Showing posts with label identity theft. Show all posts
Showing posts with label identity theft. Show all posts

Tuesday, February 28, 2012

Men Show Up Wanting Sex After 'Ex Posted Fake Craigslist ads'



By Mark Duell

(U.S.A.) A jilted boyfriend allegedly placed a series of fake adverts on Craigslist that appeared to be from his pregnant ex-girlfriend asking men for sex.

Andre Flom, 31, of Portland, Oregon, put up ads with her number and address - and up to 20 men would arrive at her home for sex, police said.

Postings under the name of Catlin Moser, 29, said ‘hit me up - I’m super horny’ and that she wanted ‘guys to take turns giving it to me good’.

The posts also asked people to remove a Japanese maple tree and a play structure from her garden, reported the Smoking Gun website.

‘He was posting my name, my phone number and my address on Craigslist for really obscene sex parties,’ Ms Moser told Fox affiliate KPTV. I was having men showing up at my house all hours of the night.'

He even allegedly posted the contact details of Ms Moser’s mother, who said she would get around 100 obscene text messages in five minutes. ‘The kinds of things that were being said were pretty obscene,’ the mother told CBS affiliate KVAL. ‘He'd set up times for them to come over.’
CONTENT OF THREE ADS ON CRAIGLIST

'What's up, my name's Catlin and I’m very real, looking for a sexy guy to come give me what I need, hit me up - I'm super horny'

'Having a party tonight at my house: encourage single guys to come through, lots of beer and single women, here is a recent pic of me, my name's Catlin, let's go boys'

'Hey, so I'm at home bored, lookin for a guy, or guys to take turns givin it to me good'

It began in October after Flom was convicted of domestic violence and more than 35 adverts were posted on the listings website, police said. Flom was convicted of strangling Ms Moser, who has a two-year-old son, last autumn and she won a restraining order against him.

One of the ads included her address, saying: ‘I’m very real, looking for a sexy guy to come give me what I need, hit me up - I’m super horny’. Another said she was ‘sitting at home bored’ wanting men to ‘give it to me good’ and was inviting people who ‘want to get a little dirty’.

Investigators subpoenaed Craigslist to give them records that showed nearly all of the fake adverts came from the same network location.

In a twist, investigators traced this to Flom’s next-door neighbour. But it turned out the man had an unsecured wireless router in his house. Police raided Flom’s home on Tuesday and took away a computer, modem and mobile phones, reported the Smoking Gun.

Flom was charged with computer crime and identity theft and is being held in Multnomah County jail in lieu of posting a $30,000 bond.

Wednesday, January 25, 2012

Online Dating Hunting Grounds for Romance Fraudster

A Ghanaian man accused of posing as a US soldier on an online dating site has been arrested on suspicion of conning a British woman into sending £271,000 to Africa.

In what is thought to be the biggest case of its kind so far, police detained Maurice Asola Fadola, 31, who is thought to be behind a series of "romance frauds" – targeting women through dating sites, and fabricating an elaborate series of stories to convince them to send money to Ghana.

The British victim, who did not want to be named, struck up a relationship over the internet with a man she believed to be an American soldier serving in Iraq.

After several months of correspondance, in which he told of his life dodging bullets and bombs, he told her that he was leaving the army – and perhaps they could meet up. But while his luggage was being returned to the US, there were a series of "problems" which the British woman was enticed into helping out – to the eventual cost of £271,000.

The head of the Ghanaian Serious Fraud Office described Mr Fadola as a suspected "kingpin", and his arrest after months of painstaking intelligence gathering is the high point of a joint Ghanaian-British campaign against alleged romance frauds.

Last month officers from the Serious Organised Crime Agency (SOCA) travelled to the Ghanaian capital of Accra to work alongside Ghanaian police in arresting Mr Fadola.

Officers had planned to mount a "sting" operation; setting traps for when he came to collect money they had sent to a money transfer service, or lying in wait for him to pick up a parcel of laptops or mobile phones from the Post Office.

Police froze his bank accounts, and when he came into the Serious Fraud Office in Accra to try and brazen his way into releasing the funds, he was arrested.

Mr Fadola, who lived in a luxurious mansion on the outskirts of Accra, is being held in custody and questioned over money laundering and passport offences, which carry a maximum sentence of 25 years.

Colin Woodcock, head of SOCA's fraud department, said that his team was working alongside Ghanaian authorities, sharing policing techniques with local forces to track down the fraudsters.

"At first we thought it was just people sending £50 here or there," he said, "but although the bulk are small frauds, now we know that some people are being robbed of hundreds of thousands.

"It's an international problem, involving police forces from across the globe working together to squeeze the criminals."

More and more cases of romance fraud are being discovered.

In August last year Philip Hunt, 58, threw himself under a train after losing £82,000 in a romance fraud. He had met a Nigerian girl on the internet, who convinced him to spend the money with promises of starting a life together.
"These people are out to get people when they are very vulnerable. They're in there like vultures," Lesley Smith, Mr Hunt's former partner, told the inquest into his death.

Mr Woodcock said: "The bottom line is: don't give anyone your money. Imagine you'd met someone in a pub for the first time, and they said I'd love to see you again but can you buy me a laptop?

"We're seeing an explosion in this. Everyone is on online dating nowadays, and criminals have cottoned onto it. These people destroy lives. It's loss on a catastrophic scale."

2 of EOPC's examples:
Nathan Ernest Burl Thomas, Jr.

Doug Beckstead

Thursday, January 5, 2012

In Just One Hour Online...


It took just one hour for internet experts to find out almost every private detail of one woman's life

Steve Boggan challenged web experts to see how much they could discover about his partner. The results were chilling...

As I sit writing this, I am feeling vaguely grubby — guilty even — in the way a neurotic husband might after hiring a gumshoe to go trawling through his wife’s secrets.

There is a 15-page report in front of me chronicling virtually every aspect of my girlfriend’s life: past and present. That includes her friends, education, embarrassing pictures, former boyfriends and long-forgotten relatives.

Much of the information is new to me. And the uses to which it could be put — uses I hadn’t dreamt of until this week — are chilling.

Armed with this information, criminals could use her identity to commit fraud or resurrect minute details of her past, her movements and friendships to lure her into scams or even dangerous liaisons.

It could be used to con her into revealing her bank details and credit card numbers.

My internet snooping began because the CEO of Google, Eric Schmidt — a man not known for worrying about internet surfers’ privacy — suggested recently that young people might want to change their identities in the future in order to separate themselves from a past lived too openly on the internet.

We all know Facebook pictures of you dancing at a party with a traffic cone on your head might come back to haunt you. But change your identity completely?

Surely, I wondered, there isn’t enough out there to warrant that.

So I decided to find out how much I could discover about my partner of 12 years, Suzanne, just by using the internet.

Before you think I’m a rat, I should point out that Suzanne, a 39-year-old with a soft furnishings business, agreed to it.

I began in the way lots of identity thieves do: with her name and address. Of course, I knew these details, but identity thieves often discover them by ‘dumpster diving’: looking through dustbins for a discarded piece of mail.

I passed Suzanne’s name and address — but no other details — to Adam Laurie, a 48-year-old computer security and internet privacy advocate.

He shared the information with Chris Sumner, 39, another security expert, who works for a multi-national corporation.

