Saturday, November 28, 2009
Avoiding Botnets
Online, the biggest battle these days is against botnets: networks of infected computers which hackers can use -- unbeknownst to the machine's owner -- for online crimes including sending out spam or launching a denial of service attack.
Unfortunately, the black-hat techniques employed to snare users into a botnet web have evolved to a level that makes them often undetectable by even the most sophisticated security products. Combine that with a lack of user knowledge, and the threat of infection becomes very high. (See: Botnets: Why it's Getting Harder to Find and Fight Them).
"The frustrating thing is they can make their chances of getting infected much, much smaller," said Steve Santorelli, who sees how users fall prey to easily avoidable traps every day. Santorelli, director of global outreach with the non-profit security investigations firm Team Cymru, spends his days monitoring malicious online activity, particularly botnets.
Santorelli notes that while just one strategy probably won't cover you, with several tools in the tool box, the rate of infection within an organization significantly drops.
Tip 1: Have work AND home machines regularly updated with patches and antivirus software
The average user doesn't necessarily have a lot of technological knowledge, said Santorelli. They might not realize the importance of working with IT to ensure they are up to date with patching and software upgrades. This problem may be especially prevalent among workers who are exclusively remote.
In fact, a study conducted by security firm Sophos last year found most computer users ignore security updates and turn off their firewalls. Sophos scanned 583 computers for 40 days and found that 81 percent of the machines failed one or more basic security checks. Most machines, 63 percent, were lacking security patches for the operating system, office application and programs like Windows Media Player and Adobe Flash. More than half, 51 percent, had disabled their firewall and another 15 percent had outdated or disabled antivirus and anti-spam software.
Those are exactly the folks that criminals love.
"These people are going to go for the low-hanging fruit and unfortunately there is a lot of it out there," said Santorelli. "There are so many machines without updated AV on it."
If your patching system isn't automated, your users need to be made aware of the risks they are taking by working with unpatched and out-dated security technologies. And while security updates are not the cure-all for malware infection, Santorelli said they certainly serve as a strong deterrent.
"If you are walking down the street as a burglar and you see a house with a Rottweiler, and a visible sign from a security company, you probably won't attack that house," he noted.
Tip 2: Use the latest browser versions
Staying away from dubious sites and sticking to known brands used to offer reasonable online safety. Unfortunately, that's less and less foolproof.
"It used to be that if you surfed to places like CNN, or the Weather Channel, you weren't going to come across great deal of malware," said Santorelli. "That isn't the case anymore. We've seen a number of cases recently where people have gone to a legitimate web site and there is an advertisement up there hosting some kind of malicious code."
That is where the latest safe browsing technologies can help, said Santorelli. The latest versions of today's browsers will often flag potentially dangerous content.
"Browsers are so much more secure now that so many of the holes that existed in these browsers have been patched. There is also a great deal of anti-phishing and anti malware that goes into them now. So if you try and go to a link that contains malware, your AV might not pick it up. But your browser will say: "Are you sure?"
The good news is most browsers are free. You can download the latest version of Internet Explorer or Firefox fairly easily and quickly, too (See: IE or Firefox: Which is More Secure?).
"It will only take you five minutes to have the latest browser technology," said Santorelli. "It is just another string to your bow, so to speak."
Tip 3: Be a little more careful when you get a link or an attachment.
"Don't just blindly click on things and rely on other people to protect your computer," noted Santorelli. "You've got to take some responsibility for your own security."
Team Cymru research reveals that the most common attack vectors for installing malware continue to be links in emails, or drive-by downloads.
"We know from our recent investigations that there is a great deal of success to be had [for hackers] by just sending links out," he said.
Just because you receive the email from someone you know and trust, it doesn't mean it is safe. This includes friends and family, whose systems or accounts may have been compromised, and also well-known web sites you use, like social networking sites or banks. See Five More Facebook, Twitter Scams to Avoid for examples of current attempts to exploit social media sites. And large banks, such as Bank of America, often find their name is used in email phishing scams where thieves send out messages warning that customers their account has been compromised with a link that leads to a fake, but very legitimate-looking login screen.
Of course, whether or not you should click any link or attachment also depends on if you have complied with steps 1 and 2 above.
"You're going to have to take it on a case-by-case basis," said Santorelli "And my concern would be significantly raised if I didn't have my computer up to date with antivirus and browsing technologies."
Tuesday, November 17, 2009
Identity Scams on Job Search Sites: Protect yourself
Legitimate employers don't need to access your bank account until you become an employee. They are more interested in getting the right candidate. If you are asked for bank account details as part of the application process, it's a warning sign that this "employer" is up to no good.
2. Never share your Social Security number (with anyone)
Legitimate employers will ask for your Social Security number only when they have made a considered selection and are serious about making a job offer (e.g., after they've interviewed you).
