Showing posts with label Security Threat. Show all posts
Showing posts with label Security Threat. Show all posts

Tuesday, 8 May 2012

Phishing Attempt on Amazon Accounts

Just the other day, I received an email supposedly coming from amazon, saying my order is successfully cancelled. The truth is, I do not know what the email is all about. I did not ordered anything from amazon this month yet. I do have an amazon account but from another email provider! It was dodgy and made me doubtful.

The email sender is from order-update@amazon.com. It sounds legitimate at first thought, but the email itself is just plain and not even in rich-text format. There is not a single amazon logo or any graphics related to amazon. Both accompanying links like the order number (103-977-685) and www.amazon.com at the bottom has the same URL address and redirects the browser to    http://ebookzforsale.com/asking.html


The legitimate automated purchase email response from amazon always comes from digital-no-reply@amazon.co.uk. The true amazon email is always with amazon graphics and logo's that has reference to amazon. All of the hyperlinks are redirected to amazon's domain and subdomains and not to strange sounding addresses.


Whatever the reason the sender of these emails is, one thing is clear, he wants to create problem on you and your computer. I suspect that this is more of a trojan attack, to infect the recipient's machine and to create more problems later on. Trojan attack is serious, as this is like a thief that have sneaked into a house and just waiting for an opportunity to open up the back door so that other bad elements can go inside the house and join him create havoc or steal anything within!

If you have received any letter from order-update@amazon.com, or any sender with similar emails, not only those supposedly coming from amazon, telling you that your order is cancelled but you know you did not ordered any, just delete the email.


Below is the discussion from amazon users that have received the same email. Read what they think at

http://www.amazon.com/Amazon-sent-me-order-update-/forum/Fx1CZJV4VBZQPY0/Tx9WBN35EX0FL/1?_encoding=UTF8&asin=B002GPPPS4

Sunday, 15 January 2012

How to Secure Online Passwords Against Hackers

Hackers are everywhere but almost impossible to pinpoint their exact whereabouts. They are so discreet that users are unaware they are prying on what we do online. Your usernames and passwords can not elude the malicious codes they let loose, with the purpose of using your online account, from email, social networks, network online stores, and online banks. They create an expensive problem within the internet community, specially at online banking and internet shopping. 


Key Logging

One of the methods that hackers use to see what you are doing online, read your emails, steal passwords, steal bank details, or simply hack your account. is keylogging. The principle of this is to record every keystrokes you make and transmit this to the hacker.

Hackers  can install a keylogging hardware with keylogging software on it  in the form of a USB stick, mouse or keyboard jack, or anything that looks harmless. And once installed, the software within can record every keystrokes you make then these recordings will be transferred to the hackers either by retrieving the device or automatic forwarding the information into their email or server.




They can also remotely install the keylogging software by tricking you into clicking on a link that has the keylogging program attached, and do the same result.


Countermeasures



Banking software knows about this activity that they urge users to install a security software from their own banks. Some banks use password random input as an added protection. It asks you for a specific character on your password or user log in. Others have online virtual keyboard added into their sites. Rather than typing into the physical keyboard, they can just click on the screen to type in. Other banks  uses software security like rapport as an added security measure for their banking clients. The software can watch out for attempted screen capture while doing online banking. You can download Rapport free at:





Ordinary users like us can make use of the virtual keyboard supplied with Windows. To activate the program, go to START, CONTROL PANEL, EASE OF ACCESS, then click START ON SCREEN KEYBOARD


It will then be ready for use. It is more secure for typing on passwords. 


We also need to update antivirus, anti malware programs and anti spywares. They provide another layer of protection against keyloggers. There are free programs out there that can perform well like paid anti viruses. My favourites can be downloaded below.




Super Antispyware at http://www.superantispyware.com/

As there is no single protection from hackers, several measures are needed to counteract them. But sometimes it is simple to avoid this kind of attack by just being sensible on what to CLICK online!




Keylogging Devices

Sunday, 11 September 2011

How To Check If Your Computer is a Part of a Botnet

Is your computer running slowly? Or perhaps it is acting strangely? Is your email sending messages to contacts in your address book? Do your friends  recieve emails from you that you did not send?  This is rather annoying and quite embarrassing especially with messages that contain in appropriate contents, malwares and viruses. 

