<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; Social Engineering</title>
	<atom:link href="http://www.darknet.org.uk/tag/social-engineering/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Social Engineering Vulnerability Evaluation and Recommendation Project</title>
		<link>http://www.darknet.org.uk/2011/12/social-engineering-vulnerability-evaluation-and-recommendation-project/</link>
		<comments>http://www.darknet.org.uk/2011/12/social-engineering-vulnerability-evaluation-and-recommendation-project/#comments</comments>
		<pubDate>Thu, 22 Dec 2011 15:52:25 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[formal methodology for social engineering]]></category>
		<category><![CDATA[formal social engineering structure]]></category>
		<category><![CDATA[how to social engineer]]></category>
		<category><![CDATA[how to use social engineering]]></category>
		<category><![CDATA[sever]]></category>
		<category><![CDATA[social engineering for penetration testers]]></category>
		<category><![CDATA[social engineering guide]]></category>
		<category><![CDATA[social engineering how to]]></category>
		<category><![CDATA[social engineering methodology]]></category>
		<category><![CDATA[social engineering methods]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3115</guid>
		<description><![CDATA[Social engineering has been around for tens of thousands of years so it is time we approach the topic in a professional manner. The Social Engineering Vulnerability Evaluation and Recommendation (SEVER) Project is one way to help penetration testers become more consistent. It is also intended to be the best way to teach novices about [...]]]></description>
			<content:encoded><![CDATA[<p>Social engineering has been around for tens of thousands of years so it is time we approach the topic in a professional manner. The Social Engineering Vulnerability Evaluation and Recommendation (SEVER) Project is one way to help penetration testers become more consistent.  It is also intended to be the best way to teach novices about social engineering concepts.</p>
<p>By distilling thousands of pages of theory into a simple form the SEVER project hopes to: </p>
<ol>
<li>Provide the fastest means of training novices about complex social engineering concepts.</li>
<li>Provide penetration testers with a methodology that minimizes their effort while increasing their chance of success. </li>
</ol>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<p>You will begin by defining requirements, then brainstorm solutions, and then refine your solutions through multiple phases. Each phase increases in detail, allowing you to identify &#8216;show stoppers&#8217; as soon as possible. This will help you avoid wasting time working on a plan that is not going to succeed. If an idea makes it through the entire process and you still feel good about it then you should have a very high chance of success. </p>
<p>The best format for this content would be an electronic form with a lot of context-sensitive notes. But since there is currently no effective, portable way of accomplishing that I decided to split the content into two PDF files – the SEVER Worksheet and the SEVER Instructions. Go through these instructions while you fill out the form until you have a thorough understanding of how the form works. If you cheat and try to do one before the other (or skip the instructions altogether) you will miss things which will make failure far more likely.</p>
<p>You can download both papers here:</p>
<p>- <a href="http://www.kgb.to/SEVER_Instructions_Final.pdf">SEVER_Instructions_Final.pdf</a><br />
- <a href="http://www.kgb.to/SEVER_Worksheet_Final.pdf">SEVER_Worksheet_Final.pdf</a></p>
<p>Or read more <a href="http://www.kgb.to/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Social+Engineering+Vulnerability+Evaluation+and+Recommendation+Project+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3115+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/12/social-engineering-vulnerability-evaluation-and-recommendation-project/&amp;t=Social+Engineering+Vulnerability+Evaluation+and+Recommendation+Project" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/12/social-engineering-vulnerability-evaluation-and-recommendation-project/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/12/social-engineering-vulnerability-evaluation-and-recommendation-project/&amp;title=Social+Engineering+Vulnerability+Evaluation+and+Recommendation+Project" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/12/social-engineering-vulnerability-evaluation-and-recommendation-project/&amp;title=Social+Engineering+Vulnerability+Evaluation+and+Recommendation+Project" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/12/social-engineering-vulnerability-evaluation-and-recommendation-project/&amp;title=Social+Engineering+Vulnerability+Evaluation+and+Recommendation+Project" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/12/social-engineering-vulnerability-evaluation-and-recommendation-project/&amp;title=Social+Engineering+Vulnerability+Evaluation+and+Recommendation+Project" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F12%2Fsocial-engineering-vulnerability-evaluation-and-recommendation-project%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/12/social-engineering-vulnerability-evaluation-and-recommendation-project/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Facebook Attachment Uploader Owned By A Space</title>
		<link>http://www.darknet.org.uk/2011/10/facebook-attachment-uploader-owned-by-a-space/</link>
		<comments>http://www.darknet.org.uk/2011/10/facebook-attachment-uploader-owned-by-a-space/#comments</comments>
		<pubDate>Thu, 27 Oct 2011 19:45:01 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[attachment parsing]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[facebook hacking]]></category>
		<category><![CDATA[facebook malware]]></category>
		<category><![CDATA[facebook security]]></category>
		<category><![CDATA[facebook virus]]></category>
		<category><![CDATA[file attachment]]></category>
		<category><![CDATA[file parsing]]></category>
		<category><![CDATA[hacking-facebook]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[malware attachment]]></category>
		<category><![CDATA[malware parsing]]></category>
		<category><![CDATA[nathan power]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Social Engineering]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3219</guid>
		<description><![CDATA[Oh look &#8211; another vulnerability in Facebook! It wasn&#8217;t long ago we reported New Research Shows Facebook’s URL Scanner Is Vulnerable To Cloaking. Well this time the private messaging function has been compromised, you can attach an executable and send it to anyone as long as you put a space after the filename. It&#8217;s not [...]]]></description>
			<content:encoded><![CDATA[<p>Oh look &#8211; another vulnerability in <a href="http://www.darknet.org.uk/tag/facebook/">Facebook</a>! It wasn&#8217;t long ago we reported <a href="http://www.darknet.org.uk/2011/10/new-research-shows-facebooks-url-scanner-is-vulnerable-to-cloaking/">New Research Shows Facebook’s URL Scanner Is Vulnerable To Cloaking</a>.</p>
