[+] Wayc0de's Blog[+]

Tampilkan postingan dengan label Scam. Tampilkan semua postingan
Tampilkan postingan dengan label Scam. Tampilkan semua postingan

25/10/11

Beware Facebook lottery email scams!

Congratulations! You've won the Facebook lottery!
At least, that's what the following email claims.

Facebook lottery email

The email says that you can turn up in person at an address in London to claim your prize, but you will have to confirm your identity and eligibility.

If you don't want to visit London, then you can choose to pay a mere £385 to have the necessary paperwork couriered to you.
for your convenience, we can have your Facebook Claim Paper Work sent to you via our contracted Courier Service for signing and then send back to us to effect immediate release of your Winning. But note that you are to bear courier charges of this option which attracts the sum of £385 British Pound, only to be paid if you decide to settle for the Facebook Claim Paper Work to be sent to you via our contracted Courier Service. Please note that the £385 British Pound courier charges includes insurance and tax fees, as the paper work in question is highly confidential and needs to be insured for safety measures.
Hmm.. So, you've won a lottery but the company awarding you the prize won't stretch to having something couriered to you? Never mind! It's sure to be covered by your prize winnings, right?

Facebook lottery email

Although the phone number given in the email looks, to the casual observer, to go to a UK mobile phone it actually could be redirected anywhere in the world. The 0770 number is registered with British firm Cloud9, which offers international mobile services.

In short, you think you're phoning Facebook in London - but the phone could be being picked up by Fabian in Nairobi.

If you do call that number, chances are that you will be asked to share personal information and perhaps even conned into paying a fee in advance for the paperwork to be couriered to you.

Facebook lotteryIn short, it's a scam. You never entered a Facebook lottery - so why do you think you've won one? Remember - you cannot win a lottery you haven't entered.

Lottery scams are not new, but they continue to occur because there are plenty of vulnerable people at risk of handing over their personal information or giving money to scammers in advance of their promised winnings.
Read More...

18/10/11

Free coffee from Starbucks and Tim Hortons? No, it's a Facebook scam

Tim Hortons Facebook scamAs of late things have been somewhat quiet on the Facebook scam front, but today we have seen a resurgence in free voucher scams targeting both Americans and Canadians.

A little more than a day ago a scam appeared purporting to be a free gift card for the famous Canadian coffee and doughnut shop Tim Hortons.

It asks you to like the page and to share it with your Facebook friends thanking Tim Hortons (or Timmies as it's known to some Canadians) for the free coffee.

It would appear scamming Canadians was not enough for the folks behind this scam and within a day they had branched out to include Starbucks fans.

Starbucks Facebook gift card scamThe Starbucks fraud proclaims to be a give away to celebrate the 40th anniversary of the Seattle coffee giant.

It's a tried and true formula for con-artists to get your to share their scam with your friends, and then lead you to a website asking you to divulge personal information.

These scams begin with asking you for your email address with some standard legal verbiage about being 18 years old and a resident of -insert country here-. They then proceed to lead you to another form asking you to disclose sensitive personal information.

Facebook users sharing fraudUnfortunately thousands of Facebook users have been spreading the message, helping these criminals propagate their fraud. Innocent people thinking they might share a great deal with their friends are being used to social engineer those same friends.

Steer clear of these frauds and warn your friends that not even a cup of coffee comes at no cost. While both Starbucks and Tim Hortons may be trustworthy brands and offer occasional specials, be sure to only participate in contests from their own websites or stores.
Read More...

08/10/11

Email fraud came close to wrecking my life – and the charity I run

On the last day of our summer holiday in my Dorset cottage, my son shouted down the stairs "Mum, you've been hacked".

That sunny day, 25 August, saw the beginning of the most gruelling, frustrating and miserable period of my recent life. It lasted nearly four weeks, when I felt totally isolated from all my contacts across the world, and work virtually stopped as I had no access to my Google Gmail account.

The phones, landlines and mobile, never stopped ringing as an endless list of people – friends, colleagues, civil servants (surely they should have recognised the money-seeking message as fraudulent?), people I had not spoken to for years – called to ask if I was in Spain, whether I had been robbed, or if it was a scam. Moreover, various elderly friends and relations (I am in my 80th year so it is not surprising that many on my list are as old or older) unwittingly fell for the trick, followed the instructions and sent off the requested money.

