Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Friday, May 15, 2015

Protecting Your Kids Against the Dangers of the Cyber World


I always thought I had technology on the brain before, but it’s impossible to work in the Information Security industry without letting even more paranoia into your life outside of the office.  My job has put me on the front lines of the cyber wars that are being fought every day, or rather, every second of the day.  I’ve seen glimpses of digital grifters working hard to scam regular people out of their life savings, malware attacks being used to allow cyber criminals into protected systems, and Advanced Persistent Threats from organized professionals in other countries trying to attack our own.  It’s enough to make anyone paranoid.

That’s why even before my son Kaden was born, and now that we have a little girl on the way, my mind has already been racing years into the future to make a game plan for how I can protect them from the dangers that lurk just beyond the keyboard.

The thing is, cybercrime isn’t always what Hollywood makes it out to be.  Hackers aren’t always young, scrawny kids wearing sweatshirts with their hoods up, sitting in the dark in their parents’ basement as they clack away on their keyboards with their noses just mere inches from the screen.  They’re not always hacking into banks to fill their accounts or their schools to bump up their GPA.  They’re not always on a crusade against “the man.”  In fact, you don’t even have to be a “hacker” to be a cyber criminal.

Cybercrime is exactly what it’s name implies…it is unlawful activity that just happens to take place on a computer.  Theft, extortion, espionage, it can all happen online, and it does every day.

The Internet has also made many crimes must easier to commit.  Decades ago, sexual predators would have to somehow charm their victims in person to gain their trust.  Years ago they moved their playing field into chat rooms where they could pretend to be someone else and lure others into traps.  Nowadays all they need is a Facebook account.

It’s a scary world out there, and there are several windows into that world scattered across our homes in the form of computers, tablets, smartphones, and now even watches. So what are we supposed to do?  Do we boycot technology and purchase a horsedrawn carriage?  Or more realistically, do we prevent our children from using computers outside of doing homework and keep them away from electronic devices?

This is the 21st century.  Technology is a huge part of life and to force your kids back into the stone age is going to negatively affect their social and intellectual growth.  When I was growing up, we didn’t actually get a computer in our home until I was around 9 or 10 years old.  However, both of my grandparents had computers that they didn’t know how to use that I was immediately drawn to.  My grandpa on my mom’s side had an old, DOS-based PC on which I used to write my own little stories using the text editor.  Thinking back, I’m still surprised that I was able to teach myself how to navigate in that text-based operating system without Google to help me.

My grandma on my dad’s side had an old (well, “new” at that time) Apple Macintosh Classic II, which I fell in love with.  Even though it was black and white and the drawing program only had different shades of gray, I had a lot of fun with that machine.  I also introduced myself to the first stages of programming by figuring out how to edit a choose-your-own-adventure game that was installed and creating my own side-stories.

As years went on and my grandma replaced her Mac II with a blueberry iMac, I continued to experiment with the new technology as my cousin Ty and I discovered how to change the error sounds to be a voice recording of us chanting “Grandma you screwed up!” instead.

Comparing my life now to my adventures as a child, I see that I still learn the same way.  Whenever I come across a new piece of technology, the way I figure it out is just by experimenting with it until I know how it works and what it’s capable of.  It’s how I’ve made it where I am today.  I’m grateful that my grandparents allowed me to play with their expensive toys, and that my parents were able to invest in some computers at our house as well so that I could improve my talents.

On the other hand, while growing up I was surprised at how dangerous the digital frontier could be.  I’m not just talking about computer viruses or worms, but about how mature content could be introduced so easily.  It was terrifying how easily a web search for how to beat a level on a Nintendo game could turn into pictures of naked women.  Luckily I had trained myself to close the window as soon as I saw anything like that, but I’m sure not everyone who was surprised with those pop-ups would do the same.

In today’s world, the situation is both better and worse.  With nearly all browsers including pop-up blockers and other similar features, it is much harder to come across offensive content on accident like it was years ago.  It is much easier to protect our kids from getting blindsided by pornography by putting the proper filters in place.  However, with the help of Google, Yahoo, Bing, and other search engines, finding the same content on purpose has never been easier and is only a search away.