Or at least, that is Sumner’s day job; by night, he analyses vast amounts of information publicly available on the internet to see what it can tell him about criminal activity — in this case, how fraudsters are using social networking sites to choose their victims.

Using sophisticated and completely legal computer techniques, he looks for patterns in the behaviour of internet users to uncover otherwise hidden links.

In the case of social networking sites, he can see just how close two people, or groups of people, really are to each other.

He had met neither me nor Suzanne and knew nothing of her existence until given her name and address.

A day later, his findings dropped into my email inbox.

Picking Suzanne’s life apart, he told me, had taken him just over an hour.

This is because, in common with millions of people in Britain, Suzanne uses the social networking sites Facebook and Friends Reunited, and has signed up to the business networking site LinkedIn and Flickr, the photo-sharing website.

By also using the genealogy website ancestry.co.uk, Sumner was able to piece together the names of all but one of Suzanne’s relatives, including cousins.

Using electoral rolls on 192.com and by searching on Google, he found the addresses of her parents and lots of her friends and colleagues.

From her LinkedIn and Facebook profiles, he found the names of Suzanne’s primary and secondary schools, and a college she had attended in Derby. He also discovered she had studied fine art at Central St Martin’s College of Art & Design in London.

He also had details of Suzanne’s qualifications and pictures of her from her days at school. The snaps weren’t hers — an old schoolfriend had put them on Facebook.

There were some naff hairstyles, but that was as deep as the embarrassment went. Only you know whether a trawl of pictures of you would be more damaging.

But Sumner didn’t stop there. He was able to tell me that Suzanne had travelled extensively in Europe, Asia, the Caribbean and the South Pacific.

This was because she had used an application on Facebook that linked to the travel website TripAdvisor. You fill in where in the world you have been to keep your relatives up to date. But anyone can see it.

He was not only able to list all 41 countries she had visited, but also the 162 towns and islands to which she had been.

Sumner was able to tell me Suzanne’s exact movements by cross-referencing her TripAdvisor entries with photographs she had posted on Flickr.

When you click on a picture on Flickr, a small box gives you access to detailed information that is entered not by you, but by your camera. So, the date and time of the shot are included.

Now that phones and cameras have GPS, there are even concerns that the location of where you uploaded the picture — normally where you live — might be visible.

From a mixture of all of these websites, Sumner listed Suzanne’s likes, dislikes, hobbies, the 34 towns and cities she had visited in Britain, the places where she used to socialise in her youth and details of her former jobs in the newspaper industry.

In fact, it’s fair to say that after just one hour’s trawling he knew more about many aspects of my girlfriend’s past than I did.

Shocking? Perhaps. Yet also astonishingly easy. Suzanne had voluntarily signed up to these websites and, bit by bit, put most of this information out there herself — and forgotten much of it.

However, what I found even more disturbing is that much of what Sumner found was supposed to have been visible only to people whom Suzanne had accepted into her inner circle of ‘friends’ on each networking website. This turned out to be dangerously naive.

Over the years, standard privacy settings— notably for Facebook — have changed, so what you once thought was private has become public.

You are notified about these changes, but if you forget to adjust your individual settings to return to the old level of privacy (which can be fiendishly complicated) then some of your private information becomes available for everyone to see.

‘There are some weird, strange quirks that let you into places you aren’t supposed
to go,’ says Sumner.

‘For example, on Facebook you may not be allowed to see someone’s photographs because they’re private. But if they post a message with one of their photos attached, you are given the option of seeing their whole album. And as you can imagine, that can be embarrassing.’

According to Sumner and Laurie, organised criminals are using this information
in increasingly sophisticated ways to target victims.

‘Criminal gangs are carefully fishing for victims,’ says Laurie. ‘In the past, they would have sent out thousands and thousands of spam emails in a scattergun fashion — and many still do.

‘These are called phishing scams and involve fake requests from banks asking
people to confirm their account details, passwords and so on. The hope is that, once in a while, someone would be silly enough to reply.

‘Today, they are much more targeted. For example, with the information we got about Suzanne from Flickr, you would be able to see where she visited, when, and, if there were captions on the pictures, with whom.

‘After that, the criminals (or romance scammers) would tailor a scam. If they noticed that, say, she was a regular visitor to Malawi, they would make an introduction online, claiming they were a friend — for example, called Dave — of someone she visited there with five years ago.

‘Surely she remembers them? From that beach — her friend was there, too ... yes?

‘Usually people are too embarrassed to say they don’t remember. Then ‘‘Dave’’ claims he is setting up an orphanage — would she like to make a contribution towards it?

‘Or they might simply say they’re a friend of a person you were with and say he’s gone back there, broken his leg and they’re having a fund-raising collection to airlift him home. It’s crude, but effective.’

Sumner says it can get even more complex, with software tools that can work out who is friends with whom among your online groups of contacts.

‘Once you have established a person’s inner network, you go back into their history to find someone they knew at school who isn’t in that network of close friends and who hasn’t signed up to networking sites,’ he says.

‘Then you join those sites in their name, establish yourself with their online identity and ask your original target to accept you as a friend on, say, Facebook.

‘Before you know it, you are inside their life as a trusted person they think they used to know.

‘Once you are in, you can read about what your target and their friends are up to, such as when they are going on holiday. With that information, you can burgle their homes.

‘You can even ask to be Facebook friends with their children. This is a particularly frightening way for someone to stalk you or your family. They can introduce themselves as a Facebook friend of Mum or Dad. And then it’s only a couple of steps away from something awful happening.

‘Teenagers, in particular, are very indiscreet and post hundreds of pictures of themselves, sometimes drunk with their friends in the living room in front of the plasma screen TV or home cinema.

‘Not only are these the sort of pictures that will come back to haunt them in the future — potential employers aren’t supposed to look at these, but they do — but it’s also a dumb way to show burglars what property you have and where it is.

‘Especially after your children have told all their “friends” when the house is going to be empty.’

Sumner described how some of the information he gained from Suzanne would have helped him to get hold of her bank and credit card details. I won’t reveal exactly how he did it, but it involved using some of her social networking information to gain her confidence, then posing as a friend and asking if her business would make some curtains for him with a sample of material he’d seen on another website.

The catch would be that he had set up that other website himself and when she visited it some rudimentary programming he had installed would help him acquire her credit card details.

I ask Suzanne if she would have fallen for the scam. ‘It’s hard to know, but based on what he said, why wouldn’t I have gone along with the requests of a potential customer?’ she says.

There are other ways, too, that criminals can use personal information harvested from the internet. For example, people often use the names of their children or
pets as passwords for online shopping sites.

If criminals can find these names, by gaining access to your social networking circle, they can try to hack into your accounts on popular shopping sites such as Amazon and view your shopping history, or even order expensive goods to be sent to a pick-up address. (I did not ask Laurie or Sumner to attempt this because it would be in breach of data protection law.)

What can we do about all this? Well, not a lot, other than to be aware your information can be used in more sinister ways than you can possibly imagine, and to be on your guard.

As for your children, they can be warned to modify their behaviour and to think twice about what they write and post online and whom they accept as ‘friends’.

According to Linda Weatherhead, principal policy advocate for the campaign group Consumer Focus, social networking sites bear much responsibility for this explosion of potentially useful information.

‘It is a complex problem, but one simple way of making things safer would be to have all our information kept private as the default setting,’ she says. ‘Then it would be up to you how much you want to relax them as you decide to share more of your private
information.

