Now a days fake anti-virus software (scareware )distributors are offering 'Online Support' to convince their victims to steal their valuable data including credit card information. This was discovered by Mr. Nicolas Brulez of Kaspersky that the scareware distributors are now offering actual live support. Users installing fake anti-virus software Security Master AV and clicking on the 'Online Support' button are directed to a chat window in which they can put questions directly to the scareware 'vendor'. As a special offer, the 'support team' offers a one-day trial version of the full product, which reliably removes the imaginary malware identified by the 'demo' version from the user's system. Debora Brown, Kendra Grace and David Lee appear to have all the time in the world online to convince victims in fluent English that their software is genuine and to get them to install the bogus full product. Alternatively, victims can call them up, or send an email. It is suspected that the extra-helpful scareware distributor is located in Russia or the Ukraine. The FBI recently charged three men accused of extracting around $100 million from internet users in more than 60 countries.
Cyber Security Tips N Tricks describes various tips and tricks about cyber security, safe surfing, ethical hacking, network security, Internet, news related to software, hacking, security breaches, vulnerabilities, phishing, google, yahoo, CERT, US CERT, security agencies, etc.
Monday, July 19, 2010
Beware about Scareware Software Live Supports
Now a days fake anti-virus software (scareware )distributors are offering 'Online Support' to convince their victims to steal their valuable data including credit card information. This was discovered by Mr. Nicolas Brulez of Kaspersky that the scareware distributors are now offering actual live support. Users installing fake anti-virus software Security Master AV and clicking on the 'Online Support' button are directed to a chat window in which they can put questions directly to the scareware 'vendor'. As a special offer, the 'support team' offers a one-day trial version of the full product, which reliably removes the imaginary malware identified by the 'demo' version from the user's system. Debora Brown, Kendra Grace and David Lee appear to have all the time in the world online to convince victims in fluent English that their software is genuine and to get them to install the bogus full product. Alternatively, victims can call them up, or send an email. It is suspected that the extra-helpful scareware distributor is located in Russia or the Ukraine. The FBI recently charged three men accused of extracting around $100 million from internet users in more than 60 countries.
Sunday, December 28, 2008
90 Percent of emails received Worldwide are SPAM
90 Percent of emails received Worldwide are SPAM
A recent survey has found that 90 percent of the emails sent to a person’s inbox are usually spam. 90pct of emails received worldwide are spamThe survey report suggests that more and more hackers are devising new ways to send in spam emails, reports the China Daily.
It further states that virus-infected computers are woven into “botnets” used to attack more machines, and to send sales pitches to e-mail addresses in low-cost quests to bilk readers out of cash.
“Every year we see threats evolve as criminals discover new ways to exploit people, networks and the Internet,” Cisco chief security researcher Patrick Peterson, who was involved in drafting the report, said.
According to the Cisco Annual Security Report, junk e-mail make up for nearly 200 billion messages daily, approximately 90 percent of email worldwide.
As per the survey, the US is the biggest source of spam, accounting for 17.2 percent messages.
Turkey and Russia ranked second and third, accounting for 9.2 percent and 8 percent spam respectively, according to Cisco.
This year, botnets were used to inject an array of legitimate websites with an IFrames malicious code that reroutes visitors to websites that download computer viruses into their machines.
“The botnet is, in many cases, ground-zero for online criminal threats,” Peterson said.
“Using malware to infect someone's computers is an incredibly common mechanism and harnessing them all together is a way they do their click fraud, spam emails, and data stealing,” he added.
Online criminals are turning botnets on web-based e-mail accounts. Hackers are "reputation hijacking" by using botnets to figure out weak passwords protecting web-based e-mail accounts, according to Peterson.
Weak passwords consist of family names, birthdays, home addresses or other terms considered relatively easy to deduce.
Once access is gained to legitimate e-mail accounts, a plethora of spam messages are sent in the owners' names.
Source: ANI
Tuesday, November 4, 2008
Beware of debit card skimmers
card at a gas pump because there’s no way to be sure it hasn’t been
tampered with.
