Showing posts with label sunbelt blog. Show all posts
Showing posts with label sunbelt blog. Show all posts

Wednesday, February 13, 2008

A badge of authority is a time tested tool cyber fraudsters use to steal cash!


(Photo courtesy of brykmantra at Flickr)

Using a badge of authority to lure victims is nothing new in social engineering circles. I've written about instances, where law enforcement agencies and the IRS have been used to hook victims for all kinds of sinister purposes.

Another badge of authority frequently used is security software. Historically, a victim was required to download something to become infected. This isn't completely the case anymore -- with advancements in hacker techniques -- all a person has to do is to visit an infected site to make their system become sick.

Of course, the less technical versions (requiring a person to click on something) are still out there, also.

Just the other day, John Leyden (Register) reported that an Indian antivirus site, AVSoft technologies was infecting unsuspecting visitors with the Virut virus. This virus opens a "backdoor on infected PCs, allowing hackers to download and run other malware (or anything else they fancy) onto infected computers," according to John.

In case anyone want more information on the Virut virus, Symantec's definition can be seen, here.

Recently, I also read a post by Alex Eckelberry at the Sunbelt blog, which showed that affiliates of reputable security software companies were spreading malware:

We’ve seen a number of examples lately of legitimate security companies being advertised through malware.

It is important to note that this advertising is not from the companies themselves. It’s coming through affiliates (meaning, people who make commissions sale they refer).
Alex finished his post with a sage comment for his peers:

Affiliate programs are a great way to spread the word on your product, but they need to be monitored carefully for abuse.
Technology changes all the time, but the lures used to attract the unwary seem to remain the same. Interestingly enough, some of the same lures have been used for hundreds of years and will probably still being used long after this blog has been deleted by a search engine.

Alex's post, along with some interesting (educational comments) from people within the industry, can be seen, here.

Wednesday, November 21, 2007

Too good to be true employment opportunities

Patrick Jordan (Sunbelt blog) did a nice post about a huge problem that frequently occurs on the dark-side of the Internet.

The problem, I'm referring to is people being recruited (some might say duped) to assume the risk involved in collecting the proceeds of Internet crime.

With all the fraud occuring on auction and e-commerce sites -- criminals need a way to move they money they are stealing. This activity is often referred to as money laundering.

They accomplish this with money transfer scams, which are sometimes referred to as job scams.

These scams are nothing more than a way to trick people into negotiating bogus financial instruments, or launder the proceeds of auction fraud!

We've all probably seen a spam e-mail, or two (I get several daily) with job offers that seem a little too good to be true. Most of these jobs seek a financial representative to handle payments for a foreign company. In reality -- the person is moving stolen money overseas -- where it disappears into thin air.

Besides being offered in spam e-mails, people are also recruited off job sites and sometimes even from the classifed sections of newspapers and magazines.

A sister scam to money transfer scams is referred to as a reshipping scam. The difference is in this job a person reships hot merchandise (normally from auction sites) to their bosses.

In most of these scams, they prefer you use Western Union or MoneyGram to send them their money. Once the money is picked any efforts to recover it will most likely be useless. Please note that there are many e-cash venues that are used, also.

While these jobs might have fancy titles, a lot of people refer to someone doing this as a "mule."


(courtesy of mattcoz at Flickr)

In Patrick's post, he reveals another twist to this activity, which are websites set-up to make these jobs appear to be legitimate.

Here is a screen shot (courtesy of the Sunbelt blog) of the site Patrick discovered:



He also lists some other sites to avoid from the same IP in his post, which can be seen, here.

Most of these scams are pretty easy to discover because they are offering too much money for too little work.

These job offers are nothing more than a way for criminals to get other people to take all the risk, while they reap the rewards of their illegal efforts!

Besides facing almost certain financial ruin, some of these employees are ending up living in new digs:

Sunday, October 07, 2007

The somewhat slow response to the hacking of California.gov

With all the technology that California is famous for, you would think their government websites were state of the art, when it comes to security.

