Thursday, August 12, 2010

WHEN A ROBBER WAIT AT THE ATM


FIGHTING CRIME AT THE CASH MACHINE

Not much stands between you and a crook at a cash machine, but security measures such as alarm buttons and secret codes might actually make you less safe.

Your odds of getting robbed at an ATM are about the same as the chance you'll die of falling out of a tree.

So ATM's are really safe, right? Maybe yes, maybe NO

On a deserted street in an unfamiliar part of town, though, your antennae naturally go up, and for good reason. It seems inevitable that where there's cash, there's crime, even if the odds of getting hurt are apparently slim. The closed-circuit TVs and video cameras common at ATMs don't prevent crime so much as document it for trial

For victims -- such as a man recently robbed, bloodied and left with a shoeprint on his forehead -- those slim odds are no comfort. And efforts to arm ATMs with panic buttons and secret PIN codes not only have gone nowhere, they might actually backfire if implemented.

In the end, you're on your own at the ATM, armed with common sense.

An incomplete picture

ATM's are placed on sites where demand is greatest. Each year, the network of cash machines in the countries logs about 14 billion transactions -- or about $1 trillion worth.

"As a whole, they're very safe and very convenient," says Kurt Helwig, the president of the Electronic Funds Transfer Association, a trade group based in Fairfax, Va., that promotes adoption of electronic payment systems.

Violent crime at ATMs appears to be uncommon. How uncommon? on whether panic buttons and secret codes are good ideas for improving safety.

The researchers came to no conclusions. They pointed out that the only statistics on ATM crimes were sketchy, with most of the data coming from old banking industry surveys.

The surveys cite low odds --- one in 1 million to one in 3.5 million -- that you'll be robbed at an ATM. But those odds are probably useless. Without knowing how the research was done, their reliability is impossible to assess,

The real problem is, nobody is carefully tracking violent crimes being committed at ATMs,. "There's no government agency at the federal or state level that's doing it. The Authorities collects some data on bank robberies, but those data would not tell you what you want to know."

Robbery versus fraud

That's in part because crime statistics usually fail to distinguish between ATM robberies and fraud, which is another (and much bigger) issue.

Also, when police tally up robberies and kidnappings, they don't typically note whether an ATM was involved. For example,a woman was abducted from her working place and forced by a stranger to drive to an ATM and withdraw cash. That crime is likely to be counted as a kidnapping, not an ATM robbery.Now how would police decide what qualified as ATM robberies? Would they count only holdups that occurred as customers withdrew money? Or would they include robberies that occurred after customers left the ATMs? If so, how far from the machines?


ATM robberies probably aren't widespread; if they were, there'd be a national hue and cry. In at least a couple of larger cities, police say they have worse things to worry about.

A worse problem, is ATM card thefts. Crooks also steal the PINs or figure them out, and then use the cards to loot bank accounts.


Thursday, July 8, 2010

PIRATES


Like I did promised you,I will be rolling out article series on the threat of cyber crime on your business,also check out more articles on the article page.....Enjoy reading

Members of a transnational telephone hacking scheme were indicted in New Jersey,few months ago. These individuals, many based in the Philippines, were accused of unauthorized entry into the telephone systems of major U.S. businesses and other entities and of attempting to sell information about these vulnerabilities to Pakistani nationals residing in Italy. The arrests and indictments were the result of a three-year investigation that included a high degree of cooperation and coordination among many affected US businesses and foreign entities.

The most tempting, untapped markets can have significant security challenges. Perhaps the most tempting markets are those where technological pirates and privateers dominate. These are not pirates that plunder the high seas, nor are they privateers given ships and commissioned by royalty. These technological scallywags constitute very real threats to the multinational corporation. Personal identifying info - PII, is a deliberate target of cyber criminals, members of criminal organizations and foreign governments. These cyber criminals obtain sensitive Private info for profit. They perceive corporations as galleons - giant, slow ships filled with a vast stockpile of assets; they seek to overtake the ships to take as much as they can before being identified or captured. They vanish as suddenly as they strike using the anonymity of the Internet for mobility, masking their trails and escaping to reemerge another day in another guise.

