Showing posts with label trojans. Show all posts
Showing posts with label trojans. Show all posts

Tuesday, May 27, 2014

Phishing, Fraudulent and Malicious Websites

Whether we like it or not, we are all living in the Information Age. We have nothing left but adapt to rapidly developing information technology, no matter who we are and what we do for living. 

The Internet, in particular, means for us boundless opportunities in life and business – but also lots of dangers unheard of just a decade ago. We should be aware of these dangers if we want to use the huge potential of the Internet and to avoid the hazards it brings us.

<b>Warning: There are Websites You'd Better Not Visit</b>

<b>Phishing websites</b>

Thanks to authors of numerous articles on this topic, "classic" phishing technique is relatively well known. This scam involves setting bogus websites and luring people to visit them, as a rule, by links in emails. Phishing website is disguised to look like a legitimate one -- of a bank or a credit card company, and users are invited to provide their identifying information. Sites of this kind are used solely to steal users' passwords, PIN numbers, SSNs and other confidential information.

At first phishing consisted only of a social engineering scam in which phishers spammed consumer e-mail accounts with letters ostensibly  from banks. The more people got aware of the scam, the less spelling mistakes these messages contained, and the more these fraudulent websites resembled legitimate ones. Phishers are getting smarter. They eagerly learn; there is enough money involved here to turn criminals into earnest students.

Since about November 2004 there has been a lot of publications of a scheme which at first was seen as a new kind of phishing. This technique includes contaminating a PC with a Trojan horse program. The problem is that this Trojan contains a keylogger which lurks at the background until the user of the infected PC visits one of the specified websites. Then the keylogger comes to life to do what it was created for -- to steal information.

It seems that this technique is actually a separate scam aimed at stealing personal information and such attacks are on the rise. Security experts warn about commercialisation of malware -- cybercriminals prefer cash to fun, so various kinds of information-stealing software are used more actively.

<b>Fraudulent websites are on the rise</b>

Websense Security Labs -- a well-known authority in information security -- noticed a dramatic rise in the number of fraudulent websites as far back as in the second half of 2004. These sites pose as ones for e-commerce; they encourage users to apply for a reward or purchase something, of course never delivering the product or paying money. The most popular areas for such fraud are online pharmacies, lottery scams, and loan / mortgage sites. Experts predict there will be more fake merchants in future and their scams will become more sophisticated.

<b>Malicious websites</b> are especially dangerous. Cybercriminals create them exclusively to execute malicious code on the visitors' computers. Sometimes hackers infect legitimate sites with malicious code.

Bad news for blog readers: blogs can be contaminated, too. Since January, Websense Security Labs has discovered hundreds of these "toxic" blogs set by hackers.

When unsuspecting users visit malicious sites, various nasty applications are downloaded and executed on their computers. Unfortunately, more and more often these applications contain keyloggers--software programs for intercepting data.

Keyloggers, as it is clear from the name of the program, log keystrokes --but that's not all. They capture everything the user is doing -- keystrokes, mouse clicks, files opened and closed, sites visited. A little more sophisticated programs of this kind also capture text from windows and make screenshots (record everything displayed on the screen) – so the information is captured even if the user doesn't type anything, just opens the views the file.

In February and March 2005, Websense Security Labs researched and identified about 8-10 new keylogger variants and more than 100 malicious websites which are hosting these keyloggers EACH WEEK. From November of 2004 through December 2004 these figures were much smaller: 1-2 new keylogger variants and 10-15 new malicious websites per week. There is by all means a disturbing tendency--the number of brand-new keyloggers and malicious website is growing, and growing rapidly.

<b>What a user can do to avoid these sites?</b>

As for phishing, the best advice is not to click any links in any email, especially if it claims to be from a bank.

Opening an attachment of a spam message can also trigger the execution of malicious program, for example a keylogger-containing Trojan horse.

As for fraudulent websites, maybe buying goods only from trusted vendors will help -- even if it is a bit more expensive.

As for malicious websites… "Malicious websites that host adult entertainment and shopping content can exploit Internet Explorer vulnerabilities to run code remotely without user interaction."(a quote from Websense's report). What can a user do about it? Not much, but avoiding adult sites and buying only from known and trusted online stores will reduce the risk.

Hackers also attract traffic to malicious websites by sending a link through spam or spim (the analog of spam for instant messaging (IM). So a good advice never follow links in spam is worth remembering once more.




