Help Support my Blog!

Virgin Mobile USA
Glasses USA
Amazon
Newegg
VPN4ALL
Netflix
Hulu
CafePress

 

Subscribe to Paul’s Tech Talk Affiliate Marketing Blog

Subscribe to Paul’s Tech Talk Science Fiction Blog

Subscribe to Paul’s Tech Talk Scams Blog

  • Acer 11.6
    Acer 11.6" Laptop 2GB 16GB | C710-2856
    Acer

    Currently  in process review this Acer Chrome book and boy is it nice!

Navigation
Sponsors

Entries in Phishing (30)

Monday
Jan232012

Protecting your personal information!


Booted from AmigaOS 4.1 Update 1 Live CD. Image via Wikipedia

People will steal your information in a heartbeat!


If you have had your head in the ground lately, you would let people see your information without you even knowing it.  If your one of those people who use your Ipad, kindle Fire (Affiliate link), or some really good Android device to check your emails or browsing the web, then your information is vulnerable to people reading or getting your information.

There are several ways to get your information, I've already talk about one way that someone hacked an account on one of my favorite science fiction site.   I actually had to help solve the problem and get the site running without redirecting visitors to another site.   This isn't always about scaring people but to help them do what is needed.

Security starts with simple stuff!


To protect your personal information is a simple as one, two, and three.   Nothing in this article is going to be very hard but I intent to help you make it even easier to for those who are untrained.   Having to help a couple of my customers with this, I've pretty much come up with a way to safely browse the web without leaving footprints for those really hard to find viruses.

Portable Apps -- This is a great little tool that you can customize and install Lastpass.   I thoroughly recommended it in the past and still do, it is a great deterrent for key loggers and phishing attacks.  Lastpass even has a portable(Mobile) application so you don't have to install anything on the computer in questions.


Create a Live CD -- Making a Pen Drive can go a long way to prevent from getting a virus or even someone getting your personal information, but that won't help if your using a wireless hotspot.


Install Ubuntu -- This the easiest way to have a Linux system on your computer.   Now I am not going to say Linux is worry free from viruses, but that does make it less likely to get them.   I really think Linux is OS is something that will stand the test of time because of it being an Open Source and not a closed projects like Apple and Windows.


Create a Virtual Machine --  this is like creating a live CD but not having to reboot.   You can create a virtual machine and run the live cd in the virtual machine.  This is however not as secure as rebooting because some program could be watching the network and logging everything.   I don't recommend this as much but it is something useful if you are worried about getting a virus.



Don't forget to use a VPN(Virtual Private Network)!


Now I already talked about some VPN's for Ubuntu/Kubuntu but that doesn't work with Windows or Macintosh, but I will talk about some alternatives for those who want to use Windows or Macintosh!

PublicVPN -- This works with Macintosh and Windows but have not tried this so I am only showing alternatives and thus you will need to determine if this is right for your situation.


Hotspot Shield -- This is one of the ones that I have used in the past and still recommend it and it now seems to work with Ipads and Apple products.


Android VPN -- The Android Market Place has some great choices for several different VPN's that may work well with your situation but I have yet to test them out and see which one is the best but yet this is something that may require some testing on your Android Device.



 Do you use a VPN?


This is something that I thought I would ask and thought I would ask it as a poll.   I would love to hear if you use a VPN and how much.   I encourage everyone to use a VPN when ever you are at a open wireless hotspot.

 

Paul Sylvester


Need Glasses? Try GlassesUSA!





Wednesday
Dec142011

Androids aren't immune because of people!

virus Image by twenty_questions via Flickr

Androids having viruses?


Really, I do not know who thinks android devices will be just as secure as an Apple product.  Now I know people have probably said that Androids are just as insecure as a Windows Machine.   I am not going to argue those points because they seem to be always floating to the surface every day from some unskilled computer user.   I’ve been asked by a few friends and even some family members who are concerned about a virus on their android device and thus want to buy Ipads more.  Even though Androids OS is an open sourced project the more the market share goes up for Android’s the more the evil guys will focus on creating applications and fraudulent software or games.   It is the nature of security and of the beast.   Nothing you can do to stop it.

Use Common sense!


