Showing posts with label cybercrime. Show all posts
Showing posts with label cybercrime. Show all posts

Tuesday, September 16, 2008

Improved OnGuardOnLine Site Teaches Cyber Safety to the Average Person



One of the better places for the average person to learn about the sometimes murky waters of the Internet is free and sponsored by the Federal Trade Commission. Although OnGuardOnline.gov and AlertaEnLinea.gov, its Spanish-language counterpart have been around for awhile -- some new and exciting improvements have been made to the site with a just released Web 2.0 redesign.

The new and improved site allows users to grab and embed games and videos, search for topics on the site, take a “show of hands” poll, and have a more interactive experience while learning how to avoid becoming an Internet crime statistic.

Articles and games covering sixteen topics -- including social networking, phishing, email scams and laptop security; plenty of buttons and banners you can post on your blog or website; free publications consumers and organizations can order; and links to the OnGuard Online partners from the public and private sector.

I should add that a lot of good people from both the government and private sectors have given resources and their valuable time to assist the Federal Trade Commission with this site. Industry and government partners -- include the U.S. Department of Justice, Office of Justice Programs, Department of Homeland Security, Internal Revenue Service, United States Postal Inspection Service, Department of Commerce, Technology Administration, Securities and Exchange Commission, National Cyber Security Alliance, Anti-Phishing Working Group, i-SAFE, AARP, National Consumers League, Direct Marketing Association, WiredSafety.org, The SANS Institute, The National Association of Attorneys General, Better Business Bureau, NetFamilyNews, CompTIA, National Crime Prevention Council, Association of College Unions International, and the Latinos in Information Sciences and Technology Association.

In my opinion, this represents a valuable partnership in dealing with the ever growing problem of crime on the Internet. This also represents a very credible collaboration of resources and industry experts (my humble opinion).

There is also a lot of material that businesses and organizations can use to educate their people with. Frequently, I get approached on this subject and I will continue to recommend this site as a valuable resource. Of course, the benefits for the individual person wanting to protect themselves, or become more knowledgeable are there (free for the taking), also.

If you are one of those businesses or organizations wanting additional matertials, you can get free OnGuard Online publications. For 50 or more copies, visit ftc.gov/bulkorder. If you need less than 50 copies, call 1-877-FTC-HELP.

Sunday, August 24, 2008

How to buySAFE on the Internet


(Courtesy of buySAFE)

The Center for American Progress and the Center for Democracy and Technology recently released a report concluding that not enough is being done to protect the public from fraud on the Internet. "If problems such as malware, phishing, and spam are left unchecked, many consumers may lose trust and abandon e-commerce," according to the report.

What if a shopper could safely enjoy the convenience, lower prices and choices offered by the world of e-commerce, while avoiding all the fraud lurking on the Internet free?

In 2006, buySAFE entered the e-commerce scene with a unique concept, giving sellers the ability to become bonded and display the buySAFE seal on their site. Once a seller is bonded, the purchase is guaranteed up to $25,000.

The buySAFE guarantee covers virtually any loss that might occur during an online shopping transaction. This includes, but isn't necessarily limited to fraud, phishing and financial misdeeds.

Last month, they grew their concept with the buySAFE Shopping Advisor, which is a free software tool that rates the safety/security of all sites within a search term. The tool also points to sites sites with the buySAFE seal, which guarantees the transaction.

Shopping Advisor leverages buySAFE’s advanced technology and bonded merchant customer base to provide a fully closed-loop safe shopping experience. "There is nothing else like it in the world as it provides comprehensive safe shopping for consumers from search through purchase and beyond – guaranteed," according to Jeff Grass, buySAFE's CEO.

While buySAFE offers a free service to the e-consumer, they aren't in business to lose money. Some of the due diligence performed on every bonded merchant includes ensuring they have a SSL certificate and a privacy policy describing how they protect personal information. Additionally, bonded sellers are required to allow buySAFE access to inspect their business anytime they choose to do so.

Shopping Advisor provides a tool to analyze e-commerce sites and provides a safe shopping portal, which consists of bonded sellers, only. Once in the safe shopping portal every purchase is guaranteed within the limits of the bond buySAFE provides.

Shopping Advisor uses buySAFE's proprietary website inspection and assessment technology to analyze almost 100 different safety/security attributes of an e-commerce site. It then provides objective ratings on the site when searching with Google, Yahoo and MSN (Firefox is on the way). This allows the shopper to make an informed decision before forking over their hard-earned cash.

Within the Shopping Advisor tool is the Safe Shopping Portal providing alternative product choices from thousands of merchants that are protected with the buySAFE seal. It is within the Safe Shopping Portal that every purchase is guaranteed with a Bond of up to $25,000 and it's protected against identity theft, also.

Essentially, Shopping Advisor shows all the shopping opportunities for the search term listed, rates the sites in question and then gives the consumer the ability to make an informed buying decision. If the buyer chooses to buy a product via the Safe Shopping Portal, it is automatically guaranteed and the transaction is protected against identity theft for 30 days. When the buyer purchases an item from the Safe Shopping Portal, they automatically receive an e-mail with the specifics on the guarantee for their personal records.

buySAFE offers a lot of benefits to sellers, also. The biggest is which is what ensures any successful business, or the trust of it's customers. They've also added a cost-per-sale pricing model that has received positive feedback from the merchants using it. If a merchant needs more information on this, I'll refer them to Jeff Grass' blog, or the press release on this matter.

According to most if not all of the reports out there, Internet crime continues to grow and become more sophisticated. Saying that, no matter how sophisticated it becomes the primary motivation to commit cybercrime is money. This rings true from the most simple social engineering scheme to most sophisticated attacks using crimeware. What buySAFE has done is remove this primary motivator from the mix, or at least made it a lot less attractive to Internet fraudsters, charlatans and tricksters.

Shopping Advisor
takes this concept to the next level by providing the consumer with a tool to make an educated shopping decision without falling prey to the pitfalls of a too good be true come-on. Too good to be true lures are the common theme Internet fraudsters, charlatans and tricksters use to snare their prey. In other words, Shopping Advisor is a tool a consumer can effectively use to practice the principle known as caveat emptor, or buyer beware.

buySAFE is also offering a shopper referral program. They pay $1.00 for every user referred to Shopping Advisor. This is a great fundraiser opportunity for charities, sports leagues, churches or any good cause.

Monday, August 18, 2008

Report Reveals That Internet Fraud Threatens E-Commerce

The Center for American Progress just released a report indicating that not enough is being done to protect the public from fraud on the Internet. It's also warning that the convenience, choices and lower prices enjoyed by Internet users are at risk because of this.

They report reveals that high levels of fraud and abuse may cause more and more consumers to lose trust, a key-component of any successful business. Malicious software, phishing and spam were cited as primary causes for the high levels of fraud and abuse on the Internet.