===========================================
<!-- Beginning of Freelancer.com Affiliates Widget -->

<script type="text/javascript"><!--
GAF_text_color = "black";
GAF_link_color = "green";
GAF_title_color = "blue";
//--></script>
<script src="http://www.freelancer.com/widgets/projects/hs2.js"></script>
<div id="GAF_projects_hs2_box" style="width: 468px; height: 60px; padding: 0px; font-family:sans-serif; font-size: 11px;">
<div style="padding: 0px; overflow: hidden">


<div id="GAF_projects_hs2" style="padding:3px; cellpadding:0px;"></div>

<div style="padding: 0px;" align="right"><span style="font-size:11px; padding: 0px;">
<a href="http://www.freelancer.com/" target="_blank"><font color="blue" style="text-decoration: none">Outsourcing Services</font></a>?
Try <a href="http://www.freelancer.com/" target="_blank"><font color="blue">Freelancer.com</font></a>.
</div>

</div></div>
<script src="http://api.freelancer.com/Project/Search.json?aff=4329971&callback=GAF_update_projects_hs2_callback&order=rand&count=2&iads=true&nonpublic=0&charset=UTF-8"></script>
<!-- End of Freelancer.com Affiliates Widget -->



===========================================
Summary:
Warning: There are Websites You'd Better Not Visit.

Saturday, May 17, 2014

My Spyware Nightmare, Your Lesson

Have you asked yourself any of these questions lately?

1. Why is my brand new computer slowing down to a crawl?
2. Why is it taking so long to load a basic word processor?
3. Why do I have so many popups? Where are they coming from?
4. Why do I keep being sent to places I did not ask to go?
5. Where are these embarassing popups coming from?  I never visit sites like that!

I did. I was ignorant. I was slow and it cost me a brand new computer. Here is my story.

A couple of years ago, we bought a new eMachine for my wife. She had just enrolled in school and needed something better for her school work. Prior to that, we had an older HP machine. I believe it was a pentium II. It worked pretty well, though a little slow. I wanted us to get another HP, but she wanted an eMachine. Her cousin had one and she thought it was good. I did not like eMachines a lot and did not think highly of them. She was bent on having one so we bought one. 

With the arrival of the new computer, the HP was quickly abandoned. I was pretty much the only one that used it. Not because of my disdain for eMachine, but becasue the HP was more in a central location. Our three boys loved the new machine and spent quite some time on it. I was eventually won over to the eMachine and I must confess, it turned out to perform excellently well. It was good on speed and the resolution was great.

Several months down the road, I noticed how the new computer was slowing down. I knew in my mind it was the eMachine. They were no good. And then I thought it was the dial up connection. But I soon realized that it was also slow when I was offline. It was taking long to open up applications and even longer to load webpages.  I also noticed there were strange windows openning up at the most awkward  times. Some of the pages were to sites I would not ordinarily visit. May be the boys are going to places that we don't know about.  As a concerned parent, I asked them and they promptly denied. I was still not sure they did'nt. They were teenagers.

As time passed, it became more difficult to do anything on the eMachine. We gradually migrated back to the HP and there was no immediate need to find out what was wrong with it.

Finally, it was time to act. I was ready to find out what the problem was. I started asking questions and doing querries on google. I was encouraged to get a good popup blockers. I did and it did not do much. That computer was far gone and corrupted. I had waited too long. I was not sure what was going on and did not know where to ask. The warrantee on the computer had also expired.

One afternoon, I turned the computer on to take another look and was greeted by a blank screen. The monitor had also quit I said to myself. Now I knew almost for sure it was the eMachine. They were really no good. My wife disagreed. But to be sure, I hooked the monitor up to the HP and it came alive. So it was'nt eMachine after all. I was a little embarrassed.

I reconnected the monitor and rebooted and was again faced by a blank screen. The following week, I took the cpu to a repair and they told me the computer was dameged beyond repair. I retrived it and took it to a sencond repairman and it never came back.

You know, lightening they say does not strike the same spot twice.  But spyware is different. It can strike the same spot many times. Early 2005, I bought another computer, having out grown the HP. Months latter, I noticed the same exact symptons that ruined the eMachine. The slow down, the multiple popups, redirects to undesirable websites, they were all there. This time I did not wait. That afternoon I was frantic. I began searching for a quick answer. It was not until late that night that I found a product that worked for me. And once I found the right solution, spyware was no longer an issue to me.

Spyware can make your online experience a nightmare if you are not forward thinking about internet security. The good news is that there are plenty of products out there that can cure that effectively.




