SUBSCRIBER SERVICES: Manage Preferences | Unsubscribe | Help
This is a free service provided by the Federal Trade
Commission.
|
The purpose of this blog is to help small-medium businesses (SMB's) deal effectively with their unique cyber security needs. With over 15 years experience in IT and cyber security I will show SMB's how they can leverage their limited resources to develop effective cyber defenses to the most common threats using information security best practices and no/low cost tools.
LinkedIn: http://www.linkedin.com/in/ecissorsky/
Twitter: @ecissorsky
Monday, April 7, 2014
2014-04-07 FTC Scam Alert: Fake IRS Collectors
2014-04-07 Link of the Day: Data Breach Today
Stay abreast of the latest data breach news, what you can do to prevent them and how to handle a breach at your organization.
Data Breach Today
Data Breach Today
Any/all products/services are provided for informational purposes only. The author does not endorse any single product.
Use these products/services at your own risk.
Sunday, April 6, 2014
How To Respond To A Data Breach
From Network World:
How To Respond To A Data Breach
Here's a summary of the key points:
How To Respond To A Data Breach
Here's a summary of the key points:
- Establish a response team
- Train employees on their roles and responsibilities
- Prepare reports and submit them to the appropriate parties
- Assess the extent of the breach
- Offer assistance to affected individuals
- Perform a post mortem
2014-04-07 Email Scam of the Day #2
This one came with a Word attachment titled "WESTERN_UNION_WINNING_IDENTIFICATION_LETTER.doc" with a file size of 977kb. Notice the different email addresses in the return-path/from and reply-to header fields.
==== Begin Scam Email =====
===== Begin Scam Email Header Info =====
Return-path: <unionlo65@gmail.com>
Received: from omp1012.access.mail.bf1.yahoo.com ([unknown] [66.196.81.136])
by vms172089.mailsrvcs.net
(Sun Java(tm) System Messaging Server 7u2-7.02 32bit (built Apr 16 2009))
with ESMTP id <0N3M00J52615R720@vms172089.mailsrvcs.net> for
<recipient_address_omitted>; Sun, 06 Apr 2014 09:39:07 -0500 (CDT)
Received: (qmail 43263 invoked by uid 1000); Sun, 06 Apr 2014 14:39:05 +0000
Received: (qmail 52426 invoked by uid 60001); Sun, 06 Apr 2014 14:39:03 +0000
Received: from [41.150.143.170] by web5706.biz.mail.ne1.yahoo.com via HTTP;
Sun, 06 Apr 2014 07:39:03 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s1024;
t=1396795143; bh=kpQrbCrXyq3FnLKr2y0DrW4WT4zHjn7VpJR6u1tztSA=;
h=X-YMail-OSG:Received:X-Rocket-MIMEInfo:X-RocketYMMF:X-Mailer:References:Message-ID:Date:From:Reply-To:Subject:To:In-Reply-To:MIME-Version:Content-Type;
b=nNJWG3H72vLHM+zZgl/an2Md+Zi7d9WatwQP9KWGF+xjCkufm/K/5uq6/QdBneWBWaFVhfU1sBGHHFDUtNFhN+rmEEa48Nv9Et9h6tLJ4hws0VB2DQQI6oQX4FERHPCYID++DuxzOOdN9c77VioFmfYtXOiuoNKgCAXADSKBAXk=
Date: Sun, 06 Apr 2014 07:39:03 -0700 (PDT)
From: Western Union Lottery <unionlo65@gmail.com>
Subject: Congratulations! You have won
In-reply-to: <1396791543.64860.YahooMailNeo@web5704.biz.mail.ne1.yahoo.com>
X-Originating-IP: [66.196.81.136]
To: undisclosed recipients: ;
Reply-to: Western Union Lottery <mrfredrichard2013@yahoo.co.za>
Message-id: <1396795143.8634.YahooMailNeo@web5706.biz.mail.ne1.yahoo.com>
MIME-version: 1.0
X-Mailer: YahooMailWebService/0.8.182.648
Content-type: multipart/mixed; boundary="Boundary_(ID_qVeOTNi3bBw9jDX9SE/nyA)"
X-YMail-OSG: L6fAxeoVM1kMOjyFKDaNiG0ac_GNCoSe69lZI162yylvSxT
dRnWJlb0QWbbuKHywtYD6RIR_Qv1PDqddiazG1P0UVuX3FFsXUD8.j8KMstz
O_DetDO2aXCB98UsCwRFpe66Qq1qGkp4gZBn2wwpneP2UMTkkdz3jd_NU0At
hQAn42sCJmpDSngBubsjV_czPqoKTvAEqCoOfoWAugaikH5B.i7DqKGkm2U4
