Phishers Hone Skills, Craft More Impressive Attacks
CWmike writes "Recent break-ins at high-profile targets like the International Monetary Fund demonstrate just how proficient hackers have become at so-called spear phishing, researchers said on Tuesday. 'Today's spear phishing is not only more prevalent but also much more technically proficient,' said Dave Jevans, chairman of the Anti-Phishing Working Group. 'They're not going for a password, anymore; they're getting people to install crimeware on their computers.' The trend highlights the need for defenses against such targeted threats, requiring companies to look beyond security strategies focused purely on dealing with traditional network threats, analysts said. Increasingly, companies also need to focus on approaches such as continuous monitoring of networks, databases, applications and users, outbound traffic filtering and whitelisting."
I have had the Indian MS helpdesk ring a few times about the viruses of my Windows PC, surely there has to be a way of "honey potting" them to shut them down?
The Art of Deception. By Kevin D. Mitnick. It's worth reading.
Life is not for the lazy.
Class act.
Well, someone have been reading too many bad "cyber" novels, with a bit of Karl Marx in the mix, while on crack.
...to stop employing people who are so clueless when it comes to IT. Personal computers have been commonplace for more than twenty years now, it's time people started learning how to use them correctly.
I'm still coming across businessmen of a certain vintage (typically 50+) for whom it's a matter of pride that they "don't know anything about computers". FFS, it's 2011. Get a grip or retire.
worldmobilenet.com -- World Prepaid Wireless Internet plans
"Ass a security measure we hat to temporarily suspend your account. To restore your account Please download the form and fallow the instructions on your screen."
I don't think we have to worry too much until they learn English.
No, I think the best is to provide super-special sandboxing for them. One could even periodically send "test probes" to random people on one's network to better judge their level of acumen vs. current phishing techniques. Those who fail (or originally admit to being clueless) get:
Phishing means tricking users into divulging sensitive data, usually a password. It is just one type of social engineering. What is being described here is another form of social engineering, where users are told instead to install malware or something like that. It is not phishing, or even spear phishing. When you get a lot of information together to plan out an effective attack on human psyche, it's called pretexting.
network security so closely resembles societal security
No, and you are dumb for posting this, and you made everyone who read this, a little bit dumber.
Contrary to the popular belief, there indeed is no God.
Is it any wonder, that network security so closely resembles societal security. And when religion finally dies, the only security we will have is an all pervasive police state. It is a paradox unimaginable.
WTF? What security has religion ever provided?
Fact of the matter is, the less companies, governments, organizations, etc trust their employees the less control they will give them. Every time a phisher is successful more control over the PC is taken away by security (in general).
I've seen this happen in my organization. The flexibility of having a computer you can install software that helps you do your job without permission is vanishing very quickly. Before long I expect that you will not be able to download any executable (even archived in zip) or run them. Of course this not saying they will not
Basically people's desktops at work are going to become less "personal computer" and more "web/document processing workstation".
Someone used the word hone correctly, and without appending "in" to it. I am going to go weep for joy.
And the malware that they're installing continues to evade antivirus software
Support: Hello this is anti-virus/malware company XYZ how can I help you.
Caller: Yes I have this software called Anti-something 2010 that just popped up on my screen. I have your software installed and it still came up.
Support: You can call our 1-900-BLAH number and they can assist you for $39.95 a minute to remove the software.
Caller: So why did I buy your software in the first place?
http://it.slashdot.org/comments.pl?sid=2239506&cid=36449478
These are simple, easy-to-implement measures vs. malware attack in email (which IS how phishing &/or spamming works anyhow):
---
1.) Set email readers (like Outlook variants & others external to webbrowsers) to do TEXT ONLY message displays.
2.) Use a custom HOSTS file (filled with malware sites &/or phishing/spamming site data - yes, there are places like SpamHaus for instance (or there used to be) that have THAT type of data that's regularly updated) since HOSTS files do what things for browsers in addons like AdBlock can't - cover email readers!
3.) Use a decent email reader that already has blocks of known malwares (Windows LIVE has such features for example).
4.) If/when possible - don't allow scripting in browsers OR email readers
---
* Those SIMPLE MEASURES can stall hack/crack attempts in emails easily... for starters!
APK
P.S.=> Is there MORE you can do? Yes, sure, & at the firewall perimeter level, as well as local DNS servers using DNSBL lists too (if not browser level TPL's like for IE, NoScript in FireFox, Opera's urlfilter.ini too etc.), but those measures above? A decent enough start!
... apk
Or, is your not answering a simple question not enough to evidence that much, here:
http://it.slashdot.org/comments.pl?sid=2198230&cid=36418054
Hmmm?
OIC - It's "ok for falconhell to troll others, but not for him getting 're-trolled'", right?? Wrong - what's "good for the goose, is good for the gander" - learn to take what you dish out! OR, just stop trolling others, pretty simple!
(Additionally?? Learn to SPELL and WRITE... lol, please! We're not here to decipher your 'hieroglyphics' falconhell...)
Lastly - your replies as "AC" to try to 'defend yourself', especially when you have a registered 'LUSER' account here??? Pitiful... lol!
"WTF? What security has religion ever provided?"
WTF you say? Considerable social cohesion for starters. But more specifically, the way individuals manage the chaos. That is, the framework for a brain to function in the world. You may say "that is simply opiate for _lame persons_", but the amazing Zizek can certainly help disabuse you of that naivety. I dish off to him bc to attempt to describe it is beyond the scope of a few paragraphs, (plus I'm never going to come close to doing it adequately anyway). But I will hint at the notion that 'religion' isn't the core of it, that is, the 'brands' you recognize, but rather the innate human faculty which creates religion(s) and which belief creates. It might even be fair to say that there is no security without "religion". You're soaking in it!
look sig is kool
you are a goat fucking goat fucker, obviusl youy are also illiterate and obese and fat.
Wow, the ghost of Oscar Wilde is posting on slashdot.
To have a right to do a thing is not at all the same as to be right in doing it
Trying to read falconhell's hieroglyphics style attempts at the english language alone is hours of translation from badly spelled manglings of the english language. I am judging that from the other replies here that actually had many a quoted proof of it. Utterly hilarious proofs in fact. I've never seen anyone write that poorly in only 1 day's time in fact.