Home > > Printer-friendly

Printer-friendly

Facebook Awarded $711 Million from "Spam King" [1]

Facebook won a huge judgment from the spammer who already owes MySpace $234 million from an earlier suit.

Sanford Wallace [2] has been a known spammer since the 1990's and is one of the first to be crowned "Spam King". His most recent spamming scheme was sending phishing messages to Facebook users that contained links to phishing websites asking for login information. The information submitted was used by Wallace to spam the phishing victims' friends with the aim to pull in even more potential phishing victims. It's also believed that Wallace was paid to redirect Facebook users to money generating web sites.

"The record demonstrates that Wallace willfully violated the statutes in question with blatant disregard for the rights of Facebook and the thousands of Facebook users whose accounts were compromised by his conduct," Fogel said in his ruling.

Facebook sought $7 billion in damages, as allowed by the CAN-SPAM act and California business code. However, California federal judge Jeremy Fogel felt that was disproportionate to the actual damage caused by Wallace and awarded Facebook only $710,737,650 instead. Judge Fogel also turned Wallace over to the U.S. Attorney's Office to be prosecuted for criminal contempt and for willful violation of a temporary restraining order and injunction.

With Wallace possibly facing jail time and owing MySpace $234, it won't be easy for Facebook to collect its money.  But at least the "Spam King" as been caught and may be taken off the grid for a time.

More information on Information Week [3]. Photo courtesy of Canadian Broadcasting Centre.

 

October 30, 2009
4 comments [4]

Why Twitter Links Should Scare You [5]

26% of Twitter messages contain links, half of which are from spammers and lead to malicious websites.

With only 140 characters per Twitter message, it makes sense to shorten URLs and leave characters to say what you have to say. But with shortened URLs you have no idea what your final web destination will be. A spreader of malware and malicious websites couldn't be happier!

Malicious Links in Abundance

Researchers at Kaspersky Labs have found that as many as one in every 500 links on Twitter lead to sites hosting malware. They have also discovered that about 26% of Twitter messages - tweets - contain links and about half of those are created by spammers and people with bad intentions.

The two most popular URLs that the Krawler found posted to Twitter so far passed through the system in September. Both directed users to online dating sites. One of the sites, getion.com, is known to have hosted malware in the past, Raiu said.

What Twitter is Doing

So why isn't Twitter doing something to keep its users safe?  Well, it is to an extent. In August Twitter started using a filtering system by Google to detect malicious URLs. The system checks the URLs against a blacklist and then either blocks the malicious URL from being posted or warns users to think before clicking on the link. However, the system only scans URLs that are shortened using the Bit.ly shortening service - the most commonly used on Twitter. Any links shortened using any of the over 200 other formats are not picked up by Twitter's filter.

Malicious URLs were discovered over a year ago before Twitter gained it's current level of popularity. Now, malware links regularly appear in "trending topics" where people are often checking to see what is the latest and greatest.

What You Can Do

  • There are several companies that have developed more inclusive filters to sift through the shortened URLs on Twitter. Kaspersky [6] has developed the Krab Krawler that currently examines 500,000 unique URLs a day. Of the URLs examined, 100 to 1,000 a day are sites hosting malware.
  • AVG Technologies offers LinkScanner [7], a tool that scans and strips URLs of any malware that they may contain. Finjan Inc. has a tool, SecureTwitter [8], that sends out a warning message when a malicious URL is detected.
  • You also have the option of expanding the shortened link before you click on it. The bit.ly blog [9] has instructions on how to get the plug-in tool to expand bit.ly (and other) shortened URLs.
  • Consider using stand-alone Twitter software such as TweetDeck [10]. They will often provide filtering of their own and/or a preference item to expand shortened URLs before you click them.

Video Interview with Kaspersky Lab Malware Researcher Costin Raiu

 Read more at the Threat Level blog [11]. Graph courtesy of Kaspersky Labs [6]

October 29, 2009
4 comments [12]

Data Breach Danger: Study Shows It’s Real [13]

Data Breach

So you received a data breach notification in the mail… no big deal, right? Not according to Javelin Strategy & Research’s latest report [14]. In fact, Javelin’s latest research reveals you are four times more likely to suffer identity fraud if you’ve received a data breach notification within the past year.