Just as the threat landscape has changed, so has the need for us to protect our children in a different way.  Is it enough anymore to put firewalls and content filters in place, or spy on your kids’ activities by rifling through their Internet history?  First of all, boundaries can always be overcome when someone wants to badly enough.  Firewalls have weaknesses and filters can be bypassed.

Does that mean you shouldn’t bother turn on parent controls at all?  Of course not.  But technology alone will not solve the problem.  Let me talk about three things that need to be done to protect your family against the dark side of the digital world.

 

Be aware of what’s out there

Not everyone is tech savvy.  In fact, many don’t know how to do more on a computer outside of checking their email, writing a document, and looking at Facebook.  However, if you are a parent then you need to know a little more than that if you want to keep your children safe.  That doesn’t mean that you need to rush to the library and check out “Internet for Dummies” or sign up for an adult learning class (although if you’re ambitious enough to do that then well done!), but you do need to become familiar with the risks that your children have the potential of facing every day so that you can help them to overcome them.

Every year the company that I work for holds a security conference known as RSA Conference, which features many very interesting security-related keynote presentations.  One of these presentations was called Into the Woods: Protecting Our Youth from the Wolves of Cyberspace.  One of the panelists in this presentation, Alicia Kozakiewwics, shares the story of how she was abducted as a young girl because she was innocently chatting with her would-be captor on the Internet, believing the person was somebody else.  You can watch her story on YouTube here.

Because of what happened to her, she started The Alicia Project, the purpose of which is to raise awareness of Internet safety with children.  On her website is a great page of Internet Safety Tips that I highly recommend to parents so that they can know at a high level how to prepare their children for the dangers that are out there.  This leads me to my next suggestion.

 

Train them while they’re young

While it is never too late to teach your children about Internet safety, your advice will be much more influential if you can train them from the beginning.  Teach them to never share private or identifying information like their home address, where they go to school, etc.  Teach them the dangers of “checking in” with apps like FourSquare and Facebook, as it can alert potential predators to their location.  Engraining these habits in your children while they’re young will make sure that they exercise these good practices for years to come.

 

Make them a part of the team

So what is the best way to go about teaching your children?  Do you use scare tactics to try to make them afraid of the Internet?  No, rather than telling cyber ghost stories, it is better to make them a part of the team so that they can work with you to keep your family safe.  So how do you go about doing this?  Another panelist from from same keynote presentation I mentioned gave a good example of how this technique can be done.

Let’s say you are concerned about how much time your child spends on Instagram. and are worried that the wrong types of people could be following her profile.  Since we all know that kids in this day and age become one with technology from the ground up, we can always count on them to teach us something new.  (Heck, my one-year-old son has somehow already managed to learn how to scroll through photos on an iPhone whenever he can manage to get his hands on one.)

Imagine you walk up to your child and find her looking at Instagram on her phone.

“What are you doing?” you ask.
“Just looking at Instagram,” she replies.
“Oh yeah?  How does it work?”
“C’mon Dad, you’ve seen it before.  I follow my friends and I get to see when they post pictures, and they get to see mine.”
“Wow, that’s pretty cool.  Do you think it’s something I would like?”
“Yeah, maybe.”
“Alright, do you think you could help me set it up on my phone?  And maybe I could follow you so that I can see your pictures too.”
“Ok sure.  It’s easy, I’ll show you.”

There you have it.  It’s not rocket science, and now instead of playing Big Brother and spying on your kids and their Internet usage, you are able to show your trust in them while still being able to know what’s going on in their digital lives.  It also opens the door for you to teach them about potential pitfalls that may come about and make it into a learning experience rather than scolding them on how they are acting.

Here’s another example:

“Is that Minecraft you’re playing?” you ask your son.
“Yep, I’m just playing it with my friend down the street.”
“Oh nice, so you can chat with him while you play?”
“Yeah, see?  I just sent him a message.”
“Oh yeah you’re right.  So can other people on the Internet chat with you too?”
“Sometimes.  I usually don’t though.”
“Yeah, I wouldn’t dare either.”
“What do you mean?”
“Well, remember how we taught you when you were younger not to talk to strangers?”
“Yeah.”
“Do you remember why?”
“Yeah, it’s because they could really be bad guys and try to steal me or hurt me.”
“Exactly.  So chatting with people you don’t know on the computer is just like talking to strangers in real life.  You don’t know who they really are and if they’re really bad guys.”
“Oh yeah, I hadn’t thought about it like that.”

