Showing posts with label spam. Show all posts
Showing posts with label spam. Show all posts

Saturday, February 27, 2010

Interrupted lives - A story of a Twitter Hack

Yesterday my Twitter account was hacked causing me to spam at last 100 of the people I follow with sexually suggestive Direct Messages. Apparently I was not alone in this phishing attack. There was also something similar recently in Facebook. In my case it was caused by rather stupidly clicking on a DM sent to me on Thursday night. I knew the person who sent it and had no immediate reason not to trust it. As Pete Cashmore said we're less wary when a link appears to be from a trusted contact. The message read “Is this you?” and provided a link (via a deceptively meaningless short URL) which I clicked on almost without thinking.

Almost instantaneously I regretted clicking although nothing happened immediately. Barely minutes later I saw someone’s Facebook warning that the “is this you?” message was malware and you shouldn’t click on the attached link. I was annoyed at my stupidity and hoped nothing further would come of it. But when I checked the Internet on Friday morning it was obvious a lot more had come of it.

Apparently what happens when you click on the link is that your Twitter password is sent to the attackers, permitting them access to your account. According to Cashmore, your friends receive the same message shortly after, which will look like it was sent out by you. I didn’t send out the same message (as far as I can tell) but the one I did send was a classic in its own right.

At approximate 7am yesterday morning, about a hundred DMs were unleashed from my account. Twitter has now cleaned out all the messages from my sent folder however someone however was kind enough to send me a screenshot of how it looked. In the message I was claiming to be “female/24/horny” and added “I have to get off here but message me on my windows live messenger name paris928love@hotmail.com” It is unlikely that any of the messages would have fooled their recipients. For starters they were all sent out complete with my name and headshot avatar which makes it blatantly apparent I am neither female, 24 nor horny (unless, as I wrote later by ‘horny’ they meant ‘scaly’).

I was blissfully unaware of this activity while munching my weetbix for breakfast. When I logged on an hour later, I became aware of the problem when I checked my regular emails and noticed quite a lot of Twitter DMs sent to me in return. These were all genuine DMs sent to me by friends who were either laughing at the absurdity of the message (if they knew me well) or warning me I was hacked (if they didn’t). When I logged on to Twitter there were many more messages.

“excuse me?”

“Just got a DM from @derekbarry that makes me think his account has been hacked.”

“Time to change your Twitter passwd. Ur sending our "interesting" DM spam. eg "..hi, i'm 24/female/horny...message me on my...”

“unless you are leading a secret double life someone is using your account for spam”.

“Derek, your account has been compromised. Unless you really ARE 24 and horny.”

“You don't look like a 24yo horny female to me.... :) I think you've been hacked!!”

“so u won't hit any "is this you?" messages in future? :) was caught by one back at Xmas. Mine sent out colonic irrigation tweets :P”

One person wrote to tell me he had received one of female/24/horny messages but he also had been hacked and was “going nuts” about how to solve the problem. While I was sympathetic, this was not a reaction I shared. I was momentarily embarrassed so much spam had been sent out in my name but looking at how absurd it was, I found it funny. It was also unwittingly the cause of more real interaction with people than I would normally have had if I'd been left alone.

I sent out a few Tweets apologising for the spam, joked about being scaly rather than horny and immediately changed my Twitter password. This in turn got a lot of responses most of which saw the funny side of what had happened. Here, I hope my reputation in Twitter allowed me to turn a potentially nasty situation into one which people could laugh at. And as far as I know, no one stopped following me thinking I was a spambot.

Within a half hour, I got an email from Twitter saying they believed my account was compromised. They forced me to change my password again and hopefully I’m now clean until the next time I accidentally click on a safe looking link. I say “next time” because despite my increased wariness I’m convinced it will happen again. Spammers are becoming more adept at mimicking convincingly real behaviours – though as my own messages proved they still leave a lot to be desired in matching physical attributes with the text!

Tuesday, February 16, 2010

Scammers use Haiti earthquake for online fraud

The Haiti earthquake had an unintended consequence of driving up phishing and scam attacks across the Internet in the first month of this year. In the days after the Haiti quake, scammers asked users to donate money to a charity however any donation disappeared into an offshore bank account. Building on this, spammers began to send phishing messages, pretending to be from legitimate organisations like UNICEF. Hackers also took advantage of the tragedy to deliver malware. In one example, users download a Trojan when they click on the link to view a supposed video of the earthquake damage. The findings were in the monthly State of Spam and Phishing report from Symantec. (photo by alex_lee2001)

The report found both scam and phishing categories doubled as in percentage of all spam in January 2010 compared to a month earlier. The total of scam and phishing messages came in at 21 percent of all spam, which is the highest level recorded since the inception of the report. As well as Haitian scams, the report found the well-known Nigerian 419 scam (named for the section of the Nigerian penal code which addresses fraud schemes) was on the rise again as was online pharmacy spam.