The average fraud victim will spend 30 hours and $496 out-of-pocket costs to restore their affairs, merchants and financial providers will spend billions to protect systems and brands, and law enforcement will work hard to chase the bad guys.

Many states around the country are enacting laws requiring entities that have experienced data security breaches to notify affected individuals whose personal information may be at risk. However, there seems to be a disconnect between breach notifications and consumer awareness of the risk they bring.

Why You Should Take Notice

  • During each of the past three years, an average of 11% of consumers received a breach notification.
  • Of these consumer breach victims, more than 33% experienced exposure of their Social Security numbers and 15% had their ATM PINs compromised.
  • Despite 19.5% of breach victims suffering some kind of fraud in the past year, only 2% attribute their fraud to the breach.

Come On, Do I Really Need To Worry About This?

It might be a good idea considering the Identity Theft Resource Center [15] has already tracked 356 data breaches so far this year. Forty-six of those breaches have involved financial institutions, and when they or their third-party service providers are breached, it’s nasty.

Take for example the Heartland Payment Systems [16] breach earlier this year. The result of this breach was a staggering compromise of 130 million credit and debit cards. Now that’s a lot of Visa cards…yikes!

What You Can Do?

There is very little we can do to avoid data breaches, however there are steps that we can take to better prepare ourselves for the next time that breach notification shows up in the mailbox:

  • If you get a data breach notification, don’t dismiss it. "Data breach notifications are intended to help consumers take protective action," said Mary Monahan, Javelin Managing Partner & Research Director.
  • Obtain credit monitoring services. Most companies will provide this free of charge in the event of a security breach, so take them up on it. You may also consider employing a more complete credit monitoring service [17] or even initiating a credit freeze [18].
  • Limit the amount of sensitive data you give out online or over the telephone. If the requested information has nothing to do with the transaction you’re making, don’t provide it. For more on this, read our article about becoming a "privacy grouch [19]."
  • Avoid or be cautious using wireless devices, “convenience cards”, credit cards or unfamiliar online transaction sites.

Lastly, remember the words of the orator, Robert Green Ingersoll when he said:

“It is a thousand times better to have common sense without education than to have education without common sense.”

October 28, 2009
0 comments [20]

For Scareware, Every Day is Halloween [21]

Halloween is all about tricks, treats and pretending to be something your not. Scareware must think every day is Halloween.

Computer experts are reporting that scareware is on the rise. Scareware - a sneaky hacker technique used to steal personal information and spread viruses - is being found in more and more places online and even on trusted sites, like the New York Times.

"The recent scareware attacks are cropping up everywhere and can be found on even the most trusted Web sites online," said Alison Southwick, BBB spokesperson. "The threat of scareware undermines consumer trust in compromised Web sites, and on the Internet in general, but there are steps computer users can take to protect themselves."

How Scareware Tricks and Treats

Scareware usually presents itself as a pop up window on your computer that looks like it is from your computer. It gives some message that your computer has been infected with a virus that needs to be removed. Often the message tells you to go to the link provided to purchase and download anti-virus software. Once the software is purchased the download begins. Unfortunately, it is not anti-virus software that is being downloaded, but more viruses and malware.

If that weren't bad enough, now the hackers have your credit card information too.

This senario is playing out all over the internet. It was in mid-September that visitors to the New York Times web site started getting the infected pop up window. The New York Times traced the infected window back to an unauthorized ad. They later found out that the ad space was sold to hackers posing as Vonage.

But The New York Times is not the only site being affected and pop up windows are only half the story with scareware. According to Computer World Magazine, hackers are also "poisoning Google search results." Hackers monitor popular search topics and then create infected web pages with related content. They work to get those to the top of Google search results and when someone clicks a link in the search results - the infamous pop up window appears.

 

How to Protect Your Computer

Fortunately there are steps that you can take to protect your computer from scareware:

  • Never let your guard down. It is a fact that scareware can show up on even the most trusted sites, Google, Twitter, The New York Times, etc.
  • Protect your computer. Keep your operating system updated and install a good quality anti-virus program. We recommend the following packages: Norton 360 [22] (includes backup and other features), Norton Internet Security 2010 [23] (good all around option), or avast! [24] (free and good), and keep it up to date. Also make sure that all security patches and updates are installed for your webrowser and programs like Adobe Flash Player.
  • Take immediate action during an attack. If a scareware window opens up, force close it using the task manager and then run your trusted anti-virus software.