BvQmGrbgKe_svsW25fAhszc0p1_LcR9vMoUXIRuG0f9fW3Yp6pjHvsBHtHKT
uOFY5UkWxSRZVVmOQw0OVg.Z2AHejFkLU8Trf6V7oX9PeMXES3AFb.yjn2Yc
GWwLpju8yy1pyRhBGRsct9iXY9D1x_NMvw0_WspZvC2hdoclFJrKjZmKpWKH
5rDq.pfR5eS8rE2qNBzJAn7kATuGC8GIpgU4ND8fILGDXjEPEP24T4ibBfzm
55TJsbtODCMmNka5RipTfpYsLHgUqcPkSDJn5bweyii1dM79loMMYJWnmE7q
KJcef77JGkswfyu8utbjuPXm9Ed9pDg8wVij6sqqkSQQHDZj3A0PgX.El
X-Rocket-MIMEInfo:
002.001,CgpPcGVuIFlvdXIgQXR0YWNobWVudCBGb3IgTW9yZSBEZXRhaWxzIAEwAQEBAQ--
X-RocketYMMF: webzol
References: <1396791310.83680.YahooMailNeo@web5706.biz.mail.ne1.yahoo.com>
<1396791418.12776.YahooMailNeo@web5703.biz.mail.ne1.yahoo.com>
<1396791543.64860.YahooMailNeo@web5704.biz.mail.ne1.yahoo.com>
Original-recipient: rfc822;<recipient_address_omitted>
==== Begin Scam Email =====
Open Your Attachment For More Details
===== Begin Scam Email Header Info =====
Return-path: <unionlo65@gmail.com>
Received: from omp1012.access.mail.bf1.yahoo.com ([unknown] [66.196.81.136])
by vms172089.mailsrvcs.net
(Sun Java(tm) System Messaging Server 7u2-7.02 32bit (built Apr 16 2009))
with ESMTP id <0N3M00J52615R720@vms172089.mailsrvcs.net> for
<recipient_address_omitted>; Sun, 06 Apr 2014 09:39:07 -0500 (CDT)
Received: (qmail 43263 invoked by uid 1000); Sun, 06 Apr 2014 14:39:05 +0000
Received: (qmail 52426 invoked by uid 60001); Sun, 06 Apr 2014 14:39:03 +0000
Received: from [41.150.143.170] by web5706.biz.mail.ne1.yahoo.com via HTTP;
Sun, 06 Apr 2014 07:39:03 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s1024;
t=1396795143; bh=kpQrbCrXyq3FnLKr2y0DrW4WT4zHjn7VpJR6u1tztSA=;
h=X-YMail-OSG:Received:X-Rocket-MIMEInfo:X-RocketYMMF:X-Mailer:References:Message-ID:Date:From:Reply-To:Subject:To:In-Reply-To:MIME-Version:Content-Type;
b=nNJWG3H72vLHM+zZgl/an2Md+Zi7d9WatwQP9KWGF+xjCkufm/K/5uq6/QdBneWBWaFVhfU1sBGHHFDUtNFhN+rmEEa48Nv9Et9h6tLJ4hws0VB2DQQI6oQX4FERHPCYID++DuxzOOdN9c77VioFmfYtXOiuoNKgCAXADSKBAXk=
Date: Sun, 06 Apr 2014 07:39:03 -0700 (PDT)
From: Western Union Lottery <unionlo65@gmail.com>
Subject: Congratulations! You have won
In-reply-to: <1396791543.64860.YahooMailNeo@web5704.biz.mail.ne1.yahoo.com>
X-Originating-IP: [66.196.81.136]
To: undisclosed recipients: ;
Reply-to: Western Union Lottery <mrfredrichard2013@yahoo.co.za>
Message-id: <1396795143.8634.YahooMailNeo@web5706.biz.mail.ne1.yahoo.com>
MIME-version: 1.0
X-Mailer: YahooMailWebService/0.8.182.648
Content-type: multipart/mixed; boundary="Boundary_(ID_qVeOTNi3bBw9jDX9SE/nyA)"
X-YMail-OSG: L6fAxeoVM1kMOjyFKDaNiG0ac_GNCoSe69lZI162yylvSxT
dRnWJlb0QWbbuKHywtYD6RIR_Qv1PDqddiazG1P0UVuX3FFsXUD8.j8KMstz
O_DetDO2aXCB98UsCwRFpe66Qq1qGkp4gZBn2wwpneP2UMTkkdz3jd_NU0At
hQAn42sCJmpDSngBubsjV_czPqoKTvAEqCoOfoWAugaikH5B.i7DqKGkm2U4
BvQmGrbgKe_svsW25fAhszc0p1_LcR9vMoUXIRuG0f9fW3Yp6pjHvsBHtHKT
uOFY5UkWxSRZVVmOQw0OVg.Z2AHejFkLU8Trf6V7oX9PeMXES3AFb.yjn2Yc
GWwLpju8yy1pyRhBGRsct9iXY9D1x_NMvw0_WspZvC2hdoclFJrKjZmKpWKH
5rDq.pfR5eS8rE2qNBzJAn7kATuGC8GIpgU4ND8fILGDXjEPEP24T4ibBfzm
55TJsbtODCMmNka5RipTfpYsLHgUqcPkSDJn5bweyii1dM79loMMYJWnmE7q
KJcef77JGkswfyu8utbjuPXm9Ed9pDg8wVij6sqqkSQQHDZj3A0PgX.El
X-Rocket-MIMEInfo:
002.001,CgpPcGVuIFlvdXIgQXR0YWNobWVudCBGb3IgTW9yZSBEZXRhaWxzIAEwAQEBAQ--
X-RocketYMMF: webzol
References: <1396791310.83680.YahooMailNeo@web5706.biz.mail.ne1.yahoo.com>
<1396791418.12776.YahooMailNeo@web5703.biz.mail.ne1.yahoo.com>
<1396791543.64860.YahooMailNeo@web5704.biz.mail.ne1.yahoo.com>
Original-recipient: rfc822;<recipient_address_omitted>
2014-04-07 Email Scam of the Day #1
When you receive an email from yourself that you didn't send it's a scam. Take note of the email address in the body of the message and the one given in the header return-path section.
