Wednesday, November 5, 2008

SPAMS WITH THE HIGHEST RATINGS IN MY E-MAIL INBOX


Email spams can be described in two simple words "junk e-mail". Junk as they are, which are now a common fare in everyone's email inbox, but they can rob and con you and are dangerous, malware embedded, links you to dangerous sites if you heed them. Sometimes before branding them as spam in my Yahoo Mail inbox, I took the time to read them, and found out that they are becoming more creative each day. If you have read my previous post, "One of My Fave Spams ..." you will find that some are amusing to the point of beguiling the ignorance in us. Presently these spams cluttered my inbox in various prose and forms. As usual, no point in being irritated, so, I took the time to read, 'appreciate', and research them in various anti spam sites.
Here's what I found out:

THE "NIGERIAN" E-MAIL SCAMS
The Bait: Con artists claim to be officials, businesspeople, or the surviving spouses of former government honchos in Nigeria or another country whose money is somehow tied up for a limited time. They offer to transfer lots of money into your bank account if you will pay a fee or "taxes" to help them access their money. If you respond to the initial offer, you may receive documents that look "official." Then they ask you to send money to cover transaction and transfer costs and attorney's fees, as well as blank letterhead, your bank account numbers, or other information. They may even encourage you to travel to the country in question, or a neighboring country, to complete the transaction. Some fraudsters have even produced trunks of dyed or stamped money to try to verify their claims.
The Catch: The emails are from crooks trying to steal your money or your identity. Inevitably, in this scenario, emergencies come up, requiring more of your money and delaying the "transfer" of funds to your account. In the end, there aren't any profits for you, and the scam artist vanishes with your money. The harm sometimes can be felt even beyond your pocketbook: according to State Department reports, people who have responded to "pay in advance " solicitations have been beaten, subjected to threats and extortion, and in some cases, murdered.
Your Safety Net: If you receive an email from someone claiming to need your help getting money out of a foreign country, don't respond. If you've lost money to one of these schemes, call your local Secret Service field office. Local field offices are listed in the Blue Pages of your telephone directory.

FOREIGN LOTTERIES
The Bait: Emails boasting enticing odds in foreign lotteries. You may even get a message claiming you've already won! You just have to pay to get your prize or collect your winnings.
The Catch: Most promotions for foreign lotteries are phony. The scammers will ask you to pay "taxes," "customs duties," or fees – and then keep any money you send." Scammers sometime ask you to send funds via wire transfer. Don't send cash or use a money-wiring service because you'll have no recourse if something goes wrong. In addition, lottery hustlers use victims' bank account numbers to make unauthorized withdrawals or their credit card numbers to run up additional charges. And one last important note: participating in a foreign lottery violates U.S. law.
Your Safety Net: Skip these offers. Don't send money now on the promise of a pay-off later.
For more spams update, visit:
Hoax Busters.org
OnGuard OnLine
Snopes.com

