Sunday, November 30, 2008

Small Credit Unions Equal Compter Security Risk

OK, it has been a long time since I've posted a story on my blog. I write about computer security. Today's story talks about a couple of small local credit unions here in my town of Topeka. Educational Employees Credit Union and Kansas Super Chief Credit Union sites had what is called a code injection attack on their websites. The site that their customers were re-directed to was hxxp://ytgw123.cn (Don't go to this site. It will attack you PC with exploits.) The attack happened somewhere around September 26th, 2008.

So how did this attack happen? First, the web sites were not coded securely which allowed the criminal attacker to inject this code into the online banking sites for these two credit unions. The attacker didn't actually access the credit union's customer accounts. However, if any of their customers innocently went to either credit union's website, they were re-directed to this malicious site. If not properly patched, these customers probably now have malicious code installed on their PC that could be a password stealer, keylogger, and is now a robot which means someone with bad intentions now controls your PC.

I've been told that the problem has been corrected but I have my doubts. Since I have an account at Educational Employees Credit Union, I will be watching this closely. The problem I see is that this was not reported and customers of EECU and KSCCU have spyware or malware installed on their PC and may not realize it.

Hopefully the company that is contracted to create and maintain these credit union's websites has found the actual vulnerability in their own code and closed this hole. From my experience in computer security, code developers are trained to write code quickly to add to a companies bottom line. They are not trained to code securely. I believe that this situation is so common and customers of these smaller banks and credit unions who have to contract with companies who develop and write code are putting the customers of these institutions in danger of criminal hackers stealing login credentials for their banks and credit union's accounts. I will be watching my credit union. Maybe you should too!

Saturday, September 20, 2008

How to Avoid Fake AV

Have you been one of the many who have had the rogue anti-virus installed on your PC and wondered how you got it? Actions you have taken may have installed this nasty piece of malware. Here are a few of the ways you may have had the fake AV installed on your machine.

  • Spammed email messages (ecards) that contain malicious links
  • Instant messaging applications where links are sent as messages
  • Private messages in social networking sites
  • As codecs for videos hosted on social networking sites
  • Downloaded by malware in a prior infection
  • Mass SEO poisoning involving several compromised Web sites
What happens from that point may vary, but the bad guys goal is to trick the user through a variety of system modifications and scary warning messages that something is wrong with their PCs. These scare tactics include showing fake Windows popup balloons, modifying the PC’s wallpaper to an alarming message, and performing an unsolicited system scan that yields worrying scan results.

These attacks were starting to pop up in August, and they have continued here in September. This basically tells me the attacks are pretty successful. Beware of the social engineering that actually tricks you into installing this rogue AV badware from the criminal attackers.

Stay safe and have a great weekend.

Saturday, September 13, 2008

Fire Fighters Targeted in Phishing Scam

The Boston Fire Fighters Credit Union was targeted in a social engineering scam purporting to take a survey and then they will credit your account with $99.99 after you complete it. Well, those malicious attackers hit paydirt it sounds like. Many fell for it and gave up their credentials for their accounts. Sounds like the Credit Union was notified and hopefully many of the folks who fell for it, aren't going to be out too much money if any.

Click here to read the full story. Remember my advise. If it sounds too good, it probably is. And last, never respond to unsolicited e-mails. Protect yourself and your financial health. Stay safe and we are thinking of those being affected by Ike.

Sunday, September 7, 2008

Cleaner 2009 = Fake AV

Hope the weekend has gone good for you. I've written about Antivirus 2009, now we are seeing another application calling itself Cleaner 2009. It performs system scans that shows false positives or exaggerated spyware results. Even though Cleaner 2009 attempts to look legitimate with its reviews, you don't really want it on your home or small business PC's. Do not fall for it. It is NOT a legitimate spyware removal tool, only a waste of time and, most of all, money.

Cleaner 2009 prompts users with multiple warning messages and popups that state Cleaner 2009 detected spyware on the machine. This is a poor attempt by Cleaner 2009 to get you to purchase the Cleaner 2009 program. Cleaner 2009 program may be difficult to remove manually. I've had a few machines that I have seen with the fake AV on it and it is a pesky thing to get rid of. Popular rogue anti-spyware programs like Cleaner 2009 are dressed up and renamed to confuse unsuspecting computer users.

Stay safe and have a fabulous weekend!

Thursday, September 4, 2008

Are You Getting Obama Spam Like Me?

Well I have this throw away e-mail address that I get a lot of "interesting" spam sent to me. I have been finding some rather unusual e-mail from Barrack, Michelle, and Joe too. When you look at the header information, it is being sent from the IP 70.42.50.186 which belongs to EHLO mta-inap4.bluestatedigital.com. It appears that the Obama campaign doesn't mind buying e-mail lists so they can spam to millions. The people who maintain these large e-mail lists are actively participating in not so nice ways of collecting these e-mail addresses.