===== Begin Scam Email =====
===== Begin Scam Email Header Info =====
Return-path: <highboys39@google.com>
Received: from google.com ([unknown] [199.192.224.137])
by vms172095.mailsrvcs.net
(Sun Java(tm) System Messaging Server 7u2-7.02 32bit (built Apr 16 2009))
with ESMTP id <0N3L00GI4905FG40@vms172095.mailsrvcs.net> for
<recipient_address_omitted>; Sat, 05 Apr 2014 21:46:40 -0500 (CDT)
Received: from 199.192.224.137(helo=verizon.net) by verizon.net with esmtpa
(Exim 4.69) (envelope-from )
id 1MM5GY-2819fc-B3 for <recipient_address_omitted>; Sat,
05 Apr 2014 21:47:13 -0500
Date: Sat, 05 Apr 2014 21:47:13 -0500
From: <recipient_address_omitted>
Subject: Re: CV 06
X-Originating-IP: [199.192.224.137]
To: <recipient_address_omitted>
Message-id: <1758031156.5MVX98NX867117@verizon.net>
MIME-version: 1.0
X-Mailer: zmqe_04
Content-type: text/plain; CHARSET=US-ASCII
Content-transfer-encoding: 7BIT
Original-recipient: rfc822;<recipient_address_omitted>
===== Begin Scam Email =====
If you have excellent administrative skills, working
knowledge of Microsoft Office, a keen eye for detail, well-versed in the use of
social networking sites such as Twitter and Facebook, are organized, present
yourself well and are a team player with the ability to work independently, are
reliable and punctual and can understand and execute instructions are
determined to work hard and succeed - we need you.
===== Begin Scam Email Header Info =====
Return-path: <highboys39@google.com>
Received: from google.com ([unknown] [199.192.224.137])
by vms172095.mailsrvcs.net
(Sun Java(tm) System Messaging Server 7u2-7.02 32bit (built Apr 16 2009))
with ESMTP id <0N3L00GI4905FG40@vms172095.mailsrvcs.net> for
<recipient_address_omitted>; Sat, 05 Apr 2014 21:46:40 -0500 (CDT)
Received: from 199.192.224.137(helo=verizon.net) by verizon.net with esmtpa
(Exim 4.69) (envelope-from )
id 1MM5GY-2819fc-B3 for <recipient_address_omitted>; Sat,
05 Apr 2014 21:47:13 -0500
Date: Sat, 05 Apr 2014 21:47:13 -0500
From: <recipient_address_omitted>
Subject: Re: CV 06
X-Originating-IP: [199.192.224.137]
To: <recipient_address_omitted>
Message-id: <1758031156.5MVX98NX867117@verizon.net>
MIME-version: 1.0
X-Mailer: zmqe_04
Content-type: text/plain; CHARSET=US-ASCII
Content-transfer-encoding: 7BIT
Original-recipient: rfc822;<recipient_address_omitted>
Tuesday, April 1, 2014
2014-04-01 Another FTC Scam Alert
SUBSCRIBER SERVICES: Manage Preferences | Unsubscribe | Help
This is a free service provided by the Federal Trade Commission.
|
U.S. notified 3,000 companies in 2013 about cyberattacks
If your organization has suffered a cyber attack fear not, you're not alone. From the Washington Post:
U.S. notified 3,000 companies in 2013 about cyberattacks
U.S. notified 3,000 companies in 2013 about cyberattacks
How much will a cyber incident cost your organization?
Booz Allen Hamilton in conjunction with The Economist Intelligence Unit has just released a tool to calculate the damage of a cyber incident. Using information you provide the tool, Cybertab, calculates the cost freely and, most importantly, anonymously.
Designed for information security professionals and executives the cost of a potential incident can be determined by using it in Planning Mode. If your organization has already experienced an incident, Reporting Mode will help you determine the loss suffered by the attack.
Cybertab - Tallying the bill from cybercrime
Any/all products/services are provided for informational purposes only. The author does not endorse any single product.
Use these products/services at your own risk.
2014-04-01 FTC Scam Alert
SUBSCRIBER SERVICES:
Manage Preferences | Unsubscribe | Help
This is a free
service provided by the Federal Trade Commission.
|
2014-04-01 Nigerian 419 of the day
It wouldn't be April Fools Day if I didn't get a scam email.
