Malware News

Mozilla Firefox is prone to a remote code-execution vulnerability. Successful exploits may allow an attacker to execute arbitrary code in the context of the user running the affected application. Failed attempts will likely result in denial-of-service conditions. The issue affects Firefox 3.5; other versions may also be vulnerable. NOTE: Remote code execution was confirmed in Firefox 3.5 running on Microsoft Windows XP SP2.

Phishing Scams

Print PDF

Top 10 Phishing Scams: 1. security alert! 2. account notification! 3. account notification 4. please confirm your data! 5. Chase Bank: online banking notification 6. Chase Bank: necessary to be read! 7. Chase Bank: important notice 8. Chase Bank: important security notice 9. Chase Bank: account secure confirmation 10.Chase Bank customer service: security alert.

Recognize phishing scams and fraudulent e-mail

Published: September 14, 2006 | Updated: October 15, 2008
* *
* *

Phishing

Phishing is a type of deception designed to steal your valuable personal data, such as credit card numbers, Windows Live IDs, other account data and passwords, or other information.

You might see a phishing scam:

In e-mail messages, even if they appear to be from a coworker or someone you know.

On your social networking Web site.

On a fake Web site that accepts donations for charity.

On Web sites that spoof your familiar sites using slightly different Web addresses, hoping you won't notice.

In your instant message program.

On your cell phone or other mobile device.

Often phishing scams rely on placing links in e-mail messages, on Web sites, or in instant messages that seem to come from a service that you trust, like your bank, credit card company, or social networking site.

 

What does a phishing scam look like?

Phishing e-mail messages take a number of forms. They might appear to come from your bank or financial institution, a company you regularly do business with, such as Microsoft, or from your social networking site.

In the United States, recent bank mergers have created new opportunities for scammers. For more information, read FTC Consumer Alert: Bank Failures, Mergers and Takeovers: A "Phish-erman’s Special."

Spear phishing is a targeted form of phishing in which an e-mail message might look like it comes from your employer, or from a colleague who might send an e-mail message to everyone in the company, such as the head of human resources or IT. For details, see Spear phishing: highly targeted scams.

Phishing mail often includes official-looking logos and other identifying information taken directly from legitimate Web sites, and it may include convincing details about your personal information that scammers found on your social networking pages.

The main thing phishing e-mail messages have in common is that they ask for personal data, or direct you to Web sites or phone numbers to call where they ask you to provide personal data.

The following is an example of what a phishing scam in an e-mail message might look like.

Phishing Scams

Example of a phishing e-mail message, which includes a deceptive Web address that links to a scam Web site.

To make these phishing e-mail messages look even more legitimate, the scam artists may place a link in them that appears to go to the legitimate Web site (1), but actually takes you to a phony scam site (2) or possibly a pop-up window that looks exactly like the official site.

 

Here are a few phrases to look for if you think an e-mail message is a phishing scam.

"Verify your account."

Businesses should not ask you to send passwords, login names, Social Security numbers, or other personal information through e-mail.

If you receive an e-mail message from Microsoft asking you to update your credit card information, do not respond: this is a phishing scam. To learn more, read Fraudulent e-mail that requests credit card information sent to Microsoft customers.

"You have won the lottery."

The lottery scam is a common phishing scam known as advanced fee fraud. One of the most common forms of advanced fee fraud is a message that claims that you have won a large sum of money, or that a person will pay you a large sum of money for little or no work on your part. The lottery scam often includes references to big companies, such as Microsoft. There is no Microsoft lottery.

"If you don't respond within 48 hours, your account will be closed."

These messages convey a sense of urgency so that you'll respond immediately without thinking. A phishing e-mail message might even claim that your response is required because your account might have been compromised.

What does a phishing Web site or link look like?

Fake, copycat Web sites are also called spoofed Web sites. They are designed to look like the legitimate site, sometimes using graphics or fonts from the legitimate site. They might even have a Web address that's very similar to the legitimate site you are used to visiting. (For details, see Typos can cost you.