I lost all the contacts in my computer address book. It meant I almost had to close the charity I direct, Widows for Peace through Democracy, because I had missed so many deadlines and our work was badly compromised.

I am simply one of the many thousands of victims of the "mugged in Spain" scam. For Spain, substitute "Athens", "Cyprus", "Kuala Lumpur" or whatever destination the fraudsters care to use. Most of us, surely, can immediately recognise the message that urgently pleads for a loan of around £2,000 because I have been "attacked on my way back to my hotel …" as fraudulent.

But many people did not. As far as I know some £5,000 has been sent, as if to me, as a "loan to be repaid with interest". And during the month I was unable to use my Gmail account, I learned of at least six other cases where people had received similar emails as if from people they knew, and sent off large sums.

Yes, it is easy for us to express amazement that anyone could send off money without first doing a little bit of detective work – such as telephoning one's children to ask whether we really are abroad, or taking other advice. But the fact is, that in a contact list of maybe over 3,000 names, if just a handful of people fall for the scam, the fraudsters have won.

Google has no human helpline you can contact, unlike the paid-for providers, such as AOL and Virgin, and I feel its website is sadistically ambiguous in the instructions it gives on what to do if you cannot access your emails. But, eventually, we got back by changing the password to one very esoteric and surely uncrackable, and were able to message everyone on the contact list about what had happened.

For a whole week I worked hard to re-establish the work of our charity – the only NGO in the world that represents the needs of widows and wives of the missing in mainly conflict-afflicted countries. I was desperately concerned that I had let down my partner associations in Iraq, India, Afghanistan, Nepal, Sri Lanka, Congo, Nigeria, Southern Sudan (to name just a few on our network) since, due to the hack, I failed to meet UN deadlines to report specific human rights violations. I missed putting in project proposals and grant applications to various UN and other fund sources, and let down so many people vainly trying to contact me.

WPD operates from my home; has no core funding; no paid staff and all our work is done on the internet, using our Gmail address which is printed on all our publicity material and our website.

However, once reinstated in Gmail, I pulled myself together, buoyed up by the marvellously sympathetic Eddie Mair of Radio 4's PM programme, who gave me a slot to describe what these scams can do to one's work, and to one's life. And then … Boom, Crash, it happened again, this time back in my west London house.

On 29 September I got a call from Fiona Hodgson, on my advisory committee, who was preparing to chair the forthcoming Conservative Conference. "I am so sorry, Margaret. I know what you've been through in the last month but you have been hacked again."

I have to admit I nearly collapsed, since the horrors of the past month were so vivid and I knew I could not face a repetition of that saga. I would have to close down WPD and cease all work on the issue of widows' rights that I feel so passionate about and which is so neglected by the UN, the international community, and our UK International Development Department.

In Dorset, I had called the local police, but they admitted there were no resources to deal with these frauds since the priorities for a much-strapped police force are "burglary, violence and Asbo". When it happened again in London, we called the Met and they were rather more on the ball.

Their advice was to close down my Gmail account completely; transfer all the contact addresses to a private account I have with AOL, and to take a hard copy of the contacts so I would not be caught out should anything happen in the future. They also explained that my new password was easily decipherable once the fraudsters had my email address, for they have some device that browses every combination of letters and numbers until they get the magic mix. They advised: "Don't use any of the free internet providers like Google, Hotmail or Yahoo. None of these have help lines. Only use providers you pay for."

Although I have put the Met in touch with Dorset Police, and sent them all the evidence I have collected from other people's experiences of this hack, I fear nothing can be done. The police agree. They say the public must become more vigilant and aware of these frauds. This scam is on a vast global scale but neither Western Union, which is designated as the channel for these money transactions, nor Google itself, is prepared to bear any responsibility or help track down these criminals. Besides, the UK police are powerless to act since the fraudsters mostly operate from overseas.

There is much discussion in the media on cyber-crime, but it is mostly directed at gangs that hack into bank accounts, credit cards and big company or government computer systems. No one seems to pay any attention to the hacking of individuals' identity through their email accounts.