===== Begin Scam Email =====
--
mike2014b@mail.bg
===== Begin Scam Header Info =====
Return-path: <info@acicsa.com.py>
Received: from mail.intercoop.com.py ([unknown] [201.217.50.174])
by vms172057.mailsrvcs.net
(Sun Java(tm) System Messaging Server 7u2-7.02 32bit (built Apr 16 2009))
with ESMTP id <0N3C00KFHX7A7240@vms172057.mailsrvcs.net> for
<recipient_address_omitted>; Tue, 01 Apr 2014 09:50:00 -0500 (CDT)
Received: (qmail 11383 invoked by uid 520); Tue, 01 Apr 2014 11:38:19 -0300
Received: from 192.168.0.4 by serv-ftp
(envelope-from <info@acicsa.com.py>, uid 519) with qmail-scanner-1.25-st-qms
(clamdscan: 0.96/10755. spamassassin: 3.1.9. perlscan: 1.25-st-qms. Clear:RC:0
(192.168.0.4):SA:0(-1.4/2.5):. Processed in 0.281442 secs); Tue,
01 Apr 2014 14:38:19 +0000
Received: from unknown (HELO webmail.intercoop.com.py)
(info@acicsa.com.py@192.168.0.4) by mail.intercoop.com.py with SMTP; Tue,
01 Apr 2014 11:38:17 -0300
Received: from 41.58.31.133
(SquirrelMail authenticated user info@acicsa.com.py) by
webmail.intercoop.com.py with HTTP; Tue, 01 Apr 2014 03:40:05 -0300 (PYST)
Date: Tue, 01 Apr 2014 03:40:05 -0300 (PYST)
From: "MIKE MORGANS" <info@acicsa.com.py>
Subject: Dear Sir/Madam,
X-Originating-IP: [201.217.50.174]
Reply-to: lucianakimus@oi.com.br
Message-id: <e9913ff956316ab09891a17b6b297486.squirrel@webmail.intercoop.com.py>
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII
Content-transfer-encoding: 7BIT
Importance: Normal
X-Priority: 3 (Normal)
X-Antivirus-MYDOMAIN-Mail-From: info@acicsa.com.py via serv-ftp
X-Antivirus-MYDOMAIN: 1.25-st-qms (Clear:RC:0(192.168.0.4):SA:0(-1.4/2.5):.
Processed in 0.281442 secs Process 11343)
User-Agent: SquirrelMail/1.4.15
Original-recipient: rfc822;<recipient_address_omitted>
X-Spam-Status: No, hits=-1.4 required=2.5
===== Begin Scam Email =====
--
Dear Sir/Madam,
Greetings to you and your loved ones.
I am The Acting Chief Financial Officer of Ulster Bank
located in Belfast, Northern Ireland.
I solicit your audience to discuss some financial matters
with you, if you would be well disposed to giving me a piece of your time.
On receipt of your response in affirmation of your
willingness to work with me, I will divulge details for your perusal
Kindly send to me your phone, fax numbers and addresses
to enable my further discussion.
Best regards,
Mike Morgan
REPLY TO
mike2014b@mail.bg
===== Begin Scam Header Info =====
Return-path: <info@acicsa.com.py>
Received: from mail.intercoop.com.py ([unknown] [201.217.50.174])
by vms172057.mailsrvcs.net
(Sun Java(tm) System Messaging Server 7u2-7.02 32bit (built Apr 16 2009))
with ESMTP id <0N3C00KFHX7A7240@vms172057.mailsrvcs.net> for
<recipient_address_omitted>; Tue, 01 Apr 2014 09:50:00 -0500 (CDT)
Received: (qmail 11383 invoked by uid 520); Tue, 01 Apr 2014 11:38:19 -0300
Received: from 192.168.0.4 by serv-ftp
(envelope-from <info@acicsa.com.py>, uid 519) with qmail-scanner-1.25-st-qms
(clamdscan: 0.96/10755. spamassassin: 3.1.9. perlscan: 1.25-st-qms. Clear:RC:0
(192.168.0.4):SA:0(-1.4/2.5):. Processed in 0.281442 secs); Tue,
01 Apr 2014 14:38:19 +0000
Received: from unknown (HELO webmail.intercoop.com.py)
(info@acicsa.com.py@192.168.0.4) by mail.intercoop.com.py with SMTP; Tue,
01 Apr 2014 11:38:17 -0300
Received: from 41.58.31.133
(SquirrelMail authenticated user info@acicsa.com.py) by
webmail.intercoop.com.py with HTTP; Tue, 01 Apr 2014 03:40:05 -0300 (PYST)
Date: Tue, 01 Apr 2014 03:40:05 -0300 (PYST)
From: "MIKE MORGANS" <info@acicsa.com.py>
Subject: Dear Sir/Madam,
X-Originating-IP: [201.217.50.174]
Reply-to: lucianakimus@oi.com.br
Message-id: <e9913ff956316ab09891a17b6b297486.squirrel@webmail.intercoop.com.py>
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII
Content-transfer-encoding: 7BIT
Importance: Normal
X-Priority: 3 (Normal)
X-Antivirus-MYDOMAIN-Mail-From: info@acicsa.com.py via serv-ftp
X-Antivirus-MYDOMAIN: 1.25-st-qms (Clear:RC:0(192.168.0.4):SA:0(-1.4/2.5):.
