Yes, our weekly article is back on track, due to time constraints and a huge workload, I was unable to write articles for the blog the last couple of months. Things are slowly getting back to normal and hopefully I will be able to fill our regular timeslot each week with a brand new article about cyber crime.
Before we get to this week's article, just a little interesting background information. The article was initially titled "Hardcore Porn - Fuel For Spyware And Spam". According to EzineArticles, this is in violation of Section 2-a of their Editorial Guidelines, more specifically "Website/Author/Brand Names are not Allowed in Your Title". My idea behind the words "Hardcore Porn" was to emphasise the hardcore facts that we are stuck with the most explicit and disgusting material shoved down our throats (and the throats of our children) everyday. I had to change the title to get it approved on EzineArticles, hence I stuck to the same title here.
Do you think Hardcore Porn is a brand name? Generally speaking, isn't this exactly the reason why we are stuck with this junk in our mailboxes? A brand being protected instead of our freedom to use the Internet without being plagued by psychopaths and sex maniacs. What do you think? Please post your comments.
Article written by Coenraad De Beer
People can't thank you enough when you helped them to get rid of spyware from their computer. But this gratefulness soon changes to disgruntlement when you tell them they need to stay away form their favourite porn websites, 3d sex games, sexy desktop mates and screen savers if they do not want to fall victim to another spyware attack. For these people it is too much to sacrifice, but what they don't realise or don't want to accept, is that all these things are not worth the damage they may cause.
Porn is not good for the human psyche, it becomes an addiction just like any other addictive substance. Whether you believe porn is immoral or not, is beside the point, it remains a fact and it is no good for your computer either. But lets forget about the adults for a while and think about our children. In homes where everyone does not have his or her own computer, is a family computer, used by each member of the family. If mom or dad surfs porn websites, do you think it will remain for the eyes of mom and dad only? Unfortunately no. It is not only mom or dad who gets hooked on porn, the family computer gets hooked as well, hooked by spyware. These websites make sure you come back for more by constantly throwing offensive pop-up advertisements in your face while browsing the Web or simply by working on your computer while being connected to the Internet. The spyware does not know and does not care who is in front of the computer screen, it is only the ad that counts.
A while ago I worked with a HijackThis log from someone struggling with annoying website redirects and Google warning him about being infected with spyware. I replied with the disinfection instructions, but also warned him about the adult related software that caused the infections. I never received any response from him, he was probably not prepared to get rid of his virtual desktop girlfriend. I guess he must love her very much for being willing to sacrifice his own online security, privacy and the freedom to browse without being redirected to websites he does not want to visit. Not my idea of an ideal relationship. The best of all is that this person also had Parental Control Software installed on his computer. This is either a naughty teenager bypassing the content filters installed by his parents, or even worse, a father who believes the content filters will prevent his children from being exposed by the filthy software installed on the computer. Parental content filters and control software are designed for Internet adult content filtering, like offensive images, websites, e-mails and text, not spyware or adult related software already installed and allowed to run on your computer. Using parental monitoring software (which does not block content) may help you monitor the activities of your children online, but it does not prevent them from being exposed to adult content in the first place. Anyway, what does it help to monitor your children if you can't set them a better example yourself?
With all the free e-mail services available today, everyone with Internet access have their own e-mail account, even your children. Some spyware programs are also e-mail address harvesters. When a child uses the same computer a parent or older family member use for browsing porn sites, chances are good that this poor child will fall victim to endless offensive, disgusting and explicit adult related e-mails. Everyone who uses the infected computer is at risk. If the spyware is a keylogger, the e-mail address is stolen the moment you type your e-mail address into a web form, this can be the page where you log into your e-mail account or when you sign up for a newsletter or web service. The most common method used by spyware is the extraction of e-mail addresses from the e-mail accounts set up with e-mail clients like MS Outlook, Outlook Express or Thunderbird. The spyware may even pull all the addresses from your address book and you may end up becoming a distributor of spam without even knowing it. I don't think your friends and family will be chuffed if they receive porn spam because of your inability to control yourself. If you continue to browse porn websites with the same computer used by your children for e-mail and other Internet activities, don't be surprised if they suddenly ask you out of the blue about Viagra or genital enlargement patches.
When your e-mail address lands on a spammer's list, you are in a catch-22 situation. It is futile to try and get your e-mail address removed from this list. By the time you succeed in getting your e-mail address removed, which is in any case unlikely to happen, your e-mail address will be distributed among many other spammers. Once a spammer has your e-mail address, it is an open channel for him to send you absolutely anything under the sun and no spammer is ethical, they don't mind how many children they pollute with porn spam, as long as someone reads their e-mails, they are happy.
Porn and spam have 2 things in common, they waste bandwidth and they are the same thing over and over again. Many people believe that porn is only innocent mischievousness. Whenever you encounter cyber crime, porn and adult related content is often involved. In a recent article by Scambusters.org (http://www.scambusters.org/fakeantivirus.html) it was mentioned that adult sites are special favourites for causing trojan infections, taking control over your computer once you visit the website. I find it hard to believe that something that's responsible for things like trojan horses, identity theft, spam and many other cyber crimes, can be innocent.
