{"id":7667,"date":"2005-01-20T06:59:48","date_gmt":"2005-01-20T13:59:48","guid":{"rendered":"http:\/\/hill-kleerup.org\/blog\/wp\/2005\/01\/20\/spam-spam-spam-and-phish.html"},"modified":"2005-01-20T06:59:48","modified_gmt":"2005-01-20T13:59:48","slug":"spam_spam_spam","status":"publish","type":"post","link":"https:\/\/hill-kleerup.org\/blog\/2005\/01\/20\/spam_spam_spam.html","title":{"rendered":"Spam, spam, spam and phish"},"content":{"rendered":"<p>Intersting &#8212; and alarming &#8212; note on how <a href=\"http:\/\/www.computerworld.com\/securitytopics\/security\/cybercrime\/story\/0,10801,99057,00.html?source=x06\" target=\"_blank\">phishers are getting more sophisticated<\/a>.  &#8220;Phishing&#8221; is an attempt, usually through e-mail, to get you to reveal confidential account information.  The most common manifestation of this is an e-mail saying, &#8220;Hey, you need to update your account info at [fill in the name of the financial institution].  Click here.&#8221;<\/p>\n<p>These sorts of attacks used to be (and, sometimes, still are) crude frauds, with typos and bad writing and all sorts of other tells that it wasn&#8217;t, in fact, Citibank trying to contact you.  But the phishers are getting more sophisticated.<\/p>\n<p class=\"block\">Phishing attacks have reached 57 million U.S. adults and have compromised at least 122 well-known brands so far, according to several estimates. At the end of 2004, nearly half of those attacks contained some sort of spyware or other malicious code, Trudeau said.<\/p>\n<p>One attack, first documented last month by the Danish security firm Secunia, misdirects Web surfers by modifying a little-known directory in Microsoft Windows machines called a host file. When an Internet user types a Web address into a browser, he is directed instead to a fraudulent site.  This technique has shown up in attacks spoofing several South American banks, said Scott Chasin, chief technology officer at MX Logic Inc., a security firm in Denver. The convergence of all of these threats means &#8220;we can expect to see some large attacks in the near term,&#8221; he said.<\/p>\n<p>Another more ambitious attack targets the domain name servers that act as virtual telephone books, matching domain names with numerical addresses given to each computer on the Internet. If one of those computers is compromised, Internet users who type in www.bankofamerica.com, for example, could be directed to a look-alike site run by identity thieves.<\/p>\n<p>Domain name servers are thought to be tougher to crack, but hackers can find a way in by posing as a company&#8217;s tech-support department and asking new employees for their passwords, Trudeau said.  Domain-name hijacking is suspected in incidents involving Google Inc., Amazon.com Inc., eBay Germany and HSBC Bank of Brazil, Chasin said.<\/p>\n<p>As a general rule, I ignore (in fact, flag as spam) any messages that come in with a subject line that indicates I have account info that needs updating.  That&#8217;s because legitimate financial institutions and the like are well aware of this problem, and <em>don&#8217;t use such messages<\/em>.<\/p>\n<p>If such a message does come in from an institution that I actually do business with, I&#8217;ll look at it.  Anything that requires me to click through in the message to go to a web site, I consider to be a scam.<\/p>\n<p>That all said, there&#8217;s not a lot that folks can do about DNS spoofing like the above passage mentions (any more than there&#8217;s much you can do about someone who works at a credit card company stealing your data).  Just be vigilent, check your statements, and be careful before you click through on anything.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Intersting &#8212; and alarming &#8212; note on how phishers are getting more sophisticated. &#8220;Phishing&#8221; is an attempt, usually through e-mail, to get you to reveal confidential account information. The most&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_seopress_titles_title":"","_seopress_titles_desc":"","_seopress_robots_index":"","_seopress_robots_follow":"","_seopress_robots_imageindex":"","_seopress_robots_snippet":"","_seopress_robots_primary_cat":"","_seopress_robots_breadcrumbs":"","_seopress_robots_freeze_modified_date":"","_seopress_robots_custom_modified_date":"","_seopress_robots_canonical":"","_seopress_social_fb_title":"","_seopress_social_fb_desc":"","_seopress_social_fb_img":"","_seopress_social_fb_img_attachment_id":0,"_seopress_social_fb_img_width":0,"_seopress_social_fb_img_height":0,"_seopress_social_twitter_title":"","_seopress_social_twitter_desc":"","_seopress_social_twitter_img":"","_seopress_social_twitter_img_attachment_id":0,"_seopress_social_twitter_img_width":0,"_seopress_social_twitter_img_height":0,"_seopress_redirections_value":"","_seopress_redirections_enabled":"","_seopress_redirections_enabled_regex":"","_seopress_redirections_logged_status":"","_seopress_redirections_param":"","_seopress_redirections_type":0,"_seopress_analysis_target_kw":"","_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[39],"tags":[],"class_list":["post-7667","post","type-post","status-publish","format-standard","hentry","category-spam"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack-related-posts":[{"id":45614,"url":"https:\/\/hill-kleerup.org\/blog\/2014\/10\/01\/heavens-to-bit-ly.html","url_meta":{"origin":7667,"position":0},"title":"Heavens