<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Tekblog</title>
	<atom:link href="http://tekblog.teksquisite.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://tekblog.teksquisite.com</link>
	<description>Tackling Technology One Byte At A Time!</description>
	<lastBuildDate>Sun, 07 Mar 2010 15:24:34 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Google ALERT poisoned URL</title>
		<link>http://tekblog.teksquisite.com/2010/03/07/google-alert-poisoned-url/</link>
		<comments>http://tekblog.teksquisite.com/2010/03/07/google-alert-poisoned-url/#comments</comments>
		<pubDate>Sun, 07 Mar 2010 15:17:41 +0000</pubDate>
		<dc:creator>Teksquisite</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[alerts]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[poisoned url]]></category>

		<guid isPermaLink="false">http://tekblog.teksquisite.com/?p=2615</guid>
		<description><![CDATA[
			
				
			
		
While happily perusing Google malware alerts this morning, I managed to click on a poisoned URL.  The Vista computer that I use for alerts/surfing/chatting/social networking is not my main PC, but is obviously one that I have no desire to infect!

So as to not reinvent the wheel, I went to Norton Safeweb and got a fairly [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Ftekblog.teksquisite.com%2F2010%2F03%2F07%2Fgoogle-alert-poisoned-url%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Ftekblog.teksquisite.com%2F2010%2F03%2F07%2Fgoogle-alert-poisoned-url%2F&amp;source=teksquisite&amp;style=normal&amp;service=is.gd" height="61" width="50" /><br />
			</a>
		</div>
<p>While happily perusing Google malware alerts this morning, I managed to click on a poisoned URL.  The Vista computer that I use for alerts/surfing/chatting/social networking is not my main PC, but is obviously one that I have no desire to infect!</p>
<p><a href="http://tekblog.teksquisite.com/wp-content/uploads/2010/03/Shot1.png"><img class="aligncenter size-full wp-image-2616" title="Shot1" src="http://tekblog.teksquisite.com/wp-content/uploads/2010/03/Shot1.png" alt="" width="636" height="363" /></a></p>
<p>So as to not reinvent the wheel, I went to <a href="http://safeweb.norton.com/report/show?url=the-best-antivirus.info" target="_blank">Norton Safeweb</a> and got a fairly good description of what this threat entails:</p>
<p>This particular malware is a drive-by-download and HTTP Fake Scan Webpage.  It is not OK to click <strong>OK </strong>on the popup! You should immediately use <a href="http://support.microsoft.com/kb/323527" target="_blank">task manager</a> to end the browser session.  Next you should run an antivirus and anti-malware scan (<a href="http://www.malwarebytes.org/" target="_blank">Malwarebytes</a> is a good choice.)</p>
<div id="_mcePaste">
<p><strong>This is a short-n-sweet!  Until next time — stay safe online! </strong></p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://tekblog.teksquisite.com/2010/03/07/google-alert-poisoned-url/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TrademytweetsDOTcom &#8211; just another Twitter Scam!</title>
		<link>http://tekblog.teksquisite.com/2010/02/21/trademytweets-com-just-another-twitter-scam/</link>
		<comments>http://tekblog.teksquisite.com/2010/02/21/trademytweets-com-just-another-twitter-scam/#comments</comments>
		<pubDate>Mon, 22 Feb 2010 02:55:23 +0000</pubDate>
		<dc:creator>Teksquisite</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[identity theft]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[scam]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://tekblog.teksquisite.com/?p=2598</guid>
		<description><![CDATA[
			
				
			
		
Trademytweets[SCAM]com is a new variation of the old Tweeterfast, Tweeterfollow theme. Recent domains that have operated under the same gray umbrella are gettwitterfollowersforfree.com and
SpreadMyTweets.com.
Trademytweets claims:
&#8220;How does it work? When you sign in with your Twitter details, our system will find you 20, 40, 60 or 100 other Tweeters. Then with these people it will begin [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Ftekblog.teksquisite.com%2F2010%2F02%2F21%2Ftrademytweets-com-just-another-twitter-scam%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Ftekblog.teksquisite.com%2F2010%2F02%2F21%2Ftrademytweets-com-just-another-twitter-scam%2F&amp;source=teksquisite&amp;style=normal&amp;service=is.gd" height="61" width="50" /><br />
			</a>
		</div>
<p>Trademytweets[SCAM]com is a new variation of the old <a href="http://tekblog.teksquisite.com/2009/12/15/tweeterfast-tweeterfollow-twtkingz-the-never-ending-twitter-scam/" target="_blank">Tweeterfast, Tweeterfollow theme.</a> Recent domains that have operated under the same gray umbrella are gettwitterfollowersforfree.com and<br />
SpreadMyTweets.com.</p>
<p>Trademytweets claims:</p>
<p><em>&#8220;How does it work? When you sign in with your Twitter details, our system will find you 20, 40, 60 or 100 other Tweeters. Then with these people it will begin to make them follow you as you follow them, instantly. &#8220;An eye for an eye.&#8221; This service will continue until you choose to stop it.&#8221;</em></p>
<p style="text-align: center;"><a href="http://tekblog.teksquisite.com/wp-content/uploads/2010/02/trademytweets-1.png"><img class="aligncenter size-full wp-image-2599" title="trademytweets-1" src="http://tekblog.teksquisite.com/wp-content/uploads/2010/02/trademytweets-1.png" alt="" width="472" height="357" /></a></p>
<p style="text-align: center;">
<p style="text-align: left;">
<p style="text-align: center;"><a href="http://tekblog.teksquisite.com/wp-content/uploads/2010/02/followers.png"><img class="aligncenter size-full wp-image-2602" title="followers" src="http://tekblog.teksquisite.com/wp-content/uploads/2010/02/followers.png" alt="" width="550" height="317" /></a></p>
<p style="text-align: left;"><strong>Current keyword tweets:</strong>with approximately 10 tweets per minute involving numerous affected accounts.</p>
<p>&#8220;Want some Free Twitter Followers?&#8221;<br />
&#8220;Just used TMT for some free followers&#8221;<br />
&#8220;Get Free Twitter Followers!&#8221;</p>
<p style="text-align: center;"><a href="http://tekblog.teksquisite.com/wp-content/uploads/2010/02/registrant.png"><img class="aligncenter size-full wp-image-2605" title="registrant" src="http://tekblog.teksquisite.com/wp-content/uploads/2010/02/registrant.png" alt="" width="540" height="224" /></a></p>
<p style="text-align: left;">
<p style="text-align: left;"><strong>Until Next time &#8211; stay safe online!</strong></p>
<p style="text-align: center;">
<p style="text-align: center;">
<p style="text-align: left;">
]]></content:encoded>
			<wfw:commentRss>http://tekblog.teksquisite.com/2010/02/21/trademytweets-com-just-another-twitter-scam/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>A quick and dirty on vigilante hackers</title>
		<link>http://tekblog.teksquisite.com/2010/02/16/a-quick-and-dirty-on-vigilante-hackers/</link>
		<comments>http://tekblog.teksquisite.com/2010/02/16/a-quick-and-dirty-on-vigilante-hackers/#comments</comments>
		<pubDate>Tue, 16 Feb 2010 22:34:15 +0000</pubDate>
		<dc:creator>Teksquisite</dc:creator>
				<category><![CDATA[hacking]]></category>
		<category><![CDATA[DDoS]]></category>
		<category><![CDATA[hacktivism]]></category>
		<category><![CDATA[vigilante hackers]]></category>

		<guid isPermaLink="false">http://tekblog.teksquisite.com/?p=2591</guid>
		<description><![CDATA[
			
				
			
		

Psychological harassment, obstruction of justice,  and misuse of Internet technologies is clearly breaking the law.
For those of us who are involved in the realm of information security, it is a sad time indeed to see the control that some vigilante hackers have over the Internet.
Some of these cyber-criminals are not at all who they portray [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Ftekblog.teksquisite.com%2F2010%2F02%2F16%2Fa-quick-and-dirty-on-vigilante-hackers%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Ftekblog.teksquisite.com%2F2010%2F02%2F16%2Fa-quick-and-dirty-on-vigilante-hackers%2F&amp;source=teksquisite&amp;style=normal&amp;service=is.gd" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://tekblog.teksquisite.com/wp-content/uploads/2010/02/tantrum.jpg"><img class="alignleft size-full wp-image-2593" title="DDoS tantrum" src="http://tekblog.teksquisite.com/wp-content/uploads/2010/02/tantrum.jpg" alt="" width="200" height="171" /></a></p>
<p>Psychological harassment, obstruction of justice,  and misuse of Internet technologies is clearly breaking the law.</p>
<p>For those of us who are involved in the realm of information security, it is a sad time indeed to see the control that some vigilante hackers have over the Internet.</p>
<p>Some of these cyber-criminals are not at all who they portray themselves to be. If you tear down their core belief system, vigilante hacker intentions are rarely focused on the good of society as a whole, and almost always seeking some form of self-gratification in the realm of fame and glory.</p>
<p>Would you really support a child who is having a major temper tantrum with rewards of praise for such actions?  Or would you teach that child how to utilize appropriate coping skills so that she/he could become a better family member, friend and neighbor.</p>
<p><strong>This is a short-n-sweet!  Until next time — stay safe online! </strong></p>
]]></content:encoded>
			<wfw:commentRss>http://tekblog.teksquisite.com/2010/02/16/a-quick-and-dirty-on-vigilante-hackers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Spam Spam (What It Do)</title>
		<link>http://tekblog.teksquisite.com/2010/02/11/spam-spam-what-it-do/</link>
		<comments>http://tekblog.teksquisite.com/2010/02/11/spam-spam-what-it-do/#comments</comments>
		<pubDate>Thu, 11 Feb 2010 19:43:44 +0000</pubDate>
		<dc:creator>Teksquisite</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[bredolab]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[harvesting]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[pushdo]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[spoofing]]></category>
		<category><![CDATA[Trojans]]></category>
		<category><![CDATA[UPS]]></category>

