Showing posts with label Social Engineering. Show all posts
Showing posts with label Social Engineering. Show all posts

Friday, July 3, 2009

Beware of any Independence Day Links

The folks over at the Internet Storm Center have some great suggestions.
  • Celebrate
  • Watch Fireworks
  • Enjoy the cook out food (This is my suggestion)
What not to do?
  • Don't click on links in e-mails
  • Don't surf to sites with Fourth of July, Independence Day or Fireworks as keywords.
The security company Websense is reporting that the subjects listed above are being seen in the subject lines of spam e-mails. They contain links that are supposed to be videos, however all it leads you to is malware that attacks your PC.

Click here to visit the folks over at ISC. They do great work.

Small Organizations Lack Computer Security Training

It is becoming more apparent with stories like the Sisters of Charity Marian Clinic in Topeka, KS, and the Bullitt County, KY loss, that there is a huge hole where folks just don't know what to do or what not to do. Click here to read the Sisters of Charity story, and here to read the Bullitt County story. Combined, they have lost more than $500,000.

Smaller organizations don't have the funding to do much with Computer Security Awareness training and for sure they don't have the resources to watch for malicious activities on these networks. It is sad but true statement, and it is really taking a huge financial bite out of these organizations.

Computer security is not easy, but with some work, you can protect yourself from most of the malicious stuff out there on the Internet. Can you avoid it completely? Probably not. Especially if you use a PC with a Microsoft Windows operating system like XP, or Vista. I try and post helpful hints for those who don't have a lot of money to invest in computer security. Read through some of my past posts and watch for new content as I will continue to post new ideas to help you.

Stay safe this holiday weekend and have a FABULOUS celebration Saturday night.

Saturday, June 27, 2009

Farrah and Michael Spam

With the news of Farrah Fawcett and Michael Jackson's deaths on the same day this week, the spam campaigns that have followed are leading people to getting their PC's compromised. The criminal attackers out there love to take advantage of current events to spread their malicious software. It's a social engineering trick that preys on people's curiousity to know as much as they can about the events.

Along with these spamming e-mail campaigns, you will also need to be VERY careful when going to web sites on the topic of these deaths. Malicious web sites have popped up and the bad guys are using black hat search engine optimazation (SEO) to raise their malicious site's Google ranking so that their sites will come up in the top 10 web sites when you do a Google search. Only go to trusted sites if you are wanting to read more information on these current events.

Stay safe and have a FABULOUS weekend.

Saturday, June 20, 2009

Twitter Followers Lead to Porn

Here is the example of Twitter and the dangers that lie waiting in the Twitter world. Twitter, if you don't know, is a micro blogging site where you can post what you are doing in 140 characters or less. People can then follow what you do. Well since I'm in computer security, I follow several in the field of computer security. I logged on Saturday night, and noticed I had an additional follower. A closer look at this follower turned up interesting results.

First, here is the screen on Twitter showing who follows me. I see that this Ana Torres is following me. See the screen shot below.



So I clicked on the link on Ana's name. Here is what I saw.


Here you see that Ana states that if I want to see her pictures, I can click on the tinyurl listed above. So the curious guy that I am, I decided to check to see where that tinyurl led me to before actually going there. (Notice it says I must register first please, to see her pictures).

I did a preview of the tinyurl and found what the true url behind that tinyurl. I took that address and ran it through Trustedsource.org and found that the true web site behind the tinyurl is actually a porn site.


So be careful out there. Don't just click randomly on these url's trusting someone you do not know. In the next few days, Twitter will catch up with this follower of mine and they will be removed. So be aware that hot girls will not follow you if you are a computer security professional. LOL. Or any other type of Twitterer you are.

Have a great Sunday and stay safe.

Thursday, June 18, 2009

How to Avoid Fake Anti-virus - DON'T CLICK


So have you been one who has been presented with a window that tells you that your PC is full of malware including worms, trojans, and keyloggers, OH MY!