The need for protection against cyber crime is great, especially considering the PII and financial transactions which corporations and financial institutions manage on a daily basis. Cyber criminals, members of criminal organizations, and potentially foreign governments all specifically target PII.

Unless current cyber crime legislation is modified to permit virtual "self defense" against these pirates, business to business e-commerce in lawless areas is likely best conducted via VPNs. In areas with minimal security and law enforcement capabilities, this method of self protection is critical. Current cyber crime legislation around the world does not address virtual "self defense." Most existing cyber crime legislation is broad, and does not yet distinguish among attacks based on intent. Unless current legislation is changed or modified, using VPNs and security awareness training are likely the best option for operating in unstable areas.

Businesses, particularly those in the financial sector, are facing the challenge of ensuring self-protection within legal bounds that do not drive away their clientele. The balance between customer service and Internet security is delicate.

Monday, July 5, 2010

IS CYBERCRIME A THREAT TO YOUR BUSINESS ?


Welcome back. I will be starting an article series on how cyber crime could be a threat to your business

The need for protection against cyber crime is ever increasing, especially considering the volume of personally identifiable information (PII) and financial transactions which corporations and financial institutions manage on a daily basis. Moreover, cyber crime is often a transnational threat, creating even more difficulty for law enforcement to pursue cyber criminals. The added complexities of international inconsistencies with respect to laws pertaining to PII exacerbate the problem, and current cyber crime legislation in key areas around the world currently does not permit virtual self defense.

Data protection law has been the subject of an increasing number of jurisdictional disputes, which have largely been driven by the ubiquity of the Internet, the interconnectedness of the global economy, and the growth of data protection law around the world in recent years.

There are also an increase Artwork: A number of instances where data protection law conflicts with legal obligations in other areas. Moreover, the rapid development of new computing techniques (such as so-called 'cloud computing') is putting even greater pressure on traditional jurisdictional theories. Jurisdictional uncertainties about data protection law have important implications, since they may dissuade individuals and companies from engaging in electronic commerce, can prove unsettling for individuals whose personal data are processed, and impose burdens on regulators. These difficulties are increased by the fact that, so far, there is no binding legal instrument of global application covering either jurisdiction on the Internet or data protection.

This discussion is restricted to traditional crimes committed through virtual means and the implications of potential solutions. This articles address how corporations and financial institutions can conduct e-commerce in areas with minimal security and cyber law enforcement capabilities and also discuss the question of which areas and organizations are most often targets of cyber crime and which attackers pose the greatest threat to e-commerce is also discussed.

We will continue from here next time...............................

Wednesday, June 30, 2010

FACEBOOK AND THE LOW HANGING FRUIT

There is a continued effort afoot to get people to quit Facebook over privacy concerns.

If you didn't know it, May 31 was actually dubbed "Quit Facebook Day" and over 30,000 people quit using Facebook and cancelled their accounts.

The user base for Facebook is estimated by some to be over a half billion users. I don't think too many of them knew about Quit Facebook Day.

If anything manages to kill Facebook, it will not be privacy concerns. It will be scams on its naïve users.

Right now nobody is quitting Facebook. And if they do quit they will probably be back.

I, for one, decided never to join Facebook in the first place. It seemed like a slicker MySpace targeted at people who cannot figure out how to get an online presence any other way. But I should use it anyway

Because of the huge number of people using Facebook, it has actually become a viable sub-platform where people can take care of much, if not all, of their online business. They can message people, do email, status updates and keep tabs on their friends and events.

MySpace has a similar sub-platform status, at least for a while.

The dark side of all this is that most Facebook users have settled comfortably in with this platform, and have become targets for cybercriminals. Sitting ducks, as it were.

The fact is that a classic Facebook user has no long-term online experience.

