Translate

12/01/2013

Anonymous - The Authentic Haunted

Since several years there is a Synonym for Antonym: ANONYMOUS.



The following Article includes Assange, Snowden etc. the following Article gets to be BulletPROOF for the allegation: Who is haunting Who ? Someone is chasing a NOT hiding...Pseudonym ! It's Real. And (Or) almost noone noticed...The Headline, in New York !

Hacker linked to Anonymous gets 10-year sentence

"A computer programmer linked to the online hacktivist group Anonymous who pleaded guilty to hacking the intelligence firm Stratfor was sentenced Friday to 10 years in prison, prosecutors said. 
Jeremy Hammond, 28, whose case has been supported by digital rights activists and others, also was part of a group which broke into the FBI computer network and later delivered documents to WikiLeaks, according to investigators. 
He was sentenced by a US federal judge in New York after pleading guilty in May to conspiracy charges in connection with the 2011 hack of Stratfor. 
"As he admitted through his plea of guilty, Jeremy Hammond launched a series of computer hacks that stole confidential information pertaining to companies, law enforcement agencies, and thousands of innocent individuals," US Attorney Preet Bharara said in a statement. 
"His sentence underscores that computer hacking is a serious offense with damaging consequences for victims, and this office is committed to punishing the perpetrators of such crimes." 
Officials said Hammond and his co-conspirators stole Stratfor emails as well as account information for approximately 860,000 Stratfor subscribers. 
Officials also say the group stole credit card information from 60,000 credit card users and used that to make more than $700,000 in unauthorized charges. 
His supporters claim he was exposing wrongdoing, some comparing him to Chelsea Manning, the US army private prosecuted for giving some 700,000 classified diplomatic and military documents to WikiLeaks. 
The "Free Jeremy" website claims Hammond was prosecuted for "leaking information... which revealed that Stratfor had been spying on human rights activists at the behest of corporations and the US government." 
The Electronic Frontier Foundation argued in a brief that Hammond "did not profit financially as a result of his actions, but rather, exposed uncomfortable truths." 
Hammond read a statement in court claiming his acts were "civil disobedience." 
"The acts of civil disobedience and direct action that I am being sentenced for today are in line with the principles of community and equality that have guided my life," the statement text said. 
"I hacked into dozens of high profile corporations and government institutions, understanding very clearly that what I was doing was against the law... But I felt that I had an obligation to use my skills to expose and confront injustice - and to bring the truth to light." 
Hammond also highlighted the role of a government informant, Hector Monsegur, known by his nickname Sabu, in the case. 
"I had never even heard of Stratfor until Sabu brought it to my attention," he said. 
"Sabu was encouraging people to invade systems, and helping to strategize and facilitate attacks. He even provided me with vulnerabilities of targets passed on by other hackers, so it came as a great surprise when I learned that Sabu had been working with the FBI the entire time." 
The intrusions "were suggested by Sabu while cooperating with the FBI," and foreign government websites as well, according to Hammond's statement. 
Hammond was among five people indicted in 2012 alleged to be members of Anonymous, Lulz Security and other international hacking groups. 
The indictments cover some of the most notorious hacking incidents of the past several years including those against Sony Pictures Entertainment, Stratfor and computer security firm HBGary. 
Hammond, who could have faced a longer prison sentence before his "non-cooperating plea agreement," admitted his involvement in computer intrusions into the FBI Virtual Academy, the Arizona Department of Public Safety and other government networks. 
The Hammond case is linked to that of Barrett Brown, a journalist and former spokesman for Anonymous who faces up to 105 years in prison. 
The Brown case is being watched by media rights activists who argue that he was targeted for sharing links of Hammond's hacked materials. But he also faces charges of threatening a federal agent. His trial is due next year in a Texas federal court."
 SOURCE: http://www.channelnewsasia.com/news/world/hacker-linked-to/888540.html

