<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; Social Engineering</title>
	<atom:link href="http://www.darknet.org.uk/category/social-engineering/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Social Engineering Vulnerability Evaluation and Recommendation Project</title>
		<link>http://www.darknet.org.uk/2011/12/social-engineering-vulnerability-evaluation-and-recommendation-project/</link>
		<comments>http://www.darknet.org.uk/2011/12/social-engineering-vulnerability-evaluation-and-recommendation-project/#comments</comments>
		<pubDate>Thu, 22 Dec 2011 15:52:25 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[formal methodology for social engineering]]></category>
		<category><![CDATA[formal social engineering structure]]></category>
		<category><![CDATA[how to social engineer]]></category>
		<category><![CDATA[how to use social engineering]]></category>
		<category><![CDATA[sever]]></category>
		<category><![CDATA[social engineering for penetration testers]]></category>
		<category><![CDATA[social engineering guide]]></category>
		<category><![CDATA[social engineering how to]]></category>
		<category><![CDATA[social engineering methodology]]></category>
		<category><![CDATA[social engineering methods]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3115</guid>
		<description><![CDATA[Social engineering has been around for tens of thousands of years so it is time we approach the topic in a professional manner. The Social Engineering Vulnerability Evaluation and Recommendation (SEVER) Project is one way to help penetration testers become more consistent. It is also intended to be the best way to teach novices about [...]]]></description>
			<content:encoded><![CDATA[<p>Social engineering has been around for tens of thousands of years so it is time we approach the topic in a professional manner. The Social Engineering Vulnerability Evaluation and Recommendation (SEVER) Project is one way to help penetration testers become more consistent.  It is also intended to be the best way to teach novices about social engineering concepts.</p>
<p>By distilling thousands of pages of theory into a simple form the SEVER project hopes to: </p>
<ol>
<li>Provide the fastest means of training novices about complex social engineering concepts.</li>
<li>Provide penetration testers with a methodology that minimizes their effort while increasing their chance of success. </li>
</ol>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<p>You will begin by defining requirements, then brainstorm solutions, and then refine your solutions through multiple phases. Each phase increases in detail, allowing you to identify &#8216;show stoppers&#8217; as soon as possible. This will help you avoid wasting time working on a plan that is not going to succeed. If an idea makes it through the entire process and you still feel good about it then you should have a very high chance of success. </p>
<p>The best format for this content would be an electronic form with a lot of context-sensitive notes. But since there is currently no effective, portable way of accomplishing that I decided to split the content into two PDF files – the SEVER Worksheet and the SEVER Instructions. Go through these instructions while you fill out the form until you have a thorough understanding of how the form works. If you cheat and try to do one before the other (or skip the instructions altogether) you will miss things which will make failure far more likely.</p>
<p>You can download both papers here:</p>
<p>- <a href="http://www.kgb.to/SEVER_Instructions_Final.pdf">SEVER_Instructions_Final.pdf</a><br />
- <a href="http://www.kgb.to/SEVER_Worksheet_Final.pdf">SEVER_Worksheet_Final.pdf</a></p>
<p>Or read more <a href="http://www.kgb.to/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Social+Engineering+Vulnerability+Evaluation+and+Recommendation+Project+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3115+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/12/social-engineering-vulnerability-evaluation-and-recommendation-project/&amp;t=Social+Engineering+Vulnerability+Evaluation+and+Recommendation+Project" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/12/social-engineering-vulnerability-evaluation-and-recommendation-project/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/12/social-engineering-vulnerability-evaluation-and-recommendation-project/&amp;title=Social+Engineering+Vulnerability+Evaluation+and+Recommendation+Project" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/12/social-engineering-vulnerability-evaluation-and-recommendation-project/&amp;title=Social+Engineering+Vulnerability+Evaluation+and+Recommendation+Project" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/12/social-engineering-vulnerability-evaluation-and-recommendation-project/&amp;title=Social+Engineering+Vulnerability+Evaluation+and+Recommendation+Project" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/12/social-engineering-vulnerability-evaluation-and-recommendation-project/&amp;title=Social+Engineering+Vulnerability+Evaluation+and+Recommendation+Project" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F12%2Fsocial-engineering-vulnerability-evaluation-and-recommendation-project%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/12/social-engineering-vulnerability-evaluation-and-recommendation-project/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>VeriSign Demands The Power To Take Down Websites/Domains</title>
		<link>http://www.darknet.org.uk/2011/10/verisign-demands-the-power-to-take-down-websitesdomains/</link>
		<comments>http://www.darknet.org.uk/2011/10/verisign-demands-the-power-to-take-down-websitesdomains/#comments</comments>
		<pubDate>Wed, 12 Oct 2011 14:00:49 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Legal Issues]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[domain takedown]]></category>
		<category><![CDATA[icann]]></category>
		<category><![CDATA[Registry Services Evaluation Process]]></category>
		<category><![CDATA[rsep]]></category>
		<category><![CDATA[url takedown]]></category>
		<category><![CDATA[verisign]]></category>
		<category><![CDATA[verisign takedown power]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3208</guid>
		<description><![CDATA[I was scanning the news today, and nothing much was going on. There were some half-arsed stories about Anonymous and LulzSec &#8211; but nothing really worth writing about. And then, and then I spotted this, which quite frankly scares the shit out of me. As much as it may well have a use in law [...]]]></description>
			<content:encoded><![CDATA[<p>I was scanning the news today, and nothing much was going on. There were some half-arsed stories about <a href="http://www.darknet.org.uk/tag/anonymous/">Anonymous</a> and LulzSec &#8211; but nothing really worth writing about. And then, and then I spotted this, which quite frankly scares the shit out of me.</p>
<p>As much as it may well have a use in law enforcement, I&#8217;m sorry but I don&#8217;t want any single organization, corporation or entity to have the power to take out domains.</p>
<p>It&#8217;s just plain wrong, and well the UK has already started tabling something like this <a href="http://www.theregister.co.uk/2011/09/02/cops_to_get_dot_uk_takedown_powers/">back in September</a>.</p>
<blockquote><p>VeriSign, which manages the database of all .com internet addresses, wants powers to shut down &#8220;non-legitimate&#8221; domain names when asked to by law enforcement.</p>
<p>The company said today it wants to be able to enforce the &#8220;denial, cancellation or transfer of any registration&#8221; in any of a laundry list of scenarios where a domain is deemed to be &#8220;abusive&#8221;.</p>
<p>VeriSign should be able to shut down a .com or .net domain, and therefore its associated website and email, &#8220;to comply with any applicable court orders, laws, government rules or requirements, requests of law enforcement or other governmental or quasi-governmental agency, or any dispute resolution process&#8221;, according to a document it filed today with domain name industry overseer ICANN.</p>
