Tagged: e-mail RSS

  • alex 2:07 pm on July 15, 2008 Permalink | Reply
    Tags: , Backdoor, Backdoors, Bank Details, , e-mail, , email, Free Adult Sites, Free Porn, , , Hacking Into Computers, Mass Emails, New Ways, phising, Scammers, , , , Spelling Mistakes, Spoof, spoof sites, trojan, Trojan Horse, , Virus Scanner, World War 3   

    Social Engineering Tactics: Attacking With e-mails 

    Computer security:How Social Engineers are hacking into computers using Trojans as backdoors by getting users to click links in e-mails

    Background
    We are all very aware of attacks to gain our bank details by sending spoof emails of various banks, eBay and google ads accounts. More info about social engineers can be found on the The Art of Deception post.

    The Con
    Social Engineers are finding new ways to attack victims using Phishing methods. They send mass emails with subjects similar to those pictured bellow:

    phising e-mails subject headers

    the subject of the e-mails are designed so that you click on them, some other headers included World War 3 videos, video of saddam beheading etc

    phising email

    emails typically contain a link to the page which contains a Trojan. Most of the time (as in most of the emails written by scammers), the grammar isn’t correct, many spelling mistakes as well as other mistakes such as the formatting of addresses.

    phising email content

    So when the user goes to ‘play’ the video, they are promted to download a file in order to play the file (often the file downloads without interaction from the user). However, this file contains a backdoor into your system (Trojan Horse).

    Similarly this method of getting the user to download a file in order to ‘play’ a video or somehow access content is used on ‘free’ adult sites – claiming free porn – when in fact they are getting a virus.

    How to Prevent?

    Have a good Virus Scanner that scans sites and files as you visit them on the Internet. The one i use is AVAST Free edition and it stops the Trojan entering the PC, and terminating the connection with that server….and keep it up to date, otherwise its pointless having it installed

    In general if the email looks dodgy don’t click links in it – simple!

     
c
compose new post
j
next post/next comment
k
previous post/previous comment
r
reply
e
edit
o
show/hide comments
t
go to top
l
go to login
h
show/hide help
esc
cancel