What is to be done? I feel wretched about the kind people who truly believed I was in dire need and sent money to these criminals; but I can hardly afford to repay them as I, too, am a pensioner trying to run my NGO with practically no financial support.

As hacking individual accounts is one of the most lucrative of all cyber-crimes, I hope that greater resources will be invested to raise awareness of this type of fraud among the public, especially the elderly. Given that this crime has no borders, information sharing between law enforcement officials internationally is vital. And I very much hope that the government will accommodate this type of fraud within its cyber-security strategy, to be presented shortly to parliament.
Read More...

06/10/11

Steve Jobs death exploited by Facebook scammers

It's impossible to express how sad many people in the technology world feel at the news of the death of Steve Jobs.

Sickeningly, as with the deaths of other figures in the public eye, there are scammers waiting to take advantage of bad news.

Here's a scam we have seen on Facebook, claiming that free iPads are being given away "in memory of Steve Jobs".


In memory of Steve, a company is giving out 50 ipads tonight. R.I.P. Steve Jobs [LINK]

The cool-sounding link sucks you in, tricking you into believing that you may get a free iPad but then goes on to get you to complete online surveys to "qualify".

The link goes through the bit.ly short url service (we have asked our friends at bit.ly to shut the link down) and we can see that over 15,000 people have already clicked on the link which was set up within hours of Steve Jobs's death first being announced.



Of course, if you were one of those people who clicked on the link you may be wondering what the chances are that you will receive a free iPad. I hate to disappoint you, but it's pretty unlikely.

The webpage you are taken to is very similar to ones we have seen pointed to by other scammers. Here's what I saw:



I am writing this article from the Virus Bulletin conference in Barcelona, and you can see that the page has automagically determined where I am in the world and adjusted its language and wording as appropriate.

Below you'll see how the survey pages look if you visit them from Sydney, Australia, for instance.

Survey site visited from Australia
If you don't click through within a few seconds, it plays an audio message urging you to do so:

You'll notice that the audio message spectacularly fails to mention the 50 free iPads, which have by this time been reduced to the promise of "an exclusive reward", whatever that might be.

My colleague Paul Ducklin captured the audio and - being a fountain of interesting but not always entirely relevant information - tells me that the speaker is an Australian who grew up in South Africa.

When Duck visited the page a second time from Sydney, this is what he saw:
Casino website
How do the scammers make money? Well, they are earning affiliate cash - in a nutshell, they make more money the more traffic they can direct to websites, driving more people to become customers, or take online surveys and competitions.

Cynically, they exploited the death of Steve Jobs in the hope of driving large numbers of internet users to websites offering content such as contests, surveys and online gambling. The fact is, of course, that they could just as easily have taken those users to a webpage containing malicious code or a phishing page designed to steal credentials.

Chances are that this won't be the only scam we see regarding the untimely death of Steve Jobs. It wouldn't be a surprise, for instance, to see scams which might try to take advantage of those moved by the loss of Apple's founder with lures like "Donate to Steve's favourite charities as a tribute".

If you do want to pay tribute to Steve Jobs, the most appropriate place it seems to me would be Apple's website itself.

The truth is that the scammers are not geniuses like Jobs, and they don't contribute anything to the world of technology or wider society as Steve Jobs did. It's a shame that they can't be inspired by speeches like the one Jobs gave at Stanford University in 2005, and make something better of their lives.



I think that's how we should remember Steve Jobs today.

Please folks - always think carefully about the links that you click on. Time and time again scammers and cybercriminals have proven themselves to have no qualms about exploiting news stories - whether it be the personal tragedy of a teenage girl committing suicide, bizarre escapades, a natural disaster or the latest salacious celebrity gossip.


Read More...

Cybercriminals Remember Steve Jobs Through Facebook Scam

In an inevitable turn of events, cybercriminals were found leveraging the death of Apple co-founder Steve Jobs through Facebook scams within hours after it was announced.

The particular scam we found involves a website which claims that Apple has decided to give away 1000 iPads, in memory of Steve Jobs. The said site displays the following:

The site asks users to share the page in order to be eligible. After the user follows the instructions, he is directed to an ad site, while in the background, the link is posted on their Facebook wall.