Processed in 0.281442 secs Process 11343)
User-Agent: SquirrelMail/1.4.15
Original-recipient: rfc822;<recipient_address_omitted>
X-Spam-Status: No, hits=-1.4 required=2.5
Cloud Wars
Who says competition isn't good for the consumer? Cloud service providers are making significant price cuts to their services. If your organization is considering using a cloud service this is good news.
From Network World:
Microsoft slashes Azure prices, introduces new basic tier
From Network World:
Microsoft slashes Azure prices, introduces new basic tier
Any/all products/services are provided for informational purposes only. The author does not endorse any single product.
Use these products/services at your own risk.
2014-04-01 Link of the Day: CheckPoint Top 10 SMB Security Best Practices
Since it's April Fools Day I was going to have some fun with todays LOTD. A good old fashioned Rick-Rolling or All Your Base Are Belong To Us redirection would be a good way to have some fun today. But after thinking about it I decided cybersecurity is a serious subject and to just stick to business.
After all, the hackers aren't taking off today. I doubt your organization would care for any April Fools jokes they might play on it.
CheckPoint Top 10 SMB Security Best Practices (requires registration)
After all, the hackers aren't taking off today. I doubt your organization would care for any April Fools jokes they might play on it.
CheckPoint Top 10 SMB Security Best Practices (requires registration)
Any/all products/services are provided for informational purposes only. The author does not endorse any single product.
Use these products/services at your own risk.
Monday, March 31, 2014
2014-03-31 - Another FTC Scam Alert
SUBSCRIBER SERVICES: Manage Preferences | Unsubscribe | Help
This is a free service provided by the Federal Trade Commission.
|
2013-03-31 - FTC Scam Alert
SUBSCRIBER SERVICES: Manage Preferences | Unsubscribe | Help
This is a free service provided by the Federal Trade Commission.
|
HHS Data Breach Wall of Shame
Here's a website you never want to see your SMB listed on.
Dept. Health & Human Services: Data Breaches Affecting 500 or More Individuals
Dept. Health & Human Services: Data Breaches Affecting 500 or More Individuals
2014-03-31 Link of the Day: SANS Mobile Device Checklist
SMB's rely on their mobile devices to stay connected. This reliance creates a new attack vector for cybercriminals. The SANS Institute has developed a checklist to help mitigate the growing risks associated with mobile device use.
SANS Mobile Device Checklist
Special thanks to Ed Skoudis (@edskoudis) for this mornings tweet on this.
SANS Mobile Device Checklist
Special thanks to Ed Skoudis (@edskoudis) for this mornings tweet on this.
Any/all products/services are provided for informational purposes only. The author does not endorse any single product.
Use these products/services at your own risk.
Wednesday, March 26, 2014
2014-03-26 Link of the Day: Protecting Your Mid-Size Business from Today’s Security Threats
This free eBook from Network World and HP explains the methods used by attackers and why your SMB should take cyber security seriously.
Protecting Your Mid-Size Business from Today’s Security Threats
Protecting Your Mid-Size Business from Today’s Security Threats
Any/all products/services are provided for informational purposes only. The author does not endorse any single product.
Use these products/services at your own risk.
Tuesday, March 25, 2014
Employee with Minnesota-based insurer risks data of 38K members
From SC Magazine:
Employee with Minnesota-based insurer risks data of 38K members
Repeat after me:
I WILL NEVER ALLOW EMPLOYEES TO TAKE HOME PERSONALLY IDENTIFIABLE INFORMATION!!!
I WILL NEVER ALLOW EMPLOYEES TO TAKE HOME PERSONALLY IDENTIFIABLE INFORMATION!!!
I WILL NEVER ALLOW EMPLOYEES TO TAKE HOME PERSONALLY IDENTIFIABLE INFORMATION!!!
Employee with Minnesota-based insurer risks data of 38K members
Repeat after me:
I WILL NEVER ALLOW EMPLOYEES TO TAKE HOME PERSONALLY IDENTIFIABLE INFORMATION!!!
I WILL NEVER ALLOW EMPLOYEES TO TAKE HOME PERSONALLY IDENTIFIABLE INFORMATION!!!
I WILL NEVER ALLOW EMPLOYEES TO TAKE HOME PERSONALLY IDENTIFIABLE INFORMATION!!!
Microsoft releases Fix It tool for Word 2010 vulnerability
Microsoft has released a tool to prevent .rtf formatted documents from opening in Word. This appears to be a stop gap measure until an official update is released.
Microsoft Security Advisory (2953095) - Vulnerability in Microsoft Word Could Allow Remote Code Execution
MS Fix It solution
Microsoft Security Advisory (2953095) - Vulnerability in Microsoft Word Could Allow Remote Code Execution
MS Fix It solution
Microsoft Word 2010 0-day vulnerability being actively exploited
This goes hand in hand with my earlier post, 2014-03-25 Phishing Scam Alert, which included a text file (.txt) attachment. Attackers can easily hide the correct file extension to make things appear to be a different file type.