Giving your kids the opportunity to have open discussions with you about these sorts of things is much better than having them be afraid to talk to you or believe that you won’t understand or relate to them.

 

Conclusion

It is a scary world out there, but that doesn’t mean you have to shut all the blinds and unplug your modems.  The Internet is hear to stay and is only becoming more and more prevalent in our lives.  The more that we can go on the offensive and preemptively train our children to be on the lookout for digital hazards, the more rewarding your lives will be.

I don’t pretend to be an expert, especially seeing as my oldest child hasn’t even learned to walk yet.  But I know that every parent has or will face these dangers and it is important to know what we can do to protect our family from the seen and the unseen.  There are many resources at our fingertips and we just have to use them.  But on top of that, we just have to continue to love our children and be willing to communicate with them.  By doing this, we will know that our families are protected from any dangers that the Internet may introduce.

Friday, December 20, 2013

What on earth does Jeff actually do?!

I have been wanting to sit down for a while now and write about my job and what exactly I do for forty hours each week, mainly because I feel so bad for my wife and family whenever they get popped the question and have to fumble around to try to explain it.  Even I have a hard time trying to describe it to people when asked, and usually have a few different explanations based on the technical understanding of the person asking the question.  Some of the responses I'll often give are....

  • "I work in the IT industry."
  • "I work in maintaining data centers."
  • "I work with 'The Cloud' and data storage."
  • "I am a tech support engineer."
  • "I support Network-Attached Storage arrays."
That's just a small sample of the different replies I give to people who want to know what I do for a living.  But in reality, my job is pretty complex to explain.  In fact, even my entire title is an acronym:  FAST VP SME, which stands for Fully Automated Storage Tiering for Virtual Pools Subject Matter Expert.

That's certainly a mouthful, so I'll try to start at the beginning.

I work at EMC Corporation in Draper, which is an IT company that is most widely known for its storage arrays and its acquisitions of VMware and RSA Security.  Not being able to afford multi-million dollar computer equipment, I'd never really heard of EMC in terms of their data storage systems, but knew who they were because of VMware and RSA, which I was exposed to quite a bit while studying at UVU.



If there was one word I could use to describe EMC, it would be "HUGE!"  Especially after coming from a small business of maybe 80 employees, I was incredibly shocked to be surrounded by several hundred employees just in Utah, as well as hundreds if not thousands more worldwide, all supporting a large variety of products.

I was hired on as a Technical Support Engineer for the Symmetrix department.  I don't usually like to refer to myself as being in "tech support" because of the call-center stigma that is associated with it, because even though I work with customers in resolving break/fix issues, I think the term "technical support" doesn't do my role very much justice.

But I'm getting ahead of myself.  I think I should first explain a little bit about what this Symmetrix thing is.  The Symmetrix storage array is the first product created by EMC, and is what is called a Network-Attached Storage (NAS) array.  These arrays look like giant refrigerators that line up beside each other like a football team on the scrimmage line, and are filled with hundreds or thousands of hard drives.  



Why on earth would someone need so many drives?  Well, just think about it.  If you're reading this post, then chances are you have a Facebook account, unless somehow I'm way more famous that I think I am...which is not very.  How many photos and videos would you say you've uploaded to your account?  Hundreds?  Thousands?  Ok, now ask yourself how many users exist on Facebook right now?  I sparked my own interested just now and Googled the answer, and it turns out that Facebook has about 1.19 BILLION active users as of October, 2013.  So multiply that number by the number of photos and videos you have on just your account and see what you get.  I'm not sure my calculator even goes that high.



