The issue stemmed from how Facebook assist the user when they attempt to login after an unsuccessful attempt. Facebook returns a special “Please re-enter your password” page, which includes the Facebook photo and full name of the person associated with their email address. This information can be used by hackers to obtain proper information about Facebook user and can be scripted to automate the process.
What made it more interesting this bug allowed anyone, even those without an account, to obtain this information about Facebook users.
00Kellep CharlesKellep Charles2010-08-15 01:22:442010-08-15 01:22:44Facebook Fixes Privacy Issue – Full Disclosure of User Information
As we discussed a few days ago in a previous article titled, “Jailbreaking Apple’s Mobile iProducts Get Easier “ the eagerly awaited patch for the remote jailbreaking of iDevices was released yesterday August 11th.
Apparently, everyone was waiting for the update, while small in size and a quick download for the iPad, the same could not be said for the iPhone. The patch for the iPhone took over an hour for the 300+ MB file to be downloaded. The latest versions are now 4.0.2 for the iPhone and 3.2.2 for the iPad.
The patch has been released with no support for first generation devices; I guess that is one way to get people to upgrade to new devices and a way for Apple to increase their profit margins.
For those who jail-broke their phones on their own, if you patch your phone the device will be restored back to Apple’s specifications and no longer jail-broken.
Security experts have urge everyone, jailbreakers included, to apply Apple’s update that fixes the vulnerabilities in iOS that can be used to hijack iPhones and iPads though
Cydia jailbreak repository has another fix that allows the user to keep their jailbroken phone intact, but beware of suspicious PDF files.
Security experts at Kaspersky Lab stated they have discovered a malware application that targets the Google Android mobile operating system in Russia. The malware named “Trojan-SMS.AndroidOS.FakePlayer.a” is the first of its kind specifically implement to target the Android mobile OS according to the researchers at Kaspersky Lab.
The malware hides as a media-player called “Movie Player”, and when installed it begins to send text messages to a premium rate number without the knowledge of the Android-base device owner.
Even though initial cases are in Russia, Android-based users all over should be aware of the matter and be vigilant when downloading applications to their mobile device.
securityorb.com/ has five key recommendations for Android-based cell-phone users:
Pay close attention to the services that an application requests access to when it is being installed.
Check the permissions of your apps and revoke unnecessary access to remote locations and SMS request.
Install apps from trusted companies and sources ONLY.
Set Android-based device to only download applications that are in the Android Market
Research, read and/or review before installing apps
00Kellep CharlesKellep Charles2010-08-11 14:21:062010-08-11 14:21:06Google’s Android Targeted by Malware
Recently in the media, there has been a big “commotion” about the 100 million Facebook profiles containing user IDs, names, URLs and other data that was obtained and place into a file and posted online by Ron Bowles a security consultant. The media and surprisingly many security professionals have been spinning this matter as massive hack on Facebook and its users, when it fact it really was not.
The data obtained by Bowles were publicly available information that can be acquired by conducting Internet searches using Google, Yahoo and Bing to name a few. Reports stated, Bowles implement a “scraper” which is a small program to collect data from Facebook’s website automatically and the result was a 2.8GB file that he later posted on a peer-to-peer site.
So the driving question is it a hack or not?
To best answer that questions here are some points:
When creating a Facebook account, the user is given many options to what information will be available to the public. The user has the option of sharing “nothing”, “everything” or “a little”. Depending on what was selected will depend on what others are able to view and if your information was obtained by Bowles.
Computer hacking usually involves a degree of infringement on the privacy of the victim or damage to computer-based property. Bowles legally scanned and placed the files in a database, but many feel their privacy was infringed on even though the information was already publicly available.
This event should raise the awareness of what people are doing on Facebook and if they are comfortable enough with the information, they are putting out there. Facebook users need to take stock of their conversations and what information they are posting to others. That information can be used to create a profile along with the publicly available data that can lead to identity theft.
What is your position on the Facebook event?
00Kellep CharlesKellep Charles2010-07-30 15:03:262010-07-30 15:03:26Facebook Hacked or Not? – 100 Million User Profiles on Public Site
Below is the latest scam that is going around, I received this from a lady who wanted to know if it was real or not. I did some research and of course it was not. If you google the following (Joan Own, David Dupont or daviddupont154@aol.com) , you will find more information on this scam.