<p>The company has already helped law enforcement agencies in the US, such as the Immigration and Customs Enforcement agency, seize domains that were allegedly being used to sell counterfeit goods or facilitate online piracy, when the agency first obtained a court order.</p>
<p>That seizure process has come under fire because, in at least one fringe case, a seized .com domain&#8217;s website had already been ruled legal by a court in its native Spain.</p>
<p>Senior ICE agents are on record saying that they believe all .com addresses fall under US jurisdiction.</p>
<p>But the new powers would be international and, according to VeriSign&#8217;s filing, could enable it to shut down a domain also when it receives &#8220;requests from law enforcement&#8221;, without a court order.</p></blockquote>
<p>Yes VeriSign do manage all the .com and .net domains, but they aren&#8217;t technically ruled under the US jurisdiction &#8211; there are plenty of .com domains that are hosted outside of the US, including the DNS infrastructure.</p>
<p>What I&#8217;m especially interested in, is how they plan to handle the fact that lots of things are illegal in some countries and perfectly legal in others. The part that scares me is they will be able to take down a domain without a court order, just on &#8216;request&#8217; from a law enforcement agency.</p>
<p>To me, that opens it up to abuse &#8211; if you are going to do something like this, at least institute a due process to manage it properly.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<blockquote><p>&#8220;Various law enforcement personnel, around the globe, have asked us to mitigate domain name abuse, and have validated our approach to rapid suspension of malicious domain names,&#8221; VeriSign told ICANN, describing its system as &#8220;an integrated response to criminal activities that utilize Verisign-managed [top-level domains] and DNS infrastructure&#8221;.</p>
<p>The company said it has already cooperated with US law enforcement, including the FBI, to craft the suspension policies, and that it intends to also work with police in Europe and elsewhere.</p>
<p>It&#8217;s not yet clear how VeriSign would handle a request to suspend a .com domain that was hosting content legal in the US and Europe but illegal in, for example, Saudi Arabia or Uganda.</p>
<p>VeriSign made the request in a Registry Services Evaluation Process (RSEP) document filed today with ICANN. The RSEP is currently the primary mechanism that registries employ when they want to make significant changes to their contracts with ICANN.</p>
<p>The request also separately asks for permission to launch a &#8220;malware scanning service&#8221;, not dissimilar to the one recently introduced by ICM Registry, manager of the new .xxx extension.</p>
<p>That service would enable VeriSign to scan all .com websites once per quarter for malware and then provide a free &#8220;informational only&#8221; security report to the registrar responsible for the domain, which would then be able to take re-mediation action. It would be a voluntary service.</p></blockquote>
<p>Scary thoughts really. However the malware scanning service sounds like something that would help the Internet clean up all the nasty stuff, but then again &#8211; do the registrars really care, and would they respond?</p>
<p>Either way, I don&#8217;t like the fact that these draconian control laws may be placed on the Internet as we know &#8211; that basically allow US law enforcement agencies to take down domains as they please.</p>
<p>What I&#8217;m guessing, if this is implemented, it may well become a major target for <a href="http://www.darknet.org.uk/category/social-engineering/">Social Engineering</a> efforts. What&#8217;s more effective than a traditional <a href="http://www.darknet.org.uk/tag/ddos/">DDoS</a> attack? Having the domain completely killed by VeriSign &#8211; that&#8217;s what.</p>
<p>Source: <a href="http://www.theregister.co.uk/2011/10/11/verisign_asks_for_web_takedown_powers/">The Register</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=VeriSign+Demands+The+Power+To+Take+Down+Websites%2FDomains+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3208+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/10/verisign-demands-the-power-to-take-down-websitesdomains/&amp;t=VeriSign+Demands+The+Power+To+Take+Down+Websites%2FDomains" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/10/verisign-demands-the-power-to-take-down-websitesdomains/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/10/verisign-demands-the-power-to-take-down-websitesdomains/&amp;title=VeriSign+Demands+The+Power+To+Take+Down+Websites%2FDomains" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/10/verisign-demands-the-power-to-take-down-websitesdomains/&amp;title=VeriSign+Demands+The+Power+To+Take+Down+Websites%2FDomains" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/10/verisign-demands-the-power-to-take-down-websitesdomains/&amp;title=VeriSign+Demands+The+Power+To+Take+Down+Websites%2FDomains" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/10/verisign-demands-the-power-to-take-down-websitesdomains/&amp;title=VeriSign+Demands+The+Power+To+Take+Down+Websites%2FDomains" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F10%2Fverisign-demands-the-power-to-take-down-websitesdomains%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/10/verisign-demands-the-power-to-take-down-websitesdomains/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>The Social-Engineer Toolkit (SET) &#8211; Computer Based Social Engineering Tools</title>
		<link>http://www.darknet.org.uk/2010/10/the-social-engineer-toolkit-set-computer-based-social-engineering-tools/</link>
		<comments>http://www.darknet.org.uk/2010/10/the-social-engineer-toolkit-set-computer-based-social-engineering-tools/#comments</comments>
		<pubDate>Mon, 25 Oct 2010 10:09:36 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[david kennedy]]></category>
		<category><![CDATA[ettercap]]></category>
		<category><![CDATA[java]]></category>
		<category><![CDATA[java applet attack]]></category>
		<category><![CDATA[metasploit]]></category>
		<category><![CDATA[pen-test]]></category>
		<category><![CDATA[pen-testing]]></category>
		<category><![CDATA[penetration-testing]]></category>
		<category><![CDATA[rel1k]]></category>
		<category><![CDATA[SET]]></category>
		<category><![CDATA[social engineer toolkit]]></category>
		<category><![CDATA[social engineering tools]]></category>
		<category><![CDATA[tabnapping]]></category>
		<category><![CDATA[teensy usb]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2976</guid>
		<description><![CDATA[The Social-Engineer Toolkit (SET) is specifically designed to perform advanced attacks against the human element. SET was designed to be released with the http://www.social-engineer.org launch and has quickly became a standard tool in a penetration testers arsenal. SET was written by David Kennedy (ReL1K) and with a lot of help from the community it has [...]]]></description>
			<content:encoded><![CDATA[<p>The Social-Engineer Toolkit (SET) is specifically designed to perform advanced attacks against the human element. SET was designed to be released with the <a href="http://www.social-engineer.org">http://www.social-engineer.org</a> launch and has quickly became a standard tool in a penetration testers arsenal. SET was written by David Kennedy (ReL1K) and with a lot of help from the community it has incorporated attacks never before seen in an exploitation toolset. The attacks built into the toolkit are designed to be targeted and focused attacks against a person or organization used during a penetration test.</p>