Malicious & Sharing Malware Sub-Domain - dc612.4shared.com

dc612.4shared.com REDIRECTS to www.4shared.com


MALICIOUS PHISHING (SHARING MALWARE) DOMAIN:
  • https://www.virustotal.com/de/url/98ca9becdfad946540fde165af8e4e322506b63bcfbee6a5e582ca94c303a544/analysis/1385916108/
  • http://wepawet.iseclab.org/view.php?type=js&hash=02c10884176e12ba2604ea8c7b5b7518&t=1345339776
  • http://www.urlvoid.com/scan/dc612.4shared.com/
THE FOLLOWING URL & FILES HAVE BEEN SHARED THROUGH THIS SUBDOMAIN:

  • https://www.virustotal.com/de/url/7a83d9db1f7417308a9d8a803dca1f51f7a0446e7e3bad664b45d011d18b393b/analysis/
Backdoor.Win32.DarkKomet.bijw (Threat Description) 
https://www.virustotal.com/de/file/8459f1304094579af94d0e73bb125c7888edc243fd17d911cc7a7664ce49d2e5/analysis/1383266175/
------------------------------------------------------------------------------------------------------------
  • https://www.virustotal.com/de/url/52095ed0f4c67f5165a43a863b5edfe36dc2236e5f6e67ecfafc7d924a45e332/analysis/1385918019/
Trojan-Banker.Win32.Banbra.axhv (Threat Description)
https://www.virustotal.com/de/file/4870236ff27e8d560612337d909a529637abe38495f135568fe19d7077aec680/analysis/
------------------------------------------------------------------------------------------------------------
  • https://www.virustotal.com/de/url/47dbf39907bee90a1de4d951422fa6e83e5c94e52feed39adbc828c269d6e107/analysis/
Trojan-Spy.Win32.Banker
https://www.virustotal.com/de/file/f2a2ac45538e7075fce661422206c458587a2a0ae48072c2914629a732e04d39/analysis/1355936554/
------------------------------------------------------------------------------------------------------------
  • https://www.virustotal.com/de/url/cb2d0e5ffe44f93a2fd0c445f1c0f22fe2741b8df9ee331491ef0c8cc0989705/analysis/
Trojan.Win32.ChePro.wh (Threat Description)
https://www.virustotal.com/de/file/4025caad62473392e74efb828ad3214101dc0e8401e87097834317e650b75388/analysis/1357198015/

AND MANY MORE !
******************

The Dark Side of Super Technology - The Human cost of America's deadly Drone Strikes in Pakistan

DFUSDS 2013
US drones attacks in Pakistan have killed more than 2000 people. This heartbreaking film bears witness to people in a remote part of Pakistan (Waziristan) near the Afghan border whose lives continue to be shattered by the attacks. "This child was killed in an attack too", says a local journalist as he flicks through photos of drone attack victims. Children's faces emerging from his photographs contradict the assertion that drone attacks only target "suspected terrorists".


                                                     The Wounds of Waziristan  


According to the US Army, all military-age males in a strike zone are counted as terrorists. This idea upsets Karim, who lost his brother and son in a drone attack. "There is no bigger terrorist than Bush or Obama, who drop bombs on our homes." Meanwhile, with several drones flying low over the villages at a time, the constant fear of bombardment and grief is putting an psychological strain on the survivors. "I feel guilty about being alive", confesses Saddam, who lost his sister-in-law and 1-year old niece in a drone attack.

This striking film offers a rare view of the human face of collateral damage.

ORIGIN SOURCE: The Journeyman

The Cryptolocker



The Cryptolocker Ransomware (as well known as Crilock) intrusions are becoming Polycephaly, and so far there is a Antivirusvendor (AVV) counting more than 12.000 infections in the United States alone.


The Nasty piece of Malware, which encrypts your files (mainly .DOC files, pictures as well as AutoCAD-Files) when infected, requires thereafter a Ransom for decryption, up to 300 USD (in bitcoins) and more. Time available you have left to pay: up to between 3 days and 100 hours. Some may say that the genuine thoughts (targets) of those developers of Cryptolocker were, or, could have been the clientele of the ongoing Expansion of World-Wide-Web-Communities of Pedophiles, in fearness of getting "outed" !