		<guid isPermaLink="false">http://tekblog.teksquisite.com/?p=2297</guid>
		<description><![CDATA[Spammers often collect email addresses from customer lists, chatrooms, email chain letters, forums, newsgroups, websites, and viruses. Current email accounts that are receiving spam have connections to prior chain mails, forums, and newsgroups. Spam or junk email is almost always unsolicited and unwanted.]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Ftekblog.teksquisite.com%2F2010%2F02%2F11%2Fspam-spam-what-it-do%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Ftekblog.teksquisite.com%2F2010%2F02%2F11%2Fspam-spam-what-it-do%2F&amp;source=teksquisite&amp;style=normal&amp;service=is.gd" height="61" width="50" /><br />
			</a>
		</div>
<p><strong>Disclaimer:</strong> This blog post is in relation to my collection of spam. I am not a spam expert.</p>
<p>The past few weeks have elicited all manner of spam at Teksquisite, and also at Gmail and Yahoo accounts.  Spammers often collect email addresses from customer lists, chatrooms, email chain letters, forums, newsgroups, websites, and viruses. Current email accounts that are receiving spam have connections to prior chain mails, forums, and newsgroups. Spam or junk email is almost always unsolicited and unwanted.</p>
<p><em>&#8220;Increasingly, e-mail spam today is sent via &#8220;zombie networks&#8221;, networks of virus- or worm-infected personal computers in homes and offices around the globe; many modern worms install a backdoor which allows the spammer access to the computer and use it for malicious purposes. This complicates attempts to control the spread of spam, as in many cases the spam doesn&#8217;t even originate from the spammer.&#8221;</em> &#8211;<a title="wikipedia" href="http://en.wikipedia.org/wiki/Spam_%28electronic%29" target="_blank">Wikipedia</a></p>
<p><strong>Most common email spam:</strong> <strong> </strong></p>
<ol>
<li><strong>Chain mail</strong> &#8211; Gordon Brown Hoax <strong> </strong></li>
<li><strong>Trojans</strong> &#8211; botnets, bredolab, Pushdo</li>
<li><strong>Phishing</strong> &#8211; Please log into your financial account and confirm</li>
<li><strong>You are a winner</strong> &#8211; congratulations, lotteries</li>
<li><strong>Offers</strong> &#8211; Viagra, educational, OEM software</li>
<li><strong>Personals</strong> &#8211; find true love here</li>
<li><strong>Scam news</strong> &#8211; generally will contain a link to malware</li>
</ol>
<p>With an increase in botnet-related spam (mainly Bredolab,) a sharp rise in educational and pharmaceutical/medical spam, and definitely far more activity in the arena of phishing spam regarding financial accounts &#8211; you really should pay close attention to what lands in your inbox, because Trojans in the form of zipped files do not always end up in your spam folder.</p>
<p>I find it inconceivable, and somewhat disturbing that I collected almost 900 spam emails last week.  This is quite a jump in spam, considering, that during the first week of January spam for all accounts leveled slightly below 300.</p>
<p><span id="more-2297"></span></p>
<p>Over the past three weeks I have seen a sharp rise in <strong>UPS Postal Support</strong> email that always contains an attachment <em>&#8220;invoice&#8221;</em> that is spoofed from some.address@ups.com with signatures such as:<br />
Postal Support RANDOM NAME<br />
UPS Manager, RANDOMNAME</p>
<p>The attachment currently arrives as a ZIP file:  <a href="http://tekblog.teksquisite.com/wp-content/uploads/2010/02/attachment.jpg"><img title="attachment" src="http://tekblog.teksquisite.com/wp-content/uploads/2010/02/attachment.jpg" alt="" width="265" height="26" /></a></p>
<p>My advice to you is to <strong>KEEP IT ZIPPED AND DELETE IT!</strong></p>
<p><strong><br />
</strong></p>
<p style="text-align: center;"><span style="text-decoration: underline;"><strong>Spam Examples</strong></span></p>
<p style="text-align: center;">
<ul>
<li><strong>Chain Mail:</strong> Gordon Brown Virus</li>
</ul>
<p>Chain mail claiming that if you receive a picture of British Prime Minister, Gordon Brown smiling, your computer will become infected with a virus.</p>
<p style="text-align: center;"><a href="http://tekblog.teksquisite.com/wp-content/uploads/2010/02/gordon-brown.png"><img class="size-full wp-image-2504 aligncenter" title="gordon-brown" src="http://tekblog.teksquisite.com/wp-content/uploads/2010/02/gordon-brown.png" alt="" width="553" height="123" /></a></p>
<p style="text-align: left;">You can read more about this hoax over at<a title="GC Sophos Blog" href="http://www.sophos.com/blogs/gc/g/2010/02/05/gordon-browns-smile-infect-computer-virus/" target="_blank"> Graham Cluley&#8217;s Blog</a>.</p>
<p style="text-align: center;">
<p style="text-align: center;"><span style="text-decoration: underline;"><strong><br />
</strong></span></p>
<ul>
<li><strong>Trojans: </strong>Trojan.Downloader, Bredolab, Pushdo, Zeus [botnets]</li>
</ul>
<p><a href="http://tekblog.teksquisite.com/wp-content/uploads/2010/02/email-shot.jpg"><img class="aligncenter size-full wp-image-2301" title="email-shot" src="http://tekblog.teksquisite.com/wp-content/uploads/2010/02/email-shot.jpg" alt="" width="449" height="217" /></a></p>
<p>Once the zip file is extracted, an exe file (disguised as an Excel file) downloads Pushdo (a malacious bredolab downloader.) In an article at <a title="cnet News" href="http://news.cnet.com/8301-27080_3-10445337-245.html" target="_blank">cnet News,</a> Joe Stewart, director of malware research at SecureWorks stated:</p>
<p>&#8220;<em>Pushdo downloads different Trojans onto infected machines and has been used to send spam as part of the Cutwail spambot&#8230;&#8221;It&#8217;s a typical pay-per-install system,&#8221; used to distribute banking Trojans, password stealers, ad clickers, and search hijackers&#8221;</em> <a title="cnet News" href="http://news.cnet.com/8301-27080_3-10445337-245.html" target="_blank"> </a></p>
<p><em>&#8220;For those unfamiliar, Bredolab is a simplified botnet – a loader which simply connects to a remote server to report and receive files to download/execute. Apart from rogue antivirus software (”scareware”), Bredolab’s other favorite download is Pushdo.&#8221; </em> &#8211;Fortinet</p>
<p>Since Pushdo is not written to disk and is memory resident, botnet owners frequently change the code and behaviors of Pushdo, which further makes it difficult to classify variants over time.  What I have posted here today, may not be applicable tomorrow!</p>
<p>For a better understanding of Bredolab see <a title="you scratch my back" href="http://us.trendmicro.com/imperia/md/content/us/trendwatch/researchandanalysis/bredolab_final.pdf" target="_blank">You Scratch My Back</a>&#8230;BREDOLAB’s Sudden Rise in Prominence by David Sancho, Senior Threat Researcher at <a title="Trend Micro" href="http://us.trendmicro.com/us/home/" target="_blank">Trend Micro</a>.</p>
<ul>
<li><strong>Phishing</strong> &#8211; Please log into your account</li>
</ul>
<ol>
<li>This type of spam requests that you verify your account via a spoofed link where your personal details will be captured for the phishers</li>
<li><a title="HSBC Bank" href="http://www.us.hsbc.com/1/2/3/personal/inside/securitysite/alerts" target="_blank">HSBC Bank</a> will never send an email asking you to verify details.</li>
<li>There are all types of variations in these spoofed emails.  If you receive e-mail claiming to be from HSBC, call HSBC at 1-800-975-4722. Follow the instructions regarding fraudulent email <a title="here" href="http://www.us.hsbc.com/1/2/3/personal/inside/securitysite/alerts" target="_blank">here</a>.</li>
</ol>
<p style="text-align: center;"><a href="http://tekblog.teksquisite.com/wp-content/uploads/2010/02/HSBC2.png"><img class="size-full wp-image-2522  aligncenter" title="HSBC" src="http://tekblog.teksquisite.com/wp-content/uploads/2010/02/HSBC2.png" alt="" width="546" height="527" /></a></p>
<p style="text-align: center;">
<p style="text-align: center;">
<ul>
<li><strong>You are a winner</strong> &#8211; congratulations, lotteries</li>