Over the past two weekends, various scams aimed at the hapless Facebook users have emerged and now it is believed that Facebook and its users will be the number one fraud target in the months ahead.

The initial salvo comes from what are known as rogue apps that run on Facebook and infect the user's computer with various levels of malware. The tamest of these are pop-up ads that inundate the user with offers and deals.

In the worst case scenario the user clicks on something and ends up getting a Trojan Horse downloaded on to the machine. A Trojan Horse infection allows outsiders to take over your computer at will to use it for nefarious purposes such as sending spam to others.

Your machine could also become a storage center for pornography, a proxy machine for criminal activity or any number of things you do not want.

Facebook users have become the low-hanging fruit for this sort of effort. Few even know about Trojan Horses, malware, ad-ware, any of it. They do not read computer magazines and few actually explore the information on the web to any extent. So they have no real way to find out about the problem.

Worse they are susceptible, like all naïve users, to fake alerts and online notifications which are scams unto themselves.

None of this bodes well for the future of a company that probably should be public already. The potential for a remarkable initial public offering for Facebook is limitless.

In fact, the company should have already gone public and the financiers of the operation have to wonder why it has not happened.

In the meantime, as the worldwide scamming network of schemers, phishers and fraudsters gravitate towards Facebook and its users, the operation is now at risk.

What makes it worse is that Facebook commercial orientation has always been based upon the idea that users like to share information about what they do and what they like in hopes that advertising revenue can be obtained by exploiting this milieu of frankness.

What if I never said any such thing and what if the coupon is a link to malware? You click on it and you and your machine are compromised.

This is no laughing matter and such hacks may become the downfall of the service and the downfall of many advanced concepts developed to exploit social networking.

Meanwhile, a killer IPO is going by the wayside as time is running out. Tick tock.


Thursday, June 24, 2010

WORM USES GOOGLE TO SQUIRM AROUND FACEBOOK



A malicious program that sprang up on Facebook.com in late July 2009,has surfaced again, this time using Google's Web sites to sneak around security filters.

Hackers initially unleashed Koobface in late July2009, but Facebook's security team soon slowed its spread by blocking the Web sites that were hosting the malicious Trojan software.

That has prompted the criminals to change tactics. In this latest attack they have hosted files that appear to be YouTube videos on Picasa and Google Reader and used Facebook to send them to victims.

The links appear safe because they go to Google.com Web sites, but once the victim arrives on the Google Reader or Picasa page, he is invited to click on a video or a Web link. The victim is then told he needs to download special code decompression software to view the video. That software is actually a malicious Trojan Horse program, which is blocked by most antivirus programs, according to Facebook.

Lovet believes the cyber-criminals behind Koobface have deliberately misspelled their Facebook messages to further help them evade detection by filters.

"Sommebody uupload a viideo witth you on utubee. you shuold ese," reads one message.

This latest attack use the self-copying worm code that Koobface used last August, but it could easily be added.

Facebook is working with Google to shut down the problem, said Facebook spokesman Barry Schnitt.

Koobface has been a top security concern at Facebook since July.It's been out there constantly, but it's surfaced a little bit more lately.

The worm's creators have used other tricks to try to circumvent Facebook filters. They've used Facebook's instant messaging feature and also hosted their malicious links on sites such as Tinyurl.com and Bloglines.

Nobody knows how widespread this malware really is, but when Koobface first appeared on the scene, Facebook said it was affecting less than 0.02 percent of users. Facebook boasts more than 200 million users; 0.002 percent of that would represent 440,000 users.

Security experts have long warned that the Web 2.0 mash-up model of allowing users to put together their own content from many different sources naturally creates many security problems. In part, this is because it allows anyone to post material on trustworthy domains such as Google.com.

I believe that you will see more of this stuff happening,With corporate Intranets adopting new technologies such as blogging and Wikis, corporate targets may soon be ripe for attack.If you have a worm inside a corporation that works the same way as the worm on Facebook, you have a huge problem.