This happens sometimes when you web searches using Google and Yahoo. Other instances, you may browse to a web site and BAM! you get that same message about malware infestations on your PC.

This appears to be a message window but it is actually an Internet Explorer window. You should not click on any button or the X to close this window. In this specific case, the criminal attacker disabled the user from going to the Start Bar and right clicking on the IE window to close it. However, you can just bring up the Task Manager and under the Applications tab, close the Internet Explorer application from there. Any other clicking on this window will get your PC infected.


Stay safe out there and the weekend is almost upon us. Have a fabulous weekend!!

Saturday, May 30, 2009

Twitter Credentials Being Stolen

So recently, some Twitter users were offered a link to Twittercut to gain more followers. It appeared to be coming from a known contact, and they promised you to accumulate more and more followers.

It seems that TwitterCut appeared to be the real Twitter login page. A phishing site for sure.

If a person were tricked into entering their login credentials, Twittercut continued to send the same message you got to all of your contacts. At this point, it appears that no malware is being installed on victim's PCs.

For sure, Twittercut has the login credentials to many Twitter accounts. Twittercut has been listed on services that blacklist malicious sites but was still active just a couple of days ago.

This attack takes advantage of the trust that is built on networks like Twitter, as well as FaceBook, MySpace, LinkedIn, and other social networks. Always beware of messages that are unsolicited. My motto is "trust no one".

Stay safe and have a fabulous rest of the weekend.

Friday, May 8, 2009

Facebook Links - Trust Them or Not?

So you new to computers in general, or new to social networks like FaceBook? If so, listen up. One of the ways the bad guys take advantage of people is to take advantage of the trust factor that is built up with social networks.

How can this happen? Let's just say you happen to go to a website....say usatoday.com. And lets say you just happen to be unlucky and an ad that flashes up on the usatoday.com site happens to be one that the criminal bad guy has taken advantage of and planted a redirect that takes you to a site that runs the latest and greatest attacks on your computer. Could be a malformed PDF, Word, or Excel document. Next thing you know, your PC is being watched by the bad guy.

After a PC is has been infected with malicious software (Malware), some of the things bad guys try and steal are e-mail accounts, social network accounts, etc. Along with these of course, they also are looking for banking credentials, credit card credentials too. Now what? The bad guy has to keep spreading his malicious software around and take over more and more computers. This is how they continue to exist. Computers get cleaned from time to time so they are always looking to take advantage of people and tricking them to go places they really shouldn't go and take control of new computers.

With someone else's Facebook signon credentials, they can now send a message to all of your contacts with a link to a malicious website. Your friends trust you, so your friends click and BAM! They are now under the control of the bad guy and this scenario just continues to roll along. So, my advice to you is this when it comes to links sent from friends. DON'T CLICK ON THEM!!

Hang in there. Have fun, but be safe. Have a great weekend!

Monday, March 2, 2009

Obama Has My E-mail Address!

OK, it really isn't the real President Obama. It is the work of social engineers who are trying to entice you into clicking on links that promise you money from the stimulus bill that was recently signed in to law. Here is my friendly reminder to NEVER click on unsolicited links or attachments. Don't be a fool.

Spammers are always trying to figure out ways to get people to click on there tricks. I actually have 3 identical e-mails from someone purporting to be the president and he has money for me.

Hope your week has started off good and I hear the warm weather is coming! Stay safe.

Saturday, February 28, 2009

Adobe, Microsoft, Facebook

Well this week has been all about the Adobe Reader/Acrobat 0day vulnerability, but Adobe did release updates to Flash this week. Along with the 0day that Adobe has, word comes out that Microsoft has their own 0day vulnerability that is being seen in only targeted attacks.

Really the best defense against these types of attacks is YOU. You have to decide if you are going to click on either a link that takes you to a document either through e-mail or a web site. Trust no one is my best advice.

Now turning to Facebook. This past week there have been a couple of apps that folks fall for. Both attacks are types of social engineering that try to get you to enter your login credentials. Folks, if you are already logged on to Facebook or whatever other site you are on and you click something that prompts you to login, DON'T DO IT!! Something is wrong with that scenario.

