Thursday, January 17, 2008

Adopting a homeless critter is a better idea than taking a chance of being scammed on the Internet!


(Billboard calling out puppy mill abuse in Pennsylvania courtesy of Star Cat at Flickr)


The fact that there are so many homeless dogs and cats is a sad thing to ponder. If you are like me (and a few humans I know) a trip to the local pound can be a heart breaking experience.

With so many homeless animals in the world, it amazes me that anyone would buy one. Nonetheless for whatever reason -- people do and the result is a lot of abuse and a fair amount of scam activity -- especially when the "I word" (Internet) is involved.

I happened to run into a pretty good article by Marissa Maroff published on eHow on how to avoid getting scammed, and in a lot of instances (also avoid) supporting, animal abuse.

Marissa writes:

Buying a new pet on the Internet is usually not a good idea. In addition to unscrupulous dealers and puppy mills selling their “stock” to unsuspecting buyers—online scammers use elaborate websites and fabricated stories to bilk substantial amounts of money out of people for pets that don't even exist. And the pets that do exist, very often have serious, if not fatal health problems. Here are ways to keep from getting duped by online pet sellers.

If you insist on getting a pet via the Internet, the full article can be read, here.

The Puppy scam is also known in the Advance Fee (419) scam circles, also. Basically this variation of the advance fee (419) scam entails free pure bred puppies, or pure bred puppies at a "too good to be true" price. After a few e-mails to hook the victim into believing the deal is for real, shipping fees are sent (normally Western Union or MoneyGram) and the puppy never arrives.

Please note that the media loves to attribute all this activity to Nigeria (it makes good press), but Nigeria isn't the only point of origin for these types of scams. Scams can orginate from just about anywhere.

Going back to my original thought in writing this post, there are a lot of lovable animals out there waiting to be adopted that really are free. These animals, who need a good home can be found at your local pound, the SPCA, numerous rescue organizations, or even your local Petsmart on weekends.

On a personal level, I highly recommend you start there before looking for a paid companion on the Internet. In the long run, you will receive some good karma and probably avoid (not support?) a lot of pain and suffering.

I'm dedicating this post to Raleigh, Ellen, Carole, Kim, Scott, Frank, Dave, Michael, Sam (1, 2 and 3), Olivia and Dr. Marylou Randour, who is the author of Animal Grace.

Animal Grace
is a book that explores the spiritual relationship we share with furry critters of all kinds.

Wednesday, January 16, 2008

Your computer will not love this Valentine

The Storm Worm, which turns systems into spam spewing zombies without their owner's knowledge is taking a predicted twist and using Valentine's Day as a lure.

Websense is reporting:

Websense® Security Labs™ has received reports and confirmed that the Storm worm has once again switched lure tactics. The worm has now adopted a Valentine's Day twist in its attempts to infect users with malicious code. For more details on how we protect against Storm attacks, see http://www.websense.com/securitylabs/blog/blog.php?BlogID=141.
Websense (full) alert with screenshots, here.

Most recently, we've seen the Storm Botnet leased by the phishermen to steal people's personal and financial details.

CNet (Robert Vamosi) did a good write-up on this latest Storm phenomenon, here.

The best way to protect your computer from this (besides having good security software) is to simply "just say delete" to any unsolicited Valentines you receive!

Previous posts I've written about the Storm Worm can be seen, here.

Sunday, January 13, 2008

Blogger exposes security flaws on TSA site

Since 9-11, we've spent billions upgrading security. Here is a sad report about how the TSA (Transportation Security Agency) put up a NOT very secure site with some of the money earmarked for making the nation more secure.

Even worse, it seems it wasn't the TSA didn't even discover the problem themselves. The problem was brought to light by a blogger!

Here is some commentary from the government report that examines this problem:

In October 2006, the Transportation Security Administration launched a website to help travelers whose names were erroneously listed on airline watch lists. This redress website had multiple security vulnerabilities: it was not hosted on a government domain; its homepage was not encrypted; one of its data submission pages was not encrypted; and its encrypted pages were not properly certified. These deficiencies exposed thousands of American travelers to potential identity theft.