‘Beyond that, we just have to be careful what we put out there — you can advise children about what they are doing, but you can’t wrap them in cotton wool. You can never make anything completely safe.’

But if Adam Laurie and Chris Sumner are right, then the risks of social networking extend far beyond a few embarrassing photos.

In particular, be careful who your ‘friends’ are; they could turn out to be your worst enemies.

Monday, November 7, 2011

When Your Online Life is Hacked


By Rowenna Davis

(NEW ZEALAND) In a technology-driven society, when an account gets hacked, you're suddenly hit with an organisational bombshell as the realisation dawns that the email account is the nexus of the modern world.

For the past week, a hacker has been occupying my email account. And he or she may still be there. A disembodied intruder, this person has been stalking my inbox, replying to messages, signing off with my nickname and refusing to let me in. He or she has been going through my personal history and making judgments about my character.

In the weirdest twist, the hacker even started writing to me. If it wasn't so unsettling, it could be the plot of a black postmodern comedy.

It started when my phone went crazy in the middle of a crucial meeting. Some 5000 contacts received an email from my account saying that I'd been held up at gunpoint in Madrid. My internet-savvy friends sent texts to say I'd been hacked, while my elderly, migrant and more vulnerable friends wanted to know where to send the cash. According to the story, my mobile phone and credit cards had been taken and I was badly in need of money. There was a number to call to reach me at my hotel - presumably chargeable - and a Western Union account had been set up in my name to wire a transfer.

Suddenly you're hit with an organisational bombshell: drop what you're doing; freeze your bank account, answer anxious calls, lose crucial messages; miss work deadlines, irritate bosses, reset all email-based passwords, forget to pay e-bills, irritate friends who think you're ignoring them. The realisation dawns that the email account is the nexus of the modern world. It's connected to just about every part of our daily life and, if something goes wrong, it spreads.

But the biggest effect is psychological. On some level, your identity is being held hostage.


Out of sheer frustration, I fired off an email to my occupied address labelled "to those who hacked my account", laying out how I felt and asking for my contacts. Shockingly, I got an almost instantaneous reply. The hacker said my address book would be returned for £500 ($989). It was unreal. Whoever it was must have been watching my account and responding. Who else was this person replying to in the same way?

I wrote back straight away, saying that I didn't have those kind of finances and pointing out that I had no reason to believe the deal would be kept even if I did send the money. I couldn't help but end with a rhetorical: "Do you ever feel even slightly bad about what you are doing?"

Just for a minute, the hacker seemed anxious to prove that he or she had any sense of morality. The reply: it "didn't feel great" to be a hacker, but they didn't have a choice. Why? They said their life "wasn't as nice and sweet" as mine. In what I guess was supposed to be a gesture of magnanimity, the hacker promised to release my contacts for just £300, and even offered to send me 20 contacts upfront as a sign of "goodwill".

I could tell this person thought this was being reasonable - that these actions weren't as bad as robbing people on the streets.

What I wanted to reply, but found difficult to articulate at the time, was that hacking can be worse than that. When someone holds you up in the street, you lose a set of isolated possessions and then get to walk away. But if someone colonises one of your chief platforms of interaction with the world, there's always a feeling of "what next?" They can read your most intimate emails and potentially pass them on. A simple search would allow them to find out not just my address, but also those of my friends and family.


Apparently around 3000 people reported such scams last year, but too few of these are brought to justice. When I did eventually get access to my account through Gmail a week later, I found that the hacker had written to more than 30 people who had asked about my problems in Madrid. The intruder said I'd had a "terrible experience" and signed off with my nickname, "Row". That someone could be so callous to people who cared about me - in my name - left me furious.

I was lucky. The only reason I was able to regain access to my account was through chance - a friend of a friend works at Google. Until then, my hacker had given me better feedback than Gmail and Google, following my attempts to get in touch with them. The company that presents itself as the friendly face of the web doesn't have a single human to talk to in these circumstances. The office just cut me off and, after a friend waited on hold for 20 minutes to ask if there was anything that could be done to help, the reply was a simple "nope".

When someone did bother to look into my problem, it took only five minutes to fix. The hacker had doubled the verification process on my password so I couldn't get in. Once Google disabled it from the inside, I was able to reset all my security checks without a problem.

Even now, I'm not sure it's over. In one last message, addressed from myself just two days ago, the hacker wrote: "I see you got the account back. Sorry for the trouble." I never replied, so I guess I'll never know what this individual's circumstances were. But I feel the need to understand them. Perhaps we believe that if we find reasons for things, we'll feel safer. Perhaps it's about restoring faith in human nature.

However, my hacker seems to have disappeared back into the ether. Of course, they could be reading this now.

Chatting with a hacker


Tuesday, 8.33am
From: Rowenna Davis
Hi, I can't believe you would do this. The poorest, most vulnerable of my contacts are the most worried about me and most likely to send you money. The most educated people with resources know it's a scam. I also find it difficult to make ends meet, but without access to this account I can't work because all my contacts are stored in the account you have taken over. I am totally paralysed. If there is any way you can send me my address book, I would be willing to pay for it. It's horrible to be forwarded messages that have been sent in your own name. I honestly don't know how you justify this to yourself.


8.42am
From: the hacker
Can you send me 500 quid?

10.33am

From: Rowenna Davis
1) I literally don't have 500 quid to give you. I can't make any more money until I have access to my account back - I work freelance and all my work contacts are being held by you. 2) How would I know if I gave you any money that you'd actually send me my contacts? 3) Do you ever feel even slightly bad about what you're doing?

10.38am
From: the hacker

Sure I don't feel great, but I don't seem to have a choice, it's way better than robbing you on the streets. I give you my word, if you send me money, I will give you back access to you account with all your emails and contacts intact. If you can't send 500 quid at least 300 quid will do. Send money by Western Union to Rowenna Davis Madrid Spain. Waiting


10.40am

From: Rowenna Davis

Why don't you have a choice?

10.44am
From: the hacker

You don't wanna the kinda life I am living. You think it's as nice and sweet as your life? But at least I don't rob on the streets


10.56am

From: Rowenna Davis
I'm not making judgments about your life - you are making judgments about mine. If you read some of those emails you'll know it gets pretty shit at this end too. And even if my life was really happy, I don't see why that justifies you taking over my emails. But I wonder why you feel that you have no choice.


10.58am

From: the hacker
Are you sending money?

11.17am

From: Rowenna Davis
I don't have £300. I have asked some of my friends if they can help, but they think it's a stupid idea because you can't be trusted to return the details.

11.23am
From: the hacker

I don't need your details for anything, to show some good will I could give you about 20 contacts, then when you send money, I give you the rest of it.

Thursday, 11.04pm

From: the hacker

I see you got back your account. Sorry for the trouble.


original article found here

Thursday, November 3, 2011

Sentenced to Prison for Net Harassment, Stalking and E-Personation

by LUIS HERNANDEZ

A Tulare man who authorities said harassed, repeatedly threatened and falsely impersonated a woman on the Internet was sentenced to 32 months in state prison Friday.

Michael Rosa, 36, received his sentence after being convicted of stalking, false impersonation, identity theft, and electronic harassment last month.

According to the Tulare County District Attorney's Office, while they were married, Rosa often threatened to kill the woman, whose name was withheld.