Stumble Upon Toolbar

Monday, November 3, 2008

'GOOGLE HACKING' POSSIBLE . . . WARNS SECURITY ANALYST


Search engines such as Google are increasingly being used by hackers against Web applications that hold sensitive data, according to a security expert.
Even with rising awareness about data security, it takes all of a few seconds to pluck Social Security numbers from Web sites using targeted search terms, said Amichai Shulman, founder and chief technology officer for database and application security company Imperva.
The fact that Social Security numbers are even on the Web is a human error; the information should never be published in the first place. But hackers are using Google in more sophisticated ways to automate attacks against Web sites, Shulman said.
Shulman said Imperva recently discovered a way to execute a SQL injection attack that comes from an IP (Internet Protocol) address that belongs to Google.
In a SQL injection attack, a malicious instruction is entered on a Web-based form and answered by a Web application. It often can yield sensitive information from a backend database or be used to plant malicious code on the Web page.
Shulman declined to give details on how the attack works during his presentation at the RSA Conference on Monday, but said it involves Google's advertising system. Google has been notified, he said.
Manipulating Google is particularly useful since it offers anonymity for a hacker plus an automated attack engine, Shulman said.
Tools such as Goolag and Gooscan can execute broad searches across the Web for specific vulnerabilities and return lists of Web sites that have those problems.
"This is no more a script kiddy game -- this is a business," Shulman said. "This is a very powerful hacking capability."
Another attack method is so-called Google worms, which use the search engine to find specific vulnerabilities. With the inclusion of additional code, the vulnerability can be exploited, Shulman said.
"In 2004, this was science fiction," Shulman said. "In 2008, this is a painful reality."
Google and other search engines are taking steps to stop the abuse. For example, Google has stopped certain kinds of searches that could yield a trove of Social Security numbers in a single swoop. It also puts limits on the number of search requests sent per minute, which can slow down mass searches for vulnerable Web sites.
In reality, it just forces hackers to be a bit more patient. Putting limits on search also hurts security professionals who want to do automated daily searches of their Web sites for problems, Shulman said.
Shulman said he's seen another kind of attack called "site masking," which causes a legitimate Web site to simply disappear from search results.
Google's search engine penalizes sites that have duplicate content and will drop one from its index. Hackers can take advantage of this by creating a Web site that has a link to a competitor's Web page but is filtered through a proxy server.
Google indexes the content under the proxy's domain. If this is done enough times with more proxy servers, Google will consider the targeted Web page a duplicate and drop it from its index.
"This is quite a business hassle," Shulman said.
One way Web site administrators can defend against this is barring their Web site from being indexed by anything other than the legitimate IP address of a search engine, Shulman said.

Stumble Upon Toolbar

Saturday, November 1, 2008

WHAT PROGRAMS I RUN AT STARTUP . .

Let's just put it this way.. You boot your computer and you let these programs load at startup... your entire Microsoft Office, your Quicktime is always there so why not your Winamp too, and your day is not complete without your tinkering with Photoshop and with Adobe Reader as well. While you're at it, I think you're going to need some guardians, so let's include your all security tools.. your anti virus/spywares in real time. Now we know what happens next when we boot and load all these programs at startup, and it's the right after, I'm stressing here. Most likely these programs will be in the system tray, unused, still in memory usage and running in background. Personally, I have nothing against those programs, in fact I like them, I just don't want their files running around causing extra overhead everytime even when they are not in use.

With the exception of various Microsoft autoloading programs that can't be disabled, here is a brief round up of what programs I allow to autoload at startup and this changes from time to time:

- Security first for my computer, with the Windows Security Center running in background, I let go running my security tools like my antivirus and firewall, and enable my anti spyware to realtime only when I go online.

- useful utilities like MYUsbOnly, which locks my usb ports against uninvited usb devices, 3D Audio Configuration, and Web Accelerator- my accelerator sometimes tends to run long diagnostics when I go online without me enabling it first, so I put it on standby and ready.


- I let go a bit with my desktop decoratives or rather just improving my Windows' interface with WinCustomize-LogOn and Vista Start Menu.
Some Some programs' autoloading can be disabled automaticaly right during the installation stage with their check or uncheck options to appear in the system tray. On already installed programs you can disable them by going to their Menus, Options or Preferences settings, or through their icon's settings in the system tray, there is likely a " to appear in the system tray or startup" option which you can uncheck. There are also some autoloading programs whose icons never appear in the system tray but autoloads everytime are running in the background. With Glary Utilities' Startup Manager these programs are now visible and you can just simply uncheck them to disable their autoloading or even delete their entry. You can also Add Program to startup if you want to. In some cases, there are programs that need to be keep running all the time, from boot to shutdown, for them to function fully, so always be careful and gather the details first about a particular program before disabling it.

Stumble Upon Toolbar

Search Engine Spider Simulator

Enter URL to Spider