Phishers Hone Skills, Craft More Impressive Attacks
CWmike writes "Recent break-ins at high-profile targets like the International Monetary Fund demonstrate just how proficient hackers have become at so-called spear phishing, researchers said on Tuesday. 'Today's spear phishing is not only more prevalent but also much more technically proficient,' said Dave Jevans, chairman of the Anti-Phishing Working Group. 'They're not going for a password, anymore; they're getting people to install crimeware on their computers.' The trend highlights the need for defenses against such targeted threats, requiring companies to look beyond security strategies focused purely on dealing with traditional network threats, analysts said. Increasingly, companies also need to focus on approaches such as continuous monitoring of networks, databases, applications and users, outbound traffic filtering and whitelisting."
I have had the Indian MS helpdesk ring a few times about the viruses of my Windows PC, surely there has to be a way of "honey potting" them to shut them down?
In World 2.0, our new 21st century hyperconnected, hyperlinked multipolity, what is "identity"? What is the "individual"? Let's move beyond dealing with this phenomena like a police procedural. I propose that the phishers are really the new philosophers of our age, telling us that we are all eafch other, and that humanity is one. Hooray and hozanna for the new age of equaius!!!!!
UNITE with the Campaign for a Free Internet because today, our future begins with tomorrow!
The Art of Deception. By Kevin D. Mitnick. It's worth reading.
Life is not for the lazy.
i use their brains as anal lubricant
Is it any wonder, that network security so closely resembles societal security. And when religion finally dies, the only security we will have is an all pervasive police state. It is a paradox unimaginable.
...to stop employing people who are so clueless when it comes to IT. Personal computers have been commonplace for more than twenty years now, it's time people started learning how to use them correctly.
I'm still coming across businessmen of a certain vintage (typically 50+) for whom it's a matter of pride that they "don't know anything about computers". FFS, it's 2011. Get a grip or retire.
worldmobilenet.com -- World Prepaid Wireless Internet plans
"Ass a security measure we hat to temporarily suspend your account. To restore your account Please download the form and fallow the instructions on your screen."
I don't think we have to worry too much until they learn English.
No, I think the best is to provide super-special sandboxing for them. One could even periodically send "test probes" to random people on one's network to better judge their level of acumen vs. current phishing techniques. Those who fail (or originally admit to being clueless) get:
Phishing means tricking users into divulging sensitive data, usually a password. It is just one type of social engineering. What is being described here is another form of social engineering, where users are told instead to install malware or something like that. It is not phishing, or even spear phishing. When you get a lot of information together to plan out an effective attack on human psyche, it's called pretexting.
network security so closely resembles societal security
No, and you are dumb for posting this, and you made everyone who read this, a little bit dumber.
Contrary to the popular belief, there indeed is no God.
Is it any wonder, that network security so closely resembles societal security. And when religion finally dies, the only security we will have is an all pervasive police state. It is a paradox unimaginable.
WTF? What security has religion ever provided?
Fact of the matter is, the less companies, governments, organizations, etc trust their employees the less control they will give them. Every time a phisher is successful more control over the PC is taken away by security (in general).
I've seen this happen in my organization. The flexibility of having a computer you can install software that helps you do your job without permission is vanishing very quickly. Before long I expect that you will not be able to download any executable (even archived in zip) or run them. Of course this not saying they will not
Basically people's desktops at work are going to become less "personal computer" and more "web/document processing workstation".
Someone used the word hone correctly, and without appending "in" to it. I am going to go weep for joy.
And the malware that they're installing continues to evade antivirus software
Support: Hello this is anti-virus/malware company XYZ how can I help you.
Caller: Yes I have this software called Anti-something 2010 that just popped up on my screen. I have your software installed and it still came up.
Support: You can call our 1-900-BLAH number and they can assist you for $39.95 a minute to remove the software.
Caller: So why did I buy your software in the first place?
Or rather, a MURDER of the english language (lol, read on, this is hilarious - 5 yr. olds write better):
"It's enlessly amusing to see such incredible ignorance." - by Professor FalconDUMMY (1289630) on Monday June 13, @06:57PM (#36430124)
Look - we're not here to decipher your "hieroglyphics", and you're correct (especially about yourself, lol!) - however? It's endlessly you illiterate DOLT!
Now, for everyone's amusement here?
However, below?
I managed to do a translation of your "troll speak", and, with CONSIDERABLE effort, for the benefit of others here (and for their amusement at your expense trolling dolt) and, I have consolidated your single day 'fine effort' & attempts at writing properly (lol, not - 4 blunders in writing in a single day? Please... lol!) here:
"THE CONSOLIDATED ILLITERACY COLLECTION BY PROFESSOR FALCONDUMMY" (world reknowned master of illiteracy, lol!)
---
FROM http://slashdot.org/comments.pl?sid=2235170&cid=36431020
"its hillarious" - by Professor FalconDUMMY (1289630) on Monday June 13, @08:07PM (#36430760)
LMAO! Hahahahahaha... Now that? That's HILARIOUS!
