Showing posts with label Hoaxes. Show all posts
Showing posts with label Hoaxes. Show all posts

Saturday, August 02, 2008

Cyber Top Cops Goes Spammy (or rather SHPAMEE)

You may have noticed that my last article was published more than 2 months ago. I may have been absent from the blog, but I was not taking a break. I devoted all my time and attention to a new project aimed at educating the Internet community about Internet crime. All my hard work finally paid off and I am proud to announce that the project is finally ready for launch.

Today marks the launch of a new educational initiative called the SHPAMEE project. SHPAMEE is short for Spam, Hoaxes, Phishing and Malware E-mail Examples and replaces the current Hoaxes, Spams & Scams section of our website. The main goals of the new project will remain the same as the old one, but the SHPAMEE project features several new enhancements and improvements over the old project:

  • Full headers of e-mail examples will now be published.
  • Names (aliases) and contact details of perpetrators will no longer be removed from the examples, but will be published along with the examples.
  • More emphasis will be placed on the techniques used by spammers to bypass spam filters and these techniques will be highlighted more prominently.
  • E-mail examples will be categorised and grouped more effectively, combined with an integrated search feature, something that was missing from the previous project.
  • An RSS feed will be updated each time when a new example is published. This will help users to stay up to date with the latest examples published on our site. The RSS feed will also be used as an alert service, where possible, to warn subscribers about the latest spam outbreaks (however the main purpose of this project remains education).
  • E-mail examples will be discussed in greater detail.

Why replace the old project? A lot of work was done behind the scenes to simplify our job of publishing these e-mail examples. Too much time went into the preparation of the e-mail examples, so we had to find a way to publish the examples in a more efficient way. I'm still not completely satisfied with the current publishing model and I'm constantly working on improvements, but the new system saves us a lot of time and the time saved during publishing is used to investigate and discuss the examples in greater detail. The number of examples in the database might be disappointing at first, but we plan to add new examples on a regular basis. We could cut back on the time spent on investigating each spam example, to publish more examples in a shorter time frame, but we do not want to sacrifice the quality of our comments and the background information about each spam example. After all, this is what the project is all about, publishing interesting and valuable information about these examples to educate the Internet community. We still have a huge backlog of examples to publish, quite obviously, because there is never a shortage of spam examples to investigate.


But now a little more about the reasons behind the creation of this project.

There is still a huge problem among Internet users when it comes to the identification of spam. I get loads of requests from people who want me to take a look at some dodgy e-mail to confirm whether it is legitimate or not. Most of these dodgy e-mails are 419 scams and it is shocking to see that there are so many people who are still unaware of these scams, not even to speak of their inability to identify these e-mails as fraudulent. Many people might say: "That's easy for you to say, you work with these scams everyday, so it is easy for you to spot a scam when you see one". Perhaps so, but it is not rocket science to identify a 419 or phishing scam, you just need to use common sense and a little bit of scepticism. There are always certain elements in these e-mails that do not add up and the scammers make these mistakes over and over again.


Identifying a spam e-mail before opening it, is crucial, because spam is the cause of several problems like malware, fraud, distribution of illegal and harmful substances, porn, piracy, identity theft and even more spam (yes, one spam e-mail can be the igniting spark for a forest fire of spam). I mentioned earlier that we will use this project as an alert service where possible, but the main goal remains education. Why so much emphasis on education, isn't it more important to get the word out on new threats and outbreaks? Well, from my point of view I believe education plays a larger role in our defences against cyber crime.

My biggest problem with any alert service is the fact that many threats need to occur before one can take notice of them. There is always a delay between discovering a threat and alerting the public about it and a lot can happen during this time. Another drawback about an alert service is the fact that it can only reach the people who are subscribed to the service (unless you make use of mainstream media off course), so not everyone gets the message. Education on the other hand enables people to think for themselves and helps them to asses the situation on their own terms, based on their knowledge and previous experience. This means the threat is isolated more effectively and buys more time for the alert services to get the word out. So I'm not against an alert service, I simply believe that education will enable the community to adapt to new threats much quicker than a community relying on alert services alone to keep them safe. Your best weapon would therefore be a combination of education and alerts.