OK, hope you all are having a fabulous weekend and snow sucks. Stay safe and Rock Chalk Jayhawk!!

Sunday, February 1, 2009

February = Malicious E-cards for Valentine's Day

February is here and with it, love is in the air. As February 14 nears, expect to see some fake e-cards from people you don't know to show up in your inbox. They are already being seen by some security research companies. All you have to do is remember this easy statement. NEVER click on any attachments or links in unsolicited e-mails. Anymore today, you can't even trust e-mail from those you know because if they are hacked, expect everyone in their contact list to get malicious spam e-mails also.

Have a happy Super Bowl Day today. I'm cheering for the Cards. Always hanging with the underdogs. Stay safe.

Monday, January 19, 2009

Fake Antivirus Scenario

So you do a search in your favorite search engine like Google, Yahoo, or others. You search on a topic of interest, then you click the link to see if it is something you were researching on.


But when you click on the link it does not take you to the site. It pops up a message that looks like this. It's kind of a scary message that says hey you have some bad stuff on your machine.

Now if you get this message, I would advise you not click on the OK or the Cancel buttons. Wouldn't even click on the X. Interesting thing is the bad guy has disabled the ability to go down to the START bar in Windows and right click the Windows Internet Explorer to close it. So here is my advice to close that Explorer window. Bring up the Task List (Cntl + Alt + Dlt) and then kill it from there.

Stay safe out there and Rock Chalk Jayhawk!!!!!

Wednesday, December 31, 2008

Fake AV - Stubborn to Rid from Your PC

I've worked on a few of these fake AV's on friend's PC's. These run bogus scans and tells you that you have bunches of malware that is infecting your machine. It prevents you from going to websites to get cleaning software. Prevents your legitimate AV from updating. Turns your Automatic Updates off. Gives you the fake Microsoft Windows Security Shield and tells you that you need to activate whatever the current name of AV that is installed on your PC. Some give you fake BSOD (Blue Screen of Death). Popups take over your PC. Your browser is hijacked.

It goes by many different names. Total Protect 2009, eXPress Antivirus 2009, iSafe 2009 (Sounds like an Apple application), Antivirus 360, Perfect Defender 2009, and on and on and on. This is just some of the more recent fake AV's that have been plaguing PC's lately.

It's tough to remove this type of malware because it defends itself very well. The best thing is to not get the nasty stuff. The most common delivery method is social engineering. Tricking you into installing the malware yourself. Be wary of messages sent to you from friends on social networking sites like MySpace, FaceBook, etc. A very effective way of propagating itself is once it is installed on a PC, any user of these social networking sites sends messages to all the friends on you list trying to trick your friends into installing this malware.

Stay safe. My Kansas University Jayhawks rocked the Insight Bowl earlier tonight 42 to 21 against Minnesota. Hope you had a safe and happy New Year!

Tuesday, December 30, 2008

More and More Fake AV!

Just recently, Microsoft built in to its malware removal tool a lot of the fake AV's that have been infecting so many PC's. And now of course we find even more fake AV's seemingly going strong. Click here to read a posting from the Internet Storm Center. Seems that the way they are infecting PC's is through a very effective way of social engineering.

Play it smart, don't just randomly click on things, and patch your software applications like, Adobe, all your Microsoft applications, etc. I've written previous posts that talks about the Secunia Tool that helps you keep up to date.

Stay safe, and have a Happy New Year! Rock Chalk Jayhawk. Insight Bowl on December 31.

Thursday, December 25, 2008

Same Old Story - Malicous eCards

Well, just a warning to all this holiday season that the bad guys are still using the malicious eCards sent via e-mail. Be warned, don't open them!! You can click here to read the story from the Internet Storm Center.

Hopefully all of you have been good boys and girls and Santa has rewarded you well this Christmas. Take care and have a safe holiday season.