So you know?
The correct phrase, and spelling, is "it's hilarious" using the contraction for "it is" properly, and spelling hiliarious properly... apostrophes boy, learn about 'em!
(Not what you 'ScRiBBLeD' in your droolings on the printed page fool quoted above!)
---
This one take the cake:
FROM -> http://slashdot.org/comments.pl?sid=2231292&cid=36430236
Soemthing more complicated for me... Would have liked to arrive earlier but definately left on time! - by FalconDUMMY (1289630) on Monday June 13, @07:13PM (#36430236)
It's "SOMETHING" and "DEFINITELY" you illiterate moron! The only thing that appears COMPLICATED for you is writing properly, hahahaha...
(However, you MAY have a future in "encryption", lol, because your "hieroglyphics" style of writing is unbelieveable! LOL!)
---
FROM -> http://slashdot.org/comments.pl?sid=2222626&cid=36381748
"Climate deniers have done a lot of damage to the credibilty of all scientists with their vile lies and obsufcation of the issue." by Professor FalconDUMMY (1289630) on Wednesday June 08, @07:27PM (#36381748)
LMAO - You've done CONSIDERABLE DAMAGE to the English lanuage Roman Maroni (see the film Johnny Dangerously, lol) and to your own attempts at "acting intelligent", because your spelling is HORRENDOUS!
(It's credibility and obfuscation, moron!)
As you can see? Professor FalconDUMMY is trying to "obsufcate" (???) the english language. His own form of encryption, perhaps? NO, it's just trollspeak (illiterate trollspeak, lol).
(Wait, wait... read on, it only gets BETTER, lol!)
---
FROM -> http://slashdot.org/comments.pl?sid=2222626&cid=36381748
its endless fun hoisting them with their own petard of scein tific corruption. " by Professor FalconDUMMY (1289630) on Wednesday June 08, @07:27PM (#36381748)
Well, what about YOUR CORRUPTION OF THE ENGLISH LANGUAGE THERE, "Roman Maroni"? LMAO!
---
FROM -> http://slashdot.org/comments.pl?sid=2235170&cid=36429940
"Personal I find the "free market" does a fine job of slandering itself." - by Professor Fa
http://it.slashdot.org/comments.pl?sid=2239506&cid=36449478
These are simple, easy-to-implement measures vs. malware attack in email (which IS how phishing &/or spamming works anyhow):
---
1.) Set email readers (like Outlook variants & others external to webbrowsers) to do TEXT ONLY message displays.
2.) Use a custom HOSTS file (filled with malware sites &/or phishing/spamming site data - yes, there are places like SpamHaus for instance (or there used to be) that have THAT type of data that's regularly updated) since HOSTS files do what things for browsers in addons like AdBlock can't - cover email readers!
3.) Use a decent email reader that already has blocks of known malwares (Windows LIVE has such features for example).
4.) If/when possible - don't allow scripting in browsers OR email readers
---
* Those SIMPLE MEASURES can stall hack/crack attempts in emails easily... for starters!
APK
P.S.=> Is there MORE you can do? Yes, sure, & at the firewall perimeter level, as well as local DNS servers using DNSBL lists too (if not browser level TPL's like for IE, NoScript in FireFox, Opera's urlfilter.ini too etc.), but those measures above? A decent enough start!
... apk
Or, is your not answering a simple question not enough to evidence that much, here:
http://it.slashdot.org/comments.pl?sid=2198230&cid=36418054
Hmmm?
OIC - It's "ok for falconhell to troll others, but not for him getting 're-trolled'", right?? Wrong - what's "good for the goose, is good for the gander" - learn to take what you dish out! OR, just stop trolling others, pretty simple!
(Additionally?? Learn to SPELL and WRITE... lol, please! We're not here to decipher your 'hieroglyphics' falconhell...)
Lastly - your replies as "AC" to try to 'defend yourself', especially when you have a registered 'LUSER' account here??? Pitiful... lol!
"WTF? What security has religion ever provided?"
WTF you say? Considerable social cohesion for starters. But more specifically, the way individuals manage the chaos. That is, the framework for a brain to function in the world. You may say "that is simply opiate for _lame persons_", but the amazing Zizek can certainly help disabuse you of that naivety. I dish off to him bc to attempt to describe it is beyond the scope of a few paragraphs, (plus I'm never going to come close to doing it adequately anyway). But I will hint at the notion that 'religion' isn't the core of it, that is, the 'brands' you recognize, but rather the innate human faculty which creates religion(s) and which belief creates. It might even be fair to say that there is no security without "religion". You're soaking in it!
look sig is kool
Trying to read falconhell's hieroglyphics style attempts at the english language alone is hours of translation from badly spelled manglings of the english language. I am judging that from the other replies here that actually had many a quoted proof of it. Utterly hilarious proofs in fact. I've never seen anyone write that poorly in only 1 day's time in fact.