Wednesday, June 30, 2010

FACEBOOK AND THE LOW HANGING FRUIT

There is a continued effort afoot to get people to quit Facebook over privacy concerns.

If you didn't know it, May 31 was actually dubbed "Quit Facebook Day" and over 30,000 people quit using Facebook and cancelled their accounts.

The user base for Facebook is estimated by some to be over a half billion users. I don't think too many of them knew about Quit Facebook Day.

If anything manages to kill Facebook, it will not be privacy concerns. It will be scams on its naïve users.

Right now nobody is quitting Facebook. And if they do quit they will probably be back.

I, for one, decided never to join Facebook in the first place. It seemed like a slicker MySpace targeted at people who cannot figure out how to get an online presence any other way. But I should use it anyway

Because of the huge number of people using Facebook, it has actually become a viable sub-platform where people can take care of much, if not all, of their online business. They can message people, do email, status updates and keep tabs on their friends and events.

MySpace has a similar sub-platform status, at least for a while.

The dark side of all this is that most Facebook users have settled comfortably in with this platform, and have become targets for cybercriminals. Sitting ducks, as it were.

The fact is that a classic Facebook user has no long-term online experience.

Over the past two weekends, various scams aimed at the hapless Facebook users have emerged and now it is believed that Facebook and its users will be the number one fraud target in the months ahead.

The initial salvo comes from what are known as rogue apps that run on Facebook and infect the user's computer with various levels of malware. The tamest of these are pop-up ads that inundate the user with offers and deals.

In the worst case scenario the user clicks on something and ends up getting a Trojan Horse downloaded on to the machine. A Trojan Horse infection allows outsiders to take over your computer at will to use it for nefarious purposes such as sending spam to others.

Your machine could also become a storage center for pornography, a proxy machine for criminal activity or any number of things you do not want.

Facebook users have become the low-hanging fruit for this sort of effort. Few even know about Trojan Horses, malware, ad-ware, any of it. They do not read computer magazines and few actually explore the information on the web to any extent. So they have no real way to find out about the problem.

Worse they are susceptible, like all naïve users, to fake alerts and online notifications which are scams unto themselves.

None of this bodes well for the future of a company that probably should be public already. The potential for a remarkable initial public offering for Facebook is limitless.

In fact, the company should have already gone public and the financiers of the operation have to wonder why it has not happened.

In the meantime, as the worldwide scamming network of schemers, phishers and fraudsters gravitate towards Facebook and its users, the operation is now at risk.

What makes it worse is that Facebook commercial orientation has always been based upon the idea that users like to share information about what they do and what they like in hopes that advertising revenue can be obtained by exploiting this milieu of frankness.

What if I never said any such thing and what if the coupon is a link to malware? You click on it and you and your machine are compromised.

This is no laughing matter and such hacks may become the downfall of the service and the downfall of many advanced concepts developed to exploit social networking.

Meanwhile, a killer IPO is going by the wayside as time is running out. Tick tock.


Thursday, June 24, 2010

WORM USES GOOGLE TO SQUIRM AROUND FACEBOOK



A malicious program that sprang up on Facebook.com in late July 2009,has surfaced again, this time using Google's Web sites to sneak around security filters.

Hackers initially unleashed Koobface in late July2009, but Facebook's security team soon slowed its spread by blocking the Web sites that were hosting the malicious Trojan software.

That has prompted the criminals to change tactics. In this latest attack they have hosted files that appear to be YouTube videos on Picasa and Google Reader and used Facebook to send them to victims.

The links appear safe because they go to Google.com Web sites, but once the victim arrives on the Google Reader or Picasa page, he is invited to click on a video or a Web link. The victim is then told he needs to download special code decompression software to view the video. That software is actually a malicious Trojan Horse program, which is blocked by most antivirus programs, according to Facebook.

Lovet believes the cyber-criminals behind Koobface have deliberately misspelled their Facebook messages to further help them evade detection by filters.

"Sommebody uupload a viideo witth you on utubee. you shuold ese," reads one message.

This latest attack use the self-copying worm code that Koobface used last August, but it could easily be added.

Facebook is working with Google to shut down the problem, said Facebook spokesman Barry Schnitt.

Koobface has been a top security concern at Facebook since July.It's been out there constantly, but it's surfaced a little bit more lately.

The worm's creators have used other tricks to try to circumvent Facebook filters. They've used Facebook's instant messaging feature and also hosted their malicious links on sites such as Tinyurl.com and Bloglines.

Nobody knows how widespread this malware really is, but when Koobface first appeared on the scene, Facebook said it was affecting less than 0.02 percent of users. Facebook boasts more than 200 million users; 0.002 percent of that would represent 440,000 users.

Security experts have long warned that the Web 2.0 mash-up model of allowing users to put together their own content from many different sources naturally creates many security problems. In part, this is because it allows anyone to post material on trustworthy domains such as Google.com.