My recommendation is to delete it and do not respond to this email.
_________________
From: BANK OF AMERICA <joan.own@bankofamerica.com>
Sent: Tue, Aug 4, 2009 7:41 am
Subject: YOUR PAYMENT NOTIFICATION…
Bank of America Corporate Center
Senior Personal Banker – Head Office
Bank Of America Corp Ctr 100 North Tryon Street
Charlotte, NC 28255-0001
ATTN: BENEFICIARY
This is to Officially inform you that it has come to our notice and we have thoroughly completed an Investigation with the help of our Intelligence Monitoring Network System that you legally won the sum of $800,000.00 USD from our online balloting system in the Banks Head Quarter in United States of America. This funds have been investigated and we have discovered that your e-mail won the money from our Online Balloting System and we have been authorized to contact you and pay to you, your winnings via a Certified Cashier’s Check.
Normally, it will take up to 2 business days for an Bank of America Check to be cleared, cashed and remmited into your account by another local bank. We have successfully notified the banks on your behalf that funds are to be drawn from our registered bank, the Bank Of America so as to enable you cash the check instantly without any delay, henceforth the stated amount of $800,000.00 USD has been deposited with our bank, Bank Of America in COVINA, CALIFORNIA. where your check is deposited in a new online account. This is the Online Number: 626-453-8400 to verify the deposited Check.
We have completed this investigation and you are hereby approved to receive the certified cashier’s check into your personal account as we have verified the entire transaction to be Safe and 100% risk free, due to the fact that the funds is with Bank Of America you will be required to settle the following bills directly to the Bank of America Agent in-charge of this transaction whom is located here in United States of America.
According to the directives, you are required to pay for the following –
(1) Deposit Fee’s (Fee’s paid to setup a new account for the beneficiary by the Bank Of America)
(2) Courier Delivery Fee (Fee paid to deliver the check through UPS deleivery to your designated address)
(3) Insurance (This is the fee paid by bank to insure the check before been deposited at the bank)
The total amount for everything is $450.00 (Four Hundred and Fifty-US Dollars). We have tried our possible best to indicate that this $450.00 should be deducted from your funds but we found out that the funds have already been deposited at Bank Of America and cannot be accessed by anyone apart from you the beneficiary, therefore you will be required to pay the required fee’s to the Agent in-charge of this transaction via Western Union Money Transfer Or Money Gram.
In order to proceed with this transaction, you will be required to contact the agent in-charge (Mr. David Dupont) via e-mail. Kindly look below to find appropriate contact information:
CONTACT AGENT NAME: MR. David Dupont
E-MAIL ADDRESS: daviddupont154@aol.com
BANK OF AMERICA, 1375 N Citrus Ave, Covina, CA 91722.
You will be required to e-mail him with the following information:
FULL NAME:
ADDRESS:
CITY:
STATE:
ZIP CODE:
DIRECT CONTACT NUMBER:
You will also be required to request Western Union details on how to send the required $450.00 in order to immediately Deliver your funds $800,000.00 USD via Certified Cashier’s Check drawn from Bank Of America, also include the following transaction code in order for him to immediately identify this transaction : EA2948-910.
After making the payment to the Agent in-charge, an Account Information, with Account Name and Access Code will be given to you, to access your funds where it is deposited in an online account with the bank of america. This is the Online Account Number: 626-453-8400 and the Agent incharge will issue you the CODES.
This letter will serve as proof that the BANK OF AMERICA is authorizing you to pay the required $450.00 ONLY to Mr. David Dupont via information in which he shall send to you, if you do not receive your funds of $800,000.00 we shall be held responsible for the loss and this shall invite a penalty of $10,000 which will be made PAYABLE ONLY to you (The Beneficiary).Failure to contact Mr. David Dupont and complete the delivery of your check to you, the check will be deposited with the bank reserve.
Best Regards
JOAN OWEN
Senior Personnel Banker – Head Office
Note: The $450 can not be deducted from your fund of $800,000 becuase the cashiers’s check have been insured and also all fees must be paid before the check will be delivered your designated address.
