Author Archives: Hacker Medic

News of the Royal Birth is a Goldmine for Spammers

Breaking news, no matter how wonderful or horrible it may seem, can be a breeding ground for scams, especially on the Internet. Just as ticket scalpers look to make a profit off concerts and sporting events, scammers are looking to take advantage of people on the hunt for the exclusive scoop in big name news. Read more…

How to Turn Off GPS on Your Child’s Phone

Mobile phone technology is amazing isn’t it? It’s so amazing it can track your child’s location (hey, they are called ‘smart phones’ for a reason). In fact, your family is likely uploading dozens of photos a week and inadvertently broadcasting your exact whereabouts. Both safety and privacy is put at risk each time your child Read more…

?????????????????????

      No Comments on ?????????????????????

寄稿: Sujay Kulkarni

image1_9.png

ジ・アッシズ(The Ashes)は、イングランド代表とオーストラリア代表の間で競われるクリケットのテストマッチとして人気の高いシリーズです。両国の間で最も古いテストマッチであり、イングランドとオーストラリアで 1 年ごとに交互に開催されます。クリケットファンであれば、この注目のシリーズを観戦するためにテレビとインターネットに釘付けになっていることでしょう。

現在のところイングランドが 3-0 でリードしていて、最後のテストマッチでイングランドが快勝することになれば(実現しそうです)、対オーストラリア戦における転換点になるでしょう。とはいえ、今話題になっているのは、スコールズ(Scholes)、キャリック(Carrick)、ロビン・ファン・ペルシ(Robin Van Persie)といったサッカー選手ではなく、打倒オーストラリアをもくろむキャプテンのアラステア・クック(Alastair Cook)と彼が率いる精鋭チームです。

この興味深いシナリオを悪用しようと、詐欺師が待ち構えています。詐欺師は、あなたの電子メールアドレスが「2013 年アッシズシリーズで 242,500,000 ドルに当選(242,500,000 USD in the 2013 ASHES SERIES)」したと称して、個人情報をメールで送信させようとします。

詐欺の手口としてユーザーに求められるのはただ 1 つ、詐欺師に個人情報を返信することだけです。それだけで、後は詐欺師の思いのままになるというわけです。

これは典型的な 419 スパムです。電子メールの中で詐欺師は、あなたが抽選に当たった(たとえば、50,000 ドルの賞金が当たった)と説明し、それを受け取るために今すぐ個人情報を返信するようにと要求してきます。

シマンテック製品をお使いのお客様は、安全対策として以下の予防措置をお守りください。

  • オペレーティングシステムのパッチが公開されたらすぐに適用する。
  • ウイルス対策定義を定期的に更新する。
  • 送信者や件名に覚えがない迷惑メールは開かないようにし、疑わしい添付ファイルもクリックしないようにする。
  • 迷惑メールを扱うときは、不明な相手に個人情報を送信しないよう特に注意する。

詐欺師の攻撃に不意を突かれないよう注意しながら、今年のアッシズシリーズをお楽しみください。

 

* 日本語版セキュリティレスポンスブログの RSS フィードを購読するには、http://www.symantec.com/connect/ja/item-feeds/blog/2261/feed/all/ja にアクセスしてください。

Is Your Baby Monitor Peeking in on You?

      No Comments on Is Your Baby Monitor Peeking in on You?

Could the monitors we as parents use to keep tabs on our children playing or sleeping in other rooms of the home be used to eavesdrop in reverse? That is exactly what happened to a family in Houston, TX who were surprised by an unfamiliar voice screaming obscenities out of the child monitor in the Read more…

Spammer’s Googly Over Ongoing Ashes Series

Contributor: Sujay Kulkarni

image1_9.png

The Ashes Test cricket series, one of most popular Test series in cricket, is played between England and Australia. It is played alternately in England and Australia and is the oldest test rivalry between these two sides. Cricket fans are glued to the TV and their online devices to watch this riveting series.

In the current Ashes series England is leading 3-0 and is on the cusp of creating history against Australia—if they beat them hands down in the last test match, which now is a real possibility. However, what is making the rounds is not Scholes, Carrick, or Robin Van Persie, but Captain Cook and his elite squad waiting to steamroll Australia.

This interesting scenario has got scammers smacking their lips. They have come up with a trick to lure you into sending them your personal information over email because your email address has won  “242,500,000 USD in the 2013 ASHES SERIES”.

Here is the catch, you have one obligation to fulfill by replying back to the scammer with your “personal details”. Well, that would set the ball rolling for the scammer, wouldn’t it?

In a typical 419 spam, the scammer mentions in the email that you have won—an award of $50,000 USD for example—and asks you to reply back with your personal details, immediately to claim the money.

Symantec customers should take the following precautionary measures to stay safe:

  • Update operating system patches when prompted
  • Update the antivirus patches regularly
  • Do not open any unsolicited emails when you do not recognize the sender or the subject and avoid clicking on suspicious email attachments
  • When dealing with unsolicited mails avoid sending any personal details, especially to unknown persons

Enjoy the ongoing the Ashes Test cricket series without getting bowled over by any Spammer’s googly.