</ul>
<p>Never reply to this type of email because you will end up on a global spammer list.  Delete it.</p>
<p style="text-align: center;"><a href="http://tekblog.teksquisite.com/wp-content/uploads/2010/02/winner.jpg"><img class="aligncenter size-full wp-image-2507" title="winner" src="http://tekblog.teksquisite.com/wp-content/uploads/2010/02/winner.jpg" alt="" width="353" height="514" /></a></p>
<p style="text-align: center;">
<ul>
<li><strong>Offers: </strong>OEM Software (Original Equipment Manufacturer)</li>
</ul>
<p style="text-align: center;"><strong><a href="http://tekblog.teksquisite.com/wp-content/uploads/2010/02/oem-sftware1.jpg"><img class="size-full wp-image-2478 aligncenter" title="oem-sftware" src="http://tekblog.teksquisite.com/wp-content/uploads/2010/02/oem-sftware1.jpg" alt="" width="638" height="271" /></a></strong></p>
<p style="text-align: center;">
<p style="text-align: center;"><strong><br />
</strong></p>
<p>OEM software is NOT FOR RESALE (NFR) and always includes licensing along these lines: <em>&#8220;For distribution with a new personal computer only. This software may not be sold independently.&#8221; OEM software must be sold with hardware. </em></p>
<p>Some spam email often links to ebay where you can purchase OEM software. The seller appears compliant with the hardware requirement by advertising to remove hardware from the original system (or so they claim!)</p>
<p><em>&#8220;In accordance with eBay policy, I offer the HDD that came with the system (it currently has bad sectors and is not usable), which I can ship at the buyer&#8217;s request.&#8221;</em></p>
<p>Many recent OEM emails that I received are claiming to be a company located at 1100 South State Rd 7, Suite 501 in Margate, FL 33068.  Their website is registered to a Russian domain.  Thanks to Twitter folks <a title="ChrisMuncy" href="http://twitter.com/ChrisMuncy" target="_blank">@ChrisMuncy</a>, <a title="dckovar" href="http://twitter.com/dckovar" target="_blank">@dckovar</a> and <a title="Lisa827" href="http://twitter.com/Lisa827" target="_blank">@Lisa827</a> for advice on contacting the tax office in order to find out about the building that the business is located in.  In this particular case, the City of Margate, Florida was unable to find any records for a business registered at Suite 501 at the above address.  They will be sending out a code officer today to inspect the location since they only have four active businesses registered at this building.</p>
<p>Also be sure to stop by <strong>SIIA</strong> (Software &amp; Information Industry Association) and brush up on<br />
<a title="what you need to know" href="http://www.siia.com/index.php?option=com_content&amp;view=article&amp;id=350:software-buying-guides-what-you-need-to-know-about-oem-and-academic-software&amp;catid=162:anti-piracy-articles&amp;Itemid=377" target="_blank">What You Need to Know About OEM and Academic Software</a>.</p>
<p><em><br />
</em></p>
<p style="text-align: center;"><a href="http://tekblog.teksquisite.com/wp-content/uploads/2010/02/OEM-email2.jpg"><img class="size-medium wp-image-2487 aligncenter" title="OEM-email" src="http://tekblog.teksquisite.com/wp-content/uploads/2010/02/OEM-email2-300x79.jpg" alt="" width="420" height="127" /></a></p>
<p style="text-align: left;"><strong>12 steps to less spam:</strong></p>
<ol>
<li>Do not post your email address online in clear text.  If you must post it online be sure that your address is <a title="munged" href="http://www.addressmunger.com/" target="_blank">munged</a> so that the bots will not see it.</li>
<li>Never respond to suspicious emails.</li>
<li>Do not <strong>unsubscribe</strong> to spam email.</li>
<li>Do not use your personal email address for public use. Instead, use a <a title="disposable" href="http://www.spamhelp.org/services/listings/disposablemail/" target="_blank">disposable email address</a> and set it up to forward messages to your personal email account.  If you begin to receive spam in a disposable account &#8211;simply delete the disposable account and sign up for a new one.</li>
<li>Do not open suspicious attachments, links, or images. This could lead to malware downloading on your computer.</li>
<li>If you are using a software email program (and not a web-based one) be sure to disable the preview pane.</li>
<li>Use spam-blocking tools and filters.</li>
<li>If you need to forward email to <span style="text-decoration: underline;">groups of people</span> use a disposable email address in the <strong>TO:</strong> field and add all recipients to the <strong>BCC:</strong> field.  This will shield the email address from others as well as from spam harvesters.</li>
<li>Be sure to have antivirus software installed on your computer, run a full scan every week, and keep it updated!  You should run some form of an anti-malware software each week too, such as <a title="malwarebytes" href="http://malwarebytes.org/" target="_blank">Malwarebytes</a>.</li>
<li>When you sign up for something on the web, be sure to uncheck the box that says <em>&#8220;YES, I want to be contacted by select third parties concerning products I might be interested in.&#8221;<br />
</em></li>
<li>Be sure to take advantage of reputable and free computer scans such as the <a title="Firewall leak" href="http://www.grc.com/lt/leaktest.htm" target="_blank">firewall leak</a> and <a title="shieldsup" href="https://www.grc.com/x/ne.dll?bh0bkyd2" target="_blank">ShieldsUP tests</a> over at Gibson Research Corporation.</li>
<li><a title="Report spammers" href="http://www.ftc.gov/spam/" target="_blank">Report spammers</a>.  Register for free spam reporting service at <a title="spamcop" href="http://www.spamcop.net/anonsignup.shtml" target="_blank">SpamCop</a>.</li>
</ol>
<p style="text-align: center;"><a href="http://tekblog.teksquisite.com/wp-content/uploads/2010/02/spam1.jpg"><img class="size-full wp-image-2557 aligncenter" title="spam" src="http://tekblog.teksquisite.com/wp-content/uploads/2010/02/spam1.jpg" alt="" width="451" height="335" /></a></p>
<p style="text-align: center;">If you plan on using this service often, consider making a donation!</p>
<p style="text-align: center;">
<p><strong>Some helpful Links:</strong></p>
<p><a title="FTC" href="http://www.ftc.gov/spam/" target="_blank">Federal Trade Commision FTC</a></p>
<p>If you are a victim of a financial solicitation contact<br />
the <a title="ICCC" href="http://www.ic3.gov/default.aspx and fill out the ICCC's online complaint form. http://www.ic3.gov/complaint/default.aspx" target="_blank">Internet Crime Complaint Center</a></p>
<p>Medical fraudulent claims (devices or products)<br />
<strong>Email:</strong> <a href="email:webcomplaints@ora.fda.gov">webcomplaints@ora.fda.gov</a></p>
<p>Investment-related email- *<span style="text-decoration: underline;">Copy headers</span> and forward to:<br />
<strong>Email</strong>: <a href="email:enforcement@sec.gov">enforcement@sec.gov</a></p>
<p><a title="copy email headers" href="http://www.consumerfraudreporting.org/email_headers.php" target="_blank">*How to copy email headers</a></p>
<p><strong>Until next time &#8212; stay safe online!</strong></p>
<p style="text-align: center;">
<p style="text-align: left;">
]]></content:encoded>
			<wfw:commentRss>http://tekblog.teksquisite.com/2010/02/11/spam-spam-what-it-do/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The invisible customer gobsmacked &#8212; NOT!</title>
		<link>http://tekblog.teksquisite.com/2010/02/10/bad-cashier-bad-attitude-bad-customer-service/</link>
		<comments>http://tekblog.teksquisite.com/2010/02/10/bad-cashier-bad-attitude-bad-customer-service/#comments</comments>
		<pubDate>Thu, 11 Feb 2010 04:00:17 +0000</pubDate>
		<dc:creator>Teksquisite</dc:creator>
				<category><![CDATA[blog]]></category>
		<category><![CDATA[attitude]]></category>
		<category><![CDATA[business]]></category>
		<category><![CDATA[customer service]]></category>
		<category><![CDATA[experience]]></category>
		<category><![CDATA[retail]]></category>
		<category><![CDATA[service]]></category>
		<category><![CDATA[Small Business]]></category>