<p>Well this time the private messaging function has been compromised, you can attach an executable and send it to anyone as long as you put a space after the filename.</p>
<p>It&#8217;s not the first time I&#8217;ve seen a mime/file/etc parser be owned by a space, but I expected better from Facebook to be honest.</p>
<blockquote><p>A security penetration tester discovered a major flaw in Facebook that could allow a person to send anyone on the social-networking site malicious applications.</p>
<p>Nathan Power, a senior security penetration tester at technology consultancy CDW, discovered the vulnerability and publicly disclosed it Thursday on his blog. The flaw was reported to Facebook on Sept. 30, which acknowledged the issue on Wednesday, he wrote.</p>
<p>Power, who could not immediately be reached, wrote that Facebook does not normally allow a person to send an executable attachment using the &#8220;Message&#8221; tab. If you try to do that, it returns the message &#8220;Error Uploading: You cannot attach files of that type.&#8221;</p></blockquote>
<p><a href="http://www.darknet.org.uk/tag/facebook/">Facebook</a> has acknowledged the bug (which is a pretty serious one) but it&#8217;s unknown if they&#8217;ve actually fixed it yet or not.</p>
<p>You can see the original blog post outlining the vulnerability here:</p>
<p><a href="http://www.securitypentest.com/2011/10/facebook-attach-exe-vulnerability.html">Facebook Attach EXE Vulnerability</a></p>
<p>Good job Nathan Power!</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<blockquote><p>Power wrote that an analysis of the browser&#8217;s &#8220;POST&#8221; request sent to Facebook&#8217;s servers showed that a variable called &#8220;filename&#8221; is parsed to see if a file should be allowed. But by simply by modifying the POST request with a space just after the file name, an executable could be attached to the message.</p>
<p>&#8220;This was enough to trick the parser and allow our executable file to be attached and sent in a message,&#8221; Power wrote.</p>
<p>A person would not have to be an approved friend of the sender, as Facebook allows people to send those who are not their friends messages. The danger is that a hacker could use social engineering techniques to coax someone to launched the attachment, which could potentially infect their computer with malicious software.</p>
<p>Facebook representatives contacted in London did not have an immediate response on Thursday afternoon.</p></blockquote>
<p>The dangerous part I can see here is that Facebook allows users to send messages to anyone (with attachments) even if they are not friends. Which makes me wonder, how many random guys are sending girls they don&#8217;t know pictures of their junk as attachments on Faceobok messages&#8230;</p>
<p>I don&#8217;t want to know really.</p>
<p>Anyway this should be a fairly simple fix for Facebook and I&#8217;d imagine they have probably already fixed this or will be doing so fairly soon.</p>
<p>Source: <a href="http://www.networkworld.com/news/2011/102711-researcher-finds-major-flaw-in-252463.html?source=nww_rss">Network World</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Facebook+Attachment+Uploader+Owned+By+A+Space+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3219+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/10/facebook-attachment-uploader-owned-by-a-space/&amp;t=Facebook+Attachment+Uploader+Owned+By+A+Space" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/10/facebook-attachment-uploader-owned-by-a-space/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/10/facebook-attachment-uploader-owned-by-a-space/&amp;title=Facebook+Attachment+Uploader+Owned+By+A+Space" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/10/facebook-attachment-uploader-owned-by-a-space/&amp;title=Facebook+Attachment+Uploader+Owned+By+A+Space" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/10/facebook-attachment-uploader-owned-by-a-space/&amp;title=Facebook+Attachment+Uploader+Owned+By+A+Space" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/10/facebook-attachment-uploader-owned-by-a-space/&amp;title=Facebook+Attachment+Uploader+Owned+By+A+Space" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F10%2Ffacebook-attachment-uploader-owned-by-a-space%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/10/facebook-attachment-uploader-owned-by-a-space/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Penetration Testing Course Pro 1.1 &#8211; New Version &amp; New Module</title>
		<link>http://www.darknet.org.uk/2011/02/penetration-testing-course-pro-1-1-new-version-new-module/</link>
		<comments>http://www.darknet.org.uk/2011/02/penetration-testing-course-pro-1-1-new-version-new-module/#comments</comments>
		<pubDate>Wed, 09 Feb 2011 08:26:38 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[General Hacking]]></category>
		<category><![CDATA[ceh]]></category>
		<category><![CDATA[cisco ccie]]></category>
		<category><![CDATA[eCPPT]]></category>
		<category><![CDATA[elearnsecurity]]></category>
		<category><![CDATA[GCIA]]></category>
		<category><![CDATA[giac]]></category>
		<category><![CDATA[GSEC]]></category>
		<category><![CDATA[learn hacking]]></category>
		<category><![CDATA[learn penetration testing]]></category>
		<category><![CDATA[learn social engineering]]></category>
		<category><![CDATA[learn to hack]]></category>
		<category><![CDATA[network-security]]></category>
		<category><![CDATA[online penetration testing course]]></category>
		<category><![CDATA[online penetration testing training]]></category>
		<category><![CDATA[online security course]]></category>
		<category><![CDATA[online security training]]></category>
		<category><![CDATA[pen-test]]></category>
		<category><![CDATA[pen-testing]]></category>
		<category><![CDATA[penetration testing course]]></category>
		<category><![CDATA[penetration testing lab]]></category>
		<category><![CDATA[penetration testing training]]></category>
		<category><![CDATA[penetration-testing]]></category>
		<category><![CDATA[sans gcia]]></category>
		<category><![CDATA[sans giac]]></category>
		<category><![CDATA[sans gsec]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[social engineering toolkit]]></category>
		<category><![CDATA[system-security]]></category>
		<category><![CDATA[vulnerability-assessment]]></category>
		<category><![CDATA[web-application-security]]></category>
		<category><![CDATA[what ceh should have been]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3046</guid>
		<description><![CDATA[Penetration Testing Course Pro 1.1 release aims at addressing all of the suggestions collected in the first 6 months of activity and adds 1 new module and 50 minutes of video training on Social Engineering Toolkit. As reviewed by us before (eLearnSecurity – Online Penetration Testing Training) this course is becoming a very popular choice [...]]]></description>
			<content:encoded><![CDATA[<p>Penetration Testing Course Pro 1.1 release aims at addressing all of the suggestions collected in the first 6 months of activity and adds 1 new module and 50 minutes of video training on Social Engineering Toolkit. As reviewed by us before (<a href="http://www.darknet.org.uk/2010/05/elearnsecurity-online-penetration-testing-training/">eLearnSecurity – Online Penetration Testing Training</a>) this course is becoming a very popular choice for <a href="http://www.elearnsecurity.com/course/penetration_testing/">Penetration Testing Training</a>.</p>
