<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Barracuda Labs Internet Security Blog &#187; Uncategorized</title>
	<atom:link href="http://www.barracudalabs.com/wordpress/index.php/category/uncategorized/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.barracudalabs.com/wordpress</link>
	<description></description>
	<lastBuildDate>Thu, 02 Feb 2012 14:24:57 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1</generator>
		<item>
		<title>Human Rights Group Used to Spy on Activists</title>
		<link>http://www.barracudalabs.com/wordpress/index.php/2011/12/22/authoritarian-regime-uses-human-rights-group-to-spy-on-activists/</link>
		<comments>http://www.barracudalabs.com/wordpress/index.php/2011/12/22/authoritarian-regime-uses-human-rights-group-to-spy-on-activists/#comments</comments>
		<pubDate>Thu, 22 Dec 2011 17:44:25 +0000</pubDate>
		<dc:creator>Paul Royal</dc:creator>
				<category><![CDATA[Current Events]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Web Security]]></category>
		<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[spear-phishing]]></category>

		<guid isPermaLink="false">http://www.barracudalabs.com/wordpress/?p=2216</guid>
		<description><![CDATA[By Paul Royal, Research Consultant Amnesty International&#8217;s UK website has been compromised and is serving drive-by downloads. Historical data indicates the website AIUK was compromised on or before Friday, December 16. Details: Visiting hxxp://www[.]amnesty[.]org[.]uk loads hxxp://3max[.]com[.]br/cgi-bin/ai/ai.html via an iframe. 3max.com.br, which itself is a legitimate but compromised Brazilian automotive website, loads malicious Java content (stolen [...]]]></description>
			<content:encoded><![CDATA[<p><em>By Paul Royal, Research Consultant<br />
</em></p>
<p>Amnesty International&#8217;s UK website has been compromised and is serving drive-by downloads. Historical data indicates the website AIUK was compromised on or before Friday, December 16.</p>
<p>Details:</p>
<p>Visiting hxxp://www[.]amnesty[.]org[.]uk loads hxxp://3max[.]com[.]br/cgi-bin/ai/ai.html via an iframe. 3max.com.br, which itself is a legitimate but compromised Brazilian automotive website, loads malicious Java content (stolen from the <a href="https://metasploit.com/svn/framework3/trunk/external/source/exploits/CVE-2011-3544/Exploit.java">Metasploit project</a>), which targets CVE-2011-3544. If the exploit is successful, malware is installed on the visitor&#8217;s system.</p>
<p>Details of Vulnerability Targeted by the Exploit<br />
<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3544">http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3544</a><br />
VirusTotal Detections for Exploit<br />
<a href="http://www.virustotal.com/file-scan/report.html?id=1cc214cee10f02d37359c0e3d04fd57899333c4b1eaa81489c74e5c2fa17c3a8-1324068153">http://www.virustotal.com/file-scan/report.html?id=1cc214cee10f02d37359c0e3d04fd57899333c4b1eaa81489c74e5c2fa17c3a8-1324068153</a><br />
VirusTotal Detections for Exploit Payload<br />
<a href="http://www.virustotal.com/file-scan/report.html?id=0e53832e1c36d34a3d05c05f73ebab22a74ade95c5f3b7d9f74fad4f56d10023-1324067892"> http://www.virustotal.com/file-scan/report.html?id=0e53832e1c36d34a3d05c05f73ebab22a74ade95c5f3b7d9f74fad4f56d10023-1324067892</a></p>
<p>The exploit payload possesses properties of targeted malware but is being served by an exploit of a popular, public website. The working theory for this anomaly relates to Amnesty International as a human rights non-governmental organization. To explain, certain countries use zero day exploits and other techniques to gain electronic information about the activities of human rights activists. Of course, a subset of these activists are too smart to click on links in even well-worded spearphishing emails. But what if you compromised a website frequented by these activists (e.g., Amnesty International)? Then your targets come to you. The context-specific damage potential is significant.</p>
<p>Amnesty International UK has been notified about the compromise.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.barracudalabs.com%2Fwordpress%2Findex.php%2F2011%2F12%2F22%2Fauthoritarian-regime-uses-human-rights-group-to-spy-on-activists%2F&amp;title=Human%20Rights%20Group%20Used%20to%20Spy%20on%20Activists" id="wpa2a_2"><img src="http://www.barracudalabs.com/wordpress/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.barracudalabs.com/wordpress/index.php/2011/12/22/authoritarian-regime-uses-human-rights-group-to-spy-on-activists/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Do we really want better spam detection on social networks?</title>
		<link>http://www.barracudalabs.com/wordpress/index.php/2011/12/15/do-we-really-want-better-spam-detection-on-social-networks/</link>
		<comments>http://www.barracudalabs.com/wordpress/index.php/2011/12/15/do-we-really-want-better-spam-detection-on-social-networks/#comments</comments>
		<pubDate>Thu, 15 Dec 2011 13:14:28 +0000</pubDate>
		<dc:creator>Barracuda Labs</dc:creator>
				<category><![CDATA[SEO Poisoning]]></category>
		<category><![CDATA[Social Networking]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.barracudalabs.com/wordpress/?p=1971</guid>
		<description><![CDATA[by Daniel Peck, Research Scientist The question sounds crazy, especially for someone who&#8217;s spent a fair amount of the last year working on making spam and other malicious message detection on social networks better.  But we do a disservice to tools geared for protection when we don&#8217;t think long term about the consequences of them.  [...]]]></description>
			<content:encoded><![CDATA[<p><em>by Daniel Peck, Research Scientist</em></p>