Well, all those pictures have to be saved somewhere, and that's a LOT of storage space.  That's where storage arrays like the Symmetrix come into play.  These powerful machines can hold petabytes and petabytes of data, and make sure that it's ready and accessible every time someone needs to use it.  These arrays have loads of features to make sure that the data remains intact no matter what by having several backup power supplies, spare replacement hard drives that will kick into gear the moment one starts to fail, and even the ability to have a mirrored system set up hundreds of miles away just in case a major disaster occurred in the area like an earthquake or tornado and the primary data center went offline.

I was trained to support these arrays for all of our customers (which are pretty much all Fortune 500 companies) and make sure that there are no problems accessing their data at any time and at the speed that they want.

The Symmetrix has a really interesting system in place where it actually complains automatically to EMC whenever it's having any problems.  This "call home" feature allows the array to automatically dial home to an EMC server with any issues, which in turn automatically opens a support ticket for my team to investigate.  These "dial home errors" that dial home arrive in the form of a four-digit hexadecimal number with a two-digit modifer number which refers to a specific error.  Some examples of these errors are 24AF.78, 01B3.C0, 0471.02, and 033E.38.



This was probably one of the hardest parts of the job, learning how to decipher these codes to know what they are referring to.  One may refer to a failed drive that needs to be replaced, whereas one may refer to a backup power supply that won't hold a charge, and another could indicate that a cable was plugged into the wrong jack.  I look at the list of errors now and am still surprised when I know what they mean, when they looked completely Greek to me months before.

This is why I say that we are not the "traditional" type of technical support center, because in our case we will receive a report of an issue and have it corrected or a local representative onsite with a replacement part before the customer even knew there was a problem in the first place.

The way we do this is by remotely accessing a laptop built into one of the arrays, which is called the service processor.  The same way that I'll patch into my dad's computer to help him get rid of a virus or install a program, I can connect to an array in Sweden or Australia or anywhere else and remotely troubleshoot issues.

My primary role when I was hired was to investigate and resolve these dial home errors, which I performed until I was enrolled in a two-week course taught by a colleague from our Hopkinton, MA, office.  James Nigrelli was a Technical Support Engineer (TSE) like I was, but he had been flown out to Utah to teach me--along with a small group of people--about a new feature in our top-of-the-line Symmetrix VMAX arrays called FAST VP, or Fully Automated Storage Tiering for Virtual Pools.

This feature is surprisingly exactly what it sounds like, although it probably makes no sense to anyone reading this at the moment.  But in a nutshell, here's how it works.  There are essentially three types of drive technologies that make up a storage array.  The first type is called SATA, which is the hard disk that most of us are used to, with the spinning metal plate touched by a spindle used to read and write data, making it essentially look like a tiny vinyl player if you were able to see inside its chassis.  Next comes the Fibre Channel (FC) drive type, which is essentially a SATA drive but with a much faster, optical connection and a faster speed.  Third is the Enterprise Flash Drive (EFD) type, which is an Enterprise version of the Flash or Solid State technology, which is what you'd find in a USB thumb drive, your iPhone, or even some computers like the Macbook Air.

Obviously the faster, better drives are going to be more expensive than the slower ones, and customers want to make sure they're getting their money's worth out of them.  FAST VP is a completely automatic system built into the VMAX arrays that collect performance statistics on the data and then uses those statistics to make sure the data that is "hot" and being used all the time is being kept on the faster drives so they can be accessed quickly and that the "cold" data that isn't being used very much stays on the slower, less-expensive drives.

Did I lose you?  Well, then think of if this way.  Let's imagine you are a fashion extraordinaire and have a pretty extensive wardrobe, but just moved into a small apartment with only one closet.  With all of the clothes you have, you're going to need to keep them in three different locations: your closet, the garage, and at your parents' house.  Naturally you're going to want the clothes you wear all the time in the closet, the clothes you might wear every now and again in the garage, and the clothes you own but really should have been given to Goodwill a long time ago at your parents' house.  It's the same thing with FAST VP, but with data.

I really enjoyed learning about FAST VP and, after James returned home, I soon became the "go-to guy" for any FAST VP-related cases that were opened.  I had such an aptitude for it that, one year ago, my manager approached me and informed me that he wanted to send me out to the Hopkinton lab with another TSE named Richard Kimball (no relation to Harrison Ford) to study FAST VP "from the masters" in order to become a Subject Matter Expert.