Taking action against the injustice committed against our children, committed against the people who don't want this junk shoved down their throats, is really hard with poor legislation and so many people supporting the sites responsible for it. Many people browse porn websites without realising the dangers they pose (no pun intended). Off course many people don't care about these dangers, even if they know about it. It is just like any other addiction, people smoking crack don't care about the negative effects it has on their health. Next time when you have to convince someone about the harmful effects of porn, tell them about the dangers of visiting these sites. Educating people about the dangers of web porn and porn spam is the best way to battle an ever-increasing problem in cyber space.
About the Author
Coenraad is webmaster and founder of Cyber Top Cops, leaders in Internet security, prevention of online fraud and raising awareness about online scams and malicious software.
Monday, June 04, 2007
Wednesday, April 04, 2007
Internet Security Is More About Prevention Than Disinfection
By Coenraad De Beer
Almost everywhere you go on the Internet, you come across victims of malware, hackers, phishing attacks and e-mail scams. These victims turn up like wounded civilians at all the malware removal forums and the security divisions of community driven web sites, seeking for help and advice to recover from the damages caused by these malicious threats. It is like a war ground, claiming casualties everyday. As with any war, you suffer a lot of casualties when you allow the enemy to get past your defences and it is even worse when you have no defences at all.
An anti-malware application is just as good as its resident shield. Anything that gets past an active resident shield will seldom be detected by any anti-malware protection system. Today's generation of anti-malware packages have heuristic detection technology helping them to detect virus- or spyware-like activity without actually knowing anything about the threat. But heuristic analysis is only a secondary layer of protection, your primary line of defence against malicious software is a definition or signature file containing the details and characteristics of specific malware threats. Even firewalls and spam filters have definition files in the form of blacklists. Neglecting to keep your signature or definition files up to date is like neglecting to pay your monthly insurance premium. Your insurance company will refuse to pay out any claims because you did not maintain your insurance policy. An update a day keeps the malware at bay.
A decent anti-malware application will isolate any known malware before it enters your system, but becomes vulnerable when unknown malware enters your system undetected. It is harder for anti-malware applications to take over a system, already infected with malware, than protecting a clean system from getting infected. Anti-malware software is primarily designed to protect your system from getting infected and its secondary objective is to neutralise threats as quickly as possible before they start to spread throughout your system. I have seen how top class anti-virus systems self-destruct when they are infected with high-risk viruses that were already present on the system, before the anti-virus software was installed. It basically means that the virus infects critical components and files of the anti-virus application, the anti-virus application detects these infected files and delete them or move them to the virus vault. If the anti-virus software deletes any of its critical components, it will eventually shut down, crash or become inoperable. The only way to repair the damaged anti-virus software is to re-install it.
Installing an anti-malware application on a system already infected with malware can be troublesome. Many viruses and spyware are aggressive and kill the setup wizard of many well-known anti-virus and anti-spyware packages, preventing them from gaining control over the system. They even terminate some anti-malware scanners if they attempt to disinfect infected files or remove any threats. It is a case of taking over some territory and defending it. Malware can be programmed to do almost anything in order to retain control over your system and it is hard to get rid of stubborn and aggressive programs refusing to surrender to an anti-malware package. Viruses and spyware are normally small, operate very fast and are very flexible. They mutate all over your system, making it hard for anti-malware applications to pin them down. On Microsoft Windows systems, you can always start your computer into Safe Mode when malware refuses an anti-malware application from being installed in Normal Mode, but many anti-malware applications rely on the Windows Installer, something that is normally disabled under Safe Mode. When it comes to disinfecting an infected system, you can't expect the installer to rely on faulty, damaged, infected or disabled components of the operating system. Off course it is not possible to make the anti-malware application completely independent, but at least develop its own independent installer, with built-in malware protection. This will make it possible to run the software under Safe Mode, where many malicious programs are automatically disabled, making the job of disinfection a little easier for you and the anti-malware application.
Unfortunately there are people under the false impression that they are untouchable when they have an anti-malware application installed on their system. Any defence system will eventually fail if you continue to expose it to constant attacks. I have come across people asking for the best anti-virus protection because they have a friend or cousin using their computer to browse porn web sites, but they do not want to confront this person about it, they rather want to increase the protection on the computer. Porn sites are polluted with viruses and spyware, not viruses alone. It is because if this approach that people fail to remove spyware from their computer, because they are using the wrong tools for the job. You can't protect your system effectively against spyware, or remove spyware from your computer if you are using an anti-virus package or vice versa. You can't keep viruses from infiltrating your system by using a firewall alone. It may block a virus attempting to enter your system through a blocked port, but it will not be able to block a virus travelling through a trusted application like your browser.