If you clicked on the link and have downloaded the software all is not lost, but things aren't good. The Washington Post offers advice on their Security Fix blog [25] of how to rid your computer of the viruses and malware. But if you aren't computer savvy, you may think about calling a professional to clean up the mess.

 

UPDATE: An article from Wired magazine's Threat Level blog [26] sheds more light on how web sites are being targeted for malware distribution:

Web ads have become much more advanced over the years and many now include scripts that provide data tracking and other functions. Because of this, crooks are working to have their "ads" run on popular websites. Their ads also contain scripts, but the code displays scareware instead of tracking clicks or views.

In the article, Gawker Media - a major blog network of sites like Gizmodo, LifeHacker, Jalopnik and others - was targeted for ad placement, but fortunately Gawker has a team of geeks that digs into the code of any ad and confirms that it contains no malicious code. I'm guessing the NY Times now is enforcing a similar policy (yep, it is now [27]).

Heaven help us when we visit sites that have no such team of geeks to protect us from malicious ads...

October 27, 2009
2 comments [28]

Clampi Trojan Virus Attacks the World of Online Banking [29]

July 2009 not only brought the hopes of fun summer activities, but it also brought the new vicious Trojan virus called Clampi. Clampi is a newly sophisticated virus designed to attack online banking systems. And unlike most Trojan viruses this virus can be picked up from trusted sites like blogs, online magazines, search engines and mainstream news websites, not just gambling and pornography sites. It also is only designed to attack computers running the Microsoft Windows operating system. So Mac users are safe from Clampi, for now.

Currently, Clampi is tracking over 4,500 financial websites. Most Trojan viruses usually track 30-40 sites at a time. Clampi is designed to watch: banks, credit card companies, e-mails, retail sites, utilities, online casinos, wire transfer services, share brokerages, government sites and mortgage lenders. Clampi is also not just limited to the United States. It has been found attacking in the United States, Britain and other English speaking countries.

How Clampi Operates

Once Clampi has been picked up it settles into your computer and waits.  What does it wait for? It waits for the user to log on to a bank account, credit card or some other financial website. Once the login information is entered, Clampi grabs it and shoots it to the cyber criminal's computer. From there the criminal uses the information to fulfill their desires. Whether it is taking money from a bank account, using a credit card to make purchases or reek whatever havoc they may. 

What Clampi Can Do

Maybe you're thinking that this can't happen to you and maybe it won't. But it has been reported that through the use of Clampi criminals have stolen $75k from a car parts company in Georgia, $30k from a non-profit childcare organization [30] in Seattle, $480k from an online city bank account [31], $150k from a public school district in Oklahoma, $350k from a Chicago-are school district [32] and $700k from the Western Beaver School District [33] in Pennsylvania. There have also been reports of companies losing anywhere from $10k to $500k because of this one virus. There is really no telling how many people have been victims of the Clampi virus.

What You Can Do

The most important thing you can do is to be proactive about protecting yourself from getting Clampi. Here are some ways to be proactive:

  • Protect your computer with security software. It should be a natural part of being online. Make sure that you have the most current version of your anitvirus software and download any necessary patches to keep it current.
  • Avoid clicking on suspicious links on blogs, e-mails and social networking sites. If you are not sure that it can be trusted, then don't go there.
  • Don't use e-commerce sites that you are not familiar with and use a credit card instead of a debit card when making online purchases.
  • Use caution when using a wi-fi network - especially one outside your home, like at an airport [34] or coffe shop. Don't access financial web sites when using wifi in these kinds of locations. Make sure that your connection is password protected so that others cannot hack into your connection. Use WPA2 [35] (or stronger) encryption and strong passwords when setting up your wireless network at home.
October 22, 2009
0 comments [36]

Free Zone Pro Firewall Software - Oct. 13 Only! [37]

Zone Alarm has made their excellent Zone Alarm Pro 2010 software available for download today - October 13, 2009 - free of charge. It will be available until 6am PST on October 14, 2009.

