Just a quickie here with a link. As most who read this probably know the hacking group LulzSec went on a 50 day tour. Each day they posted their successes on Twitter. Many encouraged and laughed along with them until the day they posted 550961 email addresses and passwords garnered from various places including hackforums.net, nato-bookshop.org, and several gaming forums. They told their followers to just try them in some places. And all was a lot of fun and games until the reports started coming in. Some ordered books and other things using the combos in Amazon.com. These were no Bill Gates to whom 100.00 might be an annoyance, these are people from all over, gamers, some have money some do not and most have done LulzSec no harm. That was when the old skool ones stepped in. The quiet hackers that are spoken of in whispers and as legend by some. Sure some of them are TOO old skool. They maybe have lost the touch the or not kept up. But some were not. They moved on LulzSec. Hacker wars have begun - let the rest of us beware. Some have sworn to turn LulzSec over to the fed (sort of unhacker like), others have declared they will 'Show' the 'script kiddies' what hacking is. It is rumored that LulzSec site was hacked for under an hour, I have heard everything from 1 minute to 47. Though 19 seems to be the standard and sounds about right.
Here is a site with the list of emails. Search it, if you find you are on it change passwords to any and all sites that you even think maybe there is a chance you even THOUGHT of using a standard or similar password on. Do not panic, you may have to go only to page 347 on it instead all of the way to 1102. Yes, it is tedious - but it beats having your AMEX for work charged up and you being responsible for paying it. Ih and stay off the porn sites - seems they got a lot from them too.
Ramblings, meanderings, rants and discoveries.
Showing posts with label identity theft. Show all posts
Showing posts with label identity theft. Show all posts
Thursday, June 30, 2011
Monday, May 30, 2011
Viruses and Facebook
I would like to say I am part of the cause for the new Facebook awareness of Viral banners, links and apps on their site. But I am not that full of myself to think that my one voice actually got through in spite of my complaining for a year. Last month I basically left Facebook. I got the third infection in less than 12 months. It is time for me to move on and leave that site to the lowlifes on the internet.
The first was a stupid registry reviver one, easily spotted and cleaned. The second was a basic speed up your computer one - eight months later. Same idea, They want you to run out to their site, and BUY the product that is going off except of course it is not finding the 30 viruses and spyware it lists as finding on your machine, though it may be installing them.
I noticed it because my drive started cranking , then Flash tried to start. I was reading an article. No reason for flash unless it is a banner which I had blocked, yep it was payload drop time.
The screens look like they could be official. Perhaps it is a mutation. all I know is suddenly my files seemed to disappear. I started to panic then relaxed, it was only MY user directory affected. Fine, Easy solution - SYSTEM RESTORE. Several hours later I had it found, removed it and then cleaned, recleaned and reupdated the machine.
This one was the last straw. It had attacked the FAT. The File Allocation Table could not FIND the files to tell me they were there. I muttered steamed until I realized Trend was scanning them.They were there. Just not able to be found.
Trend Micro's Housecall took it out. I then followed with Malwarebytes which traced the rest of the components and removed them. Where exactly these came from, I am not certain to this day but most evidence points to Facebook and one of those crappy banners. But hell for all I know Bleeping Computer, GamerDNA or even Major Geeks could have been the source. All are sites I frequent. So I cleaned it up kept a component or two that were non functioning without the rest to test virus checkers with and moved on.
Last month I got hit again. This time a bit more seriously. Yes it was another crapware banner delivering a javascript to my machine. As far as I can tell I had this..Vista Total Security 2011 the link is to a site describing it. This one is a Royal pain. Thank goodness no one codes for Opera. It starts by setting off the Official looking Your computer is infected. It looks like a Windows defender screen. Except.. Vista is no longer really supported, and they would not charge for the fix.
If you try to open defender it is blocked, if you try to go to a website it is blocked. Here is how it works, it downloads a little .js that sits in your roaming directory. Every time you try to open a browser page, it calls the .js to put up the page that says that the site you are trying to go to is infected. Solution - turn off javascript right? Well not exactly. I do not know if it was Firefox 4.0 or the virus but I would turn off the .js and it would still run. When I reopend the tools in Firefox it was checked to allow .js again and again and again. Firefox has a 4.01, perhaps it a was a glitch in their browser or perhaps it was the virus finding a way past that.
So I did what any geek would do. I opened Opera, opened a new tab, got the error and then opened Dragonfly. I saw what it was being called and from where. So I typed in https://trendmicro.com in Firefox and guess what it worked. I got housecall to run (I do NOT keep the component in a default directory) and got it to start cleaning off the virus, except - it did not get the java script. So I tried Panda. Got a message that Activescan does not work with my version of Firefox or of course with Opera. Mutter. I downloaded the 30 day trial. I will give my evaluation of that soon.
