Sunday, May 17, 2009
FaceBook Hack Reveals Trend in Targeting Social Networks
For the past couple of weeks, the ongoing attack on FaceBook has figured prominently in the media. The attack isn't much different than some of the other ones we've seen in recent years – which are to take over a user account – and then use it to trick people into falling for a scam. In this instance, a phishy link is being used to direct the effort.
The intended victim receives a communication from someone they know (who has already been compromised), which directs them to a page that appears to be a FaceBook login. They are then prompted to put in their user name and password. If they do, their information is stolen and will be used to trick even more people into doing the same thing.
Stealing stolen user accounts on eBay has been a problem for years. On eBay, it is a means of using an established seller's credentials to trick people into thinking they are dealing with a "trusted seller." The only difference here is that instead of selling bogus or non-existent merchandise, the intent on FaceBook is probably to trick people into giving up personal or financial information.
This information can then be used to commit financial crimes, using the victim’s identity.
I found some information about the FaceBook attack on Symantec's Security Response blog. Thus far, according to the research conducted on this at their lab, no computers have been infected.
According to Marian Meritt at Symantec, the danger of giving up your FaceBook credentials might go beyond having your account compromised. She believes the hackers behind this are looking to compromise other accounts, where you might use the same credentials. I read some other articles on this and thus far this seems to be the consensus of why the attack is occurring, but no one seems to know for sure.
Whether this is the intent, or not – the advice given in the post is something that should be considered when dealing with the multiple accounts a lot of us have.
First and foremost, you should pay attention to the address in the bar at the top of your page. If it is not exactly the address of the legitimate site, you are probably being tricked into thinking that it is. For instance, www.faceboot.com is not www.facebook.com. Even better, if you spot a suspicious link, hover your mouse on it (without clicking on it) and the actual address will appear at the bottom left-hand of the page. Entering the legitimate address in your address bar is always smarter than clicking on a link, too.
Of course, it's also wise to check out the address at the top of the page after arriving at your destination, also. You should also stop and think when something pops up instructing you to enter your user and password information.
Also recommended is to use complex and unique passwords for each of your accounts, maintain an up-to-date browser and operating system and use updated security software from a reliable vendor.
When purchasing security software, ensure you are not buying counterfeit software or being tricked into purchasing scareware. Scareware is bogus security software that normally prompts a user to run a scan of their system, which reflects all kinds of bad things going on. The problem is that the problems normally do not really exist and the protection they are selling doesn't really protect you, either.
So far as buying counterfeit software, it normally doesn't protect you very well and it might even have some malicious code built right into the program.
While the FaceBook attack is the flavor of the week, it’s not the only social networking site that has been targeted in the recent past. Twitter and MySpace have been the targets of recent attacks, too. SC Magazine did a recent article where a security researcher from Websense was quoted as saying they have detected more than 200,000 sites impersonating the above mentioned social networking sites.
Going beyond social networking sites, financial, auction, e-commerce are frequently attacked, too. The common denominator is sites where criminals can harvest information and turn it into money. Please note that people interested in doing a little bit of due diligence on you personally might see what you are putting up on these sites. I’ve recently seen this presented as a “best practice” when doing background checks on people.
The key is to adopt the known best practices if you enjoy using these sites. Another wise thing to do is to be extremely thoughtful about what information you post on them and how it might be used against you.
Anything you post on these sites can and will be used against you if the wrong person gets their hands on it. In the end, being mindful of the information you are posting on a social networking site is probably the best defense you have. After all, you never know who is looking at it!
Sunday, February 15, 2009
Sending Children to the Slammer for Profit
On February 12, 2009, two judges appeared in federal court to plead guilty to $2.6 million in income tax and wire fraud. The crimes they were charged with resulted from locking up teenagers for profit in Scranton, PA.
Judge Michael T. Conahan and Judge Mark A. Ciavarella Jr. were the two barristers, who received kickbacks to send teens to privately run detention centers. Apparently, Conahan secured the contracts and Civarella kept them filled with fresh prisoners (victims?) from his docket (court calendar). The privately run centers in questions were PA Childcare and its sister organization, Western PA Childcare.
A press release on January 28th from the Administrative Office of the Pennsylvania Courts announced the two judges' removal from the bench. The release goes into detail about the charges that were brought against them.
In one example cited by the NY Times, a teenager was given three months for setting up a MySpace page mocking her assistant principal at a Wilkes Barre, PA high school. The student in question, Hillary Transue, was a stellar student and had never been in trouble before. At the end of the hearing, with her parents watching, she was handcuffed and taken away. In another case, a teenager got three months for giving another teenager a black eye.