By default Microsoft turns on "Hide extensions for known file types". If this is enabled the true file extension is not displayed. In other words, "Malicious File Attachment.txt.rtf" will be displayed to the user as "Malicious File Attachment.txt". However when the file will open in Word because it is a Rich Text Format (.rtf) file.
Now for the alert which is being actively exploited in the wild:
Microsoft Releases Security Advisory
By default Microsoft turns on "Hide extensions for known file types". If this is enabled the true file extension is not displayed. In other words, "Malicious File Attachment.txt.rtf" will be displayed to the user as "Malicious File Attachment.txt". However when the file will open in Word because it is a Rich Text Format (.rtf) file.
Now for the alert which is being actively exploited in the wild:
Microsoft Releases Security Advisory
2014-03-25 Phishing Scam Alert
Wow, I'm entitled to compensation from the UN. Who would've guessed? This one came with an attachment titled "UN COMPENSATION FOR VICTIMS.txt".
===== Begin Phishing Email =====
Subject: RE: REPLY TO YOUR QUESTIONS
===== Begin Header Info =====
Return-path: <infoweb747@yahoo.co.nz>
Received: from mindseye-marketing.com ([unknown] [217.147.94.54])
by vms172059.mailsrvcs.net
(Sun Java(tm) System Messaging Server 7u2-7.02 32bit (built Apr 16 2009))
with ESMTP id <0N2Y00JKGJ35HH10@vms172059.mailsrvcs.net> for
<recipient_address_omitted>; Mon, 24 Mar 2014 15:18:41 -0500 (CDT)
Received: from User (unknown [41.138.188.229]) by mindseye-marketing.com
(Postfix) with ESMTPA id 9BCF088B9AB; Mon, 24 Mar 2014 20:28:45 +0000 (GMT)
Date: Mon, 24 Mar 2014 21:18:39 +0100
From: "MIKE"<infoweb747@yahoo.co.nz>
Subject: RE: REPLY TO YOUR QUESTIONS
X-Originating-IP: [217.147.94.54]
Reply-to: <frankbia@qq.com>
Message-id: <0N2Y00JKJJ35HH10@vms172059.mailsrvcs.net>
MIME-version: 1.0
X-MIMEOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
Content-type: multipart/mixed; boundary="Boundary_(ID_EmuTymv+ioSYNqS00skCvA)"
X-Priority: 3
X-MSMail-priority: Normal
Original-recipient: rfc822;<recipient_address_omitted>
===== Begin Phishing Email =====
Subject: RE: REPLY TO YOUR QUESTIONS
KINDLY GO THROUGH THE ATTACHMENT TO SEE THE CATEGORY YOU
FALL INTO AS WE WANT YOU TO GET ALL YOU HAVE SPENT BACK NOW.
REGARDS,
MIKE
===== Begin Header Info =====
Return-path: <infoweb747@yahoo.co.nz>
Received: from mindseye-marketing.com ([unknown] [217.147.94.54])
by vms172059.mailsrvcs.net
(Sun Java(tm) System Messaging Server 7u2-7.02 32bit (built Apr 16 2009))
with ESMTP id <0N2Y00JKGJ35HH10@vms172059.mailsrvcs.net> for
<recipient_address_omitted>; Mon, 24 Mar 2014 15:18:41 -0500 (CDT)
Received: from User (unknown [41.138.188.229]) by mindseye-marketing.com
(Postfix) with ESMTPA id 9BCF088B9AB; Mon, 24 Mar 2014 20:28:45 +0000 (GMT)
Date: Mon, 24 Mar 2014 21:18:39 +0100
From: "MIKE"<infoweb747@yahoo.co.nz>
Subject: RE: REPLY TO YOUR QUESTIONS
X-Originating-IP: [217.147.94.54]
Reply-to: <frankbia@qq.com>
Message-id: <0N2Y00JKJJ35HH10@vms172059.mailsrvcs.net>
MIME-version: 1.0
X-MIMEOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
Content-type: multipart/mixed; boundary="Boundary_(ID_EmuTymv+ioSYNqS00skCvA)"
X-Priority: 3
X-MSMail-priority: Normal
Original-recipient: rfc822;<recipient_address_omitted>
Monday, March 24, 2014
2014-03-24 Link of the Day: Introduction to Computer Security - Information Security Lesson #1 of 12
Here is the first video in a series by Dr. Daniel Soper that will benefit technical and non-technical users alike.
Introduction to Computer Security - Information Security Lesson #1 of 12
Dr. Soper does a very good job of explaining the basics of cyber security in an easily understandable manner. Addressing topics such as threats posed by hardware failure, identifying and classifying data and assets, threats vs vulnerabilities, the CIA triad and so on. If you're concerned about security in your SMB please invest some time in this video series.
Introduction to Computer Security - Information Security Lesson #1 of 12
Dr. Soper does a very good job of explaining the basics of cyber security in an easily understandable manner. Addressing topics such as threats posed by hardware failure, identifying and classifying data and assets, threats vs vulnerabilities, the CIA triad and so on. If you're concerned about security in your SMB please invest some time in this video series.