<p>SET is a menu driven based attack system, which is fairly unique when it comes to hacker tools. The decision not to make it command line was made because of how social-engineer attacks occur; it requires multiple scenarios, options, and customizations. If the tool had been command line based it would have really limited the effectiveness of the attacks and the inability to fully customize it based on your target. Let’s dive into the menu and do a brief walkthrough of each attack vector. </p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<p>This is an extremely complete and advanced toolkit, which also harnessed the power of <a href="http://www.darknet.org.uk/tag/metasploit/">Metasploit</a> and <a href="http://www.darknet.org.uk/tag/ettercap/">Ettercap</a> and  it provides following attack vectors:</p>
<ul>
<li>
Spear-Phishing Attack Vector</li>
<li>Java Applet Attack Vector</li>
<li>Metasploit Browser Exploit Method</li>
<li>Credential Harvester Attack Method</li>
<li><a href="http://www.darknet.org.uk/tag/tabnapping/">Tabnabbing</a> Attack Method</li>
<li>Man Left in the Middle Attack Method</li>
<li>Web Jacking Attack Method</li>
<li>Multi-Attack Web Vector</li>
<li>Infectious Media Generator</li>
<li>Teensy USB HID Attack Vector</li>
</ul>
<p>You can find some tutorials and videos on how to get up and running and use SET here:</p>
<p><a href="http://www.social-engineer.org/se-resources/">Social Engineering Resources</a></p>
<p>You can download SET using SVN.</p>
<pre><code>svn co http://svn.secmaniac.com/social_engineering_toolkit set/</code></pre>
<p>Or read more <a href="http://www.social-engineer.org/framework/Computer_Based_Social_Engineering_Tools:_Social_Engineer_Toolkit_%28SET%29">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=The+Social-Engineer+Toolkit+%28SET%29+%E2%80%93+Computer+Based+Social+Engineering+Tools+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2976+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/10/the-social-engineer-toolkit-set-computer-based-social-engineering-tools/&amp;t=The+Social-Engineer+Toolkit+%28SET%29+%E2%80%93+Computer+Based+Social+Engineering+Tools" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/10/the-social-engineer-toolkit-set-computer-based-social-engineering-tools/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/10/the-social-engineer-toolkit-set-computer-based-social-engineering-tools/&amp;title=The+Social-Engineer+Toolkit+%28SET%29+%E2%80%93+Computer+Based+Social+Engineering+Tools" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/10/the-social-engineer-toolkit-set-computer-based-social-engineering-tools/&amp;title=The+Social-Engineer+Toolkit+%28SET%29+%E2%80%93+Computer+Based+Social+Engineering+Tools" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/10/the-social-engineer-toolkit-set-computer-based-social-engineering-tools/&amp;title=The+Social-Engineer+Toolkit+%28SET%29+%E2%80%93+Computer+Based+Social+Engineering+Tools" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/10/the-social-engineer-toolkit-set-computer-based-social-engineering-tools/&amp;title=The+Social-Engineer+Toolkit+%28SET%29+%E2%80%93+Computer+Based+Social+Engineering+Tools" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F10%2Fthe-social-engineer-toolkit-set-computer-based-social-engineering-tools%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/10/the-social-engineer-toolkit-set-computer-based-social-engineering-tools/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Malware Pushers Abuse Firefox Warning Page</title>
		<link>http://www.darknet.org.uk/2010/10/malware-pushers-abuse-firefox-warning-page/</link>
		<comments>http://www.darknet.org.uk/2010/10/malware-pushers-abuse-firefox-warning-page/#comments</comments>
		<pubDate>Thu, 21 Oct 2010 10:12:36 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[Spammers & Scammers]]></category>
		<category><![CDATA[fake firefox warning page]]></category>
		<category><![CDATA[firefox warning page]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[malware pushers]]></category>
		<category><![CDATA[reported attack page]]></category>
		<category><![CDATA[scammers]]></category>
		<category><![CDATA[spammers]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2979</guid>
		<description><![CDATA[This is a pretty neat attack from the malware pushes leveraging on the ignorance of the average user &#8211; which in all honestly is a safe bet most of the time! You could consider it a Social Engineering attack as it&#8217;s taking something that&#8217;s familiar and changing it to deliver malware. I&#8217;m sure all the [...]]]></description>
			<content:encoded><![CDATA[<p>This is a pretty neat attack from the malware pushes leveraging on the ignorance of the average user &#8211; which in all honestly is a safe bet most of the time! You could consider it a <a href="http://www.darknet.org.uk/category/social-engineering/">Social Engineering</a> attack as it&#8217;s taking something that&#8217;s familiar and changing it to deliver malware.</p>
<p>I&#8217;m sure all the Firefox users reading have at some point or another been faced with the warning screen that tells you a site is not safe to visit, the red page which states in big white letters &#8220;Reported Attack Page!&#8221;.</p>
<blockquote><p>Hackers have subverted warnings generated by Firefox about dangerous sites to punt fake anti-virus portals.</p>
<p>Surfers straying onto a web page offering the &#8220;Security Tool&#8221; rogue anti-virus are offered a warning page that convincingly mimics the genuine Firefox block page. The site offers supposed updates for Mozilla&#8217;s technology that are actually scareware packages.</p>
<p>If Windows users apply these updates they will be falsely warned that their system is infected and continuously nagged into buying worthless scareware packages that serve only to line the pockets of cyber-scammers.</p>
<p>The rogue application will automatically attempt to install itself on the machines of prospective marks in cases where scripts are enabled, net security firm F-Secure warns.</p></blockquote>
<p>Personally I&#8217;d say this attack would be pretty effective, my only question would be &#8211; how would the user land on that site in the first place? I guess through the normal channels (e-mail spam, facebook wall worms and so on).</p>
<p>After landing the user would realize they&#8217;ve been spammed/scammed and see the Firefox warning&#8230;then download the &#8216;security update&#8217; and install it &#8211; unknowingly pwning themselves in the process.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<blockquote><p>Firefox&#8217;s genuine attack warning technology is all server-side and never requests that users download updates. The attack relies, in part, on the ignorance of the majority of potential victims on this point.</p>
<p>The attack is a rare but not unprecedented attempt by malware slingers to use Firefox features to push their wares. Previous attacks by the same gang have involved tricking users into downloading scareware in the guise of a supposed Firefox/Flash update.</p>
<p>The malware is offered from a page designed to trick Firefox users into thinking their browser software has just been updated but that they still need to apply a Flash Player patch, which is actually a rogue anti-virus installation utility. The sneaky tactic, first spotted back in July, is explained in more detail in a blog post by F-Secure.</p></blockquote>
<p>It just goes to show the bad guys are pretty creative when it comes to new ways to trick people into installing their malware, I wonder what we&#8217;ll see next?</p>
<p>The full entry by F-Secure can be seen here:</p>
<p><a href="http://www.f-secure.com/weblog/archives/00002051.html">Reported Attack Site! &#8211; Security Tool&#8217;s Latest Trick</a></p>
