Showing posts with label online security. Show all posts
Showing posts with label online security. Show all posts

Monday, November 2, 2009

Many social-media games turning into scams

I can't get into Facebook. I do have an account, though I use it more to communicate with some of my friends. And I can't see spending a lot of time on it to play the games.

I have some friends who are seriously into the Facebook games and applications. Farmville, Bejeweled, YoVille, and Mafia Wars are real popular among the people I know. I can't be bothered with that stuff myself. I go on Facebook maybe long enough to check my messages, say hello to a few friends, and log off to check my Twitter account.

At first glance the Facebook games seem to be harmless fun. I understand you play many of them in levels; you clear the first level and move up to the bigger and better stuff -- much like the old-school Mario Brothers game or Dungeons & Dragons. So far, so good.

But TechCrunch has been working on a series of articles on the social-media games, and writer Michael Arrington smells a lot more scam than score.

With a lot of these games, there are two ways to hit another level: Earn it by playing well enough to clear the level you're on, or pull a George Steinbrenner and buy a new level. With real money. Your real money.

Already you can see this coming, if you're half perceptive. The game gets you hooked. It's like any other "progressive" type of game, and I can vouch for that. I've spent many hours trying to crack the combination on FreeCiv, an open-source version of Sid Meier's Civilization. Next I know the sun's coming up, my legs are frozen in one position, my left hand is all cramped up from pushing the mouse around, and my butt lost all feeling hours ago. So I can understand that.

But crank in the buy-ins and the special offers, especially if you're frustrated at the %$&#! game and your brain is fuzzed over from a marathon session, then things get real interesting.

On Oct. 31, Arrington wrote this:

... these games try to get people to pay cash for in game currency so they can level up faster and have a better overall experience. Which is fine. But for users who won’t pay cash, a wide variety of "offers" are available where they can get in-game currency in exchange for lead gen-type offers. Most of these offers are bad for consumers because it confusingly gets them to pay far more for in-game currency than if they just paid cash (there are notable exceptions, but the scammy stuff tends to crowd out the legitimate offers). And it’s also bad for legitimate advertisers. The reason why I call this an ecosystem is that it’s a self-reinforcing downward cycle. Users are tricked into these lead gen scams ...

Here's one scam, according to Arrington:

... users are offered in game currency in exchange for filling out an IQ survey. Four simple questions are asked. The answers are irrelevant. When the user gets to the last question they are told their results will be text messaged to them. They are asked to enter in their mobile phone number, and are texted a pin code to enter on the quiz. Once they’ve done that, they’ve just subscribed to a $9.99/month subscription. Tatto Media is the company at the very end of the line on most mobile scams, and they flow it up through Offerpal, SuperRewards and others to the game developers ... nothing in the offer says that the user will be billed $10/month forever for a useless service.

Had enough yet? Here's another:

Video Professor ... users are offered in game currency if they sign up to receive a free learning CD from Video Professor. The user is told they pay nothing except a $10 shipping charge. But the fine print, on a different page from checkout, tells them they are really getting a whole set of CDs and will be billed $189.95 unless they return them. Most users never return them because they don’t know about the extra charge. Woot. Again, sites like Offerpal and SuperRewards flow these offers through to game developers ...

Slashdot, one of my favorite sites for geeky news, says this about the TechCrunch articles:

... the system is rife with scams, and many game developers turn a blind-eye to them, much to the detriment of the players and the legitimate advertisers — not to mention the games that rightly disallow these offers and fall behind in profits. The article asserts that Facebook and MySpace themselves are complicit in this, failing to crack down on the abuses they see because they make so much money from advertising for the most popular games ...

If you play these online games -- or if you're thinking about it -- I highly recommend these three TechCrunch articles, all by Arrington:

Part One - Social Games: How The Big Three Make Millions

Part Two - Scamville: The Social Gaming Ecosystem Of Hell

Part Three - Two Companies That Said No To Social Media Scams

I'm getting awfully tired of doing these pieces on Internet scams. I'd rather do how-tos and reviews any old day. You think these scammers can give me enough of a break to pursue this? C'mon guys ... at least do it for my convenience?

###

Thursday, October 29, 2009

Site outlines 10 ways to spot an Email scam

I've spent a bit of time looking at some of the nefarious things that can find themselves on your computer courtesy of the Internet. You can get bad programs, spyware, viruses, and some eerie email at the click of a mouse.

What with the speed and ease with which one can send off mass emails, the scammer has all the tools he needs to separate many people from their dollars. And you've probably seen a few of these messages showing up in your inbox -- maybe even a few this week.

From switched.com, here are 10 red flags that the email you've received is probably a scam:

Look for things like requests for personal information, lots of misspellings, clickable Web links, innocent-sounding surveys, that "hot tip" you don't remember requesting, unsolicited attachments, and you-must-act-now pitches.

From Switched:

If you see the phrases "verify your account," "you have won the lottery" or "if you don't respond within XX hours, your account will be closed," it's a scam – every time. Hit the delete button and don't look back.


This is one you should delete, kill, whatever you do with it.

It's a jungle out there. But then you already knew that.

###

Wednesday, October 28, 2009

Facebook password-reset email carries a virus

Sheesh!

These writers of viruses and other nefarious code will stop at nothing to spread the love. But while you can see many viruses coming a mile away, I understand this one looks official.

This one, a Trojan horse dubbed Bredolab, comes dressed up as a "Password Reset Confirmation Email" from Facebook. In the email you click on the link to -- you think -- get your new password. That's when the fun -- if you can call it that -- starts. That link downloads system-destroying files, such as rogue "anti-spyware" programs that inject their own spyware, into your computer.

Considering some of the problems Facebook has been encountering -- partly from increased traffic and partly from its own recent redesign, this email almost sounds plausible.

I haven't seen this one myself; I got the details from Mashable! and MXLab.

According to MXLab, here's the body of the message:

Hey vguysville ,

Because of the measures taken to provide safety to our clients, your password has been changed.
You can find your new password in attached document.

Thanks,
The Facebook Team


Here's the drill. If you see something like this from Facebook, watch out. It's probably not from Facebook. Bear this in mind:

- If you didn't request a password change from Facebook, you have no reason to receive a reset confirmation. Don't bother opening it; dispose of it immediately.

Enjoy your computer, don't be skeered of the virus bogeyman, but be wary when you go online. Cool?

###

Tuesday, October 20, 2009

Scareware a big business, but fake virus 'protection' can be removed





Viruses and spyware are a real concern when you spend any time on the Internet, and some people are feeding on your fears for big bucks.

But while there are quite a few legitimate anti-virus programs out there, there are more that not only do not get rid of your viruses and malware, but install more of the same on your hard drive.

Symantec, which owns Norton, says more than 40 million people have fallen victim to the "scareware" scam in the past 12 months. According to the BBC, "online criminals make millions of pounds by convincing computer users to download fake anti-virus software." Which translates into an awful lot of dollars, not to mentioned the number of computers that are trashed by this cottage industry.

Over my years of surfing on the Internet, I've seen plenty of this. An ad shows up on a Web page I'm browsing, offering to scan my hard drive for free. Or flashing a message that would make even the most savvy Web surfer sweat -- that viruses have been detected.

The idea is that you click on the ad and it will scan your disk, or install a virus-protection device. That's what you think, anyway.

In reality, the scan or program is useless at best. At best.

At worst, the program or scan will install its own spyware, or its own virus, and really make hash of your hard drive -- and maybe even bill your credit card in the bargain.

Welcome to the rogue security software. They either are disguised viruses, trojans or are nothing but a sales pitch, trying to push another product to the user.

Call it scareware, because it's designed to frighten you into buying its product or download its own viruses, Trojan horses, or spyware.

Most of my Internet work is with this netbook, using Windows. But even while using Linux I've even seen these ads come up. I'm talking about the ads saying that viruses have been detected on my computer.

Which told me right away the claim was a bunch of horsesqueeze. For several reasons, Linux is not prone to viruses or spyware. Nor is MacIntosh, really.

OK. Time to check your computer. See what kind of virus protection you have. If it's from this list, you're in a bunch of trouble:

Cyber Security
Alpha Antivirus
Braviax
Windows Police Pro
Antivirus Pro 2010
PC Antispyware 2010
FraudTool.MalwareProtector.d
Winshield2009.com
Green AV
Windows Protection Suite
Total Security 2009
Windows System Suite
Antivirus BEST
System Security
Personal Antivirus
System Security 2009
Malware Doctor
Antivirus System Pro
WinPC Defender
Anti-Virus-1
Spyware Guard 2008
System Guard 2009
Antivirus 2009
Antivirus 2010
Antivirus Pro 2009
Antivirus 360
MS Antispyware 2009

These are rogue programs, according to ghacks. And if you have one of these, you'd better get rid of it awful fast. You probably clicked on something, downloaded what you thought was virus protection, and you may have noticed your computer running like crap.

So what do you do?

There's an article in ghacks which mentions "Remove Fake Antivirus," a portable software program for the Windows operating system that has been designed to uninstall 27 different rogue antivirus software programs from the computer system. You can download Remove Fake Antivirus here, and it's free.

I downloaded and ran it, though for me the on-the-workbench test was inconclusive. This is probably because I know the likelihood of me actually downloading and installing some of this scareware is really slim. The dialogue box showed, though, that it was removing each of these antivirus programs. My assumption was that this is the "default" dialog box. After running the program, you will be asked to reboot.

In truth, I'm a little chary of installing a virus-protection program from a non-company website (this is from a blog, how sketchy is that?) but sites like Download Squad (which gave it really lukewarm reviews), Softpedia, TechForums, and CNet (which rated it two-and-a-half stars out of five; not that great, and none of the readers reviewed it) carry links and product descriptions. Plus, I've never found reason to fault the information I get from ghacks.

A caveat: Here's one of the Download Squad reviews:

Well, I ran it, and it killed my main windows service and forced a restart. When the PC came back up, I had no internet connection. Warnings should be posted.

With that in mind, I checked things out when I rebooted. The Windows security service flashed a warning saying I had no virus protection, but I see ClamWin had loaded itself in the system, per normal. A glitch, perhaps? The good news was that my wireless Internet ran just fine. But be careful!

Menawhile, there are several good virus-removal programs out there. Some -- Norton and McAfee -- are the kind you pay for, while others -- AVG, ClamWin, and Avast! -- are free. The for-pay ones are probably a bit better than the free ones, but any of these are good for the computer and your peace of mind. That is, if you update them every so often -- there's always some idiot thinking that if he builds a better virus, the world will beat a path to his door. These viruses seem to be coming down the pike faster and faster. A virus protection program is only as good as its updates, and it's also useless if you don't run it regularly.

For spyware removal programs, only two are worth downloading -- AdAware by Lavasoft, and Spybot Search And Destroy. And neither one is perfect. But, unlike antivirus programs, you can have both installed and running on your computer. I highly recommend you run both, one after the other, as part of your regular security regimen. What spyware program one doesn't catch, the other one probably will.




Thursday, October 8, 2009

Ways to keep phishers out of your email

A few days ago, I wrote about how phishing (Password Fishing) attacks exposed a lot of Hotmail user accounts. It turns out the attacks were much bigger than Hotmail -- Google's Gmail (which is my go-to email system) got compromised, along with Yahoo, Earthlink, Comcast, and AOL.

Shoot, it might be easier to list the major email carriers that didn't get hit.

Meanwhile, the major email carriers are in damage control mode, and many put out statements and how-to's for self protection.

Here are some basics, courtesy of Mashable. Most of these involve passwords, the user's first line of defense:

*****

Use different passwords on different sites After all, if you use the same login credentials for multiple sites and one gets compromised, they all are. Since many of us use umpteen web services daily, it’s worth checking out a good password manager tool to help you keep the all straight — and safe.

Don’t use common words or sequences — Simple dictionary terms or sequential numerical sequences won’t cut it. You should make sure your passwords are a mix of letters, numbers and symbols.

Don’t base passwords on personal data — Hackers often use “social engineering” techniques to greater effect than running actual lines of code. Since we routinely share various bits of personal data with others, things like pet names, middle names, birthdays and so on don’t make a good basis for passwords.

Don’t leave your password somewhere visible — If you simply must write it down, don’t put it on a post-it attached to your monitor. Relatedly, if you keep a list of passwords on your computer, name the file something more cryptic than "password file."

Make sure your password recovery questions are also secure — Strong passwords that lack semantic meaning are unfortunately also easier to forget. Many sites allow you to reset your password over email or after answering one or more Security Questions you set up when creating the account. Make sure these aren’t based on common-knowledge personal data either — try to make them difficult to guess, and avoid any information you’ve posted publicly online anywhere as well.

*****

Good advice, that. An analysis of the data from Hotmail showed the most common password among the compromised accounts to be '12345.' I mean, duh! You don't need expensive software to crack that password, and it appears there are quite a few folks around that have no business running a computer. But that's fodder for another rant.

Here's more, from gHacks:

*****

The most powerful weapon against phishing is common sense and the following rules that every user should oblige to.

If you are not a customer of the site delete the email immediatly. Don´t click on the link or reply.

If you are a customer and you are not sure if the email is legit do one of the following:

Contact the institute by phone or contact at the official website ( do not use the email link of course) and ask if the mail is official.

Instead of using the link provided open the website by typing in the official link there. The site should have news about the email on their starting page. (most of the time).

*****

There's plenty more on that site. I highly recommend checking it out.

If you're using Firefox (as I am), go into the Tools > Options > Security in the Firefox options to set up your protection levels. I really recommend you do this now, while you're reading this. If you don't find these options, you're probably using an older Firefox. You'll find more Firefox phishing protection and testing tricks here.

Also, I did download LastPass, though I haven't installed it yet. I see where it involves creating an account online, though it's free for private use. According to the manufacturer, the password information is stored on your own computer. Still, I'm a little chary of using any Web-based password keeper. I'll install it and take a look at it, but my instincts tell me it's not a perfect solution.

In the meantime, enjoy your computer. It's a great tool, and the more plugged-in the world is, the more your computer will become a part of your life. But be careful. It's a jungle out there.



Tuesday, October 6, 2009

Phish tales: My Twitter, 1000s of Hotmail accounts hijacked

I'm fairly new at this Twitter thing, and I'm still prone to rookie mistakes. And for a few days, I was paying for one.

I occasionally get worthless tweets from folks about quick-and-dirty ways to build my traffic. Most of them are pure crap, by the way, but while some are harmless crap, others are more nefarious. I came across one -- GET 1000's OF FOLLOWERS, with a link. OK. I could smell the crap all the way from here, but I thought I'd take a look at it to, well, see what was going on. Research purposes, you understand.

I clicked on the link and immediately got the warning that the site was possibly one for phishing. For those who don't know what that is, phishing is when someone is trying to harvest information from you. Valuable information that you wouldn't give out otherwise. Like a password.

As soon as I saw that warning, I clicked on it to basically abort the mission. Supposedly, that was the end of that.

Not so. Soon after that, I noticed I had been making some real strange tweets, or more correctly, some jerkface was sending them out under my name. Every day. There would be some message credited to me, advertising some "service" that gives you thousands of followers. Or something. In social media, followers and friends are the coin of the realm. The more followers you have, the bigger your network and the more valuable your site. I use Twitterfeed to link my writing directly into Twitter, and all of my followers (right now about 40 of them) gain access to my work.

Soon I noticed these posts linking to the phishing site started going out every day, with the link and my name on them. Some idiot hijacked my Twitter account, and I became a spammer.

I tried a few quick damage-control measures. Blocking the original source of the link. Adding a disclaimer to warn followers away from that link. Part of that was saving face -- letting my followers know it wasn't me sending those things. And the spam messages still showed up, every day.

Final analysis: There seems to be a simple fix, a real no-brainer. Change your Twitter password. I did that, and the messages stopped. D'oh!