Sunday, June 20, 2010

BUGNETS COULD SPY ON YOU VIA MOBILE DEVICES


Imagine sitting in a café and discussing the details of a business proposal with a potential client. Neither you nor the client has a laptop; you're just two people having a conversation. But unknowing to you, someone half a world away is listening to every word you say. Later, as you leave, you receive a text message referring to the proposal and demanding money in exchange for silence.Andy PottsRecent research from two universities suggests that such a remote-eavesdropping scenario may soon be possible.

According to George Mason University researchers Ryan Farley and Xinyuan Wang, cell phones make excellent surveillance devices for remote snoops. An attacker could control over what they call a "roving bugnet." The eavesdropper would use a piece of malware called a "bugbot" to listen in on in-person interactions via a nearby smartphone or laptop. Such attacks would be more likely to target specific people than to play a role in widespread attacks on the general public.


Mobile Malware on the Rise

Though fewer than 500 pieces of cell phone malware have been written since 2004, there has been an explosion of recent. 95 percent of mobile malware was written for the Symbian OS, but that's changing fast due to the success of Apple's iPhone and Google's Android OS.

Given the relative scarcity of mobile malware,experiments on Windows XP and Mac OS laptops, directing bugbot to join an Internet Relay Chat channel shows that it is possible to remotely enable and disable each laptop's microphone to stream real-time conversations occurring in the area. The same thing, could be done on almost any smartphone.

Get more INFO on the LATEST THREAT PAGE.



Wednesday, June 16, 2010

FACEBOOK INVASION :BEWARE OF NEW SMART WORM


The Facebook Hijack

First, the hijacking: An organization called "Control Your Info" apparently took control of as many as 300 Facebook groups over the past several days. Members added their own logo onto the pages, announcing they'd "hijacked" the groups and providing a link back to their own site.

(Facebook maintains no confidential information was ever exposed--the affected groups, representatives say, were abandoned and open for any member to take over.)

The "Control Your Info" Web site states that the organization's mission was to expose security holes in social media--a fitting segue to today's new threat.

Facebook's New Concern

The new threat has a familiar name. Koobface--which, by the way, is an anagram of the word Facebook--first popped up in mid 2008 and has been pestering users ever since.

The worm typically works by taking over your PC, then sending messages or wall postings to your friends. The messages include links to what appear to be funny videos or risqué photos of people you and your friends know. Anyone who follows the links, however, will ultimately end up infected with the malware themselves--usually by way of a bogus software update that pops up on-screen.

The updated Koobface variation, according to the virus-fighting team at Trend micro, takes things a step further by automating the entire process. Instead of depending solely upon real accounts to spread the malicious links, the attackers have found a way to have bots do their bidding.

Here's how Trend Micro says it's happening: Botnets are registering new Facebook accounts and confirming them via accompanying Gmail addresses, all without any human interaction. The zombie accounts are then joining Facebook groups, adding friends, and posting dangerous links onto those people's walls.

"This new component behaves like a regular Internet user that starts to connect with friends in Facebook," explains Jonell Baltazar, an advanced threats researcher with Trend Micro. "The details provided about the account are complete such as a photo, birth date, favorite music, and favorite books."

The system is even advanced enough to monitor maximum friend levels allowed by Facebook, to avoid drawing any attention to the ill-intended account.

Facebook Protection

So, what can you do to keep yourself safe from this Koob-faced villain? The steps are nothing you haven't heard before: Keep your antivirus software up to date, and use some common sense.

Antivirus software will alert you if you click onto a site that's known to host malware -- and that's exactly where these Koobface links want to take you. The easiest way to stay safe, then, is just to be cautious in choosing what you click.

If you see a link that looks questionable, even if it's from someone whose name you know, don't follow it. And if you find yourself on a Web page that's asking you to download a software update, don't do it. Instead, close the window and go directly to the software vendor's own Web page to see if the update is the real deal.

Otherwise, you might end up with Koob smeared all over your face--and, suffice it to say, that's one fate you'd be better off avoiding.