Saturday, March 22, 2014
Ex-Microsoft employee arrested, accused of stealing Windows RT, product activation secrets
From Network World:
Ex-Microsoft employee arrested, accused of stealing Windows RT, product activation secrets
With the epic failure of Windows 8.x Microsoft should be promoting this guy. Considering rumors have been circling that they are going to make Windows 8.1 free for everyone this guy was helping them out.
Disclaimer: I in no way, shape or form advocate software piracy. However considering how poorly the adoption rate for Windows 8.x has been giving it away may be the only way Microsoft can get people and organizations to use it.
Ex-Microsoft employee arrested, accused of stealing Windows RT, product activation secrets
With the epic failure of Windows 8.x Microsoft should be promoting this guy. Considering rumors have been circling that they are going to make Windows 8.1 free for everyone this guy was helping them out.
Disclaimer: I in no way, shape or form advocate software piracy. However considering how poorly the adoption rate for Windows 8.x has been giving it away may be the only way Microsoft can get people and organizations to use it.
Friday, March 21, 2014
FTC Scam Alert #2
|
|
This email was sent to <recipient_address_omitted> using
GovDelivery, on behalf of: Federal Trade Commission · 600 Pennsylvania Ave.,
NW · Washington, DC 20580 · 1-877-382-4357
|
FTC Scam Alert #1
|
|
This email was sent to <recipient_address_omitted> using
GovDelivery, on behalf of: Federal Trade Commission · 600 Pennsylvania Ave.,
NW · Washington, DC 20580 · 1-877-382-4357
|
Tuesday, March 18, 2014
2014-03-18 Link of the Day: Get Cyber Safe Canada
The Canadian government has put together an excellent web site for cyber security. The site, Get Cyber Safe, offers a wealth of information on how to protect your SMB. It also has great resources for home users.
Get Cyber Safe Canada
Get Cyber Safe Guide for Small and Medium Businesses
Get Cyber Safe Canada
Get Cyber Safe Guide for Small and Medium Businesses
Monday, March 17, 2014
Latest email scam
If you receive an email from yourself that you didn't send it's a scam. This is called email spoofing. In this economy preying on the unemployed nauseates me.
===== Begin Scam Email =====
===== Begin Header Info =====
Return-path: <oftenestrr10@google.com>
Received: from bro67-1-81-56-100-130.fbx.proxad.net ([unknown] [81.56.100.130])
by vms172083.mailsrvcs.net
(Sun Java(tm) System Messaging Server 7u2-7.02 32bit (built Apr 16 2009))
with ESMTP id <0N2J00F2FKZ1E600@vms172083.mailsrvcs.net> for
<recipient_address_omitted>; Sun, 16 Mar 2014 13:35:41 -0500 (CDT)
Received: from apache by pcbiphpgpagajh.regallager.com with local (Exim 4.67)
(envelope-from <<sender_address_same_as_recipient_and_omitted>>)
id 4UV2WA-YX1UC7-8X for <recipient_address_omitted>; Sun,
16 Mar 2014 19:41:07 +0100
Date: Sun, 16 Mar 2014 19:41:07 +0100
From: <sender_address_same_as_recipient_and_omitted>
Subject: Manager position
X-Originating-IP: [81.56.100.130]
X-Sender: <sender_address_same_as_recipient_and_omitted>
To: <recipient_address_omitted>
Message-id: <5A3TKY-0PTIRR-JB@pcbiphpgpagajh.regallager.com>
MIME-version: 1.0
X-Mailer: PHP
Content-type: text/plain; CHARSET=US-ASCII
Content-transfer-encoding: 7BIT
X-Priority: 1
X-PHP-Script: pcbiphpgpagajh.anbid.com.br/sendmail.php for 81.56.100.130
Original-recipient: rfc822;<recipient_address_omitted>
===== Begin Scam Email =====
We are offering a shipping manager assistant position.
We are offering a
distant job.
The job routine will take 2-3 hours per day and requires
absolutely no investment.
You will work with big shops, suppliers, factories all
around the States.
The communication line will flow between you and your
personal manager, you will receive orders via email and phone, and our trained
manager will be with you while every step to help you to work out first orders
and answer any questions which may appear.
The starting salary is about ~2800 USD per month +
bonuses.
You will receive first salary in 30 days after you will
successfully complete your first task.
When the first working month will be over you will have a
right to receive salary every 2 weeks.
The bonuses are calculated on the very last working day
of each month, and paying out during a first week of the next month.
We will accept applications this week only!
To proceed to the next step we should register you in HR
system so we will need a small piece of your personal information.
Please fill in the fields:
Full name:
Your Contact phone number:
Your email address :
City of residence :
We need your personal information to create HR file only,
it will stay secure on the separate server till the moment it will be deleted
(which take place every 2 days), and only HR people will have access to it.
Please send your answer to my secured email Kristine@usasodexo.com I will reply you personally as soon as
possible.