Studies indicate that over 80 percent of all e-mail is spam. It should be noted that spam is the preferred delivery vehicle of fraud and abuse on the Internet. Malware and phishing normally start with a spam e-mail. In Phishing schemes -- which are designed to steal personal and financial information -- the use of malicious software to automatically steal information is on the rise. In the past, phishing normally relied on a social engineering scheme to accomplish this goal.

The Anti Phishing Working Group, an organization that tracks phishing activity, has noted an increase in the use of malicious software to phish information. They speculate that ability of e-criminals to use automated tools to spread crimeware (a.k.a. malware) could be the reason for the increase.

The report states that although the Federal Trade Commission is stepping up enforcement activity, it's resources are limited and more action by the State attorney generals is desperately needed. It cites as an example that over the past three years, only 11 cases against spyware distributors have been brought forward by the States, which is the same number taken for action by the FTC.

The Center for American Progress and the Center for Democracy and Technology asked States to provide data on the complaints they received 2006 and 2007. Thirty six States responded and most of them had a Internet related category listed in their top-ten complaints. It was also noted that overall Internet related complaints increased from 2006 to 2007. Eight of the States listed Internet related complaints in their top-three and four States listed them as being the number-one complaint.

The FTC, who gathers data on a much wider scale noted an increase of 16,000 Internet related complaints in 2007 versus the number received in 2006. When comparing the numbers to 2005, a 24,000 increase in complaints was noted.

The report points out that many experts speculate that not all cybercrime is reported or even discovered. Additionally, the standard for classifying it varies from State to State, which makes it hard to evaluate current statistical data. Given these factors, many believe the problem is understated.

In looking at the enforcement level by the States, the Center for American Progress and the Center for Democracy and Technology gathered information from annual and biennial reports, websites, news articles, and the bimonthly Cybercrime Newsletter released by the National Association of Attorneys General.

Data from the Cybercrime Newsletter revealed that 60 percent of the cases prosecuted were for the sexual enticement of minors or pornography. Crimes involving the theft of information or identity theft represented 8.9 percent of the total and 15.5 percent involved online sales and services. The majority of the cases involving online sales and services were for false advertising or the quality of a product or service.

The conclusion given by the researchers is that not very many crimes involving phishing, spyware, spam, adware and hacking were being effectively investigated or prosecuted. "Internet crime requires almost no expense to execute, carries potentially high financial rewards, and involves relatively little risk of being caught and punished," according to the report.

The monetary cost of all this activity isn't cheap, either. In 2007, an estimated $7.1 billion was lost due to phishing, viruses and malware in the United States, alone. Given that the estimated losses in 2006 was a mere $2 billion, this would lead a reasonable person to speculate that the problem is a growing one. Worldwide estimates put the losses at about $100 billion.

The report gives a possible reason for the increase in activity. With few overhead or start-up costs a phishing group can net about $250,000 a month and operate anonymously from just about anywhere in the world.

Do it yourself (DIY) phishing kits for sale on the Internet have been cited as a primary cause of more and more activity, also. Some of these DIY kits even come with technical support. The bottom line is that it no longer takes much technical knowledge to become a phisherman.

The report speculates that we shouldn't be surprised that online fraud and abuse are at high levels and calls for stronger deterrents. They believe that stronger action by the state attorneys general is key to this effort.

While more support at the State level is needed, I'm not sure if the States can control Internet crime all by themselves. Internet crime moves across borders with a click of a mouse and it's going to be difficult for Alabama to prosecute a spammer or phisherman living in Moscow, Shanghai, Montreal or London.

Two so-called spam kings were recently prosecuted by the federal government. One later escaped and killed himself and family members in the process. These arrests didn't seem to make much of a dent in the amount of spam being sent. Both of the government press releases on these stories mentioned they were catering to commercial clients. Any solution to crime on the Internet will have to take a long and hard look at what enables the activity to be too easy to facilitate in the first place.

Some blame the Internet Service Providers (which seem to be a dime a dozen) for looking the other way because spam brings in revenue for them. Of course, auction sites like eBay have long been criticized for looking the other way at the the criminal activity on their sites. Since Internet Service Providers and Auction sites operate worldwide with a click of the mouse, it's difficult to prosecute or investigate anything on the Internet.

This list of Internet crime enablers is long and the one's referenced regarding service providers and auction sites are merely two examples of them. But if you were to take a look at all them, they have one thing in common: which is maintaining an environment conducive to making money easily. The question is how long will it take for the financial and social costs of Internet fraud and abuse to inspire a more responsible and practical approach to the problem?

Saturday, May 24, 2008

International Phishing Gang, nailed with a little teamwork!

I suppose it's big news when a phishing gang gets caught. Sadly, few of them ever seem to get nabbed, or prosecuted. Phishing is a crime that is committed across borders with the click of a mouse, or "bot," which makes investigating and prosecuting this type of crime, slightly challenging.

Saying that, the times might be changing, especially (more and more) when U.S. citizens are targeted. Besides this latest series of arrests, the FBI recently conducted a very successful operation against bot-herders in an effort dubbed "Operation Bot Roast."

Bot-herders, who run botnets are behind growing amounts of spam. Spam is the preferred method of spreading scams and other questionable activity across cyberspace.

According to the DOJ press release, 33 phishermen have been hooked, in an operation that was truly International in nature:

A federal grand jury in Los Angeles charged 33 individuals in a 65-count indictment unsealed today for their alleged participation in an international racketeering scheme that used the Internet to defraud thousands of individual victims and hundreds of financial institutions. Seven individuals were charged in a District of Connecticut indictment for their roles in an Internet phishing scheme, including two who were also charged in the Los Angeles case.

U.S. law enforcement authorities are executing nine arrest warrants in the Los Angeles area and Romanian law enforcement authorities are executing search warrants in Romania today in connection with the racketeering indictment.
Supporting the "global theory" of this activity, these phishermen operated from six different countries. They also claimed citizenship from several different countries:

The individuals named in the indictment operated from locations in the United States and abroad including Canada, Pakistan, Portugal and Romania, and include both U.S. citizens and foreign nationals. Sonny Duc Vo, Alex Chung Luong and Leonard Gonzales are U.S. citizens. Nga Ngo, Thai Hoang Nguyen, Loi Tan Dang and Dung Phan are permanent legal residents of Vietnam. Hiep Thanh Tran is a U.S. permanent resident from Vietnam. Caroline Tath is a permanent legal resident of Cambodia. Hassan Parvez is a citizen of Pakistan. Rolando Soriano is a Mexican citizen and is currently charged in Los Angeles with illegal entry by an alien following deportation. Ovidiu Ionut Nicola-Roman; Petru Bogdan Belbita; Stefan Sorin Ilinca; Sorin Alin Panait; Costel Bulugea; Nicolae Dragos Draghici; Florin Georgel Spiru; Marian Daniel Ciulean; Irinel Nicusor Stancu; Didi Gabriel Constantin; Mihai Draghici; Marius Sorin Tomescu; Lucian Zamfirache; Laurentiu Cristian Busca; Dan Ionescu; Marius Lnu; Alex Gabriel Paralescu; and Andreea Nicoleta Stancuta are Romanian citizens. An additional four individuals known only by their aliases, “Cryptmaster”; “PaulXSS”; “euro_pin_atm” and “SeleQtor” are believed to be Romanian citizens.