<p align="center"><a href="http://www.elearnsecurity.com/"><img src="http://farm4.static.flickr.com/3416/4641585136_8123f4ca6e_o.png" alt="eLearnSecurity" /></a></p>
<p>In the first 6 months of the course there has been an unexpected success and eCPPT, first born as a proof of attendance of the course, is now in the certification path of a lot of students in 2011 as a preparatory course for more advanced courses.</p>
<p>As for the changes and the additions, as you should know the area of <a href="http://www.darknet.org.uk/tag/social-engineering/">Social Engineering</a> has changed in the last 2-3 years and social networks and the <a href="http://www.darknet.org.uk/2010/10/the-social-engineer-toolkit-set-computer-based-social-engineering-tools/">Social Engineer Toolkit</a> have boosted the number of targeted and advanced attacks against people.</p>
<p>Students of eCPPT will now learn everything about SET and will be introduced to Social Engineering with nice real world scenarios and the use of social networking tools for advanced attacks.</p>
<p>The great thing is that the existing students got this update for free and they will continue to get new updated for free until 2.0 release. </p>
<p>The course developers also realized that the most important feature for their students was the opportunity of getting their exam report reviewed by an instructor and to recieve real feedback. So the certification is felt by the student as a final test on the skills acquired as well as yet another opportunity to learn more about the business and professional aspects of being a pentester.</p>
<p>They also have a lot of cool new projects going on under the radar and they will give word soon, through the Darknet community.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Penetration+Testing+Course+Pro+1.1+%E2%80%93+New+Version+%26+New+Module+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3046+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/02/penetration-testing-course-pro-1-1-new-version-new-module/&amp;t=Penetration+Testing+Course+Pro+1.1+%E2%80%93+New+Version+%26+New+Module" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/02/penetration-testing-course-pro-1-1-new-version-new-module/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/02/penetration-testing-course-pro-1-1-new-version-new-module/&amp;title=Penetration+Testing+Course+Pro+1.1+%E2%80%93+New+Version+%26+New+Module" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/02/penetration-testing-course-pro-1-1-new-version-new-module/&amp;title=Penetration+Testing+Course+Pro+1.1+%E2%80%93+New+Version+%26+New+Module" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/02/penetration-testing-course-pro-1-1-new-version-new-module/&amp;title=Penetration+Testing+Course+Pro+1.1+%E2%80%93+New+Version+%26+New+Module" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/02/penetration-testing-course-pro-1-1-new-version-new-module/&amp;title=Penetration+Testing+Course+Pro+1.1+%E2%80%93+New+Version+%26+New+Module" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F02%2Fpenetration-testing-course-pro-1-1-new-version-new-module%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/02/penetration-testing-course-pro-1-1-new-version-new-module/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>The Social-Engineer Toolkit (SET) &#8211; Computer Based Social Engineering Tools</title>
		<link>http://www.darknet.org.uk/2010/10/the-social-engineer-toolkit-set-computer-based-social-engineering-tools/</link>
		<comments>http://www.darknet.org.uk/2010/10/the-social-engineer-toolkit-set-computer-based-social-engineering-tools/#comments</comments>
		<pubDate>Mon, 25 Oct 2010 10:09:36 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[david kennedy]]></category>
		<category><![CDATA[ettercap]]></category>
		<category><![CDATA[java]]></category>
		<category><![CDATA[java applet attack]]></category>
		<category><![CDATA[metasploit]]></category>
		<category><![CDATA[pen-test]]></category>
		<category><![CDATA[pen-testing]]></category>
		<category><![CDATA[penetration-testing]]></category>
		<category><![CDATA[rel1k]]></category>
		<category><![CDATA[SET]]></category>
		<category><![CDATA[social engineer toolkit]]></category>
		<category><![CDATA[social engineering tools]]></category>
		<category><![CDATA[tabnapping]]></category>
		<category><![CDATA[teensy usb]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2976</guid>
		<description><![CDATA[The Social-Engineer Toolkit (SET) is specifically designed to perform advanced attacks against the human element. SET was designed to be released with the http://www.social-engineer.org launch and has quickly became a standard tool in a penetration testers arsenal. SET was written by David Kennedy (ReL1K) and with a lot of help from the community it has [...]]]></description>
			<content:encoded><![CDATA[<p>The Social-Engineer Toolkit (SET) is specifically designed to perform advanced attacks against the human element. SET was designed to be released with the <a href="http://www.social-engineer.org">http://www.social-engineer.org</a> launch and has quickly became a standard tool in a penetration testers arsenal. SET was written by David Kennedy (ReL1K) and with a lot of help from the community it has incorporated attacks never before seen in an exploitation toolset. The attacks built into the toolkit are designed to be targeted and focused attacks against a person or organization used during a penetration test.</p>
<p>SET is a menu driven based attack system, which is fairly unique when it comes to hacker tools. The decision not to make it command line was made because of how social-engineer attacks occur; it requires multiple scenarios, options, and customizations. If the tool had been command line based it would have really limited the effectiveness of the attacks and the inability to fully customize it based on your target. Let’s dive into the menu and do a brief walkthrough of each attack vector. </p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<p>This is an extremely complete and advanced toolkit, which also harnessed the power of <a href="http://www.darknet.org.uk/tag/metasploit/">Metasploit</a> and <a href="http://www.darknet.org.uk/tag/ettercap/">Ettercap</a> and  it provides following attack vectors:</p>
<ul>
<li>
Spear-Phishing Attack Vector</li>
<li>Java Applet Attack Vector</li>
<li>Metasploit Browser Exploit Method</li>
<li>Credential Harvester Attack Method</li>
<li><a href="http://www.darknet.org.uk/tag/tabnapping/">Tabnabbing</a> Attack Method</li>
<li>Man Left in the Middle Attack Method</li>
<li>Web Jacking Attack Method</li>
<li>Multi-Attack Web Vector</li>
<li>Infectious Media Generator</li>
<li>Teensy USB HID Attack Vector</li>
</ul>
<p>You can find some tutorials and videos on how to get up and running and use SET here:</p>
<p><a href="http://www.social-engineer.org/se-resources/">Social Engineering Resources</a></p>
<p>You can download SET using SVN.</p>
<pre><code>svn co http://svn.secmaniac.com/social_engineering_toolkit set/</code></pre>