Sincerely,
Kristine Dillon===== Begin Header Info =====
Return-path: <oftenestrr10@google.com>
Received: from bro67-1-81-56-100-130.fbx.proxad.net ([unknown] [81.56.100.130])
by vms172083.mailsrvcs.net
(Sun Java(tm) System Messaging Server 7u2-7.02 32bit (built Apr 16 2009))
with ESMTP id <0N2J00F2FKZ1E600@vms172083.mailsrvcs.net> for
<recipient_address_omitted>; Sun, 16 Mar 2014 13:35:41 -0500 (CDT)
Received: from apache by pcbiphpgpagajh.regallager.com with local (Exim 4.67)
(envelope-from <<sender_address_same_as_recipient_and_omitted>>)
id 4UV2WA-YX1UC7-8X for <recipient_address_omitted>; Sun,
16 Mar 2014 19:41:07 +0100
Date: Sun, 16 Mar 2014 19:41:07 +0100
From: <sender_address_same_as_recipient_and_omitted>
Subject: Manager position
X-Originating-IP: [81.56.100.130]
X-Sender: <sender_address_same_as_recipient_and_omitted>
To: <recipient_address_omitted>
Message-id: <5A3TKY-0PTIRR-JB@pcbiphpgpagajh.regallager.com>
MIME-version: 1.0
X-Mailer: PHP
Content-type: text/plain; CHARSET=US-ASCII
Content-transfer-encoding: 7BIT
X-Priority: 1
X-PHP-Script: pcbiphpgpagajh.anbid.com.br/sendmail.php for 81.56.100.130
Original-recipient: rfc822;<recipient_address_omitted>
Phishing: How many take the bait
I found this on Canada's Get Cyber Safe web site. The full site will be posted as tomorrow's LOTD but in the mean time this infographic illustrates just how successful phishing campaigns are. Click the image for the full size version.
After looking at this you should start thinking about educating your employees about how to spot and avoid phishing scams.
After looking at this you should start thinking about educating your employees about how to spot and avoid phishing scams.
2014-03-17 Link of the Day: Group Policy Inventory (GPInventory.exe)
While browsing Microsofts download section I came across this tool:
Group Policy Inventory (GPInventory.exe)
Per Microsoft - Group Policy Inventory (GPInventory.exe) allows administrators to collect Group Policy and other information from any number of computers in their network.
The Group Policy Inventory has an easy to use interface. It also offers a range of useful queries such as; a number of RSOP queries, OS info, service packs/hotfixes installed, shares on the system, startup programs (very useful for detecting malware), memory, disk space ... I'm sure security professionals and administrators will find this application to be a valuable tool.
Group Policy Inventory (GPInventory.exe)
Per Microsoft - Group Policy Inventory (GPInventory.exe) allows administrators to collect Group Policy and other information from any number of computers in their network.
The Group Policy Inventory has an easy to use interface. It also offers a range of useful queries such as; a number of RSOP queries, OS info, service packs/hotfixes installed, shares on the system, startup programs (very useful for detecting malware), memory, disk space ... I'm sure security professionals and administrators will find this application to be a valuable tool.
Any/all products/services are provided for informational purposes only. The author does not endorse any single product.
Use these products/services at your own risk.
Sunday, March 16, 2014
Sophisticated scam targeting Verizon Wireless customers
From Network World:
Sophisticated scam targeting Verizon Wireless customers
"The Better Business Bureau recently warned of a scam targeting Verizon Wireless customers that tries to trick users into giving up personal information.
According to the BBB, the scam begins when a customer gets a call that appears to come from "Technical Support" and claims to be Verizon Wireless. It is a recorded message saying you are eligible to receive a voucher for your account. You need to visit a website to claim it. The web address given contains "Verizon" and the value of the voucher. One recent version of the scam used "verizon54.com," but watch for variations, the BBB stated."
Sophisticated scam targeting Verizon Wireless customers
"The Better Business Bureau recently warned of a scam targeting Verizon Wireless customers that tries to trick users into giving up personal information.
According to the BBB, the scam begins when a customer gets a call that appears to come from "Technical Support" and claims to be Verizon Wireless. It is a recorded message saying you are eligible to receive a voucher for your account. You need to visit a website to claim it. The web address given contains "Verizon" and the value of the voucher. One recent version of the scam used "verizon54.com," but watch for variations, the BBB stated."
Cyber warrior of the future
I came across this cartoon awhile ago. It's a pretty good representation of how conflict has evolved.
Friday, March 14, 2014
Samsung - Android backdoor discovered
Just one of the many reason I prefer my iPhone. From Dark Reading and InformationWeek:
Samsung Galaxy Security Alert: Android Backdoor Discovered
Samsung Galaxy Security Alert: Android Backdoor Discovered
FTC Scam Alert #2
To receive these alerts send a subscribe email to Federal Trade Commission subscribe@subscribe.ftc.gov
|
|
This email was sent to <recipient_address_omitted> using
GovDelivery, on behalf of: Federal Trade Commission · 600 Pennsylvania Ave.,
NW · Washington, DC 20580 · 1-877-382-4357
|
Subscribe to:
Posts (Atom)