By Herb Weisbaum
MSNBC
Becki Turner got the call from her bank’s fraud department on Labor
Day. The investigator wanted to know if she had withdrawn $500 from an
ATM in California over the holiday weekend. She hadn’t. She couldn’t.
Turner was home in Puyallup, Wash.
“I was just flabbergasted,” she says. “I had the card with me, the ATM
was in another state, and the person using the machine had to have my
security code.” Turner worried crooks had gotten into the banking
system and stolen her password.
It wasn’t anything that complicated. Puyallup police say thieves
snagged her account information — along with the debit card numbers
and PIN codes of hundreds of other people — at two gas stations in the
area.
They did it by installing their own hard-to-spot card reader, called a
skimmer, on top of the card reader built into the pump. The skimmer is
able to grab the account information from the card without interfering
with the legitimate payment transaction.
The crooks used the stolen data to create (or clone) fake debit cards
that were used at ATMs in Washington State over the Fourth of July
weekend and in Northern California on Labor Day weekend. The bad guys
like three-day holidays because it gives them more time to use the
cards before the unauthorized withdrawals are spotted.
“We are looking at a sophisticated, very well-organized group of
individuals,” says Detective Jason Visnaw with the Puyallup Police
Department. When all the victims from these two incidents are
identified, the total loss could reach half a million dollars.
Why steal debit card numbers? “With a credit card you have to go and
buy merchandise and then you have to fence it or pawn it,” Det. Visnaw
explains. “With a debit card, you’re getting cash money.”
This is not an isolated case. Gas pumps are being compromised in
cities across the country. “We don’t view it as an epidemic, but there
are cases open in at least a half dozen states right now,” says Ed
Donovan, spokesman for the U.S. Secret Service. These investigations
are underway in California, Nevada, Pennsylvania, Delaware and
Washington.
Donovan tells me the Secret Service believes some of these crimes are
inside jobs, involving someone at the service station.
Gas pumps are just the latest target
Skimming credit cards and debit cards is not new. Portable card
readers make it possible for anyone to copy the information stored on
a card’s magnetic stripe. This information is not encrypted so it’s
easy to steal.
“You just run it through the skimmer and it has all the information
right there in plain text,” says former White House cyber security
advisor Howard Schmidt. “It’s very easy to imprint that data on
another magnetic strip and use it somewhere else.”
The first skimming cases were reported at restaurants and stores where
dishonest employees ran cards through their reader before ringing up
the sale. As technology improved, the bad guys developed skimmers for
ATMs. Now they’ve added gas pumps.
The skimmers are designed to slip over the real card reader. They can
be hard to spot. And quite frankly, most of us would never look for
something like this anyway. We want to pay and go.
So how do they get your PIN number? They can hide a little camera in
the skimmer or on the pump. It shows your fingers as you type in the
number.
There are also fake keypads that slip over the real keypad that can
transmit the PIN code as you enter it.
In Las Vegas, police have discovered even more sophisticated
technology – wireless transmitters installed inside the pump. “They
can actually sit in the parking lot with a laptop and get real-time
information as victims use their card,” explains Lt. Robert Sebby of
the Las Vegas Metropolitan Police Department. Because there’s nothing
on the outside of the pump, there’s no way you can tell the pump is
compromised.
Not a safe way to pay
Nancy and Jim Tew no longer use their debit cards to pay at the pump —
and for good reason. They both had their debit card numbers stolen at
one of those gas stations in Puyallup, Wash.
Nancy Tew found out about the theft when her card was rejected at the
grocery store. “To my astonishment, I had no money in the bank,” she
said.
The thieves used her account number at ATMs in Hollywood, Calif., to
steal $600. They got $900 from her husband’s checking account. She
tells me it was “totally bizarre and really scary” to be targeted like
that and not even know it.
The Tews now pay for their gas — with cash or debit card — at the
register. That may sound paranoid, but other victims of this skimming
attack tell me they now do the same thing.
Police in Puyallup and Las Vegas now advise residents not to use their
debit card at a gas pump because there’s no way to be sure it hasn’t
been tampered with.