<p>Or read more <a href="http://www.social-engineer.org/framework/Computer_Based_Social_Engineering_Tools:_Social_Engineer_Toolkit_%28SET%29">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=The+Social-Engineer+Toolkit+%28SET%29+%E2%80%93+Computer+Based+Social+Engineering+Tools+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2976+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/10/the-social-engineer-toolkit-set-computer-based-social-engineering-tools/&amp;t=The+Social-Engineer+Toolkit+%28SET%29+%E2%80%93+Computer+Based+Social+Engineering+Tools" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/10/the-social-engineer-toolkit-set-computer-based-social-engineering-tools/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/10/the-social-engineer-toolkit-set-computer-based-social-engineering-tools/&amp;title=The+Social-Engineer+Toolkit+%28SET%29+%E2%80%93+Computer+Based+Social+Engineering+Tools" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/10/the-social-engineer-toolkit-set-computer-based-social-engineering-tools/&amp;title=The+Social-Engineer+Toolkit+%28SET%29+%E2%80%93+Computer+Based+Social+Engineering+Tools" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/10/the-social-engineer-toolkit-set-computer-based-social-engineering-tools/&amp;title=The+Social-Engineer+Toolkit+%28SET%29+%E2%80%93+Computer+Based+Social+Engineering+Tools" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/10/the-social-engineer-toolkit-set-computer-based-social-engineering-tools/&amp;title=The+Social-Engineer+Toolkit+%28SET%29+%E2%80%93+Computer+Based+Social+Engineering+Tools" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F10%2Fthe-social-engineer-toolkit-set-computer-based-social-engineering-tools%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/10/the-social-engineer-toolkit-set-computer-based-social-engineering-tools/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Malware Pushers Abuse Firefox Warning Page</title>
		<link>http://www.darknet.org.uk/2010/10/malware-pushers-abuse-firefox-warning-page/</link>
		<comments>http://www.darknet.org.uk/2010/10/malware-pushers-abuse-firefox-warning-page/#comments</comments>
		<pubDate>Thu, 21 Oct 2010 10:12:36 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[Spammers & Scammers]]></category>
		<category><![CDATA[fake firefox warning page]]></category>
		<category><![CDATA[firefox warning page]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[malware pushers]]></category>
		<category><![CDATA[reported attack page]]></category>
		<category><![CDATA[scammers]]></category>
		<category><![CDATA[spammers]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2979</guid>
		<description><![CDATA[This is a pretty neat attack from the malware pushes leveraging on the ignorance of the average user &#8211; which in all honestly is a safe bet most of the time! You could consider it a Social Engineering attack as it&#8217;s taking something that&#8217;s familiar and changing it to deliver malware. I&#8217;m sure all the [...]]]></description>
			<content:encoded><![CDATA[<p>This is a pretty neat attack from the malware pushes leveraging on the ignorance of the average user &#8211; which in all honestly is a safe bet most of the time! You could consider it a <a href="http://www.darknet.org.uk/category/social-engineering/">Social Engineering</a> attack as it&#8217;s taking something that&#8217;s familiar and changing it to deliver malware.</p>
<p>I&#8217;m sure all the Firefox users reading have at some point or another been faced with the warning screen that tells you a site is not safe to visit, the red page which states in big white letters &#8220;Reported Attack Page!&#8221;.</p>
<blockquote><p>Hackers have subverted warnings generated by Firefox about dangerous sites to punt fake anti-virus portals.</p>
<p>Surfers straying onto a web page offering the &#8220;Security Tool&#8221; rogue anti-virus are offered a warning page that convincingly mimics the genuine Firefox block page. The site offers supposed updates for Mozilla&#8217;s technology that are actually scareware packages.</p>
<p>If Windows users apply these updates they will be falsely warned that their system is infected and continuously nagged into buying worthless scareware packages that serve only to line the pockets of cyber-scammers.</p>
<p>The rogue application will automatically attempt to install itself on the machines of prospective marks in cases where scripts are enabled, net security firm F-Secure warns.</p></blockquote>
<p>Personally I&#8217;d say this attack would be pretty effective, my only question would be &#8211; how would the user land on that site in the first place? I guess through the normal channels (e-mail spam, facebook wall worms and so on).</p>
<p>After landing the user would realize they&#8217;ve been spammed/scammed and see the Firefox warning&#8230;then download the &#8216;security update&#8217; and install it &#8211; unknowingly pwning themselves in the process.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<blockquote><p>Firefox&#8217;s genuine attack warning technology is all server-side and never requests that users download updates. The attack relies, in part, on the ignorance of the majority of potential victims on this point.</p>
<p>The attack is a rare but not unprecedented attempt by malware slingers to use Firefox features to push their wares. Previous attacks by the same gang have involved tricking users into downloading scareware in the guise of a supposed Firefox/Flash update.</p>
<p>The malware is offered from a page designed to trick Firefox users into thinking their browser software has just been updated but that they still need to apply a Flash Player patch, which is actually a rogue anti-virus installation utility. The sneaky tactic, first spotted back in July, is explained in more detail in a blog post by F-Secure.</p></blockquote>
<p>It just goes to show the bad guys are pretty creative when it comes to new ways to trick people into installing their malware, I wonder what we&#8217;ll see next?</p>
<p>The full entry by F-Secure can be seen here:</p>
<p><a href="http://www.f-secure.com/weblog/archives/00002051.html">Reported Attack Site! &#8211; Security Tool&#8217;s Latest Trick</a></p>
<p>Source: <a href="http://www.theregister.co.uk/2010/10/20/scareware_scumbags_subvert_firefox_security_warnings/">The Register</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Malware+Pushers+Abuse+Firefox+Warning+Page+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2979+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/10/malware-pushers-abuse-firefox-warning-page/&amp;t=Malware+Pushers+Abuse+Firefox+Warning+Page" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/10/malware-pushers-abuse-firefox-warning-page/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/10/malware-pushers-abuse-firefox-warning-page/&amp;title=Malware+Pushers+Abuse+Firefox+Warning+Page" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/10/malware-pushers-abuse-firefox-warning-page/&amp;title=Malware+Pushers+Abuse+Firefox+Warning+Page" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/10/malware-pushers-abuse-firefox-warning-page/&amp;title=Malware+Pushers+Abuse+Firefox+Warning+Page" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/10/malware-pushers-abuse-firefox-warning-page/&amp;title=Malware+Pushers+Abuse+Firefox+Warning+Page" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F10%2Fmalware-pushers-abuse-firefox-warning-page%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/10/malware-pushers-abuse-firefox-warning-page/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Brittany Murphy Dies &amp; Scareware Scammers Strike</title>
		<link>http://www.darknet.org.uk/2009/12/brittany-murphy-dies-scareware-scammers-strike/</link>
		<comments>http://www.darknet.org.uk/2009/12/brittany-murphy-dies-scareware-scammers-strike/#comments</comments>
		<pubDate>Tue, 22 Dec 2009 10:35:04 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[Spammers & Scammers]]></category>
		<category><![CDATA[britanny murphy dead]]></category>
		<category><![CDATA[brittany murphy]]></category>
		<category><![CDATA[brittany murphy dies]]></category>
		<category><![CDATA[brittany murphy malware]]></category>
		<category><![CDATA[brittany murphy scam]]></category>
		<category><![CDATA[brittany murphy spam]]></category>
		<category><![CDATA[brittany murphy virus]]></category>
		<category><![CDATA[fakevimes]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[scammers]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2374</guid>
		<description><![CDATA[It seems to be a trend now, whenever someone famous dies some kind of malware or phishing scam will pop up playing on their death with the usual social engineering aspect. The most memorable one recently of course was the passing of The King of Pop &#8211; Michael Jackson The latest one is Brittany Murphy [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>It seems to be a trend now, whenever someone famous dies some kind of malware or phishing scam will pop up playing on their death with the usual <a href="http://www.darknet.org.uk/category/social-engineering/">social engineering</a> aspect.</p>
<p>The most memorable one recently of course was the passing of <a href="http://www.darknet.org.uk/2009/06/michael-jackon-spammalware-rip-the-king-of-pop/">The King of Pop &#8211; Michael Jackson</a></p>
<p>The latest one is Brittany Murphy who passed away last Sunday, search results lead users to fake anti-virus products labeled as &#8216;scareware&#8217; tactics.</p>
<blockquote><p>Actress Brittany Murphy&#8217;s sudden death, just like Michael Jackson&#8217;s untimely demise before her, has quickly been exploited by scareware scammers.</p>
<p>A spike in searches on Murphy&#8217;s death has been taken as a theme for Black Hat SEO attacks, designed to push sites that have been hacked to redirect surfers to scareware portals into prominence in search engine results.</p>
<p>Windows users who click on links to poisoned search results get exposed to a fake anti-virus scan, designed to frighten users into buying rogue security software of little or no utility.</p></blockquote>
<p>They have to act fast of course to get their results ranking at the top during the aftermath of a celebrity death.</p>
<p>For most tech-savvy users I don&#8217;t think it would be much of an issue, but for the average joe it seems they are fairly gullible when it comes to promises of anti-viral solutions.</p>
<blockquote><p>Net security firm F-Secure, which has a full write-up of the attack <a href="http://www.f-secure.com/weblog/archives/00001842.html">here</a>, detects the strain of scareware involved in the attack as Fakevimes-T. More detail on how search results were poisoned can be found in a blog posting be WebSense <a href="http://securitylabs.websense.com/content/Alerts/3514.aspx">here</a>.</p>
<p>Murphy, who starred in movies including 8 Mile, Sin City and Spun died on Sunday, 20 December after <a href="http://www.tackynews.com/2009/12/21/brittany-murphy-is-dead/">collapsing at her LA home</a>. She was only 32. The precise cause of death is yet to be determined but an autopsy is planned. ®</p></blockquote>
<p>It&#8217;s a sad event nevertheless and I hope the news doesn&#8217;t come out that yet another celebrity died from a drug overdose.</p>
<p>It has been rumoured that Brittany Murphy used drugs due to intense Hollywood pressure to maintain her slim stature.</p>
<p>Oh well, Merry Christmas indeed!</p>
<p></p>
<p>Source: <a href="http://www.theregister.co.uk/2009/12/21/brittany_murphy_scareware/">The Register</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Brittany+Murphy+Dies+%26+Scareware+Scammers+Strike+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2374+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/12/brittany-murphy-dies-scareware-scammers-strike/&amp;t=Brittany+Murphy+Dies+%26+Scareware+Scammers+Strike" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2009/12/brittany-murphy-dies-scareware-scammers-strike/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/12/brittany-murphy-dies-scareware-scammers-strike/&amp;title=Brittany+Murphy+Dies+%26+Scareware+Scammers+Strike" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/12/brittany-murphy-dies-scareware-scammers-strike/&amp;title=Brittany+Murphy+Dies+%26+Scareware+Scammers+Strike" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2009/12/brittany-murphy-dies-scareware-scammers-strike/&amp;title=Brittany+Murphy+Dies+%26+Scareware+Scammers+Strike" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/12/brittany-murphy-dies-scareware-scammers-strike/&amp;title=Brittany+Murphy+Dies+%26+Scareware+Scammers+Strike" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2009%2F12%2Fbrittany-murphy-dies-scareware-scammers-strike%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/12/brittany-murphy-dies-scareware-scammers-strike/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Facebook E-mail Spam Conceals Malware Attack</title>
		<link>http://www.darknet.org.uk/2009/10/facebook-e-mail-spam-conceals-malware-attack/</link>
		<comments>http://www.darknet.org.uk/2009/10/facebook-e-mail-spam-conceals-malware-attack/#comments</comments>
		<pubDate>Wed, 28 Oct 2009 09:47:07 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[Spammers & Scammers]]></category>
		<category><![CDATA[anti sandbox]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[bredolab]]></category>
		<category><![CDATA[bredolab trojan]]></category>
		<category><![CDATA[cutwail]]></category>
		<category><![CDATA[drone]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[facebook password]]></category>
		<category><![CDATA[facebook security]]></category>
		<category><![CDATA[facebook spam]]></category>
		<category><![CDATA[hacking-facebook]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[password theft]]></category>
		<category><![CDATA[pushdo]]></category>
		<category><![CDATA[sandbox]]></category>
		<category><![CDATA[scam]]></category>
		<category><![CDATA[scammers]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[spammers]]></category>
		<category><![CDATA[viruses]]></category>
		<category><![CDATA[worm]]></category>
		<category><![CDATA[zombie]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2236</guid>