According to an article in PC World by John E. Dunn, stolen financial details (mostly payment card numbers) were stolen using a fake website. The stolen financial details were then sent via SMS (text) messaging to their cohorts in the United States and counterfeit payment (credit/debit) cards were produced.

After the counterfeit cards were produced, we can assume "runners" went to ATM machines and drained the accounts.

Financial institutions targeted included "People’s Bank, Citibank, Capital One, JPMorgan Chase & Co., Comerica Bank, Wells Fargo & Co., and PayPal," according to the DOJ press release. Although, not a financial institution, the DOJ press release mentioned eBay was a phishing target, also.

Two good resources, largely from the private sector that study phishing and provide a lot of relevant information about the activity are the Anti-Phishing Working Group and Artists Against 419. Besides goverment resources, there are private warriors out there dedicated to taking down phishing sites, also. The PIRT Phishing Incident Reporting and Termination Squad run by CastleCops, a site dedicated to computer and internet security, is a leader in this private effort to curb phishing. PIRT goes after phishing as it occurs in the "wild," or on the Internet.

Most of the information gathered by these groups is provided and used as intelligence by law enforcement resources. As a disclaimer, in this case, it is unknown what private resources might have contributed intelligence to this effort.

Law enforcement resources on a local, national and international level contributed to this latest series of arrests. Most experts agree that cybercrime has flourished in the past because of the inability of members of the "white side of the fence" to come together as a team. Sadly, the members of the "black side of the fence" have seemed to embrace teamwork and the result has been devastating, to say the least.

Last month, Attorney General Mukasey announced a "Law Enforcement Strategy to Combat International Organized Crime." This strategy was developed to combat a growing threat to the stability of U.S. interests posed by organized crime groups.

DOJ press release, here.

Wednesday, April 16, 2008

Corporate suits targeted in spear phishing attack!

The mainstream media is reporting that the Phishermen attempted to spear a large number of corporate executive types this week.

This form of phishing is referred to as spear phishing, or whaling. The intent of phishing is to trick an unwary human being into giving up sensitive personal or financial information, which is later used to for illicit purposes. Spear phishing or whaling is simply a more focused approach designed to target more specific targets than everyday run of the mill phishing attacks, which are sent out by the millions via spam spewing botnets.

The New York Times is reporting:

Thousands of high-ranking executives across the country have been receiving e-mail messages this week that appear to be official subpoenas from the United States District Court in San Diego. Each message includes the executive’s name, company and phone number, and commands the recipient to appear before a grand jury in a civil case.

If any of them clicked on the link directing them to a view of the full subpoena, they probably downloaded malicious software with keylogging capabilities. Once this is dropped on a system, keystrokes are recorded and transmitted back to the criminals behind the attack.

The normal intent when this done is to commit financial crime, but given the targets in this attack, corporate espionage (information theft) could be the intention, also.

The malware bundle allegedly places the victim's computer under the control of the phishermen. When this occurs, the infected computer is often referred to as a zombie.

The latest attack has prompted warnings to be placed on the websites of two California Federal Courts, as well as, the administrative office of the United States Courts.

The New York Times article speculated that this attack was of Chinese origin, while Brian Kreb's article in the Washington Post speculated the attack could be of Romanian origin. Both of these speculations came from noted industry security experts. Unfortunately in the world of cybercrime, the activity often so anonymous, all the rest of us can do is speculate as to who might actually be behind it.

Please note that speculating that the activity might have come from either China or Romania is probably a good deduction. Both countries are known to host a lot of criminal activity of a cyber nature.

It is also being reported that not all the security products out there will detect this attack.

I guess that the only solace from this fact is that if you can teach the user to recognize the social engineering aspects of these attacks, they aren't going to click on the link and infect their system.

Even though "fear" is well-known social engineering technique, if you examine the attack it doesn't make very much sense. After all, the last time I checked, a subpoena delivered via electronic communication wouldn't be legally binding. It's probably a no-brainer that federal courts wouldn't issue a subpoena via an e-mail.

Sadly, more employees fall for phishing attempts than many might realize. In fact, some organizations are now testing their own employees with scary results. Most recently, this was done by both the U.S. Army and the IRS.

Update 4/19/08: The FBI announced that a new phishy e-mail is circulating regarding a grand jury summons. Not sure if this is a tie in, but as Alex Eckelberry lamented on the Sunbelt blog -- phishing attacks are becoming more specifically targeted and the intent might be more than to steal financial information. Of course, that's not to say there isn't financial motivation involved, there normally is.

Monday, February 25, 2008

Australian Competition and Consumer Commission releases the little black book of scams



I normally write with an emphasis on what is going on in North America, but in the digital world a scam can travel thousands of miles with a click of a mouse, or probably more frequently a "bot."

Most of the scams I see don't vary much from country to country.

Ran into this interesting educational tool provided by the Australian Competition and Consumer Commission on how to identify and not fall victim of fraudsters a.k.a. scammers. After reading it, I found a lot of great information in here that is a worthwhile read for anyone interested in the wide variety of scams that are out there.

In their own words:

The little black book of scams highlights a variety of popular scams that regularly target Australian consumers and small business in areas such as fake lotteries, internet shopping, mobile phones, online banking, employment and investment opportunities. It also offers consumers tips on how to protect themselves from scams, what they can do to minimise damage if they do get scammed and how they can report a scam.

The entire book can be downloaded free of charge, here.

Saturday, January 19, 2008

January Symantec Report reveals questionable blogs, polls and Nigerian Scam restitution schemes

If you ever want to know what criminals and other misfits are up to on the Internet, watching spam traffic can reveal a few clues.

After all, spam is the vehicle most cybercriminals use to pass along whatever scheme they are behind designed to part people with their hard-earned money.

Symantec noted in December that close to 75 percent of all e-mail being sent is spam.

A little over a week ago, they issued their January report, which showed spam levels peaking towards the end of December to 83 percent.

Highlights noted in the January report are:

Holiday Spam Spikes: Spam levels reached new levels as spammers inserted holiday-oriented keywords into everything from subject lines to images.

Spammers Get Honest? Not So Fast: Spammers tried a new twist on an old scam, falsely promising past spam victims restitution of $100,000.

As Oil Prices Hike, Spammers Strike: This new spam claims to identify gas stations that fraudulently tamper with pump prices.

Not-So-Happy New Year: Recipients were invited to download a fun New Year’s song and dance, but instead found themselves downloading something far more malicious.

Presidential Polling Scam: Promising gift cards in exchange for opinions, spammers leverage the US presidential primaries to collect personal information.

Beware of Blogs: The use of blogs within spams appears to be on the rise, particularly in China where simplified character sets are common.
I found the 419 restitution activity interesting. In case you've never heard the term "419," it is the penal code in Nigeria for the infamous Advance Fee scam.