		<guid isPermaLink="false">http://tekblog.teksquisite.com/?p=2371</guid>
		<description><![CDATA[
			
				
			
		
Just got back from my favorite grocery store (anonymous) that I have been frequenting for eight years.  The cashier at the speedy check-stand was less than pleasant &#8212; she was downright rude. This is the first time in eight years that I have had a bad experience/negative encounter at this particular store.
I was so [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Ftekblog.teksquisite.com%2F2010%2F02%2F10%2Fbad-cashier-bad-attitude-bad-customer-service%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Ftekblog.teksquisite.com%2F2010%2F02%2F10%2Fbad-cashier-bad-attitude-bad-customer-service%2F&amp;source=teksquisite&amp;style=normal&amp;service=is.gd" height="61" width="50" /><br />
			</a>
		</div>
<p><img class="alignleft size-full wp-image-2376" title="cashier" src="http://tekblog.teksquisite.com/wp-content/uploads/2010/02/cashier1.png" alt="" width="153" height="291" />Just got back from my favorite grocery store (anonymous) that I have been frequenting for eight years.  The cashier at the speedy check-stand was less than pleasant &#8212; she was downright rude. This is the first time in eight years that I have had a bad experience/negative encounter at this particular store.</p>
<p>I was so annoyed with her attitude that I did not even wait for my receipt.  I walked off in a bit of a huff, anxious to subdue the bubbling cauldron of negativity brewing within. Attitude is everything when it comes to customer service skills.   Bad attitudes can spread like a virus. You can&#8217;t teach someone to play nice when they don&#8217;t want to play at all!</p>
<p><strong>Could it be that she is having a bad night? (It doesn&#8217;t matter!)<br />
</strong></p>
<p><strong>Cashier: </strong> No eye contact, no conversation, and actively inaccessible in providing any form of decent customer service experience.</p>
<p><strong>Me: </strong>It is uncomfortable to be at this check-stand. She won&#8217;t even look at me.  She is staring at the cigarette cartons.  She won&#8217;t talk to me!</p>
<p>If she is having a bad night, this is NOT my problem.  I am the customer.  If she is going to be manning the front lines of a business, she needs to make the customer feel, at minimum, the two <strong>&#8220;W&#8217;s.&#8221; </strong></p>
<ol>
<li><strong>Warm &#8211; </strong>friendly and responsive</li>
<li><strong>Welcome &#8211; </strong>Decent greeting\reception</li>
</ol>
<p><strong>Get Proactive!</strong></p>
<p>In the past I have directly confronted bad customer service.  It has never resolved anything and I am not one who likes to hold up a check out line!</p>
<p>While writing this post I decided that I will be informing the grocery store about this perceived negative customer experience. Not because I want to complain about experiencing bad service, but because I am concerned about how this particular cashier may eventually affect their business.  Negativity tends to breed negativity.</p>
<blockquote><p>An old article by Anna Thibodeaux in CRM Weekly summarized it best: <em>“According to a 2006 survey released by a group within the Wharton School of the University of Pennsylvania, a typical business only hears from 4 percent of its dissatisfied customers; the other 96 percent leave quietly. Of that 96 percent, 68 percent never reveal their dissatisfaction because they perceive an attitude of indifference in the owner, manager or employee.</em></p></blockquote>
<p style="text-align: center;">
<p style="text-align: center;"><img class="size-full wp-image-2380 aligncenter" title="badcust1" src="http://tekblog.teksquisite.com/wp-content/uploads/2010/02/badcust1.png" alt="" width="466" height="159" /></p>
<p style="text-align: center;">
<p style="text-align: left;"><strong>How can companies resolve bad customer service?</strong></p>
<ul>
<li>Provide appropriate training on how to provide good customer service</li>
<li>Provide higher pay rates to employees that excel in customer service</li>
<li>Pay attention to customer complaints</li>
<li>Transfer an employee that does not meet good customer service standards (GCSS)<br />
to another position that does not involve direct contact with customers</li>
<li>Teach your employees to <span style="text-decoration: underline;">make a difference Today</span>!</li>
</ul>
<p>I hope that this article was helpful and now I am off to contact the company!</p>
<p><strong>Until next time &#8212; stay safe online <img src='http://tekblog.teksquisite.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </strong></p>
<p style="text-align: center;">
<p style="text-align: center;">
<p style="text-align: left;">
]]></content:encoded>
			<wfw:commentRss>http://tekblog.teksquisite.com/2010/02/10/bad-cashier-bad-attitude-bad-customer-service/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Facebook redesign!  Nobody told us!</title>
		<link>http://tekblog.teksquisite.com/2010/02/04/facebook-redesign-nobody-told-us/</link>
		<comments>http://tekblog.teksquisite.com/2010/02/04/facebook-redesign-nobody-told-us/#comments</comments>
		<pubDate>Fri, 05 Feb 2010 04:27:43 +0000</pubDate>
		<dc:creator>Teksquisite</dc:creator>
				<category><![CDATA[social networking]]></category>
		<category><![CDATA[anniversary]]></category>
		<category><![CDATA[communication]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[redesign]]></category>

		<guid isPermaLink="false">http://tekblog.teksquisite.com/?p=2336</guid>
		<description><![CDATA[
			
				
			
		

Great Facebook communication!  Are you simply too huge, too cool, and too awesome to share GUI changes with our community?
Ermmm, Happy 6th Anniversary!
 
]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Ftekblog.teksquisite.com%2F2010%2F02%2F04%2Ffacebook-redesign-nobody-told-us%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Ftekblog.teksquisite.com%2F2010%2F02%2F04%2Ffacebook-redesign-nobody-told-us%2F&amp;source=teksquisite&amp;style=normal&amp;service=is.gd" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://tekblog.teksquisite.com/wp-content/uploads/2010/02/fb-red4.png"><img class="aligncenter size-full wp-image-2346" title="fb-red" src="http://tekblog.teksquisite.com/wp-content/uploads/2010/02/fb-red4.png" alt="" width="757" height="400" /></a></p>
<p>Great Facebook communication!  Are you simply too huge, too cool, and too awesome to share GUI changes with our community?</p>
<p>Ermmm, Happy 6th Anniversary!</p>
<p><strong> </strong></p>
]]></content:encoded>
			<wfw:commentRss>http://tekblog.teksquisite.com/2010/02/04/facebook-redesign-nobody-told-us/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Register today for the FOSE 2010 experience!</title>
		<link>http://tekblog.teksquisite.com/2010/02/03/register-today-for-the-fose-2010-experience/</link>
		<comments>http://tekblog.teksquisite.com/2010/02/03/register-today-for-the-fose-2010-experience/#comments</comments>
		<pubDate>Wed, 03 Feb 2010 09:57:04 +0000</pubDate>
		<dc:creator>Teksquisite</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[cloud]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[digital forensics]]></category>
		<category><![CDATA[DNSSEC]]></category>
		<category><![CDATA[forensics]]></category>
		<category><![CDATA[FOSE2010]]></category>
		<category><![CDATA[gov]]></category>

		<guid isPermaLink="false">http://tekblog.teksquisite.com/?p=2284</guid>
		<description><![CDATA[
			
				
			
		

You are well aware of the challenges we as a CyberSecurity community face from rapid changes in the technology landscape. FOSE 2010 is the place to discover opportunities and solutions along with changing expectations for government IT professionals.
Register today for the FOSE 2010 experience http://www.fose.com.
You can expect:

3 days of IT resources helping you navigate today’s [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Ftekblog.teksquisite.com%2F2010%2F02%2F03%2Fregister-today-for-the-fose-2010-experience%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Ftekblog.teksquisite.com%2F2010%2F02%2F03%2Fregister-today-for-the-fose-2010-experience%2F&amp;source=teksquisite&amp;style=normal&amp;service=is.gd" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://tekblog.teksquisite.com/wp-content/uploads/2010/02/fose1.jpg"><img class="aligncenter size-full wp-image-2292" title="fose" src="http://tekblog.teksquisite.com/wp-content/uploads/2010/02/fose1.jpg" alt="" width="578" height="158" /></a></p>
<p>You are well aware of the challenges we as a CyberSecurity community face from rapid changes in the technology landscape. <strong>FOSE 2010</strong> is the place to discover opportunities and solutions along with changing expectations for government IT professionals.</p>
<p><strong>Register today for the FOSE 2010 experience <a title="http://www.fose.com" href="http://www.fose.com" target="_blank">http://www.fose.com</a>.</strong></p>
<p><strong>You can expect:</strong></p>
<ul>
<li><strong>3 days of IT resources</strong> helping you navigate today’s shifting tech landscape</li>
<li><strong>2 full conference days</strong> packed with education on emerging technologies, trends, and new improvements to existing solutions</li>
<li> Thousands of products on the <strong>FREE* EXPO </strong>floor allowing you to gain one-on-one insight into the capabilities of our exhibitors through demos, theater presentations and <strong>FREE Educatio</strong>n.</li>
<li>Attend the <strong>Accenture CyberSecurity Pavilion</strong> or <strong>Focus on Digital Forensics</strong>.</li>
</ul>
<p>*<strong>FOSE</strong> is a must-attend free show for government, military, and government contractors.</p>
<p>It’s time to register and reserve your place at<strong> FOSE <a title="http://www.fose.com" href="http://www.fose.com" target="_blank">http://www.fose.com</a></strong></p>
<p style="text-align: center;">
<p style="text-align: center;">
<p style="text-align: center;"><strong>Connect with FOSE</strong><br />
<strong><a title="twitter" href="http://twitter.com/FOSE  " target="_blank">Twitter</a> |  <a title="Facebook" href="http://www.facebook.com/pages/Washington-DC/FOSE/147042779837" target="_blank">Facebook</a> |  <a title="linkedIn" href="http://www.linkedin.com/groups?gid=1786987&amp;trk=myg_ugrp_ovr" target="_blank">LinkedIn</a> |  <a title="GovLoop" href="http://www.govloop.com/group/fose" target="_blank">GovLoop</a></strong></p>
<p style="text-align: center;">
<p style="text-align: center;"><strong><a href="http://tekblog.teksquisite.com/wp-content/uploads/2010/02/fose2.jpg"><img class="aligncenter size-full wp-image-2289" title="fose2" src="http://tekblog.teksquisite.com/wp-content/uploads/2010/02/fose2.jpg" alt="" width="421" height="71" /></a></strong></p>
<p style="text-align: center;"><strong><br />
</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://tekblog.teksquisite.com/2010/02/03/register-today-for-the-fose-2010-experience/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>3 important steps that can take the bite out of cyberharassment</title>
		<link>http://tekblog.teksquisite.com/2010/01/26/3-important-steps-that-can-take-the-bite-out-of-cyberharrassment/</link>
		<comments>http://tekblog.teksquisite.com/2010/01/26/3-important-steps-that-can-take-the-bite-out-of-cyberharrassment/#comments</comments>
		<pubDate>Tue, 26 Jan 2010 15:53:24 +0000</pubDate>
		<dc:creator>Teksquisite</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[cyberharassment]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[cyberstalking]]></category>
		<category><![CDATA[Internet security]]></category>

