My Pages

Showing posts with label virus. Show all posts
Showing posts with label virus. Show all posts

Friday, 13 March 2020

And another recruitment agent called

What you can do with knowledge
I can imagine that not many recruitment consultants would have the time to go through my curriculum vitae (CV) in a professional quest to know their candidate, it makes me wonder if they devote any time to knowing their client too. Maybe, it would take time for the recruitment industry to adopt the due diligence activities of the financial institutions to ‘know your customer’ (KYC) as part of anti-money laundering (AML) requirements and regulations.
Now, I raise this because, if the recruitment consultant that called me this morning had bothered to KYC by reading my CV and before that, KYC by fully appreciating what their customer requirements along with details of the opportunity being offered, we might have had a different conversation along with my offering some grudging respect to a professional cohort that rarely works hard enough to earn it.
Know the location
It transpired that this recruitment called me about a job in Marburg in Germany, I asked there exactly Marburg was, she didn’t know (KYC) and eventually found it was near Frankfurt, between Bonn and Frankfurt, she said, but it has no relation to the former.
I know a bit of German geography and places, it is indeed near Frankfurt am Main to be differentiated from Frankfurt an der Oder on the Polish border, for there are many same name towns in Germany that need to be qualified by their regions, else you might end up hundreds of kilometres away from your intended destination.
One must make that point; if you are a recruitment consultant seeking to place a candidate abroad, do the research, find out about the place, the history, the cost of living, the interesting things. Sell the place as you sell the opportunity. Don’t appear stupid, it is annoying.
A chilling discovery
The offer was not exciting though, you don’t take me from an exciting English city and plonk me in the middle of a provincial German town for a pittance, though it does have centuries of interesting history and recent notoriety. It did not occur to me in these Coronavirus times until I checked that Marburg is an eponym for the Marburg virus which was first described in 1967 when German workers were exposed to tissues of infected grivet monkeys. The Marburg virus is in the class of the Ebola virus, they are both haemorrhagic fever viruses.
Obviously, I found myself going down this rabbit hole, in search of why grivet monkeys that are native to a region of East Africa were leaving infected tissue in provincial Germany. Then for the grace of absolution, the entry for the hapless grivet monkey does not cross-reference to the virus. They must have edited their Wikipedia entry to remove the stigma.
Going from my reaction, I began to understand why for posterity reasons, the new Coronavirus, first identified in Wuhan, China, ended up with the name COVID-19 rather than the Wuhan virus, for a sudden irrational thought somewhere in the future, might unwittingly taint any desire to be anywhere near Wuhan for anything. Much as we somewhat identify many other diseases that are eponymously named. [List of eponymously named diseases – Wikipedia][Science Magazine – WHO rules for Naming Diseases]
Don’t waste my time
Then, back to the crux of this blog, I wrote two blogs yesterday, one about recruitment agents and the other about the Coronavirus, there are links to my blogs from within my CV if it looks interesting enough to the reader.
In the case of the recruitment agent who had not done her homework and was completely out of her depth matching my profile to the requirements, if she understood either, a little more attention to detail rather than shuffling papers and manning a phonebank to earn commission might have achieved more for her, probably not with me, but with someone who might have seen the Marburg role as an opportunity.
Finally, if you are recruiting for an architect, don’t suggest the remuneration of a technician, it is a waste of time for both parties. It is not arrogance, just a bit of self-respect, many candidates are not hungry dogs jumping at any bone tossed at them and recruitment agents need to begin to earn their commissions by really putting in the work.

Saturday, 9 March 2013

Thought Picnic: Of restaurants that upset the peace of the belly


Service matters
I am usually one to sing the praises of a restaurant if I both enjoyed my meal and the service both of which are very important to me regardless of cost.
Where the meal has been very good and the service leaving much to be desired, in fact, to be honest, the service for me is part of the meal, it is the spice, enhancing the aroma, giving the right ambience making it all worthwhile.
Paris is somewhat known for atrociously rude waiters, they have their moods but for me, many things are evident, I walked into the restaurant of my own volition and I am paying; it means I will not take aggro with my food and I can so easily drop my napkin on the table and walk out.
I once called a French waiter aside and told him, “If you are not happy with us being here, we’ll leave, we don’t take aggro with our food and honestly, I don’t care for his manner.”
I can be generous but do not create an atmosphere where the only tip you get is best for the tip, my leftovers after I could stomach no more.
Wait a bit before praise
Last weekend, we searched out a nice Brazilian restaurant in the West-End, good food, good music, an ethnic feel and amazing company, however, before I could get to my keyboard to write about it, having all decided we will all return at a later date, I was already feeling queasy and queer with the evidence of an unfortunate mishap, by the morning, everyone had a story – we know that only the bravest of the most foolhardy of us will return for second helpings of that experience.
Now, one can only imagine the glee of those who might just have secured a table at Copenhagen’s Noma which gastronomic buffs have awarded the superfluous, if not hoity-toity title of the World’s Best Restaurant for three years running.
That far North?
Denmark? It does beggar belief to me because I belong to the school of thought that the further away you are from the equator the less bright colours your local food has, something to do with nature, weather and local agriculture – but now the world is a much smaller place than when spices travelled by clipper from the East Indies, you can find global foods anywhere there is means to convey its freshness or preserved state to some other place.
In any case, having ate, drank and been merry, 67 out of 78 patrons that flaunted their bookings apparently either saw their meals again or had it run out of them with great discomfort, they had picked up the Norovirus in the world’s best restaurant, one can only think that the meal would have been as memorable as it would have been forgettable – what an experience.
What goes out came in
The Norovirus could well be unpalatably referred to as the shit-virus, at the great risk of being crude, it derives from faecal matter – perish the thought, you say – there? Yes, even best restaurants are, well...
To compound the matter, the visit of the authorities into the kitchen and the office showed a number of hygiene shortcomings and probably an apparent lack of responsiveness to complaining customers due to the hubris of status – the restaurant is too busy being the best that it conveniently delivered the worst after-dinner experience to the diners – any wise setup will quickly bake and eat humble pie and keep a very low profile on being the best at delivering strange food and not being concerned about it.
Beware that your great repute does not leave you less caring about the smallest things that can bring great grief to more than one.