Today you need protection against malware (viruses, spyware, rootkits, trojans, etc) not just viruses or spyware alone. You also need a firewall and a good spam filter. You need a browser that protects you from phishing attacks, browser hijackers and pop-up windows. Anti-malware applications are not super applications, they have their limitations and you can't expect your system to stay malware free if you constantly expose it to malware attacks from porn, illegal music and pirate software web sites. You can keep your system clean, your identity safe and prevent someone from destroying his/her life with junk like porn, by disallowing anyone (including your cousin) from using your computer for illegal and indecent activities. Who do you think is going to take the fall for illegal porn, music or pirated software? Your cousin? I don't think so, especially if YOUR computer and YOUR Internet connection were used. Even if you can prove it wasn't you, you will still be seen as an accomplice.
So what is the bottom line? Internet security is more about prevention than disinfection. The large number of single purpose disinfection tools, available for specific threats, is proof of this. Definition files are mainly for prevention and detection purposes. When a malicious program exploits vulnerabilities beyond the reach of definition files, you need a specific tool to get rid of it and often a special patch to prevent re-infection. This is why anti-malware developers have to release new versions of their software on a regular basis to stay abreast of the latest threats and vulnerabilities. Developing anti-malware applications, limited by strict standards, protocols and rules, is like arming a S.W.A.T. team with water pistols when they need to go up against a group of terrorists armed with AK47's. Malware does not play by the rules, it is time that anti-malware developers follow the same route, but without compromising the stability and performance of our computer systems.
About the Author
Coenraad is webmaster and founder of Cyber Top Cops, leaders in Internet security, prevention of online fraud and raising awareness about online scams and malicious software.
Almost everywhere you go on the Internet, you come across victims of malware, hackers, phishing attacks and e-mail scams. These victims turn up like wounded civilians at all the malware removal forums and the security divisions of community driven web sites, seeking for help and advice to recover from the damages caused by these malicious threats. It is like a war ground, claiming casualties everyday. As with any war, you suffer a lot of casualties when you allow the enemy to get past your defences and it is even worse when you have no defences at all.
An anti-malware application is just as good as its resident shield. Anything that gets past an active resident shield will seldom be detected by any anti-malware protection system. Today's generation of anti-malware packages have heuristic detection technology helping them to detect virus- or spyware-like activity without actually knowing anything about the threat. But heuristic analysis is only a secondary layer of protection, your primary line of defence against malicious software is a definition or signature file containing the details and characteristics of specific malware threats. Even firewalls and spam filters have definition files in the form of blacklists. Neglecting to keep your signature or definition files up to date is like neglecting to pay your monthly insurance premium. Your insurance company will refuse to pay out any claims because you did not maintain your insurance policy. An update a day keeps the malware at bay.
A decent anti-malware application will isolate any known malware before it enters your system, but becomes vulnerable when unknown malware enters your system undetected. It is harder for anti-malware applications to take over a system, already infected with malware, than protecting a clean system from getting infected. Anti-malware software is primarily designed to protect your system from getting infected and its secondary objective is to neutralise threats as quickly as possible before they start to spread throughout your system. I have seen how top class anti-virus systems self-destruct when they are infected with high-risk viruses that were already present on the system, before the anti-virus software was installed. It basically means that the virus infects critical components and files of the anti-virus application, the anti-virus application detects these infected files and delete them or move them to the virus vault. If the anti-virus software deletes any of its critical components, it will eventually shut down, crash or become inoperable. The only way to repair the damaged anti-virus software is to re-install it.
Installing an anti-malware application on a system already infected with malware can be troublesome. Many viruses and spyware are aggressive and kill the setup wizard of many well-known anti-virus and anti-spyware packages, preventing them from gaining control over the system. They even terminate some anti-malware scanners if they attempt to disinfect infected files or remove any threats. It is a case of taking over some territory and defending it. Malware can be programmed to do almost anything in order to retain control over your system and it is hard to get rid of stubborn and aggressive programs refusing to surrender to an anti-malware package. Viruses and spyware are normally small, operate very fast and are very flexible. They mutate all over your system, making it hard for anti-malware applications to pin them down. On Microsoft Windows systems, you can always start your computer into Safe Mode when malware refuses an anti-malware application from being installed in Normal Mode, but many anti-malware applications rely on the Windows Installer, something that is normally disabled under Safe Mode. When it comes to disinfecting an infected system, you can't expect the installer to rely on faulty, damaged, infected or disabled components of the operating system. Off course it is not possible to make the anti-malware application completely independent, but at least develop its own independent installer, with built-in malware protection. This will make it possible to run the software under Safe Mode, where many malicious programs are automatically disabled, making the job of disinfection a little easier for you and the anti-malware application.