<p>Source: <a href="http://www.theregister.co.uk/2010/10/20/scareware_scumbags_subvert_firefox_security_warnings/">The Register</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Malware+Pushers+Abuse+Firefox+Warning+Page+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2979+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/10/malware-pushers-abuse-firefox-warning-page/&amp;t=Malware+Pushers+Abuse+Firefox+Warning+Page" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/10/malware-pushers-abuse-firefox-warning-page/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/10/malware-pushers-abuse-firefox-warning-page/&amp;title=Malware+Pushers+Abuse+Firefox+Warning+Page" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/10/malware-pushers-abuse-firefox-warning-page/&amp;title=Malware+Pushers+Abuse+Firefox+Warning+Page" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/10/malware-pushers-abuse-firefox-warning-page/&amp;title=Malware+Pushers+Abuse+Firefox+Warning+Page" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/10/malware-pushers-abuse-firefox-warning-page/&amp;title=Malware+Pushers+Abuse+Firefox+Warning+Page" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F10%2Fmalware-pushers-abuse-firefox-warning-page%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/10/malware-pushers-abuse-firefox-warning-page/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Regional Trojan Threat Targeting Online Banks</title>
		<link>http://www.darknet.org.uk/2010/07/regional-trojan-threat-targeting-online-banks/</link>
		<comments>http://www.darknet.org.uk/2010/07/regional-trojan-threat-targeting-online-banks/#comments</comments>
		<pubDate>Thu, 08 Jul 2010 10:53:14 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[Spammers & Scammers]]></category>
		<category><![CDATA[ambler]]></category>
		<category><![CDATA[bank phishing]]></category>
		<category><![CDATA[banking trojan]]></category>
		<category><![CDATA[banking-security]]></category>
		<category><![CDATA[british bank security]]></category>
		<category><![CDATA[british banks]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[e-commerce]]></category>
		<category><![CDATA[location specific trojan]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[regional trojans]]></category>
		<category><![CDATA[silon]]></category>
		<category><![CDATA[torpig]]></category>
		<category><![CDATA[trojans]]></category>
		<category><![CDATA[trusteer]]></category>
		<category><![CDATA[yaludle]]></category>
		<category><![CDATA[zeus]]></category>
		<category><![CDATA[zeus trojan]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2785</guid>
		<description><![CDATA[Well it was inevitable really, I&#8217;ve noticed in the last couple of years Phishing e-mails have started to use targeted lists especially for banking sites and the next up of course is trojans developed for specific regions. A security company Trusteer (who makes Rapport) has done some research on this matter which has pin-pointed certain [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Well it was inevitable really, I&#8217;ve noticed in the last couple of years <a href="http://www.darknet.org.uk/category/phishing/">Phishing</a> e-mails have started to use targeted lists especially for banking sites and the next up of course is <a href="http://www.darknet.org.uk/tag/trojans/">trojans</a> developed for specific regions.</p>
<p>A security company <a href="http://www.trusteer.com/">Trusteer</a> (who makes <a href="http://krebsonsecurity.com/2010/04/a-closer-look-at-rapport-from-trusteer/">Rapport</a>) has done some research on this matter which has pin-pointed certain malware which is specifically targeted at UK banking sites and their users. And they actually appear to be using the rather successful <a href="http://www.darknet.org.uk/tag/zeus/">Zeus</a> trojan, with 2 botnets targeting the UK.</p>
<p>I would guess that targeting on a per-country basis increases the chances of success hugely as there only limited banks in each country and especially in the small countries like UK there aren&#8217;t <em>that</em> many popular ones, especially with all the mergers that took place.</p>
<blockquote><p>Cybercrooks have developed regionally-targeted banking Trojans that are more likely to slip under the radar of anti-virus defences.</p>
<p>Detection rates for regional malware vary between zero and 20 per cent, according to a study by transaction security firm Trusteer. This company markets browser security add-ons to banks, which offer them to consumers as a way of reducing the risk of malware on PCs resulting in banking fraud.</p>
<p>Trusteer cites two pieces of regional malware targeted at UK banking consumers. Silon.var2, crops up on one in every 500 computers in the UK compared to one in 20,000 in the US. Another strain of malware, dubbed Agent-DBJP, was found on one in 5,000 computers in the UK compared to one in 60,000 in the US.</p>
<p>The Zeus Trojan is the most common agent of financial fraud worldwide. The cybercrime toolkit is highly customisable and widely available through underground carder and cybercrime forums. Trusteer has identified two UK-specific Zeus botnets, designed to infect only UK-based Windows and harvest login credentials of only British banks from these compromised systems.</p></blockquote>
<p>It seems like a sensible shift in the paradigm for the bot-herders and <a href="http://www.darknet.org.uk/category/virustrojanswormsrootkits/">malware</a> pushers, rather than spraying their malware everywhere they can geolocate the IP addresses they are attacking and send out specific versions of their malware for clients from different countries.</p>
<p>Rather than in the early days when phishing and trojans only targeted the very largest US banking organizations (Citibank, Bank of America etc.).</p>
<p>Plus the fact more and more people are using online banking, micro-payment systems and sharing all kinds of sensitive data with the World online and stored on their computers. This makes it a much richer field for the would-be fraudster.</p>
<blockquote><p>Trusteer reckons the crooks behind the attack are using UK-centric spam lists and compromised websites to spread the malware while staying under the radar of security firms. It compares this process to the shift from mass assaults to targeted strikes in corporate espionage-motivated attacks such as Operation Aurora, which struck Google and other hit-tech firms last year.</p>
<p>&#8220;Unlike known malware kits such as Zeus, Torpig, and Ambler which simultaneously target hundreds of banks and enterprises around the world and are on the radar of all security vendors, regional financial malware such as Silon.var2 and Agent.DBJP are highly targeted,&#8221; said Mickey Boodaei, Trusteer&#8217;s chief exec.</p>
<p>&#8220;In the UK, each campaign would usually focus on three to seven banks and target them for a period of six to nine months and then morph and change the list of targets, using a new more advanced version of the malware.”</p>
<p>Regionally-targeted malware has also cropped up in South Africa and Germany over recent months. A strain of malware called Yaludle, almost unseen outside Germany, has been used to target the online banking credentials of German surfers. Trusteer is urging banks to share information on targeted attacks locally as well as working with regulators and local law enforcement agencies to shut down command and control servers associated with regionally-targeted malware. The firm, naturally enough, also wants to persuade more banks to use its Rapport secure browsing software as a way of providing an extra defence against fraud.</p></blockquote>
<p>As the report states, it&#8217;s started to appear in other countries too such as Germany and South Africa. If you live in a non-major country, I&#8217;d imagine it&#8217;ll be coming to your shores soon enough. I already started seeing regionally targeted phishing e-mails here last year, I&#8217;d expect the location aware trojans to hit soon too.</p>
<p>The trojans were actually identified by Trusteer&#8217;s Flashlight service, which is a kind of <a href="http://www.darknet.org.uk/category/forensics/">forensics</a> software for banking. It allows  banks to diagnose whether a client&#8217;s PC has been infected with <a href="http://www.darknet.org.uk/category/virustrojanswormsrootkits/">malware</a> following incidents of suspected fraud.</p>