Wednesday, December 24, 2008

Antivirus 2009 Really Sucks

I have commented a few times about all the fake AV going around the Internet. It appears that it morphs and adds "enhancements" that defends itself well. Turning off Microsoft Automatic Updates, not allowing you to browse to sites that will help you clean your PC, etc.

Well I ran across another blog today written by Gary Warner. He has a nice detailed post going into the details of how the bad guys are taking advantage of Google searches to raise their ratings that when people click on these links, it infects your PC with fake AV.

Click here to learn more on how the bad guys take advantage of things we use everyday, Google, and use it to propagate their nasty malware. Hey Nancy, this may be how it got installed on your PC!

Stay safe, have a Merry Christmas and a happy and safe New Year!

Thursday, December 18, 2008

Examing A Spam E-mail



Some days you get e-mails that are obviously spam e-mails. Just the little things you look at and can tell right away that it is not real. Above you can see a copy of the e-mail. Right away you know that the fake UPS e-mails are still going around. Now someone in SPAMMERVILLE should tell them UPS stands for United Parcel Service. Not United Postal Service. LOL

Have a great Thursday tomorrow!

Sunday, December 7, 2008

FaceBook Being Used to Spread Malware

So you are signed up on Facebook.com and you get an e-mail stating that they can't believe what you did in this video. If the user clicks to view the video, a message pops up stating that they need to download some additional software to view the video. Once this has been clicked, malicious software (malware) is downloaded and run and your PC becomes the newest member of some bad guy's botnet.

This is a type of social engineering that makes you click on something and is sort of a trojan (something malicious posing as some useful application). Patching your machine is probably your best defense that you can do for yourself. One tool you can use that checks a wide variety of software on your PC is one from Secunia. Click here to scan your PC to see if you have any vulnerabilities that need patching.

Take care and have a fabulous Monday. I know I will.

Saturday, September 20, 2008

How to Avoid Fake AV

Have you been one of the many who have had the rogue anti-virus installed on your PC and wondered how you got it? Actions you have taken may have installed this nasty piece of malware. Here are a few of the ways you may have had the fake AV installed on your machine.

  • Spammed email messages (ecards) that contain malicious links
  • Instant messaging applications where links are sent as messages
  • Private messages in social networking sites
  • As codecs for videos hosted on social networking sites
  • Downloaded by malware in a prior infection
  • Mass SEO poisoning involving several compromised Web sites
What happens from that point may vary, but the bad guys goal is to trick the user through a variety of system modifications and scary warning messages that something is wrong with their PCs. These scare tactics include showing fake Windows popup balloons, modifying the PC’s wallpaper to an alarming message, and performing an unsolicited system scan that yields worrying scan results.

These attacks were starting to pop up in August, and they have continued here in September. This basically tells me the attacks are pretty successful. Beware of the social engineering that actually tricks you into installing this rogue AV badware from the criminal attackers.

Stay safe and have a great weekend.

Saturday, September 13, 2008

Fire Fighters Targeted in Phishing Scam

The Boston Fire Fighters Credit Union was targeted in a social engineering scam purporting to take a survey and then they will credit your account with $99.99 after you complete it. Well, those malicious attackers hit paydirt it sounds like. Many fell for it and gave up their credentials for their accounts. Sounds like the Credit Union was notified and hopefully many of the folks who fell for it, aren't going to be out too much money if any.

Click here to read the full story. Remember my advise. If it sounds too good, it probably is. And last, never respond to unsolicited e-mails. Protect yourself and your financial health. Stay safe and we are thinking of those being affected by Ike.

Thursday, August 21, 2008

People Really Do Click on Spam E-mails

One of my responsibilities is teaching Security Awareness Training. We sound like a broken record at times, but we always say NEVER click on links OR attachments in unsolicited e-mails. I never really thought too many people clicked on these types of e-mails.

Read this article from ZDNet and was shocked. Click here to read the blog entry from ZDNet. And NEVER click on any type of spam e-mail.