Cyber Security Tip & Tricks
Showing posts with label e-mail. Show all posts
Showing posts with label e-mail. Show all posts

Sunday, December 28, 2008

90 Percent of emails received Worldwide are SPAM

90 Percent of emails received Worldwide are SPAM


A recent survey has found that 90 percent of the emails sent to a person’s inbox are usually spam.  90pct of emails received worldwide are spamThe survey report suggests that more and more hackers are devising new ways to send in spam emails, reports the China Daily.
 
It further states that virus-infected computers are woven into “botnets” used to attack more machines, and to send sales pitches to e-mail addresses in low-cost quests to bilk readers out of cash.
 
“Every year we see threats evolve as criminals discover new ways to exploit people, networks and the Internet,” Cisco chief security researcher Patrick Peterson, who was involved in drafting the report, said.
 
According to the Cisco Annual Security Report, junk e-mail make up for nearly 200 billion messages daily, approximately 90 percent of email worldwide.
 
As per the survey, the US is the biggest source of spam, accounting for 17.2 percent messages.
 
Turkey and Russia ranked second and third, accounting for 9.2 percent and 8 percent spam respectively, according to Cisco.
 
This year, botnets were used to inject an array of legitimate websites with an IFrames malicious code that reroutes visitors to websites that download computer viruses into their machines.
 
“The botnet is, in many cases, ground-zero for online criminal threats,” Peterson said.
 
“Using malware to infect someone's computers is an incredibly common mechanism and harnessing them all together is a way they do their click fraud, spam emails, and data stealing,” he added.
 
Online criminals are turning botnets on web-based e-mail accounts. Hackers are "reputation hijacking" by using botnets to figure out weak passwords protecting web-based e-mail accounts, according to Peterson.
 
Weak passwords consist of family names, birthdays, home addresses or other terms considered relatively easy to deduce.
 
Once access is gained to legitimate e-mail accounts, a plethora of spam messages are sent in the owners' names.
 
Source: ANI

Saturday, December 27, 2008

Take precaution against Cyber Theft - During this Holidays


  1. Be wary of holiday gift cards and holiday coupon offers sent via e-mail—these often have malicious links within the offer which lead to downloads of info-stealing Trojans or the hackers try to scam you out of your bank account information.
  2. When visiting your favorite online retailer to purchase gifts, be sure to type the actual Web site address of the retailer into your browser. Do not follow links provided by e-mail offers or pop up ads. Many times these are fraudulent sites made to look like the legitimate retail sites.
  3. When making online purchases, always use a credit card that limits your fraud liability. Avoid using debit cards to do online purchases when possible so as to limit your personal exposure to any possible fraudulent transactions.
  4. When making online purchases, always look at your Web browser for the https (as opposed to http) protocol that proceeds a Web address. The “s” let’s you know that the Web site is providing a layer of security for transmitting your personal information over the Internet.
  5. Be wary of unsolicited e-mails, even from senders that you know, that include links or attachments. Before clicking on links or attachments, ALWAYS verify that the correspondent sent you the e-mail and enclosed link or attachment.
  6. Be wary of e-mails notifying you that your banking certificate or token is out of date and to download a new certificate or token. Before taking any action, verify with your financial institution by calling them on a number that is not provided in the email.
  7. Avoid using simple (weak) or default passwords for any online site.


Tuesday, July 24, 2007

iPhone Hacked Successfully - Security Firm Says

iPhone Hacked Successfully - Security Firm Says

A vulnarabilty has found in the Apple Inc.'s iPhone handset that can help an attacker to gain access to the private data stored on it. This flaw has found by a team of security expert of Independent Security Evaluators (ISE). Hackers could gain access to the iPhone through a wireless access point or through a website controlled by the attacker. This was the first major security incident reported.

Numerous hackers have been working to gain access to the iPhone in order to activate certain features or to allow it to be used on cellular networks other than AT&T Inc.'s. However, this is the first major exploitation of an iPhone security flaw.

The expolit is delivered via a malicious web page opened in the Safari browser on the iPhone, ISE said on its Website. There are several methods that an attacker utilize to get a victim to open such a webpage.

1. An attacker controlled wireless access point:

The iPhone connects to wireless Internet access networks, such as Wi-Fi, an attacker could create a network with the same name and encryption method as one the handset already uses. The attacker could then substitute a Web page with exploit code to gain access to the phone.

2. A misconfigured forum website:

A link planted on an unedited or unmoderated online forum, an attacker could cause the exploit to run in any iPhone browser that viewed the thread.

3. A link delivered via e-mail or SMS:

A link sent by SMS or e-mail to use make use of the flaw and gain access to the handset.

The ISE said that when the iPhone's Safari browser opens a malicious Web page, malicious code can be run on the phone via the flaw, allowing the attacker to read the iPhone's SMS log, address book, call history, and voicemail information, which are also then sent to the attacker. It could send the user's mail passwords to the attacker, send text messages that sign the user up for pay services, or record audio that could be relayed to the attacker.

Source: nytimes

Friday, June 1, 2007

Internet Spam King Robert Soloway, 27 was arrested by US Police


A man nicknamed the "spam king" for allegedly sending out millions of junk e-mails has been arrested in the US.
Robert Soloway, 27, was arrested in Seattle, Washington, after being indicted on charges of mail fraud, identity theft and money laundering.
Mr Soloway allegedly sent millions of e-mails on hijacked computers. Using computers secretly infected with orders to send out millions of his e-mails. Such computers are known as "zombies" because their owners often have no idea they have been hijacked for another purpose.

According to prosecutors, Mr Soloway was responsible for tens of millions of unsolicited e-mails promoting his own company between November 2003 and May 2007.
He is said to have frequently changed the web address of his internet marketing business to avoid being caught.
A US lawyer said Mr Soloway was the first person to be prosecuted for sending out spam e-mails using federal laws against identity theft.
Prosecutors want to seize the sum of $773,000 (£391,000) that Mr Soloway is said to have made from his firm.
If convicted of all the charges, he also faces a fine of $250,000 (£126,500) and a maximum prison term of 65 years.


Video on Robert Soloway Arrest.
Source: BBC News

AddThis Social Bookmark Button

Recent Comments