<p>The question sounds crazy, especially for someone who&#8217;s spent a fair amount of the last year working on making spam and other malicious message detection on social networks better.  But we do a disservice to tools geared for protection when we don&#8217;t think long term about the consequences of them.  Does better spam detection on say twitter for example reduce the total amount of spam that users see, or does it just change the signal to noise ratio?</p>
<p>Websites who&#8217;s only content is related to spam didn&#8217;t get many hits.  This led spammers to move to Search Engine Optimization techniques, which have had a good run are still fairly effective, but more often than not spam sites are full of legitimate content harvested from other sites.</p>
<p>I suspect, and have seen several examples, that the same trend is taking place in social media.  We build systems that force spammers to put more &#8220;real&#8221; content into the stream, so that they don&#8217;t immediately out themselves. These fake accounts contain plenty of retweets of popular stories, and shared links on facebook with a bit of &#8220;hey, what a great deal on shoes&#8221; or &#8220;click here to see my naked&#8221; thrown in here and there.</p>
<p>Times are changing here too, sharing too many popular things also indicates than an account is a spammer, or at the very least a much less valuable node in the network.  So the next step is wholesale copying of real peoples profiles, complete with pictures of their cat, a bizzaro you with everything from your facebook account duplicated on another network, such as tumblr or google+, with an occasional spam or malicious link thrown in.  The kind of place where friends will eagerly add you, because everyone needs to be connected to every one of their friends through every medium possible of course, and not think twice about clicking on the malicious link that bizzaro you just shared out.</p>
<p>Besides being quite a blow to the privacy of the accounts being copied, this also reduces the trust that anyone can put into a user, which may not necessarily be a bad thing from a security point of view, are we making a problem that&#8217;s cosmically easy to spot for end users, such as the endless number of Nigerian prince scams, morph into something that is much more difficult for the end user to distinguish from real content?  Are we moving towards an advertorial world where the signal and the noise are nearly impossible to separate?</p>
<p>When it comes to advanced vulnerability discovery and exploitation techniques I am all for raising the level of discourse and seeing talented researchers raise the bar for attack and defense alike, but with something like this I&#8217;m not so sure.  Maybe it’s best to keep the bar low with regards to detection/blocking on social media and focus on securing APIs and the data they access, understanding that its better for those with less benevolent intent to pull out a few weak individuals from the herd than to give them incentive to find methods to take the whole.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.barracudalabs.com%2Fwordpress%2Findex.php%2F2011%2F12%2F15%2Fdo-we-really-want-better-spam-detection-on-social-networks%2F&amp;title=Do%20we%20really%20want%20better%20spam%20detection%20on%20social%20networks%3F" id="wpa2a_4"><img src="http://www.barracudalabs.com/wordpress/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.barracudalabs.com/wordpress/index.php/2011/12/15/do-we-really-want-better-spam-detection-on-social-networks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Facebook suggestions fuel fake profile business</title>
		<link>http://www.barracudalabs.com/wordpress/index.php/2011/06/24/facebooksuggestion/</link>
		<comments>http://www.barracudalabs.com/wordpress/index.php/2011/06/24/facebooksuggestion/#comments</comments>
		<pubDate>Fri, 24 Jun 2011 19:41:40 +0000</pubDate>
		<dc:creator>Barracuda Labs</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.barracudalabs.com/wordpress/?p=1622</guid>
		<description><![CDATA[by Nidhi Shah, Security Researcher Have you ever encountered  people selling designer shoes on Facebook for prices that are too good to be true?  Check out these links if you have not (here, here, and here&#8230;).  The interesting things about these links is that the profile owner almost always is a hot chick with lots [...]]]></description>
			<content:encoded><![CDATA[<p><span style="color: #808080;"><em>by Nidhi Shah, Security Researcher</em></span></p>
<p>Have you ever encountered  people selling designer shoes on Facebook for prices that are too good to be true?  Check out these links if you have not (<a href="http://www.facebook.com/photo.php?fbid=135854666492336&amp;set=p.135854666492336&amp;type=1">here, </a><a href="http://www.facebook.com/photo.php?fbid=127894873957922&amp;set=p.127894873957922&amp;type=1">here</a>, and <a href="http://www.facebook.com/photo.php?fbid=127046007377110&amp;set=p.127046007377110&amp;type=1">here</a>&#8230;).  The interesting things about these links is that the profile owner almost always is a hot chick with lots of male friends with regular posts about expensive shoes for sale.   The order links mentioned on the shoe photo go to many different domains which   ultimately lead to one store, kicksbay.com.</p>
<p>e.g.</p>
<p><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/06/profiletokicksbay4.png"><img class="aligncenter size-full wp-image-1645" title="profiletokicksbay" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/06/profiletokicksbay4.png" alt="Designer shoe leading to fake profile and fake storeleading to" width="500" height="185" /></a></p>
<p>The above three are just an example.  We searched Facebook for similar shoe products and found it smothered with such links.</p>
<pre>http://www.facebook.com/photo.php?fbid=126073080809309&amp;set=p.126073080809309&amp;type=1