to Bit.ly","author":"***Dave","date":"Wed 1-Oct-14 10:11am","format":false,"excerpt":"Well, one mostly-sussed-out mystery solved. Bit.ly links weren't working from my company's network, and it turns out that the company has blocked it because the service was so widely used in phishing attacks.Of course goo.gl and t.co and other shorterner services all seem to be functioning fine, but presumably phishers\u2026","rel":"","context":"In &quot;~PlusPosts&quot;","block_context":{"text":"~PlusPosts","link":"https:\/\/hill-kleerup.org\/blog\/category\/blogging\/plusposts"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/hill-kleerup.org\/blog\/wp\/wp-content\/uploads\/2014\/10\/Batman%2BNo.gifimgmax%3D660.gif?resize=350%2C200&ssl=1","width":350,"height":200},"classes":[]},{"id":8227,"url":"https:\/\/hill-kleerup.org\/blog\/2006\/01\/17\/spam_spam_spam.html","url_meta":{"origin":7667,"position":1},"title":"Spam, spam, spam, spam &#8230;","author":"***Dave","date":"Tue 17-Jan-06 6:15pm","format":false,"excerpt":"My Internet host, Hosting Matters, is rolling out a new anti-spam system to its various servers, and it finally got to mine. The new system, MailScanner, still uses the SpamAssassin...","rel":"","context":"In &quot;Spam&quot;","block_context":{"text":"Spam","link":"https:\/\/hill-kleerup.org\/blog\/category\/blogging\/computer-security\/spam"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":48618,"url":"https:\/\/hill-kleerup.org\/blog\/2014\/12\/02\/a-big-phishing-catch.html","url_meta":{"origin":7667,"position":2},"title":"A Big Phishing Catch","author":"***Dave","date":"Tue 2-Dec-14 5:08pm","format":false,"excerpt":"Yeah, I admit that I rely a lot on \"boy, this formatting looks bad\" and \"gee, this doesn't sound like it was written by a native speaker of English\" in evaluating phishing emails (http:\/\/en.wikipedia.org\/wiki\/Phishing). Oh, I try to follow good practices, too (\"Um, no, I will not click on this\u2026","rel":"","context":"In &quot;~PlusPosts&quot;","block_context":{"text":"~PlusPosts","link":"https:\/\/hill-kleerup.org\/blog\/category\/blogging\/plusposts"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":8175,"url":"https:\/\/hill-kleerup.org\/blog\/2005\/05\/02\/go_phish.html","url_meta":{"origin":7667,"position":3},"title":"Go phish","author":"***Dave","date":"Mon 2-May-05 10:52pm","format":false,"excerpt":"Phishing is the attempt to get you to tell folks your userids and passwords and similar identity-thievable items, usually by tricking you. The classic is the false bank (or credit...","rel":"","context":"In &quot;Spam&quot;","block_context":{"text":"Spam","link":"https:\/\/hill-kleerup.org\/blog\/category\/blogging\/computer-security\/spam"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":4827,"url":"https:\/\/hill-kleerup.org\/blog\/2003\/12\/23\/what_have_you_g.html","url_meta":{"origin":7667,"position":4},"title":"What have you got in your in-box?","author":"***Dave","date":"Tue 23-Dec-03 3:55pm","format":false,"excerpt":"An Open Letter to Businesses Sending Out E-Mail, Capital One in Particular: Given the wide array of Internet e-mail scams and spoofs and phishing expeditions, if you send out an...","rel":"","context":"In &quot;Spam&quot;","block_context":{"text":"Spam","link":"https:\/\/hill-kleerup.org\/blog\/category\/blogging\/computer-security\/spam"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":15563,"url":"https:\/\/hill-kleerup.org\/blog\/2009\/08\/12\/its-not-the-phishing-attempt-its-the-implication-that-im-an-idiot.html","url_meta":{"origin":7667,"position":5},"title":"It&#8217;s not the phishing attempt, it&#8217;s the implication that I&#8217;m an idiot","author":"***Dave","date":"Wed 12-Aug-09 1:24pm","format":false,"excerpt":"I mean ... Subject: Account Review From: service <update@support.com> As part of our security measures, we regularly screen activity in the system. We recently contacted you after noticing an issue on your account. We requested information from you for the following reason: We have observed activity in this account that\u2026","rel":"","context":"In &quot;Spam&quot;","block_context":{"text":"Spam","link":"https:\/\/hill-kleerup.org\/blog\/category\/blogging\/computer-security\/spam"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]}],"_links":{"self":[{"href":"https:\/\/hill-kleerup.org\/blog\/wp-json\/wp\/v2\/posts\/7667","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/hill-kleerup.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/hill-kleerup.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/hill-kleerup.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/hill-kleerup.org\/blog\/wp-json\/wp\/v2\/comments?post=7667"}],"version-history":[{"count":0,"href":"https:\/\/hill-kleerup.org\/blog\/wp-json\/wp\/v2\/posts\/7667\/revisions"}],"wp:attachment":[{"href":"https:\/\/hill-kleerup.org\/blog\/wp-json\/wp\/v2\/media?parent=7667"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/hill-kleerup.org\/blog\/wp-json\/wp\/v2\/categories?post=7667"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/hill-kleerup.org\/blog\/wp-json\/wp\/v2\/tags?post=7667"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}