<p>Anyway interesting stuff, if you work in the financial sector give those upstairs a heads-up about this, if you have a big user-base &#8211; please warn your users too.</p>
<p></p>
<p>Source: <a href="http://www.theregister.co.uk/2010/07/01/regional_trojan_threat/">The Register</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Regional+Trojan+Threat+Targeting+Online+Banks+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2785+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/07/regional-trojan-threat-targeting-online-banks/&amp;t=Regional+Trojan+Threat+Targeting+Online+Banks" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/07/regional-trojan-threat-targeting-online-banks/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/07/regional-trojan-threat-targeting-online-banks/&amp;title=Regional+Trojan+Threat+Targeting+Online+Banks" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/07/regional-trojan-threat-targeting-online-banks/&amp;title=Regional+Trojan+Threat+Targeting+Online+Banks" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/07/regional-trojan-threat-targeting-online-banks/&amp;title=Regional+Trojan+Threat+Targeting+Online+Banks" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/07/regional-trojan-threat-targeting-online-banks/&amp;title=Regional+Trojan+Threat+Targeting+Online+Banks" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F07%2Fregional-trojan-threat-targeting-online-banks%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/07/regional-trojan-threat-targeting-online-banks/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Brittany Murphy Dies &amp; Scareware Scammers Strike</title>
		<link>http://www.darknet.org.uk/2009/12/brittany-murphy-dies-scareware-scammers-strike/</link>
		<comments>http://www.darknet.org.uk/2009/12/brittany-murphy-dies-scareware-scammers-strike/#comments</comments>
		<pubDate>Tue, 22 Dec 2009 10:35:04 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[Spammers & Scammers]]></category>
		<category><![CDATA[britanny murphy dead]]></category>
		<category><![CDATA[brittany murphy]]></category>
		<category><![CDATA[brittany murphy dies]]></category>
		<category><![CDATA[brittany murphy malware]]></category>
		<category><![CDATA[brittany murphy scam]]></category>
		<category><![CDATA[brittany murphy spam]]></category>
		<category><![CDATA[brittany murphy virus]]></category>
		<category><![CDATA[fakevimes]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[scammers]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2374</guid>
		<description><![CDATA[It seems to be a trend now, whenever someone famous dies some kind of malware or phishing scam will pop up playing on their death with the usual social engineering aspect. The most memorable one recently of course was the passing of The King of Pop &#8211; Michael Jackson The latest one is Brittany Murphy [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>It seems to be a trend now, whenever someone famous dies some kind of malware or phishing scam will pop up playing on their death with the usual <a href="http://www.darknet.org.uk/category/social-engineering/">social engineering</a> aspect.</p>
<p>The most memorable one recently of course was the passing of <a href="http://www.darknet.org.uk/2009/06/michael-jackon-spammalware-rip-the-king-of-pop/">The King of Pop &#8211; Michael Jackson</a></p>
<p>The latest one is Brittany Murphy who passed away last Sunday, search results lead users to fake anti-virus products labeled as &#8216;scareware&#8217; tactics.</p>
<blockquote><p>Actress Brittany Murphy&#8217;s sudden death, just like Michael Jackson&#8217;s untimely demise before her, has quickly been exploited by scareware scammers.</p>
<p>A spike in searches on Murphy&#8217;s death has been taken as a theme for Black Hat SEO attacks, designed to push sites that have been hacked to redirect surfers to scareware portals into prominence in search engine results.</p>
<p>Windows users who click on links to poisoned search results get exposed to a fake anti-virus scan, designed to frighten users into buying rogue security software of little or no utility.</p></blockquote>
<p>They have to act fast of course to get their results ranking at the top during the aftermath of a celebrity death.</p>
<p>For most tech-savvy users I don&#8217;t think it would be much of an issue, but for the average joe it seems they are fairly gullible when it comes to promises of anti-viral solutions.</p>
<blockquote><p>Net security firm F-Secure, which has a full write-up of the attack <a href="http://www.f-secure.com/weblog/archives/00001842.html">here</a>, detects the strain of scareware involved in the attack as Fakevimes-T. More detail on how search results were poisoned can be found in a blog posting be WebSense <a href="http://securitylabs.websense.com/content/Alerts/3514.aspx">here</a>.</p>
<p>Murphy, who starred in movies including 8 Mile, Sin City and Spun died on Sunday, 20 December after <a href="http://www.tackynews.com/2009/12/21/brittany-murphy-is-dead/">collapsing at her LA home</a>. She was only 32. The precise cause of death is yet to be determined but an autopsy is planned. ®</p></blockquote>
<p>It&#8217;s a sad event nevertheless and I hope the news doesn&#8217;t come out that yet another celebrity died from a drug overdose.</p>
<p>It has been rumoured that Brittany Murphy used drugs due to intense Hollywood pressure to maintain her slim stature.</p>
<p>Oh well, Merry Christmas indeed!</p>
<p></p>
<p>Source: <a href="http://www.theregister.co.uk/2009/12/21/brittany_murphy_scareware/">The Register</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Brittany+Murphy+Dies+%26+Scareware+Scammers+Strike+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2374+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/12/brittany-murphy-dies-scareware-scammers-strike/&amp;t=Brittany+Murphy+Dies+%26+Scareware+Scammers+Strike" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2009/12/brittany-murphy-dies-scareware-scammers-strike/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/12/brittany-murphy-dies-scareware-scammers-strike/&amp;title=Brittany+Murphy+Dies+%26+Scareware+Scammers+Strike" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/12/brittany-murphy-dies-scareware-scammers-strike/&amp;title=Brittany+Murphy+Dies+%26+Scareware+Scammers+Strike" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2009/12/brittany-murphy-dies-scareware-scammers-strike/&amp;title=Brittany+Murphy+Dies+%26+Scareware+Scammers+Strike" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/12/brittany-murphy-dies-scareware-scammers-strike/&amp;title=Brittany+Murphy+Dies+%26+Scareware+Scammers+Strike" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2009%2F12%2Fbrittany-murphy-dies-scareware-scammers-strike%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/12/brittany-murphy-dies-scareware-scammers-strike/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Facebook E-mail Spam Conceals Malware Attack</title>
		<link>http://www.darknet.org.uk/2009/10/facebook-e-mail-spam-conceals-malware-attack/</link>
		<comments>http://www.darknet.org.uk/2009/10/facebook-e-mail-spam-conceals-malware-attack/#comments</comments>
		<pubDate>Wed, 28 Oct 2009 09:47:07 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[Spammers & Scammers]]></category>
		<category><![CDATA[anti sandbox]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[bredolab]]></category>
		<category><![CDATA[bredolab trojan]]></category>
		<category><![CDATA[cutwail]]></category>
		<category><![CDATA[drone]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[facebook password]]></category>
		<category><![CDATA[facebook security]]></category>
		<category><![CDATA[facebook spam]]></category>
		<category><![CDATA[hacking-facebook]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[password theft]]></category>
		<category><![CDATA[pushdo]]></category>
		<category><![CDATA[sandbox]]></category>
		<category><![CDATA[scam]]></category>
