by Michael Smith
By all rights and also to all intents and purposes, using fake websites as a malware attack vector should have died out long ago.
Rather than dying, however, those attacks initiated through phony celebrity websites have continued to grow and expand. This is possibly because their intended victims – the celebrity-obsessed among us – either do not have an abundance of brains or a basic knowledge of how computers and the Internet actually work. One could probably assume that in the majority of the cases both would apply.
According to recent data from McAfee, a leading anti-virus program vendor and research company, an Internet user searching for a range of Brad Pitt-themed items, say wallpapers, screensavers, photos, and the like, has, on average, an 18% chance of running into malware in one form or another. Such malware is often served up by a "fake" celebrity website the primary purpose of which it is to push Trojans and worms onto the desktops of the unwary. These websites differ from standard malware landing pads, inasmuch as they try to appear as a legitimate source of news.
In order to create such sites, malware authors rely on an ever-changing list of "hot" celebrities. The turnover rate is fairly high – Paris Hilton was the most dangerous celebrity to search for in 2007, but doesn't even make the top 20 this year, while Britney Spears, which was #4 in 2007, is also missing in action.
This year, 2008, Brad Pitt, Justin Timberlake, and George Clooney are the top three dangerous male searches, and come in first, third, and ninth on McAfee's list and for the women we have Beyonce in first place, followed by Heidi Montag and Mariah Carey. I must say that, personally, I am not even sure who they are; the women, I mean.
McAfee's findings suggest that these sorts of searches are quite common, both at home and in the workplace. Aggressively searching such content while on the job is almost certainly against an employer's rules, even in a company with a fairly lax Internet policy, but that doesn't change the fact that such searches occur, and could expose company systems to any number of attacks. One form of damage control would be to present users with a list of verified "clean" news websites and encourage them to use these for news on any number of topics. Corporate policies that tacitly encourage non-work-related web use aren't going to find a warm reception in the boardroom, but practical advice on where to surf might do more to solve the problem than attempting to beat a basic understanding of the problem into employees' heads.
All of the usual rules about using an up-to-date virus scanner, avoiding suspicious-looking URLs, and not opening an unknown program just because a web browser shoves it in your face still apply, but in this case, the best protection is simply not to look. There are plenty of celebrity websites that make it their mission to stay right on top of the latest rumor, photo, or scandal, and they do so without serving up a healthy portion of Storm Worm on the side. If nothing else, try to remember that you don't actually need Brad Pitt wallpaper or a screensaver featuring outtakes from the Chinese movie My Wife is a Gambling Maestro. When in doubt—heck, even when not in doubt—it's best to stay away entirely.
Searching for desktop items such as Brad Pit screensavers of the like is not a recommended pastime whether or not you have all the relevant anti-virus protection even.
Aside from relying on the unwary to search for celebrity items the distributors of malware also try to trap the news hungry with fake news, such as “Third World War has started”, “USA has attacked Iran”, “Iran has sunk US aircraft carrier”, and similar. I am sure they will not cease to come up with new stuff. Invariably those attempts come via email with links in them which the recipient is meant to click on. He or she will then end up on a website specially created for the sole purpose of distributing this or that Trojan or worm.
News can be had from such a large variety of legitimate main stream and underground news sources – via RSS feed – that no one has to even go as far as opening such emails and clicking on the links therein. If the BBC or the CNN sites are not running it then it has not happened, such as an attack or such, we can rest assured of that. No need to fall prey to the virus distributors.
Whether fake celebrity sites or fake news sites as malware attack vectors, in most cases than not, aside from the above mentioned search for celebrity-themes items, are initiated by a spam email to the recipient. This should already have all possible alarm bells ringing and anyone with an ounce of brain should delete such mails without opening them.
The most dangerous thing on the Internet, and I have written about that before, is the unsecured PC and the user who has no idea what he or she is doing. This is how the spam and the viruses are being circulated.