Once you're at one of these spoofed sites, you might unwittingly send personal information to the con artists. If you enter your login name, password, or other sensitive information, a criminal could use it to steal your identity.

Here’s an example of the kind of phrase you might see in an e-mail message that directs you to a phishing Web site:

"Click the link below to gain access to your account."

HTML-formatted messages can contain links or forms that you can fill out just as you’d fill out a form on a Web site.

Phishing links that you are urged to click in e-mail messages, on Web sites, or even in instant messages may contain all or part of a real company’s name and are usually masked, meaning that the link you see does not take you to that address but somewhere different, usually an illegitimate Web site.

Notice in the following example that resting (but not clicking) the mouse pointer on the link reveals the real Web address, as shown in the box with the yellow background. The string of cryptic numbers looks nothing like the company's Web address, which is a suspicious sign.

Example of a masked Web address

Example of a masked Web address

Common Threats

iTunes Hacking

Microsoft launches online security patch

Microsoft has released an emergency online security patch following the discovery of a potential glitch in its technology. The software giant announced that the online security update will automatically be installed for Internet Explorer customers. Microsoft released the patch after a vulnerability in the company's Active Template Library was discovered. The software is used to build ActiveX controls and other web application components.

Web users should be cautious of fake anti-virus programs

A new report has highlighted that malware posing as anti-virus software is spreading across tens of millions of computers each month. According to research by PandaLabs, over 1,000 examples of fake anti-virus software were found in the first quarter of 2008 alone. The program works by issuing false warnings of infections, persuading web users to buy software they do not need, and can also download Trojans or malware.

Spammers translating messages cause global security issues

Spam email is becoming a growing threat in non-English speaking nations, according to a new study. Research by MessageLabs highlights that spammers are now using free online translation sites to write messages in a variety of languages and target a greater number of people across the globe. As a result, some nations which previously enjoyed a high level of internet security are now falling victim to rising levels of spam.

Malware 'the greatest threat'

The greatest threat to computer networks is malware, meaning people should be wary of introducing unnecessary software to their machines, an expert has stated. Writing for his risk management blog hosted by online publication ComputerWeekly.com, Stuart King warned that some people are reporting that their new digital picture frames and gadgets such as MP3 players are infected with viruses.

Sun Java Runtime Environment Vulnerabilities

Sun Java Runtime Environment and Java Development Kit are prone to multiple security vulnerabilities. Successful exploits may allow attackers to violate the same-origin policy, obtain sensitive information, bypass security restrictions, run untrusted applets with elevated privileges, and cause denial-of-service conditions. This may result in a compromise of affected computers.

* Geeks Houston ®, Geeks Mobile, and geeksquadonline.com have no affiliation to Geek Squad or Best Buy

Mozilla Firefox 3.5 'TraceMonkey' Vulnerability

Mozilla Firefox is prone to a remote code-execution vulnerability. Successful exploits may allow an attacker to execute arbitrary code in the context of the user running the affected application. Failed attempts will likely result in denial-of-service conditions. The issue affects Firefox 3.5; other versions may also be vulnerable. NOTE: Remote code execution was confirmed in Firefox 3.5 running on Microsoft Windows XP SP2.

Read more...
PCWorld
  • New Intel CEO creates mysterious 'New Devices' division

    Well, that didn't take long. A mere five days after Brian Krzanich took the reins as the new CEO of Intel, he's shaking things up at an organizational level.

    Krzanich has reorganized key business groups and created a new "New Devices" division destined for, well... we're not quite sure yet. Reuters first reported the changes after an anonymous source came forward with the information. Intel spokesman Chuck Mulloy confirmed to Reuters that Krzanich had sent out an internal email outlining the changes, but didn't elaborate on the shakeup.

    We're reached out to Intel and will update this post when the company gets back to us.

    New devices?

    What, exactly, falls under the purview of the New Devices division? The very name is cloaked in ambiguity, and no details are currently available.

    To read this article in full or to leave a comment, please click here