Monday, March 16, 2009

Blog Assignment 6

Phishers Abuse FBI for Malicious Intent

Article link: (http://www.spamfighter.com/News-12004-Phishers-Abuse-FBI-for-Malicious-Intent.htm)

Considering my topic for the poster project i.e. Internet Identity Theft (IIDT), I think this news will be the best example to explain one of the types of IIDT. Phishing, a very common way used for IIDT. It is the act of sending an e-mail to a user falsely claiming to be an established legitimate enterprise in an attempt to scam the user into surrendering private information that will be used for identity theft. And that’s what exactly happened with the innocent people at the Deviess County in Indiana. Several people received e-mails purportedly coming from the Anti-Terrorist and Monitoring Crimes Division of Federal Bureau of Investigation (FBI). These e-mails claims that the recipient's bank accounts have been investigated for fraudulent transactions, of which the receiver is yet unaware and demands for the couple of hundred dollars to fix the problem. According to FBI, cyber criminal easily access the ample amount of information on the internet and run this type of scams.
So to avoid this type of incidents, always think before giving out your information and you can surly minimize the chances to be a victim.

Friday, February 27, 2009

Blog Assignment 5


Information Security

Article Link:

(http://www.media-awareness.ca/english/issues/privacy/why_issue_privacy.cfm)

In the electronic age, raw data has become a valuable commodity—and the protection of personal information has become increasingly important to our sense of privacy. The Security topic I would like to share is very basic and is the one about which we have learned till now i.e. Information Privacy. I was reading about the different security topics and found one article very interesting. It provides some facts, incidents and talks about different issues like why information privacy is important? How information privacy is compromised?

Thursday, February 19, 2009

Blog Assignment 4

Well that’s something real bad.....!
Article Link:
(http://www.theregister.co.uk/2009/02/04/phpbb_breach/)


I have never ever heard the news of this type. By using an unpatched security bug, a hacker managed to hack the website "phpBB.com", one of the net's more popular bulletin board software packages and that to for more than two weeks. Till hacking, it is ok; we can understand that websites could be hacked. From the article, hacker got full access to a database containing names, email, address and hashed passwords, he tried to intercept around 400000 accounts and managed to crack around 28000 user passwords by using MD5 algorithm, now what is your reaction?

phpBB made some efforts to change their security after the attack but they lost a lot.

Friday, February 13, 2009

Blog Assignment 3


"Attack on UK Ministry of Defense"

Article Link: (http://www.defensetech.org/archives/004644.html)

“Cyber attack on UK Ministry of Defense (MoD)”, the important and may be biggest cyber attack news in the last month. According to reports, a hybrid computer virus penetrated the MoD security system, which affected their IT systems. Also, over 24 RAF bases and 75% of Royal Navy ships – including aircraft carrier Ark Royal – systems were infected. These attacks could be originated from Russia and there is possibility that other government systems are also not safe. These type of attacks fall into the Intrusion type of attacks, due to attacks on TCP, that results on connection hijacking, when the host has weak security.

If these government high level security systems can be affected then general users are easy prey.

Friday, February 6, 2009

Malware attack - Blog Assignment 2

Malware Everywhere.........!

Article Link:
(http://news.cnet.com/8301-1009_3-10149884-83.html?tag=mncol)

Are you desperately searching for a job, loading your resumes on job websites? But what if some people do not want your resume to reach to the right hands? Yes it could happen, Monster.com, one of the biggest job search website announced that Monster's database of user account information - which includes user IDs, passwords, email addresses, names, phone numbers, and some demographic data - was illegally accessed and information was taken.

According to monster, stolen information did not include CV’s or other sensitive information like social security numbers or financial data. But for scammers it is very easy to use general data and to acquire sensitive information from people.

Current economic downturn is the best time for hacker’s to load more malware into the websites and to breach people information. So, as urged by monster, if you have accounts on this type of websites keep changing passwords frequently and avoid loading sensitive information.

Wednesday, January 28, 2009

Identity theft - Blog Assignment 1

Identity theft: 'Yes, it could happen to you'

Article Link:

(http://www.telegraph.co.uk/finance/personalfinance/consumertips/banking/4272356/Identity-theft-Getting-past-security-checks-was-never-a-problem.html)

This article is actually written by a former fraudster, Tee, who currently consults a credit card company to keep its customers safe. It is important because it explains, how knowingly or unknowingly, we make available the information needed, to become a victim of identity theft. Just to start with, I believe that all of us had set up the credit card or online account passwords once or more by calling bank’s customer care service. If we lost our card or need another one, we can get it by providing some information. When we call a bank, they ask us three or four questions like address, date of birth, social security, full name etc. and that’s it, we are ready to get a new card or a password.

Tee, from his own experiences, explains how this information is easily available to people through different sources. I have seen people including me, who never open their bank statements and throw them away. Once someone gets it, that person can have enough information to access an account. Bank checks, which many of us do not take seriously contains much more information on it. Another very common source to get general information is social network websites like Facebook or Orkut, where many people provide sensitive and unnecessary information.

So, this article helps us to understand the importance of the information and how to handle the information, to avoid being a victim of identity theft. Every month, we should first go through the bank statement by making sure that transactions are correct, then burn it or at least tear it so that no one can read the information. Checks are as good as cash; place them securely. If someone called asking the personal information, make sure that you are not being a victim. Avoid loading unnecessary information on networking sites.