The United Kingdom alone was spammed with several millions of malicious e-mails. This went so far (as it looked like a Campaign), that the National Cyber Crime Unit (NCCU), a sub-organization of the
National Crime Agency (NCA) (sounds a bit like NSA), had to give out an Alert on
November 15th 2013.
"The NCA's National Cyber Crime Unit are aware of a mass email spamming event that is ongoing, where people are receiving emails that appear to be from banks and other financial institutions.
The emails may be sent out to tens of millions of UK customers, but appear to be targeting small and medium businesses in particular. This spamming event is assessed as a significant risk.
The emails carry an attachment that appears to be correspondence linked to the email message (for example, a voicemail, fax, details of a suspicious transaction or invoices for payment). This file is in fact a malware that can install Cryptolocker – which is a piece of ransomware
Cryptolocker works by encrypting the user’s files on the infected machine and the local network it is attached to.
Once encrypted, the computer will display a splash screen with a count down timer and a demand for the payment of 2 Bitcoins in ransom (Approx £536 as at 15/11/2013) for the decryption key.

The NCA would never endorse the payment of a ransom to criminals and there is no guarantee that they would honour the payments in any event.
Lee Miles, Deputy Head of the NCCU says "The NCA are actively pursuing organised crime groups committing this type of crime. We are working in cooperation with industry and international partners to identify and bring to justice those responsible and reduce the risk to the public."
An NCCU investigation is ongoing to identify the source of the email addresses used. Anyone who is infected with this malware should report it via Action Fraud
Sound advice can be found at GetSafeOnline
Advice: This is a case where prevention is better than cure.
  • The public should be aware not to click on any such attachment.
  • Antivirus software should be updated, as should operating systems.
  • User created files should be backed up routinely and preserved off the network.
  • Where a computer becomes infected it should be disconnected from the network, and professional assistance should be sought to clean the computer.
  • Various antivirus companies offer remedial software solutions (though they will not restore encrypted files)."

Researchers of Bitdefender Labs revealed that a bit more than 12.000 victims were affected during a one-week period at the end of October. “CryptoLocker servers are changed very often (it is seldom that a CnC-Botserver remains online for more than a week), however, once it has been Reverse engineered, Security Researchers can pre-analyse the relevant domains and count connection attempts.” according to a Bitdefender Post last November.

BitDefender used the DNS-Sinkholes and studied that the quantity of those connections could get traced back to IPs in the United States. Quote from that Post:

"In fact, judging by the distribution of infected hosts and the payment methods available, it would seem that only systems in the US are targeted, with the rest being collateral damage."

First appeared, Cryptolocker came into nature as a out of "the wild"-Trojan, spreading through fake emails. It penetrates then encrypted files on the user's CPU and any profiled network drive(s). Once you are padlocked, it demands you for a MoneyPak or Bitcoin payment within three days (or up to 100 hours). Further on, (if) you pay the Ransom, you will receive a key that unlocks your encrypted files.

In the very first period, the Unlock-key was destroyed 72 hours after infection, so you could forget your files for good, locking them permanently. After the Attackers found out, they may gain more money with a lucrative Scheme in giving you a "Last Chance", they rewrote CryptoLocker around beginning of November 2013, to allow the recovery of your files, beyond the designated time at a higher Ransom of Bitcoins.

According to Microsoft, Crilock affected about 34.000 machines between September and early November 2013. By today, the Malware changed to
CnC-Hosts in Countrys like Russia, Germany, Kazakhstan and Ukraine and the Ware is still spreading...
Map showing the first Rampage of Cryptolocker (Pict. by BitDefender)

Further interesting Articles about Cryptolocker:

"US-CERT is aware of a malware campaign that surfaced in 2013 and is associated with an increasing number of ransomware infections. CryptoLocker is a new variant of ransomware that restricts access to infected computers and demands the victim provide a payment to the attackers in order to decrypt and recover their files. As of this time, the primary means of infection appears to be phishing emails containing malicious attachments."