The free download has the following stipulations:

  • License valid for one year (10/13/09 to 10/14/10)
  • License valid for up to 3 PCs
  • This offer is valid for new customers only
  • Limit one per customer

The software is available for download here - http://download.zonealarm.com/bin/free/sum/index.html?cid=W100020 [38]

October 13, 2009
0 comments [39]

Source URL: http://fightidentitytheft.com/blog/archives/200910

Links:
[1] http://fightidentitytheft.com/blog/facebook-awarded-711-million-spam-king
[2] http://en.wikipedia.org/wiki/Sanford_Wallace
[3] http://www.informationweek.com/news/global-cio/security/showArticle.jhtml?articleID=221400140
[4] http://fightidentitytheft.com/blog/facebook-awarded-711-million-spam-king#comments
[5] http://fightidentitytheft.com/blog/do-you-know-what-lurking-twitter-url
[6] http://www.kaspersky.com/
[7] http://linkscanner.avg.com/
[8] http://securebrowsing.finjan.com/
[9] http://blog.bit.ly/post/68979274/expand-urls-and-get-traffic-summaries-before
[10] http://www.tweetdeck.com
[11] http://www.wired.com/threatlevel/2009/10/twitter_malware/
[12] http://fightidentitytheft.com/blog/do-you-know-what-lurking-twitter-url#comments
[13] http://fightidentitytheft.com/blog/data-breach-danger-study-shows-it’s-real
[14] http://www.javelinstrategy.com/2009/10/27/between-paranoia-and-compacency-educating-consumers-on-data-breaches-and-fraud-risk/
[15] http://www.idtheftcenter.org/artman2/publish/lib_survey/ITRC_2008_Breach_List.shtml
[16] http://www.bankinfosecurity.com/articles.php?art_id=1200
[17] http://fightidentitytheft.com/credit-monitoring.html
[18] http://fightidentitytheft.com/credit-freeze-laws.html
[19] http://fightidentitytheft.com/blog/identity-theft/protect-your-privacy-by-becoming-a-privacy-grouch
[20] http://fightidentitytheft.com/blog/data-breach-danger-study-shows-it’s-real#comments
[21] http://fightidentitytheft.com/blog/scareware-everyday-halloween
[22] http://www.amazon.com/gp/product/B001U3PYLQ?ie=UTF8&tag=fightidentity-20&linkCode=as2&camp=1789&creative=390957&creativeASIN=B001U3PYLQ
[23] http://www.amazon.com/gp/product/B002L7BR20?ie=UTF8&tag=fightidentity-20&linkCode=as2&camp=1789&creative=390957&creativeASIN=B002L7BR20
[24] http://www.avast.com/eng/avast_4_home.html
[25] http://voices.washingtonpost.com/securityfix/2009/09/what_to_do_when_rogue_anti-vir.html
[26] http://www.wired.com/threatlevel/2009/10/gawker/
[27] http://www.wired.com/threatlevel/2009/09/nyt-revamps-online-ad-sales-after-malware-scam/
[28] http://fightidentitytheft.com/blog/scareware-everyday-halloween#comments
[29] http://fightidentitytheft.com/blog/new-trojan-virus-attacks-world-online-banking
[30] http://voices.washingtonpost.com/securityfix/2009/09/online_bank_robbers_target_hea.html
[31] http://www.theregister.co.uk/2009/10/14/microsoft_windows_bank_thefts/
[32] http://www.eschoolnews.com/news/top-news/news-by-subject/technologies/index.cfm?i=61006
[33] http://www.computerworld.com/s/article/9138636/School_boards_hit_with_cash_stealing_Trojan
[34] http://www.fightidentitytheft.com/blog/airport-wireless-network-not-as-safe-as-you-think
[35] http://en.wikipedia.org/wiki/Wi-Fi_Protected_Access
[36] http://fightidentitytheft.com/blog/new-trojan-virus-attacks-world-online-banking#comments
[37] http://fightidentitytheft.com/blog/free-zone-pro-firewall-software-oct-13-only
[38] http://www.fatwallet.com/redirect/bounce.php?afsrc=1&mid=14241339&url=http://download.zonealarm.com/bin/free/sum/index.html?cid=W100020
[39] http://fightidentitytheft.com/blog/free-zone-pro-firewall-software-oct-13-only#comments