Apparently, this is NOT the case. The result has been a lot of misdirection to sites of a pornographic nature.

Alex Eckelberry, CEO of Sunbelt Software, has been blogging on this subject:

Yesterday, we reported on a federal shutdown of “ca.gov” sites to fix a hack.

Well, we have a little more information on this. It was the Marin County government website that started all of this — something we reported back in September 12th.
Does anyone besides me wonder if there wasn't much of a sense of urgency on this issue?

Bezhou Feng at Neowin.net reported that:


The shutdown, initiated by the General Services Administration (GSA), a US agency in charge of all top-level ".gov" domains, began at roughly 4:00PM (PST), quickly turning into such a problem that Gov. Arnold Schwarzenegger even considered calling the President himself.

While the porn aspect is either amusing, or disgusting (depending on your viewpoint) -- this clearly shows that .gov sites should wake up and listen when experts are trying to tell them something is wrong.

After all, this type of activity could have been something far more serious than something that is disgusting, or amusing!

Of note, as of this writing, I ran a search on Google and the Marin site (TAM) is still misdirecting users to a number of pretty nasty porn sites.

As I've written before -- exercise extreme caution when clicking on porn sites, they often make your computer come down with a virus (or worse)-- especially if "safe surfing practices" aren't being used.

Sunbelt blog post, here.

Neowin.net story, here.

Update 10/09/07: Alex Eckelberry (Sunbelt), who has covered this problem for over a month did (what I consider) an amusing post to follow-up on this one, here.

Alex and his team at Sunbelt are my favorite place to learn about computer security issues. They routinely help a lot of people free-of-charge and are experts in what they do.

Sunday, September 02, 2007

Blogger fights back against the storm worm

Since Blogger has been kind enough to host this blog for about two years now, I thought I should do a post about the recent reports concerning malware and Blogger.

Blogger itself, wasn't compromised, but a lot of bloggers individual blogs were. Most people are compromised by malware after clicking on a link they shouldn't have.

This was posted on Blogger Buzz:

You may have seen stories in the news recently about malware on Blogger, such has this one from the BBC or this one from Committee to Protect Bloggers. Blogger was not compromised. Instead, the blog posts are from bloggers whose machines were compromised by a Trojan horse.

These bloggers had their mail2blogger email addresses in their computers' address books (a perfectly legitimate use case), so when the malicious software spammed every address in their address book with its content, a copy of that email was posted to their blog.

We are in the process of notifying impacted bloggers and recommending that they scan their computers and run current anti-virus software, available in the GooglePack. This is also good advice for all computer users, especially those who may have clicked the links in the emails sent by the virus. For more information about computer security, check out upenn.edu and us-cert.gov.

The BBC article mentions that Alex Eckelberry, who blogs at the Sunbelt blog was the first to discover the problem on Blogger. Please note, Alex himself is a Blogger user and the CEO of Sunbelt Software, a computer security company.

Alex has even been kind enough to help me, when I ran into a problem, or two doing this blog.

Alex has a pretty visual post (lot's of screenshots), which show exactly how the worm would be encountered in the wild.

Of interest, Alex also discovered that Blogger wasn't the only place, where people are being lured into downloading the storm worm.

From what I understand the intent of the storm worm is to turn a computer into a zombie, which becomes part of a botnet. Botnets are networks of zombie computers.

Botnets are used to send out spam e-mail and sometimes attack other systems in what are known as DOS (denial of service) attacks. They are also used to commit click fraud.

Of note, most Internet fraud can be traced to a spam e-mail.

Besides running a scan with good anti-virus software (to see if you've been compromised) -- the best defense is to learn how to spot the lures that are designed to trick people into clicking on them. In most instances, this will stop the problem before it happens!

Monday, August 06, 2007

Bizzare site asks viewers for money to keep a bunny from being butchered!

I was reading the Sunbelt blog, written by Alex Eckelberry and came across a post he did on a bizzare and pretty sick website.

In Alex's own words:

save-me-please(dot)com is a site dedicated to saving a bunny.