That’s smart advice and here’s why. Debit cards do not offer the same
fraud protection as credit cards. If crook armed with a skimmer snags
your credit card number and uses it to buy things, you can dispute the
charges with the credit card company. You won’t owe a thing while they
investigate.
If the crook grabs your debit card number, he can go to a cash machine
and pull money out of your checking account. It could take days for
the bank to investigate and put that money back into your account.
During that time checks could bounce or you might not be able to pay
your bills. That’s why the only way I pay at the pump is with a credit
card.
Thursday, May 22, 2008
Vulnerabilities in Apple's iCal application
According to Researchers at Core Security Technologies, they have uncovered three vulnerabilities in Apple's iCal application that hackers can exploit to take over vulnerable machines or launch denial-of-service attacks. iCal is a personal calendar application provided by Apple on Mac OS X and serves as a client-side component to a calendar server, allowing users to create and share multiple calendars. It can also be used as a stand-alone application.
The most serious of the bugs is the result of a memory corruption vulnerability that can be triggered if a user runs a malicious .ics (iCal calendar file). The other two are null-pointer errors caused when parsing malformed .ics files, Core researchers wrote in the advisory. Version 3.0.1 of iCal, running on the Mac OS X 10.5.1 platform, is vulnerable, Core researchers wrote.
US Military Botnet - Weapons of Mass Denial
U.S. military is planning to botnet attacks to its enemies computer network. US botnet is a disturbing concept, but next to cluster bombs and cruise missiles it's War Lite. According to Col. Charles W. Williamson III proposes that "...America needs a network that can project power by building an af.mil robot network [botnet] that can direct such massive amounts of traffic to target computers that they can no longer communicate and become no more useful to our adversaries than hunks of metal and plastic. America needs the ability to carpet bomb in cyberspace to create the deterrent we lack." Wow, them's fighting words.In a real war this would all be devastating for the civilian infrastructure, but I doubt it would stop troops from moving or planes from flying or submarines from diving. Perhaps that's the best reason to follow Williamson's advice: Once deterrents are in place, launching an attack only ends up shooting you in the foot.
Source: eweek
Tuesday, September 25, 2007
Indian IT Act 2006 to be reviewed to tackle Cyber Crimes
The proposed amendments would address a number of concerns such as data protection, data theft, e-commerce frauds, child pornography, identity documents theft, privacy issues among others.
The ministry is holding discussions with various stakeholders to evolve the amendments, a senior official in the Department of Information Technology said. "Discussions are being held with the stakeholders including private companies, CBI and other investigative agencies," the official said. DIT would put the draft act for public comments once the review process is over.
"The law pertaining to IT should be self-containing and easily comprehensible to the global village community. Despite the experience gained in about seven years in the administration of the IT Law, no effort has been made to bring a new and exclusive legislation," the Standing Committee on Information Technology said in a report.
The Committee observed that the term 'cyber terrorism' has not been defined anywhere in the IT Act, 2000 or in the proposed amendments. Similarly, 'child pornography' has also not been mentioned anywhere in the section on pornography.
"In view of the several manifestations of sexual abuse of children and its loathsome ramifications, the Committee desires that the act of grooming the child for sexual relationship through online enticement or distributing/showing pornography or through any online means should also be made a criminal offence," it said.
Noting the complex language of legislations on monitoring the cyber space, the Parliamentary panel which was constituted to look into the proposed changes in the IT Act 2000 (which is in the form of Draft IT Act 2006), had criticised the government for not preparing a new set of laws and instead taking a "short-cut route" of making changes in the existing norms.
Source: PTI
Friday, September 7, 2007
Pentagon Computer Hacked Into By Chinese
in the most successful cyber attack on the US defense department, say
American officials.
The Pentagon acknowledged shutting down part of a computer system
serving the office of Robert Gates, defense secretary, but declined to
say who it believed was behind the attack.
Current and former officials have told the Financial Times an internal
investigation has revealed that the incursion came from the People’s
Liberation Army.
One senior US official said the Pentagon had pinpointed the exact
origins of the attack. Another person familiar with the event said
there was a “very high level of confidence...trending towards total
certainty” that the PLA was responsible. The defense ministry in
Beijing declined to comment on Monday.