New Malicious Code - Compromised Domain (Hacked): pupolandia.com (www.pupolandia.com)

Following Domain has been hacked & infiltrated with Malware (Neutrino Exploit Kit):

pupolandia.com Analysis Reports

Neutrino Exploit Kit Clicker.php (TDS)
c0896 Hacked Site Response Hex (Inbound)
c0896 Hacked Site Response (Inbound) 4
Snort Alert
Obfuscated Split String (Double Q) 8


REMOTE DESTINATION TO:

- hr.oncallinteractive.com/clicker.php

Read more about the Neutrino Exploit Kit:

PandaLabs: New Malware Creation Hits Record High Numbers in 2013

Malware creation hits record high, Newly detected Ransomware CryptoLocker, DNS poisoning attacks on the rise & Android the most malware-targeted mobile platform.



Panda Security’s anti-malware laboratory, has just published the results of its Quarterly Report for Q3 2013, drawn up by PandaLabs, the company's anti-malware laboratory. One of the main conclusions that can be drawn from this global study, is that malware creation has hit a new record high, with nearly 10 million new strains identified so far this year. One Fact is, that the number of new malware samples in circulation in just the first nine months of 2013 has already met the 2012 figure for the entire year. Trojan Horses remained the most common threat, accounting for most new threats and infections worldwide.

One of the most notable threats over the past months is CryptoLocker, a new ransomware sample which surfaced in late 2013. It hijacks users’ documents and demands a ransom for them.

Example of CryptoLocker Message
There was also a significant increase in the number of attacks, known as DNS Spoofing. Several large websites hosted in Malaysia fell victim to this type of attack, including the local websites of companies such as Google, Microsoft or even the well known Computer Security Company Kaspersky Labs.

Android continued to be the top target among all mobile platforms, despite some high-profile attacks on iOS, Apple’s operating system.

Cyber-War: NSA remains in the eye of the storm


As far as Cyber Spying is concerned, the United States (Thanks to Ed Snowden from here. GD) took the spotlight off China after revelations emerged about the clandestine PRISM Surveillance Program operated by the NSA (National Security Agency) to obtain user data from major U.S. Cyber Companies such as Microsoft, Google, Apple, Facebook, etc.

“Everything seems to indicate that there will be more upcoming revelations about other NSA surveillance programs to indiscriminately spy on users, companies and governments around the world,” said Luis Corrons, technical director of PandaLabs.

Q3 2013 malware statistics


Trojans once again topped the rankings, accounting for 76.85 % of all new threats identified by PandaLabs, followed by worms, viruses and adware/spyware.

Additionally, Trojans continued to be the weapon of choice for malware writers to infect users’ systems. 78% of all computer infections registered in the third quarter of 2013 were caused by Trojans, followed by viruses (6.63 %), adware/spyware (6.05 %) and worms (5.67 %).

Geographic distribution of malware infections


Latin America remained the most-affected area by malware. In any event, the ‘Top 10’ list of most infected countries includes nations from all over the world, with China at the top with nearly 60 % of all computers infected with Malware, followed by Turkey (46.58 %) and Peru (42.55 %).

At the other end of the chart, Europe continues to have the lowest infection rates. The least infected countries were Netherlands (19.19 %) (Although the highest Concentrate of Malware Lancers, the infamous RBN & others originate from Amsterdam and the U.K. GD), United Kingdom (20.35 %) and Germany (20.60 %). The only non-European country in the Top Ten was Australia, in ninth place with 26.67 %.

The complete quarterly reports are available @ Panda Labs Press Room


About Shopping & Getting Hacked

Christmas shoppers are carrying more mobile devices this year then the ones before, which means they're more likely to fall victim to Cybercriminals. But are they aware ?

"The number one thing you can do, and it's a real simple thing to do, is add a password to your phone. It will help protect the data that you have on there," advises Symantec's Kevin Haley.

The bigger risk is getting hacked because you're using the "wrong" or unknown WiFi. Simply, just don't do anything very important while on public WiFi.


"It's always possible that somebody in a free WiFi setting could be listening in," Haley notes.

Wade Baker
Cybertrust expert Wade Baker says the safest thing to do is just shut off the WiFi and use your own plan for Internet access.

"If you are on a public network, make sure it's a legitimate one, make sure it is the one offered by Starbucks, or the actual airport, rather than some guy sitting in the corner," Baker warns.

And if you insist on buying online from your mobile device, only enter personal information when there's an "S", for secured" at the end of the "HTTP".