Have proper anti-virus software (you do not have to pay for it to be secure) that is updates at least once a day. The same for spyware blasting programs – one is in fact called Spyware Blaster – and also have a browser that does not automatically download anything. Internet Explorer's greatest fault is that it just does that; any script and such it encounters and any .exe file it automatically downloads and runs. Use Firefox, for instance. It has a download manager that will ask you what you want to do with the file you have chose to open/download and, obviously, if you have not chosen to open/download anything directly it gives you the choice to cancel it. It is then high time to hightail it out of that site and, for safety, run a full systems check – just in case.
Without the gullibility of so many users and also the fact that so many just do not have the understand of how computers and the Internet work and how, and that despite us all telling them, viruses and such are being spread, such malware sites and spam would have ceases a long time ago.
If everyone would but listen and heed the advise that magazines and websites such as that of the ICT Review here give such malware would by now be either non-existent or very much diminished and would be headed for extinction; all of it.
Alas, as long as there are users out there who do think they know better and such we will continue to be plagued by this.
© M Smith (Veshengro), September 2008
<>
Fake celebrity websites infect the unwary with malware
Shady spammers getting more creative with links
Spammers Use Free Web Services to Shield Links
by Michael Smith
It is becoming more than obvious that the shady emailers have no intention of cutting back their malicious messages, so it is time to once again give a warning.
Take that “Chief Yussuf Osman of Nigeria” who is expecting an immediate answer by from you to get those millions he wants to share with you. By the way, no offense to any actual Yussuf Osman, chief or no chief, out there. So many people tend to fall for it and without knowing what they are clicking on, especially when using Microsoft's Internet Explorer of what ever number, and when they do so they tend to end up with a lovely little Trojan in their system which then turns their system into a bot in a botnet, sending out more and more spam.
Also the likes of Yahoo! Lotteries, which do not exist, asking for your personal dossier, as well as wire transfer requests to receive unclaimed fortunes, are dangerous, it could be even more important that people recognize the dangers of deceptive links in messages.
I am sure that many of the readers have often been warned about clicking links within unexpected emails. A common approach is to link you over to a spoofed login page to collect your password. In the beginning scammers didn’t worry much about what the link looked like but once people began looking more closely at the domain in the hyperlink the scammers started creating links that looked like they pointed to one place, but when you put your mouse over them you would see that the link actually directed you elsewhere. I personally, as and when possible, do a check on any email that I am not sure with by using the full headers.
In Outlook, Outlook Express, or similar client program, this can be called up by the use of a right-click of the mouse and then using the “properties” tabs. Here you can more often than not spot the danger by looking at the return path. If the return path for a supposedly official email from a company is to one joe.blogs@whatever.com then it should already be obvious that this is a spoof.
But theose guys get “better” every day. Malicious spammers are finding new ways to make their links look more legitimate. The latest trend is – drumroll - free web services. Yes. Those free storage facilities, the photo sharing and -storage services, and others.
One of the services, a photo-hosting site called ImageShack, lets people upload different types of photo formats, including Flash files.
Flash files, which have the extension “.swf”, can be used for animated graphics and can also be used to automatically redirect people to other Web sites. That feature can be abused.
The attack involving ImageShack works like this: Spammers upload a Flash file then copy the link for that file which comes from ImageShack's domain in a spam message. If the link is followed, the Flash file redirects the victim to a spam site.
The technique offers an advantage for spammers. Antispam software will often scan links in e-mail and block those e-mails with suspicious-looking ones. But ImageShack's domain is considered to have a good reputation, so messages won't be blocked.
Another more dangerous variation on this theme is a spam e-mail promoting a video.
If the link is clicked, a Flash file redirects the victim to a site where a pop-up window immediately implores the user to download a codec supposedly needed to play the video file. Invariably, the file isn't a codec but some piece of malicious software.
Even if the spam link in the e-mail appears to be OK, there are many other ways to tell if a message is spam.
A similar type of abuse has been made of Microsoft's Windows Live SkyDrive, which is an online file storage service.
The scenario is almost the same: The link is connected with a file on SkyDrive, but then the link performs an HTML redirect to a dodgy site. SkyDrive also allows Flash files to be uploaded, offering another possible way to attack.
Also remember that whenever an email directs you to a site (typically where you have an account and would need to login), you should instead visit the site via typical methods (bookmark, typing URL by hand, even a web search). If there is something significant going on with your account, whether at your email service, such as Yahoo Mail, or your bank, they will usually tell you when you login. If you feel that you absolutely HAVE to click on the link in an email you should examine it closely before clicking on it!
