Wednesday, 28 October 2009

10 Ways to Spot an E-Mail Scam



The increasing flood of e-mail hitting your inbox can lower the guard of even the most cautious person. In the rush to keep up with important notes, it's easier than ever to fall prey to the scam artists and identity thieves who lurk online.

E-mail scams and phishing attempts evolve constantly, hoping to take advantage of the latest trends and current events. Although the e-mails change, the people behind them inadvertently send up the same warning signs again and again. We dug through mountains of spam to find the most prevailing trends. We've collected some actual scam e-mails and highlighted the warning signs to help you spot a hustle the next time one lands in your inbox.


1. Requests for personal information


No legitimate organization will ask for your social security, bank account or PIN number via e-mail – and none will include a link, sending you to a form to enter it. No matter how authentic these emails may look, ignore 'em.


2. Watch for typos or spelling mistakes


Scam artists are street smart, but many flunked basic grammar (or barely speak English). Look for mistakes like inappropriate hyphens or confusing "your" and "you're." If the note has multiple typos or grammatical errors, odds are it's not legitimate.


3. Clickable Web links in e-mails


Don't trust links to Web sites in e-mails. What might look like a legitimate address is often linked to a third-party site that looks official, but is actually run by thieves and scammers. These are the fast track to identity and financial theft.


4. 'Market research' or surveys that ask you for personal information.


Disguising scam e-mails as marketing is a classic ploy. You'll be asked to fill out a survey or enter a contest – requiring you to give personal information or "log on" to your account. Once you've done so, the scammers can use it themselves.


5. Stock tips from random people or companies

Got a "hot stock tip" via e-mail? It's probably a "pump and dump" scheme. The sender already owns shares – and when you and others act on the "tip," the stock price soars and he sells fast – leaving you with virtually worthless shares.


6. Attachments in e-mails from anyone you don't know

It should be common sense, but just in case, we'll remind you again: Don't open an attachment from someone you don't know – even if it appears to be your bank or credit card company. It's almost always a virus or spyware meant to steal your personal information.


7. Wordless e-mails

Some legitimate looking "e-mails" are actually just images. The danger with these is that clicking anywhere in the body takes you to a suspect Web site – where you may be fooled into entering personal information, or the scammer may slip spyware onto your machine.


8. Outdated information

Some scammers like to pose as technical- or customer support from a company you associate with – but fail to keep up with current events. For example, in the example above, the senders forgot that Earthlink bought Mindspring in 2000.


9. Red-flag phrases

If you see the phrases "verify your account," "you have won the lottery" or "if you don't respond within XX hours, your account will be closed," it's a scam – every time. Hit the delete button and don't look back.


10. Generic greetings

While you can't trust every e-mail that knows your name, you can definitely ignore the ones that start "Dear member" or "Hello friend." If your bank or credit card company is writing you, it knows who you are. So do your friends.

by Chris Morris

Monday, 26 October 2009

Nigeria actually arrests, shuts down online scammers


Nigerian officials have launched a new initiative called "Project Eagle Claw" that will target Internet scams coming out of the country. The Economic and Financial Crimes Commission has already made a number of arrests and shut down 800 websites, with many more to come.

It turns out Nigeria is taking measures to fight Internet scams—law enforcement there has shut down close to a thousand websites and made 18 arrests as part of a new initiative to save the nation's reputation and crack down on Internet scammers. The program, called "Project Eagle Claw," has only just begun, but Nigerian officials expect it to be fully operational in 2010.

Nigeria's Economic and Financial Crimes Commission (EFCC) described the initiative as "a renewed bid to clap down" (*clap clap*?) on Internet fraudsters. So far, the agency claims to have shut down 800 scam sites in addition to making the arrests, with many more apparently to come.

EFCC Chairman Farida Waziri said Wednesday during a US address to the National Conference of Black Mayors that Nigeria was working with Microsoft to fully deploy Project Eagle Claw, and that it will soon be able to take down up to 5,000 fraudulent e-mails per month. She also expects the system to send up to 230,000 advisory e-mails to victims every month.

Waziri explained that the EFCC's previous strategy for fighting cybercrime involved "cyber raids" and petitions—slow and ineffective in today's fast-moving Internet world—and that Eagle Claw would be much more proactive. "We expect that Eagle Claw as conceived will be 100 percent operational within six months and at full capacity, it will take Nigeria out of the top 10 list of countries with the highest incidence of fraudulent e-mails," Waziri said.