		<description><![CDATA[Facebook has had a fair share of problems, being a large community of course it&#8217;s going to be a ripe target for spammers, scammers and malware distributors. The latest to hit is a spam e-mail claiming to be from the Facebook team that actually spreads a nasty piece of malware called Bredolab. It&#8217;s also been [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p><a href="http://www.darknet.org.uk/tag/facebook/">Facebook</a> has had a fair share of problems, being a large community of course it&#8217;s going to be a ripe target for spammers, scammers and malware distributors.</p>
<p>The latest to hit is a spam e-mail claiming to be from the Facebook team that actually spreads a nasty piece of malware called Bredolab. It&#8217;s also been observed the trojan will connect to additional servers to install more malware.</p>
<p>The ultimate goal as usual is to make the victims part of a <a href="http://www.darknet.org.uk/tag/botnet/">botnet</a>. </p>
<blockquote><p>Researchers at several security firms have uncovered a spam campaign targeting Facebook users. The e-mails, which pose as communications from Facebook about password resets, contain a nasty downloader that ultimately makes users part of a notorious botnet.</p>
<p>Researchers at several security firms have tied the Bredolab Trojan to a spam campaign targeting Facebook users.</p>
<p>The malware is being blasted out by spammers in e-mails claiming to come from “The Facebook Team.&#8221; Inside the e-mails is a message that the recipient&#8217;s Facebook password has been changed. In order to get the new one, recipients are told to open the accompanying attachment containing the malware.</p>
<p> Researchers at Websense told eWEEK Oct. 27 that they have observed more than 350,000 of the messages. On the company’s blog, researchers explained that the malware connects to two servers to download additional malicious files. Among them is Pushdo, also known as Cutwail.</p></blockquote>
<p>This spam campaign seems to be generating some fairly high levels of traffic meaning whoever is behind it is pretty serious and committed to this vector for disseminating malware.</p>
<p>Social engineering isn&#8217;t a new method for propagating malware as always the weakest link is never the technological barriers but is always the stupidity/greed/gullibility of humans.</p>
<p>You can ALWAYS hack the wetware.</p>
<blockquote><p>&#8220;One of the first things we saw this Trojan horse download was the Pushdo bot which began spamming out more of these Facebook password reset emails,” according to M86 Security. </p>
<p>MX Logic noted that Bredolab bypasses firewalls by injecting its own code into the legitimate process svchost.exe and explorer.exe. It also contains anti-sandbox code to thwart researchers, and creates the following files: %AppData%\wiaservg.log, %Windir%\temp\wpv861256600826.exe and %Programs%\Startup\isqsys32.exe. Bredolab also creates the processes isqsys32.exe and svchost.exe.</p>
<p>Sophos is detecting the malware as Troj/BredoZp-M or Mal/Bredo-A.</p>
<p>&#8220;Don&#8217;t make life easy for the hackers hell-bent on infecting your computer, stealing your identity and emptying your bank account &#8211; exercise caution when you receive unsolicited emails and protect your computer with up-to-date security software,&#8221; Graham Cluley, senior technology consultant at Sophos, advised in a blog post.</p></blockquote>
<p>It looks like a pretty advanced piece of malware code which evades firewall measures and even tries to thwart analysis by AV companies.</p>
<p>Anti sandbox code and process injection, these bad guys are getting smart.</p>
<p>That does not bode well for the average citizen.</p>
<p></p>
<p>Source: <a href="http://www.eweek.com/c/a/Security/Facebook-Password-Spam-Conceals-Malware-Attack-635899/?kc=rss">eWeek</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Facebook+E-mail+Spam+Conceals+Malware+Attack+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2236+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/10/facebook-e-mail-spam-conceals-malware-attack/&amp;t=Facebook+E-mail+Spam+Conceals+Malware+Attack" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2009/10/facebook-e-mail-spam-conceals-malware-attack/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/10/facebook-e-mail-spam-conceals-malware-attack/&amp;title=Facebook+E-mail+Spam+Conceals+Malware+Attack" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/10/facebook-e-mail-spam-conceals-malware-attack/&amp;title=Facebook+E-mail+Spam+Conceals+Malware+Attack" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2009/10/facebook-e-mail-spam-conceals-malware-attack/&amp;title=Facebook+E-mail+Spam+Conceals+Malware+Attack" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/10/facebook-e-mail-spam-conceals-malware-attack/&amp;title=Facebook+E-mail+Spam+Conceals+Malware+Attack" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2009%2F10%2Ffacebook-e-mail-spam-conceals-malware-attack%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/10/facebook-e-mail-spam-conceals-malware-attack/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Michael Jackon Spam/Malware &#8211; RIP The King Of Pop</title>
		<link>http://www.darknet.org.uk/2009/06/michael-jackon-spammalware-rip-the-king-of-pop/</link>
		<comments>http://www.darknet.org.uk/2009/06/michael-jackon-spammalware-rip-the-king-of-pop/#comments</comments>
		<pubDate>Mon, 29 Jun 2009 10:42:02 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[Spammers & Scammers]]></category>
		<category><![CDATA[michael jackson]]></category>
		<category><![CDATA[michael jackson dead]]></category>
		<category><![CDATA[michael jackson malware]]></category>
		<category><![CDATA[michael jackson spam]]></category>
		<category><![CDATA[michael jackson virus]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[twitter malware]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[viruses]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1897</guid>
		<description><![CDATA[For people of my age and generation and I&#8217;d guess for most readers of Darknet, Michael Jackson would have had a great influence on our lives. The biggest news last week was most certainly his death, as usual the bad guys were extremely quick to capitalize on this and were sending out spam within hours [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>For people of my age and generation and I&#8217;d guess for most readers of Darknet, Michael Jackson would have had a great influence on our lives.</p>
<p>The biggest news last week was most certainly his death, as usual the bad guys were extremely quick to capitalize on this and were sending out spam within hours of the announcement.</p>
<p>It was suspected malware would follow shortly after, and it did <a href="http://www.f-secure.com/weblog/archives/00001709.html">according to F-secure</a>.</p>
<blockquote><p>Within hours of the death of pop star Michael Jackson, spam trading on his demise hit inboxes, a security firm said today as it warned that more was in the offing.</p>
<p>Just eight hours after news broke about Jackson, U.K.-based Sophos started tracking the first wave of Jackson spam, which used a subject head of &#8220;Confidential &#8212; Michael Jackson.&#8221; The spam wasn&#8217;t pitching a product or leading users to a phishing or malware Web site, but instead was trying to dupe users into replying to the message in order to collect e-mail addresses and verify them as legitimate.</p>