The trip was incredible, but also difficult because it was one week before my wedding.  But I learned a ton, studying alongside James and his mentor Rob Tasker.  They taught me so much, and I was able to experience the busy life of those in Boston for a while, which actually made me pretty grateful that the Utah lab is a bit more mellow.  I also had the opportunity to meet the Symmetrix developers, including the programmer who invented FAST VP, who shockingly is actually a pretty young guy.

Upon returning from my trip, I was bestowed the title of FAST VP SME, or FAST SME for short.  Richard and I then became the first escalation point for Utah TSEs before having to escalate to the Hopkinton lab for help with FAST VP-related issues.  

A few months later, James announced that he had taken a job in the development team and would be leaving the support lab.  Shortly after that, Rob announced that he was being promoted to the L2 Support Team, which is the elite escalation team for all cases.  While he would still be a resource for troubleshooting FAST cases, I soon found myself to be the primary escalation point on a global scale, as I have a Monday through Friday shift and have more of a full exposure to the feature than Richard, who works on a rotating shift and will often spend up to a week at a time away from the lab.

Being one of two FAST SMEs on shift globally during the US business hours, I had a lot of responsibilities on my hands.  Not only was I expected to take all the FAST-related cases that appeared in the support queues and act as an escalation point to others, but I also participated in weekly and bi-weekly conference calls with the developers (referred to as Engineering) that I met in Hopkinton to discuss current and new issues that affected the feature, participating in a group called the FAST Task Force.

I have truly learned a lot while in this position.  Not only have I had to stretch my technical understanding to great lengths in order to understand the abstract concepts behind the product I support, but I have also had to hone my customer-facing skills as I have grown accustomed to sending dozens of emails each day and participating in several impromptu conference calls throughout the week.  I also became very adept at writing knowledgebase articles and other technical documents to help my colleagues in diagnosing various issues relating to FAST VP and its counterpart technology known as Virtual Provisioning.  (I'm not even going to attempt to explain this concept, as it's much more complex than even FAST VP!)

This job has been really wonderful, and yet very stressful at the same time.  More than occasionally would I go twelve hours without eating anything because I had to work through my lunch, and would come home with throbbing headaches from swiveling between my four workstations.  But on the whole, I really loved my job and felt like I lived up to expectations.



You may have noticed that I have been using the past tense when describing my job.  That is because I announced today to my team that I have taken on a new role as a TSE II in the RSA Security department, supporting the Security Analytics (also known as the NetWitness) platform, which is a tool for identifying and putting a stop to hacker infiltration attempts.

As I obtained my degree in IT Security, this has been pretty much what I would call my "dream job."  I always wanted to work in the IT Security field, keeping hackers at bay and fighting the virtual battle on the cutting-edge of technology.  I now hold a position in one of the leading IT Security companies worldwide.


This role is going to be much different than supporting the Symmetrix storage arrays, as I will be forgetting about hexadecimal error codes and proprietary software commands, and will instead be returning to my Linux roots, which I couldn't be more excited for.  I'm also being sent on a two-week business trip to Washington DC and Virginia in a few weeks for extensive onsite training to learn more about the product that I'll be supporting.

To say that I am excited would be an understatement.  This job opportunity also came at the perfect time, as Whitney and I will be having our first child at the end of March, and have had a lot to do in order to prepare for his arrival.  It really was a blessing that I discovered the offer when I did, so that I could take advantage of it and make this huge change in my life.

While I'm afraid of leaving the Symmetrix team, especially as I will be putting the burden of my role onto others' shoulders, I definitely feel like this is the right move for me at this time, and that I am doing what is in the best interest of my growing family.  But I am also so relieved and grateful that it includes starting a role in the job I've always dreamed of having.

Here's to the future!

Monday, April 9, 2012

Anatomy of a Phishing Scam

As my Information Technology major in school has a concentration in network security, I have been learning a lot--especially lately--about the variety of tactics that hackers will use to compromise our networks, gain our usernames and passwords, and even steal our digital identities.