So, remember, it is a dangerous world out there, also ion cyberspace, and we need to have out wits about us. Do not open an email that you are not sure about, especially not it is has an attachment and do not click on links in email that you are not sure of. Also remember that the sender's address can be spoofed and they can even use the name of friends of yours. So, if in doubt, before ever opening the email send the sender, if know to you, e.g. a friend, colleague, member of the family, etc., an email asking for verification. It works and keeps you and your computer safe.
© M Smith (Veshengro), September 2008
<>
The ISAF Web site opens with IT Security cross-industry support
London, UK 9th June 2008 - The Information Security Awareness Forum (ISAF) the cross-industry initiative founded by the ISSA-UK to raise awareness of information security, has formally opened its Web site.
Located at www.theisaf.org, the site seeks to act as a resource that will over time develop in to a focal point for IT security education, news and other relevant information from the Forum.
Launched in February of this year, the ISAF is backed by a number of key organisations, including the ISSA, ISACA, GetSafeOnline, (ISC)², ASIS International, the British Computer Society, Infosecurity Europe and the Institute of Information Security Professionals.
Announcing the opening of the site, the ISAF's chairperson, Dr David King, said that it will help members, as well as the industry generally, pool their expertise and help co-ordinate the Forum's development.
"The Information Security Awareness Forum has been formed to coordinate and build on existing work and initiatives, to improve their overall effectiveness, and ultimately to increase the level of security awareness that will help us all” he said.
"Our new Web site will act as the foundation stone to help us achieve these aims," he added.
Martin Smith MBE, BSc, FSyI, the chairman and founder of the Security Awareness Special Interest Group, supported the opening of the new site, saying that his group strongly recommends the use of the new Forum pages as a first port of call.
"It serves equally well those individuals seeking security awareness knowledge for themselves and their families, and managers of businesses of all sizes and all sectors looking for advice and guidance about how to protect their data from accidental or deliberate disclosure," he said.
Several other leading organisations have voiced their support for the opening of the new ISAF Web site, including the BCS, the Jericho Forum and the NCC:
“The National Computing Centre's members rely on its ability to quickly direct them to trusted best practice. www.theisaf.org provides a highly relevant link in the information chain.”
Danny Dresner, NCC
“Since its inception in 2005, GetSafeOnline.org has been working in partnership with the UK Government, law enforcement and the private sector to raise awareness of internet security issues amongst consumers and micro-businesses. We have always believed that a collaborative approach is the only way to effectively tackle online safety issues – an area that is not only complex, but also relevant to individuals and organizations in different ways. We applaud the initiative to extend this approach through the new Information Security Awareness Forum website."
Tony Neate, Managing Director, Get Safe Online, www.getsafeonline.org
“The new www.theisaf.org website is a great initiative to help improve awareness of infosecurity issues and by coordinating the activities and resources of all the member organisations enables individuals and organisations to quickly find succinct advice to help them. The Information Security Awareness Forum also has a blog on Infosecurity Adviser www.infosecurityadviser.com which is another example of how the forum's members are fulfilling their common aim of improving infosecurity awareness across the entire industry.”
Claire Sellick, Event Director, Infosecurity Europe 2008
“ISSA-UK is delighted with the progress that ISAF has made since its formation as an ISSA-UK Advisory Board initiative in September 07. ISSA-UK congratulates ISAF on the launch of its new website which we strongly believe will support the continued growth and development of Information Security awareness across organisations. It will also provide individuals with a central repository of knowledge and a first point of contact for those seeking help and guidance. This new portal will enable those seeking help to locate good, impartial advice from the leading security organisations, working together in the forum, to communicate awareness to a wider audience.“
Geoff Harris, President of ISSA-UK
“The National e-Crime Prevention Centre welcomes all efforts to protect the UK from electronic crime and the ISAF Web site is an additional and useful site for advice and guidance. Encouraging people and businesses to take action on the available advice is key to reducing the harm to individuals and the economy.”