Variety of Android Threats Extends Around the World

As the most popular mobile platform, Android has grown exponentially in recent years, increasing the market for new developers to show their skills with novel applications. However, not all developers have the best intentions in mind; some take advantage of the popularity of Android to develop malicious applications. In this blog we will show the Read more…

Android Fake AV Hosted in Google Code Targets South Koreans

During the last two years we have observed the accelerated discovery of Android malware by the security industry. Malware authors today often create and distribute fake “antimalware” apps that simulate the scan of files on a device. These fake apps report fake threats (and sometimes make the device unusable). The goal is to get victims Read more…

Don’t Take a Bite out of that Apple Gift Card Scam

Good rule of thumb on the web: When it seems too good to be true, it probably is. Those ads on the right side of your web page, promising to give you a brand new iPad for absolutely free…probably a scam. The direct message on Twitter you received stating that you can make thousands of Read more…

E-commerce in the Middle East – On the Up and Up!

E-commerce is on a massive upward trajectory in the Middle East and North Africa (MENA) region. According to a recent report issued by Visa[1], nowhere else in the world is growing as fast: MENA experienced a 45% increase in 2012, compared to the previous year, with transactions soaring from $10 to $15 billion.[2] The fastest growing markets

For retailers who have tended to ignore or avoid this market, in favour of others that have seemed both more stable and lucrative, those figures are bound to make them think again. This is fertile territory and many of their rivals are now clearly reaping the rewards to be had there. So expect to see competition hotting up!

What are people buying online right now and how can the MENA region overcome some fundamental factors to drive growth even higher? The popular and growing areas for e-commerce right now are banking, paying bills and booking travel. Purchasing items and/or services is still not as developed as in the major European markets, and clearly this offers vast promise for those who can exploit its vast potential in the MENA region[3].

That said, and despite its impressive performance of late, the MENA region is still not actually expanding at nearly the same rate as the rest of the globe when it comes to e-commerce.  Why is this? In part it’s down to lack of confidence and trust online; according to a recent survey by Onecard, 56 per cent of respondents based in the Middle East said they were concerned about credit card fraud and the region faces the same barriers seen elsewhere around the world, where lack of trust and payment security are regularly highlighted as key concerns for people when choosing to shop online. Additionally a report from Deloitte highlights[4] that it is there are three other factors that are holding growth back:

First, there are the logistical issues around physical addresses (they are not well defined enough) and also the postal system itself, whose infrastructure is poor.

Secondly, there is an absence of the relevant e-laws necessary to provide proper levels of protection for consumers and vendors.

And, finally, it can be expensive for small businesses to set up payment gateways, thus deterring them from entering the market – a factor that is reflected in the widespread popularity of cash on delivery (COD) payments across the region. Strikingly, while there are an estimated 90 million internet users in the Middle East, a mere 15% of Middle East companies have an online presence.[5] Moreover, some 70-80% of online purchases are COD, with just 30% paid for online – and that despite almost 50% of consumers owning credit cards.

At the same time, it should be said that such flexibility of payment types has certainly made e-commerce more accessible, and more attractive, to users; and no doubt has contributed substantially to the surge in sales that has taken place recently. Whilst ‘cash on delivery’ is a good solution to consumers’ lack of trust in online transactions, it can hinder the growth of e-commerce in the region due to difficulty in coordinating home delivery services and ultimately it’s much less cost effective than taking payments online. As mentioned above, ecommerce comes branded with what is a typical online question for end users and retailers alike: ‘Are you safe?’ Because, unless they truly believe that they can operate securely online – and that transactions can be undertaken and completed in a tightly protected environment – the massive potential that MENA offers will simply not be realised.

These issues are of course being addressed and in anticipation of this it’s worth considering that in order to Be successful online, and to capture more consumer mindshare and business, sites need to be:

  • Accessible (particularly for mobile) – consider responsive design to meet the needs of your visitors
  • Easy to use – e.g. clear navigation and extensive search
  • Trustworthy – demonstrate that your site can be trusted with credit card details using clear security indicators such as SSL, and through the use of online trust marks such as the Norton Secured Seal
  • Fully localised into your target markets language.

All well and good… in theory. The reality is that, while it’s relatively simple to set up an e-commerce site, there is still widespread ignorance of the potential hazards that exist when sending data via unsecured connections. In fact, many customers still do not even know that SSL certificates exist to protect them online.

Clearly, sites in the Middle East region that really want to be successful should be using SSL and trust marks to demonstrate that they are professional, dependable and safe to do business with. Indeed in my opinion SSL certificates should be mandatory for any ecommerce site or for anyone else that asks customers to submit any kind of personal information. Using SSL is also the clever option for companies that don’t ask for personal information from visitors – something that can act as a barrier on line. Companies such as Google use SSL to pass along certain information about what searchers are looking for – and are requiring this higher level of security to perform that service. This trend seems likely to continue, making SSL certificates vital to virtually any website – but especially those with e-commerce in mind.

One question when considering which security vendor can add the most value to your existing or newly established site is “how can I can demonstrate my trustworthiness to potential customers?” According to a survey carried out this year by the independent web research organisation Baymard Institute in conjunction with Google, the Norton Secured Seal is by far the most trusted, with 35.6% of the votes – nearly 13% ahead of its nearest rival. It was shown to be the seal that gave customers the strongest sense of trust when purchasing online, making it the de facto choice[6].

Such reassurance will play a major role, as the internet spreads it reach and e-commerce gathers ever greater momentum throughout MENA capturing and keeping customers is where success lies.