And as dubious as the offer sounds, it seems like some users are falling for the scheme, as we are seeing an increasing number of posts bearing the website’s URL.

The catch behind this scam is that there is no such offer from Apple, and that only ones who will get anything from this are the scammers, who will earn money from the displayed ads every time a user is tricked into following the instructions. Also, as more users share the link, the number of potential victims also increases, as well as the profit for the scammers behind it.

The death of known persons have become staple topics of social engineering schemes for the past years. Just a couple of months ago we saw scams that took advantage of the death of singer Amy Winehouse, as well as rumors about the death of Lady Gaga.

Users are advised not to click on posts like these if they see them on their Facebook newsfeeds. We also suggest users to educate those who have been tricked to stop the spreading of such scams.

For more information on threats leveraging social networking sites, check our infographic, The Geography of Social Media Threats.

Access to the mentioned website is now blocked through the Web Reputation Service. Users of the latest Trend Micro™ Titanium™ Maximum Security are also protected from this through the Social Networking Security feature.

Read More...

22/09/11

Should you trust this 'BBC' news report? Work from home scam spammed out

Who do you trust online?

Your friends? Lady Gaga? The media? How about the BBC?

If you read a news story on the BBC website, would you trust what it was saying?

A Naked Security reader forwarded us this interesting email which (fortunately) had been quarantined by his anti-spam defences. What's particularly interesting is the webpage to which it links.

Work at home spam email

If you were tempted to click on the link are taken to a website which looks like this.

Fake BBC website

A pretty convincing replica of the BBC website. But, of course, it's not the real BBC News website at www.bbc.co.uk/news, but instead a page that is copying the popular site's graphics and style.

The URL in the address bar might be a giveaway, if you were watching carefully enough.

Closeup of fake BBC website

And see how it refers to a housewife in Abingdon - that's because I was in Abingdon, just outside Oxford, UK, when I visited the webpage. The site has tailored its content to appear more compelling to me by determining where in the world I am.

If I had visited from Bhutan, Botswana or Bognor I would have been told the single mother lived in those places instead.

The purpose of the spam campaign, and the bogus BBC website, is to try to convince you to sign up for a working from home scheme.

Work at home website
As they're using subterfuge to promote their scheme - my advice would be to keep your distance.

nb : nakedsecurity.sophos
Read More...

21/09/11

Microsoft dumps partner over telephone scam claims

One of Microsoft's Gold Partners has had its relationship with the software giant unceremoniously terminated, after being revealed to be orchestrating a telephone support scam.

Comantra, based in India, are said to have cold-called computer users in the UK, Australia, Canada and elsewhere, claiming to offer assistance in cleaning up virus infections.
The bogus support calls came from Comantra employees who claimed to be representing Microsoft, and used scare tactics to talk users into opening the Event Viewer on Windows, where a seemingly dangerous list of errors would be seen.

Once terrified by what appears to be a worrying collection of warning messages, and believing this was evidence of a malware infection, users would be tricked into allowing Comantra technicians to gain remote access to their computer, and hand over their credit card details to fix any "problems".
In the past, vulnerable elderly people have even been told by scammers that heavy rain may have caused a computer virus infection.

What makes the scam particularly audacious is that during the scam campaign, Comantra were a certified Gold partner of Microsoft, and when quizzed by skeptical computer owners would use their status to trick potential victims into believing the call was legitimate.
Comantra website
A search for "Comantra" on the internet finds a large number of posts and complaints about the scam telephone calls, stretching back over 18 months. Some users have even asked on Microsoft's own message forums how it is possible for the firm to have "Gold Partner" status.

As PC Pro reports, a Microsoft spokesperson has now confirmed that Comantra has at long last been struck off their Gold Partner list:
"We were made aware of a matter involving one of the members of the Microsoft Partner Network acting in a manner that caused us to raise concerns about this member's business practices. Following an investigation, the allegations were confirmed and we took action to terminate our relationship with the partner in question and revoke their Gold status."
"There are no circumstances under which we would ever allow partners or any other organisations to pose as Microsoft. We view matters such as these extremely seriously and take immediate action if such behaviour is brought to our attention and found to be the case."
Hmm.. Maybe someone should tell Comantra to update their website and remove that Gold Partner logo?