Friday, 30 July 2010

Social Engineering Skype Trusted Contact Inquiry


Even if it was, I don’t care
Yesterday night, I was almost a victim of social engineering based on trusted connections with a contact on Skype.
The question came, “is this you on picc??..” Then a URL constructed to have Facebook in the address.
I should have been suspicious of this because my friend from whom this apparently came does his punctuation and rarely uses strange words, but my basic feeling of trust overrode the logic to my thinking.
I clicked on the link and rather than it going to a page it downloaded a file with the .exe extension, which really got me suspicious – How could he have asked if I was on a picc or picture and then send an executable file rather than a picture or a webpage?
Persuasion of the friendly kind
The genius of social engineering here is that I was first persuaded by reason of the fact that this message came from a trusted contact asking a question that would rouse ones curiosity regardless of if you were on Facebook or not.
He had apparently received this code through his Yahoo email from a trusted contact and inadvertently ran the code but not realised that he had infected his system despite the warning he received from his Antivirus utility. It is possible that the utility might just have said opening a file of that type is unsafe rather than that it was malicious.
The clean-up
We all have the tendency to override such warnings and almost always have to pay dearly for it. His Antivirus utility did not detect the problem after a full scan, however, I also asked him to download Destroy which is a free utility that inoculates web browsers and searches for malware.
The utility detected Bredolab.fb which is a kind of credential logger, it was removed and we can safely assume the system is clean. However, I happen to be one of two people whose Skype profile was online on my friend’s system who received this stuff and like me, we reacted before we questioned the real provenance.
The significance of the second link is that, when I did not fall for the redirect URL on the first inquiry it used the TinyURL link shrinker to give the same reference but deceptively named like a picture (JPG) on Facebook, but I was not taking that bait twice.
The graphic of the situation appears below.
Skype Malware

Thursday, 8 July 2010

Social Engineering UPS delivery

Showing fishy emails

I have decided that each time I see receive an email that threatens to expose me to scamming by reason of the genius of its construction, I will post the email and annotate it to expose the suspect activity, without getting too technical.

Looking through my inbox which receives close to 80 emails a day from so many email accounts there was one that appeared to arrive at my business account from UPS, the courier company.

From the header, I noticed there was no subject – No business with any sort of organised system should ever send a customer an email with a subject, on a personal basis, it is rude, in a business setting it is unprofessional.

Appearances and realities

The email appeared to come from UPS Support with the name of the sender, it looked official enough with a UPS.com email address too.

If you get an email from any organisation and the email domain does not reflect the organisation or business name, the sender is an impostor. Many lottery wins and collect emails do not use company email domains they can be classed as scams no matter how too good to be true the content might be. Yahoo, Hotmail, and MSN addresses should be ignored.

Where is my name in this email, they should know who they are delivering to, this is a delivery company for crying out loud. It looks like a fishing exercise.

PDF or broke

This email had an attachment with the name invoice. Be careful with attachments, the safest ones to open are ones with the PDF extension, anything else treat as suspicious, is probably a virus or a keylogger ready to steal your passwords to email or bank accounts. It would be safe to just delete those emails.

Nowadays, invoices must be emailed in PDF format, they are never too large to be undeliverable because of email service restrictions. ZIP files are like Trojan horses, open them and you can end up running a program that ruins your system or worse. EXE files, just NEVER open them. If they are TXT files, sometimes it is best to save the attachment first and then observe that they are really the format they say they are before you open them.

You must always have an up-to-date virus scanner on your system that scans emails too. AVG offers a free edition but the professional editions are inexpensive too.

Drawing you by the bait

Now to the social engineering part of this email; I have been informed that “Unfortunate we failed to deliv” then the rest of the text is obscured by an opaque grey box.

Out of frustration or curiosity, you will be tempted to find out what this was all about and find yourself opening the suspect attachment and you have been had – hook, line, and sinker.

I think it is a work of evil genius because many would end up opening the attachment, but I did not; there were two separate messages in this email.