This is something I tell my friends and family when buying an Application on the Market place from anywhere there is usually a bunch of reviews of it from various users and thus will help you determine if this application is worth the money or could be a problem.  When I want to add an application to my Android device, I will usually also see what others have said about the game or application and see the users ratings.   I will almost never buy an android application that has no comments but I am not novice when it comes Android.   I can always reset my android to factory defaults and restart the process.   So I know that is always my option when it comes to installing something that is unfavorable.   It however is not the end all save all for wiping a virus from your android device, if they want to get that virus on you device that would be the last place, I would put my application.   So it will clean most of the so called viruses off your device but until antivirus companies start getting the hint to make better applications for android the only true way to clean it is to erase and re-install but that is no option on your part especially if you have a phone or some proprietary device.

No Device is really safe!


Now when I go to buy a operating system, I already have that in my mind.   Nothing I have bought is ever going to truly be secured and thus I always go into this with an open mind and not worry about which one is the most secure.   I look for the one that is going to help me do what I want to do and not be restrained by any company.   I can view Netflix on Android just like I can view it on an Ipad.   I can take it anywhere I like just like my Ipad, it can be smaller for my convenience and cheaper.  Apple has their perks but then you pay for it, that is why I love Android because of the openness of the system.   I can do anything in the sun I want to do to the device and not worry about warranties and keeping it cheap.

If you understand this principle of mine then you will be FAR better than most people when it comes to buying applications on the device or installing applications from unknown websites.   As long as you know when you install an unknown application from an untrustworthy source you setting yourself up for problems.   Follow the path that has more security and don’t install anything without consulting some technology person and find out the risks and benefits of a program or application.

 

Paul Sylvester

 

Need Glasses try GlassesUSA!

 

 

 

Wednesday
Dec072011

Three ways on how to NOT waste your Money!

Another Job email!


I know it can be hard to find a job but this email from crmglobalresources.com was one of those that I thought I would talk about even more.

Here is what she said in the email:
Are you still available and looking for a new position? We were forwarded your resume and based upon your background and geographic location it may be a good match. Our Human Resources Department is currently scheduling company overviews this week for several of positions that we have open. I would like you to consider what we have to offer as a company.

We've recently launched a new Consulting Division and need individuals for Human Resources, Marketing, Recruitment, and Business Development. Experience is not required, although having a background in any of the above mentioned is helpful.

they also tried to have me join this web conference of there's.   I didn't want to  say this is a scam but every time I get these types of emails something just sounds the sirens.   I thought it would be nice for a change to tell you how to find out if a website is trust worthy or not.

Checking out the Business!


Having done this several times, I have come to use Whois.net to check out the background of the domain in question.   The site in question has only been made in the last few months.   No mater where your from you will always want to check out if a site is brand new or has been in business for quite some time.

While looking at Whois, I also see something quite interesting about domain.   Having been around the block and knowing about proxy security.   You get to wonder why this business would be proxying their address and number.

Let Google be your friend!


Never have a once not used a KEYWORD to find out more about company then when I am looking to find out more information about a company.   Never be afraid to ask words such as scam, pay, and whois.  Although these are just a few good keywords there are a ton of ways to find out information that you otherwise would never of found had you only searched for a certain term.

Nothing you put in search is ever going to be 100% right but it will give your more of an idea of what people and news are saying about this.   You can find out everything you might want to know about a business or website just by adding those to your search terms.

Check the website out!


Having been making my websites in the past, I know all to well that there are going to be people who may want a site template and just use that as their website and not change anything else.   You'll have to check out the site and make your own determination about if it looks like a template website with stock photos and words or if they actually put a lot of effort and time into the website.   The more questions you ask about the website and find out the more you can avoid being scammed.

After doing my research for the site in questions I must say that according to others, you will have to pay them money 199$.   That really isn't a deal in my mind and I suggest people go someplace else so as to not get ripped off by this so called company.

Paul Sylvester


 
Friday
Apr082011

Why I never volunteer for bacon!



"Please Enter A Valid Email Address" Image by pjsherman via Flickr


All Dogs love bacon!


If your wondering what I am talking about.   I will explain it to you in ways that you probably never considered.    If you have ever signed up to websites and they ask you if they could share your email address and name to 3rd parties.   3rd parties are like Epsilon Marketing and they make there money by selling products to people who have volunteered to receive bacon advertisements.

Security is nothing to Epsilon!