Indeed, if you live outside of Africa, Nigeria is practically synonymous with various scams, some of which predate the Internet. Thanks to the explosion of online connectivity in the last several decades, however, so-called "Nigerian scams" have taken on a new life of their own—fraudsters have managed to grift millions of dollars out of unsuspecting victims in recent years, with even major banks coming dangerously close to wiring their own cash halfway around the world.

This has caused an entire culture of scam baiters to spring up in order to troll scammers and distract them from the real victims (something that we here at Ars briefly dabbled in ourselves), showing that scams out of Nigeria are indeed more than a minor law enforcement annoyance. At this point, it's just nice to see Nigerian officials trying a more realistic strategy towards curbing cybercrime than merely blaming the victim, even if it may take years worth of enforcement before we see any tangible results.

By Jacqui Cheng

Sunday, 4 October 2009

Malware worldwide grows 15 percent in September

A rise in malware has caused the number of infected PCs worldwide to increase 15 percent just from August to September, says a report released Tuesday from antivirus vendor Panda Security.

Across the globe, the average number of PCs hit by malware now stands around 59 percent, an all-time high for the year. Among 29 countries tracked, the U.S. ranked ninth with slightly more than 58 percent of its PCs infected. Taiwan hit first place with an infection ratio of 69 percent, while Norway came in lowest with only 39 percent of its PCs attacked by malware.


(Credit: Panda Security)

The study found that in the U.S., Trojans and Adware were the two most pernicious types of malware, followed by worms and viruses.

(Credit: Panda Security)

"This is a clear sign that hackers are becoming more and more sophisticated," said PandaLabs Technical Director Luis Corrons. "Cybercriminals have found news ways to spread their creations, frequently exploiting the latest news stories to launch attacks through social networks, videos, and e-mail. The huge amount of Trojans in circulation is due to the spectacular increase in the number of banker Trojans aimed at stealing user data."

The company based its results on data taken from users who scanned their PCs with the free Panda ActiveScan online tool. The results for September were gathered from August 28 to September 28 and compared with the results from July 28 to August 27.

by Lance Whitney
http://news.cnet.com/8301-1009_3-10363373-83.html

Red Hat asks US Supreme Court to bar software patents

Red Hat asks US Supreme Court to bar software patents.

Check Here

Tuesday, 22 September 2009

Facebook Beacon shines for last time as part of settlement


Facebook's Beacon has been nothing but trouble since it launched in 2007, spurring numerous user complaints and a class-action privacy suit. The company has apparently learned its lesson, as it has now proposed a lawsuit settlement that involves shutting down Beacon and paying out $9.5 million to a settlement fund.

As quickly as it swooped into Facebook users' lives and revealed their secret purchasing habits to the world, Beacon has now been shut down as part of a lawsuit settlement. Facebook revealed late Friday that its controversial "advertising" feature would be shuttered, saying that the company had "learned a great deal from the experience." Facebook also plans to donate $9.5 million to an organization that fights for online privacy, though the settlement proposal still awaits approval by a judge.

Facebook's Director of Policy Communications Barry Schnitt said in a statement that the whole Beacon ordeal "underscored how critical it is to provide extensive user control over how information is shared." He said the company also learned how to communicate changes to users (you know, instead of just dumping things like Beacon on them without a peep), and that the introduction of Facebook Connect allows for much greater user control over how their Web antics get shared back to friends on Facebook.

"We look forward to the creation of the foundation and its work to educate Internet users on how best to control their privacy; engage in safe social networking practices; and, generally, enjoy themselves more online by having knowledge that gives them a greater sense of control," Schnitt said. "We fully expect the foundation to team with other leading online safety and privacy experts and organizations that have been working diligently in these fields."

Facebook first launched Beacon in November of 2007 as part of a new marketing strategy intended to benefit both advertisers and and Facebook users (more of the former than the latter). A number of companies signed up to be part of the program, meaning that any user activity that took place on their respective websites would be reported back to Facebook and published to users' timelines. Because Beacon was originally set up as an opt-out service instead of opt-in, many users were horrified to find their off-Facebook activities being published to their profiles automatically. Not only did users feel that their privacy was being violated, a number of users complained loudly that Beacon had ruined numerous surprise holiday gifts.

A few weeks after the initial backlash, Facebook founder Mark Zuckerberg posted an apology. He admitted that the company should have handled Beacon differently and said that the default settings had been changed so that publishing off-Facebook activities to users' news feeds would now be off. Instead, users could now opt in on a per-incident or per-site basis.