Unfortunately there are people under the false impression that they are untouchable when they have an anti-malware application installed on their system. Any defence system will eventually fail if you continue to expose it to constant attacks. I have come across people asking for the best anti-virus protection because they have a friend or cousin using their computer to browse porn web sites, but they do not want to confront this person about it, they rather want to increase the protection on the computer. Porn sites are polluted with viruses and spyware, not viruses alone. It is because if this approach that people fail to remove spyware from their computer, because they are using the wrong tools for the job. You can't protect your system effectively against spyware, or remove spyware from your computer if you are using an anti-virus package or vice versa. You can't keep viruses from infiltrating your system by using a firewall alone. It may block a virus attempting to enter your system through a blocked port, but it will not be able to block a virus travelling through a trusted application like your browser.
Today you need protection against malware (viruses, spyware, rootkits, trojans, etc) not just viruses or spyware alone. You also need a firewall and a good spam filter. You need a browser that protects you from phishing attacks, browser hijackers and pop-up windows. Anti-malware applications are not super applications, they have their limitations and you can't expect your system to stay malware free if you constantly expose it to malware attacks from porn, illegal music and pirate software web sites. You can keep your system clean, your identity safe and prevent someone from destroying his/her life with junk like porn, by disallowing anyone (including your cousin) from using your computer for illegal and indecent activities. Who do you think is going to take the fall for illegal porn, music or pirated software? Your cousin? I don't think so, especially if YOUR computer and YOUR Internet connection were used. Even if you can prove it wasn't you, you will still be seen as an accomplice.
So what is the bottom line? Internet security is more about prevention than disinfection. The large number of single purpose disinfection tools, available for specific threats, is proof of this. Definition files are mainly for prevention and detection purposes. When a malicious program exploits vulnerabilities beyond the reach of definition files, you need a specific tool to get rid of it and often a special patch to prevent re-infection. This is why anti-malware developers have to release new versions of their software on a regular basis to stay abreast of the latest threats and vulnerabilities. Developing anti-malware applications, limited by strict standards, protocols and rules, is like arming a S.W.A.T. team with water pistols when they need to go up against a group of terrorists armed with AK47's. Malware does not play by the rules, it is time that anti-malware developers follow the same route, but without compromising the stability and performance of our computer systems.
About the Author
Coenraad is webmaster and founder of Cyber Top Cops, leaders in Internet security, prevention of online fraud and raising awareness about online scams and malicious software.
Labels:
Internet Security,
Malware,
Spyware,
Viruses
Wednesday, March 28, 2007
Scammers With A Death Wish
By Coenraad De Beer
Scammers come up with the craziest ideas these days. It is hard to believe that people still fall for the ridiculous e-mail scams in circulation all over the web. It is even harder to comprehend how scammers think they are going to swindle people into believing their devious lies and unbelievable stories. Unfortunately, online scams are a harsh reality. On the one side you have innocent, uninformed victims walking into the traps of merciless con artists and on the other side you have scammers following a "shoot in the dark with a shotgun" approach to claim as many victims as possible.
Online fraud is a serious matter, but you can't help laughing at the creative, yet ridiculous ideas of online scammers. Last month I received a link exchange request from someone running a password recovery website providing a password recovery service for people who lost their e-mail account password. The only problem is that they hack e-mail accounts without confirming the real owner of the e-mail account. The other absurdity is that you can normally contact your service provider when you loose your password and don't need a password recovery service if you are the real owner of the e-mail account. Sometimes I wonder whether cyber criminals have any brain cells between their ears or whether they are simply looking for attention. It is even more absurd, even hilarious, when they are trying to scam anti-fraud activists and cyber law enforcement agencies. I know that many of these scam e-mails are sent in bulk by spam bots and the spammers never really know who receive their junk e-mails, but some scammers make it just too easy for cyber law enforcement agencies to track them down.
It is not odd for one person to receive several phishing scams on a single day, each one pretending to come from a different bank or financial institution. The best of all is the fact that these phishing scams are carbon copies of each other, the only difference in each e-mail is the logo and trading name of the financial institution. Scammers discredit their fellow scammers by sending similar e-mails on the same day to the same recipient. If I receive a phishing scam from a bank, of which I'm not even a client, I will most definitely not respond to a similar e-mail, received on the same day, using exactly the same message, even if I am a client of this institution. If everyone starts to read their e-mails more carefully and in detail, you will soon see the ordinary e-mail user being able to identify a scam just by looking at the pattern, words, techniques, formatting and writing style used by many scammers.
One of the latest schemes used by 419 scammers is the Law Enforcement Agency scam. 419 scammers seem to be less successful with their usual e-mail scams, most probably because of what I mentioned in the previous paragraph. Lottery scams, company representative scams, scams involving war victims, cancer victims, plane crash victims, you name it, have flooded our mailboxes so much that we can smell these scams a mile a way just by reading the subject line. Unfortunately you still get people who are unaware of these threats and 419 scammers usually claim victims among these people. The Law Enforcement Agency scam involves 419 scammers trying to swindle previous victims of these scams. The "agency" allegedly apprehended a group of fraudsters and recovered millions of "pounds sterling" stolen from innocent victims. (I wonder why they haven't recovered any dollars). These funds will then be disbursed to victims filing a claim with this "agency". Victims need to supply loads of personal details as well as the amount of money stolen from them. The scammers claim that the victim will not spend any money until the cheque (notice a cheque and not a secure electronic transfer) is issued to him/her. Just ask yourself, why the need to pay money to reclaim something that was lawfully yours? Do the scammers honestly believe that people will fall for a lousy scam like this? People desperate enough to get their stolen money back will most certainly walk into this trap and spend more money only to loose more money and scammers are bargaining on this. Luckily you get people who learn from their mistakes and will never make the same mistake twice, so the scammers can forget to scam vigilant people who already experienced the trauma of loosing a lot of money to empty promises from a total stranger.