Ken Rabey, Project Director, National e-Crime Prevention Centre
“Given ISACA’s long-held belief in the importance of educating both institutions and individuals on information security we are confident that the resources on the Information Security Awareness Forum website will help to improve awareness. Having a single website to locate the huge amount of valuable information available from all the member associations is an extremely useful feature.”
Lynn Lawton, CISA, FCA, FIIA, PIIA, International President of ISACA
"ASIS UK Chapter 208 is delighted to support the launch of the ISAF's Web site and encourages all those who want to work together with other security organisations to visit and contribute to the various activities located on the Web pages."
James Willison, Convergence Lead, ASIS UK, Chapter 208
"The IET is pleased to be a member of the Information Security Awareness Forum and believes that the new ISAF Web site will provide a valuable mine of information for both individuals and organisations. We support the development of a co-ordinated approach to the provision of advice and guidance on all matters to do with information security"
Margaret Smith, Member of the IT Sector Panel, The IET
“This coming together of ICT professional bodies, trade associations and interest groups to work together to promote awareness is most welcome and deserves every support from suppliers, users and the many government departments and agencies with responsibilities for the safety and security of those using their systems.”
Philip Virgo, Secretary General, EURIM
“EEMA welcomes the ISAF website initiative which will increase awareness of the online security issues. EEMA is also honoured to be a member and bring a European perspective to the ISAF; time and recourses are a scarce commodity in this day and age and co-ordination in the security space is essential if we are to face up to the issues and challenges of online crime.”
Roger Dean, Executive Director, EEMA
"The BCS is pleased to be a member of the Information Security Awareness Forum and hopes that the endeavours through the new ISAF Web site will signpost both individuals and organisations to resources that they should be aware of both personally and professionally. This is certainly a resource that our 62,000+ members should find useful ongoing.”
Andrea Simmons, CISSP, CISM, MBCS CITP, M.Inst.ISP, BCS Consultant Security Forum Manager
"The CMA, as an early supporter of the Information Security Awareness Forum, fully supports ISAF's pragmatic initiatives to promote industry wide collaboration and particularly welcomes the new ISAF web site (www.theisaf.org). This web site should become the destination (or portal) of choice for people, be they the man or woman in the street or a company Manager, seeking advice and guidance on how to secure information in this electronic and ever more inter-connected world."
Peter Wenham CISSP MICAF CLAS, Director, CMA
"The Jericho Forum welcomes the Information Security Awareness Forum's practical initiatives to promote collaboration between groups working in this crucial area. Collaboration is an essential part of our vision to allow seamless and secure communications between businesses, suppliers and customers across an open, Internet-driven, networked world."
-- Andrew Yeomans, member of Jericho Forum board of management.
Additional Background Information about ISAF Members
A number of professional bodies and organisations involved in information security have come together to form the Information Security Awareness Forum to coordinate and build on existing work and initiatives, to improve their overall effectiveness, and ultimately to increase the level of security awareness in the UK that will help protect us all:
The Information Systems Security Association UK Chapter (ISSA-UK) provides educational forums, publications and peer interaction opportunities that enhance the knowledge, skill and professional growth of its members. ISSA-UK is a founding member and primary supporter of ISAF.
The British Computer Society (BCS) is dedicated to increasing the effectiveness and productivity of security professionals by developing educational programs and materials.
The Communications Management Association (CMA) is the UK’s premier independent membership body for professionals and organisations focused on exploiting communications, networking and ICT, for business advantage.
The Cybersecurity Knowledge Transfer Network provides a single focal point for UK cyber-security expertise, and provides special interest groups and runs events.
EURIM brings together politicians, officials and industry to help improve the quality of policy formation, consultation and implementation.
Get Safe Online is sponsored by the British Government and leading businesses to give you free objective advice.
The Institute of Information Security Professionals (IISP) is setting the standard for professionalism in information security, speaking with an independent and authoritative voice.
The Information Technologists' Company are all senior IT professionals who have joined the Company in order to give something back to the IT sector and the wider community.
The Information Assurance Advisory Council (IAAC)’s aim is to work for the creation of a safe and secure Information Society. It is a unique, not for profit body with high level support from government and industry backed by world class research expertise.