That didn't stop a class-action lawsuit from being filed in April 2008, alleging that Beacon and Blockbuster (one of Facebook's marketing partners) were in violation of numerous privacy laws by reporting user activity back to Facebook. The complaint said that off-Facebook activities were still being reported back to Facebook (even if users choose not to publish the info), and that Blockbuster's participation constituted a violation of the Video Privacy Protection Act—a law that prohibits video providers from allowing third parties to access identifiable information about someone's renting or buying habits without their express, written consent.

That lawsuit has been making its way through the court system for more than a year and Facebook apparently realized that it wasn't going to win anytime soon. As a result, the company decided to settle, proposing the $9.5 million settlement fund go towards the creation of an independent foundation that would "fund projects and initiatives that promote the cause of online privacy, safety, and security."

Despite Facebook's positively spun PR speak, it's clear that the company has learned a lesson from the calamity that was the Beacon experience. Everything about Beacon's rollout was done poorly, which then tainted the service forever despite Facebook's desperate attempt to right its wrongs. It took a major class-action lawsuit and the launch of an entirely new service (Facebook Connect) for the company to pull the plug on Beacon, but Facebook has learned the hard way that it earned its users by being conscious of privacy (at least compared to MySpace), and that it needs to continue giving users control if it wants to continue growing.

By Jacqui Cheng

Monday, 21 September 2009

Saturday, 19 September 2009

Why virus writers are turning to open source


Malware developers are going open source in an effort to make their malicious software more useful to fraudsters.

By giving criminal coders free access to malware that steals financial and personal details, the malicious software developers are hoping to expand the capabilities of old Trojans.

According to Candid W?est, threat researcher with security firm Symantec, around 10 percent of the Trojan market is now open source.

The move to an open source business model is allowing criminals to add extra features to their malware.

"The advantages are that you have more people involved in developing it, so someone who is into cryptography could add a cryptographic plug-in or somebody who does video streaming could add remote streaming of the desktop," W?est said.

Releasing Trojans as open source dates back to 1999, when the Cult of the Dead Cow group released the source code for its Trojan called Back Orifice.

More recently, the developers of the Limbo Trojan published its source code in an effort to boost take-up following a slump in its use by fraudsters.

Following its release in 2007, the Limbo Trojan became the most widely used Trojan in the world but fell from favor in 2008 after the more sophisticated Zeus Trojan was released, according to security company RSA.

There is a big cash incentive to be the dominant Trojan, with infected machines and the financial and personal details they capture worth millions of dollars on the black market. The Limbo Trojan kit was previously sold to fraudsters for $350 per time before it went open source, while the Zeus Trojan today sells for between $1,000 to $3,000.

"It is a move to the same business model as that behind any open source project--to give away a basic version and sell more advanced versions, professional services or customizations."
--Uri Rivner, RSA


However, head of new technologies at RSA, Uri Rivner, said the move to become open source had not reversed Limbo's decline in fortunes.

"It is a move to the same business model as that behind any open source project--to give away a basic version and sell more advanced versions, professional services or customizations.

"At the beginning of it going open source it was big news but people have since stopped investing in it.

"It is not the best Trojan any more but because it's open source you can try it as your first Trojan and it is still used in some places," he said.

Limbo's popularity continues to slump, despite numerous features in the basic version that allow criminals to add extra fields for PIN numbers into fake banking websites and capture the keystrokes and the files saved on an infected computer.

And while open source may not have boosted Limbo's fortunes, it also brings with it separate problems for the fraudsters: open sourcing code also places it in the hands of security professionals.

"If you make (the Trojan) open source, that means that a security company can find the source code and it is easier to make a general heuristic detection for it, as they know what could be in it," Symantec's W?est said.

The majority of Trojan infections occur via drive-by downloads, where the malware is automatically downloaded after browsing an infected website, or messages sent via social networking sites that encourage people to download a Trojan masquerading as a legitimate security update, according to RSA's Rivner.

These infection methods are proving far more effective at getting Trojans onto machines than earlier techniques such as sending an e-mail with a link to an infected file or attachment.

RSA analysts say these new methods have fuelled an exponential growth in the rate of infection, with the security firm detecting 613 Trojan infections in August 2008 compared to 19,102 in August 2009.

Nick Heath of Silicon.com reports from London.