11/30/2013

Picture of the Day

U.S. citizen Merrill E. Newman reads from a piece of paper at an undisclosed location in this undated photo released by North Korea's Korean Central News Agency in Pyongyang. He has been detained since he was taken off a plane October 26th 2013


Video: Our Safe Technology ? Radiating the People - Fukushima's Cancer Legacy



It's what POST-Fukushima Japan fears the most: Cancer. Amongst all accusations of government secrecy, worrying new claims, say a cancer cluster has developed around the Atomic Radiation Zone and that the most acclaimed victims are Children !



One man's little daughter is unaccounted for after the huge Tsunami destroyed the nearby town of Okuma, in Japan, on March 11th 2011. The Government stopped searching for her a long time ago. But, her father, Norio Kimura, has not and never will. At the same time, in a children's hospital, away from the forbidden zone, parents are hoping doctors won't find what they're looking for - Thyroid cancer.


Obamacare Weekend: It begins with a Website Shutdown
for Maintenance (Security?) Fixes

It was supposed to be D-Day for President Obama’s health care overhaul. But the government took down its website for a very long maintenance fix



A crucial weekend for the troubled Website that is the backbone of President Obama's healthcare overhaul appears to be off to a shaky start, as the government took the HealthCare.gov site offline for an unusually long maintenance period that lasted into Saturday morning.

Just hours before the Obama administration's self-imposed deadline to get the insurance shopping website working for the "vast majority" of its users by Saturday, the Centers for Medicare and Medicaid Services announced that it was taking down the website for an 11-hour period.


It was unclear whether the extended shutdown of the website - about seven hours longer than on typical day - represented a major setback to the Obama administration's high-stakes scramble to fix the portal, that it hopes eventually will enroll about 7 million uninsured and under-insured Americans under the Patient Protection and Affordable Care Act, also known as Obamacare.

At the very least, the shutdown suggested that nine weeks after the website's fatal launch on October 1st 2013 prevented most applicants from enrolling in coverage and ignited one of the biggest crises of Obama's administration, U.S. officials are nervous over whether Americans will see enough progress in the website to be satisfied.

For the administration and its Democratic allies, the stakes are enormous.



The healthcare overhaul is Obama's signature domestic achievement, a program designed to extend coverage to millions of Americans and reduce healthcare costs! (a verry good Thing !! G.D.) To work, the program must enroll millions of young, healthy consumers whose participation in the new insurance exchanges is key to keeping costs in check.

After weeks of around-the-clock upgrades of software and hardware, Obama officials said they were balanced to successfully double its capacity by this weekend, to be able to handle 50.000 insurance shoppers at the same time.

However, if the website does not work for the "vast majority" of visitors this weekend as the administration has promised, uninsured Americans from 36 states could face problems getting coverage by an initial Dec. 23 deadline.



It also could cause a stir that (could) extend to the 2014 elections when control of the U.S. House of Representatives (now controlled by Republicans) and the Senate (now led by Democrats) will be up for grabs.

Obama's fellow Democrats who are up for 
re-election in Congress already have shown signs of taking distance  from the president and his Healthcare program. If the website does not show significant improvement soon, some Democrats - particularly the dozen U.S. senators who are from states led by conservative Republicans and who are up for re-election next year - might call for extending Obamacare's final March 31 enrollment deadline for 2014.

That would delay the fines that are mandated by the law for those who do not have insurance by that date, a scenario that insurers say would destabilize the market. It also would fuel Republicans' arguments that Obamacare, and its website, are fatally flawed and should be scrapped.


Related Posts:


11/29/2013

Kentucky Man will be sentenced March 2014 after trying to defraud Two Internet Companies per PayPal

A Fraudster from Covington, Kentucky, will be sentenced in March 2014 for defrauding two internet companies out of thousands of dollars (He faces a mandatory two year sentence on the aggravated identity theft count and maximum of 20 years on the wire fraud offense). One may wonder how a single man came through with a scheme of defrauding (2!) INTERNET Companies.