I won't go into detail about why because if I did you would probably agree with me just because of what happened.   Most likely Epsilon will loss a lot of customers and businesses due to the security breaches.    It just depends on how people feel about this company and why anyone should trust them after this breach.   I always tell anyone who signs up for a service to always makes sure to opt out of those emails.   I don't know about you but I know right now Epsilon has Egg on their faces and wouldn't mind sticking their heads in the sand.

Don't Get Caught Spear Phishing!


Now since the hackers have your name and your Email address, you probably are wondering what can I do not to get fooled.   I thought it would be a good idea to give some good guidance for those who might want to prevent this from happening in the first place.   You don't want them to get your sensitive information.    I don't want anyone to know my passwords or even my credit card numbers.   They will try to fool into giving out this information because there is some kind of urgent response about some kind of problem with your account.

Some stuff to consider:

  • No Company will call you asking for personal information

  • Nothing is so important as to go to the website directly

  • If they don't sound professional then tell them you will go visit the local bank or institution

  • Just because they know your name doesn't mean they are real

  • Don't click links in emails that you don't trust, always go the sites that you trust by typing it in your browser


These are just a few ways to help prevent yourself from being phished but nothing can prevent it but yourself. So remember to think before you click and think before you give out any information to unknown emails or people.


Saturday
Jul102010

Email Oppurtinities that seem Phishy!!!

Subject: Service manager position. Job ID 1278757758

Subject: New employment opportunity. Vacancy ID 1278793388
From: Xyla Cleveland <lopes_vivian@diamond-sky.net>
Date: Sat, 10 Jul 2010 11:29:22 +0100
To: (hidden)

Our company Diamond Sky, which is dynamically developing with every passing year, is going to offer you the convenience of various perspectives on the prospective position of a service-manager.

We are acting as concierge services in  7 highly-developed countries of the world. Our managers provide assistance in different spheres of business and leisure such as:
- booking of air tickets
- hotel bookings
- car renting
- search, hire and design of conference halls
- search, purchase and delivery of presents

As a result of our managers` assistance our clients are exempt from spending their personal and business time. Due to the fact that the services we deliver are in great demand all over the world, we expand  the stuff and we invite you to participate in the contest for the position of the Service MANAGER and to join, become a member of our company.

MAJOR DUTIES AND RESPONSIBILITIES of the service-manager are mentioned below:
-work with clients
-processing of orders of our clients
-processing and updating of our database of services

Position Requirements:
- efficiency in processing of orders
- responsibility in carrying out your duties
- good communication skills

We are constantly looking for diligent individuals, at all levels, to join our winning team, across all our concierge services divisions.
At Diamond Sky, we distinguish ourselves as a high performance organization with hard-working people who provide quality service to our customers. We believe that one of the most important functions of management is to provide employees with the possibility to develop their talents to the full. The benefits are job satisfaction for our employees enabling them to make a positive contribution to the success of the company.

If this position seems to be interesting to you, you fit the requirements and would like to become a member of our company
send your resume  and your contact phone number to vivian_lopes@xxxxxx and we will contact you.

My Wife got this email and I wanted to talk about how this looks phishy!!   After doing my research about this company, by going to their website. You’ll probably thinking they have a website, well it isn’t a very useful website just a page that has nothing clickable or even any phone numbers or where they are actually located.    This is why I suspect there is more than meets the eye.   I wanted to warn people not send your resumes to people you have no way of verifying because like anything else if you have done your homework, you will have found my website.  This is most likely a way to get your personal information from your resume,   like you name, your email address and you home address and other sensitive stuff.   Since there was no way to contact them directly I would advise caution when you find emails like this and the possibility of a job.   It seems like more and more these scammers and other nefarious people will lure you into giving out your personal information in hopes of landing a job to help pay off your bills and other such necessities.     If you get this email, I would just delete it and do not even consider this a viable source of a job opportunity.    My Wife got 3 different emails from the same place, I also did some searching and I found the website in question was recently made June 29, 2010. Stay Safe and remember do your homework before you jump into anything like this!!


I get my glasses from GlassesUSA. They have a Satisfaction Guarantee and evenPrescription Sunglasess for when your out doors. Give them a try, and I know you'll like them!
Friday
Jun052009

Not going to Twittertrain.net, just a Phishing attempt!!