I'm not an Obama fan. Not really that much of a McCain fan either. I do notice that I haven't got these types of e-mails from the RNC. And I find at the bottom of the e-mail, an unsubscribe link. I have always advised people to NEVER click on links in spam e-mails because you don't know what the person responsible will do with this information. Those with not so good intentions use the unsubscribe link to verify that they have a valid e-mail address and that address will be "verified" in a way that these people who market these list can sell for more.

Delete all spam e-mails that you get. Never, never, never click on any links or attachments from unsolicited e-mails.


Sunday, August 31, 2008

Scammers/Spammers will use Hurricane Gustav

People in general here in this great country of ours, The United States of America, are very giving and want to help those in need. When ever we experience a natural disaster like Hurricane Gustav, there are those who prey on our willingness to help. Those without a conscience will be there to take advantage of events like these.

When these events happen, the Internet Storm Center reports on domains that are being registered. A couple of days ago, they started seeing domains being registered relating to Gustav. Here are a few of those listed in the Internet Storm Center's latest post. Click here for the full Diary entry from the ISC.

boredatgustavus.net
contributegustav.org
contributiongustav.org
donategustav.org
donationgustav.org
gustav-hurricane.info
gustav-hurricane.net
gustav-hurricane.org
gustav-hurricane.us
gustav-relief.org
gustavassistance.org
gustavattorney.com
gustavcharities.com
gustavcharity.com
gustavclaims.net
gustavcontribution.org
gustavdonation.com
gustavfound.com
gustavhelpers.org
gustavhurricanerelief.com
gustavhurricanerelief.info
gustavhurricanerelief.net
gustavhurricanerelief.org
gustavlawsuit.com
gustavlawyer.com
gustavlegalrelief.com
gustavlegalrelief.info
gustavlouisiana.org
gustavmissing.com
gustavneworleans.com
gustavneworleans.org
gustavpictures.com
gustavrecovery.org
gustavrelief.info
gustavrelieffund.com
gustavrelieffund.org
gustavreliefvolunteers.com
gustavresponse.com
hannahrelief.org
hannainsuranceclaim.com
hannalawyer.com
hannarelief.org
helpgustavvictims.com
helpgustavvictims.net
helpgustavvictims.org
hurricanegustav08.com
hurricanegustave.info
hurricanegustavphotos.com
hurricanegustavrelief.info
hurricanegustavrelief.net
hurricanegustavrelief.org
hurricanegustavrepair.com
hurricanegustavresponse.info
hurricanegustavvictims.info
hurricanegustavvictims.org
hurricanehelp.us
hurricanelinks.info
hurricanelinks.org
hurricanerelo.com
hurricanerelo2ms.com
hurricanerelocate.com
hurricaneresponder.com
hurricaneseasonflorida.com
hurricanetrack.org
hurricanevolunteers.info
hurricanewatchnet.org
hurricanework.com
isurvivedhanna.com
lahurricanerelief.org
myhurricanephotos.com
netexashurricaneresponse.info
officialhurricanegustav2008.info
survivedgustav.com
survivedgustav.net

Some people may be registering these sites to sell in the next few days. Others may start to add "Donate Here" buttons. You need to beware of this type of scammers.

All our thoughts are with those in the Gulf Coast area. Monday is when they are scheduled to make land fall. Many have left. We all hope that this is not a repeat of Katrina. Stay safe and we'll have to see in the next 24 hours what will happen.

Tuesday, August 26, 2008

Internet Behavior Can Protect You

We've talked about this in previous entries but it is always good to review how your behavior while surfing the Internet can go a long way in protecting yourself from the bad guys. The specifics we'll talk about in this entry will be porn, P2P, and free applications on the Internet.

Porn. It is a weakness that a lot of men have and probably some women too. You have to understand that bad guys know that they want as many targets as possible so they look to what can be used to spread their evil wares. Like anyone else, bad guys want to spread their keyloggers, file stealing applications, and bot software to be able to use your computer for their evil purposes. Since many have a weakness for pornography, this is a known target for bad guys to plant their traps. My advice? Stay away. Make sure all people in your household stay away also.

P2P. Also known as peer 2 peer software. It is known as file sharing software that can be used to spread software, music, videos, and pictures. All I have to say about P2P is that you need to be warned. Not only is it illegal, you may get more that you than you bargained for. Bad guys like attaching some of their evil software along for the ride. My advice? Don't use P2P unless it is a trusted source and if it is legal.

Lastly, we'll talk free applications. I am really careful about what applications that are free that I use. I've mentioned in previous entries that I use firewall, antispyware, and antivirus that are free. When you are making the decision to download a "free" application from the Internet, it is best to actually read the EULA. The EULA is end user license agreement. You may be agreeing to be tracked so adware popups can be sent to you or your e-mail address might be given to spammers so you get even more of the e-mail crap than you do today.

Your behavior on the Internet really may be your absolutely best protection. More than antivirus, or antispyware. Be smart and don't fall for the bad guys out there trying to take advantage of you in a financial way.

That is it for now. Stay safe and have a great week!