Showing posts with label backdoor. Show all posts
Showing posts with label backdoor. Show all posts

July 5, 2008

LinkedIn Scamming Customers?

Anyone who is active in the professional world loves LinkedIn. (In my opinion) it is an absolutely flawless way to network, get your name out there, and build up on online resume that is able to be referenced on websites,blogs, or emails. It allows companies seeking employees an easy venue to find qualified personnel, helps skilled labor to find a company looking for someone just like them, and rekindles old flames left to die. Okay, so maybe isn't the hotbed of romantic activity on the internet, but its great for business. Especially LinkedIn's bottom line.


"How can LinkedIn benefit from networking?"


When you sign up for LinkedIn, you are asked to complete a resume of sorts. This initial information includes your name, date of birth, field of business,location and interests. Then you of course have the option of adding where you have worked, gone to school, and clubs/associations you are a part of. After all these personally identifiable things, you are then given the option of Joining Linkedin "Groups". These are generally trade groups or groups that allow a person to further network their profile. In short, LinkedIn has developed a complete advertiser's dream scenario. A company can buy your profile information from LinkedIn, and are provided with all of your information, along with means of contact for you. In general, LinkedIn has a full demographical breakdown of you and anyone you "Invite" to LinkedIn. And whereas the majority of LinkedIn users are over 40 and have incomes of over $100,000 dollars- they are the ideal targets of marketers, both legitimate and not. Recently LinkedIn decided to advertise merchandise to its users, but in a selective manner. For example, if Mercedes decided to advertise its new model, it would go to LinkedIn and they would choose from the member database the ones that fitted the marketing campaign. Then, LinkedIn decided to make a little more money by offering Premium Business and Premium Business Plus. With a regular membership you couldn't just send someone an e-mail, you had to be introduced first; with the new types of membership, this was no longer an issue. HR companies saw a great opportunity in this and for good reason. All they had to do was pay and they had access to all sorts of potential job candidates.

Their new Enterprise Corporate Solution gives access to all 23 million users of LinkedIn.

July 1, 2008

British Health Records Stolen

This is really beginning to get to me. With the proliferation of laptops in our society, you would think that knowledge of security would begin to rapidly spread as well. However, this is the second story in less than a week of a laptop being stolen from a car. Now, if this was an office of some sort, with semi-inconsequential data it would be understandable. But it seems that more and more, Healthcare IT staff are carrying around patient data on their personal laptops. These are people who are carrying around credit card info, banking numbers, social security numbers, Names, dates of birth. And i still wouldn't have a problem with it if they would take some sort of rudimentary precautions to ensure the protection of the data. However, there have been cases of IT staff storing full system backup tapes, laptops, USB Crypto keys, and entire servers in the back of their cars. They are then completely amazed when these top-level security measures are thwarted by a crook with a crowbar. This latest incident occured after a British IT worker for the NHS trust left his laptop unsecured in his car, along with 21,000 patients details. To make things worse, none of the information was encrypted. So the thief now has complete access to any and all patient data. The NHS trust reinforced the now common perception that they were completely technologically incompetent by stating (trying to make the situation better) "the data will almost certainly by wiped by the thief"

What steps should you take in order to secure a system from theft?
A. Set a Bios Level Password
B. Set at least a 14 digit password.
C. Require some sort of Biometric Authorization for Access
D. Always keep your data in an encrypted folder
E. If practical, Hide private data inside of another file
F. Keep any backups in humidity controlled, insulated environment.
G. Rule of Thumb: If your system can be seen, its public data.
H. Thumb of Rule: If your system is in your car, it deserves to be stolen.

June 20, 2008

ALERT: MAC OS-X New Exploits

Did you really think your precious Mac was immune? That you were exempt from the Warzone that is the interwebs? Well, unless you have the intelligence of a monkey, this alert doesn't apply. This requires you to actively allow the hacker access, however for easily manipulated clients- you may need to pay heed to this latest alert.

Security vendor SecureMac has discovered multiple variants of a Trojan capable of letting a hacker remotely commandeer a Mac computer.

The malicious code is being distributed from a hacker Web site, where there have been discussions on distributing the Trojan through iChat and LimeWire, said SecureMac, which has given the Trojan a "critical" security rating. The program can infect Mac OS X 10.4 and 10.5 machines.

A Trojan is a program that appears legitimate, but performs illicit activity when it is run, such as stealing passwords, making the system more vulnerable to future entry, or simply destroying programs or data on the hard disk. LimeWire is a popular peer-to-peer file-sharing program, and iChat is Apple's instant messaging client.

Besides offering a hacker remote access to the system, the Trojan discovered by SecureMac can transmit system and user passwords. Additionally, the application can log keystrokes, take pictures with the built-in camera on a Mac, take screenshots, and turn on file sharing.

The program takes advantage of a flaw within the Apple Remote Desktop Agent. The program avoids detection by opening ports in the firewall and turning off system logging.

The Trojan is distributed as AppleScript called Asthtv05 or as an application bundle called Astht_v06. The filed must be downloaded and opened in order to infect a machine.

Malicious code targeting the Mac isn't new. Apple in May released a patch for a serious vulnerability within its iCal calendar application. The flaw made it possible for an attacker to exploit the vulnerability by adding or modifying files on a CalDAV server. The code is distributed as an .ics calendar file in an e-mail attachment, or through a malicious Web site.

April 29, 2008

Microsoft A Good Guy?

In a recent set of closed door meetings, Microsoft met with Law Enforcement Officials to help solve a rash of crimes. Although Microsoft has generally gotten a bad-wrap for Bullying opponents out of the market place, it seems all that consolidation of resources is finally paying off. They gave a tool to the Officials that allows them to track botnets as they progress! How is this achieved you may ask? By tracking your computer :) Thats right- The Malicious Software Removal Tool is now Identifying you to law enforcement as a part of a global botnet! Oh Happy Day! We don't know exactly what the name is, what technology it uses, or even if it really exists- The Microsoft spokesperson offered this explanation: " Although Microsoft is reluctant to give out details on its botnet buster -- the company said that even revealing its name could give cyber criminals a clue on how to thwart it "

All my indicators went off at that comment- It seems that Microsoft is now engaging in the Propoganda market. We know who you are but we aren't going to do anything! Okay.

From a Microsoft White Paper:
With regard to phishing and spam, for example, it engaged in broad consumer education campaigns and worked on developing technological solutions such as phishing filters and SenderID. For both phishing and botnets, Microsoft began working more extensively with law enforcement to identify phishers and botnet herders in an attempt to create deterrent to such activity, even though the deterrent effect is limited by the current environment because it is hard to find offenders, and criminal penalties may be applied without sufficient force.