Here is what the report said:

419 spammers who have traditionally used stories about African dictators to defraud individuals have recently changed their approach to these types of emails. Certain 419 scams observed by Symantec this month claim to offer compensation to victims of 419 scams. The scam states that payments will be supervised by UN officials and about 150 scam victims will be paid compensation of $100,000 each. It provides some URL links as a reference to money that was successfully recovered by 419 scam victims. At the bottom of the email, it explains how the money may be recovered and the fraudulent background of such emails may be observed.

Interestingly enough, the Economic and Financial Crimes Commission (EFCC)of Nigeria has made real victims whole with funds seized from 419 scammers. You can see some real examples of this on their site.

The most recent time, I've mentioned the EFCC on this blog is when they were part of an International task force that intercepted large quantities of counterfeit checks at post offices in several countries. These counterfeit checks are normally used in advance fee scams, where people are tricked into cashing them and wiring the proceeds back to the criminal(s) sending them.

This led to a major press campaign and new website dedicated to educating the public about these checks called FakeChecks.org. The United States Postal Inspection Service, who worked with the EFCC on the task force, is one of the major sponsors of this site.

Most advance fee scams can be traced to a spam e-mail.

So far as the other trends noted, spammers and scammers are very adept of using what is popular or newsworthy to spread their deceit on the Internet.

It's probably not a surprise that they are taking advantage of the rise in oil prices, or political polls to lure people into their web.

If you would like to read more about this, the January report from Symantec can be read in full, here.

Thursday, November 22, 2007

Symantec predicts a flood of spam this holiday season!


dejaking posted this picture of the 2005 Symantec Christmas Party on Flickr. I wonder if they will be singing the "12 days of Christmas Spam" at this year's party. The words for this song (written by some creative Symantec types) are at the bottom of this post!

With Black Friday upon us and Cyber Monday a few days away, spammers are preparing to flood the Internet with their attempts to commit fraud, phishing and financial misdeeds.

There is no doubt that spam is the vehicle used to spread 99 percent of the scams on the Internet. From misleading advertising to outright criminal schemes, spam has become a potential threat to anyone who uses the Internet.

Just clicking on a spam link can download malicious software on your system, which can steal all your personal and financial details.

According to the National Retail Federation 39 percent of us are going to do some shopping on line. If gas prices continue to go up, we might see this number go up (my prediction).

If this occurs, this could be extremely lucrative for e-commerce merchants. Online sales are already predicted to be $26 billion this season -- up $5 billion from last year's figure of 21 billion, according to the Conference Board.

Spam is a big business that has a negative impact on the economy. The estimate of how much negative impact spam causes has reached $100 billion a year, worldwide. $35 billion of this is in the United States, according to Ferris Research.

According to Symantec -- a leading computer security company, who monitors 450 million inboxes for spam -- 71 percent of e-mail sent out is spam.

This is up from 59 percent of the e-mail sent out a year ago.

Symantec is also predicting the top lures spammers will be using to trap people in their web-of-deceit:

1. Laptops

2. Replica watches (historically the most popular online
holiday buy according to NRF)

3. Business cards (even Santa doesn’t leave home without them, at least that’s the case in the spam sample going around)

4. Male enhancement drugs (always a popular sale during the holidays)

5. MP3 Players

6. Discount software (who wants to pay hundreds of
dollars for that new Office suite for your new PC, when you can get it for $25?)

7. Free cellphones

8. Handheld video games

9. Weight loss solutions (playing right into the pending New Year’s resolutions of shedding those added holiday pounds)

10. Gift cards (from every imaginable large retailer and up to $500)
Here are Symantec's recommended Best Practices to Can Holiday Spam:

1. Protect your desktop with an up-to-date antivirus, firewall, and spam filter.

2. Do not click on, or reply to, any email that appears to be spam. Doing so could alert the spammer(s) that the user is replying from a legitimate email address (therefore, the spammer would find it worth the time to send more spam in the direction of that Inbox).

3. Never click on any link in a suspicious email. If it is felt that the sender is legitimate, contact the sender directly (not by email) to ensure the email message is also legitimate.

I would also add to make sure you only shop on legitimate websites that can be verified. One way to verify if a site is legitimate is to use TrustWatch. The site uses a color-coded system, which shows whether or not a site has been verified.

There are a lot of fake websites out there, which often appear to be real. While there is no way to be 100 percent sure because sites are sometimes hacked, it pays to be cautious.

Get Safe Online has a page on their site, which gives more detail on how to spot fake websites, here.

To end on a lighter note, the folks at Symantec seem to have changed the words to the 12 days of Christmas:

12 Days of Christmas Spam

On the first day of Christmas,
a spammer offered me
A brand new shiny PC

On the second day of Christmas,
a spammer offered me
A Rolex watch,
And a brand new shiny PC

On the third day of Christmas,
a spammer offered me
Cheesy business cards,
A Rolex watch,
And a brand new shiny PC

On the fourth day of Christmas,
a spammer offered me
H – D - TV,
Cheesy business cards,
A Rolex watch,
And a brand new shiny PC

On the fifth day of Christmas,
a spammer offered me
Vi – A – Grrrr -Ra,
H – D - TV,
Cheesy business cards,
A Rolex watch,
And a brand new shiny PC

On the sixth day of Christmas,
a spammer offered me
A pink iPod Nano,
Vi – A – Grrrr -Ra,
H – D - TV,
Cheesy business cards,
A Rolex watch,
And a brand new shiny PC

On the seventh day of Christmas,
a spammer offered me
Super chee – eap software,
A pink iPod Nano,
Vi – A – Grrrr -Ra,
H – D - TV,
Cheesy business cards,
A Rolex watch,
And a brand new shiny PC

On the eighth day of Christmas,
a spammer offered me,
A blue Razr cellphone,
Super chee - eap software
A pink iPod Nano,
Vi – A – Grrrr -Ra,
H – D - TV,
Cheesy business cards,

A Rolex watch,
And a brand new shiny PC

On the ninth day of Christmas,
a spammer offered me
Nintendo D – ee - Ses,
A blue Razr cellphone,
Super chee - eap software,
A pink iPod Nano,
Vi – A – Grrrr -Ra,
H – D - TV,
Cheesy business cards,
A Rolex watch,
And a brand new shiny PC

On the tenth day of Christmas,
a spammer offered me
A Canon camera
Nintendo D – ee - Ses,
A blue Razr cellphone,
Super chee - eap software,
A pink iPod Nano,
Vi – A – Grrrr -Ra,
H – D - TV,
Cheesy business cards,
A Rolex watch,
And a brand new shiny PC

On the eleventh day of Christmas,
a spammer offered me
The perfect weight loss drug,
A Canon camera,
Nintendo D – ee - Ses,
A blue Razr cellphone,
Super chee - eap software,
A pink iPod Nano,
Vi – A – Grrrr -Ra,
H – D - TV,
Cheesy business cards,
A Rolex watch,
And a brand new shiny PC

On the twelfth day of Christmas,
a spammer offered me
$500 gift cards
The perfect weight loss drug,
A Canon camera,
Nintendo D – ee - Ses,
A blue Razr cellphone,
Super chee - eap software,
A pink iPod Nano,
Vi – A – Grrrr -Ra,
H – D - TV,
Cheesy business cards,
A Rolex watch,
And a brand new shiny PC

Sunday, November 11, 2007

Digital gangsters can buy everything they need to commit fraud right on the Internet!

