Google Search

Google
Showing posts with label Scam. Show all posts
Showing posts with label Scam. Show all posts

Tuesday, April 24, 2007

Disappointed in Google...

Yea I know that the google search engine is great, Blogger is great, Gmail is great, Orkut is great - basically all the services are great. They just made few mistakes on the road to the greatness.

I know how much it takes to maintain huge systems, and I know that the most problems are started from the business side. Revenue is everything, so you always need to expand and create new products. I is hard to integrate different systems as they tend to have very different architecture.

I have survived several harvesting/infection attempts in Orkut - I admit they are a minor nuisance, but still, its an indication that something is broken. It may not be a problem of technology in essence, but the social engineering behind it. As people get more adept in scripting languages the patterns you need to create to suppress malicious use are getting too complex.

Bu this is not why I'm disappointed. The problem is one single decision that google made to increase the revenue with its gmail service. At the beginning the service was nice and pure - you had to be invited to join by a person. I know it is not really efficient nor failsafe against bot engines that would send up millions of invitations to them self, just to be able to send more spam. When one gets closed and the address banned the bot has several to spare.

I have pretty good filters to filter and classify spam to categories. The thing that pushed me over the line was 2 e-mails coming from the same gmail address with 1 hour interval - first was mail containing harvesting address and the second was mail inviting me to work as gmail address creator "Work from home filling forms".

Right - does anyone else see a problem here or am I alone?

How blunt do you have to be to work for the people who harvest your address or even infect you computer with spyware or trojans.


technorati tags:, , , ,

Blogged with Flock

Tuesday, April 10, 2007

The wonderful world of scams...

I don't get it - normally get spam about Viagra, loans, lottery winnings, tax refund and fake rolexes. Big deal - ThunderBird's spam filter grabs, reports, ad dumps them. But the bank scam... I don't know who's black list I have been put, but they start to get annoying. One thing is to be a professional, do your job well (ether its for good or bad - its not up to me to decide that), but the latest batch is plain pathetic. Where has the ethics gone? 10 years ago, wen you got a scam - it was fine graded text with a meaning, it had a sense of personal touch, it was estethical. When you read the text, it was believable, it had the nice "personal touch". It had the feeling that even a little effort has put to it to make it more realistic. I miss the old days...

Nowadays, when you get a scam mail, its full of some random garbage, excessive grammar errors, all mails come in with some active content to harvest your mail address and/or contact list, infect you pc with a trojan/spyware/adware/malware. the mails contain embedded insults/garbage. They are filled with pictures with sites to harvest all they can on show you the finger at the end. It just gets frustrating to even open your mailbox. When you finally get the mood up to open it all you see is SPAM. Friends sending you "I love you", your bank asking for passwords, the lottery telling you won 100 000 000 000 000 000 000 000 000 000 000 000 000 000 000 000 000$ USD even if you haven't participated in one (I wonder if there is enough currency in the world to cover that amount), the pharmacists telling you that you cant get it up, a "friend" telling you a way to pay off your 20 year mortgage in 6 months, etc... etc... etc....

Back to todays topic. Some unknown bank (BB&T) send me a mail like this:

Looks legit right? Well not really - this is not a screen shot, its the picture from the mail. I have seen a lot of nice scams, but this one was just cold - a template picture, a little text in photoshop, no personalization. This alone should arise alarms even if you secretly wish that you had an account with 1 000 000$ USD on it :) As usual it was a html mail with some embedded text from "Misery by Stephen King, 1987". I know its just for bypassing the spam filters as the optical recognition isn't so widely used to scan email pictures, but still isn't it and IP violation and if so what is the RIAA/MPAA/BSA for literature? I guess if there would be such a organization they could file charges against that person and by doing so they could enforce law enforcement organizations to fight spam - wouldn't that be a nice twist? :)

Well back to the scam - all looks legit except that the url the picture was pointing to. Poor Outlook (express) users would not even see to what they are clicking, but thanks to TB I can look at the link I'm about to click. Now look at the url in the picture and compare it to the link thats embedded to the url (I'll make comments in brackets): http://(hmm http is insecure why isn't it https wit ha valid cert? DEFCON 4) online.bbt(hmm why is the mail from @bbt.com, the url on the picture *.bbandt.* and the real url *.bbt.*? Right the author made a SMALL mistake when writing the url to the picture? DEFCON 3) .com.onlineservlet_(here comes some random numbers that can be tracked back to me, so I'm not releasing them - but still why is there a "." instead a "/"? Its part of the domain - this should rise a lot of alarms. DEFCON 1).sisopt.tk/cbus <- now the last part should put all the bells and whistles to scream on the maximum level (if the blinking read lights are not enough :)). Your right - this is not the right url for the bank - its a phishing site under the Tokelau TLD. A little more digging and the owner of the domain is Donald Williamson. Now there can be 3 explanations to why he would try to scam people like this 1) hes domain is hijacked and is used by criminal element and the owner is not aware of it 2) this person does not exist, is stolen identity, is forced to register by other parties 3) he is running the scam and was stupid enough to give out hes real information. A little more googleing gave me also this result. This means the domain is part of a larger group of domains focused on attacking BB&T.

The conclusion turn off javascript, turn off images and activex (if you are using windows), use ThunderBird or an alternative browser, look at the url before clicking on it (ant not the text that looks like a link) and finally rise your paranoia level - next time the mail might be from Your bank and it might contain personal info to make it more believable.


technorati tags:, , , , , , ,

Blogged with Flock

Tuesday, March 27, 2007

Another bank scam on the wild...

Great... When you usually get spam about fake Rolex's, lottery winnings and some other crap then now I'm getting spammed by Nordea Bank. Hmm, how come they send me a mail that links to an Hong Kong site??? What can I say - poor outlook users. One click and your harvested at best, lost all your money at worst. I don't get what good does it do to send out such crap. It does even look like a real email from a bank.

Ok, I can understand that the first half of the mail could be considered as a similar looking then wtf is the second part? Looks like random gibberish. Eee.. if few years ago there was kinda non written "code of conduct" then looking at this it looks like well... I don't know what. If you want to send SPAM then do it elegantly, make it interesting or just don't send it. I understand that there are FTTP but why the hell do you send it so much??? If it does not work the first time then it wont work on the 100-th time.

So if you want to send spam, first learn the language, secondly do your homework, thirdly get a better job and for forth DON'T SEND SPAM!


technorati tags:, , , ,

Blogged with Flock