Facebook Scams: Not Out of the Woods

By | November 22, 2011

Facebook may have just won a theoretical warchest from a spammer, but it’s not put its house in order when it comes to scams. Indeed, I suspect they’re getting worse. Now you can get infected without even having to visit your Facebook account.

What happens is that, if you have set your profile to receive email updates when someone sends you a message on Facebook, these trojan scams actually make their way direct into your inbox. Facebook is just the vector:

Here’s a message, as it looks in Gmail:

image

Click on that link and it takes you, not to the Facebook message page, but straight to the dodgy website. In this case the website is still active. It will have a name like YuoTube:

image

and a YouTube-like interface:

image

The message in the ‘player’ says “Your version of Flash Player is out of date.” Without you doing anything the download window will appear:

image

Of course, if you install that you’re in trouble. But are you in trouble if you’ve already visited the page? I’m still working on that.

The Undignified Death of Social Networks

By | November 22, 2011

I’m intrigued, and slightly depressed, at how social networking sites deteriorate so quickly into what are little more than scams. I think it started about a year ago, when a number of sites started pulling the stops out to build up membership.

Now, it seems, it’s all about the money. Take Quechup, for example, which has never had a very good reputation, though some say it’s undeserved. I don’t think anyone would try to argue that now.

I opened an account at Quechup about a year ago, and left it, with no friends. no connections, no activity (a bit like my real life.) I didn’t get anything until last month. In the past month I’ve received more than 30 messages. All of them from people I don’t know; all of them, from the subject line, spam:

image

So what’s the scam, then?

Well, if you’re fool enough to open one of these messages, that’s your limit. Suddenly your inbox looks like this:

image

The message is basically that you can’t open any messages until you upgrade your membership:

image 

Upgrading, of course, costs. Not a lot, but if you’re curious to find out who’s been scamming you, sorry, flirting with you, you have to cough up:

image

My question is this: Who is behind the spam in my inbox?

Admittedly, my profile is a bit provocative:

image

Still. One can’t help feeling that either the spam is being allowed by Quechup as a money-making exercise, or, the only other explanation I can think of, it’s spamming its members with silly messages in the hope they’ll be curious enough to upgrade and read them.

Either way, it’s a social network that’s dead from the neck up.

Sad, really.

Nightmare on Spyware Street

By | November 22, 2011

A case in Connecticut has exposed the legal dangers of not protecting your computer against spyware, as well as our vulnerability at the hands of incompetent law-enforcement officers.

Teacher Julie Amero found herself in a nightmare after spyware on her school computer popped up pornographic images in front of students. Instead of realising this was spyware at work, the state accused her of putting them there and forcing her pupils to watch.

In June of 2007, Judge Hillary B. Strackbein tossed out Amero’s conviction on charges that she intentionally caused a stream of “pop-up” pornography on the computer in her classroom and allowed students to view it. Confronted with evidence compiled by forensic computer experts, Strackbein ordered a new trial, saying the conviction was based on “erroneous” and “false information.”

But since that dramatic reversal, local officials, police and state prosecutors were unwilling to admit that a mistake may have been made — even after computer experts from around the country demonstrated that Amero’s computer had been infected by “spyware.”

It seems the nightmare may be coming to an end, but not without a price. She’s had to admit to one misdemeanour charge and surrender her teaching licence. She’s also been hospitalized for stress and heart problems.

The lesson? This was a school computer, and it seems the school failed to install the necessary updates and protection to prevent the spyware from loading itself. That’s probably something Amero should be exploring with her lawyers.

But there’s a bigger issue. We need, as individuals, to take more reponsibility for the computers we use—to learn the basics of protecting them from attacks, and to be able to at least identify what the problem is when something like this happens. It may have taken a techie guy to clean the computer in this case (I admit spyware is really hard to get rid of) but knowing, roughly, what the problem is should be the bare minimum of our working knowledge of the computers we use.

Connecticut drops felony charges against Julie Amero, four years after her arrest – Rick Green | CT Confidential

Puppy Love, Army Trojans and Perfecting the Phone Call

By | November 22, 2011

I make an appearance on the excellent Breakfast Club show on Radio Australia each Friday at about 01:15 GMT and some listeners have asked me post links to the stuff I talk about, so here they are.

Love on the net

Teenage social networking isn’t so bad, according to the MacArthur Foundation. According to the lead researcher on the project, called the Digital Youth Project, “their participation is giving them the technological skills and literacy they need to succeed in the contemporary world. They’re learning how to get along with others, how to manage a public identity, how to create a home page.”

The study, part of a $50 million project on digital and media learning, used several teams of researchers to interview more than 800 young people and their parents and to observe teenagers online for more than 5,000 hours.

The bit I like in the NYT report is the shameless flirting that goes on, cleverly disguised:

First, the girl posted a message saying, “hey … hm. wut to say? iono lol/well I left you a comment … u sud feel SPECIAL haha.” A day later, the boy replied, “hello there … umm I don’t know what to say, but at least I wrote something …”

U.S. Military Under Attack

Spooked by the rapid spread of a worm called Agent.btz, the U.S. military has banned everything from external hard drives to “floppy disks.”