		<category><![CDATA[scammers]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[spammers]]></category>
		<category><![CDATA[viruses]]></category>
		<category><![CDATA[worm]]></category>
		<category><![CDATA[zombie]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2236</guid>
		<description><![CDATA[Facebook has had a fair share of problems, being a large community of course it&#8217;s going to be a ripe target for spammers, scammers and malware distributors. The latest to hit is a spam e-mail claiming to be from the Facebook team that actually spreads a nasty piece of malware called Bredolab. It&#8217;s also been [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p><a href="http://www.darknet.org.uk/tag/facebook/">Facebook</a> has had a fair share of problems, being a large community of course it&#8217;s going to be a ripe target for spammers, scammers and malware distributors.</p>
<p>The latest to hit is a spam e-mail claiming to be from the Facebook team that actually spreads a nasty piece of malware called Bredolab. It&#8217;s also been observed the trojan will connect to additional servers to install more malware.</p>
<p>The ultimate goal as usual is to make the victims part of a <a href="http://www.darknet.org.uk/tag/botnet/">botnet</a>. </p>
<blockquote><p>Researchers at several security firms have uncovered a spam campaign targeting Facebook users. The e-mails, which pose as communications from Facebook about password resets, contain a nasty downloader that ultimately makes users part of a notorious botnet.</p>
<p>Researchers at several security firms have tied the Bredolab Trojan to a spam campaign targeting Facebook users.</p>
<p>The malware is being blasted out by spammers in e-mails claiming to come from “The Facebook Team.&#8221; Inside the e-mails is a message that the recipient&#8217;s Facebook password has been changed. In order to get the new one, recipients are told to open the accompanying attachment containing the malware.</p>
<p> Researchers at Websense told eWEEK Oct. 27 that they have observed more than 350,000 of the messages. On the company’s blog, researchers explained that the malware connects to two servers to download additional malicious files. Among them is Pushdo, also known as Cutwail.</p></blockquote>
<p>This spam campaign seems to be generating some fairly high levels of traffic meaning whoever is behind it is pretty serious and committed to this vector for disseminating malware.</p>
<p>Social engineering isn&#8217;t a new method for propagating malware as always the weakest link is never the technological barriers but is always the stupidity/greed/gullibility of humans.</p>
<p>You can ALWAYS hack the wetware.</p>
<blockquote><p>&#8220;One of the first things we saw this Trojan horse download was the Pushdo bot which began spamming out more of these Facebook password reset emails,” according to M86 Security. </p>
<p>MX Logic noted that Bredolab bypasses firewalls by injecting its own code into the legitimate process svchost.exe and explorer.exe. It also contains anti-sandbox code to thwart researchers, and creates the following files: %AppData%\wiaservg.log, %Windir%\temp\wpv861256600826.exe and %Programs%\Startup\isqsys32.exe. Bredolab also creates the processes isqsys32.exe and svchost.exe.</p>
<p>Sophos is detecting the malware as Troj/BredoZp-M or Mal/Bredo-A.</p>
<p>&#8220;Don&#8217;t make life easy for the hackers hell-bent on infecting your computer, stealing your identity and emptying your bank account &#8211; exercise caution when you receive unsolicited emails and protect your computer with up-to-date security software,&#8221; Graham Cluley, senior technology consultant at Sophos, advised in a blog post.</p></blockquote>
<p>It looks like a pretty advanced piece of malware code which evades firewall measures and even tries to thwart analysis by AV companies.</p>
<p>Anti sandbox code and process injection, these bad guys are getting smart.</p>
<p>That does not bode well for the average citizen.</p>
<p></p>
<p>Source: <a href="http://www.eweek.com/c/a/Security/Facebook-Password-Spam-Conceals-Malware-Attack-635899/?kc=rss">eWeek</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Facebook+E-mail+Spam+Conceals+Malware+Attack+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2236+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/10/facebook-e-mail-spam-conceals-malware-attack/&amp;t=Facebook+E-mail+Spam+Conceals+Malware+Attack" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2009/10/facebook-e-mail-spam-conceals-malware-attack/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/10/facebook-e-mail-spam-conceals-malware-attack/&amp;title=Facebook+E-mail+Spam+Conceals+Malware+Attack" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/10/facebook-e-mail-spam-conceals-malware-attack/&amp;title=Facebook+E-mail+Spam+Conceals+Malware+Attack" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2009/10/facebook-e-mail-spam-conceals-malware-attack/&amp;title=Facebook+E-mail+Spam+Conceals+Malware+Attack" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/10/facebook-e-mail-spam-conceals-malware-attack/&amp;title=Facebook+E-mail+Spam+Conceals+Malware+Attack" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2009%2F10%2Ffacebook-e-mail-spam-conceals-malware-attack%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/10/facebook-e-mail-spam-conceals-malware-attack/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Michael Jackon Spam/Malware &#8211; RIP The King Of Pop</title>
		<link>http://www.darknet.org.uk/2009/06/michael-jackon-spammalware-rip-the-king-of-pop/</link>
		<comments>http://www.darknet.org.uk/2009/06/michael-jackon-spammalware-rip-the-king-of-pop/#comments</comments>
		<pubDate>Mon, 29 Jun 2009 10:42:02 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[Spammers & Scammers]]></category>
		<category><![CDATA[michael jackson]]></category>
		<category><![CDATA[michael jackson dead]]></category>
		<category><![CDATA[michael jackson malware]]></category>
		<category><![CDATA[michael jackson spam]]></category>
		<category><![CDATA[michael jackson virus]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[twitter malware]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[viruses]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1897</guid>
		<description><![CDATA[For people of my age and generation and I&#8217;d guess for most readers of Darknet, Michael Jackson would have had a great influence on our lives. The biggest news last week was most certainly his death, as usual the bad guys were extremely quick to capitalize on this and were sending out spam within hours [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>For people of my age and generation and I&#8217;d guess for most readers of Darknet, Michael Jackson would have had a great influence on our lives.</p>
<p>The biggest news last week was most certainly his death, as usual the bad guys were extremely quick to capitalize on this and were sending out spam within hours of the announcement.</p>
<p>It was suspected malware would follow shortly after, and it did <a href="http://www.f-secure.com/weblog/archives/00001709.html">according to F-secure</a>.</p>
<blockquote><p>Within hours of the death of pop star Michael Jackson, spam trading on his demise hit inboxes, a security firm said today as it warned that more was in the offing.</p>
<p>Just eight hours after news broke about Jackson, U.K.-based Sophos started tracking the first wave of Jackson spam, which used a subject head of &#8220;Confidential &#8212; Michael Jackson.&#8221; The spam wasn&#8217;t pitching a product or leading users to a phishing or malware Web site, but instead was trying to dupe users into replying to the message in order to collect e-mail addresses and verify them as legitimate.</p>
<p>&#8220;The body of the spam message does not contain any call-to-action link such as a URL, e-mail or phone number,&#8221; said Sophos in its company&#8217;s blog today. &#8220;But the spammer can harvest receivers&#8217; e-mail addresses via a free live e-mail address if the spam message is replied to.&#8221; </p></blockquote>
