Showing posts with label Email. Show all posts
Showing posts with label Email. Show all posts

Wednesday, September 10, 2014

5 Million Gmail Addresses and Passwords Leaked: What This Means for You

Gmail
Earlier today, news started making the rounds that a list of 5 million Gmail addresses and passwords was leaked on Tuesday, Sept 9 2014.




So what we are probably seeing is actually some hacker’s private stash rather than someone looking for help in cracking a password database.

Friday, September 24, 2010

Yahoo Email Shows Viral Behavior

Screenshot of Yahoo Email Spam

Yahoo Email Virus


Last weekend I received an unusual email from my sister.

She had sent the message to 6 or 7 people, some of them family members.  The subject line was something unintelligible.

And the content was a sales pitch for certain male performance enhancing recreational pharmaceuticals.

Naturally, there was a link to a website that held the chemical answer to all of mankind’s ailments, or maybe just man’s ailments.

My immediate thought was, “You got hacked!”

Friday, September 10, 2010

Detect Phishing Emails With These Online Apps

Email Phishing


While cleaning out my phishing email address, I came across several emails that were apparently from the FBI.

Screenshot. Email from the FBI.

While they all appear to be from the same user, a robertmueller at fbi.gov, one of these emails came from someone on the Villanova campus. Apparently the sender forgot to modify one of the fields in their bulk email spamming software.

Thursday, August 19, 2010

Identify Phishing And Spam Email Easily And Quickly

So you just received an urgent email telling you that you need to verify your Chase Account information. 

Is it a legitimate request or is it an online phishing scammer trying to gain access to your online account information? 

Is there a definitive method that you can use to distinguish legitimate email requests from online phishing scams?

Take a peek at this (simply click on a photo to expand it):

Wednesday, July 28, 2010

Phishing With Chase As The Lure

This is a post I made back at the turn of the year, just prior to the Christmas holidays.

At the time, I had received several emails from… an organization that called itself Chase asking me to update my online credentials on their site.

Monday, December 21, 2009

Did You Get Phished By Chase?


The holiday season is upon us. And with the usual holiday cheer and shopping rush, we can expect the usual host of… unsavory characters to make attempts at getting access to our online accounts and personal information.



It’s gonna happen so just expect to see it. I know I am.



I expect to see the email from an ebay participant telling me that they are anxious to complete the transaction and get the merchandise in question if I would just take the time and complete the conveniently provided form.




I expect to see the email from the “fake” Paypal company telling me that my account has been compromised and that I need to go to the account setup page to update my password. And they are even kind enough to provide a link to the page for my convenience.






I expect to get he occasional email from some “security professional” from a small bank telling me that my account has been compromised and that I need to use the supplied link to update my security credentials. Never mind the fact that I never heard of the bank let alone opened an account with them.



As the year draws to a close, more people will come under increased pressure between closing business at work and creating a memorable holiday event at home. Consequently, they won’t scrutinize those urgent and ominous looking email messages from “the bank” in their email inbox.




A Social Engineering Lesson From A Counterfeiter




When I was in college, one of the books that made the rounds in our class was an underground classic entitled “The Poor Man’s James Bond”. It was in the same class of books that included “The Anarchist’s Cook Book” so you can make a pretty good guess about some of the content.



I had obtained a copy of a copy of a copy, so you can imagine what the print quality and readability of this dog-eared document was like. Yeah, it was pretty ugly. There was one section, however, that was still in fairly good shape with no dropouts or additional markings, probably because it was the section that the past owners were the least interested in. This was the counterfeiting section.



I don’t remember all of the steps that the author outlined to create a passable counterfeit bill back then. In truth, I found it equally uninteresting and way too much work. However, I do remember the suggestions he made for passing one off.



His suggestion was to take the play money, roll it around in the dirt, and bake it in the oven to give it that well used look and feel. Then take it to a place of business during the busiest time of the day and buy something small with it. On checking out, get in the line manned by the greenest kid you can find with as many irate people as possible to make the purchase.



Now, when the counterfeiter is standing there with their dirty, smelly counterfeit $20 bill and a big smile, all the kid sees is a mile-long line of irate, rude people behind him. In an effort to get everyone out the door with as little drama as possible, the kid won’t put up much of a challenge to the counterfeiter.



I’m happy to say that measures have been implemented that make copying US bills extremely difficult if not impossible. But the social engineering piece is still out there and the phishers are making heavy use of the basic principles.