Rosa made numerous harassing telephone calls to her, the district attorney's office said. In April of 2009, the threats escalated, with Rosa calling and telling her he was on his way to kill her.

According to the district attorney's office, on August 2009, the woman began receiving calls from unknown men contacting her about an advertisement posted on Craigslist.

Investigators learned that Rosa had previously placed numerous ads on the Craigslist website, pretending to be the woman, the DA's said. The ads identified her by name and stated she was willing to perform sexual acts on men.

Several of the ads contained photographs that were taken during the course of the marriage, the district attorney's office said. Authorities said detectives were able to trace the online ads back to Rosa, who was interviewed and eventually admitted to placing the ads.

Detectives also secured evidence from Rosa's Internet provider and Craigslist linking the ads back to Rosa.

Tulare County Superior Court Judge Gary Paden sentenced Rosa.

Friday, October 7, 2011

New 'Stalking' App for Mobile Phones Due Out Soon


(UNITED KINGDOM) A new social networking tool allows mobile phone users to identify people just by taking a photo.

The 'recogniser' application gives any mobile phone owner access to almost all online information about anyone they photograph.

IT expert Charlie Brown has expressed concerns about the application, saying it's a walk up start for stalkers and could see an increase in identity theft cases.

'You can pretty much know everything about (a person) that is listed on the internet within about 30 seconds,' he said.

Facebook and Twitter accounts and business cards become available when recogniser matches an image of someone's face online.

Software developer Dan Garden says there is a lot of ways to use the application sensibly.
'During a party, you might want to figure out some more information about the person standing across the room from you.'

Police and government agencies use a similar device to identify criminals.

The application could be on mobile phones around the world by September 2010.


original article here

Monday, July 25, 2011

Man Gets 18 Years in Prison for Internet Harassment


By Kat Asharya

A Minnesota (USA) hacker received 18-years in jail for cyber-harassment against his neighbors, demonstrating the chaos that hacking can cause on a personal level.

Barry Ardolf, 46-year-old angered his neighbors, Matt and Bethany Kostolnik, after kissing their young son. Ardolf then allegedly hacked into the Kostolniks' Wi-Fi router and hijacked e-mail accounts to frame them for child pornography, sexual harassment and professional misconduct.

"Barry Ardolf has demonstrated by his conduct that he is a dangerous man. When he became angry at his neighbors, he vented his anger in a bizarre and calculated campaign of terror against them," said prosecutor Timothy Rank in a court filing. "And he did not wage this campaign in the light of day, but rather used his computer hacking skills to strike at his victims while hiding in the shadows."

For example, Ardolf created a fake MySpace page for the husband, where he posted a picture of young teens engaged in sexual activity. He then e-mailed child porn to Kostolnik's co-workers at a law firm using Kostolnik's e-mail account, in addition to sending flirtatious messages to women in Kostolnik's office.

However, Ardolf pushed too far when he used the Kostolnik accounts to send a message threatening Vice President Joe Biden, which drew the involvement of the Secret Service and FBI. Working with packet sniffers installed by Kostolnik's law firm on its network, the federal agencies pinpointed Ardolf.

The FBI got a search warrant for Ardolf's house and computer, where they found large amounts of evidence, including hacking manuals and data copied from the Kostolnik's computers. They also found handwritten notes laying out Ardolf's detailed revenge plans, as well as messages for the family.

"I told you about a year ago that you should be very afraid. I can destroy you at will, you sorry-ass excuse for a human," one letter said.

Ardolf's campaign of cyber-intimidation may be small in scale in comparison to the spate of hacker intrusions into corporations and government websites over recent months, but it is a reminder of how deeply entrenched technology is with everyday life, and how more and more consumers must be vigilant against security threats.

"Over months and months, he inflicted unfathomable psychic damage, making the victims feel vulnerable in their own home, while avoiding detection," said Rank.

In addition to the 18-year prison sentence, Ardolf, who had no previous criminal record, forfeited his house and computer gear. Further investigation revealed he also hijacked the Wi-Fi networks of other neighbors and harassed them as well. He eventually pleaded guilty to identity theft and two child pornography accusations carrying lifetime sex-offender registration requirements.

ORIGINAL ARTICLE HERE

Monday, June 20, 2011

Technology Used by Criminals to Track or Find Victims


by Tom Smith

Instead of lurking in bushes or hiding in the shadows outside of homes, stalkers have gone high-tech, using cell phones, computers and the Internet to hunt and track their victims.

"I know of some cases where people were stalked by e-mail or through Facebook or another social networking site," said Bryan Oakley, an agent with the FBI's Huntsville office who specializes in Internet crime.

He said technology is so advanced that tracking software can be added to telephones, cell phones or laptop computers.

"(Cyberstalking) is something that five years ago would be difficult to do, but there are more people using technology every day," Oakley said. "A lot of people use Twitter or Facebook to file what they are doing and where they are doing it, every minute of the day.

"People put out information about where they're traveling, where they work, pictures of their car, their friends, or themselves. They put out all the information someone stalking another person would need to know."

According to statistics released by the Rape, Abuse and Incest National Network (RAINN), in Washington D.C., there are 3.4 million stalking victims each year. Of those, one in four victims said they have experienced a form of cyberstalking.

Alexis Moore said most people are naive about the problem.

"They have the mindset of 'it's not going to happen to me.' It does; it happened to me," said Moore, a California resident who was stalked by a former intimate friend.

"He was opening and closing my bank accounts," she said. "He never went as far as stealing from me, but I was not able to cash a check because he was making it where I was overdrawn all the time," she said. "He was going online, paying my bills on my accounts with money I didn't have, trying to ruin my credit."

She said the actions were not classified as crimes, but it was a nuisance.

"I never thought something like this would happen to me," Moore said.

To put a stop to the problem, Moore "shut down everything and lived off cash for a while."

"It was a sinister game to him, just trying to drive me crazy," she said.

Phil Bridgemon, instructor and chairman of the Criminal Justice Department at the University of North Alabama, said cyberstalking is the new wave of crime.

"People need to take this very seriously," he said. "Knowing this should cause everyone who uses a computer to manage their online identity better and more closely. There are no secrets; there is no modesty."

He said would-be stalkers search social networking sites, profiling people in hopes of finding a victim.

Katherine Hull, vice president of communications for RAINN, said people need to be aware of what they are putting online.

"People get online, and they think their activity is anonymous, but it isn't," she said. "They post things, get in a chat room and say something that leaves themselves wide open to becoming a victim of cyberstalking.

"Technology is a wonderful thing, but it opens us up to be vulnerable."

Bridgemon agrees.

"Because of the information that we put out there on the Internet, stalkers can follow someone around and never leave their home," he said.

Parry Aftab, a spokeswoman for Wired Safety, an online safety group, said people need to be taught digital hygiene.

"They have to be taught how to use the Internet and social networking systems in a safe manner," she said. "Unfortunately, that's something that people never think of before it's too late.

"Not only do they not see this coming, but they don't know they need to see it coming," Aftab said.

"We have got to do a better job in educating the public about this growing problem."

Michelle Collins, an official with the National Center for Missing and Exploited Children, said her agency has had a cyber tip line for 12 years in an effort to learn more about cyber crimes.

"Last year, we received 120,000 calls," Collins said. "Many of those were about cyberstalking."

She said cyberstalking often leads to physical assaults.