http://www.facebook.com/photo.php?fbid=126073527475931&#038;set=p.126073527475931&#038;type=1

http://www.facebook.com/photo.php?fbid=126159517467316&#038;set=p.126159517467316&#038;type=1

http://www.facebook.com/photo.php?fbid=126217434128151&#038;set=p.126217434128151&#038;type=1

http://www.facebook.com/photo.php?fbid=126300230786487&#038;set=p.126300230786487&#038;type=1

http://www.facebook.com/photo.php?fbid=126408794109113&#038;set=p.126408794109113&#038;type=1

http://www.facebook.com/photo.php?fbid=126460707436911&#038;set=p.126460707436911&#038;type=1

http://www.facebook.com/photo.php?fbid=126460854103563&#038;set=p.126460854103563&#038;type=1

http://www.facebook.com/photo.php?fbid=126804947401822&#038;set=p.126804947401822&#038;type=1

http://www.facebook.com/photo.php?fbid=126940920719740&#038;set=p.126940920719740&#038;type=1

http://www.facebook.com/photo.php?fbid=127046007377110&#038;set=p.127046007377110&#038;type=1

http://www.facebook.com/photo.php?fbid=127894873957922&#038;set=p.127894873957922&#038;type=1

http://www.facebook.com/photo.php?fbid=128218357259011&#038;set=p.128218357259011&#038;type=1