We have no idea what this is odd thing is: A joke, a hoax. Or a scam.



The whole intent of the site is to get a person to pay to save the bunny.



You can view the Sunbelt blog's entire presentation, here.

Paying to save the bunny isn't recommended and as Alex aptly states, one of the videos depicting a rabbit being skinned is "enough to make you a vegetarian."

This blog, according to a study Jonathan Edwards at Yankee Group has "mojo."

I can see why it does, besides providing a lot of great information, it tends to keep the interest of the people, who read it!

The Sunbelt blog is also an excellent place to keep up on, or learn about computer (information) security issues.

Thursday, February 15, 2007

Is Julie Amero (in reality) another victim of Internet crime?

Internet crime is a growing problem. Every week, we seem to read of large scale data breaches, and spam is filling up our inboxes, despite the spam filters designed to stop it.

The spam getting past these filters is often riddled with deceptive lures (links) to all sorts of porn sites. In turn, these sites often infect machines that aren't properly protected with adware, spyware, malware and even crimeware.

So far as properly protecting our machines, this can be a chore, also. It requires frequent updates, and new exploits are discovered all the time.

Sometimes even legitimate sites are hacked and people get infected just by surfing, or visiting (what they think) is a trusted site.

Criminals of all sorts, including those of an organized nature are getting involved in Internet crime. In fact, many believe the problem is growing because very few get caught, and even if they do, very little happens to them.

I was amazed when I got an e-mail from Alex Eckelberry (CEO Sunbelt Software) that a substitute teacher (Julie Amero) had been convicted for some porn that had shown up on a classroom computer.

A jury has already found her guilty and she could face up to 40 years in prison. Even worse, it appears the stress of the trial may have caused her to have a miscarriage.

Is her conviction a miscarriage of justice? Many computer experts (including Alex) seem to think so.

Alex writes a very convincing argument, where he states:
When I first read of the case, my reaction was how illogical it all sounded: A middle-aged, substitute female teacher accessing porn on a classroom computer, in front of her students on one particular day? It made no sense.
He's right, it doesn't make sense.

An article from the Norwich Bulletin stated that:

Computer expert W. Herbert Horner, testifying in Amero's defense, said he found spyware on the computer and an innocent hair styling Web site "that led to this pornographic loop that was out of control."
"If you try to get out of it, you're trapped, according to Horner."

Anyone, who has surfed the Internet knows there are a lot of malicious sites designed to lure people to click on them, using seemingly innocent lures.

She was also convicted on testimony that she must have had to physically click on the sites in question. According to Alex and other computer security experts, the pop-ups from these sites leave the same imprint as if they had been physically clicked on.

Alex wrote in the Norwich Bulletin:

The computer was also found to be riddled with spyware -- programs that generate popups and degrade system stability.

Spyware may or may not have played a direct part in this incident, but the fact it was on the system creates additional damning evidence of the state of this computer system. What is extraordinary is the prosecution admitted there was no search made for spyware -- an incredible blunder akin to not checking for fingerprints at a crime scene.

Alex also states that this was an old system, without adequate protection, despite the fact that federal law mandates that it should have been in place.

Julie, herself claims the website in question was accessed by students when she went to the restroom. When she noticed it, no matter what she did, more pop-ups would surface.

More on Herb Horner's analysis (courtesy of the Sunbelt blog), here.

In a criminal case, the standard is that a person should be found innocent if there is reasonable doubt. After reading about this case, it makes sense to me, that we have a lot of reasonable doubt that Julie is guilty.

At best, the investigation used to convict her seems to have been poorly researched, and therefore, flawed.

Porn is a big component of Internet crime, which according to a WebMD survey reaches a lot of children. This research was conducted by interviewing children, themselves.

Some of the children interviewed were the same age as the ones in Julie's class that day.

Survey, here.

So far as a connection to real (organized) crime, porn was allegedly one of the Gambino crime families biggest earners ($350 million).

Besides being unjust, going after Julie Amero, is a big waste of resources (taxpayer dollars) that could be put to better use.