Collins said there was an incident in Wyoming where an ex-boyfriend put a posting online claiming his ex-girlfriend had a rape fantasy and needed people who would fulfill that fantasy.

"They actually showed up at her house and raped her," Collins said.

Franklin County District Attorney Joey Rushing said there is no one definition of a cyberstalker.

"They come in all shapes, sizes, ages and backgrounds," he said. "They patrol Web sites looking for an opportunity to take advantage of people."

He said in Alabama cyberstalking falls under the stalking law, which is a felony.

Sheffield Police Chief Greg Ray said a few years ago his department worked on cybercrimes trying to catch people who were using the Internet to prey on underage girls. He said in setting up sting operations, three people, two from other states, were arrested.

"What they were doing was basically stalking these children or the profiles of these children," Ray said.

Hull said RAINN tries to stress the importance of being careful with information put on the Internet.

"We are living in an age where people are living a vast part of their lives online. That's why we encourage folks to think twice about what kind of information they put on the Internet," Hull said.

"Criminals take advantage of any tools they can, and (the Internet) is just another new tool at their disposal," Oakley said.

Moore said there have already been too many victims of cyberstalking.

"It's an invisible crime, one where the victim is usually not beat up or one where we can see the criminal," Moore said. "The answer is education, starting at the younger ages, teaching school-age children how to use technology the right way - the safe way."


Technology Used by Criminals to Track or Find Victims


by Tom Smith

Instead of lurking in bushes or hiding in the shadows outside of homes, stalkers have gone high-tech, using cell phones, computers and the Internet to hunt and track their victims.

"I know of some cases where people were stalked by e-mail or through Facebook or another social networking site," said Bryan Oakley, an agent with the FBI's Huntsville office who specializes in Internet crime.

He said technology is so advanced that tracking software can be added to telephones, cell phones or laptop computers.

"(Cyberstalking) is something that five years ago would be difficult to do, but there are more people using technology every day," Oakley said. "A lot of people use Twitter or Facebook to file what they are doing and where they are doing it, every minute of the day.

"People put out information about where they're traveling, where they work, pictures of their car, their friends, or themselves. They put out all the information someone stalking another person would need to know."

According to statistics released by the Rape, Abuse and Incest National Network (RAINN), in Washington D.C., there are 3.4 million stalking victims each year. Of those, one in four victims said they have experienced a form of cyberstalking.

Alexis Moore said most people are naive about the problem.

"They have the mindset of 'it's not going to happen to me.' It does; it happened to me," said Moore, a California resident who was stalked by a former intimate friend.

"He was opening and closing my bank accounts," she said. "He never went as far as stealing from me, but I was not able to cash a check because he was making it where I was overdrawn all the time," she said. "He was going online, paying my bills on my accounts with money I didn't have, trying to ruin my credit."

She said the actions were not classified as crimes, but it was a nuisance.

"I never thought something like this would happen to me," Moore said.

To put a stop to the problem, Moore "shut down everything and lived off cash for a while."

"It was a sinister game to him, just trying to drive me crazy," she said.

Phil Bridgemon, instructor and chairman of the Criminal Justice Department at the University of North Alabama, said cyberstalking is the new wave of crime.

"People need to take this very seriously," he said. "Knowing this should cause everyone who uses a computer to manage their online identity better and more closely. There are no secrets; there is no modesty."

He said would-be stalkers search social networking sites, profiling people in hopes of finding a victim.

Katherine Hull, vice president of communications for RAINN, said people need to be aware of what they are putting online.

"People get online, and they think their activity is anonymous, but it isn't," she said. "They post things, get in a chat room and say something that leaves themselves wide open to becoming a victim of cyberstalking.

"Technology is a wonderful thing, but it opens us up to be vulnerable."

Bridgemon agrees.

"Because of the information that we put out there on the Internet, stalkers can follow someone around and never leave their home," he said.

Parry Aftab, a spokeswoman for Wired Safety, an online safety group, said people need to be taught digital hygiene.

"They have to be taught how to use the Internet and social networking systems in a safe manner," she said. "Unfortunately, that's something that people never think of before it's too late.

"Not only do they not see this coming, but they don't know they need to see it coming," Aftab said.

"We have got to do a better job in educating the public about this growing problem."

Michelle Collins, an official with the National Center for Missing and Exploited Children, said her agency has had a cyber tip line for 12 years in an effort to learn more about cyber crimes.

"Last year, we received 120,000 calls," Collins said. "Many of those were about cyberstalking."

She said cyberstalking often leads to physical assaults.

Collins said there was an incident in Wyoming where an ex-boyfriend put a posting online claiming his ex-girlfriend had a rape fantasy and needed people who would fulfill that fantasy.

"They actually showed up at her house and raped her," Collins said.

Franklin County District Attorney Joey Rushing said there is no one definition of a cyberstalker.

"They come in all shapes, sizes, ages and backgrounds," he said. "They patrol Web sites looking for an opportunity to take advantage of people."

He said in Alabama cyberstalking falls under the stalking law, which is a felony.

Sheffield Police Chief Greg Ray said a few years ago his department worked on cybercrimes trying to catch people who were using the Internet to prey on underage girls. He said in setting up sting operations, three people, two from other states, were arrested.

"What they were doing was basically stalking these children or the profiles of these children," Ray said.

Hull said RAINN tries to stress the importance of being careful with information put on the Internet.

"We are living in an age where people are living a vast part of their lives online. That's why we encourage folks to think twice about what kind of information they put on the Internet," Hull said.

"Criminals take advantage of any tools they can, and (the Internet) is just another new tool at their disposal," Oakley said.

Moore said there have already been too many victims of cyberstalking.

"It's an invisible crime, one where the victim is usually not beat up or one where we can see the criminal," Moore said. "The answer is education, starting at the younger ages, teaching school-age children how to use technology the right way - the safe way."


Thursday, May 26, 2011

Some Thoughts About the Dangers of the Internet

Some excerpts from a blog by a student at Virginia Tech. Insightful and thoughtful. Our comments are in dark blue:

TEARING HAIR OUT

On How the Internet Scares Me So Much I Might Never Want To Use It Ever Again

Do you feel empowered by the internet?
Discuss in relation to the recent federal election in USA.

If you have yet to read my paper on social networking site, Facebook, and the dangers associating yourself with it then that ought to answer the question, along with the title of this blog entry. I felt so naive researching for my paper. How could I have thought that just because my "privacy settings" were up, that I would be protected from people? I even was unaware that my own profile was allowing data to be accessed without my permission.

Two years ago, I was being stalked on and offline by a boy I'd met through a mutual friend. We went out a few times and it didn't work out. He harassed me, he called me all the time, left messages on AIM and my phone. Even when I said I didn't want anything to do with him, he'd go away a couple days then come back to tell me that if I didn't want to "be" with him, he would make me very sorry. Mentioning shootings on campus (before April 16, 2007) such as "standing on the drill field and picking people off" and cause harm to me and those I loved. My roommates, friends and my dog who hated him (for good reason; I've never seen my puppy bite someone before him). I felt stuck. I was trapped, as long as I made a little contact. Even if it was "I hate you, leave me alone" bi-weekly, he would make less threats.

How do you reject someone who creeps you out so bad? I was scared to sleep at night, I was scared to I avoided dining halls, I was fearful leaving my puppy at home thinking I might come back to some murder scene. I felt insane thinking that this one person might do something on-campus. Things like that just didn't happen. Right?