http://www.facebook.com/photo.php?fbid=128361313909783&#038;set=p.128361313909783&#038;type=1

http://www.facebook.com/photo.php?fbid=129208183824889&#038;set=p.129208183824889&#038;type=1

http://www.facebook.com/photo.php?fbid=129476437132948&#038;set=p.129476437132948&#038;type=1

http://www.facebook.com/photo.php?fbid=129489630463165&#038;set=p.129489630463165&#038;type=1

http://www.facebook.com/photo.php?fbid=129981733747345&#038;set=p.129981733747345&#038;type=1

http://www.facebook.com/photo.php?fbid=130090707069591&#038;set=p.130090707069591&#038;type=1

http://www.facebook.com/photo.php?fbid=130204773726573&#038;set=p.130204773726573&#038;type=1

http://www.facebook.com/photo.php?fbid=131154313629317&#038;set=p.131154313629317&#038;type=1

http://www.facebook.com/photo.php?fbid=133529226726132&#038;set=p.133529226726132&#038;type=1</pre>
<p>Most of these profiles are similar enough in execution to raise suspicion.  Each one of them is pointing to a site that leads you to either kicksbay.com or similar site.</p>
<p>How many kicksbay.com site copycats are out there?   Well, here is just a snapshot</p>
<pre>
one-sweet-pair.info
only-authentic.info
only-designer-goods.info
only-heels.info
only-jordans.info
only-louisvuitton.info
only-lv-heels.info
only-nike.info
pair-time.info
player-jordans.info
player-nike.info
player-pair.info
postjordan.info
postnike.info
postshoes.info
power-time.info
priceless-heels.info
rare-jordans.info
rarejordans.info
reallygoodjordandeal.info
right-jordans.info
right-kicks.info
right-nike.info
rightnike.info
runjordan.info
runnike.info
save-heels.info
sell-jordans.info
sell-nike.info
share-jordans.info
share-nike.info
share-pairs.info
share-sole.info
star-effect.info
star-feel.info
star-hoops.info
star-pairs.info
star-skills.info
thejordan.info
wholesale-jordans.info
wholesale-nike.info
wholesale-pairs.info</pre>
<p><!-- pre.cjk { font-family: "DejaVu Sans",monospace; }p { margin-bottom: 0.08in; }a:link {  } -->Clearly these profiles are fake and shoes they are selling are fake, and real people are getting <a href="http://www.kicksbayisfake.s5.com/">scammed</a> by it.</p>
<p>So why is this scam so widespread and successful? How are fake profiles able to acquire 1000s of real people as friends to whom they can market these shoes?</p>
<p>This is where Facebook&#8217;s “people you might know” suggestion comes into play. We all know that Facebook will suggest you list of people who went to same school, worked with same employer,  lived in same area or are friends of friends.  What about people with whom you do not have any such common ground?</p>
<p>As a test, on one of my profiles I had information about a school that I went to.  So far all the suggestions were for profiles with common school in common class. However on one of the fake profiles I encountered an ad for the “Miss Interenet” Facebook app. As soon as I added that app to my account all of my friend suggestions were for profiles similar to the fake profiles we encountered in shoe scam, girls with suggestive  photos and wall postings. None of them had anything in common with my profile except they might be related to “Miss Interent” app some way (as a user or liker).</p>
<p>Why is Facebook suggesting that? My hypothesis is that everything in Facebook world is identified as an object  with id. That means you, area that you live in, employer that you work for or school you went to are objects and so  is apps you are using, photos you are uploading and websites you are liking. If two people have any common object ID – they can be friends!</p>
<p>&nbsp;</p>
<p><!-- pre.cjk { font-family: "DejaVu Sans",monospace; }p { margin-bottom: 0.08in; }a:link {  } --></p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.barracudalabs.com%2Fwordpress%2Findex.php%2F2011%2F06%2F24%2Ffacebooksuggestion%2F&amp;title=Facebook%20suggestions%20fuel%20fake%20profile%20business" id="wpa2a_6"><img src="http://www.barracudalabs.com/wordpress/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.barracudalabs.com/wordpress/index.php/2011/06/24/facebooksuggestion/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Google (does not) Announce Google Pharmacy</title>
		<link>http://www.barracudalabs.com/wordpress/index.php/2011/06/02/google-does-not-announce-google-pharmacy/</link>
		<comments>http://www.barracudalabs.com/wordpress/index.php/2011/06/02/google-does-not-announce-google-pharmacy/#comments</comments>
		<pubDate>Thu, 02 Jun 2011 20:21:23 +0000</pubDate>
		<dc:creator>Dave Michmerhuizen</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.barracudalabs.com/wordpress/?p=1542</guid>
		<description><![CDATA[by Dave Michmerhuizen and Luis Chapetti &#8211; Security Researchers The spam honeypots at Barracuda Labs have detected new spam that takes social engineering &#8211; and chutzpah &#8211; to new heights. While Google announces new products and services regularly, the skeptical email recipient will determine that this announcement fails to make the grade. We do give [...]]]></description>
			<content:encoded><![CDATA[<p><span style="color: #808080;"><em>by Dave Michmerhuizen and Luis Chapetti &#8211; Security Researchers</em></span></p>
<p>The spam honeypots at Barracuda Labs have detected new spam that takes social engineering &#8211; and chutzpah &#8211; to new heights.</p>
<div id="attachment_1543" class="wp-caption alignnone" style="width: 460px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/05/googlepharmemail.jpg" target="_blank"><img class="size-full wp-image-1543 " title="Google Pharmacy Email" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/05/googlepharmemail.jpg" alt="Google Pharmacy Email" width="450" height="522" /></a><p class="wp-caption-text">Google Pharmacy Email</p></div>
<p>While Google announces new products and services regularly, the skeptical email recipient will determine that this announcement fails to make the grade.</p>
<p>We do give the spammers an A for their eye-catching addition of Viagra and Cialis to the Google logo.</p>
<p>However, we mark them down with a D for their fractured English, (&#8220;pharmaceutical interfaces&#8221;) and a resounding F both for their choice of a domain in Russia and for landing on a run-of-the-mill  rogue <a href="http://spamtrackers.eu/wiki/index.php/Canadian_Pharmacy" target="_blank">Canadian Pharmacy website</a>, as shown here</p>
<div id="attachment_1544" class="wp-caption alignnone" style="width: 460px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/05/googlepharmasite.jpg" target="_blank"><img class="size-full wp-image-1544 " title="Canadian Pharmacy website" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/05/googlepharmasite.jpg" alt="Canadian Pharmacy website" width="450" height="326" /></a><p class="wp-caption-text">Canadian Pharmacy website</p></div>
<p>Spammers have long traded on the cachet of the Google name when sending out lottery spam, but presenting Google as a purveyor of Viagra is a whole new level of impersonation.  It has to be especially galling to Google because the company has recently been accused of <a href="http://online.wsj.com/article/SB10001424052748704083904576335483063623402.html" target="_blank">knowingly accepting advertisements from rogue online pharmacies</a>.  For their part, Google recently <a href="http://googleblog.blogspot.com/2010/09/taking-rogue-pharmacies-to-court.html" target="_blank">went to court</a> to sue some of those same advertisers.</p>
<p>&nbsp;</p>
<p><a href="http://www.barracudanetworks.com/">Barracuda Networks</a> customers using the <a title="Spam &amp; Virus Firewall" href="http://www.barracudanetworks.com/ns/products/spam_overview.php" target="_blank">Barracuda Spam &amp; Virus Firewall</a> are protected from these emails.</p>
<p>&nbsp;</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.barracudalabs.com%2Fwordpress%2Findex.php%2F2011%2F06%2F02%2Fgoogle-does-not-announce-google-pharmacy%2F&amp;title=Google%20%28does%20not%29%20Announce%20Google%20Pharmacy" id="wpa2a_8"><img src="http://www.barracudalabs.com/wordpress/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.barracudalabs.com/wordpress/index.php/2011/06/02/google-does-not-announce-google-pharmacy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>You Will Dislike the &#8220;Dislike&#8221;</title>
		<link>http://www.barracudalabs.com/wordpress/index.php/2011/05/26/you-will-dislike-the-dislike/</link>
		<comments>http://www.barracudalabs.com/wordpress/index.php/2011/05/26/you-will-dislike-the-dislike/#comments</comments>
