Showing posts with label SOCIAL ENGINEERING. Show all posts
Showing posts with label SOCIAL ENGINEERING. Show all posts

Monday, May 14, 2012

It does not matter what O/S you use when it comes to malware

Now that the Apple people got a reality check on how secure their O/S really was when they got hit with flashback.  We all may want to think about securing our machines.  It does not matter what O/S you run, we call can have our machine taken over by malware.  A few things that we all should be doing to at least slow down and make the lives of malware authors a bit harder:

  • Keep your machines up-to-date by applying patches when they are available.
  • Never open attachments from people you don't know and be skeptical about attachments when you get one from someone you know and you didn't ask for that file.  
    • Assume that senders are not as vigilant and check with them before opening.
    • Assume that the from account name was forged.
  • Never believe a popup window in your browser stating your software is out-of-date and install the update via that convenient link.
  • Never believe those popups or messages while browsing that they scanned your system and you are (or could be) infected.  
  • Never run an account with admin priviliges.  Create a simple user account that cannot add, change or delete programs.
  • Do regular backups of your files.  External USB hard drives are inexpensive.  When you are done remove the backup and do not leave it connected all of the time to your machines.  If you do get malware at least you have a chance that the backup is still clean.
  • Use a simple firewall on your computer at a minimum.  
  • If your router has the option to enable a firewall then use that firewall too.
  • Assume that your machine will get taken over and make plans on how you will rebuild your system and recover your documents.
  • Install, use and keep up-to-date an anti-virus package and scan on a regular basis.  It really does not matter now what O/S you use, assume malware writers can take over your machine.
  • If someone hands you a CD, DVD, USB Memory stick or USB drive scan it before doing anything else.  Never assume that the media is clean.
At home every machine is running A-V software (for windows I like AVG as it gives good protect, fast running and not a resource hog).

I assume that sooner or later one or more of my computers at home will get infected and I will have to wipe and rebuild the system(s).  I do run backups on all of the machines so while I may lose some recent documents or email it won't be a total loss.

Saturday, June 20, 2009

New Phishing scam - CRA

Earlier this week I got a mail from what purported to be the CRA (Canada Revenue Agency). Looking at the email I saw a grammar error and the way the email was addressed made it look like a scam. My ISP also flagged it as a possible scam. I didn't click on the attached link, but, put my mouse over it to see what the link would resolve to. The proper URL for the CRA is WWW.CRA-ARC.GC.CA. This one had that and a bit more, namely the URL went to a '.COM' site. As this was a new scam to me I forwarded the note to RECOL and reported it as a scam/phishing attempt.

It failed on a few areas:
  • Subject was 'recalculation of you tax refund'. They used 'you' instead of 'your'
  • It was addressed to 'Dear Applicant' rather than my proper name.
  • The URL provided did not end in GC.CA, but, to a COM site which the Government of Canada does not use.
  • I had already got my tax refund and I know that the CRA does not have my main email address for correspondence as I prefer hard-copy rather than email from them.
When I got home I opened the site using Linux as it was fairly safe from trojans and viruses. It asked the following questions:
  • Name and Adress
  • Date of Birth
  • Mother's maiden name
  • Phone number
  • email address
One of the first things firefox did was to warn me that this was a site reported for web forgery. If you don't have firefox I would advise you to download and install this browser ASAP as it is a second level of defense.

Again, if you get an email that claims to be from the government, bank, insurance company or anyone else asking you to key in personal information do not ever use the attached URL, go to their site yourself (using a link you know is legit).

Sunday, October 19, 2008

Another scam/spam

My wife received an email last week that purported to be from United Airlines. Even though we run Linux she didn't want to open it up until I had a chance to check it out.

The subject line was [Your Online Flight Ticket N 24097] and the contents of the message was as follows:
Good day,
Thank you for using our new service "Buy airplane ticket Online" on our website.
Your account has been created:

Your login: **Removed**
Your password: **removed**

Your credit card has been charged for $947.90.
We would like to remind you that whenever you order tickets on our website you get a discount of 10%!
Attached to this message is the purchase Invoice and the airplane ticket.
To use your ticket, simply print it on a color printed, and you are set to take off for the journey!

Kind regards,
United Airlines
The first thing I did was to check our credit card to make sure that we were not the victims of identity theft, fortunately we are not. I then checked the file attachment and it showed 'E-ticket.zip.exe'. I checked out via Google about this and found out that there is a scam for the last year with variants on the subject for other airlines. Fortunately we don't use windows so we are fairly safe from the payload. I forwared a note to United Airlines and to quote their reply:
Mr. Traynor, please know that the e-mail you have received is not legitimate as it is not sent by United Airlines.  I would request you to not to open any attachment and provide any personal information.  Rest assured that I have forwarded your concern to our Fraud Investigation Department for their review and investigation.

We truly value your business and always look forward to serving you again
Just a heads up for everyone when you receive something like this not to open the attached file if you are not sure that you are the correct recipient. I would assume that the people behind this are hoping that people are curious enough to open the package and then take over their machines. I also like the fact that United Airlines replied so quickly that the email was not legit and forwarded a copy to their fraud department.



Update - 2008/12/15

CERT has a security notice about this, you can learn more about this scam by clicking on airline ticket email scam.