Also, as I work at a web design company and am now fluent and certified in HTML and CSS, two basic web programming languages, and have a general understanding of other languages as well, it has inspired me to take a closer look at the scams and "hacks" that we see--and often disregard--on a daily basis.

In this article, I will take a closer look and analyze three types of attacks:  A Facebook "hack," a mobile SMS (text message) scam, and the classic email scam.

The Facebook "Hack"

Everyone has seen what is commonly referred to as a "Facebook hack" or scam, and most people have grown wise enough to disregard them without a second thought.  These "hacks" can often be easy to recognize, as they are usually mass-distributed messages from your Facebook friends whose accounts have already been compromised, requesting that you visit some obscure URL (web address) to see an "outrageous video" or obtain some sort of special offer.

If these messages are uncharacteristic of the friend, such as a message to check out a viral video of a schoolgirl pole dancing in her dorm room when you know that the friend is devoutly religious and would never post such a thing, it should immediately raise a red flag in your head that the post is not legitimate.

However, sometimes mere curiosity or a cleverly worded scam might fool someone into clicking the link.  The screenshot below is of a scam post that was posted one of my friend's wall.  The post was published by one of his trusted friends, most definitely without their knowledge.


So, if someone posts something like this on your wall, or you notice it in Facebook's News Feed, how do you know whether or not it is legitimate or if it is indeed a scam?  Well, there are a few warning signs to look out for.

First of all, read the message in the screenshot above, and then ask yourself, "Is this how my friend actually talks?"  In this case, I don't actually know the person who left the message on my friend's wall, but I can clearly tell by reading it that it sounds more suitable to being spoken by a used car salesman and not somebody whose profile picture is of him on a walk with his daughter.

Second, I see the link to a URL that I don't recognize.  If it was a link to YouTube or CNN or another website that I had heard of, I would probably click on it without any question.  But if it is a site like the one above, I myself would be a bit skeptical about where it might take me.  Now, maybe this is just me being paranoid, but when it comes to Internet security, I live by the motto "better safe than sorry."

If I encounter a website that I wish to visit that could quite possibly be legitimate, I will oftentimes highlight and copy the URL, open an Incognito window if I am in Chrome (which is done by holding down Ctrl+Shift+N) so that it is not in in a browser window that is already logged into my Facebook account, paste the link in the address bar, and then go to the website.  Also, since I understand HTML and how to read it, if a site looks suspicious to me, I will first view it in its pure source mode by typing "view-source:" (without the quotes) into Chrome's address bar, followed by the URL.  However, this is more of an advanced technique.

The third sign that the post in the above screenshot is suspicious, which is most often a tell-tale sign of a Facebook "hack" is the information next to the timestamp on the post.  In the example above, it says "March 23rd at 1:24am via Check It Out!"  The mere fact that the post was done via some kind of Facebook app tells me that this individual must have clicked on a link that asked them to install an app on their Facebook account.  Before installing an app, you will always receive a notice of what permissions you are giving the app over your account, but most people disregard these warnings and proceed with the installation.  But without reading it, you may be opening the door wide open to your Facebook account to a malicious app and saying "Come on in!"  The app can then post on others' walls in your behalf, as seen above.

Now let's take a deeper look into what this particular post does.  I followed the steps I mentioned in a paragraph above to view the source code of the link, and discovered the following:


The link in the Facebook post actually had a trail of website redirects, meaning that going to that website would simply forward you on to another website, and then another, and then another.  Scammers will use this tactic to have several routes to their malicious trap, in case one or more of the web addresses get flagged as spam links and are blocked or present warnings.

Finally, I was able to trace the redirects to an actual website.  This website had code written to track a visit to the web page and reported the visit back to the Facebook app, in an attempt to "prove" to Facebook that it was a well-traveled page, attempting to fool its anti-spam filters.  After tracking the visit, the website would then promptly redirect the user to the final destination where, in this case, it would offer its free Six Flags passes.

If one were to actually view the website, it would look professional and raise no suspicions in regards to what it offers.  Essentially, it would look like any other website.  But a closer look at the code behind the page would tell a different story.