		<pubDate>Thu, 26 May 2011 13:30:47 +0000</pubDate>
		<dc:creator>Barracuda Labs</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.barracudalabs.com/wordpress/?p=1529</guid>
		<description><![CDATA[by Nidhi Shah, research scientist Many Facebook users have long waited for a Dislike button and this post is  to inform them that their wait is *not* yet over. The latest scam making rounds on Facebook is offering to add a &#8220;Dislike Button&#8221; to your profile. However, clicking on the link to Activate or Enable [...]]]></description>
			<content:encoded><![CDATA[<p><span style="color: #888888;"><em>by Nidhi Shah, research scientist</em></span></p>
<p>Many Facebook users have long waited for a Dislike button and this post is  to inform them that their wait is *not* yet over. The latest scam making rounds on Facebook is offering to add a &#8220;Dislike Button&#8221; to your profile.</p>
<p><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/05/Screenshot-Gaia-BoutiqueClub-Mozilla-Firefox.png"><img class="aligncenter size-large wp-image-1532" title="Screenshot-Gaia BoutiqueClub - Mozilla Firefox" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/05/Screenshot-Gaia-BoutiqueClub-Mozilla-Firefox-1024x335.png" alt="" width="450" height="147" /></a></p>
<p>However, clicking on the link to Activate or Enable the feature will only lead you to various, and typical, malicious offerings such as likejacking, RogueAV, drive-by downloads or survey scams.</p>
<p>The most interesting thing we noticed with this one is how creative the bad guys are getting about the distribution of their malicious apps. They are no longer simply exploiting a user&#8217;s inherent trust on Facebook via an app most likely since that means is getting some attention and risks being taken down. Instead, they are using other venues that have a user&#8217;s trust and also  allows them to distribute their apps. e.g. Mozilla add on or Chrome plugin.</p>
<p><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/05/dislike_facebookdislikebuttonfurchromeandmozilla.png"><img class="aligncenter size-large wp-image-1536" title="dislike_facebookdislikebuttonfurchromeandmozilla" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/05/dislike_facebookdislikebuttonfurchromeandmozilla-1024x426.png" alt="" width="450" height="187" /></a></p>
<p>Once installed these plugins have the ability to intercept and add code to a user&#8217;s Facebook profile and any other website he or she may browse.  One such plugin inserts rotating ads whenever the victim browses Facebook. While these ads may sound benign, ad networks  in the past have been compromised and suffer from what is known as  malvertisement.</p>
<p><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/05/dislike_chromeadd.png"><img class="aligncenter size-large wp-image-1537" title="dislike_chromeadd" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/05/dislike_chromeadd-1024x648.png" alt="" width="450" height="284" /></a></p>
<p>The bottom line? As much as we might like to have it, there is no Dislike button just yet. Facebook users, and those browsing the Web in general, should remain extra careful before giving access to any apps on your browsing machine.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.barracudalabs.com%2Fwordpress%2Findex.php%2F2011%2F05%2F26%2Fyou-will-dislike-the-dislike%2F&amp;title=You%20Will%20Dislike%20the%20%26%238220%3BDislike%26%238221%3B" id="wpa2a_10"><img src="http://www.barracudalabs.com/wordpress/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.barracudalabs.com/wordpress/index.php/2011/05/26/you-will-dislike-the-dislike/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Spammers Offer iPhone 5, Deliver Malware</title>
		<link>http://www.barracudalabs.com/wordpress/index.php/2011/05/23/spammers-offer-iphone-5-deliver-malware/</link>
		<comments>http://www.barracudalabs.com/wordpress/index.php/2011/05/23/spammers-offer-iphone-5-deliver-malware/#comments</comments>
		<pubDate>Mon, 23 May 2011 16:00:53 +0000</pubDate>
		<dc:creator>Dave Michmerhuizen</dc:creator>
				<category><![CDATA[Email Security]]></category>
		<category><![CDATA[Internet Security Tips]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Anti-Spam]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://www.barracudalabs.com/wordpress/?p=1510</guid>
		<description><![CDATA[by Dave Michmerhuizen &#8211; Security Researcher &#160; The iPhone 5 isn&#8217;t due to be released until fall, or even Christmas, but the spam honeypots at Barracuda Labs are already detecting malicious messages targeting anxious Apple acolytes. The image of a beautiful see-through phone is actually a concept photo that is over two years old. All [...]]]></description>
			<content:encoded><![CDATA[<p><em><span style="color: #808080;">by Dave Michmerhuizen &#8211; Security Researcher</span></em></p>
<p>&nbsp;</p>
<p>The iPhone 5 isn&#8217;t due to be released until fall, or even Christmas, but the spam honeypots at Barracuda Labs are already detecting malicious messages targeting anxious Apple acolytes.</p>
<div id="attachment_1511" class="wp-caption alignnone" style="width: 460px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/05/Fakeiphonecloseup.jpg" target="_blank"><img class="size-full wp-image-1511 " title="Fake Phone" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/05/Fakeiphonecloseup.jpg" alt="Fake Phone" width="450" height="283" /></a><p class="wp-caption-text">Fake Phone</p></div>
<p>The image of a beautiful see-through phone is actually a <a href="http://www.toxel.com/inspiration/2009/02/15/10-beautiful-apple-iphone-concepts/" target="_blank">concept photo</a> that is over two years old.</p>
<p>All of the links in the email lead to a copy of Trojan.Zapchast, an IRC-controlled backdoor.</p>
<div id="attachment_1512" class="wp-caption alignnone" style="width: 460px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/05/fakeiphone.jpg" target="_blank"><img class="size-full wp-image-1512 " title="Fake iPhone spam" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/05/fakeiphone.jpg" alt="Fake iPhone spam" width="450" height="631" /></a><p class="wp-caption-text">Fake iPhone spam</p></div>
<p>Naturally the apple.com from: address is spoofed.</p>
<p>If you do click on one of the links and run the offered executable, another old iPhone concept photo is displayed in order to distract you from the installation of the backdoor.</p>
<div id="attachment_1524" class="wp-caption alignnone" style="width: 460px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/05/fakeiphonedistraction.jpg" target="_blank"><img class="size-full wp-image-1524 " title="Photo distracts you from backdoor installation" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/05/fakeiphonedistraction.jpg" alt="Photo distracts you from backdoor installation" width="450" height="311" /></a><p class="wp-caption-text">Photo distracts you from backdoor installation</p></div>
<p>&nbsp;</p>
<p>In this case, if you&#8217;re  curious about iPhone products, visit the Apple iPhone pages at  http://www.apple.com/iphone. And never click on links in emails, especially from unknown sources.</p>
<p><a href="http://www.barracudanetworks.com/">Barracuda Networks</a> customers using the <a title="Spam &amp; Virus Firewall" href="http://www.barracudanetworks.com/ns/products/spam_overview.php" target="_blank">Barracuda Spam &amp; Virus Firewall</a> are protected from these emails.</p>
<p>&nbsp;</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.barracudalabs.com%2Fwordpress%2Findex.php%2F2011%2F05%2F23%2Fspammers-offer-iphone-5-deliver-malware%2F&amp;title=Spammers%20Offer%20iPhone%205%2C%20Deliver%20Malware" id="wpa2a_12"><img src="http://www.barracudalabs.com/wordpress/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.barracudalabs.com/wordpress/index.php/2011/05/23/spammers-offer-iphone-5-deliver-malware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Fake AntiVirus Scams Add MacOS Support</title>
		<link>http://www.barracudalabs.com/wordpress/index.php/2011/05/19/fake-antivirus-target-m/</link>
		<comments>http://www.barracudalabs.com/wordpress/index.php/2011/05/19/fake-antivirus-target-m/#comments</comments>
		<pubDate>Thu, 19 May 2011 22:09:57 +0000</pubDate>
		<dc:creator>Dave Michmerhuizen</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[SEO Poisoning]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Web Security]]></category>
		<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[Rogue AV]]></category>
		<category><![CDATA[search engine malware]]></category>