Below is the latest scam that is going around, I received this from a lady who wanted to know if it was real or not. I did some research and of course it was not. If you google the following (Joan Own, David Dupont or daviddupont154@aol.com) , you will find more information on this scam.
My recommendation is to delete it and do not respond to this email._________________
From: BANK OF AMERICA <joan.own@bankofamerica.com>Sent: Tue, Aug 4, 2009 7:41 amSubject: YOUR PAYMENT NOTIFICATION…
Bank of America Corporate CenterSenior Personal Banker – Head OfficeBank Of America Corp Ctr 100 North Tryon StreetCharlotte, NC 28255-0001ATTN: BENEFICIARYThis is to Officially inform you that it has come to our notice and we have thoroughly completed an Investigation with the help of our Intelligence Monitoring Network System that you legally won the sum of $800,000.00 USD from our online balloting system in the Banks Head Quarter in United States of America. This funds have been investigated and we have discovered that your e-mail won the money from our Online Balloting System and we have been authorized to contact you and pay to you, your winnings via a Certified Cashier’s Check.Normally, it will take up to 2 business days for an Bank of America Check to be cleared, cashed and remmited into your account by another local bank. We have successfully notified the banks on your behalf that funds are to be drawn from our registered bank, the Bank Of America so as to enable you cash the check instantly without any delay, henceforth the stated amount of $800,000.00 USD has been deposited with our bank, Bank Of America in COVINA, CALIFORNIA. where your check is deposited in a new online account. This is the Online Number: 626-453-8400 to verify the deposited Check.We have completed this investigation and you are hereby approved to receive the certified cashier’s check into your personal account as we have verified the entire transaction to be Safe and 100% risk free, due to the fact that the funds is with Bank Of America you will be required to settle the following bills directly to the Bank of America Agent in-charge of this transaction whom is located here in United States of America. According to the directives, you are required to pay for the following -(1) Deposit Fee’s (Fee’s paid to setup a new account for the beneficiary by the Bank Of America)(2) Courier Delivery Fee (Fee paid to deliver the check through UPS deleivery to your designated address)(3) Insurance (This is the fee paid by bank to insure the check before been deposited at the bank)The total amount for everything is $450.00 (Four Hundred and Fifty-US Dollars). We have tried our possible best to indicate that this $450.00 should be deducted from your funds but we found out that the funds have already been deposited at Bank Of America and cannot be accessed by anyone apart from you the beneficiary, therefore you will be required to pay the required fee’s to the Agent in-charge of this transaction via Western Union Money Transfer Or Money Gram.In order to proceed with this transaction, you will be required to contact the agent in-charge (Mr. David Dupont) via e-mail. Kindly look below to find appropriate contact information:CONTACT AGENT NAME: MR. David DupontE-MAIL ADDRESS: daviddupont154@aol.comBANK OF AMERICA, 1375 N Citrus Ave, Covina, CA 91722.You will be required to e-mail him with the following information:FULL NAME:ADDRESS:CITY:STATE:ZIP CODE:DIRECT CONTACT NUMBER:You will also be required to request Western Union details on how to send the required $450.00 in order to immediately Deliver your funds $800,000.00 USD via Certified Cashier’s Check drawn from Bank Of America, also include the following transaction code in order for him to immediately identify this transaction : EA2948-910.After making the payment to the Agent in-charge, an Account Information, with Account Name and Access Code will be given to you, to access your funds where it is deposited in an online account with the bank of america. This is the Online Account Number: 626-453-8400 and the Agent incharge will issue you the CODES.This letter will serve as proof that the BANK OF AMERICA is authorizing you to pay the required $450.00 ONLY to Mr. David Dupont via information in which he shall send to you, if you do not receive your funds of $800,000.00 we shall be held responsible for the loss and this shall invite a penalty of $10,000 which will be made PAYABLE ONLY to you (The Beneficiary).Failure to contact Mr. David Dupont and complete the delivery of your check to you, the check will be deposited with the bank reserve.Best RegardsJOAN OWENSenior Personnel Banker – Head OfficeNote: The $450 can not be deducted from your fund of $800,000 becuase the cashiers’s check have been insured and also all fees must be paid before the check will be delivered your designated address.