===========================================
<!-- Beginning of Freelancer.com Affiliates Widget -->

<script type="text/javascript"><!--
GAF_text_color = "black";
GAF_link_color = "green";
GAF_title_color = "blue";
//--></script>
<script src="http://www.freelancer.com/widgets/projects/hs2.js"></script>
<div id="GAF_projects_hs2_box" style="width: 468px; height: 60px; padding: 0px; font-family:sans-serif; font-size: 11px;">
<div style="padding: 0px; overflow: hidden">


<div id="GAF_projects_hs2" style="padding:3px; cellpadding:0px;"></div>

<div style="padding: 0px;" align="right"><span style="font-size:11px; padding: 0px;">
<a href="http://www.freelancer.com/" target="_blank"><font color="blue" style="text-decoration: none">Outsourcing Services</font></a>?
Try <a href="http://www.freelancer.com/" target="_blank"><font color="blue">Freelancer.com</font></a>.
</div>

</div></div>
<script src="http://api.freelancer.com/Project/Search.json?aff=4329971&callback=GAF_update_projects_hs2_callback&order=rand&count=2&iads=true&nonpublic=0&charset=UTF-8"></script>
<!-- End of Freelancer.com Affiliates Widget -->



===========================================
Summary:
Spyware is a nuisance by any standard and by my standared, destructive. Not too long ago, I found myself asking,

1. Why is my brand new computer slowing down to a crawl?
2. Why is it taking so long to load a basic word processor?
3. Why do I have so many popups? Where are they coming from?
4. Why do I keep being sent to places I did not ask to go?
5. Where are these embarassing popups coming from?  I never visit sites like that!

You may be asking the same questions now or know someone who is asking the same questions. Read my story.

Friday, May 9, 2014

Is Your Computer Really Safe?

The majority of business transactions today are conducted online, which in turn has caused computers to become household necessities.  But as the internet continues to flourish, the rise of internet crimes seems endless.  With the emergence of computer malware such as viruses, worms, spyware/adware we are constantly placing ourselves at risk by simply turning our computers on.  The problem has become so widespread that Congress prepared changes in amendments specifically related to internet crimes.  In 2003 the National Cyber Security Alliance reported that 90% of all broadband users have spyware installed on their computers!  Corporations and small business owners worldwide are hiring software engineers or utilizing their own IT specialists in order to maintain appropriate internet security for their business. 

        Spyware/Adware is the latest form of internet intrusion, being any software installed on your computer without your knowledge or consent which allows information about you and/or your computer to be seen and used by others in an unwelcome manner.  Being very difficult to remove on your own it usually requires installation of anti-spyware software to erase it completely from your hard drive.  A lot of people think that their anti-virus software will protect against spyware as well, this is not the case since this software is not designed to specifically remove spyware, it goes undetected when your hard drive is scanned.  Whether you’re a small business owner or even if you just use your computer on a regular basis, if don’t have some type of antivirus and anti-spyware protection installed on your computer you are extremely visible on the web (you want to be “invisible” when browsing the web) and are placing yourself at risk to intrusion and/or theft by internet predators.  I would know since I had to pay $225 just to have viruses removed from my computer’s hard drive-which is never any fun by the way.  So as a word of caution, make sure your information will be safe before placing it on your PC.  You can visit Trend Micro to learn more about what to look for and how to protect yourself from malware, phishing sites, and, joke programs.




===========================================
<!-- Beginning of Freelancer.com Affiliates Widget -->

<script type="text/javascript"><!--
GAF_text_color = "black";
GAF_link_color = "green";
GAF_title_color = "blue";
//--></script>
<script src="http://www.freelancer.com/widgets/projects/hs2.js"></script>
<div id="GAF_projects_hs2_box" style="width: 468px; height: 60px; padding: 0px; font-family:sans-serif; font-size: 11px;">
<div style="padding: 0px; overflow: hidden">


<div id="GAF_projects_hs2" style="padding:3px; cellpadding:0px;"></div>

<div style="padding: 0px;" align="right"><span style="font-size:11px; padding: 0px;">
<a href="http://www.freelancer.com/" target="_blank"><font color="blue" style="text-decoration: none">Outsourcing Services</font></a>?
Try <a href="http://www.freelancer.com/" target="_blank"><font color="blue">Freelancer.com</font></a>.
</div>

</div></div>
<script src="http://api.freelancer.com/Project/Search.json?aff=4329971&callback=GAF_update_projects_hs2_callback&order=rand&count=2&iads=true&nonpublic=0&charset=UTF-8"></script>
<!-- End of Freelancer.com Affiliates Widget -->



===========================================
Summary:
Discusses computer safety