They can conduct a background check after they have made, and you have accepted, their offer. Also, they do not need your Social Security number, for tax purposes or any other reasons. Identity thieves will be very persuasive and will try different ways to ask for your Social Security number up front. Don't give your SS number to anyone.
3. Never agree to a background check online
Until you have proof that you are a bone fide candidate for a bone fide position, it's not necessary for an employer to do a background check, the only exception may be the government but they will be very sympathetic to your requests to prove their legitimacy.
In fact, given the high level of responses from every job ad posted, the average HR department has neither the time, the funds nor the resources to do 'background checks' on all candidates.
4. Research potential employers (always)
If you're unsure whether a potential employer you've found on a job search site is legitimate, it is very easy to check them out. Find out whether the business has a physical address and check with the local town hall, mayor's office, directory of companies or even the telephone guides.
All companies and organisations have customers, support services and suppliers. Ask who they are? A scammer will get very defensive but a 'real' company can see this as a candidate showing interest in their organisation. Even if they don't know there and then, they will be able to give you a better 'sense' of the company.
5. Consider sharing less information on your resume.
Many people include their phone numbers and mailing addresses on their resumes, and indeed, employers like to know job applicants' area codes and Zip /Post codes because they sometimes screen candidates based on that information.
So, if your wary of identity theft, you should only include one e-mail address, during the initial stages with prospective employers. The e-mail address that you use should be a clean and unique e-mail address, created only for your job search. Keep your personal e-mail accounts and social networking sites /usernames, private.
6. Opt out.
When you sign up for e-mail newsletters and offers from legitimate businesses, opt out of receiving offers from their third-party business partners. It will definitely cut down on the amount of spam e-mail you receive and substantially decrease the chances of your personal information ending up on the scammers black market.
There are no signs of these job search scams abating, but as the holiday season approaches, identity thieves are likely to shift their tactics to target online bargain shoppers. The more adventurous will run parallel activities, of course.
Be assured, if the criminals concentrate on Xmas shoppers for the season, they will bounce back to job search sites as soon as the shops close. As long as job seekers are so willing to share personal information, identity thieves will be be there to take it.
Identity Theft and Job Search Scams
Their net area increases exponentially and at the same time the virtual mesh size decreases, and the bate varies, just so they can catch the little guys too. In this case we are talking of job search scams. The posting of fake jobs or sending out fake enquiries from non-existent recruitment companies, all in an effort to make you part with your identity details.
1. Phishing Scams - Job Candidates
Currently, two types of job search scams are most common. One is a phishing scam, where identity theft perpetrators e-mail would-be victims to tell them about potential jobs and opportunities to make extra money. The e-mails direct recipients to credible websites that the identity thieves have created specifically to gather personal information. The overall appearance is contrived to make it look like a genuine job site where you would be willing to submit your genuine job application info.
These fake applications request all the information job seekers would expect to provide, such as their name, address and phone number, but in addition, they also ask for information that you would not expect to provide. Certainly not so early in the process. Beware of sites that make unusual requests and ask for Social Security numbers, permission to conduct a background check and /or bank account information.
They may tell you they need your bank account information so they can make sure your salary can be direct deposited. Some may even sweeten the request by saying that they'll place money in your account and then remove it just to make sure it works. Do not allow this. No professional company will do this. It is simply step one (1) in a trick to fool you and the bank into giving the criminals access to your bank account.
Step two (2) is to empty your bank accounts and Step three (3) is to sell your details to other scammers and criminals. Step four (4) is yours and it's the biggest and most difficult one of all, trying to convince your bank, your family and your creditors that you lost all your money by trusting someone you did not know, had never met and had not even spoken to.
Oh yes, and it goes without saying that you never will receive any information about jobs, because it is not what these people do, it is simply what they say they do.
Identity thieves buy e-mail addresses from legitimate businesses who don't care if they are selling people's information to the Internet black market. It's a bit extra cash for them. So don't expect them to protect you, that's your priority.
2. Phishing Scams - Fake Employers
In the second scam, identity thieves pose as genuine employers on legitimate job search sites. They post a generic job that would appeal to a large number of people (phishing with a wide net, small mesh), and in the course of talking to applicants (online or via phone), they carefully ask for more and more personal information.
They are professional con people (men and women). So they will take it slowly, and spend time 'romancing' you. So as not to spook you, they will sound as credible and plausable as a 'real' employer would but probably more positive about offering you a position, just to draw you further in.
Despite the efforts of the owners, there are identity thieves on all valid and existing job search websites who are posing as employers.
Remember that, in these cases, there is no job to be lost. There is no career path to join. There is only the long road to the Police station to report the loss of your money. Be cautious, question any 'strange' requests and above all good luck with the job hunting.
Thursday, October 29, 2009
Facebook Password reset scam is Bredolab botnet attack
Virus hunters are raising the alarm for a large-scale spam attack that uses fake Facebook password-reset messages to trick PC users into downloading a dangerous piece of malware.The malicious executable is linked to the Bredolab botnet, which has been linked to massive spam runs and identity-theft related attacks.