Comantra website with Gold Partner logo
Listen to this great podcast by Sophos experts Paul Ducklin and Sean Richmond where they discuss the problem of fake tech support calls, and the ways in which you can avoid falling for scams like this yourself:


(Duration 6:15 minutes, size 4.5MBytes)
Also, make sure that your family and friends are on their guard against suspicious tech support calls telling them about infections on their computer - even if the callers do claim to be from Microsoft. It only takes a lapse of common sense for you to hand your credit card details straight down the line to a criminal.

nb : nakedsecurity.sophos
Read More...

20/09/11

Pornographic movies posted on Facebook walls? Hoax spreads like wildfire

Blue movieA hoax is spreading like wildfire on Facebook, claiming that hackers are posting pornographic movies on users' walls which are invisible to the owners of the wall but are visible to friends and family.

You can imagine how that would be pretty embarrassing if it were true. Fortunately, it's nonsense.

Here's what a typical message looks like, spread by a Facebook user who thinks they are warning their friends - but really perpetuating the hoax.
Movie hoax on Facebook
ATTENTION FRIENDS! HACKERS ARE DOING DAMAGE AGAIN ON FACEBOOK! PORNOGRAPHIC MOVIES ARE BEING POSTED ON OUR BEHALF ON THE WALLS OF OUR PROFILES! WE DO NOT SEE THEM, BUT OTHER PEOPLE DO, AS IF IT WERE OUR PUBLICATION! SOMETIME EVEN OUR SUPPOSED Comments APPEARS. IF YOU SEE SUCH A THING IN MY HOMEPAGE, ALERT ME AND DO NOT OPEN IT BECAUSE IT IS A VIRUS! ...COPY AND RE POST THIS MESSAGE
The message is, of course, nonsense and users should not repost the warning.
We have not seen any evidence that hackers are able to post content to a compromised Facebook wall that the owner of the account cannot see.
The fact that the bogus warning tells you that it's invisible to your eyes just adds to the panic, of course.

Yes, scammers have often posted thumbnails of what appear to be pornographic videos to compromised Facebook users' walls, but we have never seen any incidents where the post was *invisible* to the user.

Although a hoax is nothing like as bad as a piece of malware squirming its way between users and stealing information, it's still a nuisance, clogging up communications, increasing the overall level of spam and perhaps leading people to make bad decisions.

There's an important lesson here - don't believe everything you read on the internet, and think twice before you pass a story on to your friends.

Keep your wits about you and stay informed about the latest scams, hoaxes and malware attacks spreading fast across Facebook. One of the best ways to do that is to join the Sophos Facebook page, where more than 100,000 people regularly share information on threats and discuss the latest security news.

nb : nakedsecurity.sophos
Read More...

19/09/11

Lady Gaga is still not dead - stop falling for Facebook scams

This weekend we saw another spate of Facebook messages claiming to link to a BBC News report of the death of Lady Gaga.

Of course, the claims are untrue - and Lady Gaga is still alive.

But that isn't stopping Facebook scammers from creating money-making websites that claim that the eccentric pop star has been found dead in her hotel room, and tricking Facebook users into sharing the links.

Lady Gaga is dead? Facebook scam
BREAKING: Lady Gaga Found Dead in Hotel Room :( mjide35w
[LINK]
This is the most awful day in US history
You would think that the scammers would show a little more imagination - rather than using the same disguises time and time again. But, hey, if the scam is working for them - why change it?

Clicking on the link will take you a third-party website, posing as a BBC News online report, which attempts to trick you into clicking on what appears to be a video thumbnail.

Lady Gaga is dead? Facebook scam

In the above screenshot you can see that Sophos Anti-Virus (in this case, our free anti-virus for Mac users) has correctly warned about the webpage and prevented you from being clickjacked.

We've seen scams very much like this, many times before.

Facebook could do a much better job, in my opinion, at helping users avoid falling for tricks like this and clean-up a lot of the mischievous pages and dangerous links on its network.