However to be fair it found the java script and zapped it, Can anyone tell me why Microsoft keeps people from accessing and clearing the java cache? Last week my daughter came to me, guess what - it was going off on HER machine, Facebook is about the only place in common we go anymore. She cleaned it, we think she got it all she tried the trend 30 day free download except it seems it does not like Malwarebytes. Too bad it works! I updated Firefox to 4.01 and Opera to 10.11. Activescan still does not work with those according to their site.
So I log into Facebook last week to leave a client a message. I see they have the HTTPS in full swing - except it does not work on any applications which are the biggest offenders. I see they have their protection on for links, except it blocked a legitimate site I was trying to go to on information about a virus spread through Facebook. And last I see the same ads on the right hand side. And the machine goes nuts, Yep it is trying it again! NOT THIS TIME BUDDY!
Sure they check the ads - the first time, but what about each subsequent ad. Are you sure they have not been compromised by a third party? Why are they placed on the right on the games and groups where a mis-click can potentially end in an infected user's machine. Why are there ads for products and techniques already known to be scams or at the very least suspicious in their claims? You know how many Acai berry diet plan ads i saw there when that was the big fad? Hey HERE IS AN IDEA FACEBOOK - Only accept ads from REPUTABLE companies and Websites instead of lining your pockets and including in your TOS that if any user's machine is damaged by the site it is their problem nay even their fault for trusting you to perform due diligence. So in the mean time - you all can find me on MySpace or Twitter or the gaming sites. That is unless they all decide to follow the Facebook Model and put profits over their users.
Then you will find me curled up with a good book and on the MUD.
The first was a stupid registry reviver one, easily spotted and cleaned. The second was a basic speed up your computer one - eight months later. Same idea, They want you to run out to their site, and BUY the product that is going off except of course it is not finding the 30 viruses and spyware it lists as finding on your machine, though it may be installing them.
I noticed it because my drive started cranking , then Flash tried to start. I was reading an article. No reason for flash unless it is a banner which I had blocked, yep it was payload drop time.
The screens look like they could be official. Perhaps it is a mutation. all I know is suddenly my files seemed to disappear. I started to panic then relaxed, it was only MY user directory affected. Fine, Easy solution - SYSTEM RESTORE. Several hours later I had it found, removed it and then cleaned, recleaned and reupdated the machine.
This one was the last straw. It had attacked the FAT. The File Allocation Table could not FIND the files to tell me they were there. I muttered steamed until I realized Trend was scanning them.They were there. Just not able to be found.
Trend Micro's Housecall took it out. I then followed with Malwarebytes which traced the rest of the components and removed them. Where exactly these came from, I am not certain to this day but most evidence points to Facebook and one of those crappy banners. But hell for all I know Bleeping Computer, GamerDNA or even Major Geeks could have been the source. All are sites I frequent. So I cleaned it up kept a component or two that were non functioning without the rest to test virus checkers with and moved on.
Last month I got hit again. This time a bit more seriously. Yes it was another crapware banner delivering a javascript to my machine. As far as I can tell I had this..Vista Total Security 2011 the link is to a site describing it. This one is a Royal pain. Thank goodness no one codes for Opera. It starts by setting off the Official looking Your computer is infected. It looks like a Windows defender screen. Except.. Vista is no longer really supported, and they would not charge for the fix.
If you try to open defender it is blocked, if you try to go to a website it is blocked. Here is how it works, it downloads a little .js that sits in your roaming directory. Every time you try to open a browser page, it calls the .js to put up the page that says that the site you are trying to go to is infected. Solution - turn off javascript right? Well not exactly. I do not know if it was Firefox 4.0 or the virus but I would turn off the .js and it would still run. When I reopend the tools in Firefox it was checked to allow .js again and again and again. Firefox has a 4.01, perhaps it a was a glitch in their browser or perhaps it was the virus finding a way past that.
So I did what any geek would do. I opened Opera, opened a new tab, got the error and then opened Dragonfly. I saw what it was being called and from where. So I typed in https://trendmicro.com in Firefox and guess what it worked. I got housecall to run (I do NOT keep the component in a default directory) and got it to start cleaning off the virus, except - it did not get the java script. So I tried Panda. Got a message that Activescan does not work with my version of Firefox or of course with Opera. Mutter. I downloaded the 30 day trial. I will give my evaluation of that soon.
However to be fair it found the java script and zapped it, Can anyone tell me why Microsoft keeps people from accessing and clearing the java cache? Last week my daughter came to me, guess what - it was going off on HER machine, Facebook is about the only place in common we go anymore. She cleaned it, we think she got it all she tried the trend 30 day free download except it seems it does not like Malwarebytes. Too bad it works! I updated Firefox to 4.01 and Opera to 10.11. Activescan still does not work with those according to their site.
