Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

27 March 2007

Hide Your PayPal E-mail Address From Spammers And Cons

PayPal is a great way to get online payments, but adding a PayPal button on a Web site or blog invites spammers to spam you, because the example script provided by PayPal requires that your PayPal E-mail address be included in the script. Unfortunately, PayPal requires it to be a legitimate address, because they send messages to that address. Therefore, spammers scrape Web sites and blogs continuously, hunting for E-mail addresses and when they find a PayPal address, they know they've hit pay dirt. PayPal E-mail addresses are targeted for fraud (commonly termed "phishing") because the scammer knows either a credit card or bank account (or both) is attached to it.

A side note is in order here. A common deception is to pretend something is wrong with your PayPal account that requires you to log into your account to fix it. Of course, the scammer provides a link in the E-mail, but it's not to PayPal's site. It's to the scammer's Web server that shows a bogus PayPal login page, and if you type your User ID and password on that page, the scammer has what he needs to steal everything from your account. The tip off is that they send the message to "Dear PayPal Customer" or "PayPal Member" because they have no idea what your name is. I guarantee PayPal knows your name and addresses you by name (or by your company's name if you have a business/merchant account) whenever they send you E-mail messages. And PayPal doesn't show a link with a hidden link to a Web server located in Asia or South America. If it's really from PayPal, the link is to https://www.paypal.com. It's best to type the address yourself in a Web browser instead of clicking on a link in an E-mail, even if you think you should trust the link.

When I added PayPal buttons to my Web site, I encoded my E-mail address within the PayPal button scripts to hide it from Web bots, but I later found an even better way by replacing my E-mail address with my PayPal Referral ID (or Affiliate ID) instead. To find out what your PayPal Referral ID is, log into your PayPal account. After logging in, scroll down to the bottom of the Web page, where there is a Referrals link. Select this link and you'll go to the "Merchant Referral Bonus Program" page. Near the top of this page is the code for the link to "Send your personalized referral link in an email." It looks something like this:

https://www.paypal.com/us/mrb/pal=DO1RE2ME3FA4S

Everything after the pal= is your Referral ID (I put it in red font for emphasis). Copy your Referral ID and paste it into the PayPal button script for the business name's string value (instead of your E-mail address):

<input type="hidden" name="business" value="DO1RE2ME3FA4S">

Save the script on the Web page or blog and when the customer presses the PayPal button, he'll be taken to the secure PayPal site where he can make his online payment. The customer will be able to see your real PayPal E-mail address, but Web bots that scrape Web pages won't unless they follow through with the PayPal transaction, and since Web bots aren't programmed to interact with Web site pages yet, that may be a long time coming.

And while you're on the "Merchant Referral Bonus Program" page, don't forget to copy the "Add a referral logo to your website" script to put on your Web site or blog, like this:


Sign up for PayPal and start accepting credit card payments instantly.

Any new merchant (except eBay merchants) who signs up using your referral link will make you eligible for 0.5% of that merchant's revenues for the first 12 months.

25 March 2007

Beware Of Fake Blogger.com Blogs

A security vendor, Fortinet, has discovered fake Blogger.com blogs which contain script-iniated malware or redirect the visitor to phishing sites. Google (the owner of Blogger.com) has verified this and stated to CNET, "These are not legitimate blogs that were compromised. They appear to be deliberately set up to promote phishing, which is against our terms of service. We are investigating, and blogs found to include malicious code or promote phishing will be deleted." Fortinet asserts that it's impossible for visitors to detect the danger from these hundreds of fake blogs, which look like legitimate blogs dedicated to a large range of interests, including Star Wars, auto hobbyists, school, furniture, Christmas, and girlfriends.

How can you avoid being taken for a ride when visiting Blogger.com blogs? You can turn off JavaScripts in your Web browser. If you're using Internet Explorer, this is "all or nothing" in that all Web sites visited will either be denied or allowed to run JavaScripts. Since most Web sites these days can't function without JavaScripts, your Web surfing will be decidedly boring or even unworkable until you manually turn on JavaScripts temporarily for Web sites you deem safe. And then you have to remember to turn JavaScripts off again when leaving the safe Web site.

I found that a better way to handle this is to use the free, award-winning Firefox Web browser and NoScript add-in, which denies all scripting (including JavaScript and any other executable script) until you manually allow scripting for each domain or allow scripting globally (which is not recommended). This can be per domain, so if you're visiting a Web site that uses scripts from multiple domains, you can pick and choose which ones, if any, to allow. If you don't already have Firefox installed, you can download it from the Firefox (with Google Toolbar) button in the sidebar on the right of this blog, or you can download it directly from Mozilla.com (without Google's Toolbar).

10 March 2007

Keep Your Web Browsing Habits Private

Did you know that the search engines keep track of your search history via cookies and their massive databases? The search engines collect and store information on your searches and attach them to your IP address, and if you're logged into one of their services, this information is also attached to your online identity. To avoid this tracking of your Web surfing, read Preston Gralla's article, "Seven ways to keep your search history private."

Also beware if you have installed Internet Explorer 7. If you turn on the "phishing filter" tool, the URL's you visit will be sent to Microsoft. According to IE7's help:

"When you use Phishing Filter to check websites automatically or manually, the address of the website you are visiting will be sent to Microsoft, together with some standard information from your computer such as your computer's IP address, browser type, and Phishing Filter version number. To help protect your privacy, the address information sent to Microsoft is encrypted using SSL and limited to the domain and path of the website you are visiting. Other information that might be associated with the web address, such as search terms, information you entered in forms, or cookies, will not be sent."