I went to the Women's Center to ask them what I might do and they helped me file a cyberstalking and stalking report. I felt ashamed to be putting this horrible label to someone who I thought was clearly ill.

When it was brought up to the school in November of 2006, the school dismissed it saying he was "not responsible". They felt even with hard copies of evidence provided with text messages, emails and instant messages; that cyberstalking wasn't likely.


I had already filed a report with Virginia Tech police, and thus Blacksburg Police, so the trial was set for April 2007. A week after April 16th. (GOOD FOR HER! Don't let police blow you off!)

He was found guilty. Only after a real live case blew up to something no one imagined could spawn from cyberstalking and a mentally ill derangement about our own campus, did this sort of crime seem "real" in Southwest Virginia. I am still waiting for a 2009 hearing to see if he will go to jail or not.

Cyberstalking is real.

Facebook, myspace, blogger are giving away your personal information. Your credit cards, if you used [them]. Your addresses you put on your profile, your phone numbers, your dog's name, your favorite ice cream flavor. Your face.

I got off track, but I wanted to show how it starts online. I feel frustrated and worried in this way.

I also feel that being online is wonderful in other ways though.The Internet is a wonderful form of media, it is also not in the same way. There are millions of users, millions and billions of writings, more facts and figures that you could think about and anything you want to learn about, you can find online. It's great to have that sort of power at your fingertips. Things that I never would have known about, I can learn online.

[snipped]


I guess like anything, you have people who abuse the power and people who embrace it in a good way.

We all can cause harm to others using the Internet, there are ways to inject evil towards others with a short little Google search we could steal identities, stalk and threat, invade privacy and treat people like dirt.

It comes down to ethics and morals; if you're gonna believe everything you read or see or hear.

Some Thoughts About the Dangers of the Internet

Some excerpts from a blog by a student at Virginia Tech. Insightful and thoughtful. Our comments are in dark blue:

TEARING HAIR OUT

On How the Internet Scares Me So Much I Might Never Want To Use It Ever Again

Do you feel empowered by the internet?
Discuss in relation to the recent federal election in USA.

If you have yet to read my paper on social networking site, Facebook, and the dangers associating yourself with it then that ought to answer the question, along with the title of this blog entry. I felt so naive researching for my paper. How could I have thought that just because my "privacy settings" were up, that I would be protected from people? I even was unaware that my own profile was allowing data to be accessed without my permission.

Two years ago, I was being stalked on and offline by a boy I'd met through a mutual friend. We went out a few times and it didn't work out. He harassed me, he called me all the time, left messages on AIM and my phone. Even when I said I didn't want anything to do with him, he'd go away a couple days then come back to tell me that if I didn't want to "be" with him, he would make me very sorry. Mentioning shootings on campus (before April 16, 2007) such as "standing on the drill field and picking people off" and cause harm to me and those I loved. My roommates, friends and my dog who hated him (for good reason; I've never seen my puppy bite someone before him). I felt stuck. I was trapped, as long as I made a little contact. Even if it was "I hate you, leave me alone" bi-weekly, he would make less threats.

How do you reject someone who creeps you out so bad? I was scared to sleep at night, I was scared to I avoided dining halls, I was fearful leaving my puppy at home thinking I might come back to some murder scene. I felt insane thinking that this one person might do something on-campus. Things like that just didn't happen. Right?

I went to the Women's Center to ask them what I might do and they helped me file a cyberstalking and stalking report. I felt ashamed to be putting this horrible label to someone who I thought was clearly ill.

When it was brought up to the school in November of 2006, the school dismissed it saying he was "not responsible". They felt even with hard copies of evidence provided with text messages, emails and instant messages; that cyberstalking wasn't likely.


I had already filed a report with Virginia Tech police, and thus Blacksburg Police, so the trial was set for April 2007. A week after April 16th. (GOOD FOR HER! Don't let police blow you off!)

He was found guilty. Only after a real live case blew up to something no one imagined could spawn from cyberstalking and a mentally ill derangement about our own campus, did this sort of crime seem "real" in Southwest Virginia. I am still waiting for a 2009 hearing to see if he will go to jail or not.

Cyberstalking is real.

Facebook, myspace, blogger are giving away your personal information. Your credit cards, if you used [them]. Your addresses you put on your profile, your phone numbers, your dog's name, your favorite ice cream flavor. Your face.

I got off track, but I wanted to show how it starts online. I feel frustrated and worried in this way.

I also feel that being online is wonderful in other ways though.The Internet is a wonderful form of media, it is also not in the same way. There are millions of users, millions and billions of writings, more facts and figures that you could think about and anything you want to learn about, you can find online. It's great to have that sort of power at your fingertips. Things that I never would have known about, I can learn online.

[snipped]


I guess like anything, you have people who abuse the power and people who embrace it in a good way.

We all can cause harm to others using the Internet, there are ways to inject evil towards others with a short little Google search we could steal identities, stalk and threat, invade privacy and treat people like dirt.

It comes down to ethics and morals; if you're gonna believe everything you read or see or hear.

Thursday, April 7, 2011

Hire-A-Hitman Online? Go to Jail

A young lady who was jealous and enraged about the fact that her ex-boyfriend had moved on, has been charged for trying to hire a hitman to kill his new lover with stolen credit cards from Paypal: Marissa Mark, 28, from Allentown, Pennsylvania is alleged to have hired Essam Ahmed Eid through his amateurish website www.hitmanforhire.net. She wanted him to kill Anne Royston for $37,000 in 2006. She is accused of paying a $19,000 deposit with three stolen credit cards through website PayPal. Marissa Mark, left, is accused of hiring Las Vegas poker dealer Essam Eid, left, through his website www.hitmanforhire.net to kill her ex-boyfriend’s new lover. The shoddy website said: ‘Whether you are trying to put an end to a domestic dispute or eliminate your business competitors, we have the solution for you’. The hire-a-hitman website, which has since been taken down, said: ‘Assassinations are the most practical solutions to common problems. Thanks to the Internet, ordering a hit has never been easier. We manage a network of freelance assassins, available to kill at a moment’s notice.’ Court documents show that PayPal refused to transfer the money Mark allegedly paid from three stolen credit cards, meaning Eid never received any money. According to FBI accounts and court documents, Royston – who worked as a loan broker – was first contacted by Eid in September 2006 under the pretence of wanting to refinance his house. He visited her officers in Woodland Hills, California with one of his two wives, Theresa Engle, posing as his assistant, and told her ‘Somebody wants your head. Somebody wants you killed and they hate you a lot.’ He said he decided against killing her because she reminded him of his own daughter and she could save her life and see Mark dead by settling the balance of the contract.
In this current case Mark was arrested in Jersey City, New Jersey and transferred to Allentown, Pennsylvania where she appeared in court charged with conspiracy, identity theft and other counts. She was granted bail on a $150,000 bond.