		<guid isPermaLink="false">http://tekblog.teksquisite.com/?p=2217</guid>
		<description><![CDATA[
			
				
			
		
Recently, While watching the twitter public_timeline (TPT), I managed to get myself tangled up in an uncomfortable situation online.  While on the TPT I came across an alleged hacktivist, became overly curious, and followed up by conducting private research to better understand the intentions behind his or her hacktivism activities.
It wasn&#8217;t long before I began [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Ftekblog.teksquisite.com%2F2010%2F01%2F26%2F3-important-steps-that-can-take-the-bite-out-of-cyberharrassment%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Ftekblog.teksquisite.com%2F2010%2F01%2F26%2F3-important-steps-that-can-take-the-bite-out-of-cyberharrassment%2F&amp;source=teksquisite&amp;style=normal&amp;service=is.gd" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://tekblog.teksquisite.com/wp-content/uploads/2010/01/Shot12.png"><img class="alignleft size-thumbnail wp-image-2271" title="Shot1" src="http://tekblog.teksquisite.com/wp-content/uploads/2010/01/Shot12-150x150.png" alt="" width="150" height="150" /></a>Recently, While watching the twitter public_timeline (TPT), I managed to get myself tangled up in an uncomfortable situation online.  While on the TPT I came across an alleged hacktivist, became overly curious, and followed up by conducting private research to better understand the intentions behind his or her hacktivism activities.</p>
<p>It wasn&#8217;t long before I began to notice discrepancies in the hacktivist&#8217;s focused cyber attacks. While conversing with this particular hacktivist I also drew some curious head shakes from security experts who allegedly had connections with the US government (AC).</p>
<p>In a nutshell, I managed to upset both the hacktivist and the AC&#8217;s! All of this online drama came about because I unintentionally set myself up for such a situation to occur.  Some of you may be wondering why I even bothered to pursue following and questioning such a controversial profile.</p>
<p>For as long as I can remember I&#8217;ve always been inherently curious. I was one of those kids who would find Santa&#8217;s hidden stash  and secretly unwrap everyone&#8217;s Christmas gifts, then re-wrap all of the gifts back to perfection. Perhaps I was checking gift equality or I was just a nosy kid.  Whatever the reason behind such invasive curiosity, this curiosity beast is one that I have to fend off and suppress on a consistent basis!</p>
<p>This type of curiosity could have easily become a Teksquisite reputation downfall. I could have been targeted both by the hacktivist and by government investigations. Though I did receive some direct communications via messaging and phone regarding statements I made about the hacktivist on twitter, I was not aware until much later in the game (by other concerned security<br />
professionals) that this was a situation that I should graciously remove myself from.</p>
<blockquote><p><em>&#8220;Harassment comes in many different forms and is not limited to physical or verbal abuse. Harassment can occur in any media or forum in which individuals interact.&#8221;</em> &#8211;<a title="The Free Library" href="http://www.thefreelibrary.com/Textual+Harassment%3F:+Cyber+Harassment+In+The+Workplace+And+Advice+For...-a0209640032" target="_blank">The Free Library</a></p></blockquote>
<p><strong>3 important steps to extricate yourself from situational cyberharassment</strong></p>
<ol>
<li>NEVER respond to flames.</li>
<li>NEVER confront the individual(s) with evidence or accusations</li>
<li>Remove yourself immediately from all hostile situations</li>
</ol>
<p>The above steps should sever any type of online harassment situation almost immediately.  Although there may be some negative fallout from my particular situation, I anticipate that the steps I have taken above will successfully eliminate the possibility that cyberharassment will continue to exist.</p>
<p>If the above steps do not resolve a cyberharassment situation, you may be looking at the more serious case of <strong>cyberstalking</strong>.</p>
<blockquote><p><em>&#8220;Cyberstalking and cyberharassment are very similar. Most people use them interchangeably, but there is a subtle distinction, typically relating to the perpetrator’s intent and the original motivation for their behavior.&#8221;</em></p>
<p><em>&#8220;While the two situations usually involve many of the same online tactics, cyberstalking is almost always characterized by the stalker relentlessly pursuing his\her victim online and is much more likely to include some form of offline attack, as well. This offline aspect makes it a more serious situation as it can easily lead to dangerous physical contact, if the victim’s location is known.&#8221; </em> &#8211;<a title="Wiredsafety" href="http://www.wiredsafety.org/cyberstalking_harassment/csh0.html" target="_blank">Wiredsafety</a></p></blockquote>
<p>In the past I have voluntarily worked with both <a title="Wiredsafety" href="http://wiredsafety.org" target="_blank">Wiredsafety.org</a> as an <em>Internet Security Speci</em>alist and <a href="http://www.haltabuse.org" target="_blank">HaltAbuse.org </a>as an <em>Internet Security Advocate</em>.  Both organizations offer extensive help to victims of cyberstalking. If you are involved in an online situation that has escalated beyond the status of cyberharassment, be sure to contact one of the organizations listed above for further information on how to protect yourself online.</p>
<p><strong>Until next time &#8211; stay safe online!</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://tekblog.teksquisite.com/2010/01/26/3-important-steps-that-can-take-the-bite-out-of-cyberharrassment/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>If you read it on Facebook, it must be TRUE!</title>
		<link>http://tekblog.teksquisite.com/2010/01/21/if-you-read-it-on-facebook-it-must-be-true/</link>
		<comments>http://tekblog.teksquisite.com/2010/01/21/if-you-read-it-on-facebook-it-must-be-true/#comments</comments>
		<pubDate>Fri, 22 Jan 2010 02:18:20 +0000</pubDate>
		<dc:creator>Teksquisite</dc:creator>
				<category><![CDATA[social networking]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[fake]]></category>
		<category><![CDATA[scam]]></category>
		<category><![CDATA[scammers]]></category>
		<category><![CDATA[social engineering]]></category>

		<guid isPermaLink="false">http://tekblog.teksquisite.com/?p=2168</guid>
		<description><![CDATA[
			
				
			
		
 

Facebook Is Going To Start Charging Money!
This scam first appeared on Facebook during December 2009. Users who joined this group were tricked into clicking a malicious link that took them off-site while secretly dumping malware on their computer.