The first thing I noticed in the code is that it mentioned a number of tickets left, trying to get the visitor to hastily enter their information so that they could claim their ticket before they ran out.  However, the code says differently; the remaining number of tickets is static, meaning that it never changes.

The website would ask the visitor for their information as a way for the ticket to be delivered.  In this way the visitor promptly hands over their name, address, phone number(s), email address(es), and other information, which can be then be used to sell to third-party marketers, meaning that you'll be getting a lot more phone calls during dinner.  If the scammers are smart, they may also ask you to create a username and password, or what you think is a username and password.  Why would they do this?  Well, because many people use the same username and password for several accounts online.

Yesterday I had a friend approach me and have me look at an email that she had received, claiming that her Gmail account was going to be deactivated if she didn't click on a link and enter he login credentials. She did so and nothing happened.  I looked at the email, and noticed some tell-tale signs that it was a scam email that had somehow made it through the filter (but we'll get to email scams later).  After finding out that she had already provided her information to the false website, I asked her if she had another other accounts that used the same login credentials, and she said that her Facebook and even her PayPal account used the same information.  I told her to promptly go through the real channels to change those passwords, but what if she hadn't been warned?  How long would it have taken before her savings account had been emptied via PayPal?

In the Facebook example that I have been citing, I was actually impressed (for lack of a better word) that the scammers even took legality of their actions into consideration with their scam website, providing official Privacy Policy and Terms and Conditions pages...essentially "covering their bases."  This is what I found--in the code--when I viewed the Privacy Policy:


Notice how they blatantly say that they will be selling your information to third-party marketers and that you will be receiving special offers via phone calls, emails, etc.  The Terms and Conditions page showed a similar message:


The visitors may say to themselves, however, that "at least there is an unsubscribe button at the button of the page, so I won't receive marketing ploys if I don't want them, right?"  Wrong.  I viewed the source of the Unsubscribe page, and this is what I found:


Essentially, the unsubscribe page shows a form where they can enter their email address to unsubscribe from the offers, but in this case they are literally just going through the motions, because this form is simply an empty shell.  Although it looks like it submits the information, it never actually gets sent anywhere.  In other words, there is no unsubscribe option.

So, as you can see, Facebook "hacks" can have dire consequences, but only if you ignore your common sense and click on things that you probably shouldn't.

Text Message Scams

A few weeks ago, I got a text from an unrecognized number that my Google Voice account (which I love, as it's directly integrated with my Sprint phone) told me was from Washington DC.  The message told me that I had won a $1000 gift card from Walmart and could obtain it by entering a promo code at a certain website.


As crazy as it sounds, I didn't drop everything I was doing and click on the link while popping open a bottle of champagne when I got the message.  In fact, I even showed  it to my family, who said that they'd all received the same text message at different times over the past few days.  In fact, my mom said that she had heard a story on the news, mentioning a disgruntled ex-employee of Walmart that was sending out a phishing scam.  Whether this text is from the same source, I do not know.

I was curious to know what the link actually did so, like with the Facebook hack mentioned above, I used Google Chrome's "view-source" feature to check out the HTML code behind the "offer."  What I found was this:


Instead of routing the user through several domains like with the Facebook hack, this pulled up a page at the direct URL.  From looking at the HTML, it appears that the page displays a form which asks the visitor to input a variety of information to "claim their prize."  This input includes a first name, last name, email address, up to three phone numbers, and even a username and password.  The data is then submitted to a PHP file that is a server-side script that I did not have access to view.  But let's just assume that it doesn't use the data collected to generate a legitimate Walmart gift card and email it to the customer.

So what would happen if someone were to fall into this trap and fill out their information?  Well, first of all, that person would soon become fast friends with Mr. and Mrs. Spam.  Not just email spam, but text message spam as well, and possibly even telemarketing calls and/or scams.  (Is there a difference?)

If the visitor enters a username and password, they are compromising themselves in many ways, mainly because the majority of computer users tend to use the same username and password for several different accounts, as was the case with my friend mentioned in the previous case.