This is scary in a society where Paris Hilton and Lindsay Lohan get a few days for doing a lot more than putting up a MySpace page or giving someone a black eye!
Senior Judge Arthur Grim has been appointed by the State Supreme Court to figure out what to do with the estimated 5,000 juveniles who have been sentenced by Judge Ciavarelli since the scheme started in 2003. A lot of these children were first time offenders and some of them are still locked up.
The case has shocked local residents, already strained by recent losses of a lot of industrial jobs and the shutting down of coal mines. It has also brought up a debate about how children are represented in the legal system when they face charges.
Just last year, a motion was filed by the Philadelphia-based Juvenile Law Center in behalf of 500 juveniles who had appeared in front of Ciavarelli without representation. The motion was originally denied, but it has now been reopened. Statistics show that about 50 percent of the children who waived their right to counsel in front of Ciavarelli went to the slammer. The Supreme Court ruled in 1967 that juveniles have a right to counsel, but in some states, including Pennsylvania, they are allowed to waive it.
Given the reduced tax base in the area, the money stolen in this instance could certainly have been put to better use, too.
Even worse, although Judge Ciavarella admitted to the kickbacks, he is contending that the juveniles in question deserved what they got. This is pretty arrogant, especially considering that the facts show that he sentenced a lot more of his cases (25%) to these privately run detention facilities than the state average of of 1 in 10.
I'm frequently amazed how people who have obviously done something terribly wrong rationalize their behavior.
If Ciavarella and Conahan (Judge titles intentionally removed) accept the plea bargain being offered by the government, they will get 87 months in the slammer, lose their pensions, and be disbarred. The executives running the privately run detention centers haven't been charged yet, but are expected to be.
I first saw a mention of this story on Alex Eckelberry's Sunbelt blog. His comment was "how sick." In closing, "I second that motion."
Tuesday, April 03, 2007
Will law suits stop Spam Kings?
Here is an announcement that MySpace is going after a Sanford Wallace (described as a spam king) with a civil action.
From the Business wire release:
MySpace announced today that it filed suit against Sanford Wallace for violations of state and federal laws including the CAN-SPAM Act and California's anti-spam and anti-phishing statutes. The suit, filed in United States District Court in Los Angeles on Friday, seeks a permanent injunction barring Wallace and his affiliated companies from the MySpace site in addition to unspecified monetary damages.
Full release, with other MySpace actions (commendable), here.
With each release of their statistics, the Anti Phishing Working Group seems to report that phishing and spam are breaking new records.
It would be nice to see governments (which manage law enforcement resources) take some of these cases for investigation and (if warranted) file criminal charges, also.
I'm not sure if forcing spam kings to pay fines is a very effective deterrent. They are liable to view it as a "cost of doing business." Perhaps if a few of them lost their freedom, the statistics (growing all the time) might start to go down.
Statistics are numbers, but they relate to real people being victimized by this activity.
Thursday, June 01, 2006
Phishermen are Trolling MySpace for Victims
"Websense® Security Labs™ has discovered a phishing attack that attempts to steal the account information of MySpace.com users. A hyperlink is first delivered to victims via AOL Instant Messenger. Users who follow this link are taken to a fraudulent website that spoofs the MySpace.com login page. This page captures their MySpace account information and then forwards the user to the actual MySpace.com website."
"The fraudulent site also sets a cookie on the victim's computer, which prevents the phishing attack from being displayed on any subsequent visits."
The phishing site is located in California and was up at the time of this alert.
For the full alert, along with a screen shot of the phishing site, link here.
MySpace is a hugely popular site (and when anything becomes popular) it attracts what I refer to as the cyber-scum element.
Here is an interesting article from MSNBC and Rob Stafford. If you are a user of MySpace, or care about someone who is a user, this is a great resource with information on how to navigate the waters of MySpace safely.
Why parents must mind MySpace - Dateline NBC - MSNBC.com
While I'm not sure what the intention is in "phishing" the waters at MySpace, a smart person is extremely careful before giving out any personal information on the Internet!
Here is a recent post, I wrote about how these "Internet Child Abusers" are going to be targeted through their financial transactions:
Catching Child Predators by following the Money Trail
In case anyone is unfamiliar with Phishing, here is a place to start learning:
Internet Crimes are On the Rise and Deadlier than Ever