&#8220;The ongoing thread that Facebook will soon begin charging for their site doesn’t appear to be slowing. [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Ftekblog.teksquisite.com%2F2010%2F01%2F21%2Fif-you-read-it-on-facebook-it-must-be-true%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Ftekblog.teksquisite.com%2F2010%2F01%2F21%2Fif-you-read-it-on-facebook-it-must-be-true%2F&amp;source=teksquisite&amp;style=normal&amp;service=is.gd" height="61" width="50" /><br />
			</a>
		</div>
<p style="text-align: center;"><a href="http://tekblog.teksquisite.com/wp-content/uploads/2010/01/Shot2.png"><img class="aligncenter size-full wp-image-2169" title="Shot2" src="http://tekblog.teksquisite.com/wp-content/uploads/2010/01/Shot2.png" alt="" width="354" height="110" /></a><span style="text-decoration: underline;"><strong> </strong></span></p>
<p style="text-align: center;">
<p style="text-align: center;"><span style="text-decoration: underline;"><strong>Facebook Is Going To Start Charging Money!</strong></span></p>
<p>This scam first appeared on Facebook during December 2009. Users who joined this group were tricked into clicking a malicious link that took them off-site while secretly dumping malware on their computer.</p>
<blockquote>
<p style="padding-left: 30px;"><em>&#8220;The ongoing thread that Facebook will soon begin charging for their site doesn’t appear to be slowing. The other night I was having dinner with a family friend who told me about a scoop he had that Facebook would soon begin charging for the site and proceeded to explain why he would pay. While it’s great that Facebook has provided value to his life and millions of others, the company will not charge users to access the site.&#8221; </em>&#8211;All Facebook</p>
</blockquote>
<p>Researching current 14,99 groups/pages appears to be harmless with no suspicious links found.   You can read more about this group at <a title="All Facebook" href="http://www.allfacebook.com/2010/01/again-facebook-will-not-charge-users-to-access-the-site/" target="_blank">All Facebook</a>.</p>
<p style="text-align: center;">
<p style="text-align: center;"><a href="http://tekblog.teksquisite.com/wp-content/uploads/2010/01/Shot3.png"><img class="aligncenter size-full wp-image-2179" title="UGG" src="http://tekblog.teksquisite.com/wp-content/uploads/2010/01/Shot3.png" alt="" width="537" height="88" /></a></p>
<p style="text-align: center;">
<p style="text-align: center;"><span style="text-decoration: underline;"><strong>Get A Free Pair Of UGGS!</strong></span></p>
<p style="text-align: center;">
<p style="text-align: left;">You have to first verify that you can give out some private information, via taking one of the offered quizzes:</p>
<p style="text-align: center;"><a href="http://tekblog.teksquisite.com/wp-content/uploads/2010/01/Shot1.png"><img class="aligncenter size-full wp-image-2182" title="Shot1" src="http://tekblog.teksquisite.com/wp-content/uploads/2010/01/Shot1.png" alt="" width="594" height="334" /></a></p>
<p style="text-align: center;">
<p style="text-align: left;">Does this <em><a title="IQ" href="http://www.mywot.com/en/scorecard/youmindquizzes.com/comment-4595470#comment-4595470" target="_blank">IQ Challenge</a> </em>seem a little too familiar to you?  In July 2009 <strong>WBZ-TV 4</strong> in Boston reported on the &#8220;I.Q. Test&#8221; scam occurring on Facebook.  Six months later, this scam is still connected to Facebook.  Check out the details at <a title="wbz-tv" href="http://wbztv.com/video/?id=78897@wbz.dayport.com" target="_blank">WBZ-TV video</a>.</p>
<p style="text-align: left;">
<p style="text-align: center;">
<p style="text-align: center;"><strong>Pay Attention To Possible Scams And Scammers!</strong></p>
<p style="text-align: left;">Become a fan of  <strong>*** Project NOSCAM *** </strong>and follow the weekly updated lists of:</p>
<p style="text-align: left;"><a title="scams" href="http://www.facebook.com/pages/-Project-NOSCAM-/224346101463?v=app_6009294086" target="_blank">SCAMS </a></p>
<p style="text-align: left;"><a title="scammers" href="http://www.facebook.com/pages/-Project-NOSCAM-/224346101463?v=app_7146470109" target="_blank">SCAMMERS</a></p>
<p style="text-align: center;">** <a href="http://www.facebook.com/pages/-Project-NOSCAM-/224346101463?v=app_2373072738#/topic.php?uid=224346101463&amp;topic=11961" target="_blank">Notable Facebook Scams to be aware of</a> **</p>
<p style="text-align: left;">If you find a scam or scammer on Facebook, do the site a favor and report it within the Group/Page  <a href="http://tekblog.teksquisite.com/wp-content/uploads/2010/01/Shot4.png"><img class="aligncenter size-full wp-image-2209" title="Shot4" src="http://tekblog.teksquisite.com/wp-content/uploads/2010/01/Shot4.png" alt="" width="191" height="92" /></a>and also report the scam Group/Page to <strong><a href="http://www.facebook.com/topic.php?uid=224346101463&amp;topic=11961#/pages/-Project-NOSCAM-/224346101463?v=wall" target="_blank">Project NOSCAM</a></strong>.</p>
<p style="text-align: center;">
<p style="text-align: center;">
<p style="text-align: center;">
<p style="text-align: left;">
<blockquote>
<p style="text-align: left;">
<p style="text-align: left;"><em>&#8220;If you allow an application or website to connect with your Facebook account, that application or website can access information on Facebook related to you and your friends and generate and publish stories about actions you take on that application or website <span style="text-decoration: underline;">without any additional permission</span>.&#8221;   &#8211;<a href="http://developers.facebook.com/about_platform.php" target="_blank">Facebook</a></em></p>
<p style="text-align: left;">
<p style="text-align: center;"><em><strong>Help take a Byte out of Facebook Scams!</strong></em></p>
<p style="text-align: center;"><em><strong><br />
</strong></em></p>
</blockquote>
]]></content:encoded>
			<wfw:commentRss>http://tekblog.teksquisite.com/2010/01/21/if-you-read-it-on-facebook-it-must-be-true/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>GASP YouTube: Vote-botting, false flagging, false DCMA shenanigans?</title>
		<link>http://tekblog.teksquisite.com/2010/01/05/gaspyoutube-false-flagging-false-dcma-and-vote-botting-shenanigans/</link>
		<comments>http://tekblog.teksquisite.com/2010/01/05/gaspyoutube-false-flagging-false-dcma-and-vote-botting-shenanigans/#comments</comments>
		<pubDate>Wed, 06 Jan 2010 04:26:49 +0000</pubDate>
		<dc:creator>Teksquisite</dc:creator>
				<category><![CDATA[youtube]]></category>
		<category><![CDATA[censorship]]></category>
		<category><![CDATA[DMCA]]></category>

		<guid isPermaLink="false">http://tekblog.teksquisite.com/?p=2062</guid>
		<description><![CDATA[
			
				
			
		
In May of Last year The London Daily News reported that YouTube censored US journalist Alex Jones, best known for investigative reporting on the 9/11 terrorist attacks. At that time the &#8220;Alex Jones Show&#8221; on YouTube had over 1 million views per week, and was also responsible for &#8220;The Obama Deception.&#8221;
“Increasingly YouTube has been scorned [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Ftekblog.teksquisite.com%2F2010%2F01%2F05%2Fgaspyoutube-false-flagging-false-dcma-and-vote-botting-shenanigans%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Ftekblog.teksquisite.com%2F2010%2F01%2F05%2Fgaspyoutube-false-flagging-false-dcma-and-vote-botting-shenanigans%2F&amp;source=teksquisite&amp;style=normal&amp;service=is.gd" height="61" width="50" /><br />
			</a>
		</div>
<p>In May of Last year The London Daily News reported that YouTube censored US journalist Alex Jones, best known for investigative reporting on the 9/11 terrorist attacks. At that time the &#8220;Alex Jones Show&#8221; on YouTube had over 1 million views per week, and was also responsible for &#8220;The Obama Deception.&#8221;</p>
<p><em>“Increasingly YouTube has been scorned for its move away from its foundation of “free speech video” to being seen as part of the establishment it tried to redefine when it was first established.” </em> &#8211;<a title="http://www.infowars.com/you-tube-free-speech-purge-accelerates-infowarrior-channel-banned/" href="http://www.infowars.com/you-tube-free-speech-purge-accelerates-infowarrior-channel-banned/" target="_blank">PrisonPlanet TV </a></p>
<p style="text-align: center;">
<p><strong>Censorship?</strong></p>
<p>YouTube, emulates a meritocracy where highest user ratings and most views will land you on the front page. A <strong>vote-bot</strong> is a piece of software that can be used to systematically downgrade or upgrade vote popularity. Vote-botting can also  be used to deflate vote ratings to such low levels that this forces the video out of search results.</p>
<p>Over the past two years certain YouTube communities such as <strong>Atheist YouTubers</strong> have suffered greatly under the deluge of YouTube vote-bots. Atheist video popularity ratings have been frequently sabotaged by strategically planned and maliciously orchestrated bands of malicious vote-bots. It is not unusual for video popularity to be reduced from a 5-star to a 1-star rating within a few minutes of these attacks.</p>
<blockquote><p><em>&#8220;The bot armies are particularly onerous, automating the process of creating accounts, searching for any video by a particular user, then down-rating them all — resulting in such unlikely scenarios as a few thousand 1-star ratings on a video that’s only been up for a few minutes, thus pushing the video so far down the listings that nobody’s likely to ever see it to begin with.&#8221;</em> &#8211;<a title="http://www.lousycanuck.ca/?p=447" href="http://www.lousycanuck.ca/?p=447" target="_blank">How to cheat at Youtube</a></p></blockquote>
<p>Another method utilized to censor information on YouTube is defined as <strong>false flagging</strong>. This can be an automated process that flags videos as inappropriate when content is actually innocuous. The most vile <span style="text-decoration: underline;">flagging campaigns</span> that I am aware of on YouTube, has been via fundamentalist and religious zealot groups. In their attempt to bully the YouTube fringe groups of Atheists, Wiccan&#8217;s, and Pagens, they have managed to destroy the advocacy of free speech at YouTube.</p>
<p><a href="http://tekblog.teksquisite.com/wp-content/uploads/2010/01/Shot4.gif"><img class="aligncenter size-full wp-image-2068" title="Shot4" src="http://tekblog.teksquisite.com/wp-content/uploads/2010/01/Shot4.gif" alt="" width="284" height="64" /></a></p>
<blockquote><p>In an article titled <em><a title="YouTube Needs Fixin'" href="http://scienceblogs.com/pharyngula/2010/01/youtube_needs_fixin.php" target="_blank">You Tube Needs Fixin,&#8217;</a> </em>Professor PZ Myers, biologist and associate professor at the <a href="http://www.morris.umn.edu/">University of Minnesota, Morris</a> stated:<em> &#8220;One of the big problems with YouTube is that science channels that criticize creationists are often shut down — they are targeted by votebots that lower their ratings, and there are plenty of people who file frivolous notifications of DMCA violations that lead to whole channels being shut down until the case is fought out. This is not good — the system is hair-trigger sensitive to complaints, but does nothing to filter out the noise of unwarranted claims made solely to silence people.&#8221;</em></p></blockquote>
<p>The most powerful tool that fundamentalist and religious zealot groups have used against fringe groups at YouTube is the filing of <strong>False DMCA </strong>(Digital Millennium Copyright Act) claims<strong>. </strong>This forces YouTube to legally remove the video &#8212; <strong>effective immediately.</strong></p>
<p><strong><a href="http://tekblog.teksquisite.com/wp-content/uploads/2010/01/Shot7.gif"><img class="aligncenter size-full wp-image-2067" title="Shot7" src="http://tekblog.teksquisite.com/wp-content/uploads/2010/01/Shot7.gif" alt="" width="560" height="92" /></a></strong></p>
<p>If they are still unable to restrict fringe group information with the three methods I listed above, eventually they often pull a  full monty by filing multiple false DCMA claims.  They know if they file multiple DCMA claims within a short period of time, that the victims channel will be suspended.</p>
<blockquote><p><em>&#8220;There is a fight going on at Youtube, a fight for free speech, rationality and reason.&#8221; &#8211;</em><a onmousedown="yt.analytics.urchinTracker('/Events/VideoWatch/ChannelNameLink');" href="http://www.youtube.com/user/rozeboosje">rozeboosje</a></p>
<p style="text-align: center;"><a title="Censortube.eu" href="http://censortube.eu" target="_blank"><img class="aligncenter size-full wp-image-2141" title="Censorship" src="http://tekblog.teksquisite.com/wp-content/uploads/2010/01/Shot2.gif" alt="" width="351" height="313" /></a></p>
<p style="text-align: center;">
<p style="text-align: center;">Please sign the Google/YouTube <a title="http://www.thepetitionsite.com/1/StopYouTubeCensorship" href="http://www.thepetitionsite.com/1/StopYouTubeCensorship" target="_blank">Censorship Reform Petition</a></p>
<p style="text-align: center;">
</blockquote>
<p style="text-align: left;"><strong>Until Next time &#8211; don&#8217;t allow yourself to be bullied and stay safe online!</strong></p>
<p style="text-align: left;">
]]></content:encoded>
			<wfw:commentRss>http://tekblog.teksquisite.com/2010/01/05/gaspyoutube-false-flagging-false-dcma-and-vote-botting-shenanigans/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>Tech highlights from December 2009</title>
		<link>http://tekblog.teksquisite.com/2009/12/27/tech-highlights-from-december-2009/</link>
		<comments>http://tekblog.teksquisite.com/2009/12/27/tech-highlights-from-december-2009/#comments</comments>
		<pubDate>Mon, 28 Dec 2009 00:44:04 +0000</pubDate>
		<dc:creator>Teksquisite</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[compromised]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[DNS]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacked]]></category>
		<category><![CDATA[koobface]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[web]]></category>
		<category><![CDATA[XSS]]></category>
		<category><![CDATA[Zeus]]></category>

		<guid isPermaLink="false">http://tekblog.teksquisite.com/?p=2040</guid>
		<description><![CDATA[
			
				
			
		

Twitter hack claimed by Iranian group
The hack that occurred on Twitter itself is significant beyond any wider political motives. It shows that what is the world’s fastest growing communication network is rather insecure.
Being able to change the DNS records of a website means that rather than simply redirecting users to a vanity page identifying the [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Ftekblog.teksquisite.com%2F2009%2F12%2F27%2Ftech-highlights-from-december-2009%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Ftekblog.teksquisite.com%2F2009%2F12%2F27%2Ftech-highlights-from-december-2009%2F&amp;source=teksquisite&amp;style=normal&amp;service=is.gd" height="61" width="50" /><br />
			</a>
		</div>
<p style="text-align: center;"><a href="http://tekblog.teksquisite.com/wp-content/uploads/2009/12/hacked.jpg"><img class="aligncenter size-full wp-image-2042" title="hacked" src="http://tekblog.teksquisite.com/wp-content/uploads/2009/12/hacked.jpg" alt="" width="365" height="174" /></a></p>
<p style="text-align: center;"><strong>Twitter hack claimed by Iranian group</strong></p>
<p style="text-align: left;">The hack that occurred on Twitter itself is significant beyond any wider political motives. It shows that what is the world’s fastest growing communication network is rather insecure.</p>
<p>Being able to change the DNS records of a website means that rather than simply redirecting users to a vanity page identifying the hack, hackers could actually have redirected people to a site that looked rather like Twitter itself.</p>
<p>In a similar way to phishing attacks that mimic online bank accounts, the hackers could have encouraged users to login, thus revealing usernames and passwords.</p>
<p>Expert Rik Ferguson of Trend Micro told me: “One has to wonder how quickly the attack would be noted if the dummy site was an exact replica of the victim and was simply there to harvest credentials and redirect the user then into the real site.  The hack that occurred on Twitter itself is significant beyond any wider political motives. It shows that what is the world’s fastest growing communication network is rather insecure.   &#8211;<a title="Channel 4 news" href="http://www.channel4.com/news/articles/uk/twitter+hack+claimed+by+iranian+group/3469162" target="_blank">channel4news</a></p>
<p><strong>Twitter: </strong> <a title="http://twitter.com/channel4news" href="http://twitter.com/channel4news" target="_blank">@channel4news</a> |  <a title="http://twitter.com/rik_ferguson" href="http://twitter.com/rik_ferguson" target="_blank">@rik_ferguson</a></p>
<p style="text-align: center;">
<p style="text-align: center;">
<p style="text-align: center;"><strong>Web-Based Worms: How XSS Is Paving the Way for Future Malware</strong></p>
<p>I first became aware of cross-site scripting (XSS) nearly a decade ago. At the time, despite being an all too prevalent bug in Web applications, the risk posed by the flaw was of limited value. It was the go-to vulnerability for any pen tester that was having trouble digging up a meaningful vulnerability to add to his audit report.</p>
<p>That has all changed now. Today, XSS represents a meaningful threat &#8212; a threat that is not only leveraged by attackers to harvest authentication credentials, but also is enabling a new generation of malware in the form of Web-based worms.</p>
<p>Depending upon whom you listen to, the statistics may be different, but virtually all agree that XSS remains the most prevalent Web application vulnerability that we face today.  &#8211;<a title="http://www.technewsworld.com/story/Web-Based-Worms-How-XSS-Is-Paving-the-Way-for-Future-Malware-68946.html" href="http://www.technewsworld.com/story/Web-Based-Worms-How-XSS-Is-Paving-the-Way-for-Future-Malware-68946.html" target="_blank">TechNewsWorld </a></p>
<p><a title="@technewsworld" href="http://twitter.com/technewsworld" target="_blank">@technewsworld</a> on <strong>Twitter</strong></p>
<p style="text-align: center;">
<p style="text-align: center;"><strong>Cisco gives Zeus, Koobface and Conficker awards</strong></p>
<p style="text-align: left;">Zeus is the most audacious criminal operation of the year and Koobface the most notable criminal innovation, according to Cisco’s Annual 2009 Security Report. On a positive note, the cybercrime sign of hope award goes to the Conficker Working Group.</p>
<p>Cisco Systems Inc. presented its first-ever Cybercrime Showcase awards as part of its 2009 Annual Security Report, released Tuesday.</p>
<p><strong>Zeus: the most audacious criminal operation</strong> &#8211; Designed for information stealing and specializing in online banking fraud, Zeus is a shrink-wrapped piece of malware that any criminal is able to buy, explained Henry Stern, senior security researcher at Cisco. Some vendors are selling it as service for about $700 a month, he said.</p>
<p><strong>Koobface: the most notable criminal innovation</strong> &#8211; Koobface is a piece of malware that takes over a user’s social networking account, explained Stern. “As soon as you get infected, it will send messages to all of your friends and it will try to lure them into becoming infected as well,” he said. &#8211;<a title="http://www.itworldcanada.com/news/cisco-gives-zeus-koobface-and-conficker-working-group-awards/139547" href="http://www.itworldcanada.com/news/cisco-gives-zeus-koobface-and-conficker-working-group-awards/139547" target="_blank">ITWorldCanada</a></p>
<p><a title="@technewsworld" href="http://twitter.com/ITWorldCanada" target="_blank">@itworldca</a> on <strong>Twitter</strong></p>
<p style="text-align: center;">
<p style="text-align: center;"><strong>New Facebook Privacy Settings Under Fire</strong></p>
<p style="text-align: center;">
<p style="text-align: left;">Facebook is making major changes to its privacy settings, giving you the opportunity to share your personal information with &#8220;everyone&#8221; on the Internet. But is that wise?</p>
<p>Facebook&#8217;s huge user base is signing onto their favorite social network today, and viewing an important message.</p>
<p>They&#8217;re being encouraged to review their privacy settings, as Facebook effectively encourages its 350 million users to share more information with everybody on the Internet.</p>
<p>The worry is, of course, that Facebook&#8217;s recommendations may be in the best interests of Facebook &#8212; but they may not necessarily be in the best interests of all of its users.     &#8211;<a title="http://www.darkreading.com/blog/archives/2009/12/new_facebook_pr.html" href="http://www.darkreading.com/blog/archives/2009/12/new_facebook_pr.html" target="_blank">DarkReading </a></p>
<p><strong>Twitter:</strong> <a title="@DarkReading" href="http://twitter.com/DarkReading" target="_blank">@DarkReading</a> |  <a title="@Gcluley" href="http://twitter.com/@Gcluley" target="_blank">@Gcluley</a></p>
<p><strong>Until next time — Stay safe Online!</strong></p>
<p><strong><br />
</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://tekblog.teksquisite.com/2009/12/27/tech-highlights-from-december-2009/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Greetings from the Tekblog!</title>
		<link>http://tekblog.teksquisite.com/2009/12/24/greetings-from-the-tekblog/</link>
		<comments>http://tekblog.teksquisite.com/2009/12/24/greetings-from-the-tekblog/#comments</comments>
		<pubDate>Thu, 24 Dec 2009 22:37:23 +0000</pubDate>
		<dc:creator>Teksquisite</dc:creator>
				<category><![CDATA[blog]]></category>
		<category><![CDATA[greetings]]></category>
		<category><![CDATA[happy holidays]]></category>