I would sincerely hope that people wouldn't fall into a trap as obvious as this, but if nobody fell for them, then scammers wouldn't take the time to generate false websites, so it definitely makes me wonder how many people were caught in the Walmart Scammer's net.

Spam Emails

Everyone hates spam email, but thanks to sophisticated filters within web-based email services like Gmail and Hotmail, many of us never have to deal with them unless we decide for some reason to go exploring in the Spam or Junk folder.

Another nice feature that has been incorporated into such web-based mail systems is the validation of emails from particular companies to prove their legitimacy, especially financially-related emails such as from banks and PayPal.  Hotmail, for example, will show a green shield next to emails like these.


But phishing scammers still try to catch those that are less vigilant with similar emails.  I have always been a fan of web-based email systems--Gmail in particular--and often wonder how well applications such as Microsoft Outlook, Mozilla Thunderbird, and others detect spam messages.

There are many tell-tale signs that can be used to detect whether or not an email is from a legitimate source.  Let's take the following email that I found in my own spam folder as an example:


The first warning sign, obviously, is the warning message displayed in red by the email system itself, warning the user that the email appears to be malicious in nature.  However, the other signs may be obvious to some yet more subtle to less-experienced users.

The wording of the email itself is at least attempting to sound professional, but for a company as renowned as Chase bank, I would expect something a bit more formal.  Also, if the user wasn't already mentally blinded by panic at having his or her account deactivated, it would be hard not to raise an eyebrow when seeing that the email from Chase Bank was supposedly sent from an email address from a very strange domain, being email.discover.com.  If it was a legitimate email from Chase, wouldn't it come from an email such as abuse@chase.com or something similar?

On a similar note, it is curious that the web link itself is from a strange domain, being fbren.com, as opposed to Chase's actual website.  These are things that I notice in a heartbeat and even laugh about, when others may not even notice in their panicked hurry to reactivate their supposedly canceled account.

Wanting to see where exactly this link would take me, I once again used the "view-source" feature in Chrome to view the HTML behind the so-called "re-activation website."


I noticed that, like the first example in this blog, this website also had an immediate redirect to another website.  However, this website was quite clever in its redirect, if it's not too ironic to say so.  They used an IP address as the domain, as opposed to an actual registered domain name, and then named the subdirectory of the site in such a way that the visitors would perhaps not notice the actual address and believe in its legitimacy.

Curious to know where the attackers originated, I used a simple WHOIS command in my Linux terminal, which gave me all the information I needed to know about the hackers:


It was interesting to note from the information above that the attack was actually originating from a university in China, meaning that some bored students were performing a scam right under their instructors' noses...and doing so from the school computers.

Knowing that this website was obviously a known phishing/scam website, and being very confident in the security of my computer and firewalls, I decided to take the plunge and click on the link--using the "view-source" feature, of course--to see what would happen.  Sure enough, I was immediately presented by a warning sign from Google Chrome, warning me about visiting the website in question.


Viewing the HTML code, it was very clear to me that this was web page that was designed to look identical to a legitimate page provided by Chase, complete with logo and color scheme.  However, when the visitor entered their information, it would be submitted to a PHP file called login, which would most likely execute code to capture the visitor's login information and redirect them to the actual home page of Chase Bank, so as to remove any suspicion.


And thus we see exactly how an email phishing scam works.

Conclusion

Having a strong background in Information Technology, especially in Internet security and web development, I look at all of these attacks and laugh to myself, thinking that there is no way that anyone could ever fall for such a thing.  Yet, as mentioned previously, hackers wouldn't spend so much time meticulously designing these traps unless they had at least enough people fall into them to make it worth the effort, which is highly alarming.

Kevin Mitnick, one of the world's most renowned hackers and--believe it or not--a personal hero of mine because of his vast well of knowledge of the Internet security world, recently said a quote on his Twitter feed that really makes sense with everything that I have mentioned in this post:  "Send a man a phish and he will click on it.  Teach a man to phish and 10,000 people will click on it."

It is shocking that, in such a day and age where computers and technology are so prevalent in our lives that so many people are still ignorant to the risks they take each time they click on their web browser.  But as long as they are vigilant, they need not fall into the traps that lay waiting.