So you want to have even more followers, but you don't know how to do it?   I've talked about [intlink id="3647" type="post"]Getting more followers and tips and tricks to get the people you want[/intlink].  Now let's talk about this to a point.

There seems to be automatic post going out with:

"OMG WOW Im getting 100s of followers a day, Check out this site: http://twittertrain.net"

[ad]Now going to the site and giving out your password is always a bad idea.   It seems to some people think it is easy to get followers but those who have built up your followers will know just how hard it is sometimes to get more.

I would be willing to guess this is a phishing attempt to get passwords and twitter names for later on.   Some would guess this will just become another way the spammers will use this to [intlink id="3662" type="post"]spread Scareware[/intlink].  I am thinking they want to get your password and save it for later use like this or others where they can get more people to click links and buy there fake products.

Graham Cluely blog post about this website also has a video about the problems associated with website. If you have given out your password, I'd strongly recommend Reseting your password if you can log in just changing the password.

I'd also suggest having [intlink id="2205" type="page"]Anti-virus and Firewalls[/intlink] installed to help prevent any malware that might be on your system now or later on.

If your really desperate for more followers, the best proven way is make friends and communicate.  This will make it easier for people to recommend you to other people.
Sunday
May242009

Twitter and the Acai Berry Spammers

Well According to Sopho's There seems to have been some hacking going on for the Acai Berry spam. Some of the messages were:

acaiberrytwitterspam1It seems to be a random http://random.CN domain but we've talked about this in the past.  Sopho's isn't sure how this happen but I have a suspicion that it was a Phishing attack done on the facebook users recent weeks that have the hackers going to other social sites and trying those passwords.

[ad]Although I agree with Sopho's on making sure not to have a dictionary word, I also think users should take care of all your online accounts.   As most people will become aware of is most users use only one password for all their accounts online or only have 3 different passwords for 20 different sites.  This is something that needs to change and you can do that with [intlink id="2646" type="post"]Roboform[/intlink] to keep your passwords safe and also to make sure they can't guessed.

If you have been compromised on t witter and only use one password, you can bet all you other accounts have been compromised as well.  You should change your passwords as soon as possible.   You should also make sure in the future not to be tricked into giving out your password which is called Phishing, in which a site with a different url is made to look like Twitter, Facebook, and Myspace log in page.
Sunday
May242009

New Facebook Phishing campaign!

According to Sans Internet Storm,  They have seen some signs of a new Phishing campaign like the[intlink id="3419" type="post"] Look at this Phishing campaign[/intlink] that went through a few weeks ago.  At the time of writing that report they weren't being resolved they now are being resolved making you look like you are logging into Facebook:




Phishing look a like!! Phishing look a like!!

[ad]Sites that are hosting these are in Belgium and are Redbuddy.be, Redfriend.be, and picoband.be.     If you recieve this with these urls you best thing you can do is just to delete them.   Some people have said it is using the term "look at this" I am unsure as to is or not but you can usually tell because of the the URL and if it isn't Http://www.facebook.com or Https://www.facebook.com then you aren't logging into Facebook but are logging into a fake site.


We've talked about [intlink id="2644" type="post"]why criminals want to use your account and why they need to get your passwords[/intlink].  I know they want to take control of your account for one reason or another but that is where the Facebook users need to keep watch on the URLS being displayed when you log into Facebook.    If you did that then you are one step ahead of the nefarious criminals and can be at peace.  Just like the Look at this campaign if you did visit those sites and given out your password it is strongly recommended to reset your password.


Update #1 -- More Domains have been created areps.at, greenbuddy.be, vispace.be, whiteflash.be, and bestspace .be . All these domains resolve to 211.95.78.98 And can be determined by going to Http://www.dns.be or http://www.dns.at  .   It looks like the server is hosted in China.  I wouldn't be surprised if t here were even more domains going to be regestered that were in Belgium!!  On a Side note it seems all these have a malicious hidden iframe in them so "DON''T Visit them unless you know what your doing".   I suspect that is how they are keep having people post to Facebook about these but that is only my theory!!  (Thanks Sans Internet Storm for all those updates)

Saturday
May232009

Upgrading to Twitter Pro -- ztrx.net Phishing attempt in the wild!!

