attracted in such a short time and the lengths the spammers would go to in order to achieve success."AA

June 25, 2008

Marshall Islands Attacked

The Marshall Islands, an island chain housing 55,000+ people came under attack today.
The attack didn't involve bombs, missiles, guns, or any invading forces. This attack was brought about by a small group of "Hackers", who executed a distributed denial of service attack on the National Telecommunications Authority. This attack did not destroy, or damage any property/infrastructure, rather, temporarily cut off communications with the outside world. Marshall Island residents were still able to communicate inside the NTA network. The attack was a generically low-tech one, consisting of a mass spamming of the mail servers. The incoming spam filled up all the routes for mail exiting, thus rendering the servers useless. These spam mails were sent via a series of zombie computers from around the world. Presumably an individual (Re: One Person) had complete control of all the zombies from a private IRC channel, and is still executing the attack from there.

As of Late, "Botnets" have become an increasingly lucrative business for hackers. While relatively easy to setup, Renting a Botnet out could net one upwards of 10,000 US dollars.

As of Wednesday, June 25, external communications with the nation have still not been restored.

Would it be wrong for me to point out that the Marshall Islands were also where we tested the Nuclear Bomb? Recently it came out that the US was working on developing a "Carpet Bombing" technique for shutting down a nations IT infrastructure. What motivation would any individual or group have at shutdown a national infrastructure?
I Believe this may be the first in an unfortunate series of internet militarization tests.

June 8, 2008

The Social Butterfly

In a world ripe with social networking sites such as Myspace, Facebook, LinkedIn, or any of the other 550,000 different sites allowing you to connect with people you are already friends with, there is bound to be a shady element. That underworld of exploitation, manipulation, and incredible social aptitude. Wait what?

Welcome to the world of the over-friendly and ‘single-minded' Trojan. Single-minded, as it seems to be inviting people to the site and start networking. A Trojan is a programme that appears to be desirable (like a free downloadable game or screen saver), but contains viruses or worms (self-replicating viruses) that can create havoc with the PC and the network.

However, in the case of these social networking sites, the Trojans that plant themselves on the users' computers and send invites to all mail IDs saved in the contact list, are harmless. The Trojan embeds itself in the user's computer when he/she logs on to a social networking site and sends invites to all listed in the contact list.

The receiver – believing it to be from a genuine friend – accepts the invitations and becomes a member of the social networking site. The sites use this to increase their membership, while hackers use the technique for their phishing attempts.

They do not crash the PC nor the network, an IT specialist with a leading BPO notes. But they sure can mar friendships, relationships or even lead to unwanted and unsolicited networking.

Internet Service Providers Association of India (ISPAI) president Rajesh Chharia says, "Even though these programmes only send spam and are quite harmless, at times it can lead to embarrassing situations".

"As most of these social networking sites are used for business networking and friendship, it is not possible for Internet Service Providers (ISPs) to block these sites. The best option is to put in good firewalls at the user's level," he said.
So the next time you log on to a social networking site, an invitation to join the site has gone to your super boss on your behalf. But without your knowledge!

June 2, 2008

Microsoft wants your Opinion?

In the continuing effort to improve computer and network security, Microsoft has developed the End to End Trust initiative. As a part of that initiative, Microsoft is seeking input from users and information security professionals to help answer the questions that need to be addressed in order to evolve computer security such as How should we enhance security on the Internet without undermining social values, such as privacy and anonymity? There are more questions to be answered in the End to End Trust Forums. Scott Charney, Microsoft's Corporate Vice President of Trustworthy Computing, has developed a white paper entitled Establishing End to End Trust which provides more details on Microsoft's vision.

While  it is not beyond the stretch of a reasonable person's imagination that a giant of the industry would want to keep it's users secure. The employees and designers of microsoft have showed a lack of willingness to address serious security issues, and wrap every tiny piece of security as the next big step in computing. Rather than the required software that all of this should have been back in Windows 98. It seems that every time Microsoft attempts security, it undoubtedly blows up in it's face. So I would encourage you to voice your opinion to microsoft- Let them know you value your security, as well as your wallet.

May 24, 2008

Wordpress SQL injection

Today it came out that there is yet another SQL injection in WordPress Blogs.