He (Melvin Dietz) pleaded guilty on November 19th this year that from January 2011 through December 2011, he arranged a scheme to defraud two online internet companies, WeBuyUsedCisco.com and Teksavers.com, both of which purchase used Cisco computers and equipment for Resell. The guy used 14 different PayPal accounts (each single one with a fake Identity for executing his scheme).


Now, shortly before or after he created an account, he contacted one of the companies and fraudulently offered to sell them certain Cisco items by pretending that he possessed them. Through e-mail, he used then one of his fake IDs, and bargained a price with a representative of one of those mentioned companies for the assumed Cisco equipment. At Dietz's instructions, the respective company transferred the payment for the equipment to one of the "fake" PayPal accounts that Dietz had set up using the same or a different alias identity every time. Right after, Dietz cut off communication and never sent the equipment.

To authorities, Dietz acknowledged he used or attempted to use the money in his PayPal accounts to purchase items online from other various online retail businesses or remove the money from his alias PayPal accounts in some other ways. The amount transferred by WeBuyUsedCisco.com & Teksavers.com to his PayPal account(s) totaled the amount of approximately 70.000 USD.

In committing his felony, Dietz knowingly used, without lawful authority, a means of identification of another person, during and/or in relation to the wire fraud count, in that he used that individual's Social Security number to obtain a prepaid Visa Card. Later Dietz used the card to validate the account with PayPal for the purpose of furthering his scheme to defraud Teksavers.com.

Two Singaporean arrested for Hacking Singapor's Presidential Website

Two Singaporean men have been arrested for allegedly defacing Singapor's president Tony Tan Website during a recent rash of Cyber Attacks in the city-state, police said on Thursday.



The men, aged 17 and 42, were arrested following a complaint lodged by the Website administrators of the Istana, the official residence of President Tony Tan.

Tony Tan

The Website was hacked and displayed a crude image in the early hours of November 8, about an hour after Prime Minister Lee Hsien Loong's website displayed mocking messages and pictures from activist hackers' group Anonymous. Police said the two attacks are unrelated to each other.

Lee Hsien Loong
The suspects in the Istana Website hacking will be charged in court on Friday, November 29th 2013, for offences under the city-state's Computer Misuse and Cybersecurity Act.

They face a maximum fine of Sg$10 000 or imprisonment of up to three years, or both.

Police did not reveal the identity of the two suspects, but Singaporean businessman Doolson Moo last week revealed to
The Straits Times newspaper, that he was the one who penetrated the Istana Website to “test for vulnerabilities”.

The 42-year-old said he entered a line of computer code into the search box on the website that allowed him to display a picture of an old woman pointing her middle finger, along with a string of offensive words in the southern Chinese dialect of Hokkien.

He told the newspaper that his accomplice was a 17-year-old student he knew through social networking site Facebook.

Guy Fawkes Mask
The arrests on Thursday came after another Singaporean, 35-year-old James Raj, was charged in court on November 12th 2013 with hacking a municipal council's Website and posting an image of a Guy Fawkes mask, the international symbol of Anonymous.

The council is located in a district represented by the prime minister.

A man claiming to speak for Anonymous has demanded that Singapore scrap a law requiring news websites to obtain annual licences.

The new Internet licensing rules came into force in June 2013 and have angered bloggers and activists who say they are designed to cover free expression.

Singapore strictly regulates the traditional media, but insists the new licensing rules do not have an impact on Internet freedom.

Tips to Avoid Being Scammed the Next Holiday Season

In advance of the holiday season, its always good to beware of cyber criminals and their aggressive and creative ways to steal money and personal information. Scammers use many techniques to fool potential victims, including fraudulent auction sales, reshipping merchandise purchased with a stolen credit card, sale of fraudulent or stolen gift cards through auction sites at discounted prices, and phishing e-mails advertising brand name merchandise for bargain prices or e-mails promoting the sale of merchandise that ends up being a counterfeit product.



  • Fraudulent Classified Ads or Auction Sales

Internet criminals post classified ads or auctions for products they do not have. If you receive an auction product from a merchant or retail store rather than directly from the auction seller, the item may have been purchased with someone else’s stolen credit card number. Contact the merchant to verify the account used to pay for the item actually belongs to you.