<p>The original versions were just plain old spam to harvest addresses, but later malware laden versions followed which dropped IRC bots and backdoors detected as &#8220;Trojan.Win32.Buzus.bjyo&#8221;.</p>
<p>It&#8217;s sad to see such things happening, but social engineering attacks to spread malware are always expected when some big news like this breaks.</p>
<p>Nothing is sacred to the dark side of the Internet.</p>
<blockquote><p>The timing of that campaign was not coincidental: It followed Jackson&#8217;s acquittal on all charges in child sexual abuse. &#8220;The news of his suicide attempt was believable,&#8221; said Cluley, who noted that scammers and hackers often trade on tragedies to get people to click links. In that case, users were hit with a hacker toolkit that tried several exploits against Internet Explorer.</p>
<p>&#8220;I wouldn&#8217;t be surprised to see hackers claiming that they have top-secret footage from the hospital, perhaps [allegedly] taken by the ambulance people, that then asks you to install a video codec,&#8221; said Cluley, talking about a common malware ploy. Users who click on the supposed codec update link are, in fact, then infected with attack code, often a bot that hijacks their computer. </p></blockquote>
<p>So do warn people, if someone e-mails them pictures or videos claiming to be secret or exclusive footage surrounding the death of Michael Jackson &#8211; it&#8217;s most likely an infection vector.</p>
<p>Common sense prevails, but is sadly not common.</p>
<p>RIP Michael.</p>
<p></p>
<p>Source: <a href="http://www.networkworld.com/news/2009/062609-michael-jackson-spam-spreads-malware.html">Network World</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Michael+Jackon+Spam%2FMalware+%E2%80%93+RIP+The+King+Of+Pop+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1897+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/06/michael-jackon-spammalware-rip-the-king-of-pop/&amp;t=Michael+Jackon+Spam%2FMalware+%E2%80%93+RIP+The+King+Of+Pop" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2009/06/michael-jackon-spammalware-rip-the-king-of-pop/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/06/michael-jackon-spammalware-rip-the-king-of-pop/&amp;title=Michael+Jackon+Spam%2FMalware+%E2%80%93+RIP+The+King+Of+Pop" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/06/michael-jackon-spammalware-rip-the-king-of-pop/&amp;title=Michael+Jackon+Spam%2FMalware+%E2%80%93+RIP+The+King+Of+Pop" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2009/06/michael-jackon-spammalware-rip-the-king-of-pop/&amp;title=Michael+Jackon+Spam%2FMalware+%E2%80%93+RIP+The+King+Of+Pop" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/06/michael-jackon-spammalware-rip-the-king-of-pop/&amp;title=Michael+Jackon+Spam%2FMalware+%E2%80%93+RIP+The+King+Of+Pop" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2009%2F06%2Fmichael-jackon-spammalware-rip-the-king-of-pop%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/06/michael-jackon-spammalware-rip-the-king-of-pop/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Using Twitter for Data Mining and Information Gathering</title>
		<link>http://www.darknet.org.uk/2009/01/using-twitter-for-data-mining-and-information-gathering/</link>
		<comments>http://www.darknet.org.uk/2009/01/using-twitter-for-data-mining-and-information-gathering/#comments</comments>
		<pubDate>Thu, 22 Jan 2009 10:46:31 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[General Hacking]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[5and2fish]]></category>
		<category><![CDATA[data-mining]]></category>
		<category><![CDATA[hacking twitter]]></category>
		<category><![CDATA[information gathering]]></category>
		<category><![CDATA[PeopleBrowsr]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[twitter data mining]]></category>
		<category><![CDATA[twitter hacking]]></category>
		<category><![CDATA[twitter information gathering]]></category>
		<category><![CDATA[twitter privacy]]></category>
		<category><![CDATA[Twitter Spectrum]]></category>
		<category><![CDATA[Twitter Venn]]></category>
		<category><![CDATA[TwitterFriends]]></category>
		<category><![CDATA[Twitturly]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1423</guid>
		<description><![CDATA[We&#8217;ve mentioned Twitter a few times lately as it has become a larger and larger part of the social web and the premier &#8216;micro-blogging&#8217; platform. There was a recent Phishing issue on Twitter and before that Twitter Jacking and a CSRF bug that allowed auto-following. Due to the large update of Twitter, the amount of [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>We&#8217;ve mentioned <a href="http://www.darknet.org.uk/tag/twitter/">Twitter</a> a few times lately as it has become a larger and larger part of the social web and the premier &#8216;micro-blogging&#8217; platform.</p>
<p>There was a recent <a href="http://www.darknet.org.uk/2009/01/phishing-attacks-hits-twitter-users-utilising-direct-messages/">Phishing issue on Twitter</a> and before that <a href="http://www.darknet.org.uk/2008/11/twitter-squatting-the-new-domain-jacking/">Twitter Jacking</a> and a <a href="http://www.darknet.org.uk/2008/09/csrf-vulnerability-in-twitter-allows-forced-following/">CSRF bug that allowed auto-following</a>.</p>
<p>Due to the large update of Twitter, the amount of datable available on the site and it&#8217;s easily searchable nature it has become a great platform for data-mining and information gathering (the first and sometimes most important parts of any pen test/vuln ass or security test).</p>
<blockquote><p>Twitter is fun. It&#8217;s also a powerful research tool. People increasingly use Twitter to share advice, opinions, news, moods, concerns, facts, rumors, and everything else imaginable. Much of that data is public and available for mining.</p>
<p>Here&#8217;s how to use Twitter to gather useful information about topics, companies, and individuals. I&#8217;ll cover native Twitter features, as well as third-party tools with catchy names, such as 5and2fish, Twitter Venn, TwitterFriends, PeopleBrowsr , Twitturly, Twitter Spectrum, and others.</p>
<p>Most of the techniques mentioned here don&#8217;t require you to be a registered Twitter user. If you use Twitter, consider what data tidbits you release there, and whether you need to be more careful.</p></blockquote>
<p>People don&#8217;t tend to be so careful or post in such a considered manner when using Twitter as the tidbits posted are so short and off-the-cuff.</p>
<p>This leads to an interesting source of information for people like us doing research about an individual or organization. You can really get a good gauge on the publics feelings for a certain topic too by searching Twitter for relevant keywords.</p>
<p>For example if you search Twitter for &#8216;<a href="http://search.twitter.com/search?q=darknet">Darknet</a>&#8216; you can see some people mentioning our posts and one guy pretty consistently re-syndicating our content onto the micro-blogging platform.</p>
<blockquote><p>As you gather information on Twitter, be mindful of others attempting to manipulate you into arriving at their conclusions by feeding you misinformation. Cross-check data and understand its sources. For more on this, see Is Twitter A Market Manipulator&#8217;s Dream on the TwiTip blog. If the topic of reputational attacks interests you, also look at the SpinHunters blog.</p>
<p>If using Twitter to share information and stay in touch with your friends, be mindful of how others might misuse what you reveal about yourself, others, or your company. In the words of Wired magazine&#8217;s Steven Levy, &#8220;No matter how innocuous your individual tweets, the aggregate ends up being the foundation of a scary-deep self-portrait. It&#8217;s like a psychographic version of strip poker&#8211;I&#8217;m disrobing, 140 characters at a time.&#8221;</p></blockquote>