This code exploits the Wordpress Plugin Upload File, and allows an attacker to execute an arbitrary command on the hosting machine. If you host your Blog Locally, this is an enormous problem! The exploit (Discovered by a russian hacker http://eserg.ru ) ,  is one of a myriad of security issues recently exposed by Hackers- leaving bloggers worldwide vulnerable.  

What is a Arbitrary Command?
   This is when an attacker is able to exploit a security vulnerability in a program, to execute commands on YOUR computer. For example, in this case, By simply executing this SQL query
null/**/union/**/all/**/select/**/concat(user_login,0x3a,user_pass)/**/from/**/wp_users/*
On your server- he is able to add/remove users, Delete Files, and install any number of viruses.

Be on the lookout in the next week for a patch from www.wordpress.com/www.wordpress.org

May 18, 2008

Microsoft Vista Security... Yeah Right!

Lately, Microsoft has been trumping the myriad of new security measures that have been included in Windows Vista. However, IT techs have been screaming their guts out that between the lack of any substantial changes (aside from a circular start bar), the forced User Account Control, and big brother like computing- That everyone should stay with XP. Well, now we have actual basis for this. Notice how that Microsoft is quick to shift ALL the blame to the incompetent user.  

                The claim that Vista is less secure than Windows 2000 was made last week by security vendor PC Tools, which said that over the past six months Vista had suffered 639 unique threats, whereas Windows 2000 has suffered 586. PC Tools's research was conducted by collecting data from customers using its ThreatFire behavioural detection software. "Ironically, the new operating system has been hailed by Microsoft as the most secure version of Windows to date," said Simon Clausen, the chief executive of PC Tools last week. "However, recent research conducted with statistics from over 1.4 million computers within the ThreatFire community has shown that Windows Vista is more susceptible to malware than the eight-year-old Windows 2000 operating system, and only 37 percent more secure than Windows XP," Clausen said.

        However, Microsoft strongly hit back at the claims, blaming users for executing malicious code on their machines. On Tuesday, Technet blogger and Microsoft evangelist Michael Kleef said the number of infections found by PC Tools was an indication of poor user behaviour


639 unique threats? This coming from the billion dollar brain-trust that spent four years to develop a circular start bar? I am truly, truly stunned.

May 15, 2008

Hi, Im Here to fix your computer.

How Many of us work in a hectic, stressed environment- where deadlines and bottom-lines rule your workweek? In the course of a day, How many idiotic requests do you get to do seemly mundane chores?  How Often has this happened?

You: {Bored and Seeking an excuse to take a break}
Phone Repairman: "Hi, Coorporate sent me over to do some work on your Phoneline"
You: "Oh, Alright- About How Long Will it take?"
PR: "Ten Minutes, Twenty Tops- I have some other stuff to do- so if your busy I can come back during lunch"
You: "Alright, Thanks!"

What happened here? You just gave a rival company full access to your office!
You: But he can't do anything! He doesn't Have My Password!
Me: *Hits You in the Head*

Lets go through this- He could (in Ten Minutes)
A. Steal A Hard Drive
B. Install a Hardware Keylogger

In twenty Minutes
A. Do a Stealth Boot Onto Your Computer
B. Install Software Keylogger and Screen Capture Device
C. Comb through trade secret documents, and walk out with them unquestioned.
D. Confiscate Hidden Bank documents, Client Credit cards, Even Blackmail.

Would You Give A Thief A Key? Would You Give a Murderer A Knife?
            Would You Give A Meth Addict A Pipe?

You wouldn't do it with a Hacker either, 10% of Hacking is Intelligence: 89% is Persistence: And 1% Is Technological Prowess.

Hackers won't be the typical grungy teen whilst looking for information:

When in doubt, the best way to obtain information in a social engineering attack is just to be friendly. The idea here is that the average user wants to believe the colleague on the phone and wants to help, so the hacker really only needs to be basically believable. Beyond that, most employees respond in kind, especially to women. Slight flattery or flirtation might even help soften up the target employee to co-operate further, but the smart hacker knows when to stop pulling out information, just before the employee suspects anything odd. A smile, if in person, or a simple “thank you” clenches the deal. And if that’s not enough, the new user routine often works too: “I’m confused, (batting eyelashes) can you help me?”



Need More Info/ Training?
Let Me Secure Your Network!
Gillis57@gmail.com

Or, If for some god-awful reason you actually want to know what I'm doing
twitter.com/Gillis57
gillis57.googlepages.com