For instance, a quick search of "Lady Gaga dead" finds a number of Facebook pages attempting to spread the rumour of the artist's demise.

Lady Gaga is dead? Facebook scam

Some of which have clearly been created with a scam in mind, like this following clickjacking example:

Lady Gaga is dead? Facebook scam

Watch out if you try to play the video as this is a clickjacking scam which attempts to silently say you "Like" the page when you click with your mouse.
If you've been hit by scams like this, remove the messages and likes from your Facebook page - and warn your friends not to click on the offending links. Clearly, Facebook needs to work much harder to prevent attacks like this from reoccurring and spreading so rapidly.

If you're a Facebook user and want to keep up on the latest threats and security news I would recommend you join the Sophos Facebook page - where more than 100,000 people regularly discuss the latest attacks.

nb : nakedsecurity.sophos
Read More...

13/09/11

Protect your corporate data from email honeypot scam

Researchers found they could collect sensitive corporate email by simply registering domain names that are slightly misspelled

email honeypot
Garrett Gee and Peter Kim at GodaiGroup found that a small investment in time and money could reap unexpected rewards with a simple, low-tech email honeypot technique that involves something they call "Doppelganger Domains."

Over the years there have been many reports of unscrupulous characters registering slightly misspelled domain names. Companies have responded by taking over (or taking back) these domains from so-called "typosquatters." For example, the folks at GoDaddy ensure that godadfy.com gets redirected to godaddy.com. There are numerous websites that will help you generate and look up misspelled versions of your legitimate domain name.

The technique that Gee and Kim used also involves typosquatting, but in a very precise way. They registered 30 domains that differ from legitimate subdomains only by dropping a dot. So, for example, if they found commonly used email addresses at us.somecompany.com, they registered the domain ussomecompany.com, without the intervening dot. Then they simply collected all of the email directed to @ussomecompany.com. After analyzing email that used the domain names of the Fortune 500 companies, they concluded that 151 of those companies are susceptible.

Over the course of six months, they collected 20GB of email -- 120,000 messages. Included in the haul: "trade secrets, business invoices, employee PII, network diagrams, usernames and passwords, etc."

Most frightening, they also found that several of these Doppelganger Domains had already been registered: usintel.com, for example, isn't registered to Intel, it's registered to someone with a Gmail account; demanpower.com isn't registered to manpower.com, it's registered to someone with an email account at 163.com, a site that crops up over and over again in malware lists.

If your company uses subdomains for email addresses, it would be well worth your while to take a look at the report, and perhaps take advantage of the authors' offer to perform a free domain scan to see if your domain is vulnerable to this kind of attack. Suffice it to say that if your company uses any subdomains for email addresses, your domain is most certainly vulnerable.


nb : images.infoworld Read More...

11/09/11

Nicole's baby kicking video is a Facebook scam

A video of baby kicking inside his mother's pregnant belly is the latest lure being used by Facebook scammers - and judging by the number of readers from Naked Security who have reported it to us, it's spreading like wildfire.
AWESOME Video Nicole's Baby Kicking - The Belly View - Unbelievable

AWESOME Video "Nicole's Baby Kicking - The Belly View - Unbelievable"
[LINK]
An amazing view of a baby kicking and moving his way out of the belly while at the beach.
There is, indeed, a real YouTube video of a heavily pregnant woman called Nicole, sunbathing on a beach. It was posted in May 2009 and has had over 3.5 million views so far.

The thing is, however, if you really want to watch the video: go to YouTube.

Don't click on the link being spread across Facebook. Because if you do, you are taken to a third-party website which insists you have to share the link with your Facebook friends before you can watch the video clip.

Scam webpage

Bizarrely, when I visited the page from my test Facebook account it was advertising the controversial Scientology organisation. One wonders if the scammers are earning revenue by driving traffic to the page.

You should always be suspicious of links like this being shared by your Facebook friends. The safest place to watch "viral" videos is on YouTube itself (and other established video websites such as Vimeo), or you could find yourself being asked to complete money-making surveys or imparting your personal information.