		<guid isPermaLink="false">http://www.barracudalabs.com/wordpress/?p=1486</guid>
		<description><![CDATA[by Luis Chapetti &#38; Dave Michmerhuizen &#8211; Security Researchers Fake antivirus scams are designed to scare innocent computer users with exaggerated displays of virus activity in the hope that they will hand over their credit card numbers to make it go away.   They&#8217;ve been around for years and the most prevalent ones use a [...]]]></description>
			<content:encoded><![CDATA[<p><span style="color: #808080;"><em>by Luis Chapetti &amp; Dave Michmerhuizen &#8211; Security Researchers</em></span></p>
<p>Fake antivirus scams are designed to scare innocent computer users with exaggerated displays of virus activity in the hope that they will hand over their credit card numbers to make it go away.   They&#8217;ve been around for years and the most prevalent ones use a freely available JavaScript design that mimics the Windows user interface, as seen here:</p>
<div id="attachment_1487" class="wp-caption alignnone" style="width: 460px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/05/mfav_windows.jpg" target="_blank"><img class="size-full wp-image-1487 " title="Fake Antivirus that mimics Windows" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/05/mfav_windows.jpg" alt="Fake Antivirus that mimics Windows" width="450" height="324" /></a><p class="wp-caption-text">Fake Antivirus that mimics Windows</p></div>
<p>&nbsp;</p>
<p>When these pages pop up on Macintosh computers, it&#8217;s immediately obvious that something isn&#8217;t right.</p>
<p>Last quarter, Apple set a new record (3.47 million sold in the quarter) with a growth rate of  33% over the prior year’s quarter.  Apple has about 10% of the computer market in the United States, and that doesn&#8217;t even include iPads.</p>
<p>That market share has been noticed by the fake antivirus scammers, and this week they have added a new JavaScript design that mimics the Macintosh interface, as seen here:</p>
<div id="attachment_1492" class="wp-caption alignnone" style="width: 460px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/05/mfav_applesecurity.jpg" target="_blank"><img class="size-full wp-image-1492 " title="Fake antivirus that mimics Macintosh " src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/05/mfav_applesecurity.jpg" alt="Fake antivirus that mimics Macintosh " width="450" height="600" /></a><p class="wp-caption-text">Fake antivirus that mimics Macintosh </p></div>
<p>&nbsp;</p>
<p>Drive-by download sites now serve up this page if they detect access from a MacOS computer while Windows users still see a Windows style page.   The example above is called &#8220;Apple Security Center&#8221; but similar templates have been seen named MacDefender.</p>
<p>Since this is just JavaScript, the correct move at this point is to refuse the download and browse elsewhere.  Accepting the download and running it installs &#8220;Mac Protector&#8221; which displays pornographic images and promises to remove them for a credit card payment.</p>
<p>The initial infection vector is poisoned entries in Google search results.  We&#8217;ve talked extensively about <a title="Search Result Malware" href="http://www.barracudalabs.com/wordpress/index.php/2011/03/03/email-spam-drops-by-half-while-search-engine-malware-increases-50-percent-and-twitter-crime-rate-rises-20-percent-during-2010/" target="_blank">poisoned search results</a> and this represents another example of where otherwise normal Web sites are compromised and made to serve up bogus pages that are well ranked by Google. When one of these links is clicked, the compromised Web site detects a visit from Google search results and sends the visitor to a server that presents the fake antivirus. The recent change in Google content ranking has not stymied these attacks &#8211; the malicious link we tested was on page 1 of our search results:</p>
<div id="attachment_1497" class="wp-caption alignnone" style="width: 460px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/05/mfav_google.jpg" target="_blank"><img class="size-full wp-image-1497 " title="Malicious link in Google results" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/05/mfav_google.jpg" alt="Malicious link in Google results" width="450" height="600" /></a><p class="wp-caption-text">Malicious link in Google results</p></div>
<p>&nbsp;</p>
<p>Past Search Engine Optimization campaigns targeted very popular search terms such as celebrity sightings or breaking news events.  The poisoned links mentioned in this post are more likely to show up in the results for more mundane search terms so as to attract less attention, but they&#8217;re still getting <a href="http://www.zdnet.com/blog/bott/an-applecare-support-rep-talks-mac-malware-is-getting-worse/3342" target="_blank">plenty of traffic</a>.</p>
<p>This is turning out to be a <a href="http://www.betanews.com/article/Microsoft-helps-stop-malware-while-Apple-blows-off-malware-victims/1305741363" target="_blank">big problem</a> for Apple. It has been conventional wisdom for years that one of the simplest Internet security solutions is to &#8220;just buy a Mac&#8221; and stop worrying.  Now that the most common drive-by attack vectors are serving up malware, unwary Mac users are being exposed to the <a href="http://www.barracudalabs.com/wordpress/index.php/2010/10/19/malicious-microsoft-imposter-lock-up-your-desktop/" target="_blank">harsh world</a> that Windows users have dealt with for years, and are going to have to learn the same lessons.  Don&#8217;t believe everything that pops up on your screen, and don&#8217;t run any software unless you know where it came from and what it will do.</p>
<p><a href="http://www.barracudanetworks.com/">Barracuda Networks</a> <a title="Web Filter" href="http://www.barracudanetworks.com/ns/products/web-filter-overview.php" target="_blank">Barracuda Web Filters</a> and the <a title="Cloud-based Web Security" href="http://www.barracudanetworks.com/ns/products/web_security_flex_overview.php" target="_blank">Barracuda Web Security <em>Flex</em></a> stop the download of this threat.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.barracudalabs.com%2Fwordpress%2Findex.php%2F2011%2F05%2F19%2Ffake-antivirus-target-m%2F&amp;title=Fake%20AntiVirus%20Scams%20Add%20MacOS%20Support" id="wpa2a_14"><img src="http://www.barracudalabs.com/wordpress/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.barracudalabs.com/wordpress/index.php/2011/05/19/fake-antivirus-target-m/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Facebook survey scams reappear as Verify Your Account wall posts</title>
		<link>http://www.barracudalabs.com/wordpress/index.php/2011/05/12/facebook-survey-scams-reappear-as-verify-your-account-wall-posts/</link>
		<comments>http://www.barracudalabs.com/wordpress/index.php/2011/05/12/facebook-survey-scams-reappear-as-verify-your-account-wall-posts/#comments</comments>
		<pubDate>Thu, 12 May 2011 07:17:07 +0000</pubDate>
		<dc:creator>Dave Michmerhuizen</dc:creator>
				<category><![CDATA[Social Networking]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.barracudalabs.com/wordpress/?p=1466</guid>
		<description><![CDATA[by Dave Michmerhuizen &#8211; Security Researcher Facebook survey scammers who had recent success with JavaScript cut and paste pages have changed their approach and turned loose a fast-spreading &#8220;Please verify your account&#8221;  campaign that appears as a wall post from a friend&#8230; Barracuda Labs recently reported on versions of this scam that required you to [...]]]></description>
			<content:encoded><![CDATA[<p><em><span style="color: #808080;">by Dave Michmerhuizen &#8211; Security Researcher</span></em></p>
<p>Facebook survey scammers who had recent success with JavaScript cut and paste pages have changed their approach and turned loose a fast-spreading &#8220;Please verify your account&#8221;  campaign that appears as a wall post from a friend&#8230;</p>
<p><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/05/VerifyMyAccount1.jpg" target="_blank"><img class="size-full wp-image-1468  alignnone" title="Verify your acount wall post" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/05/VerifyMyAccount1.jpg" alt="Verify your acount wall post" width="450" height="270" /></a></p>
<p>Barracuda Labs <a href="http://www.barracudalabs.com/wordpress/index.php/2011/05/10/facebook-is-infested-with-cut-and-paste-javascript-survey-scams/" target="_blank">recently reported</a> on versions of this scam that required you to cut and past a bit of JavaScript into your URL bar.  The attack above uses the same JavaScript but embeds it in a link attached to the wall post.</p>
<p>There is another version that we have no sample of which posts  an obscene message to your wall which then claims that the only way to remove the obscenity is to press a &#8220;Remove this app&#8221; button that is part of the post.</p>
<p>As was the case in the cut and past attack, if the link is pressed the JavaScript executes in the context of your Facebook page and has access to all of the APIs and credentials of your Facebook page.  The attacking JavaScript takes advantage of that context to post the same scam to the walls of all of your friends.</p>
<p>The end result is the same as our previous report &#8211; a sham survey that attempts to sign you up for some unwanted service or get your cell phone number in order to send premium SMS messages to it.</p>
<p>Eliminating the convoluted cut and paste instructions makes this version of the JavaScript attack much simpler and more convincing and it has been spreading across Facebook like wildfire.   We can only assume that at some point Facebook will sanitize links in  wall posts and not allow use of the &#8220;javascript:&#8221; scheme.   Until then,  expect to see waves of these scams using every social engineering attack  in the book.</p>
<p>In the meantime, don&#8217;t click on links that are part of unusual items posted to your wall &#8211; delete them instead.   Visit the Facebook account settings pages to take care of account related issues.</p>
<p>&nbsp;</p>
<p>As always, Barracuda Networks recommends you exercise special care when visiting links posted in your social network feeds.   <a title="Web Filter" href="http://www.barracudanetworks.com/ns/products/web-filter-overview.php" target="_blank"> Barracuda Web Filters</a> and the <a title="Web Filtering Service" href="http://www.barracudanetworks.com/ns/products/purewire_web_security_service_overview.php" target="_blank">Barracuda Web Filtering Service</a> block access to these sites.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.barracudalabs.com%2Fwordpress%2Findex.php%2F2011%2F05%2F12%2Ffacebook-survey-scams-reappear-as-verify-your-account-wall-posts%2F&amp;title=Facebook%20survey%20scams%20reappear%20as%20Verify%20Your%20Account%20wall%20posts" id="wpa2a_16"><img src="http://www.barracudalabs.com/wordpress/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.barracudalabs.com/wordpress/index.php/2011/05/12/facebook-survey-scams-reappear-as-verify-your-account-wall-posts/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Osama Bin Laden Death Picture Spam on the Rise</title>
		<link>http://www.barracudalabs.com/wordpress/index.php/2011/05/04/osama-bin-laden-death-picture-spam/</link>
		<comments>http://www.barracudalabs.com/wordpress/index.php/2011/05/04/osama-bin-laden-death-picture-spam/#comments</comments>
		<pubDate>Wed, 04 May 2011 18:57:08 +0000</pubDate>
		<dc:creator>Dave Michmerhuizen</dc:creator>
				<category><![CDATA[Email Security]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.barracudalabs.com/wordpress/?p=1400</guid>
		<description><![CDATA[by Dave Michmerhuizen &#38; Luis Chapetti &#8211; Security Researchers The spam honeypots at Barracuda Labs have detected the first of what we suspect will be a wave of spam that takes advantage of the curiosity surrounding the death of Osama Bin Laden.  Not so long ago spam emails would have been the first to exploit [...]]]></description>
			<content:encoded><![CDATA[<p><em><span style="color: #808080;">by Dave Michmerhuizen &amp; Luis Chapetti &#8211; Security Researchers</span></em></p>
<p>The spam honeypots at Barracuda Labs have detected the first of what we suspect will be a wave of spam that takes advantage of the curiosity surrounding the death of Osama Bin Laden.  Not so long ago spam emails would have been the first to exploit such a current event.   However, as we <a href="http://www.barracudalabs.com/wordpress/index.php/2011/05/02/cyber-criminals-continue-to-capitalize-on-current-events-osama-bin-laden-dead/" target="_blank">posted recently</a>, Facebook now has that distinction.</p>
<p>The spam offers up some pretty gruesome photos:</p>
<div id="attachment_1401" class="wp-caption alignnone" style="width: 460px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/05/Osama1.jpg" target="_blank"><img class="size-full wp-image-1401 " title="Spam" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/05/Osama1.jpg" alt="Spam" width="450" height="487" /></a><p class="wp-caption-text">Spam</p></div>
<p>The Portuguese text reveals that these spams target residents of Brazil.  A rough <a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/05/Osama2.jpg" target="_blank">translation </a>says that the photos visible in the email are not real, (they are indeed <a href="http://www.tmz.com/2011/05/02/osama-bin-laden-death-photo-fake-fraud-hoax/" target="_blank">fake</a>) but that real photographs are available from the attached link.</p>
<p>Following the attached link leads the user to malware, not photos, as shown here:</p>
<div id="attachment_1409" class="wp-caption alignnone" style="width: 460px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/05/Osama3.jpg" target="_blank"><img class="size-full wp-image-1409  " title="Malware, not photos" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/05/Osama3.jpg" alt="Malware, not photos" width="450" height="374" /></a><p class="wp-caption-text">Malware, not photos</p></div>
<p>This should certainly ring all sorts of alarm bells.  Users do not &#8220;Run&#8221; photos; however, this file is a version of Trojan.Banload, downloader which installs additional malware. As shown below, it downloads another file, a variant of Trojan.PWS.Banker, that settles onto the user&#8217;s PC and intercepts online banking usernames and passwords.</p>