I believe that you will see more of this stuff happening,With corporate Intranets adopting new technologies such as blogging and Wikis, corporate targets may soon be ripe for attack.If you have a worm inside a corporation that works the same way as the worm on Facebook, you have a huge problem.

Sunday, June 20, 2010

BUGNETS COULD SPY ON YOU VIA MOBILE DEVICES


Imagine sitting in a café and discussing the details of a business proposal with a potential client. Neither you nor the client has a laptop; you're just two people having a conversation. But unknowing to you, someone half a world away is listening to every word you say. Later, as you leave, you receive a text message referring to the proposal and demanding money in exchange for silence.Andy PottsRecent research from two universities suggests that such a remote-eavesdropping scenario may soon be possible.

According to George Mason University researchers Ryan Farley and Xinyuan Wang, cell phones make excellent surveillance devices for remote snoops. An attacker could control over what they call a "roving bugnet." The eavesdropper would use a piece of malware called a "bugbot" to listen in on in-person interactions via a nearby smartphone or laptop. Such attacks would be more likely to target specific people than to play a role in widespread attacks on the general public.


Mobile Malware on the Rise

Though fewer than 500 pieces of cell phone malware have been written since 2004, there has been an explosion of recent. 95 percent of mobile malware was written for the Symbian OS, but that's changing fast due to the success of Apple's iPhone and Google's Android OS.

Given the relative scarcity of mobile malware,experiments on Windows XP and Mac OS laptops, directing bugbot to join an Internet Relay Chat channel shows that it is possible to remotely enable and disable each laptop's microphone to stream real-time conversations occurring in the area. The same thing, could be done on almost any smartphone.

Get more INFO on the LATEST THREAT PAGE.



Wednesday, June 16, 2010

FACEBOOK INVASION :BEWARE OF NEW SMART WORM


The Facebook Hijack

First, the hijacking: An organization called "Control Your Info" apparently took control of as many as 300 Facebook groups over the past several days. Members added their own logo onto the pages, announcing they'd "hijacked" the groups and providing a link back to their own site.

(Facebook maintains no confidential information was ever exposed--the affected groups, representatives say, were abandoned and open for any member to take over.)

The "Control Your Info" Web site states that the organization's mission was to expose security holes in social media--a fitting segue to today's new threat.

Facebook's New Concern

The new threat has a familiar name. Koobface--which, by the way, is an anagram of the word Facebook--first popped up in mid 2008 and has been pestering users ever since.

The worm typically works by taking over your PC, then sending messages or wall postings to your friends. The messages include links to what appear to be funny videos or risqué photos of people you and your friends know. Anyone who follows the links, however, will ultimately end up infected with the malware themselves--usually by way of a bogus software update that pops up on-screen.

The updated Koobface variation, according to the virus-fighting team at Trend micro, takes things a step further by automating the entire process. Instead of depending solely upon real accounts to spread the malicious links, the attackers have found a way to have bots do their bidding.

Here's how Trend Micro says it's happening: Botnets are registering new Facebook accounts and confirming them via accompanying Gmail addresses, all without any human interaction. The zombie accounts are then joining Facebook groups, adding friends, and posting dangerous links onto those people's walls.

"This new component behaves like a regular Internet user that starts to connect with friends in Facebook," explains Jonell Baltazar, an advanced threats researcher with Trend Micro. "The details provided about the account are complete such as a photo, birth date, favorite music, and favorite books."

The system is even advanced enough to monitor maximum friend levels allowed by Facebook, to avoid drawing any attention to the ill-intended account.

Facebook Protection

So, what can you do to keep yourself safe from this Koob-faced villain? The steps are nothing you haven't heard before: Keep your antivirus software up to date, and use some common sense.

Antivirus software will alert you if you click onto a site that's known to host malware -- and that's exactly where these Koobface links want to take you. The easiest way to stay safe, then, is just to be cautious in choosing what you click.

If you see a link that looks questionable, even if it's from someone whose name you know, don't follow it. And if you find yourself on a Web page that's asking you to download a software update, don't do it. Instead, close the window and go directly to the software vendor's own Web page to see if the update is the real deal.

Otherwise, you might end up with Koob smeared all over your face--and, suffice it to say, that's one fate you'd be better off avoiding.

Monday, June 14, 2010

AFTER GOOGLE'S HACK WARNING'S POP UP IN SEC FILINGS


Five months after Google was hit by hackers looking to steal its secrets, technology companies are increasingly warning their shareholders that they may be materially affected by hacking attempts designed to take valuable intellectual property.

In the past few months Google, Intel, Symantec -- all companies thought to have been targets of a widespread spying operation -- have added new warnings to their U.S. Securities and Exchange Commission filings informing investors of the risks of computer attacks.