Shoppers should be cautious and not provide credit card numbers, bank account numbers, or other financial information directly to the seller. Fraudulent sellers will use this information to purchase items for their scheme from the provided financial account. Always use a legitimate payment service to protect purchases.



Diligently check each seller’s rating and feedback along with their number of sales and the dates on which feedback was posted. Be wary of a seller with 100 percent positive feedback if they have a low total number of feedback postings and all feedback was posted around the same date and time.


  • Gift Card Scam


The safest way to purchase gift cards is directly from the merchant or authorized retail merchant. If the merchant discovers the card you received from another source or auction was initially obtained fraudulently, the merchant will deactivate the gift card number and it will not be honored to make purchases.



  • Phishing and Social Networking

Be leery of e-mails or text messages you receive indicating a problem or question regarding your financial accounts. In this scam, you are directed to follow a link or call the number provided in the message to update your account or correct the problem. The link actually directs the individual to a fraudulent website or message that appears legitimate; however, any personal information you provide, such as account number and personal identification number (PIN), will be stolen.

Another scam involves victims receiving an e-mail message directing the recipient to a spoofed website. A spoofed website is a fake site or copy of a real website that is designed to mislead the recipient into providing personal information. (See Picture)



Consumers are encouraged to beware of bargain e-mails advertising one day only promotions for recognized brands or websites. Fraudsters often use the hot items of the season to lure bargain hunters into providing credit card information. The old adage: 

"If it seems too good to be true, it probably is," 

is a good barometer to use to legitimize e-mails !

Black Friday has traditionally been the "biggest shopping day of the year." The Monday following Thanksgiving has more recently (2005) been labeled Cyber Monday, meaning the e-commerce industry endorses this special day to offer sales and promotions without interfering with the traditional way to shop. Scammers try to prey on Black Friday or Cyber Monday bargain hunters by advertising "one day only" promotions from recognized brands. Consumers should be on the watch for too good to be true e-mails from unrecognized websites.



Along with online shopping comes the growth of consumers using social networking sites and mobile phones to satisfy their shopping needs more easily. Again, consumers are encouraged to beware of e-mails, text messages, or postings that may lead to fraudulent sites offering bargains on brand name products.

Some tips you can use to avoid becoming a victim of Cyber Fraud this year:

  • Do not respond to unsolicited (spam) e-mail.
  • Do not click on links contained within an unsolicited e-mail.
  • Be cautious of e-mails claiming to contain pictures in attached files, as the files may contain viruses. Only open attachments from known senders. Always run a virus scan on attachment before opening.
  • Avoid filling out forms contained in e-mail messages that ask for personal information.
  • Always compare the link in the e-mail to the web address link you are directed to and determine if they match.
  • Log on directly to the official website for the business identified in the e-mail, instead of "linking" to it from an unsolicited e-mail. If the e-mail appears to be from your bank, credit card issuer, or other company you deal with frequently, your statements or official correspondence from the business will provide the proper contact information.
  • Contact the actual business that supposedly sent the e-mail to verify that the e-mail is genuine.
  • If you are requested to act quickly or there is an emergency, it may be a scam. Fraudsters create a sense of urgency to get you to act impulsively.
  • If you receive a request for personal information from a business or financial institution, always look up the main contact information for the requesting company on an independent source (phone book, trusted Internet directory, legitimate billing statement, etc.) and use that contact information to verify the legitimacy of the request.
  • Remember: If it looks too good to be true, it probably is.

Microsoft Releases Security Advisory for Microsoft Windows Kernel (2914486)



Microsoft has released Security Advisory 2914486 to address a vulnerability in a kernel component of Windows XP and Windows Server 2003. This vulnerability could allow an attacker to obtain elevation of privilege and then execute arbitrary code. Microsoft is aware of limited, targeted attacks that attempt to exploit this vulnerability in the wild.

http://technet.microsoft.com/en-us/security/advisory/2914486

TIMEOUT: Something to Relax...on Thanksgiving

Take 20 Minutes Timeout, take a  look this Video (enlarged and if possible in HD), and  Chillout. Happy Thanksgiving