Sunday, December 6, 2009

A Black Friday Deal- Too Good to Be True

Office Depot had a deal on $10 webcams, the Markvision Magnetic Webcam, over the Thanksgiving Weekend. The camera came with a CD that contained a link to Markvision's website. However, when that link was clicked, it brought up a blank webpage and a popup saying the user needed to update their computer. When that pop up was closed, another window appeared which looked like a security anti-virus scan. It was veiled in such a way that to an inexperienced user, it could look like a legitimate anti-virus scan. In fact, clicking the link installed rougue anti-virus software on the users computer. "Rogue antivirus software typically generates pop-up warnings, telling the victim there's a security problem and pestering them to get it fixed until they hand over their credit card numbers." Still others install malicious keyloggers which can record all key strokes made on a computer, stealing usernames and passwords. Office Depot claimed that only a small number of customers were affected by this, and Markvision disabled their website until the problem could be fixed.

Initial reports indicate that the link was legitimate, but that Markvision's website had been hacked. Given how recently this occurred, there isn't a lot of information on how this happened or who did it, and parts of Markvision's website are still offline. Markvision would not comment for the story. I'm guessing it will take a while to figure out exactly what happened. However, their lack of disclosure, plus still having parts of their website down almost a week after the fact will certainly hurt Markvision's business.

Markvision obviously needs to create better security for their website so that a similar event doesn't happen again. Office Depot really wasn't at fault in this case, but they may want to pull the webcam from their shelves and look into their working relationship with Markvision. For the individual users affected, things are a little more complicated. Oftentimes, when people see a virus scan, or something that looks like a scan, pop up, they panic thinking their computer is infected. These sorts of programs can convince unaware people to give their credit card numbers because they think they need to update their antivirus. Instead, these fake anti-viruses end up just gathering credit card numbers. The biggest way for people to not fall prey to this is to know the details of their own antivirus. Knowing what the company is called and what a legitimate scan looks like could help them realize if they are seeing a fake or legimiate scan.

On a related note, I recently had a similar attack on my computer in which at least one symptom was a fake virus scan. I never even clicked on the scan because I figured out it was fake, but I waited too long to get it fixed. It corrupted my hard drive completely so OIT had to wipe out everything on my computer. So this is really serious. Trust me, you don't want it to happen to you.


http://www.computerworld.com/s/article/9141773/Thanksgiving_Webcam_promo_leads_to_malware?taxonomyId=17

Twitter Bug Exposes Private Tweets through Googlebot

As many have seen through celebrities and paparazzi websites, Twitter has become an up and coming social utility that allows users to update the public on what they are doing, where they are doing it, and who they are with at all times. Blackberry and iPhone applications allow users to update their status from mobile devices and have granted people the liberty to access accounts everywhere. While most “tweets” (which are the status updates themselves on the personal page of a specific user) are public information, there are settings that allow a person to protect their tweets. Privacy protected tweets are supposed to grant access to people who are friends with that specific user, or in the case of Twitter, “following” a user online.

While this seemed to be the case for most of the time, a “bug” and a whole that was brought to light in an LA Times article, allowed private tweets to be accessed through Google. This bug compromised the personal tweets of protected users and has caused a scene in the technology world that many privacy protected users on Twitter do not appreciate. Information that is revealed through Twitter states that approximately 10% of users protect their tweets through the privacy standards offered by Twitter. In this article, the LA Times revealed that one could access Twitter tweets by typing “site:twitter.com/*username*” and replacing the username with the protected user account on Twitter. This bug allowed people to find protected tweets of these users, which compromised names such as Bill Clinton who used Twitter. While it doesn’t reveal the entire message Google can access the majority of the post through it’s search engine which is called the Googlebot. The protected tweets that many want to protect are now compromised and searchers can gain general knowledge on the information posted.

For example Bill Clinton’s tweets which are protected have been compromised. Here are a couple examples of what he tweets about, "John Edwards...why did you," "NY Gov got caught with a," "Oh Hillary, 3rd place in," and "I have been too depressed..." These were all revealed in the LA Times article on October 19, 2009. While we continue to update our privacy standards in the online community we can now see why it is so important to continually update and perform checks on our personal lives and networking utilities to maintain privacy and prevent any information to become compromised.