<p>&#8220;The body of the spam message does not contain any call-to-action link such as a URL, e-mail or phone number,&#8221; said Sophos in its company&#8217;s blog today. &#8220;But the spammer can harvest receivers&#8217; e-mail addresses via a free live e-mail address if the spam message is replied to.&#8221; </p></blockquote>
<p>The original versions were just plain old spam to harvest addresses, but later malware laden versions followed which dropped IRC bots and backdoors detected as &#8220;Trojan.Win32.Buzus.bjyo&#8221;.</p>
<p>It&#8217;s sad to see such things happening, but social engineering attacks to spread malware are always expected when some big news like this breaks.</p>
<p>Nothing is sacred to the dark side of the Internet.</p>
<blockquote><p>The timing of that campaign was not coincidental: It followed Jackson&#8217;s acquittal on all charges in child sexual abuse. &#8220;The news of his suicide attempt was believable,&#8221; said Cluley, who noted that scammers and hackers often trade on tragedies to get people to click links. In that case, users were hit with a hacker toolkit that tried several exploits against Internet Explorer.</p>
<p>&#8220;I wouldn&#8217;t be surprised to see hackers claiming that they have top-secret footage from the hospital, perhaps [allegedly] taken by the ambulance people, that then asks you to install a video codec,&#8221; said Cluley, talking about a common malware ploy. Users who click on the supposed codec update link are, in fact, then infected with attack code, often a bot that hijacks their computer. </p></blockquote>
<p>So do warn people, if someone e-mails them pictures or videos claiming to be secret or exclusive footage surrounding the death of Michael Jackson &#8211; it&#8217;s most likely an infection vector.</p>
<p>Common sense prevails, but is sadly not common.</p>
<p>RIP Michael.</p>
<p></p>
<p>Source: <a href="http://www.networkworld.com/news/2009/062609-michael-jackson-spam-spreads-malware.html">Network World</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Michael+Jackon+Spam%2FMalware+%E2%80%93+RIP+The+King+Of+Pop+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1897+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/06/michael-jackon-spammalware-rip-the-king-of-pop/&amp;t=Michael+Jackon+Spam%2FMalware+%E2%80%93+RIP+The+King+Of+Pop" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2009/06/michael-jackon-spammalware-rip-the-king-of-pop/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/06/michael-jackon-spammalware-rip-the-king-of-pop/&amp;title=Michael+Jackon+Spam%2FMalware+%E2%80%93+RIP+The+King+Of+Pop" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/06/michael-jackon-spammalware-rip-the-king-of-pop/&amp;title=Michael+Jackon+Spam%2FMalware+%E2%80%93+RIP+The+King+Of+Pop" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2009/06/michael-jackon-spammalware-rip-the-king-of-pop/&amp;title=Michael+Jackon+Spam%2FMalware+%E2%80%93+RIP+The+King+Of+Pop" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/06/michael-jackon-spammalware-rip-the-king-of-pop/&amp;title=Michael+Jackon+Spam%2FMalware+%E2%80%93+RIP+The+King+Of+Pop" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2009%2F06%2Fmichael-jackon-spammalware-rip-the-king-of-pop%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/06/michael-jackon-spammalware-rip-the-king-of-pop/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>E-mail Scammers Target Microsoft Users</title>
		<link>http://www.darknet.org.uk/2008/10/e-mail-scammers-target-microsoft-users/</link>
		<comments>http://www.darknet.org.uk/2008/10/e-mail-scammers-target-microsoft-users/#comments</comments>
		<pubDate>Thu, 16 Oct 2008 13:54:06 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Spammers & Scammers]]></category>
		<category><![CDATA[email scam]]></category>
		<category><![CDATA[email-hacking]]></category>
		<category><![CDATA[hacking microsoft]]></category>
		<category><![CDATA[hacking-email]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[scammers]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[spammers]]></category>
		<category><![CDATA[trojan]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1144</guid>
		<description><![CDATA[Microsoft users are being targeted again by malware via e-mail, scammers/spammers never give up and for once the e-mail looks fairly legitimate. Usually this kind of &#8216;baitware&#8217; is riddled with terrible grammar and horrible spellings, do make sure you brief the less security aware friends you have about this though just in case. Email scams [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Microsoft users are being targeted again by malware via e-mail, scammers/spammers never give up and for once the e-mail looks fairly legitimate.</p>
<p>Usually this kind of &#8216;baitware&#8217; is riddled with terrible grammar and horrible spellings, do make sure you brief the less security aware friends you have about this though just in case.</p>
<blockquote><p>Email scams are a common way to spread malware and/or steal personal information. Some great guidelines to help you protect yourself from such scams are outlined <a href="http://www.microsoft.com/protect/computer/viruses/email.mspx ">here.</a> </p>
<p>We have recently found out about the latest in an ongoing string of email scams that target Microsoft customers. This particular scam contains the Backdoor:Win32/Haxdoor trojan as an attachment. We have seen a few emails targeting Microsoft customers that look like the email below:</p></blockquote>
<p>It&#8217;s not the first time we&#8217;ve seen this attack vector used in this way, but most AV software with a recent signature file should catch this e-mail as it comes in.</p>
<p>It shouldn&#8217;t be a big problem for corporates.</p>
<p>The email is as follows:</p>
<pre><code>Dear Microsoft Customer,

Please notice that Microsoft company has recently issued a Security Update
for OS Microsoft Windows. The update applies to the following OS versions:
Microsoft Windows 98, Microsoft Windows 2000, Microsoft Windows Millenium,
Microsoft Windows XP, Microsoft Windows Vista.

Please notice, that present update applies to high-priority updates
category. In order to help protect your computer against security
threats and performance problems, we strongly recommend you to
install this update.

Since public distribution of this Update through the official website
http://www.microsoft.com would have result in efficient creation of a
malicious software, we made a decision to issue an experimental private
version of an updatefor all Microsoft Windows OS users.

As your computer is set to receive notifications when new updates are
available, you have received this notice.

In order to start the update, please follow the step-by-step instruction:
    1. Run the file, that you have received along with this message.
    2. Carefully follow all the instructions you see on the screen.

If nothing changes after you have run the file, probably in the settings
of your OS you have an indication to run all the updates at a background
routine. In that case, at this point the upgrade of your OS will be finished.

We apologize for any inconvenience this back order may be causing you.