USBs are a problem: Lenovo this week offered a software package to XP users with a Trojan dropper called Meredrop, found in one of the drivers.

And Telstra earlier this year handed out USB drives at a security conference that were infected with malware.

Could it be China?  The conclusions reached in this year’s US-China Economic and Security Review are far more dramatic than before. In 2007, it says, about 5m computers in the US were the targets of 43,880 incidents of malicious activity — a rise of almost a third on the previous year.

Much of the activity is likely to emanate from groups of hackers, but the lines between private espionage and government-sponsored operations are blurred. Some 250 hacker groups are tolerated, and may even be encouraged, by Beijing to invade computer networks. Individual hackers are also being trained in cyber operations at Chinese military bases.

 

How to Make the Perfect Phone Call

According to the UK Post Office, the perfect phone call should last nine minutes, 36 seconds and contain a mix of chat about family news, current affairs, personal problems and the weather.

Three minutes of that should be spent catching up with news about family and friends, one minute on personal problems, a minute on work/school, 42 seconds on current affairs and 24 seconds on the weather. Chat about the opposite sex should last 24 seconds. 12 seconds of every call should be set aside for a little quiet contemplation.

One in five people said they spent most time on the phone to their mother. The research, by the Post Office, revealed that the phrase “I’ll get your mother” is common. Only three per cent of people named their father as the person they spent most time on the phone with.

Susan042764

“Please help!,” she writes. “I took my husband’s iPhone and found a raunchy picture of him attached to an email to a woman in his sent email file. When I approached him about this, he admitted that he took the picture, but says that he never sent it to anyone.

“He claims that he went to the Genius Bar at the local Apple store and they told him it is an iPhone glitch – that photos sometimes automatically attach themselves to an email address and appear in the sent folder, even though no email was ever sent.

“Has anyone ever heard of this happening?,” she asks. “The future of my marriage depends on this answer!” Read more here.

Think Hard Before You Get Linked In

By | November 22, 2011

I’ve been trying to remove a contact on LinkedIn who proudly claims to be one of the best linked people on the planet. Why that’s a good thing I’m not sure, but I noticed I was getting LinkedIn spam—spam to my own email address, but coming via LinkedIn–from this person, so I tried to remove him. 

Turns out that it wasn’t enough. This morning I got an email from another guy claiming to be the best connected person on the planet (“(he is one of the most linked people in the world”) who said I had been referred to him by none other than the LinkedIn spammer guy I thought I’d removed eight months ago. He wrote:

If so, then please accept my connection request. Since I presently have over 8,900 first tier connections, I cannot send an invitation to you because I have exceeded my limit. Therefore, to connect with me and to benefit from the millions of total connections that I have, click here: [LINK DELETED] and enter my email address [EMAIL DELETED].

So what gives? How come someone I removed from my LinkedIn network is able to refer me to someone else who has somehow been able to get my email address despite not being my buddy, nor connected to a buddy of mine? I’m asking LinkedIn about this, but I also wanted to know what happened to the original spammer I’d deleted. Was he still in my system?

Turns out he is.

Removing a connection in LinkedIn is not, it turns out, the same as removing a contact. It seems to work like this (and I might be wrong, because the explanations on LinkedIn are contradictory.)

The FAQ says you remove a connection via the Remove Connections link:

image

which takes you to a separate list:

image

What you’ll notice about this list is that, unlike your Connections list, it’s not alphabetical. Well it is, in that you can jump straight to a letter (M, say) but within that list the contacts are not in sub-alphabetical order. A cynic would say this is an extra deterrent to connection-pruning, but I’m not a cynic so I won’t say that.

But you might notice this:

image

Huh? Good that the connection won’t be notified that they’ve fallen off your Christmas card list, but how come they’ll still be on my list of contacts? And  how does it square with this other note, on the same page, that says:

Note that once this action is completed this individual will not be able to be added back as a connection.

So the person you’ve gone to all this trouble to remove will still be in your contact list—no way that I can see of removing them from there—but you can’t change your mind and then re-add them back as connection. You can, however, re-invite them, and, indeed, they will remain in your contact list as a constant reminder.

(Just out of interest, how do you re-invite someone to be a connection who didn’t know you’d banished them before? How do you explain that, exactly? “Sorry, I hated you before, but now I don’t hate you anymore?” Could be a good lyric in there.)

Confused? So am I? But here’s the kicker: Does the fact that he’s still in my contacts, and that he’s out there, apparently, recommending me to other LinkedIn spammers, mean I’m still in the LinkedIn spammer’s list of connections?

I suspect it does, because he’s still in my list of connections (but not in my Remove Connections list, if you’re still with me) and he’s still listed as 1st in my list of connections—meaning we still have a connection.

In other words, unless this is a glitch, it is impossible to remove a connection from LinkedIn once you’ve established one.

I’m going to ask LinkedIn to shed light on this. But if it’s true, it should give you pause for thought before you accept a connection via the otherwise useful service. It’s one thing to build one’s network. It’s another to find you have no control over that network—and who in that network might use the information you put there—once it’s built.