Sources:

A Twitter hole lets you Google protected tweets

http://mashable.com/2009/10/19/twitter-bug-exposes-private-tweets/

Facebook Intends to Maintain Privacy for Users

As many college students and people all over the world know, Facebook has become the largest online social networking website over the past five years. We have seen it grow from merely a college networking website to a global connection source. However, as Facebook has grown to an astonishing 350 million users, the privacy standards have somewhat diminished due to the consistent growth and additions Facebook has made over the past five years. While it is no fault of Facebook founder Mark Zuckerberg that the privacy standards been somewhat impaired, there are significant problems that have arisen in the privacy department as Facebook has grown in users. As stated in the open letter from Mark Zuckerberg on December 1, 2009,

"Starting with the very first version of Facebook five years ago, we've built tools that help you control what you share with which individuals and groups of people. Our work to improve privacy continues today."

As we have seen through this class, many information that we share online is subject to identity theft and online criminals around the globe. It has become such a complex situation that now people across the world can access information on any single person and use it to purchase and steal merchandise as well as money. The internet while very valuable and useful has also aided to one of the largest criminal acts in a very long time. Facebook has contributed to networking and is a social utility that is great for maintaining relationships throughout our nation and across the world. However, with the original setup of allowing people to access information and material through accessing a specific network, such as a school, country, or even a company, our privacy in many ways has been compromised. For this reason, Mark Zuckerberg has tried to develop a new way that Facebook will allow users to connect.

In his letter on December 1, 2009, Zuckerberg stated that he will remove the regional“networks” as he called them (which basically is countries and cities that can be used to join Facebook), stating that over 50% of all users use area networks to access material of other people, making it a complicated and difficult practice to implement privacy controls. He stated, “The plan we've come up with is to remove regional networks completely and create a simpler model for privacy control where you can set content to be available to only your friends, friends of your friends, or everyone.” This makes the privacy controls simpler and easier to maintain by the 350 million users, and will prevent people who are not granted access to uploaded and posted material by users within that network.

These new privacy controls will allow Facebook users to maintain a certain aspect of privacy while allowing them to share what they want with whomever they want. While these controls seem to be the answer to keeping the integrity of profiles on Facebook, we know that somewhere along the line privacy will always be an issue in the online community and the safest way to maintain privacy is to abstain from posting anything not wanted on that specific website.

Source:

http://blog.facebook.com/blog.php?post=190423927130


Friday, December 4, 2009

Internet message boards and attacks

Have you ever wondered where widespread internet jokes come from? All of us have probably seen, and enjoyed, many internet based jokes. Whether you laughed at the youtube video Chocolate Rain, viewed "lolcatz", or you were a victim of a rickroll prank, you are familiar with how fast and widespread these jokes can be.

For the most part, these jokes were started, or at least popularized by the website 4chan.org. WARNING: THIS SITE IS HIGHLY OFFENSIVE, AS BOTH EXPLICIT CONTENT ON THEIR MESSAGE BOARDS AND ADVERTISEMENTS ARE WIDESPREAD. This site has a large subculture following.Though mostly immature humor, sometimes the users of this site come together to take part in mischievous behavior.

The users are known for widespread attacks known as raids. Typically, many users will take part in a raid at the same time to cause widespread problems. In one instants, users "raided" a white supremacist website through a DoS Attack, causing the website to go offline. In another instance, a user of 4chan posted the Google HTML numeric character reference for the swastika symbol. A multitude of users than searched the code and pushed the symbol to the top of Google's hot trends chart. Later, Google removed the symbol. 4chan users have also caused problems for the Religious movement, Scientology, by taking parts in raids on the official website.

For the most part, the 4chan raids are harmless mischievous pranks. On the other hand, they tend to be offensive and cause harm to the sites they target. 4chan does show the potential of mass attacks taken out by an enormous amount of users, through techniques as simple as Google search.

http://en.wikipedia.org/wiki/4chan#Media_attention

Tuesday, December 1, 2009

Screen Sharing

I am a Mac user along with four of my roommates. Several days ago, a couple of these roommates were using their Macs to work on a project together for a business class. The interesting thing is that, while they were operating on separate machines, they were working on identical screens. In other words, they were screen sharing. With Mac operating systems Leopard and Snow Leopard, an individual can authorize access to their computer screen from a different machine. According to the Apple website, “You can access the other computer as if it was the computer you were using,” adding, “While you share the computer’s screen, you can control everything that happens on that computer, such as opening documents or applications; opening or closing windows; and even shutting off the computer.” As Apple explains, this can be a helpful tool if an individual wants to access a computer when they cannot physically be at that computer, or if a person wants to fix a problem on another computer, or like my roommates, work on a presentation or project together.


