Showing posts with label Tips. Show all posts
Showing posts with label Tips. Show all posts

Friday, March 16, 2012

Google opens a pharmacy? It’s spam of the day


MessageLabs Intelligence recently tracked a new pharmaceutical spam campaign promoting a supposedly "Google-accredited" online pharmacy. This is obvious brand hijacking: Google does not host or approve any pharmacy sites. We contacted Google about this, and a spokesperson responded with, "Google has a track record of fighting similar types of scams, and we also recommend that users carefully review online offers that look too good to be true before entering any of their information: http://googleblog.blogspot.com/2009/12/fighting-fraud-online-taking-google.html".
The spam message contains text promoting a drug for preventing hair loss, and a link to a blog the spammer has set up on a popular free blogging site, shown in the screenshot below:
[example of spam email promoting fake pharmacy brand]

Anyone following the link will be directed to the spammer's blog, containing spam-related content and links to the spammer's actual site, as shown in the screenshot below:
[example of well-know free blog site being used to host brand-hijacking content]

In the last two days alone, we have automatically blocked over 250 similar spam-created blogs.
The blog's most recent entry has a randomized, irrelevant title ("gourmet"), and consists of text taken from a book or some other document, interspersed with an image and link. The image contains the Google logo with the two "o" letters replaced by differently-shaped tablets. This is perhaps more plausible than it might seem due to Google's famous "doodles", where Google changes its logo to mark holidays or even famous computer scientists like the late Edsger W. Dijkstra.
The text below the logo (but still included in the image) incorrectly claims that Google has launched a "pharmaceutical interface", followed by more text and finally underlined text in blue to appear like a link. It is likely that the spammer wants to capitalize on Google's universally known name to add legitimacy to their products. With Google's increasing diverse product range, spammers are perhaps hoping that a fake Google-accredited pharmacy will be plausible to some recipients.
The link ("vriagrav - make sesxx" [sic]) points to the spammer's pharmaceutical site, an example of which can be seen below:
[example of the spam website relating to the spam campaign for the fake brand]

The image itself is not hosted on the blogging platform--instead it is hosted on a Russian site. The filename claims that the image is a GIF file, yet it is actually a JPEG file.
This type brand hijacking is a serious problem for well-known brands and can harm their reputation, as users might wrongly associate the nuisance factor of receiving such email with the brand.


If you think you need medication contact your real doctor, and stay away from quacks on the internet. 

Saturday, March 10, 2012

How to Really Take Charge of Your E-mail Account Security


E-mail Account Security











More and more users are having their Hotmail and MSN e-mail accounts hacked. What's in it for hackers? Well, snooping into users' private data and exploiting it in their criminal attempts (examples: identity theft, spamming, pump & dump schemes, 419 scams etc.).

Even my father has had his account hacked, so I thought now would be a good time to post a few helpful tips on how to properly protect your inbox.


1. How does a "hacker" find an e-mail address?

From any site you have used your e-mail on: social sites, gaming sites, forums, and anywhere else you are required to register with your e-mail address.


2. There is no such thing as a 100% "safe" database.

All databases have security measures in place, but we have learned that even big companies such as Sony and NASA have had trouble with hacking in the past.


3. Why did my antivirus software not protect me from this?

It can’t. Simply because the e-mail user database is web based, and stored externally on a server that your antivirus does not have access to. Your antivirus can protect your computer from the threats that are on the internet and, depending on the antivirus you have, it may also protect your local network.


4. How did the hacker find out my password or security question?

Chances are that you have used them before on another site, which got hacked. It could also be that the person who hacks your account is someone you know, or that you have left your details accessible without being aware of it.


Microsoft has put together these recommendations for what to do, in case your Hotmail or MSN e-mail account gets hacked: explore.live.com/windows-live-hotmail-hacked-account-faq
And Microsoft is taking serious steps in order to prevent hacking, including creating a special function for reporting hacked accounts. When an account is reported stolen, it will be monitored in order to find and stop the culprit. You can read the full article and more about how to use this function, here: windowsteamblog.com/windows_live/b/windowslive/archive/2011/07/14/hey-my-friend-s-account-was-hacked.aspx

Google also has a really nice feature for preventing account hacking. They keep track of the IP's you login from and your geographic location and  signal any other access to the account. Also, users can designate a mobile phone, landline or mobile application to receive a unique one-time login code. You must enter this code, in order to login to your account.

Yahoo also has a lot of security and spam/scam reporting features:
  • You can create a sign-in-seal for all your computers https://protect.login.yahoo.com/login/set_pref. This will display a secret message or image and a background colour for your login window, that you should always see on your computer, if you are on a valid Yahoo Sign-in page.
  • You can report any message or Yahoo contact as spam and even block them. This is very handy, since more and more Yahoo accounts are being created for the specific purpose of spam/scam.

To sum things up, there are significant steps being taken in order to keep user accounts safe, by all major IT companies. It is important, though, that users also take the few necessary steps in order to protect themselves.

Friday, March 9, 2012

Google Smart Search


1 thing you could live without: SPAM! 5 rules to reduce it

Email Spam


We all know and hate it: it’s annoyingly persistent, attention-grabbing and impossible to avoid. Yes, I’m talking about spam e-mail, creeping like a pesky bacterium you have to learn to live with. Junk e-mail has been around for a couple of (Internet) ages and has no intention of going away.

However, never lose hope of a lighter mailbox. Take a look at these promising tips to help you identify spam and learn how to prevent it.

First of all, how do you recognize a spam e-mail? Pay attention to:

  1. The sender: most of the e-mails are sent through bogus addresses that seem valid.
  2. The subject line: usually includes “money” (“Earn”/”Save”/”Win money”) and promotes a sense of urgency (“Last chance”, “Order today”, “Call now”). Check out a complete list of spam-triggering words commonly found in subject lines, here.
  3. The message: emotional or business-oriented, spammers lure you into giving away your financial information, passwords or PIN numbers under a variety of false pretexts such as doing a good deed for charity or receiving an unexpected prize. 

It may seem easy to identify a foe, but let’s use this recent Facebook scam as an example.
Facebook Spam
What’s wrong with this picture?

  • Inviting you to reply to an e-mail address which differs from the sender: if the sender is fake and risks being shut down, the second account is the one controlled by the spammer.
  • The huge amount of money involved.
  • Winning a prize even if you haven’t agreed to participate in any type of contest.
  • Keeping your winnings a secret.
  • Deceiving mobile phone number:  usually redirects you to a fake location so the spammers cannot be traced.



Now that you have spotted a bad e-mail, it’s best to cut the evil off at the root and reduce spam as much as possible. Here’s a list of good practices:

  1. 1. Don’t reveal your e-mail address in forums, blog comments or chats and don’t sign up using your primary e-mail address. If you must expose yourself online, use a special address for social networking.  You can also trick spammers by leaving out periods and “@” signs or write with letters: "yourname AT yourdomain DOTcom."

  1. 2. Make your address almost impossible to guess. Sounds ridiculous, but it’s another easy way for spammers to add names to their lists. Once given a domain name, a program will send mails to all sorts of (likely) user names at that address, from aaaronb@ to zzziddyw@, for example.

  1. 3. Use an efficient spam filter. It’s essential that you use a tool to sort out the spam you’re receiving. The most powerful ones include an advanced Bayesian filter to statistically identify spam based on word patterns or word frequency. To learn more about this technology, you can check BullGuard Spamfilter. And try it – it’s free.

  1. 4. Never reply to or click on any links in a spam message. Follow these golden rules to stay safe: don't buy any products or services advertised in spam, don't reply to or forward the e-mail and don't click on anything! If you do, you risk catching a virus or your address might be used to spam your entire contact list. And I’m sure your friends wouldn’t be happy about it.

  1. 5. Report spam to your Internet Service Provider (ISP). If you receive an e-mail who seems to come from a friend, but it’s actually fake, you can complain to his/her ISP at an address like: abuse@ (ISP’s name).com; abuse@yahoo.com, for example. To find out which ISP to contact, you can use SpamCop , a tool meant to analyze spam messages and send complaints on your behalf.


Tuesday, March 6, 2012

Top 5 Things to Check Before Downloading Apps to Your Phone


Mobile Apps

You sooo want those addictive, funny apps. And when you have a craving for a new one, your index finger itching to tap into a new, compelling app universe, you throw caution to the wind. You’re ready to download anything, and – yes, let’s be honest - security measures is the last thing you want to spend time considering.

But app land is a jungle, and not everything is what it seems. Cybercriminals are working round the clock to create illegitimate, malware-infested apps for you to download. When you do, you basically hand over control of all the content on your phone to the bad guys – including bank details, contact information, passwords and anything else you’re storing on there.

I’ve asked BullGuard’s mobile security experts  to give out a few tips on how you can make sure, an app is legitimate and doesn’t put you or your phone at risk.


Here’s their advice:

  • Only download applications from the platform’s official app store: Android Market, App World (Blackberry), Ovi Store (Symbian) or Apple Store
    Avoid 3rd party app repositories at all costs where there is little or no control over what gets published there. Spam e-mails or SMS messages with links to download apps represent a security risk as well.

  • Read the reviews Android Permissions
    All app stores display reviews for the software available for download. Pay attention to what other people say and take some time to sift through the reviews: if there are several pages of reviews, make sure to go through some of them randomly. Even if the app is legit, reading reviews can also tell you whether the software may cause issues on the device.
    When sifting through pages and pages of free apps, a healthy dose of scepticism is required and going with a “guilty until proven otherwise” mentality will go a long way to keep malware off of your smartphone.

  • It is vital to read what permission and resource access the application requires on your phone, particularly on permission based mobile platforms such as Android, Blackberry or iOS. Smartphone owners need to look at the app’s advertised features and compare those features to the list of permissions and resource access the software asks for. For example, it does not make any sense for small, entertaining games to have access to the contacts list and messages, or to send text messages to random numbers or being allowed to delete files from the device.
    You can easily identify discrepancies between advertised features, and what the application will really do on the smartphone.

  • Do nor jailbreak or root the phone.
    For iOS device owners, it may be nice to be able to install applications that do not necessarily come from Apple’s App Store, but what the jailbreaking process does, is simply strip the iPhone of all security layers leaving the owner defenceless against malware or hacking attempts. A similar situation is presented to Android users that root their device; when this happens, installed apps will have access to the entire device and features.

  • BullGuard Mobile Security

  • Install a mobile security suite and keep the operating system up-to-date.
    While security products provide protection against malware, keeping the phone’s operating system up to date will ensure that security flaws or holes through which malware can crawl on the device get patched.