There is a lot of technology with questionable applications being sold on the Internet. Of course, this is merely my opinion, but I have my reasons for believing this.

Robert McMillan, IDG News Service wrote an INTERESTING article about spyware being sold on eBay that has questionable applications.

From his article:

Think your wife may be cheating on you? Wondering who your boss might be talking to? "Learn the truth. Spy today."

So reads an ad for "Bluetooth Spy Pro-Edition," one of nearly 200 mobile phone spyware products currently listed for sale on eBay.

The software, which costs as little as US$3.99, can be used to view photographs, messages and files on the phone, listen into phone conversations, and even make calls from the phone being spied upon.

Security experts are concerned, because while these products aren't illegal, installing them without authorization to spy on someone else most definitely is.
Of course, eBay wasn't able to be reached for comment.

In August, I did a post called, Self service stamp machines targeted by credit card thieves. When writing it, I saw a quote that some of the stolen stamps were being sold on eBay and decided to see for myself. What I found was a lot of stamps for sale for what seemed to be too good to be true prices.

To be completely fair, eBay isn't the only one selling questionable merchandise on the Internet. The problem exists on auction sites in general and there are e-commerce companies that specialize in selling devices, which are marketed specifically as tools to violate other people's privacy.

In the wrong hands, these devices can be used for more sinister purposes, also.

A good example of this is keylogging software, which is is a favorite tool of cybercriminals to steal people's personal and financial information. Keylogging software is legal and easy to purchase in a variety of places, including the Internet.

Another example, which is similar to Robert McMillan's story concerns a company called FlexiSpy. I did a post on this company, who sells technology designed to spy on Smart Phone users.

In the post, I wrote:

There is already a lot of "buzz" that mobile phones, especially those of the smarter variety will be targeted for their "information value."

A product called "FlexiSPY" is being legally sold, which allows anyone (with the money to buy it) to invade the privacy of someone, who uses a smart phone.

Despite all the controversy at the time, FlexiSpy seems to be alive and selling their product to anyone with the money to buy it.

To end this post, I will refer to the worst site of this type (my opinion) out there. Hackershomepage.com is a one stop e-commerce shop selling technology and a host of manuals that could be used to commit a host of financial crimes.

I covered this website in a post entitled:

It is no wonder why skimming (credit/debit card fraud) is becoming a nasty problem!

Here is the websites legal disclaimer:

We WILL NOT answer emails from anyone asking about illegal activities, or how to use our products for illegal activities...they will automatically be deleted. All products are designed for testing and exploring the vulnerabilities of CUSTOMER-OWNED equipment, and no illegal use is encouraged or implied. We WILL NOT knowingly sell to anyone with the intent of using our products for illegal activities or uses. It is your responsibility to check the applicable laws in your city, state, and country.

Hackershomepage.com, who has the motto "they make it we break it" is up and running at the time of this writing and boasting they've been in business for eleven years.

While there might be legitimate uses for some of this technology being marketed on the Internet, you would think at the VERY least we might want to put a few controls on who it is being sold to?

When I say some of this technology MIGHT have legitimate uses, there is also some that I can think of no legitimate use for!

Unfortunately, until laws are enacted that hold the sellers accountable, little can be done about this.

One thing to remember is that even though the sellers aren't being held accountable, the buyers will be if they are caught using them in a manner deemed to be illegal. Just because it appears easy to buy doesn't mean that using it won't land a person in a lot of trouble.

It's safe to say that we could find people in correctional institutions that could attest to this fact.

IDG News Service story (courtesy of PC World), here.

Friday, September 14, 2007

Attacks on scam fighting sites prove that they are making an impact against Internet crime!

Just got a comment on my post, Anti scammers under attack by Storm botnet from the folks at Artists Against 419 stating that their site is back up after being under a DDOS (Distributed Denial of Service) attack.

After seeing this, I ran into a good article covering the recent attacks on anti-scam sites by Erik Larkin at PC World (courtesy of InfoWorld). In the article, Eric quoted Paul Laudanski as saying:
"The criminals are in it for the money," he says. "It's a huge business for them. [But] we're in it for the feeling that we get being on the side of right."

So this assault shows that "these sites are definitely doing something right," he says, "because we've got the attention of these scammers. It gives us greater resolve."

PC World story, here.

CastleCops is a great place to learn about the sometimes murky waters of the Internet. CastleCops also runs (PIRT)-The Phishing Incident Reporting and Termination Squad, where volunteers report and take out the bad guys, who make life on the Internet a pain for the rest of us. They are always looking for volunteers to help then fry phish called "handlers," and people, who are willing to forward their phishy e-mails to them.

PIRT takes these sites down and makes sure they get reported to all the appropriate places, including law enforcement.

The Artists Against 419 state what they do on their main page:

The Internet is great, isn't it? It's a magical place, where you can buy anything you want, meet new people, find information... and lose all your money to scammers.

We've never liked that last part, so we started to fight back. Over time our art has evolved, and we now maintain the largest online repository of web sites used in internet fraud.

We offer a complete public interface for our site visitors, as well as database access through webservices which can be used for automated retrieval of fake bank entries. Web browser toolbars use our database feed to warn users that a site they visit is a fake company run by scammers. But most importantly, we continue to build better relations with other anti-fraud organizations and webhosting companies, to pursue our goal of ridding the Internet of fraudulent web sites.
Both of these organizations are run by volunteers that care. They can always use the support of the people they protect. If you get a minute, I recommend taking a look at them to see what they are doing to make the Internet a safer place.

We should all "resolve" to give these fine people our support!

CastleCops has a new online forum about the DDOS attacks, here.

Wednesday, February 14, 2007

Valentine's Day Virus moving quickly across the Internet

Sophos is reporting a nasty virus, which if downloaded, sends more e-mail to everyone in your address book.

They suspect that the worm opens a gateway, which will allow your computer to be turned into a zombie and be used to send more spam e-mails.

Here is a portion of the alert from Sophos:
Experts at SophosLabs™, Sophos's global network of virus, spyware and spam analysis centers, have warned of a widespread worm posing as a St Valentine's Day greeting which is spreading fast across the internet

The W32/Dref-AB worm has been deliberately spread via email in readiness for office workers and home computer users to find the malicious Valentine email in their inbox first thing in the morning. Since midnight GMT the Dref-AB worm has accounted for 76.4% of all malware sighted at Sophos's global network of virus monitoring stations.