After an internet blogger identified these security vulnerabilities in February 2007, the website was taken offline and replaced by a website hosted on a Department of Homeland Security domain.

At the request of Chairman Henry Waxman, Committee staff have been investigating how TSA could have launched a website that violated basic operating standards of web security and failed to protect travelers’ sensitive personal information. As this report describes, these security breaches can be traced to TSA’s poor acquisition practices, conflicts of interest, and inadequate oversight.

The report reveals that the contract for the website was awarded without taking competitive bids to a company by a TSA employee, who was a former employee of the company designing the site. Even worse, it took months for the security flaws to be noticed and when they were, it was a blogger that brought them to everyone's attention!
The "hat tip" on this one belongs to a Chris Soghoian, who is a Ph.D. student at the University of Indiana’s School of Informatics. He used to write on the blog, "Slight Paranoia."

The first time Chris was considered "notorious" was when he put a fake boarding pass generator on the Internet. This attracted a lot of attention in the press, as well as that of the FBI.

Chris recently moved his blog to a CNet address, which can be seen, here.

Chris recently blogged about this report and added a comment about the lack of spell check being used on the TSA site, "Furthermore, the site was filled with typos and other errors, causing some to wonder whether TSA's site had been taken over by phishers."

The official government conclusion is:

There were multiple factors that contributed to security vulnerabilities in the TSA traveler redress website. They included poor procurement practices, conflicts of interest, and weak oversight. The result of these shortcomings was that an insecure website collected sensitive personal information from American travelers for months without detection by TSA.

This led me to wonder if the TSA employees involved still have their jobs?

Much to my chagrin, I found my answer on the Committee on Government Oversight and Reforms press release on this matter:

Neither Desyne nor the Technical Lead on the traveler redress website has been sanctioned by TSA for their roles in the deployment of an insecure website. TSA continues to pay Desyne to host and maintain two major web-based information systems: TSA’s claims management system and a governmentwide traveler redress program. TSA has taken no steps to discipline the Technical Lead, who still holds a senior program management position at TSA.
Full government report (PDF version, here.

It's unlikely the IRS is outsourcing tax preparation services to Russia!

Looks like with the start of tax season, the phishermen are again pretending to be the IRS.

Using a badge of authority in phishing is nothing new. In the past, we've seen the FBI, Interpol, DOJ and a lot of other official agencies spoofed (impersonated) to trick people into giving up their personal and financial details.

Here is a phishmail that got past my spam filter yesterday:


Date: Fri, 11 Jan 2008 16:02:36 -0500

From: "Internal Revenue Service" Add to Address Book Add Mobile Alert

Subject: IRS Annual Calculations - Tax Refund Internal Revenue Service United States Department of the Treasury

Dear Applicant:

After the last annual calculations of your fiscal activity we have determined that
you are eligible to receive a tax refund of $270,25.

Please submit the tax refund request and allow us 2 business days in order to
process it.

To access the form for your tax refund, please click here (link removed).

The links on these spam e-mails are designed to entice the unwary to give up their personal and financial details (later used to commit financial crimes)through social engineering techniques (trickery). Just clicking on a link can download malicious software designed to steal information from your computer (which will also be used in financial crimes) or it will turn your computer into a spam spewing zombie.

If you hover (don't click) your mouse on a link and read the address that shows up on the bottom of your screen, it will show the true address. In the above example, it reveals and address of a Russian domain (astrasong.ru).

It's unlikely that the IRS is outsourcing tax preparation services to the Russian Union!

I went to the IRS site and discovered that they just updated their Suspicious e-Mails and Identity Theft page the same day I received this phishmail.

The page has links to all their previous warnings and information on where to report phishing activity involving the IRS. Also included are government educational resources (recommended reading if you haven't seen them before).