Thank you,

Steve Lipner
Director of Security Assurance
Microsoft Corp.</code></pre>
<p>Once again be aware, perhaps stick a rule in your IDS at the mail gateway so you know if this one comes in.</p>
<p>And do tell people about it!</p>
<p></p>
<p>Source: <a href="http://blogs.technet.com/mmpc/archive/2008/10/13/email-scam-targets-microsoft-customers.aspx">Microsoft Technet</a> (<em>Thanks Navin</em>)</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=E-mail+Scammers+Target+Microsoft+Users+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1144+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2008/10/e-mail-scammers-target-microsoft-users/&amp;t=E-mail+Scammers+Target+Microsoft+Users" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2008/10/e-mail-scammers-target-microsoft-users/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2008/10/e-mail-scammers-target-microsoft-users/&amp;title=E-mail+Scammers+Target+Microsoft+Users" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2008/10/e-mail-scammers-target-microsoft-users/&amp;title=E-mail+Scammers+Target+Microsoft+Users" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2008/10/e-mail-scammers-target-microsoft-users/&amp;title=E-mail+Scammers+Target+Microsoft+Users" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2008/10/e-mail-scammers-target-microsoft-users/&amp;title=E-mail+Scammers+Target+Microsoft+Users" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2008%2F10%2Fe-mail-scammers-target-microsoft-users%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2008/10/e-mail-scammers-target-microsoft-users/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>Brits Give Up Passwords For a £5 Gift Voucher</title>
		<link>http://www.darknet.org.uk/2008/09/brits-give-up-passwords-for-a-5-gift-voucher/</link>
		<comments>http://www.darknet.org.uk/2008/09/brits-give-up-passwords-for-a-5-gift-voucher/#comments</comments>
		<pubDate>Fri, 26 Sep 2008 14:15:15 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Password Cracking]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[password-hacking]]></category>
		<category><![CDATA[password-security]]></category>
		<category><![CDATA[passwords]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1085</guid>
		<description><![CDATA[So it turns out you don&#8217;t need any fancy password cracking software like John the Ripper or Cain and Abel you just need a handful of £5 gift vouchers for Marks and Spencers! But we had discussed this in part before, some people will give out their passwords if you just ask, some if you [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>So it turns out you don&#8217;t need any fancy password cracking software like <a href="http://www.darknet.org.uk/2006/03/jtr-password-cracking-john-the-ripper-17-released-finally/">John the Ripper</a> or <a href="http://www.darknet.org.uk/2007/01/cain-abel-download-the-super-fast-and-flexible-password-cracker-with-network-sniffing/">Cain and Abel</a> you just need a handful of £5 gift vouchers for Marks and Spencers!</p>
<p>But we had discussed this in part before, some people will give out their passwords if you just ask, some if you offer chocolate and this time in the guise of a &#8216;survey&#8217; for a gift voucher.</p>
<blockquote><p>Although the majority (60 percent) of 207 London residents were happy to hand over computer password data which might be useful to potential ID thieves in exchange for a £5 M&#038;S gift voucher, the public at large take a hard line on firms who fail to keep tight hold of customer data.</p>
<p>In exchange for the voucher, a number of those quizzed during a street survey in Covent Garden earlier this week went on to explain how they remember their password and which online websites (from a range of email, shopping, banking and social networking sites) they most frequently use. A sizeable chunk of those surveyed (45 per cent) said they used either their birthday, their mother&#8217;s maiden name or a pet&#8217;s name as a password.</p>
<p>Perhaps it&#8217;s just as well that stolen identities are worth a lot less than £5, fetching as little as 50p on the underground black market, according to Symantec.</p></blockquote>
<p>It seems like rather than giving out the actual password they answered questions put together in such a way that a profiler could easily work out what their password was and which sites they used it on.</p>
<p>Pretty sneaky methinks, it&#8217;s a good way to test how paranoid people are about their data security&#8230;it&#8217;s ironic really seeing how much they complain but at the end of it they are their own worst danger.</p>
<blockquote><p>ine in ten (89 per cent) of 1,000 Brits quizzed during a wider survey, commissioned by Symantec and price comparison site moneysupermarket.com, expressed the opinion that &#8220;reckless and repeated&#8221; data breaches ought to be punished by criminal prosecutions. Sanctions should include the ability to incarcerate directors of negligent firms in jail. Eight out of ten of those quizzed agreed there should be a &#8220;one strike and you’re out&#8221; rule for data loss.</p>
<p>Almost four in five of those polled reckon their personal data is not secure in the hands of companies that hold it, a finding that probably stems from the steady drip of data breach stories that have followed from the massive HMRC child benefit lost disc bungle last year. Three in four consumers are concerned about the amount of information organisation hold on them, regardless of whether or not this information is held online or offline. Online payments were perceived as the single greatest risk for losing data.</p></blockquote>
<p>The general public are pretty harsh too when it comes to dishing out punishment, but then again that is human nature and that is why there&#8217;s jury service.</p>
<p>It&#8217;s not surprising either that people have very little faith in data stored by the government and their greatest fear is carrying out online transactions.</p>
<p>I think we all know well enough to keep ourselves safe&#8230;but sadly as always it seems the rest of the world don&#8217;t.</p>
<p></p>
<p>Source: <a href="http://www.theregister.co.uk/2008/09/26/security_breach_attitudes_survey/">The Register</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Brits+Give+Up+Passwords+For+a+%C2%A35+Gift+Voucher+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1085+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2008/09/brits-give-up-passwords-for-a-5-gift-voucher/&amp;t=Brits+Give+Up+Passwords+For+a+%C2%A35+Gift+Voucher" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2008/09/brits-give-up-passwords-for-a-5-gift-voucher/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2008/09/brits-give-up-passwords-for-a-5-gift-voucher/&amp;title=Brits+Give+Up+Passwords+For+a+%C2%A35+Gift+Voucher" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2008/09/brits-give-up-passwords-for-a-5-gift-voucher/&amp;title=Brits+Give+Up+Passwords+For+a+%C2%A35+Gift+Voucher" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2008/09/brits-give-up-passwords-for-a-5-gift-voucher/&amp;title=Brits+Give+Up+Passwords+For+a+%C2%A35+Gift+Voucher" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2008/09/brits-give-up-passwords-for-a-5-gift-voucher/&amp;title=Brits+Give+Up+Passwords+For+a+%C2%A35+Gift+Voucher" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2008%2F09%2Fbrits-give-up-passwords-for-a-5-gift-voucher%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2008/09/brits-give-up-passwords-for-a-5-gift-voucher/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
	</channel>
</rss>