So I log into Facebook last week to leave a client a message. I see they have the HTTPS in full swing - except it does not work on any applications which are the biggest offenders. I see they have their protection on for links, except it blocked a legitimate site I was trying to go to on information about a virus spread through Facebook. And last I see the same ads on the right hand side. And the machine goes nuts, Yep it is trying it again! NOT THIS TIME BUDDY!
Sure they check the ads - the first time, but what about each subsequent ad. Are you sure they have not been compromised by a third party? Why are they placed on the right on the games and groups where a mis-click can potentially end in an infected user's machine. Why are there ads for products and techniques already known to be scams or at the very least suspicious in their claims? You know how many Acai berry diet plan ads i saw there when that was the big fad? Hey HERE IS AN IDEA FACEBOOK - Only accept ads from REPUTABLE companies and Websites instead of lining your pockets and including in your TOS that if any user's machine is damaged by the site it is their problem nay even their fault for trusting you to perform due diligence. So in the mean time - you all can find me on MySpace or Twitter or the gaming sites. That is unless they all decide to follow the Facebook Model and put profits over their users.
Then you will find me curled up with a good book and on the MUD.
Thursday, May 19, 2011
Sony, hackers and identity security
I have avoided writing about the whole Sony debaucle, perhaps I will one day, but if nothing else it should have taught companies and consumers that data needs to be secure. As a consumer I do not want my info out there. If I am using the internet there is no reason for anyone to need my phone number unless i buying something with a credit card. Yet Google is still asking for phone numbers on accounts as can be seen on Geekwoman's blogs here and a solution for it here.
Now please look at this one by me. That is what can happen if your cellphone number gets in 'the wild'. Yep, a cellphone number can be used like a credit card in a way. So let's just get it straight. We are responsible for our identity security. One way to keep things secure is to not share them on the internet where anyone can read them. Assurances that my information is secure is not enough, it will not be Google that has to pay my cellphone bill when some hacker breaks in, gets it and sets up a skim account in another stolen identity name. It will not be Google that has to cancel all checking, credit cards and other things because their name and information is being used to apply for credit limits that are skipped out on and it will not them whose reputation is trashed. Do not try the "oh, we will never be hacked." routine either it has happened before and I have every reason to believe it will happen again sometime in the future.
So please, anyone and everyone who reads my blatherings. Start telling these companies they do not need that information. Email their tech support and customer service telling them you do not feel secure giving it. Even if they are secure and you are ask them how they protect against man in the middle attacks? Against hacking? is their database encrypted? What type of encryption? and most of all WHY do they need that information? I am sorry guys I do not want to be tracked, marketed to or even categorized.
First it seems people who think they know what is going on are telling me now what i must do and be interested in. I do not play WoW stop trying to market MMOs that are WoW-like to me. I do not have an Xbox - stop trying to sell me games for one. It seems that you all think if I type a word I must be needing to buy something for it. Well here is a word for you PRIVACY. I want that and I want to keep it and for me the easiest way to ensure that it is preserved is to just not tell anyone anything I do not want them to know.
Now please look at this one by me. That is what can happen if your cellphone number gets in 'the wild'. Yep, a cellphone number can be used like a credit card in a way. So let's just get it straight. We are responsible for our identity security. One way to keep things secure is to not share them on the internet where anyone can read them. Assurances that my information is secure is not enough, it will not be Google that has to pay my cellphone bill when some hacker breaks in, gets it and sets up a skim account in another stolen identity name. It will not be Google that has to cancel all checking, credit cards and other things because their name and information is being used to apply for credit limits that are skipped out on and it will not them whose reputation is trashed. Do not try the "oh, we will never be hacked." routine either it has happened before and I have every reason to believe it will happen again sometime in the future.
So please, anyone and everyone who reads my blatherings. Start telling these companies they do not need that information. Email their tech support and customer service telling them you do not feel secure giving it. Even if they are secure and you are ask them how they protect against man in the middle attacks? Against hacking? is their database encrypted? What type of encryption? and most of all WHY do they need that information? I am sorry guys I do not want to be tracked, marketed to or even categorized.
First it seems people who think they know what is going on are telling me now what i must do and be interested in. I do not play WoW stop trying to market MMOs that are WoW-like to me. I do not have an Xbox - stop trying to sell me games for one. It seems that you all think if I type a word I must be needing to buy something for it. Well here is a word for you PRIVACY. I want that and I want to keep it and for me the easiest way to ensure that it is preserved is to just not tell anyone anything I do not want them to know.
Subscribe to:
Posts (Atom)