The Institution of Engineering and Technology (IET) provides a global knowledge network to facilitate the exchange of ideas and promote the positive role of science, engineering and technology in the world.
The Information Security Forum (ISF) delivers practical guidance and solutions to overcome wide-ranging security challenges impacting business information today.
The Information Systems Audit and Control Association (ISACA) is a recognised worldwide leader in information technology (IT) governance, control, security and assurance.
ASIS International is dedicated to increasing the effectiveness and productivity of security professionals by developing educational programs and materials.
Infosecurity Europe addresses today’s strategic and technical issues in an unrivalled education programme and showcases the most diverse range of new and innovative products and services from over 300 of the top suppliers on the show floor.
(ISC)² is the globally recognised Gold Standard for certifying information security professionals throughout their careers.
The Jericho Forum is an international IT security thought-leadership group dedicated to defining ways to deliver effective IT security solutions.
The International Underwriting Association of London (IUA) is the world's largest representative organisation for international and wholesale insurance and reinsurance companies.
The Security Awareness Special Interest Group (SASIG) is a subscription free quarterly networking forum open to those who have an interest in, or a responsibility for, raising awareness about security within their organisations.
The National Computing Centre (NCC) has pioneered a methodology for managing the 'human vulnerabilities' in information systems.
The National e-Crime Prevention Centre (NeCPC) is a multidisciplinary and multi-agency network and currently a virtual centre of excellence in e-Crime prevention and enterprise security.
The Police Central E-Crime Unit is a centre of excellence in regard to computer and cyber crime committed under the Computer Misuse Act 1990, notably hacking, maliciously creating and spreading viruses and counterfeit software.
The organisation, EEMA – the European association for e-identity and security – brings together over 135 member organisations (and over 1,500 employees of member organisations) in a neutral environment for education and networking purposes.
For further information visit www.theisaf.org
Online Security
The recent data leak by HMRC, the British Revenue and Customs Service, in the form of mislaying in the post two CDs, has basically led to 25 million people potentially loosing their identity.
Social networking on Facebook (and other such sites) is leading to people's identities being compromised online – though in this case this is due to what often could only be described as “stupidity”.
The question is “how safe are you online?”
If you are using the Internet with a Windows based PC you must have anti-virus software, as well as anti-malware software, and you must have this updated regularly. Daily, at least once a day, as far as anti-virus program is concerned.
A note of caution here: there are some people who think that running more than one anti-virus program will make for better protection. The truth is that is won't and the two or more anti-virus programs may just about clash and fight each other.
This does not hold true, in general, as to anti-malware software. A number of programs, some often doing slightly different tasks than the other, live quite happily together on the same PC. As said, for anti-virus software this is not the case.
You also must have a firewall, at least a software one, better still software and hardware firewall.
Let us start with the Anti-Virus software.
Obviously there is a lot of software out there on the market, many of them making lots of claims as to being better than the competition. They all would, wouldn't they? And many people think that they must have the big brand name software, like Norton Anti-Virus, or Norton Security Suite, from Symantec, or McAfee, or others which all cost lots of money and many folks think that the more they cost the better the product must be.
This is, however, not (always) the case. Yes, it is true that often you get what you pay for and if it is cheap or even free then it may not be as good as the paid for stuff. While this may be the case with most things to some degree with software, however, it is very rarely the case.
For quite a number of years by now I have used, and still use, a free Anti-Virus program called AVG from a company called Grisoft, based in the Czech Republic, and the AVG Free Anti-Virus software of mine has caught and isolated the viruses that colleagues and friends of mine were also sent and whose programs, Norton and McAfee, respectively, which, like my AVG were updated religiously, failed to capture and could also not isolate.
All I can say that AVG Free, now version AVG 7.5, has been performing well for me, with one exception and that was when a Trojan Horse virus was sent to me but not via an email bu via an open port in a chat room. This is where often any such protection software fails and you have to ask yourself as to whether using such places is safe for you or not.
In all other instances AVG Free has done its job, and, if would appear, far better than the paid for programs. No, before you ask, I do not work for AVG nor do I get paid by them. Chance would be a fine things but...