I just got this alert from a friend of mine and I thought I would share it with you.  It looks like there is a new phishing attempt going on with websites try fool it's users into going http://ztrx.net and From the looks of it. It looks like this:

twitterprophish1



[ad]The message some users got were:

Upgrade to Twitter Pro - Visit http://bit.ly/[CENSORED] to upgrade your account


It seems that if you get this message on your account you should report it to @Spam and let them know. If you happen to get given out your password it is strongly recommended that you reset your password to prevent any further unauthorize access to your accounts. You should change your password as soon as possible. This is the first attempt they have tried this this weekend so be on the look out for more phishing attempts.
Thursday
May212009

Facebook and Twitter Phishing going on today!

According to Techcrunch we have one phishing site ground around peoples inboxes on facebook with it say "Check areps.at".  You go to the site and you will think your at the facebook login but your not.  I wouldn't suggest going to any of these sites, it has been reported by Phishtank.

[ad]Some of the sites to avoid today are : "nutpic.at, bests.at, areps.at, kirgo.at" each site will make you think your at facebook but this is what most will call a [intlink id="3419" type="post"]Phishing scam[/intlink].  Some other things to avoid are some Twitter phshing going on today as well.

According to Trend Micro there is one where the url looks like it is a twitter url but isn't (tvviter[dot]com).  The site is what people would call a typosquatting site.   This makes people think they are on twitter but aren't.   If you go to these to sites and have given out your passowrd, it is strongly recommended that your reset them:

Facebook password reset page

Twitter password Reset Page

If you would like to know more about what phsihing is please check out my blog for more information.  Don't forget to check out the forums for more information on this or just to talk about anything on your mind.

*Some reports I am seeing is some of these sites might be trying to get you to install the [intlink id="2249" type="post"]Koobface virus [/intlink]so please be careful, will update when I find out more.*
Tuesday
May192009

MobileMe Who me? Could this be Phishing?

Photo By : Richard Thomas
Photo By : Richard Thomas

MobileMe one of Apples latest software packages, recently started getting emails claiming they need to update their credit card information.


 


It seems that along with Twitter, Facebook, and PayPal Phishing are on the rise. I know this was going to happen do to the fact of the recession. I've seen more and more attempts to send people to the Canadian Pharmacy and to sell you drugs that I wouldn't recommend buying it online.


 


Some things I am wondering is when will Apple release they are having to protect their consumers from these types of attacks? I've talked about the Apple Botnets and how they will become more and more prevalent due to the fact users think they can never get a virus. See the Apple Ads in 2007 to prove my point.


 


So let's talk about online safety, and help those who might need help. Some of my thoughts to help keep the Apple People happy are:


 





  • [ad]Don't go Downloading Illegal stuff – This is mostly how they malware authors are getting Mac users to install malicious software. You think you downloading the I-Life 09 but are really installing a virus.




  • Don't click links in Email – This is so tempting because it easier to just click and have it open up automatically but most of the time if you click a link that says it is going to http://www.apple.com/support (That is how they fool you).




  • Don't give out your email on twitter – This is also something you should follow more and more, because you don't want to get a virus or spam from making your email public. There are ways to see your deleted twitter message so that isn't going to be hard to find those emails.




  • It's time to install Macintosh Anti-virus software – Yes you heard me, I know there are a few Mac Anti-virus software's out there. You should also make sure to keep that up to date.




Now is when Apple should start suggesting security, but they have stopped recommending it for so long. The Malware authors are getting restless with anticipation. I can only guess what they will try next but it will happen. Sooner or later you will get a virus so bad that Apple will start recommending it on there site. When that day comes, I'll be so happy because that means Apple software isn't that bad. I just hope Apple realizes it before it's too late. They've had so much Apple don't Virus propaganda thrown at it's consumers it is no wonder they aren't worried about Security.



Tuesday
May122009

When not to post #twitterpornnames

twitterpornname-security1


I've heard others call this a scam:

twitterpornname-security2


[ad]Now Although I know PCworld has made everyone paranoid that this is a scam.  I want to remind people that it was probably just a for fun.   According to Graham Cluely's blog, He points out why you shouldn't tell people the important information.


I see no evidence this was done to gather your information but Pcworld has sent out the warnings and made people think this was a scam, or a Phishing attack.  Although this could be used to get the information needed for your Gmail or other accounts.