Subject lines used in the attack are many and varied, but all pose as a romantic message. Some of them include "A Valentine Love Song", "Be My Valentine", "Fly Away Valentine", "For My Valentine", "Happy Valentine's Day", "My Lucky Valentine", "My Valentine", "My Valentine Heart", "My Valentine Sunshine", "Send Love On Valentines", "The Valentine Love Bug", "The Valentines Angel", "Valentine's Love", "Valentine's Night", "Valentine Letter", "Valentine Love Song", "Valentine Sweetie", "Valentines Day Dance", "Valentines Day is here again", and "Your Love on Valentine's".
Sophos alert, here.

Spam is getting out of control and seems to be defeating spam filters (too often). Here is more evidence of this problem:

2006 was the Year of Internet Crime - 2007 is predicted to be even worse

Spoofed (counterfeit) BBB e-mails contains virus

If you get an e-mail from the Better Business Bureau stating you have received complaints don't click on the link to view them.

Annys Shinn (Washington Post) is reporting:

The Better Business Bureau network was the target of a "spoofing" scam yesterday in which thousands of businesses in the United States and Canada received e-mails encouraging them to download what is thought to be a computer virus.

The e-mails, using the name of the 95-year-old network of nonprofit groups that looks into consumer complaints, told businesses that they were the subject of a complaint and included a link to view related documents. Clicking on the link, however, accessed the address book of an infected computer and distributed the counterfeit e-mail to more recipients, said Steve Cox, spokesman for the Council of Better Business Bureaus.

Washington Post article, here.

Wandering to the BBB site to see what they had to say, I found a little more information. Apparently, if you click on the link, it downloads an executable file, believed to contain a virus.

The BBB and others are calling this a phishing attempt, but in phishing the intent is normally to get the user to provide personal, and or financial information to the sender. Since this doesn't seem to be the case, and no one is saying exactly what the executable file (virus) is, this doesn't appear to be phishing.

It will be interesting to see exactly what this executable file does, but some computer viruses (crimeware and malware) download keyloggers, which log a person's keystrokes and are used to steal personal and financial information.

Other computer viruses might turn a computer into a zombie, which allows someone else to use it for their own purposes (sending spam or denial of service attacks). Zombie computers are formed into what is known as botnets (groups of zombie computers), which are used for illicit purposes by their "controller."

You can download a lot of nasty things by clicking on something from someone you don't know. And the people behind it like to spoof well known entities, such as the BBB. Organizations from eBay to the FBI have been spoofed in the past.

Example of spoofed e-mail from the BBB site:

From: operations@bbb.org [mailto:operations@bbb.org]
Sent: Tuesday, February 13, 2007 6:06 AM To: XXXX
Subject: BBB Case #263621205 - Complaint for XXXX

Dear Mr./Mrs. XXXX

You have received a complaint in regards to your business services. The complaint was filled by Mr. XXXX on 02/05/2007/

Use the link below to view the complaint details:

DOCUMENTS FOR CASE #263621205

Complaint Case Number: 263621205
Complaint Made by Consumer Mr. XXXX Complaint
Registered Against: Company XXXX
Date: 02/05/2007

Instructions on how to resolve this complaint as well as a copy of the original complaint can be obtained using the link below:

DOCUMENTS FOR CASE #263621205

Disputes involving consumer products and/or services may be arbitrated. Unless they directly relate to the contract that is the basis of this dispute, the following claims will be considered for arbitration only if all parties agree in writing that the arbitrator may consider them:
- Claims based on product liability;
- Claims for personal injuries;
- Claims that have been resolved by a previous court action, arbitration, or written agreement between the parties.

The decision as to whether your dispute or any part of it can be arbitrated rests solely with the BBB.

The BBB offers its members a binding arbitration service for disputes involving marketplace transactions. Arbitration is a convenient, civilized way to settle disputes quickly and fairly, without the costs associated with other legal options.

Thursday, January 25, 2007

Symantec warns of newsletters and "legitimate" advertising being hijacked!

Viagra with your Fantasy Football?

Spam is getting worse than ever, and a lot of spam filters don't seem to be stopping it. Even worse, legitimate mail is being designated as "spam" and placed in "bulk folders."

I find myself having to review my "bulk folder," daily.

Symantec is reporting a new "sneaky" spam tactic being seen out there. Legitimate newsletters and advertising from well known organizations, such as Walmart and ESPN are having ads for Viagra (example) inserted into their publications and sent out as if they are affiliated with the product.

In essence, the spammers are "hijacking" legitimate publications.

As reported in the Symantec Security Response blog by Kelly Conley:

We've noticed a tricky new spam tactic occurring recently and thought we'd share it with you. It’s always exciting when a new spamming technique comes along and it’s even more exciting when our filtering capabilities are successful against it. Most users running our product will not have seen this. Spam filtering can still protect you from this “new spam technique,” but, even if you have seen it or even opened it, you probably gave it a one-two glance and wondered “Eh? This isn't what I thought it was.”

The headers are legit – coming from a newsletter or ad that you have signed up for. You should be receiving this mail, right? Nope, it's a spam email. Look closer. There at the top of the page. It's an ad for something entirely different than what you thought was going to be in that email.


Kelly's full post, here.

Symantec's researchers have noted these "faux" (fake) images inserted on legitimate pages, or when the page is accessed - a "pop in" spam message appears moments later. They've also noted that the spammers seem to be able to control how many messages are sent out. No more than one a day is sent to any particular e-mail address -- and a different legitimate newsletter, or retailer is used each time.

According to the researchers, the motivation behind this is to (probably) make the reader more likely to read the message (believe it's credible). This method is possibly also used to in an attempt to trick a lot of the spam filters out there.

The good news is that - according to Kelly - Symantec's filters appear to be catching almost all of this.

A lot of us laugh at spammers and their "seemingly ridiculous" advertising, but the sad truth is, they wouldn't be sending it out if unless some people were falling for it. And that person might be one of your grandparents, or "younger relatives."

Even worse, the products they are "hawking" are questionable and in some instances, dangerous. In addition to this, spam is also used as a means to hook "victims" into all the various Internet scams that I frequently write about.

Symantec covers this issue "online fraud" (and others) on their blog, here.

Screenshot (below) of Kohl's ad being hijacked to sell drugs

Tuesday, January 23, 2007

People are getting tired of having their personal and financial information stolen

Are people beginning to get sick and tired of discovering that their personal and financial information has been exposed?

Employees at Xerox are picketing their office in Oregon because it took four months for anyone to be notified that a Human Resource's Manager lost a laptop with their personal information on it.

Many of the employees (rightfully feel) that an offer of "free credit monitoring services" is coming four months too late, and are wondering why their information was stored on a laptop?

KOIN 6 News story, here.

With the news that TJX has potentially exposed millions in several countries by having their systems hacked, we are likely to see more and more people speak out!

Of course, we could ask Martha Coakley, who was just sworn in as the Attorney General in state of Massachusetts. Ms. Coakley recently discovered someone was trying to use her credit card to buy a Dell. Her comment was that the chances of catching the crook "are slim to none, since even if they could link it to a person, jurisdictional issues would likely hamper an effort to prosecute."