I guess a lot of people are wondering why we didn't publish the names and contact details of spammers and scammers along with the examples in the previous project. A spammer never distribute spam under his/her own name, so the spammer will use an alias and the originating e-mail address is often spoofed. So the details are basically useless and our focus was never on the people behind the spam, but more on the mechanics of the spam examples. It is more about the things that spammers do than the persons distributing the spam. However we realised that it would be an additional benefit for the community if we published these phony details along with the examples, especially with 419 scams. This means that you that you are not only educating people about the schemes of a 419 scammer, you are also alerting them about the aliases, e-mail address and telephone numbers used by these swindlers. So as you can see we are back at the ideal of combining education and alerts into a powerful weapon against cyber crime.

Through the SHPAMEE project and a series of educational articles in the weeks to come, I plan to educate the Internet community about the common flaws made by spammers. But what if the spammers start to pull up their socks and correct their mistakes? Spammers will always make mistakes and it is our goal to stay up to date with their latest tricks and gimmicks and communicate these deceptive techniques through the SHPAMEE project.


About the Author
Coenraad is webmaster and founder of Cyber Top Cops, leaders in Internet security, analysers of security software and raising awareness about internet fraud and malicious software.

Wednesday, February 21, 2007

The Mental Dysfunction Of A Hoaxer

By Coenraad De Beer

A hoax about the death of former South African president Nelson Mandela has been in circulation among South Africans since last week. This has caused waves of panic and shocked the nation. Mr. Mandela is a role model for many people, not just in South Africa, but worldwide and has always been an icon for peace, so it is understandable why so many people were shocked about this news. But was it possible to prevent the confusion caused by this hoax?

It all started with an SMS stating that Mr. Mandela was on life support systems and the media was refusing to break the news. Soon after that, the hoax started to circulate on the Internet. But like any rumour, people started to make it a bit juicier. It did not take long before the hoax transformed into the message of a deceased Mr. Mandela and the police being put on high alert. I'm not going into the details of what the hoax exactly meant and what is rumoured to occur if this was not a hoax, that is not the purpose of this article, but I would like to discuss the damaging effects of false statements like these and the frustration of dealing with this kind of spam.

The South African media immediately jumped to the conclusion that the message originated from right-wing activists who are trying to create panic among the people of South Africa. I simply don't understand what they will gain from this by creating panic among their own people, so it makes no sense to claim that these messages came from right-wing activists. By making a claim like this, the media simply confirmed what would happen if this was not a hoax, which makes them just as guilty as the hoaxers, creating even more panic.

This simply illustrates the confusion and frustration caused by hoaxes. People start to blame each other, pointing fingers and throwing stones at each other, jumping to all kinds of conclusions and I guess that this was the exact intent of the creators of this specific hoax, creating havoc and chaos. But we are missing the point if we start to blame each other for the result of a hoax. The creator or creators of a hoax should be put in a rehabilitation centre for the mentally challenged. I can see the purpose behind unsolicited commercial e-mails, because it holds financial benefits for the creator and don't get me wrong, I strongly condone any kind of spam. But I can't see any benefit for the creator of a hoax, except for the satisfaction of confusing people and causing panic. This is the sign of a psychopath who needs a straightjacket.

And what about the fools who spread these lies like zombies by forwarding the message to all their friends? They are just as psychotic as the creator, if not worse. I mean, if you get a message from a friend who are unable to verify accuracy and truthfulness of the information and you cannot verify it either, why bother sending it to other people, wasting their time? You only contribute to the problem by letting it spread like a bush fire and other people have to put out the fires afterwards.

There are tons of examples of hoaxes, chain letters and petition lists, created ages ago, but still in circulation today, because people continue to forward them, fuelling the wave of hoaxes and spam filling up our mailboxes every day. So is it possible to prevent a hoax from going this far? Of course, a little common sense and self-control against gossip can go a very long way.

About the Author
Coenraad is webmaster and founder of Cyber Top Cops, leaders in Internet security, prevention of online fraud and educating users against online scams and malicious software.