Scammers from Nigeria have tried to become partners of cyber security agencies in an attempt to infiltrate and destroy anti-fraud organisations from the inside. Online scammers have become nut cases, fanatics, digital suicide bombers and kamikazes, trying every trick in the book (and some stupid tricks of their own) to reach their idiotic goals. It is just sad that they continue to claim victims with their amateurish schemes. Perhaps these scams are so amateurish that people struggle to see through them. It is a case of horribly underestimating your enemy, the worst part being unable to identify your enemy, even worse, not even realising that your are dealing with an evil opposing force.
About the Author
Coenraad is webmaster and founder of Cyber Top Cops, leaders in Internet security, prevention of online fraud and educating users about online scams and malicious software. Visit our Hoaxes, Spams and Scams Section and educate yourself with real life examples of online fraud.
Scammers come up with the craziest ideas these days. It is hard to believe that people still fall for the ridiculous e-mail scams in circulation all over the web. It is even harder to comprehend how scammers think they are going to swindle people into believing their devious lies and unbelievable stories. Unfortunately, online scams are a harsh reality. On the one side you have innocent, uninformed victims walking into the traps of merciless con artists and on the other side you have scammers following a "shoot in the dark with a shotgun" approach to claim as many victims as possible.
Online fraud is a serious matter, but you can't help laughing at the creative, yet ridiculous ideas of online scammers. Last month I received a link exchange request from someone running a password recovery website providing a password recovery service for people who lost their e-mail account password. The only problem is that they hack e-mail accounts without confirming the real owner of the e-mail account. The other absurdity is that you can normally contact your service provider when you loose your password and don't need a password recovery service if you are the real owner of the e-mail account. Sometimes I wonder whether cyber criminals have any brain cells between their ears or whether they are simply looking for attention. It is even more absurd, even hilarious, when they are trying to scam anti-fraud activists and cyber law enforcement agencies. I know that many of these scam e-mails are sent in bulk by spam bots and the spammers never really know who receive their junk e-mails, but some scammers make it just too easy for cyber law enforcement agencies to track them down.
It is not odd for one person to receive several phishing scams on a single day, each one pretending to come from a different bank or financial institution. The best of all is the fact that these phishing scams are carbon copies of each other, the only difference in each e-mail is the logo and trading name of the financial institution. Scammers discredit their fellow scammers by sending similar e-mails on the same day to the same recipient. If I receive a phishing scam from a bank, of which I'm not even a client, I will most definitely not respond to a similar e-mail, received on the same day, using exactly the same message, even if I am a client of this institution. If everyone starts to read their e-mails more carefully and in detail, you will soon see the ordinary e-mail user being able to identify a scam just by looking at the pattern, words, techniques, formatting and writing style used by many scammers.
One of the latest schemes used by 419 scammers is the Law Enforcement Agency scam. 419 scammers seem to be less successful with their usual e-mail scams, most probably because of what I mentioned in the previous paragraph. Lottery scams, company representative scams, scams involving war victims, cancer victims, plane crash victims, you name it, have flooded our mailboxes so much that we can smell these scams a mile a way just by reading the subject line. Unfortunately you still get people who are unaware of these threats and 419 scammers usually claim victims among these people. The Law Enforcement Agency scam involves 419 scammers trying to swindle previous victims of these scams. The "agency" allegedly apprehended a group of fraudsters and recovered millions of "pounds sterling" stolen from innocent victims. (I wonder why they haven't recovered any dollars). These funds will then be disbursed to victims filing a claim with this "agency". Victims need to supply loads of personal details as well as the amount of money stolen from them. The scammers claim that the victim will not spend any money until the cheque (notice a cheque and not a secure electronic transfer) is issued to him/her. Just ask yourself, why the need to pay money to reclaim something that was lawfully yours? Do the scammers honestly believe that people will fall for a lousy scam like this? People desperate enough to get their stolen money back will most certainly walk into this trap and spend more money only to loose more money and scammers are bargaining on this. Luckily you get people who learn from their mistakes and will never make the same mistake twice, so the scammers can forget to scam vigilant people who already experienced the trauma of loosing a lot of money to empty promises from a total stranger.
