Showing posts with label phishing. Show all posts
Showing posts with label phishing. Show all posts

Wednesday, November 13, 2013

Security tips of the Day

A shield with Microsoft Office colors in its quadrants
The international SANS organization offers excellent "Security Awareness Tip of the Day" posts. You can subscribe to them (an RSS feed) if you like. Some have links to more information. A few recent topics:
  • E-mail is insecure by default
  • Turn off your wireless AP when it's not in use
  • Don't accept offers for "Free PC Scans" that pop up
  • Avoid Spam in your IM email account
  • Don't let Spammers see your out-of-office replies
  • Four tips to keep your computer secure

Saturday, November 09, 2013

Fun games foster security awareness

Phishing Scams - avoid the bait
The U.S. government has a great site to learn more about being smart and safe online. It's called OnGuard Online. The site includes some simple online games that let you check your "smarts" about safe computing.

You may learn something new or maybe just reinforce good habits. Either way, visit the site.

Below are links to some interactive video quizzes:

Thursday, April 30, 2009

Scrapers hit social networking sites

A recent article in Windows Secrets newsletter, "Viral inviters want your email contact list", stated, "The arms race between the script builders and big-name Web services is just beginning. The massive data collections that the scrapers are able to accumulate are simply too valuable to pass up.

The problem will only get worse as social-networking sites create linked systems. For example, the Facebook Connect service that launched last year allows members to use their Facebook account to sign in to hundreds of third-party sites, such as CNET and MoveOn.org."

Unfortunately, too many people are lured by friends and acquaintances that tell them, that having a Facebook page makes them "cool". But they don't tell them (perhaps because they don't know or don't believe) about the pitfalls, the need for locked down tight security, the need to keep data you share to an absolute minimum, and the real need to be skeptical of emails you get.

Criminals can only flourish in such a naively trusting environment. Here's hoping that future tightening of the world's email system underpinnings will reduce the ability of Spammers and other Criminals to pretend to be a "friend" and sucker people into hurting themselves.

Saturday, March 21, 2009

Does that email pass the smell test?

We get lots of email messages every day. How do you tell what's a fake (and likely to try to hurt you) and what's not? Carnegie Mellon's Software Engineering Institute produced a set of checks that are still valid. It's the KREVS "test".
  • The Know test. Do you already know the sender?
  • The Received test. Have you received safe emails from the sender before?
  • The Expect test. If the email has an attachment, were you expecting to get it?
  • The Virus test. Does the message pass a virus-check? (Make sure your Antivirus program also checks your email messages).
  • The Sense test. Does it look right? Are there unexpected misspellings? Does it "smell" in any way?

If an email messages fails any of the above tests, delete it. Even if an email messages passes all 5 tests above, it still might be malicious. Be paranoid; the "bad guys" really are out to get you. Criminal attack attempts using email are increasing rapidly.

If the email is from a person you already know, still be careful. Call them and see if they really sent any unexpected attachment.

Friday, December 28, 2007

Scammers target eBay names

Anti-scammer tips:

  • Use a different name on eBay than on your webmail. Scammers target an email name on gmail, hotmail, and similar online webmail apps.
  • If it sounds too good to be true, it's not true.

- Based on a blurb in the December 28th SANS emailed newsletter (not online yet). You can subscribe to get security "NewsBites" by email.