Is This A Scam?

When something sounds too good to be true, it usually is. Less than 3 1/2 hours after receiving my first ever payment through PayPal, I received a message through that same E-mail address from what appears to be a phishing scheme. It's probably just a coincidence that this message was sent so soon after doing business with one of the sponsors of this blog, because my PayPal E-mail address, while very new, is also embedded in Web pages for a PayPal button on a Web site that has had more than 3,400 visitors in the week since I placed the button on those Web pages. Any one of those visitors (which includes bots) could have harvested my PayPal E-mail address.


From: WaMu [customer@email-wamu.com]
Sent: Thu 3/8/2007 10:51 PM
Subj: Washington Mutual OnlineSM $20 Reward Survey.

Dear Valued Customer,

CONGRATULATIONS !!!

You have been chosen by the Washington Mutual online department to take part in our quick and easy 5 question survey. In return we will credit $20 to your account - Just for your time!

Helping us better understand how our customers feel benefits everyone. With the information collected we can decide to direct a number of changes to improve and expand our online service.
The information you provide us is all non-sensitive and anonymous - No part of it is handed down to any third party groups.
It will be stored in our secure database for maximum of 3 days while we process the results of this nationwide survey.

We kindly ask you to spare two minutes of your time in taking part with this unique offer!

To Continue click on the link below:

http://www.wamu.com/secure/online.wamu.com/IdentityManagement/index.html?Washington-Mutual-survey

Many Thanks and Kind Regards - Washington Mutual Bank Customer Department

A few notes are in order:

1. The domain, email-wamu.com, supposedly their customer service address, doesn't exist.

2. I'm not a Washington Mutual bank customer, nor have I ever been one.

3. The time sent precedes the time received by more than six hours (Recv: Fri 3/9/2007 5:04 AM PST), which means their system clock is either way off or else they initiated the E-mail in the time zone that includes Guam and the eastern-most parts of Asia and Australia.

4. The clickable link in the E-mail (I removed this when I pasted it into this blog post) actually contains the following URL:

http://72.18.74.130/wamu20/online.wamu.com/IdentityManagement

While it appears that the domain is WaMu.com (Washington Mutual, a legitimate bank), that's not where the browser will open the Web page, because the IP address is used for the URL. Therefore, the browser won't use the DNS server to find the current IP address of WaMu.com. It will open the default Web page in the wamu20/online.wamu.com/IdentityManagement directory on the Web server at the 72.18.74.130 IP address. That IP address belongs to TexLink Communications (TexLink.com), which is a Texas communications carrier for small and medium businesses. No doubt the scammers have an account on TexLink's Web server.

This is one of those times when we receive the warning, "Don't click on the links in an E-mail from someone you don't know!" and we should heed that warning.

17 February 2007

Scam Alert: Drive-By Pharming

Symantec's security expert, Zulfikar Ramzan, in conjunction with two professors, Sid Stamm and Markus Jakobsson, at the Indiana University School of Informatics, has produced a proof-of-concept JavaScript Web application that, if disseminated in the wild, would mean that one only need visit a malicious Web page to be attacked and have account User ID's and passwords swiped. No malware is installed, so the user wouldn't even be aware that an attack had occurred. This special method of attack is called "drive-by pharming," and you need to know about it.

The attack is aimed at broadband users whose Internet connection is routed through a router before connecting to the user's computer. The malicious Web application changes the DNS (Domain Name Service) server setting for the router (which requires the router's password -- and half the time people don't change the default password!), so that when the user types in the URL for a bank, the router requests the IP address of the desired URL from the attacker's DNS server, not the DNS server it's supposed to get the address from. Of course, the attacker's DNS server has been set up to return the wrong IP addresses for certain banking and credit card institutions' Web sites, which just so happen to be the IP addresses for the attacker's bogus Web sites that look just like the real thing. The user types in his User ID and password at the bogus Web site and . . . bingo! The attacker has all he needs to transfer money out of the real bank account.

It's easy enough to protect yourself from this scam by changing the default password on your router, so that no one can change its settings without your knowledge. Here is a list of the most common routers and links to the manufacturers' Web sites to find out how to change your router's password.
For more information about this scam, including a short video explaining it in more detail, please follow this link.

08 February 2007

Security At Public Wi-Fi Hot Spots

You're at an airport waiting for a connecting flight with an hour to kill before it arrives. You see a public Wi-Fi hot spot and decide to fire up your laptop. Why not? It's a free connection to the Internet. Right?

Wait! Public Wi-Fi hot spots are an invitation to "come hack me"! Public Wi-Fi hot spots are becoming more and more commonplace in airports, hotels, restaurants, and even public libraries. However, while public Wi-Fi hot spots are convenient, they are also unencrypted, unsecured networks waiting for hackers to come join the party. If you haven't taken steps to secure your laptop from intruders, your User ID's, passwords, and bank account numbers you transmit through that unsecured network -- and any other data on your hard drive -- could be at risk when you connect to those public networks. Read Preston Gralla's article, "How to protect yourself at wireless hot spots," to learn what steps to take to put up the barricades that hackers can't peek through.