Thursday, April 30, 2009

Scrapers hit social networking sites

A recent article in Windows Secrets newsletter, "Viral inviters want your email contact list", stated, "The arms race between the script builders and big-name Web services is just beginning. The massive data collections that the scrapers are able to accumulate are simply too valuable to pass up.

The problem will only get worse as social-networking sites create linked systems. For example, the Facebook Connect service that launched last year allows members to use their Facebook account to sign in to hundreds of third-party sites, such as CNET and MoveOn.org."

Unfortunately, too many people are lured by friends and acquaintances that tell them, that having a Facebook page makes them "cool". But they don't tell them (perhaps because they don't know or don't believe) about the pitfalls, the need for locked down tight security, the need to keep data you share to an absolute minimum, and the real need to be skeptical of emails you get.

Criminals can only flourish in such a naively trusting environment. Here's hoping that future tightening of the world's email system underpinnings will reduce the ability of Spammers and other Criminals to pretend to be a "friend" and sucker people into hurting themselves.

Monday, April 20, 2009

First Mac botnet found

Researchers have found malware in pirated copies of Apple's iWork ’09 and Adobe Photoshop CS4. What's worse, the malware has created the first botnet for Macs.

The Mac OS has been overdue for malware attention by hackers and "safe" only due to much lower market share than IBM-clone PCs. Mac users can expect to see more such attacks.

Friday, April 03, 2009

Beware Antivirus 2009

Beware of fake antivirus software. And beware of a pop-up notice that you have a virus or "might have" a virus (unless the pop-up notice comes from software you already own).

A type of software that tricks you into installing it, then demands payment "or else" is called ransomware. And it's spreading.

One nasty piece of ransomeware seems to be a legitimate program called Antivirus2009. But after you install the software, it encrypts several document types. Then when you try to open one of the encrypted files, it pops up an alert and offers to sell you FileFix Pro 2009, which it says can decrypt the file.

So you get duped into downloading the fix. But it decrypts only one document. After that, it demands that you pay $50 to buy the software to decrypt the rest of your files (that the Antivirus 2009 encrypted).

Beware of "something for nothing". Be paranoid. Check out reviews of software at trusted sites before you download and install any.

Wednesday, April 01, 2009

Protect your personal information

A PC World test found that some search sites had random details about co-workers' and acquaintances' college roommates and boyfriends from the 1980s, political donations, shopping preferences and musical tastes.

Social networking sites give a false sense of security and if left "open" to all can result in a lot of personal information being harvested (sometimes called "scraped") by criminals.

A recent Symantec study showed that 91% of Phishing attempts are now aimed at social networking sites (the top two are My Space and Facebook). Why? The personal data is there for easy pickings. Plus, people who join social networking sites tend to feel more "free" in their personal comments.

Another disturbing tidbit ... 23% of people succumb (are tricked by) social engineering attemps via Phishing emails. At a recent Information Security conference, a speaker admitted that he had been a victim too. His daughter had joined Facebook, soon had 300 "friends" (right!) and then her got an email from "his daughter" with a link to something neat "she" wanted him to check out. He did. His computer got attacked. The problem? Too trusting. Bad assumptions.

People get tempted to take risky actions when using social networking sites. Human nature plus the very essence of a social networking site make using it risky.

How much is your identity worth? Is is humany possible to not be a social networking lemming? Just say, "No" to joining social networking sites. You'll live to rejoice in that decision.

Thursday, March 26, 2009

IE8 is gr8

I installed the newly released IE 8 and am already liking the enhancements.
  • Web Accelerators looks like something I'll use a lot, for example:http://www.microsoft.com/windows/internet-explorer/videos.aspx?mname=accelerators
  • Automatic Crash Recovery (tab closes, not all of IE).
  • Web Slices.
  • Faster page display.
  • Better pro-active built-in security (domain highlighting, SmartScreen filter -- sites ID'd with Spyware or PII collection get a pop-up warning [I assume it uses a database, so frequent updating is hopefully provided].
  • InPrivate browsing, easier data deletion/cleanup.
  • Compatibility mode for pages coded for older browsers (with compatibility updates pulled from MS as available).
  • Love the grouped, suggested URLs as you start typing in the address bar.
  • Oooo ... a "Read mail" toolbar icon automatically opened my Thunderbird email.

Next I'll have to see if FireFox 3.5 will match or beat that. As of now, IE8 is my preferred browser experience.

Saturday, March 21, 2009

Does that email pass the smell test?