Symantec say spammers have changed their tactics regarding online pharmacy spam. They have now taken to using subject lines such as “Must-Know Rules of Better Shopping” and “You Must Know About This Promotion” which are vaguer than “RE: SALE 70% OFF on Pfizer.” Other misleading subject lines such as “Confirmation Mail” and “Special Ticket Receipt” were also used for online pharmacy spam messages.

They also say phishing attacks are getting more and more targeted in nature and are focused on attacking major brands rather than being mass attacks. Symantec observed a 25 percent decrease from the previous month in all phishing attacks. The decline was primarily due to a decrease in the volume of phishing toolkit attacks which have halved from the previous month. A 16 percent decrease was observed in non-English phishing sites as well. More than 95 Web hosting services were used, which accounted for 13 percent of all phishing attacks, a decrease of 12 percent in total Web host URLs when compared to the previous month.

The US remains the most likely point of origin of spam. Approximately one in four of all spam is American-based with Brazil next most likely far behind in second place with just 6 percent. India, Germany and Netherlands are responsible for 5 percent each. The US is even more dominant in the categories of geo-location of phishing lures and hosts with 52 percent of the former category and 49 percent of the latter. Germany is second far behind with 6 percent in both categories.

Symantec notes that China has clamped down on spamming by suspending new overseas .cn domain registrations. The China Internet Network Information Center stated this suspension will allow them to implement a better procedure to verify registrant information from overseas registrations. This was a follow-up action to a related move in mid-December that required additional paperwork with registrations. As a result, spam messages with .cn domain URL dropped by more than half in January, compared to December with a steep drop towards end of January.

The report also found a new trend in adult oriented phishing. The phishing site tempts the unwary by promising free pornography after logging in or signing up. These scams affect users who enter their credentials in the hopes of obtaining pornography. Upon entering login credentials, the site redirects to a pornographic website before leading to a fake antivirus site containing malicious code. An incredible 92 percent of adult phishing scams were on social networking sites. The phishing sites were created using free webhosting services.

The report offers advice so familiar it beggars belief so many people are still falling victims. It talks about unsubscribing from lists, keeping your mail address secret, deleting all spam, avoid clicking on suspicious links and email attachments or replying to spam, don’t fill in forms online that ask for personal information and finally don’t forward virus warnings which are usually hoaxes. Spamming is a multi-billion dollar industry that relies on the truth of the hoary phrase that “there’s a sucker born every minute”.

Thursday, January 15, 2009

Optus spanked for spamming

The Australian Communications and Media Authority (ACMA) has imposed a major fine on Optus for sending thousands of unsolicited and anonymous text messages. Optus were fined under the Spam Act for not providing sufficient identification of origin on text message that were sent out to 20,000 customers. Optus tried to negotiate their way out of the penalty but failed and now face a substantial $110,000 fine for two related offences.

ACMA issued the two infringement notices to Optus for failing to provide clear and accurate sender identification with SMS promotions. The messages promoted the OptusZoo entertainment service to mobile phones with the sender identification of ‘966’. ACMA chair Chris Chapman did not accept Optus's assumption that message recipients would make the connection between the keypad letters of Zoo and 966. “This was not considered sufficient identification, as 966 could be used to represent any number of permutations on a telephone keypad,” he said. He went on to warn companies considering similar shonky schemes that “ensuring spam compliance procedures are understood by all staff is imperative for all businesses if they want to avoid the risk of costly fines.”

The fines are mandated by the 2003 Spam Act (pdf) which regulates unsolicited commercial electronic messages such as emails, SMS messages, MMS messages and instant messaging. The act imposes three key obligations on businesses that send electronic messages. They must firstly only send messages with the implied or explicit consent of customers, secondly they must include clear and accurate information about the identification of the sender and finally they must include an “unsubscribe” function in all messages. Unlike the weak ‘opt out’ US CAN-SPAM Act (message recipients had to ask the sender not to send future messages), the Australian legislation was ‘opt in’. Only charities, religious organisations, political parties and the Government are exempt from the law. The downside is that is has no jurisdiction over foreign spammers.

Yet if ACMA are to be believed, the Act has been successful in significantly reducing locally-generated spam. They say that at the time the penalty provisions of the Act were introduced (2004) Australia was 10th in the ranking of spam-relaying countries. However by end 2007, Australia had fallen to 35th. The biggest offender against the Act so far has been DC Marketing Europe Limited which copped a $150,000 fine for contraventions relating to missed call marketing (short duration calls which deliberately leave a ‘missed call message’ to entice callers to ring back) in 2006. DC Marketing breached the Spam Act on all three counts; sending unsolicited messages, not identifying the sender and not containing an unsubscribe facility. While it is arguable that Optus also failed under the first of these requirements, ACMA charged them over the second requirement. The problem is that spam remains an attractive business proposition despite the high penalties. “Eliminating spam is a war you cannot win," according to one computer security expert. "It is much cheaper to send spam than stop it.”

Nonetheless the best tactic for consumers inundated with unwanted corporate pap is to ignore it. An Optus customer who did not want to be identified told Woolly Days he had gotten the spam emails that incurred the wrath of ACMA. He said the “966” texts could be identified as coming from Optus as the term "optuszoo" did appear in the actual text. However, he added, "like all other unsolicited text I receive, I just disregard them."

Friday, November 23, 2007

Spamalot: the curse of email spam

Web security firm Message Labs claim that cybercrime will increase significantly in 2008 with spammers using ever more sophisticated malware tools to get their messages out. The lucrative $105 billion market is attracting a steady stream of new players using new tactics such as video file spam and the ‘storm worm’ (a Trojan attachment associated with mass email-outs). Despite all the new e-crime tools available, email spam remains at the heart of this massive problem that affects every computer user.

In 2004 Bill Gates predicted that the spam problem would be solved within two years. He was spectacularly wrong. The problem got worse and 2007 was the worst year yet for email spam. Experts believe that up to 90 per cent of all email is now generated by spam robots. 2007 was also the year where the total of spam emails surpassed genuine person-to-person emails: 10.8 trillion to 10.5 trillion. The gap is only likely to increase. Estimates range from 60 to 150 million emails a day spruiking penis extensions, Viagra and a variety of get-rich schemes. While the most common reaction to spam is annoyance, it is also harmful.

Spam is generally used to refer to unsolicited or unrequested junk
emails over the Internet, known as unsolicited bulk emails. Unlike regular advertising email, the sender cannot be reliable contacted and the receiver cannot unsubscribe. Spam affects productivity. In Australia, the time and bandwidth lost to spam is estimated to cost business $2 billion a year. A 2004 National Technology Readiness survey (pdf) in the US found workers spend 2.8 minutes a day deleting spam at a cost to business of $21.6 billion in lost productivity.

In response to the growing problem, the US implemented the CAN-SPAM Act in 2003. The act banned misleading header information, deceptive subject lines, and gave email recipients an opt out method that asked the sender not to send future email messages to that email address. The act was heavily watered down after pressure from lobby groups including the Direct Marketing Association. Anti-spam activists dubbed the act ‘you can spam act’ saying the act did not outlaw the practice and instead appeared to give federal approval to spammers.

Where as the US legislation is opt-out, the Australian Spam Act of the same year went much further with its ‘opt in’ clause. The act makes it illegal to send ‘unsolicited commercial electronic messages’ from Australia exempting only charities, religious organisations, political parties and the Government. The act covers email, instant messaging and other mobile phone messaging but does not include telephone traffic. Despite the stiff million dollar plus penalties, the act has been ineffective due to its inability to reach foreign spammers.

As Email filters have become more sophisticated in their response to the problem, so too have the spammers tactics themselves. Thus while filters look for common used spam words, do check-sum based filtering, and perform statistical analysis and authorisation, the spammers have hit back by disguising their messages. Thus they are replete with words like “pen1s”, “s3x” and “\ /i@gra”. And to overcome the Bayesian filtering technique (based on keyword likelihood theories), spammers include nonsense text such as “group jed dash grille.jar aghast waxen squad kerry”, a technique known as Bayesian poisoning.

While mail servers run spam filtering software such as Spam Assassin to mark those mails it thinks are spam and place them in dedicated spam folders, it remains an inexact science. User must continue to examine spam emails before deletion in case they really are not spam. Spammers get most of their distribution lists by using programs to crawl the web sniffing out email addresses.

A Center for Democracy & Technology study of what types of addresses are more likely targeted, showed the best way of combating this is by publicly listing an address in human readable form such “name AT place DOT com” so that bots cannot pilfer it for spam use. Despite these measures, spam is likely here to stay, according to Greg Toto, vice president of products and operations at computer security firm BigFix. “Eliminating spam is a war you cannot win," he says. "It is much cheaper to send spam than stop it.”