<div id="attachment_1410" class="wp-caption alignnone" style="width: 460px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/05/Osama4.jpg" target="_blank"><img class="size-full wp-image-1410 " title="Malware traffic" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/05/Osama4.jpg" alt="Malware traffic" width="450" height="52" /></a><p class="wp-caption-text">Malware traffic</p></div>
<p>Once the banking Trojan is successfully installed, a message is sent back to the malware authors:</p>
<p><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/05/Osama5.jpg" target="_blank"><img class="alignnone size-full wp-image-1411" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/05/Osama5.jpg" alt="" width="450" height="302" /></a></p>
<p>&nbsp;</p>
<p>There are similar families of malware optimized for stealing online banking credentials from American and European computer users, and appealing social engineering strategies for delivering them, Osama Bin Laden&#8217;s death being only one of many.   Do not open or run email attachments.</p>
<p><a href="http://www.barracudanetworks.com/">Barracuda Networks</a> customers using the <a title="Spam &amp; Virus Firewall" href="http://www.barracudanetworks.com/ns/products/spam_overview.php" target="_blank">Barracuda Spam &amp; Virus Firewall</a> are protected from these emails.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.barracudalabs.com%2Fwordpress%2Findex.php%2F2011%2F05%2F04%2Fosama-bin-laden-death-picture-spam%2F&amp;title=Osama%20Bin%20Laden%20Death%20Picture%20Spam%20on%20the%20Rise" id="wpa2a_18"><img src="http://www.barracudalabs.com/wordpress/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.barracudalabs.com/wordpress/index.php/2011/05/04/osama-bin-laden-death-picture-spam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Paypal account statement emails:  Do as we say, not as we do.</title>
		<link>http://www.barracudalabs.com/wordpress/index.php/2011/04/28/paypal-account-statement-emails-do-as-we-say-not-as-we-do/</link>
		<comments>http://www.barracudalabs.com/wordpress/index.php/2011/04/28/paypal-account-statement-emails-do-as-we-say-not-as-we-do/#comments</comments>
		<pubDate>Thu, 28 Apr 2011 17:28:15 +0000</pubDate>
		<dc:creator>Dave Michmerhuizen</dc:creator>
				<category><![CDATA[Email Security]]></category>
		<category><![CDATA[ID Theft]]></category>
		<category><![CDATA[Internet Security Tips]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.barracudalabs.com/wordpress/?p=1307</guid>
		<description><![CDATA[by Dave Michmerhuizen and Denis Kieft &#8211; security researchers Barracuda Labs researchers have recently seen emails from PayPal Inc. that initally seem to be phish but ultimately appear to be a security fail by a company that surely should know better. It is a well-accepted email security best practice to never click on links in [...]]]></description>
			<content:encoded><![CDATA[<p><span style="color: #808080;"><em>by Dave Michmerhuizen and Denis Kieft &#8211; security researchers</em></span></p>
<p>Barracuda Labs researchers have recently seen emails from PayPal Inc. that initally seem to be phish but ultimately appear to be a security fail by a company that surely should know better.</p>
<p>It is a well-accepted email security best practice to never click on links in emails.  Most businesses, particularly ones that are phishing targets, explicitly advise their users not to click on emails.  As you would expect, PayPal does so on their website.</p>
<div id="attachment_1308" class="wp-caption alignnone" style="width: 460px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/04/paypal_warning.jpg" target="_blank"><img class="size-full wp-image-1308 " title="Warning on PayPal website" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/04/paypal_warning.jpg" alt="Warning on PayPal website" width="450" height="466" /></a><p class="wp-caption-text">Warning on PayPal website</p></div>
<p>&nbsp;</p>
<p>Consider that warning and then take a look at this email from Paypal, via servers at responsys.net, a software service that allows marketers to manage email campaigns&#8230;</p>
<div id="attachment_1309" class="wp-caption alignnone" style="width: 460px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/04/paypal_email.jpg" target="_blank"><img class="size-full wp-image-1309 " title="PayPal &quot;enhanced account statement&quot; email" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/04/paypal_email.jpg" alt="PayPal &quot;enhanced account statement&quot; email" width="450" height="446" /></a><p class="wp-caption-text">PayPal &quot;enhanced account statement&quot; email</p></div>
<p>The email contains ELEVEN hyperlinks, all pointing to an email response servelet which records your click and then transfers the browser to the PayPal login screen.   &#8220;At first I was sure it was a phishing email,&#8221; commented a Labs researcher who received one of the emails.   Although PayPal has declined to comment on the email,  close examination shows no malicious content.    Instead, this appears to be a case of a Marketing department in need of a little security education.</p>
<p>It&#8217;s unfortunate that this is the case, because security professionals have been trying to teach good email security practices for years.  An email from a bank or online service should be considered suspect by  default.   PayPal&#8217;s own advice is the safest advice, always open your  web browser and type in the URL you intend to visit &#8211; never click on a  link embedded in an email.</p>
<p>Given that email is still the primary vector for identity theft and that PayPal is one of the most phished brands on the Internet, we would expect them to be particularly sensitive to this issue.   Phishing emails like <a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/04/paypal_spam.jpg" target="_blank">this one</a> are so common that only a blanket rule against clicking on embedded links can be effective.   When PayPal sends out their own emails containing links they confound customers who have been long been told not to click on those very links.</p>
<p>&nbsp;</p>
<p><a href="http://www.barracudanetworks.com/">Barracuda Networks</a> customers using the <a title="Spam &amp; Virus Firewall" href="http://www.barracudanetworks.com/ns/products/spam_overview.php" target="_blank">Barracuda Spam &amp; Virus Firewall</a> are protected from phishing emails.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.barracudalabs.com%2Fwordpress%2Findex.php%2F2011%2F04%2F28%2Fpaypal-account-statement-emails-do-as-we-say-not-as-we-do%2F&amp;title=Paypal%20account%20statement%20emails%3A%20%20Do%20as%20we%20say%2C%20not%20as%20we%20do." id="wpa2a_20"><img src="http://www.barracudalabs.com/wordpress/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.barracudalabs.com/wordpress/index.php/2011/04/28/paypal-account-statement-emails-do-as-we-say-not-as-we-do/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