I do recommend deleting those tweets and reminding people that you are the only ones that can prevent identity theft.  Trend Micro talks about this very detail about the subject but again they don't think this was conceived as a phishing attempt.   I'll let you decide but remember tweeting that it is a scam will only keep it on the trends, your best advice is just go on with your life and tell everyone to delete that sensitive information.

Tuesday
May052009

It is looking like a Phish to me Niggabook

niggabookphish

This site looks to be another phishing attempt, a poor one at best. I go there and it seems that you get the Facebook Login screen. According to:
mj78niggabook

If it isn't showing Http://www.Facebook.com or Https://www.facebook.com then it probably is a a phish site.   If you've did use your password with this site, I'd strongly suggest changing it.   If I find out more I'll let you know.   I know that the site is from Godaddy but if this was done by accident or not I do not know.   I don't make the Name up Niggabook.com is the site and until more things become clear, steer clear of the site for the time being.   When I find out more, you'll be the first to know!!

Monday
May042009

Facebook malware sending people to junglemix.in Phishing!

fblightfacebookphish


It looks like this is the newest phishing attempt for the Facebook community.  According to Sans, there is malware trying to send out messages to go to "junglemix.in".  I visited the site and it redirects me to "http://fblight.com/".   This is a phishing site because you can see from the address bar.   As of writing this post, it has been flagged by Phishtank that this is a phishing site.  I am glad people are reporting these types of sites to prevent people from getting there account stolen.


Find out the other phishing attempts that have been talked about, keep yourself safe.  Also this is a good time to[intlink id="2205" type="page"] install some free Anti-virus or Free Firewall[/intlink] software to help protect your computer from Malware.

Friday
May012009

Facebook Phish : "Look at this!"

Facebook seems to be coming the most widely used Social Website around right now, I went to Alexa to see what it said about how many users go there a day and I find this:

facebookalexa

So No wonder there are a lot of people who want to get your personal information. Yesterday there was a new email that was spreading with the Subject "Look at this!" and it points to fbstarter.com. When you go there you will find it looks really like Facebook but your not really at facebook sign in page. They want to use your Facebook account to gather information about your email account, or who your friends with. They also might try doing the old Scam of asking for Money because they are someplace and can't get home without your help.  They could also want to spread a [intlink id="2249" type="post"]virus through your account[/intlink], or [intlink id="2958" type="post"]steal your identity[/intlink].

[ad#cricket-right-ez]At the time of writing this the site is active and looks like Facebook but really isn't.   You should always login in to Facebook the right way by going to:

http://www.Facebook.com


or


https://www.facebook.com


If you have went to that site and entered your password in there, I know it happens to even Journalists.   You can reset your password. This way you can make sure the people behind that site don't have your password.   I do suggest however you start using a more secure password.  You should always use both Numbers and letters in your password.  Use a different password for each place your signup for.   I suggest [intlink id="2646" type="post"]Roboform[/intlink] to better help you protect your password and it helps make up a secure password for you.  The nice thing about Roboform is that you don't have to write down your password on a piece of paper, but you do have to remember to [intlink id="3171" type="post"]backup your passwords[/intlink] from time to time.  Facebook is looking to be more and more a targeted for the criminals activity, and you should watch what you do online.


Wednesday
Apr292009

Another Facebook Phishing going on again! (fbaction.net)

facebookphish1


(Click image to enlarge it)



[ad#cricket-right-ez]

It looks like site fbaction.net (Don't go there) is a phishing site for people today.  It looks like it would send out an Email with the Title being "hello'" and a link to this website.  This is being sent from people friends and should not login to Facebook through this site.  Remember the other [intlink id="3008" type="post"]Phishing sites that happen with Facebook[/intlink].


Someone is wanting your password to either spam others or to use it for other nefarious means.   For the time being anyone sending your a link should be sent through facebook and you will examine them one at a time.   You should not got this site.


Some other things you can do if you have done this is to reset your password.  You could also change it manually but you might not be able to use your current password because the Nefarious person has changed the password.  This will allow you to change the password without the current password.   You should also consider using a good [intlink id="2646" type="post"]Password Manager[/intlink], this will help you identify a fake Facebook site really easily.


If you use a good strong password, one with both Upper and Lowercase with Numbers and symbols, you will have a password that most people will not be able to guess.  This will help protect your account from being compromised.