Scammers from Nigeria have tried to become partners of cyber security agencies in an attempt to infiltrate and destroy anti-fraud organisations from the inside. Online scammers have become nut cases, fanatics, digital suicide bombers and kamikazes, trying every trick in the book (and some stupid tricks of their own) to reach their idiotic goals. It is just sad that they continue to claim victims with their amateurish schemes. Perhaps these scams are so amateurish that people struggle to see through them. It is a case of horribly underestimating your enemy, the worst part being unable to identify your enemy, even worse, not even realising that your are dealing with an evil opposing force.
About the Author
Coenraad is webmaster and founder of Cyber Top Cops, leaders in Internet security, prevention of online fraud and educating users about online scams and malicious software. Visit our Hoaxes, Spams and Scams Section and educate yourself with real life examples of online fraud.
Labels:
419 Scams,
Online Fraud,
Online Scammers,
Online Scams,
Phishing
Thursday, March 22, 2007
Spammers Replying To E-mail You Did Not Send
By Coenraad De Beer
Spammers are always on the lookout for ways to bypass our spam filters. Lately they have been very successful at this, because many people are complaining that tons of e-mails are getting past their spam filters. Spammers are combining old techniques with new ones, making it hard for even the most advanced and best trained Bayesian spam filter to keep junk mail out of our mailboxes.
Last year I came across a poster on Yahoo! Answers asking for advice on a strange e-mail she received. According to this poster she received a reply from someone on an e-mail she never sent. She immediately thought that the spammer hacked her e-mail account, sent an e-mail to himself and then replied to it. This is not impossible, but there are easier ways to do this, without hacking an e-mail account.
E-mails are plain text documents that can be modified and manipulated with a simple text editor like Notepad. The spammer simply saves any e-mail to a file, opens it with Notepad and puts your e-mail address in the "From" field. The spammer then imports it into an e-mail client and replies to this manipulated e-mail. This is only one of many ways to manipulate an e-mail message.
Spammers normally use a technique called hash busting. Hash busting is when you add random text at the beginning or at the end of an e-mail. The text makes no sense and consists of excerpts from books, articles and news bulletins. This text randomises the size, as well as the contents of the e-mail, making it hard for spam filters to find a pattern in the e-mail to base its filtering decisions on. For instance, an e-mail consisting of an image only will normally be flagged as spam, but if someone adds random text below the image, it changes the pattern of the e-mail and the spam filter can no longer use the criteria mentioned earlier to label the e-mail as spam. There are legitimate e-mails like this and the spam filter needs additional training to know which e-mails with embedded images, containing text below the image, are spam and which ones are not.
Some spammers realised that people became suspicious of the senseless text in spam e-mails, so they started to hide the text by making the colour of the text the same as the background colour. Other spammers make the size of the text so small that it appears like a horizontal line between paragraphs or at the bottom of the e-mail. The techniques used to conceal the hash buster text are easily detectable by a good spam filter because no decent person will send someone else an e-mail with hidden text or text that cannot be seen with the naked eye. So the spammers fail more often to get their e-mails through the spam filters when they use cloaking techniques like this.
Spammers needed a way to make the hash buster text look legitimate to the user as well as the spam filter. This is when they came up with the idea of pretending to reply to an e-mail message that was never really sent to them in the first place. The spammer creates the forged e-mail with hash buster text and then replies to it. The spammer still enjoys the benefits of the hash buster text coupled with a better chance to get past any spam filter, because the e-mail appears like a legitimate reply to a previous e-mail sent by the victim. A reply to an e-mail you sent to someone else is seldom unwanted and the spam filter will therefore be less suspicious about it, unless it contains specific keywords and phrases that trigger the spam filter.
But there are more consequences for the victim than just a spam filter not being able to filter the e-mail as spam. Spammers can include anything in these fake e-mails. They can even pretend that you enquired about one of their products. Instead of spamming you with an unwanted e-mail, they pretend to send you a reply to your initial enquiry, an enquiry you never sent. Abuse departments can easily use this as an excuse not to take action against the spammer. They may argue that the spam victim did not receive an unwanted commercial e-mail, because the victim enquired about something and the accused simply replied to that enquiry. Luckily abuse departments need to prove that the original e-mail was really sent before rejecting the complaint, but we all know that very few abuse departments actually take any spam reports serious these days.
It is because of the lack of proper legislation as well as poor implementation and enforcement of existing legislation that we have to deal with waves of spam every day. We are constantly one step behind cyber criminals and our current spam filters cannot keep up with all the tricks and techniques used by spammers to force their junk down our throats. There is a widespread appeal for better filtering and alternative communication methods. There is merit in developing better spam filters, but how do you replace a communication medium like e-mail without disrupting individuals and businesses that depend on it every day to stay in contact with friends, family and clients? What's the use of taking away a communication medium if you do not take action against the individuals who abuse it? It will only be a matter of time before spammers start to abuse the system replacing e-mail. You need to take action against the root of the problem and not the infrastructure through which the problem occurs.