Meanwhile, those who use Hotmail for email (I'm not sure why you'd want to) are getting phished big time. According to gHacks Technology News:

Microsoft has recently confirmed that thousands of Windows Live Hotmail customer’s credentials were exposed on a third party website. According to Neowin the account information were posted by an anonymous user at the pastebin website. The list that was posted contained over 10.000 account details of accounts starting with the letters A and B which suggests that additional lists might be in the hands of the attackers. Initial investigations suggest that only accounts used to access Windows Live Hotmail were affected (which includes email accounts ending with hotmail.com, msn.com or live.com ... Microsoft determined that the attack was not a breach of internal Microsoft data and believes that the account data was gained by a phishing attack. Phishing attacks are common ways these days to lure users into entering their account data on websites that look like the real deal but are not ...

Again, the gHacks-prescribed fix is a simple one: Change your password. Now.

There are a few before-the-fact and after-the-fact ways to protect yourself here:

Changing your password is the best back-end fix, though it is a pain in the butt. Even more painful now, when you access your accounts through a third-party application or site. For me, this meant changing the passwords on TweetDeck and Twitterfeed. As I write this, I'm pretty sure I haven't checked if my feed on this blog has been fixed yet; probably not. Note to self: Fix.

I haven't really checked it out yet, but there's a program called lastpass that's supposed to make it easy. It was mentioned in the gHacks piece, so I downloaded it and will give it a go. Might have something to write about there; stay tuned.

Also, the other standard self-protection rules apply. Don't click on Twitter links unless you know the source. Pretty much the same rule as opening email attachments. I know I'm screwing myself here, as I get a fair bit of blog traffic through Twitter. But y'all pay attention to what the link is. If the link is attached to a blog post (in my case it's prefaced with a COLUMN or WORKBENCH) it'll be OK. Those attachments will only mess with your mind, not your computer or Twitter account. If the preface is something like GAIN ZILLIONS OF FOLLOWERS, MAKE MILLIONS WHILE SITTING ON YOUR BUTT, or LOSE 20 POUNDS OF DANGEROUS UGLY FAT WITHOUT CUTTING OFF YOUR HEAD, the link is probably real sketchy and you'd do well to ignore it. But you don't need me to tell you that.

This last is going to require some extra vigilance, as so much Twitter traffic involves passing links back and forth. Especially mine. Looking at the last 40 tweets from my network (representing about two hours), 31 have clickable links. Most will refer me to a blog post or a news story. This is probably disproportionately high, as many Twitter users merely use the account to keep track of some friends. Mine actually doubles as a news feed, so I'm going to have a higher percentage of links.

Sometimes it's tempting to cut all cords and wireless, eschew all technology, and go back to quill pen and foolscap. But that's not an option, not if I wish to function in today's hooked-up dialed-in world.

###

You tell me: What protective measures are you employing here? What works? What doesn't? Do you have any horror stories you wish to share? Use the comments section below.


Saturday, September 19, 2009

People may pay $100 bounty to crack your Facebook account

It's a jungle out there.


... security vendor PandaLabs has discovered an online service offering to help those so inclined to hack into any Facebook account they choose for a price: $100 ...

Be careful out there!

A totally peripheral note: Must these idiots be referred to as "hackers?" Ask anyone in the programming community, especially those folks who create some really good free software. They call themselves hackers, and it's not the same thing. Hackers build things, they say, while "crackers" tear things down.

Tuesday, September 15, 2009

Careful of the ad, even if source is copacetic

This is must reading if you spend any time online.

... while reading the New York Times online, I was confronted with an attempted security attack, apparently delivered through an advertisement. A window popped up, mimicking an antivirus scanner. After "scanning" my computer, it reported finding viruses and invited me to download a free antivirus scanner. The displays implied, without quite saying so, that the messages came from my antivirus vendor and that the download would come from there too. Knowing how these things work, I recognized it right away as an attack, probably carried by an ad. So I didn't click on anything, and I'm fairly certain my computer wasn't infected ...

Source: Freedom To Tinker blog.

Like the man so tiresomely said in Hill Street Blues, "Be careful out there."


About YOU