If you're a Facebook user, and want to keep up-to-date on the latest scams and threats, join the Sophos Facebook page where we have a community of more than 100,000 users discussing the issues.

nb : nakedsecurity.sophos Read More...

09/09/11

Facebook birthday T-shirt scam steals secret mobile email addresses

Facebook scams are getting sneakier and sneakier - with the latest attack using the lure of a free T-shirt celebrating Facebook's birthday in an attempt to steal the secret backdoor key to your account.

The offer seems attractive enough - a webpage claiming to celebrate Facebook's 7th birthday, saying that it has over 1.9 million official T-shirts in stock.

Facebook birthday t-shirt scam
All you have to do is verify that you are a Facebook user, claims the following webpage. And this is where things get very sneaky.

Facebook birthday t-shirt scam
The webpage tells you to visit Facebook Mobile, and find on that page the personalised email address that you can use to post status updates or upload photos and videos straight to your profile.

Many people are probably unaware that such a thing exists - but every Facebook user has a secret mobile email address they can use for this purpose.

The important thing, of course, is to keep it secret. Because if someone else finds it out, they'll be able to post status messages to your Facebook page or upload videos and photos to your wall - which your friends will be able to see.

The scammers, unsurprisingly, want your secret mobile email address for Facebook. And so they claim that you have to hand it over to verify you are a legitimate Facebook user in order to get your T-shirt.

The scammers have even had the gall to make a YouTube video showing how to find the secret email address on the Facebook Mobile page, and where to enter it on their form:

The above video is made by a YouTube user called "vicsthedevil" and we have to assume that they are intimately involved in the scam. They posted the video on 5 September, the same day that they registered the website domain name where they are hosting their scam.

Of course, you're still hoping that you're going to receive a free T-shirt. So you may not baulk at the idea of completing a survey (which, by the way, earns commission for the scammers) and giving them your snail mail details so they can send through your free gift.

Facebook birthday t-shirt scam

Good luck, by the way, on that T-shirt. My hunch is that you won't ever receive one. But the scammers now have the ability to post to your Facebook page and upload pictures to your account, and you have helped them earn some money in the process.

If you were hit by this scam then you must refresh your Facebook mobile upload email address - that way the bad guys you just gave it too won't be able to use it as a secret backdoor into your account.

Upload email

If you don't change your mobile email address on Facebook, you're just asking for trouble. In the past, Facebook pages such as that belonging to the Van Gogh Museum have been hit by scammers who abused the mobile upload feature.

It would be great, of course, if there was a way of telling Facebook to not allow any email address to be used for mobile uploads, as I would imagine that many individuals and companies would find the permanent blocking of the feature attractive.

If you're a Facebook user and want to keep up on the latest threats and security news I would recommend you join the Sophos Facebook page - where more than 100,000 people regularly discuss the latest issues.

nb : nakedsecurity.sophos Read More...

30/08/11

Hurricane Irene Scam Hits Facebook

Hurricane Irene surely turned New York City to “city that never sleeps” as it brought flood waters, knocked out power to more than 4 million people and was even responsible for at least 15 deaths in six states.
What’s worse is that cybercriminals are taking advantage of the incident by spamming a fake video on Facebook.

The page, which contains the alarming title “VIDEO SHOCK – Hurricane Irene New York kills All” displays a clickable image of a fake video player on the page.


The text displayed in the succeeding pages is in Italian, which suggests that the attack specifically targets Italian users. Clicking the image of the video displays a prompt that says “Per Vedere il video devi prima condividere” which translates to “To see the video you must first share”, as well as two options that say “Share” and “See the video”.


Clicking “Share” displays the link to the Facebook on the user’s wall.


On the other hand, clicking “See the video” displays a list of deals that the user must register to, in order to view the video.


The said deals only lead to advertisement and affiliate program websites.
Such schemes in Facebook have been rampant in the past weeks, as we’ve seen such scams that lead to spam pages or surveys. We’ve seen these attacks use various social engineering lures, such as false news about the death of of singer Lady Gaga, tickets for the Twilight movie, Breaking Dawn, and invites for Google+.

For more information on threats found in social networks such as Facebook, check our report: Spam, Scams and Other Social Media Threats, and our infograph, The Geography of Social Media Threats. Read More...