About the Author
Coenraad is webmaster and founder of Cyber Top Cops, leaders in Internet security, prevention of online fraud and educating users about online scams and malicious software.
Spammers are always on the lookout for ways to bypass our spam filters. Lately they have been very successful at this, because many people are complaining that tons of e-mails are getting past their spam filters. Spammers are combining old techniques with new ones, making it hard for even the most advanced and best trained Bayesian spam filter to keep junk mail out of our mailboxes.
Last year I came across a poster on Yahoo! Answers asking for advice on a strange e-mail she received. According to this poster she received a reply from someone on an e-mail she never sent. She immediately thought that the spammer hacked her e-mail account, sent an e-mail to himself and then replied to it. This is not impossible, but there are easier ways to do this, without hacking an e-mail account.
E-mails are plain text documents that can be modified and manipulated with a simple text editor like Notepad. The spammer simply saves any e-mail to a file, opens it with Notepad and puts your e-mail address in the "From" field. The spammer then imports it into an e-mail client and replies to this manipulated e-mail. This is only one of many ways to manipulate an e-mail message.
Spammers normally use a technique called hash busting. Hash busting is when you add random text at the beginning or at the end of an e-mail. The text makes no sense and consists of excerpts from books, articles and news bulletins. This text randomises the size, as well as the contents of the e-mail, making it hard for spam filters to find a pattern in the e-mail to base its filtering decisions on. For instance, an e-mail consisting of an image only will normally be flagged as spam, but if someone adds random text below the image, it changes the pattern of the e-mail and the spam filter can no longer use the criteria mentioned earlier to label the e-mail as spam. There are legitimate e-mails like this and the spam filter needs additional training to know which e-mails with embedded images, containing text below the image, are spam and which ones are not.
Some spammers realised that people became suspicious of the senseless text in spam e-mails, so they started to hide the text by making the colour of the text the same as the background colour. Other spammers make the size of the text so small that it appears like a horizontal line between paragraphs or at the bottom of the e-mail. The techniques used to conceal the hash buster text are easily detectable by a good spam filter because no decent person will send someone else an e-mail with hidden text or text that cannot be seen with the naked eye. So the spammers fail more often to get their e-mails through the spam filters when they use cloaking techniques like this.
Spammers needed a way to make the hash buster text look legitimate to the user as well as the spam filter. This is when they came up with the idea of pretending to reply to an e-mail message that was never really sent to them in the first place. The spammer creates the forged e-mail with hash buster text and then replies to it. The spammer still enjoys the benefits of the hash buster text coupled with a better chance to get past any spam filter, because the e-mail appears like a legitimate reply to a previous e-mail sent by the victim. A reply to an e-mail you sent to someone else is seldom unwanted and the spam filter will therefore be less suspicious about it, unless it contains specific keywords and phrases that trigger the spam filter.
But there are more consequences for the victim than just a spam filter not being able to filter the e-mail as spam. Spammers can include anything in these fake e-mails. They can even pretend that you enquired about one of their products. Instead of spamming you with an unwanted e-mail, they pretend to send you a reply to your initial enquiry, an enquiry you never sent. Abuse departments can easily use this as an excuse not to take action against the spammer. They may argue that the spam victim did not receive an unwanted commercial e-mail, because the victim enquired about something and the accused simply replied to that enquiry. Luckily abuse departments need to prove that the original e-mail was really sent before rejecting the complaint, but we all know that very few abuse departments actually take any spam reports serious these days.
It is because of the lack of proper legislation as well as poor implementation and enforcement of existing legislation that we have to deal with waves of spam every day. We are constantly one step behind cyber criminals and our current spam filters cannot keep up with all the tricks and techniques used by spammers to force their junk down our throats. There is a widespread appeal for better filtering and alternative communication methods. There is merit in developing better spam filters, but how do you replace a communication medium like e-mail without disrupting individuals and businesses that depend on it every day to stay in contact with friends, family and clients? What's the use of taking away a communication medium if you do not take action against the individuals who abuse it? It will only be a matter of time before spammers start to abuse the system replacing e-mail. You need to take action against the root of the problem and not the infrastructure through which the problem occurs.
About the Author
Coenraad is webmaster and founder of Cyber Top Cops, leaders in Internet security, prevention of online fraud and educating users about online scams and malicious software.
Labels:
Spam,
Spam Filters,
Spammers
Thursday, March 01, 2007
United Against Cyber Crime
By Coenraad De Beer
Two heads are better than one. This is true and this is what we need to combat cyber crime effectively. There is much collaboration between organisations fighting cyber crime and it is important that these organisations work together to make the Internet a safer place for everyone. But there are still a lot of organisations that prefer to work alone and the abuse departments of well-known service providers are ignoring reports from the public and anti-cyber-crime organisations.