Also with people sending files, it is also recommended that you install some [intlink id="2205" type="page"]free Anti-virus and Free firewalls[/intlink] to help prevent people from sending malware to your computer.

Saturday
Mar282009

Hotmail accounts get compromised!!

I received an email on a list and wanted to warn people:
[ad]
Dear friend,
i would like to introduce a good company who trades mainly in electornic products. Now the company is under sales promotion, all the products are sold nearly at its cost. They provide the best service to customers,they provide you with original products of good quality,and what is more,the price is a surprising happiness to you! It is realy a good chance for shopping.just grasp the opportunity,Now or never!
The web address: http://www.nekcn.com

Seems this is being sent from Hotmail accounts. There are a number of ways someone could be getting a hold of your email address. According to Microsoft forums this seems to delete your email contacts and also send out this in the same time. This seems to be a new spam campaign for this one company. I would guess someone bought advertising from this company and the advertiser is doing some really unmoral things.

There are several ways someone hotmail account could be sending out these emails. It could be a [intlink id="2650" type="post"]phishing attempt like they did with Twitte[/intlink]r. They could of done a dictionary attack on each account to find the password, that I why [intlink id="2646" type="post"]I suggest having a password generator[/intlink]. It could of been a virus, and if that is the case you would need to [intlink id="2205" type="page"]check your system out for the virus[/intlink]. I would guess it is the first two, because I am unsure of if you can have pop3 account or not. I don't use Hotmail but people seem to be using it.

If you recieve this email, I'd email the account responsible to let them know that they have sent this.  I would also like to know if it was a virus or how they account got compromised.   Remember only you can prevent from getting a virus, nothing else works better than yourself.
Wednesday
Mar252009

The Seriousness of the Twitter Vulnerability?

twitter_110 The main question is how much do you want to know about this?  Yes I am talking about a Vulnerability that could risk your twitter account or even yet inject malious software into the computer.

[ad#cricket-right-ez]We've seen that there have been [intlink id="2650" type="post"]twitter phishing[/intlink] in the past, and [intlink id="3008" type="post"]Facebook phishing[/intlink] have made people wonder out much do we depend on Twitter.

Lance James and Eric Wastl have provide Proof of Concept for this vulnerability, according to Information Weekly:
James cautions that XSS vulnerabilities should be taken seriously because they can reach beyond Web pages. "A lot of people think XSS is limited to the Web," he said. If there's another vulnerability in the victim's browser, the Twitter flaw could be used to launch additional malicious code, he explained.

As you can see there is more to this problem then meets the eye.  For one using the [intlink id="2980" type="post"]URL redirects[/intlink] could be one way this could be used.  No telling what other vulnerabilities lay for the client side twitter programs.   Twitter has a long way to go to be security minded, and yet Twitter hasn't said what they will do to fix this problem.

I for one would like to see this problem fixed just as quickly as possible due to the security risk involved to me, the consumer.  Twitter needs to jump on this and fix it to prevent any more attacks against there twitter audience. Although it doesn't hurt to have [intlink id="2205" type="page"]Anti-virus And a good firewall[/intlink], it all depends on End user to prevent this for the time being.

Come on Twitter, Fix this problem.
Wednesday
Feb252009

TINYURL being used by scammers and hackers -- How to prevent it!!

With Phishing attempts going on with the TINYURL redirect website, I thought I would show you how you could prevent from going to a site you don't want. Tinyurl.com has a great little feature, although it is a feature based on your cookies. It however will help prevent you from going to a site that you don't know anything that about. It's called the Preview Feature, and is available to any user who wants to use it.

previewtiny


As you can see if you enable it and you go to a click on a tinyurl, you will see this:

http://tinyurl.com/6t7ukk

previewtiny1


[ad#ad2-right]As you can see, if you click any TINYURL links you will automatically be told where that link is redirecting you to. This however only works with there being a cookie left behind in your system to let tell Tinyurl that is has to show the link first. So if you clean your cookies out from time to time, you will need to enable it every time after you clean the browser cookies. This will help prevent you from being phished because you will be able to tell if it is the right site in the first place. If not then you don't have to visit that site. This should be enabled on all Short URL Sites, I hope they make it a mandatory for any site that redirects. This would help stop phishing and scammers because they can't hide behind unknown url. Only time will tell though, these sites are always going to have problems but this would solve so many problems.