Boston Herald story, here.

Maybe the problem is that there aren't sufficient laws to protect people's (personal and financial) information, or go after the people - who steal it?

Thursday, December 28, 2006

Federal Trade Commission will fight Internet Crime across Borders

Internet crime of often "elusive" because it crosses borders with "a click of a mouse." To fight this a new law has just been signed by President Bush, which gives the Federal Trade Commission a license to go after the problem at it's source.

In their recommendations to Congress, the FTC wrote:

Using Internet and long-distance telephone technology, unscrupulous businesses can strike quickly on a global scale, victimize thousands of consumers, and disappear nearly without a trace, along with their ill-gotten gains. For example, deceptive spammers can easily hide their identities, forge the electronic path of their email messages, and send messages from anywhere in the world to anyone in the world. Fraudulent overseas telemarketers can also victimize American consumers and hide their ill-gotten gains in offshore bank accounts.

The US Safe Web Act contains the following provisions:

Broadening Reciprocal Information Sharing and International Investigative Cooperation.

The FTC can now share confidential information in consumer protection cases with foreign law enforcers. The Act further allows the FTC and foreign law enforcement agencies to obtain investigative assistance from one another, while exempting information from foreign agencies from public disclosure laws. This provision addresses the concern expressed by some foreign government agencies that materials they share with the FTC might be publicly disclosed in response to an inquiry under the Freedom of Information Act (FOIA). This concern is reflected in certain foreign laws where the foreign consumer protection agency is not permitted to share information with the FTC unless the information is kept confidential. For example, Canada's Competition Act and the European Unions enforcement cooperation regulation contain such confidentiality requirements.

Enhancing Confidentiality of FTC Investigations.

Prevents notifying subjects of investigations if they may be likely to destroy evidence or move assets offshore.

Protecting Certain Entities Reporting Suspected Fraud and Deception Violations.

The Act protects a limited category of entities from liability for voluntary disclosures to the FTC relating to suspected fraud and deception. This provision is similar to longstanding protections for financial intuitions making disclosures to the FTC and is necessary to encourage reporting of suspected violations to federal agencies.

Allowing Information Sharing with Federal Financial and Market Regulators.

This provision assists the FTC in tracking proceeds of fraud and deception sent through U.S. banks to foreign jurisdictions so they can be returned to victims.

Enhancing Cooperation between FTC and DOJ in Foreign Litigation.

Permits the FTC to work with DOJ to increase the resources relating to FTC-related foreign litigation, such as freezing foreign assets and enforcing U.S. court judgments abroad.

Clarifying FTC Authority to Make Criminal Referrals.

Authorizes the FTC to share information with criminal authorities, which will improve information sharing with foreign agencies that treat consumer fraud and deception as a criminal law enforcement issue.

Report to Congress.

The Act requires the FTC to report to Congress within three years from the date of enactment, describing the use of the FTC's expanded authority and activities under the Act.

US Safe Web Act FTC document, here.

Although this law has just been enacted, it takes away a lot of the barriers to effectively going after individuals and organizations (businesses) that enable the growing problem of cybercrime.

Recently, I've written that technology will never solve Internet crime. It might stop it, or slow it down - but in the end "technology defeats technology."

Holding individuals and organizations accountable is likely to be a lot more effective. This new law breaks down a lot of the barriers that have prevented law enforcement agencies from doing so.

This (in my opinion) is a start in the right direction.

Interestingly enough, Microsoft has taken a similar approach - taking legal action worldwide. Here is a previous post, I wrote about this approach:

Does Microsoft's Approach to Addressing Counterfeiting Make More Sense?

Saturday, December 23, 2006

2006 was the Year of Internet Crime - 2007 is predicted to be even worse

Have you noticed spam getting past your e-mail filters lately? You're not alone, experts are saying 2006 was the worst year ever in Internet crime - and it appears - security fixes are being defeated.

Brian Krebbs (Washington Post) is warning:

Few Internet security watchers believe 2007 will be any brighter for the millions of fraud-weary consumers already struggling to stay abreast of new computer security threats and avoiding clever scams when banking, shopping or just surfing online.

Washington Post story, here.

Brian cites that in October 90 percent of all e-mail received was spam. And most spam is a come-on for one fraud scheme, or another.

Since "security fixes" are being defeated pretty quickly by organized criminals - who allegedly hire their own computer security experts - the only viable recourse is to go after the source(s) with the intent to put the people behind it out of business.

Resources allocated to fund the investigation of financial crimes are (normally) not funded very well and the people investigating them are "overwhelmed." Maybe we should take some of the money being spent on developing "fixes" and use it to solve the real problem, which is a social one. Prevention seems to only work temporarily.

Security fixes are needed, but if we don't aggressively go after the sources, the criminals develop countermeasures and we have to start all over again.

After all - it seems that organized criminals and some say, terrorists are flocking to this activity because it's financially lucrative and a lot less dangerous than other criminal activities. Until we make it more dangerous for them, the problem is likely to keep growing.

John Bambenek (Assistant Politics Editor for Blogcritics and academic professional for University of Illinois) recently wrote a compelling essay about this subject, here.

Here is a previous post, I wrote about why we are approaching this problem the wrong way:

Are We Addressing Cyber Crime from the Wrong End

Tuesday, December 12, 2006

Another Record Set for Phishing and it appears Anti-Phishing Measures are being Defeated

Brian Krebs of the Washington Post did an interesting post on his blog about how phishing is increasing (again) and how anti-phishing measures (some recently marketed to users) are failing already.

Brian writes:

The Anti-Phishing Working Group reports that 52 percent more phishing sites were recorded on the Internet than a month earlier and nine times as many as were spotted in October 2005. The steep increase coincides with a massive spike in the volume of spam circulating on the Internet. According to e-mail security firm Postini, 90 percent of all e-mail these days is spam.

Brian's post, here.

Also mentioned is "Rockphishing," which takes advantage of zombie computers formed into botnets. The result is that it is making phishing extremely hard to trace.

Brian did an excellent job in his post - and I highly recommend reading it.

I wrote recently about how technology isn't winning the war against cybercrime. It seems like a lot of expensive anti-phishing software is proving this all over again.

Maybe a better approach would be to follow the money instead? After all - I'm pretty sure that is what the cybercrimals are really after.

Thursday, June 29, 2006

Secret Shopper Scam Targets Walmart, Again

Back in November, I did a post on a Secret Shopper (advance fee) scam -- where people were solicited to act as Secret (Mystery) Shoppers -- and cash a large check at Walmart as part of their "paid" shopping assignment. They are then provided with a large dollar counterfeit cashiers check and instructed to cash it at Walmart. The second part of their assignment (if they get past the Walmart employee) is to wire the money to Canada via MoneyGram.

Of course, for their hard work they are instructed to keep a "generous" commission for themselves. And after the check returns, they are left with the responsibility of dealing with the consequences.