As I have said already, daily update for anti-virus program is a must and every time that I go live on the Net I let the AVG program check for new updates. In fact Grisoft.com does make updates available sometimes several times a day. So, as a rule: when online check for anti-virus updates.
There is no need to pay for protection software, none whatsoever.
The same also holds true for Anti-Malware software, as well as Firewall, and others.
Anti-Malware
Under malware we understand all those little programs that are called cookies, and there are good cookies and bad cookies, and other tracking files, as well as a variety of others, such as so-called spyware, including keyloggers.
Again, having good programs, and here you can indeed run more than one, again is a must but, once again, there is no need to pay good money out for any of them.
My recommendation for anti-malware software are Spybot Search and Destroy, Spyware Blaster and Ad-Aware.
There is no problem running those three together on the same machine; I have been doing so for ages on a variety of Windows operating systems.
Each of those works a little different and together they make a good package as there are chances that one program will not attack something that another will.
Spybot Search and Destroy has a resident shield that basically immunizes the PC against blacklisted programs as well as blacklisted sites. In addition to that Spybot S&D has a scanning feature for malware and can remove those that it finds.
Spybot S&D also has a nigh military grade fire shredder that is found under advanced tool with which you can erase, to have virtually to no trace left of the files, material from your PC that might be able to incriminate you should it fall into the wrong hands.
In addition to those items discussed above you do need, no two ways about it, at least a software Firewall and I can highly recommend another free program here (oh, yes, they also have a version you can pay for but no need to get that one) and that is ZoneAlarm.
A firewall is intended to protect you and your PC from hacking attempts and in proper stealth mode your PC is nigh on invisible bar to the websites.
A hardware firewall in addition to a software one is still better than just the software one but hardware firewalls, good ones, are not cheap and for general use it may not be necessary though I'd love to test drive one some day.
In order to be even safer than with the above mentioned, and you also have to use your own head to make sure that your information stays with you and you alone, you may want to consider a different browser for surfing the Internet.
The Internet Explorer from Microsoft is very vulnerable to attacks and the way it works also leaves you, the user, and your PC, open to attacks via various means. One of the favorite of malware writers is using Active X as a medium on a website and with Internet Explorer every items of malware and hijackers, etc. immediately install without you, as user, knowing it. Been there and done it, so to speak, in the very beginning when I was rather naïve as well.
My recommendation is that if you want to be safe on the Net and protect yourself then download Firefox Browser from Mozilla.org. Here you get prompted if a website wants to install an .exe fire, for instance, by means of a pop-up box that states “you have chosen to download... what do you want Firefox to do with this file” and you have the option to “open”, “save to disc” or “cancel”. If you have not actually clicked to download a program, and any .exe file basically is that, then the action to take in that case is “cancel” and immediately leave the site you are on.
Once again to recap. For personal use you do not have to go and purchase Norton, McAffee or any other such software packages. There are enough free programs out there that perform equally well if not, as I explained, better even than the paid for competition.
In addition to all those programs your own vigilance is also called for. Do not fall for the scams of “you have won the lottery”. They do not notify over the Internet. Not fall into the banking scam trap or any of the others. Any offer that sounds too good to be true more than likely is and your bank will not send you an email to give you password and PIN or what-have-you over the Internet. If you think it is from your bank, phone them and check. More than likely it is not.
On social networking sites do not give name, address, telephone number and such details, especially not in a public profile. Any such information is on a “need to know” basis and the general public does not need to know. Your handle, as they used to call that in CB Radio jargon, and your interest are enough. I also would suggest do use an avatar and not a real picture.
Remember: Your Internet safety and security is only as good as you. You can have all the software and even hardware firewall But if you slip up then nothing will help. If you are gullible and naïve and fall for scams or open emails with attachments without checking and double checking then then there is little that will protect you. A virus can even come from a friend without the friend knowing it or with his or her name having been cloned by the virus senders. Never open attachments unless you are really, really sure about that your friend or family member has sent you a document, photograph or whatever via email.
It a jungle out there. So let's be careful.
One little final note before I go: If you really want to be sure that you are safe then the only recommendation one could make is to use Linux operating system instead of Windows but, alas, not all websites work with Linux and Firefox 100%.
© Michael Smith (Veshengro), December 2007