According to Websense, the address of the sender is spoofed to display “support@facebook.com,” a trick commonly used to trick targets into believing it’s a legitimate e-mail from the popular social network.
The messages contain a .zip file attachment with an .exe file that connects to two servers to download additional malicious files and joins the Bredolab botnet which means the attackers have full control of the PC, such as steal customer information, send spam emails. One of the servers is in the Netherlands and the other one in Kazakhstan.
Saturday, August 1, 2009
Avoiding Identity Theft: What to be aware of
Look out! Look out! There's a thief about! You would be amazed how little information a criminal needs to steal your identity.Social Engineering is the real threat
Even a piece of direct mail that you've carelessly thrown away, can be enough for a fraudster to pose as you, borrow money or acquire sweets and goodies and then vanish. What do you get? Debts in your name and your credit status in tatters.
The information they use varies but the personal information that an ID thief is typically interested in is your full name, date of birth, current addres, account numbers and, if possible, passwords and PINs.
It sounds a lot but a little work can deliver a surprisingly large amount of data. The idea is to do a bit of cherry picking, and the internet and social networks are a big help.
1. A bank statement
If they're really lucky, a statement might indicate your overdraft limit as well as your full name, address and account number. Shred, burn or rip em up, before binning them
2. A credit card statement
This won't contain your PIN, so they can't use the card account in a British retailer, but it could be enough information to enable the fraudster to purchase from foreign websites. Shred, burn, rip..
3. Access to your social networking pages
It may seem innocent enough, but many people innocently reveal enough information on Facebook, My Space or other social networking sites for a fraudster to guess their PIN and passwords. Don't make it too easy. Change them regularly.
4. Direct mail
Fraudsters are always on the lookout for direct mail containing an offer of a credit card or loan, with your details filled in that they can intercept. Once a crook has one fake account in your name, it's easier to open others. Shred, burn, rip...
5. Your driving licence or passport
These documents provide vital photographic ID that can be amended by an expert and used to prove that he or she is actually you. Secure them securely....they are worth 50,000 GBPs
6. Replies to phishing e-mail
Phishing e-mails are messages that appear to be sent from your bank or other trusted authority and are designed to capture your personal or financial information. Always remember that banks never ask for your PIN or internet banking details. Don't respond to scam stuff...
7. Your PINs and passwords
These are essential if a criminal wants access to any of your accounts or to use your payment cards. Guard them securely and change them regularly
8. A catalogue
Mail-order catalogues may appear innocuous enough, but if they're stamped with your name, address and account number, a thief could claim you've moved home and hijack your spending limit. Shred, burn, rip up anything with your name and address on it before binning
9. Your CV
Most CVs had a lot of personal information, such as your name, address, date of birth, employment history and marital status. Your CV contains so much information that could be used to impersonate you that some online job search services are advising people to be careful before uploading them to to their sites Be selective and question people who want your details.
I agree that it is difficult if you are looking for work and broadcasting lots of CVs in an uncontrolled manner. Keep a spreadsheet of who you have contacted (Company, Contact person, phone number) and when, also which CV version they have but 'be aware' that not all e-mails asking for CVs or CV updates are genuine.
Question them! and do some research on THEIR contact details and website credentials. We all know how easy it is to create a believable or viable website!
If in doubt, don't do it! or severely restrict the amount of personal information on the CV provided. Think of it like this; someone (an attractive stranger) has just stopped you in the street and asked for your contact details; name, address, phone number, e-mail address, etc. In return, you get a moment's 'hope'; hope of a job, hope of money, hope of a future. It is a very attractive offer!
Would you do it? Consider under what circumstances you would do it and why? Consider also how you could replicate those 'conditions' online, when responding to requests for personal details?
10. Online banking information
A prime target for credit-hungry fraudsters, who often set up fake websites to con genuine account holders into parting with their access data. Never click a link in an e-mail directing you to a supposed banking site - it could be a trap. Watch out for scam e-mails and don't click on anything from anyone you don't know
The snail mail post and mailing lists, is the most likely way that ID fraudsters would get hold of some of your personal details. The crooks' top choice of method is to forward your mail to a collection address. This was the cause of 36% of identity frauds during 2007. Check with the Post Office if your mail suddenly stops arriving
In second place, with 30% of cases, comes present address fraud, in which someone living at the same address - often flats with communal postal delivery areas - steals your mail. Previous address frauds, when the criminal uses your name and a previous address to take over your ID, account for 24 per cent of cases. Make sure your Postie knows you (I am Spartacus) and make sure your post box is secure - change the lock if you are suspicious or paranoid
Other popular cons to steal your personal details include:
- Stealing your stuff /belongings
- Tenancy fraud, where the tenant uses the landlord's details to borrow money
- Jackal fraud, when the criminal uses personal details of a dead person
- Card not present fraud, which occurs when someone has your credit or debit card details, but not the card, uses it on the internet or over the phone