They are sending you email with official logos and lots of words implying urgency and importance in an effort to get you to react emotionally instead of responding logically.



They will do this at a time when they know you have will have lots of email from other companies making offers. And all of this will occur at a time when you are trying to juggle 7 different things while struggling under time and emotional pressures.




Email Phishing Example




Take this entry for example. Now I know that phishers have used banks in the past, but this is the first time I’ve seen them use bait this big.









As you can see, I’ve received what appears to be an urgent request from Chase asking me to update my security information (let's forget for the moment that I don't have an account with Chase, a dead give away that it's a phishing scam, and proceed with the usual shock and suprise). My guess is that the big oversized logo coupled with phrases like “site authorization”, “security”, and “strongly advise” will stir up some type of visceral response. The additional title of “Chase Security” is probably there to make me pay less attention to the name of the person encouraging me to change my security information. (John Edwards? Wasn’t he running for President of the US?)



They’ve even provided a convenient link for me to sign into my account.



Rolling the mouse of the link will give you the URL in the browser status bar (that bar down below that has the word “Done”). While I don’t have it shown here, the URL turned out to be a shortened URL, probably to hide the final destination. The URL was http//nuurl.us/97061.



Naturally, this thing stinks to high heaven. It has ‘phish’ written all over it. First there is the simple fact that I’ve received this email from a bank. Banks will never send out email regarding security. They may use email for marketing purposes and tell you about some new wonderful services they are about to unleash or some new shops where you can spend your money. But for any type of serious communication you can expect to get something in the USPS or a phone call. You can forget about email. They are wound way to tight for that.



Then there’s the URL, a masked URL that ultimately doesn’t go back to the Chase domain. Of course you can’t see where it goes until you click on it. But the very fact that it’s hidden is a very telling sign.



There are some other unspoken rules here as well. Nothing hard and fast, but it is something that I’ve observed. Banks are large corporations. As such, their IT department typically has a set structure when creating email accounts, and that structure is usually something like firstname.lastname@companydomain.com.



The other unspoken rule is the punctuation. Again, there is no hard and fast rule here on how someone in the banking industry should behave, but when was the last correspondence you got from a banker that had an exclamation point, let alone three? When someone in the financial industry is writing some type of correspondence, they tend to stick with the facts and figures. They leave little room for any emotional involvement. In general, if you get a correspondence from a bank punctuated with exclamation points, chances are it’s not from someone in the financial industry.



Now, clicking on this link results in the following:








So if you have the smartscreen filter turned on in IE8 (or Chrome or Firefox), you will see a screen similar to this. Congratulations! You’ve done your part to thwart the phishers.



However, with the smartscreen filter turned off, we see a page that looks like the following:













I imagine that Chase has a page somewhere that looks like this. The guys who are sending this one out probably just ripped off the template and modified it for their purposes. The phrase, “Chase.com Demo” is a giveaway.



Also look at the URL in the address bar. There is no reference to any legitimate business domain name, which is why the smartscreen filter kicked this thing to the skids.



The other thing here to notice is that this is not a secure connection. Anytime a web connection is transferring secure data, the connection will encrypt the data before it sends it. If the connection is secure, you will see something like the following:








This is for a Google Analytics account. The connection is secured using the https protocol. The quick way to tell if the connection is secure is to look for the “lock” at the top of the browser. If you don’t see the lock at the top and the site is requesting that you pass over secure or sensitive data like passwords or account numbers, it’s time to cut and run.



This site from “Fake Chase” is using the unsecured protocol, it isn’t locked down and it’s asking for secure information, like your User ID, the password to your Chase account, social security number…



And of course, no financial institution would ask you for this kind of information via email, ever. So don’t give it out.



This holiday season while you are out doing the “shop ‘til you drop” thing, remember that there are some unsavory characters who are also out there shopping… for you and your bank account numbers. Don’t let them get yours.



Stay vigilant.


Saturday, August 22, 2009

Open Multiple Yahoo Accounts In IE8

Gaining Access To Multiple Yahoo Accounts Using IE8


OK. I logged into my second Yahoo email account recently. I typically login to my catchall account everyday to look at the spam, check email marketing samples, and look for anything of value that may find it’s way into the account. But I login to my “technical” account about once or twice a month.