Why are people reluctant to report spam to the abuse departments of well-known e-mail and hosting service providers? Many people don't know that such departments exist and other are fed up with the ignorant approach of these departments towards reports from the public. What's the use of an abuse department if it doesn't do anything about the problems and abuse reported to it? But it is not only members of the public who experience these frustrations, anti-cyber-crime organisations have the same problem. These abuse departments eventually decide whether it is necessary to suspend the services of the guilty party or not, no matter how much evidence you provide to support your claim.
It revolves all around money, even the free services generate revenue for these companies. Free web site hosting normally involves adds of the hosting company displayed on the web site. Web sites involved in spamming activities bring in a lot of visitors which means the ads of the hosting company also gets exposure. Why would they want to terminate a web site that brings them a lot of revenue? This means that they are not enforcing their own terms of service, or you can even say their terms of service are only applicable to those who abuse the services without generating any revenue for the company. The problem becomes even worse when the abusing party pays for the services. Why would they want to cancel the account of a loyal client if it is going to cause revenue loss for them? What these companies don't understand is that they are making themselves less popular by being so reluctant to take action against these abusers and they will eventually only attract the criminals, effectively making them accomplices to these criminal activities. I believe most world-class companies will stare bankruptcy in the face if they terminate the accounts of all the spammers and unethical companies making use, or I should rather say, abusing their services.
Money is also the stumbling block for collaboration between cyber crime fighters. A web site owner will not want to refer visitors to a partner's web site without getting something in return. This is understandable to some extent because many anti-cyber-crime organisations provide their services free of charge and generate revenue mainly through advertisements. Without visitors they cannot make money from the ads displayed on their site. But is this enough reason to refuse a helping hand from a partner? A united force is much stronger than a divided force. The scammers love the fact that law enforcement agencies are not working together with anti-cyber-crime organisations to battle cyber crime. Spammers love it when e-mail and hosting service providers do not respond to the reports from anti-cyber-crime organisations and complaints from the public. Cyber criminals are laughing out loud at the divided force against cyber crime, battling to keep their heads above the flood of spam and scams reported to them on a daily basis.
The cyber criminals are constantly one step ahead of cyber law enforcement, it is time we turn the tides and stand united against cyber crime.
About the Author
Coenraad is webmaster and founder of Cyber Top Cops, leaders in Internet security, prevention of online fraud and educating users about online scams and malicious software.
Two heads are better than one. This is true and this is what we need to combat cyber crime effectively. There is much collaboration between organisations fighting cyber crime and it is important that these organisations work together to make the Internet a safer place for everyone. But there are still a lot of organisations that prefer to work alone and the abuse departments of well-known service providers are ignoring reports from the public and anti-cyber-crime organisations.
Why are people reluctant to report spam to the abuse departments of well-known e-mail and hosting service providers? Many people don't know that such departments exist and other are fed up with the ignorant approach of these departments towards reports from the public. What's the use of an abuse department if it doesn't do anything about the problems and abuse reported to it? But it is not only members of the public who experience these frustrations, anti-cyber-crime organisations have the same problem. These abuse departments eventually decide whether it is necessary to suspend the services of the guilty party or not, no matter how much evidence you provide to support your claim.
It revolves all around money, even the free services generate revenue for these companies. Free web site hosting normally involves adds of the hosting company displayed on the web site. Web sites involved in spamming activities bring in a lot of visitors which means the ads of the hosting company also gets exposure. Why would they want to terminate a web site that brings them a lot of revenue? This means that they are not enforcing their own terms of service, or you can even say their terms of service are only applicable to those who abuse the services without generating any revenue for the company. The problem becomes even worse when the abusing party pays for the services. Why would they want to cancel the account of a loyal client if it is going to cause revenue loss for them? What these companies don't understand is that they are making themselves less popular by being so reluctant to take action against these abusers and they will eventually only attract the criminals, effectively making them accomplices to these criminal activities. I believe most world-class companies will stare bankruptcy in the face if they terminate the accounts of all the spammers and unethical companies making use, or I should rather say, abusing their services.
Money is also the stumbling block for collaboration between cyber crime fighters. A web site owner will not want to refer visitors to a partner's web site without getting something in return. This is understandable to some extent because many anti-cyber-crime organisations provide their services free of charge and generate revenue mainly through advertisements. Without visitors they cannot make money from the ads displayed on their site. But is this enough reason to refuse a helping hand from a partner? A united force is much stronger than a divided force. The scammers love the fact that law enforcement agencies are not working together with anti-cyber-crime organisations to battle cyber crime. Spammers love it when e-mail and hosting service providers do not respond to the reports from anti-cyber-crime organisations and complaints from the public. Cyber criminals are laughing out loud at the divided force against cyber crime, battling to keep their heads above the flood of spam and scams reported to them on a daily basis.
The cyber criminals are constantly one step ahead of cyber law enforcement, it is time we turn the tides and stand united against cyber crime.
About the Author
Coenraad is webmaster and founder of Cyber Top Cops, leaders in Internet security, prevention of online fraud and educating users about online scams and malicious software.
Labels:
Anti-cyber-crime,
Cyber Crime
Subscribe to:
Posts (Atom)