Google doesn't talk about the specific attack against its systems, but it now warns shareholders that this type of event is a material risk.

Outside parties may attempt to fraudulently induce employees, users, or customers to disclose sensitive information in order to gain access to data or our users' or customers' data," Google wrote in a section added to its annual financial report in February, a month after it disclosed the hacking incident.

Google warned that it could lose customers following a breach, as users question the effectiveness of its security. "Because the techniques used to obtain unauthorized access, disable or degrade service, or sabotage systems change frequently and often are not recognized until launched against a target, we may be unable to anticipate these techniques or to implement adequate preventative measures," the company said in the filing.

Google's admission that it has been targeted put a public spotlight on a problem that had been growing for years: targeted attacks, known to security professionals as the advanced persistent threat (APT).This attacks are often successful because they are low-volume, fly under the radar of most security companies and are extremely targeted. In many APT attacks, the victim is sent an interesting-looking document or a link to a Web site that contains attack code. If the victim's software isn't up-to-date (Google is thought to have been compromised via a bug in Internet Explorer 6), the criminals break into the computer, gaining a foothold in the company.

In February, Intel disclosed in a SEC filing that it had been targeted by a similar attack in January, and warned investors that the theft of its trade secrets could hurt its bottom line.

Last year, Heartland Payment Systems was sued by shareholders for failing to disclose that the company had been hit by a December 2007 SQL injection attack. Plaintiffs argued that the company should have disclosed the incident in SEC filings and in calls with financial analysts. The December incident was eventually linked to the largest data breach in U.S. history, and Heartland's stock dropped nearly 80 percent when the company finally disclosed the full extent of the attack in January 2009.

Continue your reading on the News page..........Thanks

Thursday, June 10, 2010

SKYPE WORM NO CAUSE FOR PANICK




Security research warned of a vicious virus targeting both Skype and Yahoo! Messenger.The attack involved inserting malicious URLs into chat windows with sophisticated social engineering hooks.

Each time, the messages sent have different contents, examples include "Does my new hair style look good? bad? perfect?" "My printer is about to be thrown through a window if this pic wont come our right. You see anything wrong with it?" The message contains a link to a web page that appears to lead to a JPEG or image file.

The users are more easily tricked into clicking the link by these messages, because users tend to think that their friend(s) a re asking for advice. "If a user clicks the link, his browser will immediately load to a website with Rapidshare-like interface, and a .zip file will be available for download.

The W32.Skyhoo.Worm, as it was named, automatically exits if the victim's computer is not installed with Skype or Yahoo! Messenger and automatically sends messages with different contents containing malicious URLs to user names in the Skype/Yahoo! Messenger friend list of the user. while this virus is targeting Skype, it's really social engineering and awareness that need to be considered.

If I can get you to install anything I own the system and the applications, it does not matter which app. The fact this is taking advantage of Skype is secondary or almost moot. Skype has APIs and functionality that allows this to be used. If Skype wants to change the code to prevent this from happening they may break or disable functionality they actually wanted to provide.

In other words, don't knock Skype for this attack. Instead focus on awareness among users if you are using Skype in the workplace and give them a warning about social engineering rather than worrying about the application's security.

This is actually just another social engineering attack. The user has to be fooled into downloading and installing a piece of malware. So really it is not attacking Skype, it is trying, in many cases successfully to fool a user to provide access and then use an application, in this case Skype to proliferate more social engineering."

Tuesday, June 8, 2010

UNIVERSITY OF OSUN -NIGERIA PARTNERS MICROSOFT

The war against cyber crimes has been given a boost in Osun State - NIGERIA . At the just concluded annual conference of Association of Vice-Chancellors of Nigeria Universities (AVCNU) the management of Osun State University (UNIOSUN) entered into a charter with the world computer giant, Microsoft.

Tagged ‘Saying No to Cybercrime’, the signing of Internet Safety Security and Privacy Charter was aimed at correcting the notorious image of Nigeria as the third in the global list of cyber crime perpetrators.
Apart from UNIOSUN, the charter was also expected to be entered into by all the universities in the country, be it government-owned or privately established, as well as the National Universities Commission (NUC) and the body of Vice-Chancellors (AVCNU).

GET READY FOR CYBER CRIME ON THE PHONE

With the coming of 3G, the next wave of cyber attacks will be on the mobile phone.

Mobile phones will be the next computer and with the coming of 3G on handsets that will ensure faster Internet speeds on the go, the number of frauds too will go up.

In such a scenario it becomes all the more important for an Internet user to be aware of the ways in which fraud can be perpetrated online.

The internet is now the dominating force for commerce and online security for the travel industry is important as the biggest frauds happen in this segment.

If you are booking tickets online, it is essential to guard against identity theft, and validate the credentials of the online merchant. Users are also advised to upload anti virus and malware protection on their personal computers.