Showing posts with label Compromising Information. Show all posts
Showing posts with label Compromising Information. Show all posts

Saturday, September 29, 2007

"Death and Taxes"

As every Security Professional knows, phishing is a problem. Let's first take a step back. Phishing is the act of sending an email or placing a phone where the attacker pretends to be a legitimate company to get your information. You generally see emails like "Your Ebay account has been disabled. Click here and enter your account info to reactivate".When you click on it, it takes you to the attacker's site and he/she has your account info.


Well, those dirty attackers are at it again. This time they are posing as the IRS. here is a sample of an email you may receive:

After the last annual calculations of your fiscal activity we have determined that
you are eligible to receive a tax refund of $268.32.
Please submit the tax refund request and allow us 3-6 days in order to
process it.

A refund can be delayed for a variety of reasons.
For example submitting invalid records or applying after the deadline.

To access the form for your tax refund, please click here

Note: For security reasons, we will record your ip-address, the date and time.
Deliberate wrong inputs are criminally pursued and indicated.

Regards,
Internal Revenue Service

© Copyright 2007, Internal Revenue Service U.S.A. All rights reserved.

________________________________________________

Turns out, when you click on that link. It takes you to a Russian site. Last time i checked the IRS didn't have a Russian Branch.

Click here for the article.

Monday, September 24, 2007

Cough Up the Dough or Your Email Gets It

Jesse Sklar found himself in a predicament when he noticed that not only was he locked out of his hotmail account, but there was also someone holding it for ransom at one hundred dollars. While Sklar states that he no longer uses the email account on a regular basis, it contains many passwords and other crucial information dealing with his finances.

When it came to his account on Ticketmaster.com or Amazon.com and the like, Sklar soon came to realize that the credentials for these accounts and various others could be compromised and decided to change them immediately. While he implemented the security measures that hotmail has all users place, such as a security question and a backup email -- this was useless for Sklar due to having signed up for the hotmail service decades ago, as he recalls. All he really wants is for the email to be shutdown. Upon later inspection, the kidnapper asked Sklar to send the information via "Paypalll.tk" which is some sort of phishing scam that may result in Sklar losing more than one hundred dollars had he decided to give the money.

If there's anything to take out of Sklar's story, it is not to make the same passwords for everything, as well as not storing crucial information in your emails -- especially one that is a free service.

via WashingtonPost.com

Friday, September 14, 2007

“There is a place in New Zealand called…”

Taumatawhakatangihangakoauauotamateaturipukakapikimaungahoronukupokaiwhenuakitanatahu. It’s also true that on September 10th the New Zealand government’s computer systems was breached.

From the article: “New Zealand Prime Minister Helen Clark confirmed Tuesday that foreign spies had tried to hack into government computers but said they had not found out any state secrets. The Dominion Post newspaper quoted Tucker saying government departments' websites had been attacked, information stolen and hard-to-detect software had been installed which could be used to take control of computer systems. There was evidence foreign governments were responsible for the attacks, he said, but did not name the countries concerned, although he did refer to comments by Canada's security service about Chinese spying activities. Reports have also alleged China hacked into government computer systems in the US, Germany and Britain.”

Pretty crazy, eh? I know when most people think about hacking they think about corporations getting attacked or maybe you hacking your buddy’s machine. But can you imagine government verses government attacks? Holy Government Espionage, Batman!

You’ll find the full article here.

Thursday, September 6, 2007

Facebook no longer private

Facebook is a social networking site used by high school and college students to keep in touch with friends they go to school with and friends at other schools. You also can meet people with similar likes and interests at other schools around the country. It has been considered more private than the more popular social networking site called MySpace. However, Facebook Inc. has decided to allow non-registered guests to be able to view profiles of members without actually providing your information to become a member. This opens the risk of people being able to get personal information about individuals registered on the Facebook site. Students using this service need to make sure and be careful about information they post since even more individuals will have easier access to whatever members post about themselves. Even scarier is the fact that Facebook Inc. engineer Philip Fung states that in the coming weeks not only will non members be able to access information they will be making profiles searchable through search engines such as Google and Yahoo. Individuals must be aware of these new changes and might want to consider changing their privacy settings that will make their profiles not searchable to everyone. Facebook feels that these new imp limitations will allow for a greater amount of people to reunite and make Facebook a larger community by the assumption that if people search and find others they know they will decide to join the Facebook population.

http://www.computerworld.com/action/article.do?command=viewArticleBasic&taxonomyName=security&articleId=9034538&taxonomyId=17&intsrc=kc_top

Would You Give Your Email Password to Facebook.com? Most Users Would.

Debates over sites like facebook.com are common and something many people, especially the kids who love it and their parents, are familiar with. Newsweek recently ran a cover story[1] that covered everything from its “coolness” factor to the concerns that the online community is actually creating teenagers who are unable, or at least uninterested, in actual face-to-face social interaction. What is rarely discussed in relation to this site, and others like it however, is the security threat it can represent to its users.

Facebook, like a growing number of other respected websites, actually asks for both new users’ email addresses and email passwords as part of the registration process. They use the information to send invitations to other users and stress that providing the information is optional. What is scary is that in a study, 41 percent of the 200 users contacted willingly offered up not only their email information, but also their phone numbers and dates of birth. Considering that facebook.com profiles regularly contain cell phone numbers, employment information, and home addresses this probably shouldn’t be surprising but it should raise concerns. Kids are failing to learn basic security measures and are giving out information that used to be considered private to anyone who is interested. Facebook.com may be a respectable site but many others aren’t. Habits are hard to break, and it is important that the correct ones be formed before it is too late. It can be hard, if not impossible, to tell the difference between a legitimate site and one that is a scam looking for easy targets.

See http://www.eweek.com/article2/0,1895,2179213,00.asp for more information.
[1] http://www.msnbc.msn.com/id/20227872/site/newsweek/

Monday, August 27, 2007

New Software censors work communication

The Health Insurance Portability and Accountability Act (HIPPA) was created in 1996 in order to protect the use and disclosure of private medical information. Now with a new technological box, HIPPA laws can be further enforced. The box is currently being used in Georgia’s DeKalb Medical Center, and is connected to the hospital's computing system. Personal medical information needs to stay personal. The purpose of the box is to detect anything in a message, whether it’s email or an instant message, that would be considered private information. The box, then encrypts the private information, and sends it to its destination. Sometimes personal information needs to be sent in a digital format. This just makes the transaction safer to do. This is a huge step in terms of technology and privacy rights working together.

Monster Waited 5 Days To Tell of Leaked Information

This article appealed to me and how that the largest job seeking company waited nearly five days before telling its users that they were hacked. August 17, 2007 is when Monster first noticed there was a problem with their internet security. The illegal operation was run from two server computers at a web-hosting company in Ukraine. Monster has nearly 1.3 million job seeker records to this date, and the names and confidential contact information was stolen. The security team got the servers shut down late in the evening on August 20, 2007. Monsters web page was warning people that their information might have been stolen. The effects of this type of an attack are very dangerous, because it now puts people at risk for phone calls trying to get personal information, identity theft of information, or spam email so greatly that it will become hard to detect. If a user was to open this spam email and it was to load malicious content on the machine it could breech system security and open up a backdoor for them to gain more personal information. I am a Monster user and I have not noticed any usual spamming lately. The bad part about this situation though is whoever got the information, has full contact with names, addresses, and phone numbers. I am a little concerned at the present moment but hopefully everything will remain safe.