We get lots of email messages every day. How do you tell what's a fake (and likely to try to hurt you) and what's not? Carnegie Mellon's Software Engineering Institute produced a set of checks that are still valid. It's the KREVS "test".
  • The Know test. Do you already know the sender?
  • The Received test. Have you received safe emails from the sender before?
  • The Expect test. If the email has an attachment, were you expecting to get it?
  • The Virus test. Does the message pass a virus-check? (Make sure your Antivirus program also checks your email messages).
  • The Sense test. Does it look right? Are there unexpected misspellings? Does it "smell" in any way?

If an email messages fails any of the above tests, delete it. Even if an email messages passes all 5 tests above, it still might be malicious. Be paranoid; the "bad guys" really are out to get you. Criminal attack attempts using email are increasing rapidly.

If the email is from a person you already know, still be careful. Call them and see if they really sent any unexpected attachment.

Wednesday, February 04, 2009

Malware worms its way into social networking

Social network site users tend to be more trusting than they should be about emails from "friends". They seem to assume that since they have to login to the account that messages from others are "safe". Criminals know that.

So with increasingly sophisticated social engineering, criminals are successfully attacking social networking services. Angry Facebook members created a special facebook page for victims of the Koobface worm.

Malicious software "scrapes" Facebook for all the user data it can find. People who give out real names, addresses, email addresses, and other information may find it cropping up in the hands of criminals. We teach kids to be wary of strangers, but then we turn around are and much too trusting in our online behavior ourselves. Parents, schools, and churches all need to start educating kids and even other adults about being wary of online personas and of being careful not to release personal information. Criminals now "mine" data from multiple sites to "fill in the picture" about victims identities and personal information.

Government agencies normally let their employees do personal surfing, yet they are starting to block access from the government offices to social networking sites. Why? It just too unsafe, at least for now.

Part of the challenge is that in order for social networking sites to be "fun", they have to encourage their members to share information. The default for most social networking sites is to be "open" rather than to have tight security. And most people are much more gullible online than in the "real world". So social networking sites like FaceBook and MySpace may continue to be a rich feeding ground for criminals.

If you insist on risking use of a social networking site, it might be a good idea to subscribe to a service that tracks your credit card actions as well as actions taken that relate to your credit rating. For example, you'd get an alert if someone was applying for a loan or credit card and using your credit record. And make sure to keep your Antivirus, AntiSpyware, and Firewall software up to date. You might also want to add prayer to the list. You may need it.

Wednesday, January 28, 2009

Be paranoid!

Be very wary of emails you did not expect to get and of any web pages they may link to. Just because an email or web page looks nice or is interesting or you are just plain curious is no reason to start clicking away.

A case in point is the recent malware that pretends to be about President Obama (or for you Irish folks, O'Bama). The Microsoft Malware Protection Center (MMPC) blog has more about this Waledac Trojan, including pictures of an email and the malicious web page.

Remember, it's perfectly OK to be paranoid -- the bad guys really out to get you!

Saturday, December 20, 2008

Infected web pages increase

During 2008, the rate at which the number of web pages infected with malicious software (malware) increased rose from one every 14 seconds to one ever 4.5 seconds. [See "Forecast: Security Threats for 2009"]

So what can you do?

  • Don't "assume" a web site is safe to visit.
  • Don't "assume" a link in an email is safe to click on.
  • Don't "assume" an email from a friend was really sent by them.
  • Use anti-phishing software, antivirus software, and anti-spam software.
  • Keep all your computer programs updated. If there is a security patch available for any of your programs, install the patch.
  • Use a program like Secunia's free Personal Software Inspector to check for program updates.
  • Use a program like Driver Detective to check for updates to program driver files.

Firefox less secure?

Firefox has often been touted as fundamentally "more secure" than Internet Explorer. If you have been led to believe that, you need to look at some cold, hard facts:
  • From March to September 2005 (yes, even as early as 2005), FireFox had 40 vulnerabilities to IE's 10. [ZDNet article]
  • From April through September 2005, the number of published Firefox exploits was 11 compared to IE's 6.
  • The most recent FireFox-related security problem is that some Russian criminals are using it to add malicious software as a "Plug-In". The malware detects when you connect to any of over 100 banks and then steals your account name and password, sending them to the criminals. [read the SC Magazine article]
  • In terms of vulnerability numbers reported in March 2008, Opera had the most, followed by Safari, FireFox, then Internet Explorer.

The biggest problem with malware is not the browser, it's the person using the browser. People are either too trusting of links and unknown sites or just think they will never get attacked.