The first was the text about a delivery and one I was not expecting, and the second was an invoice for something I cannot say I paid for.

No effect without cause

The invoice if I paid for anything should have come from the company, I bought stuff from and not from UPS except if I had engaged the services of UPS which I did not.

So, on the balance of probability, this is a scam, if UPS were unable to deliver a product, it would have arrived at my address and a note left in my post-box not an email sent to me.

The more this email looks authentic the more I am suspicious of its origins. In the worst-case scenario, I have replied to this email asking for it to be sent in legible text, with a PDF invoice and a letter sent by post explaining why they could not deliver the service. If your name is not in the email you received, do not sign off with your name.

Don’t give them more

They do not need my name or address in the reply, they should already have it – do not volunteer excess information to suspect situations.

People are looking to have you, so ensure you are not had by innocuous emails masquerading as authentic customer support emails. Benign as this might seem, it screams scamming to the rafters at best, I cannot think of what the worst of their intentions might be.

Tuesday, 3 February 2009

Your mum inadvertently uses your computer

A text for help

It was an SMS which was a half-panic text about his computer being infected by a virus and inquiring about what he had to do. Please can you advice? It ended, indicating a sense of calmness in the midst of the turmoil that could lose you your data in an instant.

Well, I hope my magnanimity in sharing this event is shared by my friend because it might well be my first real computer-usage related blog.

In fact, I really should have written much in this area since I wrote so much along these lines in my Masters programme and I do have 21 years of experience behind me.

However, stemming from a series of conversations with my friend about his computer and protecting himself from embarrassing situations, I have knocked up this little piece and it pertains mainly to Microsoft Windows systems.

If anything, it makes it safe for your mum to use your computer when you happen not to be around to prevent her seeing things she should not and you trying to explain yourself out of the impossible.

Updating an antiviral dosage

In times past you needed to protect your computer from viruses [PCHelpForum] [Wikipedia] [DirectoryM] that could destroy or mangle your data – you cannot scrimp on this – you MUST install an antivirus utility and always keep it up to date.

There are free offerings like AVG [AVG (Download)] or subscription offers from Symantec, McAfee or some other outfit, it is your first line of defence.

It is generally inexcusable to have an unlicensed operating system especially if you use the ubiquitous Microsoft Windows because its popularity lends to people finding ways to exploit its vulnerabilities – software is NOT perfect workmanship, it is generally a work in progress.

There are critical and security updates as well as service packs, you must always ensure your system is fully patched. Enable the reminders in your installed applications so you get informed when something needs to be updated – this also goes for drivers of devices installed in your system.

Pull up the drawbridge

People would always want to attack your system which is most probably always connected to the Internet, preventing that from happening requires that you enable your firewall [Wikipedia]. Your firewall is like a drawbridge with a sentry that check who goes there before allowing access.

You can make it more restrictive ask it to prompt for programmes trying to access the Internet which are not the usual email to Internet browser applications.

Your firewall must always be ON.

Gifts of suspect providence

So, they cannot get on your computer through the means of viruses or by your firewall and they try a Trojan horse [Wikipedia]. You visit a suspect site and inadvertently download some software or you receive a silly email that promises you a winning for a competition you did not enter – you double-click on some file and your computer grinds to a halt.

Meanwhile, the inadvertently installed programme is harvesting your usernames, passwords and even keystrokes then sending that information out to a computer where the malevolent can attempt to access your emails, bank accounts and do something so despicably evil with your personal details.

This is called malware [Wikipedia] and neither your antivirus application nor your firewall can handle this – you need a spyware [Wikipedia] remover and this is where Spybot – Search & Destroy [Safer Networking – (Download)] [AOL Video – (Tutorial)] is going to be your best friend.

What had happened was that a spyware programme masquerading as an antivirus toolkit needed an update had installed on his system and hijacked the Microsoft Security Centre giving the impression his antivirus was out of date.

Deceptive Antivirus

One look at the malware called Antivirus 2009 [SpyWare.com] [Wikipedia] leaves me both disgusted at the malevolent intend and impressed with the social engineering qualities the programme contains that the unsuspecting would have handed over all their information without knowing what had happened.

Through going to his Control Panel he was able to see that the Microsoft Security Centre was fine but being cloned and interfering with the normal operation of his system.

He downloaded Spybot – Search & Destroy which thoroughly searched through his system and completely removed every trace of the malware and any other suspect material.

Things you cannot share with mum

Finally, if you have been visiting places you cannot tell your mum about the built-in ability of Internet browsers to remove cached data would not suffice, it still leaves copious amounts of data that any smart guy can check to see where you have been as your face goes redder than beetroot.

To save your blushes you should get CCleaner [FileHippo (Download)] [YouTube – (Tutorial)] and run it regularly on your system – it rids your computer of any traces of where you have been, cleans your computer registry of obsolete or invalid data and offers a clean interface for removing applications.

These are not necessarily endorsements of the products mentioned but they are tools I have used for years to keep both myself and my computers out of trouble.

Maybe I should stick to writing my regular kind of blogs.