There are rumours that the events could be turning into a movie.


original article here

Hire-A-Hitman Online? Go to Jail

A young lady who was jealous and enraged about the fact that her ex-boyfriend had moved on, has been charged for trying to hire a hitman to kill his new lover with stolen credit cards from Paypal: Marissa Mark, 28, from Allentown, Pennsylvania is alleged to have hired Essam Ahmed Eid through his amateurish website www.hitmanforhire.net. She wanted him to kill Anne Royston for $37,000 in 2006. She is accused of paying a $19,000 deposit with three stolen credit cards through website PayPal. Marissa Mark, left, is accused of hiring Las Vegas poker dealer Essam Eid, left, through his website www.hitmanforhire.net to kill her ex-boyfriend’s new lover. The shoddy website said: ‘Whether you are trying to put an end to a domestic dispute or eliminate your business competitors, we have the solution for you’. The hire-a-hitman website, which has since been taken down, said: ‘Assassinations are the most practical solutions to common problems. Thanks to the Internet, ordering a hit has never been easier. We manage a network of freelance assassins, available to kill at a moment’s notice.’ Court documents show that PayPal refused to transfer the money Mark allegedly paid from three stolen credit cards, meaning Eid never received any money. According to FBI accounts and court documents, Royston – who worked as a loan broker – was first contacted by Eid in September 2006 under the pretence of wanting to refinance his house. He visited her officers in Woodland Hills, California with one of his two wives, Theresa Engle, posing as his assistant, and told her ‘Somebody wants your head. Somebody wants you killed and they hate you a lot.’ He said he decided against killing her because she reminded him of his own daughter and she could save her life and see Mark dead by settling the balance of the contract.
In this current case Mark was arrested in Jersey City, New Jersey and transferred to Allentown, Pennsylvania where she appeared in court charged with conspiracy, identity theft and other counts. She was granted bail on a $150,000 bond.


There are rumours that the events could be turning into a movie.


original article here

Saturday, April 2, 2011

The 7 Deadliest Social Networking Hacks

Think you know who your real online friends are? You could be just a few hops away from a cybercriminal in today's social networks
social networking Pictures, Images and Photos

By Kelly Jackson Higgins


It started with a stolen Facebook photo attached to an inflammatory profile. It led to online harassment, death threats, and emails to the victim’s boss questioning the victim’s character. But an online personal attack against Graham Cluley earlier this year is one example of how easy it is to use a social network to damage the identity of an individual -- or an entire company.

Cluley’s case shows just how rapidly social networks can spread a smear campaign or personal attack -- and how it can quickly spread to the victim’s professional life. Cluley, who is a senior technology consultant with Sophos, recently met another victim who experienced a similar attack on Facebook, Kerry Harvey. He says it was apparently an acquaintance of Harvey’s who built a phony Kerry Harvey Facebook profile that branded her occupation as a “prostitute,” complete with her cellphone number.

Could such a thing happen to you or employees at your company? You bet. Social networks are the next major attack venue for trolls, spammers, bot herders, cybercriminals, corporate spies -- and even jilted ex-lovers or enemies -- to make money, or just plain wreak havoc on their victims’ personal lives, security experts say.

“It's the easiest way to passively gain intelligence on the largest groups of society and nearly every walk of life,” says Robert Hansen, aka RSnake, founder of SecTheory LLC.

The root of the problem is that social networking sites by nature aren't secure. They typically don’t authenticate new members -- you can’t always be sure that your online friend is who she says she is -- and attackers can easily exploit and capitalize on the “trusted” culture within the social network. Users often don't deploy the security and privacy options that some of these sites offer, either.

Social networking application development tools like OpenSocial and third-party tools on Facebook, for example, can be abused by attackers to readily spread malware or lift personal information. There’s also the very real risk of corporate espionage, with attackers culling tidbits from personal or professional social net profiles to wage targeted attacks on businesses via their employees. And popular Web attacks, like cross-site scripting, can also be used against members of social networks.

And don’t think for a minute that your “private” or closed profile keeps you safe from an attack or potential personal embarrassment, either. “There is no such thing as privacy on the Internet,” says Adam O’Donnell, director of emerging technologies for Cloudmark. “You are only delaying the inevitable information leakage for any content you put online. My recommendation is to treat the Internet as if all content there lasts forever.”

Attacks on social networking sites have only just begun, so think twice before you get too personal with what you post on them, or too loose about accepting and trusting new friends and connections.

“You’re only going to see these attacks on social networks go up,” says researcher Nathan Hamiel, who along with colleague Shawn Moyer recently conducted some relatively simple but scary hacks recently on various social networks that they demonstrated at Black Hat USA and Defcon 16 this month. “We’ve noticed some weird social networking attacks since we did our talk” at those hacker conferences, he says.

Here's a look at the seven most lethal social networks hacks:

* 1) Impersonation and targeted personal attacks

* 2) Spam and bot infections

* 3) Weaponized OpenSocial and other social networking applications

* 4) Crossover of personal to professional online presence

* 5) XSS, CSRF attacks

* 6) Identity theft

* 7) Corporate espionage

1) Impersonation and targeted personal attacks
You’d think security experts would be relatively immune from social networking hacks since, well, they’re security experts. But a recent wave of nasty hacks targeting security industry figures such as Alan Shimel of StillSecure and Petko Petkov of GNUCitizen, where their personal email accounts and other private data were raided and posted on the Net, have demonstrated that a determined attacker can even get to the experts.

Putting yourself “out there” with a social network presence basically leaves you open for all kinds of attacks, even personal ones. Just ask Sophos’s Cluley, who faced hate messages, death threats to his wife, and his photo being superimposed on some pornographic images after his Facebook photo hack. “They didn’t use my name,” he says, but all it took was someone to recognize his face.

Twitter, the microblogging site where members post quick updates on what they’re doing or comments to multiple “followers,” introduces a whole other element to social networking security -- physical security, experts say. “I never talk about where I am, who I'm with, where I'm going, or any other specific details,” RSnake says. “But that doesn't stop anyone else who knows that same information from doing that behind my back - maliciously or not.”

Sophos’s Cluley says posting too much information on Twitter, such as your whereabouts or trip plans, leave you wide open to things like burglary or stalking. “Twitter is a fascinating thing. To be honest, it could lead to all sorts of physical problems, such as physical theft…or jealous ex’s” tracking what their ex is up to, says Cluley, who “tweets” his blog titles. “When I post to my blog, I’m not saying ‘I’m at the supermarket.’ First of all, who cares? I much prefer to wait until I get back” from the store to say what I’m doing, he says.

And as Hamiel and Moyer demonstrated at Black Hat USA and Defcon 16, you don’t even have to have a social networking profile to be targeted. The two researchers were able to easily impersonate security icon Marcus Ranum (with his permission) on LinkedIn, the social network for businesspeople. Ranum doesn’t have an account, so the two basically lifted Ranum’s photo off the Internet and gathered information on him online and built a convincing phony Ranum profile. (See LinkedIn Hack Demonstrates Ease of Impersonation.)

They channeled Ranum so well that they amassed 42 LinkedIn connections within 12 hour, even duping Ranum’s own sister into friending the phony Ranum profile.

2) Spam or bot infections
Spammers -- for plain old advertising, click fraud, or for bot recruitment -- need mechanisms that efficiently and effectively deliver and spread their messages, malware, or both. And attackers have already honed in on the social networking community, hijacking accounts and using their address books to spread spam, worms, or other malware.

“We’re seeing more and more malware via spam and links in spam. We’re seeing this with malware text on Facebook and Twitter that’s designed to draw people to particular pages,” Sophos’s Cluley says.