I am in agreement with Apple in that this could be a very useful tool. That being said, as with all technology, it can only be an asset if it is secure. With screen sharing, there certainly seem to be vulnerabilities that could detract from the application’s security. Thus, my goal as a user would be to ensure that confidentiality is maintained between me and those who I authorize, and also that those authorized individuals can be trusted to preserve the integrity of the information I am sharing.


As a hacker, my goals would obviously be to ruin the integrity, availability, confidentiality depending on the particular objective of my attack, which would presumably prey on the vulnerabilities. Regarding screen sharing, it seems that there is a risk for the integrity and confidentiality of the shared information to be breached. In authorizing access to another individual, that person now has control over information that they can not only share as they see fit, but can also manipulate at will. Therefore, a great degree of care should be included in the decision to authorize someone so that only trustworthy people can gain access.


Furthermore, while I am by no means a computer expert, it seems likely that a proficient hacker could readily hack this application on the computer of another person in their network in order to gain access without receiving authorization. While this may be more difficult that I perceive, my experiences in this class and the apparent prevalence of security breaches lead me to believe that such an attack is probably possible.


Therefore, my recommendation is that people who screen share are cautious about who they invite to share their machine and to encrypt the sensitive information they share. While this cannot eliminate all threats, it can significantly decrease the probability of an attack and lessen the damage in the event that one does occur.


Source: http://docs.info.apple.com/article.html?path=Mac/10.5/en/14066.html



Facebook's Farmville loses its country glow

So, as most of you know, FarmVille, a recent Facebook app, has really taken off in terms of popularity. Most Facebook users that I know have at least heard of FarmVille, if they are not already playing on it. One of my good friends is constantly raving about how she expanded on her farm, and that I should join. Just the other day, there was an update on her facebook page that said she saved an animal from certain, um, danger (i.e. piglet saved from the butcher, or something to that effect). Bottom line, it is interesting to see that this farming application has really taken off, and it's popularity continues to grow everyday.

However, like any application, FarmVille (which is a gaming application developed by US developer Zynga) is also experiencing it's own setbacks. For example, my roommate told me the other day that one of her teachers had discussed recent events where people are getting their accounts hacked into and having their property stolen/sold. While, yes, FarmVille is a game, people still do invest a lot of time and virtual money to build their farms, day by day. Quite frankly, a player's farm is the fruit of their labor, even if the result is not exactly tangible. Just an interesting tidbit to think about.

In more recent news (an article dated Dec.1, 2009), however, there appears to be a FarmVille Scam going around: some users have been "complaining of unauthorised payments taken from their credit cards after participating in promotions linked to the game which serve to generate in-game currency or other rewards". With 60 million FarmVille players worldwide, it's safe to say that there are a lot of people who are at risk of being subject to this scam. What makes it more difficult is the fact that it is nearly impossible for users' money to be refunded, due to the nature of agreeing to subscribe or participate in certain promotions that are full of unread fine-print. According to the article, this particular scam seems to be a classic case of SMS subscription scam, and FarmVille is just one of many Zynga applications that seem to be under fire for their suspicious billing policies. Facebook has made moves to improve its standards for third-party applications, however, one cannot be assured that this will necessarily prevent similar scams from happening in the future. The fact is that the FarmVille application was not created by a random third-party user, but rather by a legitimate developer brand that was "also was named Hot Brand by US magazine Advertising Age last month". Perhaps it was the responsibility of FarmVille users to read the fine-print, wherein they would have discovered some information relating to these otherwise unauthorized billings. But really, who ever reads the fine print?

So...FarmVille users: make sure that you keep an eye on your credit card charges.

Source:

http://www.smh.com.au/digital-life/digital-life-news/facebooks-farmville-loses-its-country-glow-20091201-k3c7.html

Class Slides

Here are the remaining slides for class: