My Pages
Friday, 13 March 2020
And another recruitment agent called
Saturday, 9 March 2013
Thought Picnic: Of restaurants that upset the peace of the belly
Friday, 30 July 2010
Social Engineering Skype Trusted Contact Inquiry
Thursday, 8 July 2010
Social Engineering UPS delivery
Showing fishy emails
I have decided that each time I see receive an email
that threatens to expose me to scamming by reason of the genius of its construction,
I will post the email and annotate it to expose the suspect activity, without getting
too technical.
Looking through my inbox which receives close to 80 emails
a day from so many email accounts there was one that appeared to arrive at my business
account from UPS, the courier company.
From the header, I noticed there was no subject – No
business with any sort of organised system should ever send a customer an email
with a subject, on a personal basis, it is rude, in a business setting it is unprofessional.
Appearances and realities
The email appeared to come from UPS Support with the name
of the sender, it looked official enough with a UPS.com email address too.
If you get an email from any organisation and the email
domain does not reflect the organisation or business name, the sender is an impostor.
Many lottery wins and collect emails do not use company email domains they can
be classed as scams no matter how too good to be true the content might be. Yahoo,
Hotmail, and MSN addresses should be ignored.
Where is my name in this email, they should know who
they are delivering to, this is a delivery company for crying out loud. It looks
like a fishing exercise.
PDF or broke
This email had an attachment with the name invoice.
Be careful with attachments, the safest ones to open are ones with the PDF extension,
anything else treat as suspicious, is probably a virus or a keylogger ready to steal
your passwords to email or bank accounts. It would be safe to just delete those
emails.
Nowadays, invoices must be emailed in PDF format, they
are never too large to be undeliverable because of email service restrictions. ZIP
files are like Trojan horses, open them and you can end up running a program that
ruins your system or worse. EXE files, just NEVER open them. If they are TXT files,
sometimes it is best to save the attachment first and then observe that they are really
the format they say they are before you open them.
You must always have an up-to-date virus scanner on
your system that scans emails too. AVG
offers a free edition but the professional editions are inexpensive too.
Drawing you by the bait
Now to the social engineering part of this email; I
have been informed that “Unfortunate we failed to deliv” then the rest of the text
is obscured by an opaque grey box.
Out of frustration or curiosity, you will be tempted
to find out what this was all about and find yourself opening the suspect attachment
and you have been had – hook, line, and sinker.
I think it is a work of evil genius because many would
end up opening the attachment, but I did not; there were two separate messages in this
email.
The first was the text about a delivery and one I was
not expecting, and the second was an invoice for something I cannot say I paid for.
No effect without cause
The invoice if I paid for anything should have come
from the company, I bought stuff from and not from UPS except if I had engaged the
services of UPS which I did not.
So, on the balance of probability, this is a scam, if UPS
were unable to deliver a product, it would have arrived at my address and a note
left in my post-box not an email sent to me.
The more this email looks authentic the more I am suspicious
of its origins. In the worst-case scenario, I have replied to this email asking
for it to be sent in legible text, with a PDF invoice and a letter sent by post
explaining why they could not deliver the service. If your name is not in the email
you received, do not sign off with your name.
Don’t give them more
They do not need my name or address in the reply, they
should already have it – do not volunteer excess information to suspect situations.
People are looking to have you, so ensure you are not had
by innocuous emails masquerading as authentic customer support emails. Benign as
this might seem, it screams scamming to the rafters at best, I cannot think of what
the worst of their intentions might be.
Tuesday, 3 February 2009
Your mum inadvertently uses your computer
A text for help
It was an SMS which was a half-panic text about his computer being infected by a virus and inquiring about what he had to do. Please can you advice? It ended, indicating a sense of calmness in the midst of the turmoil that could lose you your data in an instant.
Well, I hope my magnanimity in sharing this event is shared by my friend because it might well be my first real computer-usage related blog.
In fact, I really should have written much in this area since I wrote so much along these lines in my Masters programme and I do have 21 years of experience behind me.
However, stemming from a series of conversations with my friend about his computer and protecting himself from embarrassing situations, I have knocked up this little piece and it pertains mainly to Microsoft Windows systems.
If anything, it makes it safe for your mum to use your computer when you happen not to be around to prevent her seeing things she should not and you trying to explain yourself out of the impossible.
Updating an antiviral dosage
In times past you needed to protect your computer from viruses [PCHelpForum] [Wikipedia] [DirectoryM] that could destroy or mangle your data – you cannot scrimp on this – you MUST install an antivirus utility and always keep it up to date.
There are free offerings like AVG [AVG (Download)] or subscription offers from Symantec, McAfee or some other outfit, it is your first line of defence.
It is generally inexcusable to have an unlicensed operating system especially if you use the ubiquitous Microsoft Windows because its popularity lends to people finding ways to exploit its vulnerabilities – software is NOT perfect workmanship, it is generally a work in progress.
There are critical and security updates as well as service packs, you must always ensure your system is fully patched. Enable the reminders in your installed applications so you get informed when something needs to be updated – this also goes for drivers of devices installed in your system.
Pull up the drawbridge
People would always want to attack your system which is most probably always connected to the Internet, preventing that from happening requires that you enable your firewall [Wikipedia]. Your firewall is like a drawbridge with a sentry that check who goes there before allowing access.
You can make it more restrictive ask it to prompt for programmes trying to access the Internet which are not the usual email to Internet browser applications.
Your firewall must always be ON.
Gifts of suspect providence
So, they cannot get on your computer through the means of viruses or by your firewall and they try a Trojan horse [Wikipedia]. You visit a suspect site and inadvertently download some software or you receive a silly email that promises you a winning for a competition you did not enter – you double-click on some file and your computer grinds to a halt.
Meanwhile, the inadvertently installed programme is harvesting your usernames, passwords and even keystrokes then sending that information out to a computer where the malevolent can attempt to access your emails, bank accounts and do something so despicably evil with your personal details.
This is called malware [Wikipedia] and neither your antivirus application nor your firewall can handle this – you need a spyware [Wikipedia] remover and this is where Spybot – Search & Destroy [Safer Networking – (Download)] [AOL Video – (Tutorial)] is going to be your best friend.
What had happened was that a spyware programme masquerading as an antivirus toolkit needed an update had installed on his system and hijacked the Microsoft Security Centre giving the impression his antivirus was out of date.
Deceptive Antivirus
One look at the malware called Antivirus 2009 [SpyWare.com] [Wikipedia] leaves me both disgusted at the malevolent intend and impressed with the social engineering qualities the programme contains that the unsuspecting would have handed over all their information without knowing what had happened.
Through going to his Control Panel he was able to see that the Microsoft Security Centre was fine but being cloned and interfering with the normal operation of his system.
He downloaded Spybot – Search & Destroy which thoroughly searched through his system and completely removed every trace of the malware and any other suspect material.
Things you cannot share with mum
Finally, if you have been visiting places you cannot tell your mum about the built-in ability of Internet browsers to remove cached data would not suffice, it still leaves copious amounts of data that any smart guy can check to see where you have been as your face goes redder than beetroot.
To save your blushes you should get CCleaner [FileHippo (Download)] [YouTube – (Tutorial)] and run it regularly on your system – it rids your computer of any traces of where you have been, cleans your computer registry of obsolete or invalid data and offers a clean interface for removing applications.
These are not necessarily endorsements of the products mentioned but they are tools I have used for years to keep both myself and my computers out of trouble.
Maybe I should stick to writing my regular kind of blogs.