If this is the case, your computer might have been attacked with a trojan horse or other computer viruses which in effect turned your machine into a computer "robot" or bot that  have been set up to forward transmissions (including spam or viruses) to other computers on the internet. Your zombie computer then serves the wishes of some master spam or virus originator.  Most computers compromised in this way are home-based. 

How do you know if you are a part of a bot net? 
Botnetchecker.com lets you check if your computer has been detected in a sort of a trap set to capture the IP addresses of computers spotted exhibiting botnet-like behaviour. The site reads your IP address (as all websites do, including prakticality) as you visit http://www.botnetchecker.com and compares it to list of recently trapped bots. If nothing is found, it will give you a "no activity detected" message (screen shot below).


If your IP address has recently flagged, BotNetChecker.com will let you know so you can address the issue.

 So it is really a good idea for your firewall and other security protections to be active while online. Antiviruses like AVG and Avast have free versions that are excellent in providing peace of mind when it comes to viruses, trojans,  malwares, rootkits, and other internet nasties protection.


Saturday, 25 June 2011

Email Scams

Since the birth of the internet especially emails, these bugs from the web keep on sprouting like mushrooms after a thunder storm. But unlike the real mushrooms, they just pop out without any warning. The main reason of any of these is money. They want your money by luring you into letting them know your bank details. And when they get hold of your account's data, your pocket ends up busted and sometimes beyond negative balance without you knowing.

Money Mails

Email is the favourite medium. The sender might be somebody familiar (your friends email address which became zombie accounts for the scammers) or names never heard at all, saying something about a large sum that needs to be collected and looking for an associate (that's you) to do this. They talk about God, their dying situations, struggles, everything that will make you feel good about themselves even you haven't met them yet.



What to do?

Ignore or play with them like the scambaiters are doing, making the scammers suffer for what they have started. See hilarious stories of failed scams at  http://www.419eater.com/  , the photos of those sending you scams at http://forum.419eater.com/forum/album.php   and if you want videos, keywords are, scam baits, scambaiters, scambaiting on you tube.

Phishing

 Phishing emails are more of a threat as they send it with a spoof email addresses ( legitimate bank email addreses), which is quite easy to do and sometimes come with a fee.  Just google hoax email or spoof email and it will give you sites that can make you send emails from your favourite superstar or bank account like  http://www.hoaxmail.co.uk/ . The idea of phishing is to lure you to log in into your bank account by giving you a hoax landing pages. And when you type in your information, the details will be saved in their servers and then you will be transferred  to the legitimate site using a URL forwarder to make it not very obvious that they have your log in details already.

List below comes from my fairytale bank accounts and mortgage provider.


When you open up your email and click on the link with in it, you will be redirected to a site which might be similar to the login page of your bank but of different URL address(web address).

Taking for example, the second email on my Phishing Attempt collection, the email address is legitimate, but the landing page of the link and the real URL address of the link is of a different address. On this letter, the sender wants me to go to http://1url.com/ubg  which is very different.

How to see the real URL landing page? If you are using Mac or a PC, just hover your mouse over the link and the link will be shown at the left bottom corner, If it does not show, try right clicking it and then copy location then paste it to a note or any word processor. Right click in Mac is to hold the ctrl button while clicking.

As the link is more than a year ago and the sender uses a subdomain, his sub-domain account "ubg" under the domain 1url.com is no longer working, expired or might have been taken down with complaints. 

Another example is the tax refund from the HRM revenue which looks like legit but the link is not, and wants me to go to  http://www.frenstravel.com/UserFiles/File/zlo.php 

Like the above link, the subdomain is already taken down.


The sender keeps sending me about refunds but I just do not bite on his bait.


What to do?

If you receive emails of this nature, it is wiser to forward it to the corresponding bank account so they can make an action straight away, rather than logging into it. Or just ignore it, if your bank wants to talk to you and inform you about something important, letter is their best medium that's true with the tax man as well.

I thought these scams are already declining but I heard a similar story from a friend a while ago, and this made me alarmed that they are still on, and even the savvy internet users might be lured into it. Warning guys, if you want to log in to your bank account, just type the address in your address bar, do not rely on links!
google.com, pub-9356159227116695, DIRECT, f08c47fec0942fa0

ShareThis

Popular Posts