<p>It&#8217;s an article well worth reading if you are a Twitter user or not, if you are an infosec professional it gives you another source to search when you are doing information gathering or data-mining tasks.</p>
<p>The Internet is always evolving along with the way people use it, as it becomes a more social platform &#8211; more information is bound to be &#8216;<em>exposed</em>&#8216; online &#8211; for us to find..</p>
<p></p>
<p>Source: <a href="http://isc.sans.org/diary.html?storyid=5728&#038;rss">SANS ISC</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Using+Twitter+for+Data+Mining+and+Information+Gathering+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1423+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/01/using-twitter-for-data-mining-and-information-gathering/&amp;t=Using+Twitter+for+Data+Mining+and+Information+Gathering" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2009/01/using-twitter-for-data-mining-and-information-gathering/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/01/using-twitter-for-data-mining-and-information-gathering/&amp;title=Using+Twitter+for+Data+Mining+and+Information+Gathering" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/01/using-twitter-for-data-mining-and-information-gathering/&amp;title=Using+Twitter+for+Data+Mining+and+Information+Gathering" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2009/01/using-twitter-for-data-mining-and-information-gathering/&amp;title=Using+Twitter+for+Data+Mining+and+Information+Gathering" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/01/using-twitter-for-data-mining-and-information-gathering/&amp;title=Using+Twitter+for+Data+Mining+and+Information+Gathering" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2009%2F01%2Fusing-twitter-for-data-mining-and-information-gathering%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/01/using-twitter-for-data-mining-and-information-gathering/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Scammers Using Asterisk VoIP Systems to Make Calls</title>
		<link>http://www.darknet.org.uk/2008/12/scammers-using-asterisk-voip-systems-to-make-calls/</link>
		<comments>http://www.darknet.org.uk/2008/12/scammers-using-asterisk-voip-systems-to-make-calls/#comments</comments>
		<pubDate>Mon, 08 Dec 2008 11:43:31 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[asterisk]]></category>
		<category><![CDATA[asterisk scam]]></category>
		<category><![CDATA[asterisk spam]]></category>
		<category><![CDATA[asterisk vulnerability]]></category>
		<category><![CDATA[digium]]></category>
		<category><![CDATA[hacking voip]]></category>
		<category><![CDATA[scammers]]></category>
		<category><![CDATA[spammers]]></category>
		<category><![CDATA[vishing]]></category>
		<category><![CDATA[voice-over-IP]]></category>
		<category><![CDATA[voip]]></category>
		<category><![CDATA[voip phishing]]></category>
		<category><![CDATA[voip scam]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1296</guid>
		<description><![CDATA[It seems like &#8216;vishing&#8216; (basically Phishing &#8211; but utilising VoIP call services) as it&#8217;s known is getting bigger, especially since the scammers have been using a flaw in Asterisk systems that allows them to hijack the VoIP exchange. Older versions of Asterisk do have quite a number of serious flaws and it looks like scammers [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>It seems like &#8216;<a href="http://www.darknet.org.uk/tag/vishing/">vishing</a>&#8216; (basically <a href="http://www.darknet.org.uk/category/phishing/">Phishing</a> &#8211; but utilising VoIP call services) as it&#8217;s known is getting bigger, especially since the scammers have been using a flaw in Asterisk systems that allows them to hijack the VoIP exchange.</p>
<p>Older versions of Asterisk do have quite a number of serious flaws and it looks like scammers and phishing crews have been exploiting these to make thousands of outbound calls. The traditional way they did this was to setup the exchange themselves so they can receive calls that follow-up to their phishing e-mails.</p>
<blockquote><p>Criminals are taking advantage of a bug in the Asterisk Internet telephony system that lets them pump out thousands of scam phone calls in an hour, the U.S. Federal Bureau of Investigation warned Friday.</p>
<p>The FBI didn&#8217;t say which versions of Asterisk were vulnerable to the bug, but it advised users to upgrade to the latest version of the software. Asterisk is an open-source product that lets users turn a Linux computer into a VoIP (Voice over Internet Protocol) telephone exchange. </p>
<p>In so-called vishing attacks, scammers usually use a VoIP system to set up a phony call center and then use phishing e-mails to trick victims into calling the center. Once there, they are prompted to give private information. But in the scam described by the FBI, they apparently are taking over legitimate Asterisk systems in order to directly dial victims. </p></blockquote>
<p>So if you are running any kind of Asterisk exchange or derivative (even a hardware based VoIP device based on Asterisk) please make sure you&#8217;ve updated to the latest version (this includes firmware for hardware devices).</p>
<p>If not you might find yourself with a very large phone bill that&#8217;s hard to explain.</p>
<blockquote><p>&#8220;Early versions of the Asterisk software are known to have a vulnerability,&#8221; the FBI said in an advisory posted Friday to the Internet Crime Complaint Center. &#8220;The vulnerability can be exploited by cyber criminals to use the system as an auto dialer, generating thousands of vishing telephone calls to consumers within one hour.&#8221;</p>
<p>The software, developed by Digium, has been available for nearly a decade, and a number of critical flaws have been found in the software. In March, researchers at Mu Security reported a bug that could allow an attacker to take control of an Asterisk system.</p></blockquote>
<p>With the digital nature of Asterisk it&#8217;s very easy to dial out then play back a mp3 or wav file that was pre-recorded by the phisher.</p>
<p>They don&#8217;t need to take a lot of effort to do this, I imagine they just write a script that auto-generates the phone numbers to dial &#8211; then away it goes. Whatever the victim needs to do will be contained within the voice message.</p>
<p>I can&#8217;t believe people still fall for these things, but well they do.</p>
<p></p>
<p>Source: <a href="http://www.networkworld.com/news/2008/120608-fbi-criminals-auto-dialing-with-hacked.html?fsrc=rss-security">Network World</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Scammers+Using+Asterisk+VoIP+Systems+to+Make+Calls+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1296+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2008/12/scammers-using-asterisk-voip-systems-to-make-calls/&amp;t=Scammers+Using+Asterisk+VoIP+Systems+to+Make+Calls" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2008/12/scammers-using-asterisk-voip-systems-to-make-calls/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2008/12/scammers-using-asterisk-voip-systems-to-make-calls/&amp;title=Scammers+Using+Asterisk+VoIP+Systems+to+Make+Calls" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2008/12/scammers-using-asterisk-voip-systems-to-make-calls/&amp;title=Scammers+Using+Asterisk+VoIP+Systems+to+Make+Calls" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2008/12/scammers-using-asterisk-voip-systems-to-make-calls/&amp;title=Scammers+Using+Asterisk+VoIP+Systems+to+Make+Calls" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2008/12/scammers-using-asterisk-voip-systems-to-make-calls/&amp;title=Scammers+Using+Asterisk+VoIP+Systems+to+Make+Calls" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2008%2F12%2Fscammers-using-asterisk-voip-systems-to-make-calls%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2008/12/scammers-using-asterisk-voip-systems-to-make-calls/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