This scam seemed to die out for a few months, but is again raising it's "ugly head." I've received several reports -- by my readers and other sources -- that they are again being solicited to perform these so-called shopping assignments. The current scams seemed to be based out of Canada, which is where the original ones were based, also.

Walmart is known to take a tough stance on check fraud and makes use of local District Attorney programs as part of their "collection" efforts. This normally means -- if you fall for one of these scams and Walmart cashes the check -- failure to pay them back could mean criminal prosecution. Since the person cashing the check is responsible for the full amount cashed, the "generous commission" isn't a very good deal.

Of course, they might also call the authorities while someone is in their establishment passing a counterfeit check.

So far as the "Walmart connection," these scams all mutate and instructions to "shop" other establishments (although not seen yet) could be a future development. Only the result will remain the same, which is the person cashing the check will ultimately be held responsible. The best protection any of us have is to recognize the scam and ALWAYS remember that anything too good to be true, often IS NOT.

Here is the previous post, I wrote in November:

Secret Shoppers Scammed

If you want to report one of these scams, a good place to do so is:

Internet Crime Complaint Center (FBI)

And Canada (where most of this seems to come from) has a site of their own to report activity:

Phonebusters

Wednesday, May 10, 2006

Are We Addressing Cyber Crime from the Wrong End

Deb Radcliff is a noted author on cybercrime and it's implications. Recently, Deb did a very enlightening post suggesting that our current problems with cybercrime are caused by approaching security "Ass Backwards."

Please note that she got this perspective from someone, who knew little or nothing about the world of cyber crime or fraud. Although fraud has been around since the beginning of time, there is little doubt that technology is enabling it to grow more quickly than ever before. There is also little doubt that the Internet, which provides a lot of anonymity is a enabling factor, also.

Here is the "thought process" Deb and her friend came to:

Oh I see what you're saying! It's like we've got two ends of the same business working against each other," I said as I grabbed a notepad and started writing things down. "On the back end, we've got all these information security experts working their tails off trying to close the vulnerabilities. But on the front end, we've got systems that are laying bare our financial identities."

For example, why, after all these years in not-present mediums, are the credit card issuers unable or unwilling to unequivocally vet new applicants to ensure they're issuing the card to a real person with a legitimate identity? Why, at the very least, is the application not tied to a customer phone number for verification?

So now I'm looking at the bigger financial identity framework and I'm seeing all kinds of gaps.

Let's start with the credit reporting agencies who are responsible for our credit ratings and yet they prevent us from getting the information we need to protect our ratings by not alerting us to new accounts opening under our identities. The reporting agencies have the system in place to do this. But they've made it so hard for consumers to order this service (and when they do, they can only get it for 90 days unless they can prove fraud). Why? Because they make much more money processing our financial identities in real-time than they would if they imposed wait times to get approvals.
For the rest of the post on Deb's blog (On line Crime Bytes), link here.

For more on Deb and where you can read her articles, link here.

When we look at too good to be true Internet crime schemes, greed is always one of the factors a fraudster uses to hook a victim. Could it be possible that it isn't only individual(s), who are guilty of letting greed cause a large part of the problem with cybercrime?

To take this thought process further, could the criminals be taking advantage of "corporate greed," which values profit over the people being victimized? After all, up until now, these companies have been able to pass the cost of fraud on to their customers and make a tidy profit.

Forget the "zero liability" public relations programs, we are being sold. The fact is fraud losses are being added into the "cost of the product." These companies are in the business of making a profit and wouldn't be operating otherwise. They are even trying to add to their income streams by pushing "identity theft products," which some consider a little "questionable," also.

I'm always amazed to note that many of the same companies, who have lost massive amounts of information are marketing identity theft insurance. Some of them probably helped create the need for this service.

Until the financial, information and now even retail sectors are forced to take action, I fear the criminals will continue to take advantage of an "Ass Backward" approach to protecting information.

Bruce Schneier, another well-known security expert echoes this sentiment and has an interesting perspective on what is needed to address cyber crime. He recently wrote:

Push the responsibility -- all of it -- for identity theft onto the financial institutions, and phishing will go away. This fraud will go away not because people will suddenly get smart and quit responding to phishing e-mails, because California has new criminal penalties for phishing, or because ISPs will recognize and delete the e-mails. It will go away because the information a criminal can get from a phishing attack won't be enough for him to commit fraud -- because the companies won't stand for all those losses. If there's one general precept of security policy that is universally true, it is that security works best when the entity that is in the best position to mitigate the risk is responsible for that risk. Making financial institutions responsible for losses due to phishing and identity theft is the only way to deal with the problem. And not just the direct financial losses -- they need to make it less painful to resolve identity theft issues, enabling people to truly clear their names and credit histories. Money to reimburse losses is cheap compared with the expense of redesigning their systems, but anything less won't work.

For more on Bruce Schneier and his work, link here.

Let's face it, cybercrime by all estimates continues to grow. The criminal element seems to be very adept at beating current security systems and are beating new measures, daily.

Until some "forward thinking" is applied to address this problem, we will never find an effective solution.

Tuesday, April 25, 2006

Do It Yourself Hacker Kits

Not too long ago, you needed some technical expertise to become a Internet criminal. Think again, for about $15.00 you can buy your own do it yourself kit from Russia. This kit downloads a Trojan when someone visits the site it is installed on. It logs keystrokes, (which can give someone access to your personal and financial information), downloads additional cybernasties and opens backdoors to a compromised system.

The Trojan is even smart and can detect what browser is being used via the user agent and customize the exploit based on the browser settings.

Here is the ad, which was translated into English by Websense:

Dear Friends! We would like to offer you multi-component exploit Web-Attacker IE604, that realizes vulnerabilities in the internet browsers Internet Explorer and Mozilla Firefox. With the help of this exploit you will be able to install any programs on the local disks of visitors of your web pages. In the foundation of work of the exploit Web-Attacker IE0604, there are 7 already-known vulnerabilities in the internet browsers: Objective of the Exploit: Hidden drop of the executable from the deleted source to the local hard drive of the site visitor.

-Bypasses all security measures-Is not blocked by Firewalls [Agnitum Outpost, Zone Alarm, Sygate Personal Firewall]

-Tri-level protection -Flexible installation -Updates -Detailed Statistics

For the full alert, with screenshots, click here.

John Leyden of the Register is also covering this story.

trimMail's E-Mail Battles has an interesting story about why some of these kits are so dangerous. Here is an excerpt:

Smart computer users know that once a computer is infected by a rootkit, it's changed forever. And as Windows rootkits go, Hacker Defender is among the most dangerous. The author of Hacker Defender, holy_father, explains why he does what he does, and what you can do to detect his rootkit.

Antivirus companies sell a fake sense of security, but they do not bring real security to your computer. Antivirus just fights programs that are visible to common users. They don't care about the cause.

Do it yourself kits are becoming increasingly common and are making the Internet increasingly dangerous for the common user.

Here is a recent post, I wrote about "how to scam kits" and one that is designed for use in committing fraud on eBay.

Link, here.