00Kellep CharlesKellep Charles2010-07-26 05:23:282010-07-26 05:23:28Bank of America Scam
Visits to social networking sites account for more than 10% of the total time people spend on the Internet, according Nielsen Online. A social network site focuses on building online communities of people who share common interests and activities, such as Linkedin.com and Facebook.com. Facebook is now the most visited social networking site on the Internet, with nearly 1.2 billion visits in January 2009 alone, while Twitter and Linkedin are steadily gaining ground.
Hackers have adopted the popularity of social networking sites into their malicious plans to compromise systems and steal personal identifiable information. Recent attacks such as the Koobface virus on Facebook and the clickjacking issues faced by Twitter are all prime examples of the recent challenges. Also, these very same hackers have the capability to remain anonymous on these social networking sites, which enforces the notion, you really do not know who is on the Internet with you.
Security on social networking sites are at a minimal standard right now, they rely on usernames and passwords for authentication and security, which means that anyone who finds out your username and password can gain access to your account. Until social networking site security evolves with time and improves, users need to be very careful and diligent.
Here are a few tips that should assist in making sure you are safe when using social networking sites:
1. Understand how the social networking site displays your information. Some sites will allow the user to control who can see your information, while others will allow anyone and everyone to view postings.
2. Don’t click on shortened (or “condensed”) URL’s, like those created by TinyURL and Bit.ly. There’s no telling where these links lead to, and that makes it easy to funnel you to malicious websites (Drive-by-Download).
3. Be mindful of your personal information such as, don’t post your full name, address, age, hometown or information about your family. Even your screen name can pose a lot of identifiable information.
4. Post appropriate information that are comfortable with others seeing and knowing, such as your employer, co-workers and acquaints. Many people will see your page or postings, including the people who will be interviewing you for a current position or a future job.
5. Remember that once you post information online, it may be impossible to take it back. This includes photos that can be manipulated.
6. Be careful when it comes to online personal socializations such as flirting or disputes. Some people lie about whom they are. Be wary if a new online friend wants to meet you in person.
7. Trust your instincts if you have suspicions. If you feel threatened by someone or uncomfortable because of something online, report it to the police and to the operators of the social networking site. You could end up preventing someone else from becoming a victim.
Social networking sites are evolving into our personal and business lives. People from various stages and walks of life are participating in these events with very little knowledge into the dangers of these social networking sites. The site owners only provide the minimal required security measures, while hackers are using tactics that has shown great success in circumventing them. It is up to us, to do what is necessary to protect ourselves until better security measures are implemented or the hackers give up. Don’t hold your breath on the hacker’s giving up.
For more information on this article and other informative articles go to: www.securityorb.com
00Kellep CharlesKellep Charles2010-07-15 09:51:402010-07-15 09:51:40Personal Security on Social Networking Sites
Information technology conflicting with personal and information privacy has been a major topic in recent months keeping privacy organizations including the Washington D.C. based Electronic Privacy Information Center (EPIC) busy as the premiere privacy watchdog in the U.S. For example, recent issues such as Google asking the NSA for assistance in the investigation of a cyber-attack that occurred on its network. In addition, the initial roll-out of Google’s social networking application “Buzz” that caused quit a stir due to how Google automatically suggested and added Gmail contacts to its followed list. Now, with recent allegations that the Lower Merion School District in PA used remote-controlled web cameras attached to laptops to spy on high school students has surfaced and is under investigations.<!– wp_ad_camp_1 –>
Information security and personal privacy has been increasingly important as our reliance to the Internet has grown in all areas including business and play. Many people try to understand how much privacy they are you willing to give up for security and many people often confuse the concept of security and privacy to be synonymous.
Information privacy is an individuals claim that data about themselves should not be automatically available to other individuals and organizations while information security means protecting information from unauthorized access, use, disclosure, modification or destruction.
What are you view on information security and your information privacy? How much of your information privacy would you be willing to give up to ensure your information security level?
00Kellep CharlesKellep Charles2010-06-14 00:27:262010-06-14 00:27:26Information Security vs Information Privacy