For the longest time, if you had multiple Yahoo email accounts, you had to log out of the one that you had opened on your machine because Yahoo only allowed access to one email account per machine.

So before I could open a browser window and log into my Yahoo email tech account, I had to log out of my Yahoo catchall account, even if I had the “stay logged in” box unchecked.


Well, I made a mistake two days ago. I was on my laptop logged into my Yahoo email catchall account in IE8 and I opened a second IE8 window and opened the Yahoo site. To my amazement, it didn’t come up with my catchall account logged in.


Out of curiosity, I signed in to my Yahoo email technical account and it allowed me to do that. Furthermore, I was still logged in on my Yahoo email catchall account in the first IE8 browser.


What happened?


I mean, for the longest time, when IE7 was in full bloom and IE8 was nothing more than a sparkle in an engineer’s mind, I could only login to one Yahoo account per machine. Which meant that while I could open up multiple browsers and login to multiple Google accounts simultaneously, Yahoo only allowed me to login to one account on one machine regardless of the number of IE7 sessions I opened.


Now, my Yahoo accounts were behaving almost like my Gmail accounts.


First, I thought it was the new IE8 browser configuration that accounted for the change.


But that didn’t wash. I had another machine still running IE7 and I saw the same behavior on both configurations with Yahoo email accounts.


Then I thought that maybe it was because I also had Firefox and Chrome loaded on my test rig.


But that didn’t make sense either because I had no other browsers on my machine that was running IE7. My Yahoo email accounts still behaved like my Gmail accounts on both machines.


Eventually, I determined that regardless if I was running IE7, IE8, Firefox, or Chrome in combination with Windows XP, Windows Vista Ultimate or Vista Business, Yahoo mail was now behaving more like Google Gmail.


After much brain wracking and gnashing of teeth, I came to the conclusion that it was nothing that I had done. It was something that the good people at Yahoo had done.


Was it a result of the new portal look?


Did it happen after they killed off their personal blog and briefcase services?


Or maybe the team up with Microsoft had something to do with it.


I’m still waiting to hear something from the Yahoo team.


For now, know that if you configure your IE8 browser using the “nomerge” flag, your machine will handle multiple Yahoo email accounts the same way that if handles multiple Gmail email accounts.

Thursday, June 4, 2009

Put A Linkedin HTML Signature In Gmail To Make Your Message Stand Out

While perusing my web stats, I noticed that a search kept coming up regarding how to put a LinkedIn button into an email signature, Gmail in particular.



I’ve seen these queries in the past and had even looked into putting some kind of LinkedIn button into the signature file of my Google Gmail messages. While there are email apps that will allow you to use html tags in the signature file, the one downfall of Gmail messaging is that it will only accept text characters in the signature box. It won’t accept HTML tags.




Today, however, I decided to take a quick spin on Google to see what was actually out there. And while I didn’t find a clean solution, I did find “A” solution and a Linkedin function that I had previously forgotten about.



However, this is truly a case of “buyer beware” because this workaround is more of a hack.



While it is simple to do and it will integrate your Linkedin signature with your outgoing Gmail message, this is not a push button configuration.



Here’s what I mean.



With your typical text signature, like the one you’ve typed into the Gmail signature box, the minute you hit the “compose message” button to create your next message, your signature file is automatically loaded into the body of the message before you even start typing.



You set the signature up once and you don’t have to worry about it ever again, until you are ready to change it.



With this particular hack, you have to install it every time you send off an email.



So if you have 15 emails to send off, this activity is what is commonly called overhead and it can be very high, significantly impacting your time management activities.



Do you want to do this activity every time you send out an email? Probably not.

But if you are trying to impress a client, or if you want to push your LinkedIn profile to encourage your certain clients and prospects to connect with you, this could be a useful hack.



Still game? Then read on.




Getting The Linkedin HTML Signature


Turns out that some email apps will allow you to compose a rich signature file. Unfortunately, Gmail is not on that list. Gmail doesn’t support HTML tags in the signature file – yet. However, Gmail will allow you to drag and drop HTML objects into the compose pane. So you can create an email signature that looks real nice in LinkedIn, highlight the whole object, copy it and then past it into the body of the Gmail message.



First, get the signature.



Log into your Linkedin account and scroll down to the bottom of the page:



Finding the location for the linkedin HTML signature generator.

When you get to the bottom, you will see menu items that are more utilitarian. You want the “overview” link under the “Tools” heading. This will take you to the Linkedin Tools overview page. On this one, get down to the “email Signature” section and hit the “Try it Now” button:



Linkedin Tools page.



When you hit the “Try it Now” button, you will be taken to the “Create Email Signature” page where you will have an opportunity to create your signature.



The LinkedIn signature setup page.

Linkedin provides several layouts that you can choose from.



Selecting the Linkedn signature layout.

Select your layout that you like. Linkedin will also backfill some of the information, like your name, headline and company. But you will need to supply some additional information like phone number, the address or your company’s website, any additional websites that you have, and your company’s address.



The Linkedin Signature template generated.

Once you have it set up the way you want, you can transfer it over to your Gmail message.


Bringing over your Linkedin Signature over to your Gmail Message


In another browser window, open our Gmail account. Here we again are using our old standby, the EPW Test Dude.



Preparing Gmail to receive the Linkedin HTML signature.

Go ahead and compose your message as you normally would:



Creating the Gmail message.

When you have your message composed, go back to the browser holding your Linkedin session and highlight the signature that you just made:



Highlighting the LinkedIn signature.

Then, copy the highlighted section:



Copying the LinkedIn Signature Object

And then paste it into the body of the message that you have finished composing in your Gmail browser window:

Pasting the LinkedIn Signature Object into the Gmail Message Pane.

Then, it just a matter of sending it off. When it arrives, it will look something like this:



What the message looks like when delivered.

You’ll notice the funny little boxes in place of the missing graphics. The graphics aren’t gone. They just aren’t being displayed. As with most email programs, the default setup is to not display graphics, so count on your recipient not initially seeing your pictures. However, by merely clicking the link “Display images below” you can make the app display them.



What the LinkedIn Signature looks like after the graphics are allowed to display.

See?



Quick, simple and easy.



However, this is by no means automated. So as I said at the top of this post, you’ll have to repeat the process for every email that you want to send out with the Linkedin profile signature. Not exactly the most heartwarming of thoughts, but it is possible to include a Linkedin profile in our outgoing email.



Kudos to Amit Agarwal at Digital Inspiration for discovering the hack.

Friday, August 8, 2008

Sales Reps on Laptops: Watch Your Six...

Watch out for phishing scams attempting to get your personal information.
Well, it was bound to happen. I finally got mine.



A few days ago, I got a security alert that the email phishers were trying some new tactics to pry information out of the unsuspecting user. One involved a ticket verification process from the airlines. The major airlines immediately went public denying that they practiced communication of this nature and if you saw anything that asked you for personal information, it didn’t come from them.



The other was FedEx. Apparently, phishers posing as FedEx tracking brokers send out emails saying that you have received a package, but because of the nature of the package, you need to supply personal information in order for them to deliver it.



As far as I can recall, correspondence with FedEx has always been unidirectional in nature. They leave a sticker on my door stating that they tried to deliver a package and if I want it, I can come down the station to pick it up. Sometimes they will attempt to deliver it again the next day at a specific time.


But they always leave a note. I have never received an email from them.



Until today.



Here are some things to look out for in this, or any other, suspected phishing email:


  1. Generic greetings. Most likely, they are sending bulk email, meaning that they can’t address you by name without tipping off everyone else on the distribution list.



  2. Suspicious or unofficial “from” address. In the header of the email, you will see the address of the sender (From), the recipient (To), where to send a reply (Reply-to), and a return path (Return-Path). If you know how to do it, the “From” address can be altered to look official. In a real correspondence, however, the domain name (that part of the address between the @ sign and the first period) should match in all addresses except for the recipient address. There is no reason an official request should be sent from info@fedex.com while the reply-to address is jimbo@yahoo.com.



  3. Empty recipient address. The “To” field is typically left blank to hide the fact that this “private” correspondence has just been sent to everybody on God’s green earth.



  4. Urgent requests to act. Typically, you’ll see notices that your account has been compromised, that the “company” is about to close out your account, or that you have won a whole bunch of money and that you need to act now. $800,000.00 USD is a whole bunch of money to most people.



  5. Suspicious looking links. This email doesn’t use links back to phishing websites. However, there is a phone number you can call. Probably goes to a phone in the phisher’s basement.



  6. Spelling and Grammatical errors. This email is littered with them. The line I really like is at the end of the email right after the piece about not copying the email: FEDEX INTL>>>LICENCE OF FEDERAL EXPRESS CORPERATION.



  7. Requests for personal information. Things like PINs, SS numbers, credit card numbers. Legitimate companies will never ask for this information via email. They may use a secured form (look for the pad lock in your browser indicating that encryption is in place) or they may ask via telephone. But they will never use email to request this type of information.

The email is included below for your entertainment. If you haven’t received on yet, rest assured that yours is in the mail… uh, I mean email.



Stay Vigilant. Good Selling.



Dear Customer!

We have been waiting for you to contact us for your Confirmed Package that
is registered with us for shipping to your residential location.We had
thought that your sender gave you our contact details.It may interest you
to know that a letter is also added to your package.However, we cannot
quote its content to you via email for privacy reasons.

We understand that the content of your package itself is a Bank Draft
worth of $800,000.00 USD, FedEx do not ship money in CASH or in CHEQUES
but Bank Drafts are shippable.The package is registered with us for
mailing by your colleague, and your colleague explained that he is from
the United States but he is here in Nigeria for a three (3)months
Surveying Project as he works with a consultant firm in Nigeria West
Africa We are sending you this email because your package is been
registered on a Special Order.

What you have to do now, is to contact our Delivery Department for
immediate dispatch of your package to your residencial address.Note that
as soon as our Delivery Team confirm your information, it will take only
one working day (24 hours) for your package to arrive it's designated
destination.For your information, the VAT & Shipping charges as well as
Insurance fees have been paid for by your colleague before your package
was registered.Note that the payment that is made on the Insurance,
Premium & Clearance Certificates, are to certify that the Bank Draft is
not a Drug Affiliated Fund (DAF) neither is it funds to sponsor Terrorism
in your country. This will help you avoid any form of query from the
Monetary Authority of your country.

However, you will have to pay the sum of £105GBP to the FedEx Delivery
Department being full payment for the Security Keeping Fee of the FedEx
company as stated in our privacy terms & condition page. Also be informed
that your colleague wished to pay for the Security Keeping fee, but we do
not accept such payment considering the facts that all items & package
that are registered with us have a time limitation and we cannot accept
payment not knowing when you will be contacting us for your package or
even responding to us.So we cannot take the risk to have accepted such
payment incase of any possible demurrage.

Kindly note that your colleague did not leave us with any further
information.We hope that you respond to us as soon as possible because if
you fail to respond until the expiry date of your package, we may refer
the package to the British Commission for Welfare as the package do not
have a return address.

Kindly contact the delivery department (FedEx Delivery Post) with the
details given below:

FedEx Online Delivery Post
Contact Person:Gary Anderson
Email:fedex.delivery1963@live.com
Tel: +234 805 8814 416

Kindly complete the below form and send it to the email address given
above.This is mandatory to reconfirm your Postal address and telephone
numbers.

FULL NAMES:
TELEPHONE:
POSTAL ADDRESS:
CITY:
STATE:
COUNTRY:

Kindly complete the above form and summit it to the delivery manager on:
fedex.delivery1963@live.com

As soon as your details are received, our delivery team will give you the
neccessary payment procedure so that you can effect the payment for the
Security Keeping Fee. As soon as they confirm your payment receipt of
£105GBP which is equivalent to $210USD , they will not hesitate to
dispatch your package as well as the attahced letter to your residence. It
usually takes 24 hours being an overnight delivery service.

Note that we were not instructed to email you, but due to the high
priority of your package we had to inform you as your sender did not leave
us with his phone number because he stated that he just arrived Nigeria
and he hasn't fix his phone yet. We indeed personally sealed your Bank
Draft and we found your email contact in the receivers column as the
recipient of the foremost package.

Ensure to contact the delivery department with the email address given
above and ensure to fill the above form as well to enable a successful
reconfirmation.

Do not reply this email because this email account is not monitored.Send
your details to:fedex.delivery1963@live.com

Yours Faithfully,
Mrs. Margaret Blaire.
FedEx Online Team Management.
All rights reserved. © 1995-2008
----------------------------------------------------------------------------------------------------------
This E-mail is only for the above addressees. It may contain confidential
or Privileged information. If you are not an addressee you must not copy,
distribute, disclose or use any of the information in it or any
attachments.
----------------------------------------------------------------------------------------------------------
FEDEX INTL>>>LICENCE OF FEDERAL EXPRESS CORPERATION.