Most recently, attackers hijacked some Facebook accounts, and posing as members sent messages to their friends to dupe them into viewing a video clip link, which instead was actually a Trojan that silently downloaded malware onto their machine once they opened the link.

A recent report by ScanSafe found that in July, up to one in 600 profile pages on social-networking sites hosted some form of malware, mostly adware and spyware.

3) Weaponized OpenSocial and other social networking applications
Users often don’t think anything of installing an application in their browser. “But these applications can all have the same levels of access to their system, and some of the most private information is often [stored] in the browser, so it can be more dangerous,” Moyer says. “It blows my mind how people can think that downloading [these applications] is not as bad” as downloading some application to their system.

That makes third-party application services like OpenSocial a dangerously handy tool for attackers. “The addition of the third-party application service also allows for another avenue for code-based attacks to occur,” Cloudmark’s O’Donnell says.

It’s not that all of the developers of those social networking virtual kisses, secret crushes, or birthday reminder widgets are necessarily malicious. OpenSocial, for example, offers an option for writers of these tools to limit malicious JavaScript in these applications, but inexperienced developers typically don’t bother or know to use these measures, O'Donnell says.

“These are opt-in only, and a limited number of developers use the tools. What ends up happening is that developers with a limited amount of security-sensitive development experience create these applications that spread like wildfire, allowing a new vector for infection on many profiles -- and by infection, I primarily mean attacks focused inside the social network,” O’Donnell says.

Users don’t always realize that the third-party widgets for Facebook, for example, weren’t written by Facebook. Some have holes that collect more information on users than necessary or safe, and others have been written specifically to install adware or generate revenue. “To their credit, Facebook has closed down some of these apps that behaved inappropriately,” Sophos’ Cluley notes.

A rogue application called “Secret Crush” was circulating around Facebook earlier this year, spreading spyware instead of love. (See 'Secret Crush' Spreads Spyware, Not Love.) It sent victims an invitation to find out who has a secret "crush" on him or her, and lured them into installing and running the Secret Crush app, which spread spyware via an iFrame. The attack got more advanced and worm-like when it required the victim to invite at least five friends before learning who their “crush” was.

“They [these sites] are basically under constant attack,” Moyer says. “We think a lot of the Web 2.0 problems [with these sites] are more about how much trust is being placed on the client side.”

4) Crossover of personal to professional online presence
Even if you keep a MySpace account for personal use, and a LinkedIn one for professional networking, there’s no guarantee that those late-night partying pictures aren’t going to end up in front of your colleagues on LinkedIn, or worse, your boss.

“Consider everything on a social network to be public, whether it’s private photos or work history,” Hamiel says. “You can’t stop a ‘friend’ from copying your stuff and putting it wherever” they want.

There are some measures social networkers can take to prevent the details of their social and personal lives from spilling over to their professional ones. Cloudmark’s O’Donnell says he doesn’t bother with separate personal and professional social networking accounts: “For me I find it far easier to not keep them separate, and to present a professional face on both my personal and my professional profiles."

You can set up “limited” profiles on sites like Facebook. “I can add someone as a limited friend, and they don’t know they’re limited. They can’t see my holiday photos,” for instance, Sophos’s Cluley says. That way, “I’ve really tied down and parceled up what I want as my real close friends” on the site.

There are also privacy settings that can control what information you share with others on the social network, and what information Facebook apps can get and share about your profile.

5) XSS, CSRF attacks
Cross-site scripting (XSS) and cross-site request forgery (CSRF) vulnerabilities are obvious attack vectors, and some social networking worms have used XSS flaws to help propagate themselves. But most social networks have tightened their defenses against XSS attacks, security experts say, and CSRF attacks are not yet common.

XSS and CSRF do pose a big risk to these sites, especially when it comes to social networking applications, experts say. In an XSS attack, malicious code is injected into vulnerable Web applications and users who view those pages can get hacked. In a CSRF attack, an attacker basically tricks the victim's browser into making a request on his behalf -- as the logged-in user.

“Anytime [that] you, an attacker, can force a user to load HTML, the potential is there for browser exploits, botnet infections, and account manipulation via XSS/CSRF,” says HD Moore, director of security research for BreakingPoint Systems.

A CSRF attack could potentially jump and spread across multiple social networking sites that the user is logged onto -- effectively spreading the attack from one social network to another. It could, for example, force a victim viewing a CSRF-infected page on MySpace to post something on his own wall on Facebook if the wall-posting function was vulnerable. “I think [CSRF] certainly is one useful vector that's being overlooked now,” Moyer says.

Meanwhile, with the openness of social networks, attackers don’t really need to bother with complicated XSS or CSRF attacks. “But if you [the attacker] combine attack vectors, you could be a lot more effective. We think as long as [social networks] allow users to create markup in profiles and comments and link to external content, this will continue to be a problem,” Moyer says.

6) Identity theft
A social network profile can give away some valuable tidbits –- victim’s name and date of birth –- that identity thieves can use to guess passwords or impersonate them, and even eventually steal their identity, some security experts say.

But that doesn’t mean that identity thieves are crawling all over social networks, Hamiel says. “I just think that the claims that social networks are an identity theft magnet are overblown."

Social networkers sometimes inadvertently hand over the goods themselves: In a study Sophos conducted over a year ago, about 41 percent of Facebook users in the study gave out their email address, date of birth, and phone number to someone they didn’t know.

One safety tip for social networkers is not to answer all the questions posed to them by the site, and don't provide your true date of birth, Sophos's Cluley says. “You don’t need to tell Facebook your educational background, your phone number, etc. You don’t even have to tell them your real date of birth,” he says. “I want the identity thief to get the wrong date of birth.”

You can even make up a phony maiden name for your mother. “Don’t make it something that’s a matter of public record,” he says.

Even so, social networks basically tap into human nature’s innate need to socialize, and the bad guys know it. “People aren't very good at security,” RSnake says. “We were built to work in teams, we're pack animals.”
Social Networking Pictures, Images and Photos
7) Corporate espionage
Even if an employer blocks access to social networks from the office, the organization still could be susceptible to corporate espionage attacks via its employees’ personal profiles.

To pull off a spear phishing attack, for example, all an attacker has to do is search for Company A’s employees on a social networking site and then pose as someone within the organization -- such as the head of human resources -- and email the employee addresses he finds, for example. A phony HR spear phish could look something like this, Sophos’s Cluley says: “Dear Fred Jones, Congratulations on joining XYZ Company. Click on this link to access our HR Intranet and then log in with your regular network username and password so we can update our files.”

A newbie to the company could easily fall for the ploy and hand over access to the corporate network, he says.

The only shot at preventing this hack is for social networkers to limit what they post publicly and to keep their employer’s name out of their profile. “Keeping the name of your employer... far away from your personal profiles can reduce the chance that someone will target your employer through you,” BreakingPoint’s Moore says. “The trouble is that even with completely separate personal and professional identities, it only takes one scrap of public information linking the two to negate all of the time that went into separating them in the first place.”

That’s because the “six degrees of separation” rule applies on most social networks: You’re only a few hops away from a bad guy. “We know that there are bad people on these networks using them to steal information,” Cluley says. “You may be only a half a dozen hops from an identity thief if we’re all connected.”

Responses to: editors@darkreading.com

ORIGINAL ARTICLE

Many thanks to support group member, Gypsy for this gem!

Popular Posts

Blog Archive