		<guid isPermaLink="false">http://tekblog.teksquisite.com/?p=2036</guid>
		<description><![CDATA[
			
				
			
		


]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Ftekblog.teksquisite.com%2F2009%2F12%2F24%2Fgreetings-from-the-tekblog%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Ftekblog.teksquisite.com%2F2009%2F12%2F24%2Fgreetings-from-the-tekblog%2F&amp;source=teksquisite&amp;style=normal&amp;service=is.gd" height="61" width="50" /><br />
			</a>
		</div>
<p style="text-align: center;"><a href="http://tekblog.teksquisite.com/wp-content/uploads/2009/12/happy-holidays.png"><img class="aligncenter size-full wp-image-2037" title="happy-holidays" src="http://tekblog.teksquisite.com/wp-content/uploads/2009/12/happy-holidays.png" alt="" width="408" height="429" /></a></p>
<p style="text-align: center;">
]]></content:encoded>
			<wfw:commentRss>http://tekblog.teksquisite.com/2009/12/24/greetings-from-the-tekblog/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Tweeterfast, Tweeterfollow, Twtkingz &#8212; The never-ending Twitter scam&#8230;</title>
		<link>http://tekblog.teksquisite.com/2009/12/15/tweeterfast-tweeterfollow-twtkingz-the-never-ending-twitter-scam/</link>
		<comments>http://tekblog.teksquisite.com/2009/12/15/tweeterfast-tweeterfollow-twtkingz-the-never-ending-twitter-scam/#comments</comments>
		<pubDate>Tue, 15 Dec 2009 23:32:33 +0000</pubDate>
		<dc:creator>Teksquisite</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[identity theft]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[scam]]></category>
		<category><![CDATA[tweeterfollow]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://tekblog.teksquisite.com/?p=1915</guid>
		<description><![CDATA[
			
				
			
		
I&#8217;ve been following the Tweeterfollow musical domain saga since late September 2009.  The theme never changes.  I&#8217;ve also written about their scam/phishing/twitter account hijackings here.
Yesterday the Tweeterfollow (AKA: TF) domain push on Twitter was via Twtxtreme.info  (currently disabled) using short url services tinyURL and retwt.me.  Today it looks like TF is promoting twtkingz.info via [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Ftekblog.teksquisite.com%2F2009%2F12%2F15%2Ftweeterfast-tweeterfollow-twtkingz-the-never-ending-twitter-scam%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Ftekblog.teksquisite.com%2F2009%2F12%2F15%2Ftweeterfast-tweeterfollow-twtkingz-the-never-ending-twitter-scam%2F&amp;source=teksquisite&amp;style=normal&amp;service=is.gd" height="61" width="50" /><br />
			</a>
		</div>
<p>I&#8217;ve been following the <strong>Tweeterfollow </strong>musical domain saga since late September 2009.  The theme never changes.  I&#8217;ve also written about their scam/phishing/twitter account hijackings<a title="tweeterfollow" href="http://tekblog.teksquisite.com/2009/09/28/avoid-tweeterfast-this-site-will-give-you-more-than-100-followers/" target="_blank"> here</a>.</p>
<p>Yesterday the Tweeterfollow (AKA: <strong>TF</strong>) domain push on Twitter was via <span style="color: #008000; font-family: Arial,Tahoma,Helvetica,Verdana,sans-serif; font-size: 14px; white-space: pre;"><strong>Twtxtreme.info</strong> </span> (currently disabled) using short url services <em>tinyURL</em> and <em>retwt.me</em>.  Today it looks like <strong>TF</strong> is promoting <span style="color: #008000;"><strong>twtkingz</strong>.<strong>info </strong></span>via <em>retwt.me</em> and <em>kiwi.url</em>.  TF consistently uses <strong>IP: 124.217.246.188</strong> but because <strong>TF</strong> switches domains frequently, they have not been blacklisted.</p>
<p><strong>The web login page is always the same:</strong></p>
<p><img class="aligncenter size-full wp-image-1943" title="gui" src="http://tekblog.teksquisite.com/wp-content/uploads/2009/12/gui1.gif" alt="gui" width="458" height="468" /></p>
<p><strong>Description: </strong>A place to add more followers for your twitter page. This is a twitter adder site</p>
<p><strong>Keywords</strong>: get more twitter followers, tweet, twitter network,twitter train, get more followers on twitter, twitter, tweeter, tweeteradder, tweeterfollow, deadlyx, rawhood, hoodzone, followers, train, vip, tweet</p>
<p><span id="more-1915"></span></p>
<p><strong>Logged in to the TF Web GUI</strong></p>
<p>Once you are logged in to their website you will automatically follow all <strong>VIP</strong> members. Then you click  on Twitter profile random images [graphics from a3.twimg.com] to follow <strong>regular users </strong><em>[SIC]</em>.</p>
<p><img class="aligncenter size-full wp-image-1945" title="follow-users" src="http://tekblog.teksquisite.com/wp-content/uploads/2009/12/follow-users2.gif" alt="follow-users" width="485" height="292" /></p>
<p>Once you have clicked on all 20 default regular users profiles, the pop-up below appears:</p>
<p><img class="aligncenter size-full wp-image-1961" title="train" src="http://tekblog.teksquisite.com/wp-content/uploads/2009/12/train.gif" alt="train" width="464" height="142" /></p>
<p>Click on the <strong>OK button </strong>and 20 new profiles will reappear.  You can click all day long and into the night and you will still get the congratulatory pop-up each time you click the 20th profile.</p>
<p>You are also encouraged to purchase a<strong> VIP membership</strong> using PayPal or a credit card. The account that TF is currently using at PayPal is registered to <strong>ryann.johnson2009@gmail.com.</strong></p>
<p><img class="aligncenter size-full wp-image-1977" title="no-refunds" src="http://tekblog.teksquisite.com/wp-content/uploads/2009/12/no-refunds1.gif" alt="no-refunds" width="446" height="311" /></p>
<p><strong>Ability to view protected tweets</strong></p>
<p>Using <a title="http://isfollow.com/" href="http://isfollow.com/" target="_blank">http://isfollow.com/</a> I wanted to see if the locked accounts that I randomly followed through the <strong>TF API</strong> were following me.  The accounts listed below were not following me but I was able to view their PROTECTED TWEETS!</p>
<p>afrheyy<br />
aliamutia<br />
ibaddbxtch<br />
IamHoodBarbie<br />
ohannaweb</p>
<p><img class="aligncenter size-full wp-image-1985" title="hoodbarbie" src="http://tekblog.teksquisite.com/wp-content/uploads/2009/12/hoodbarbie1.gif" alt="hoodbarbie" width="754" height="308" /></p>
<p>Since the above account is not following my test account I should not have been able to view <a title="IamHoodBarbie" href="http://www.twitter.com/IamHoodBarbie" target="_blank">IamHoodBarbies</a> protected twitter stream. Obviously these Twitter profiles are all compromised accounts. A simple change of password is probably not the band-aid that should be used.</p>
<p>The Twitter filter managed to nab the <strong>&#8220;100 followers&#8221;</strong> string and filtered these tweets from the test account Twitter stream.  The test account is also not currently accruing a steady stream of profiles from Twtkingz[TOX]info API like it was yesterday.  During the past six hours the test account has only followed one protected account via the TF API.  The test account is still able to view protected tweets of accounts that are not following the test account.</p>
<p><img class="aligncenter size-full wp-image-1986" title="Shot9" src="http://tekblog.teksquisite.com/wp-content/uploads/2009/12/Shot92.gif" alt="Shot9" width="499" height="244" /></p>
<p><!--more--></p>
<p><strong>Who is behind all this?</strong></p>
<p>With all the emphasis on botnets, security breaches, and malware; In comparison, Tweeterfollow appears harmless.  Is it?</p>
<p><img class="aligncenter size-full wp-image-1997" title="deadlyisgreat" src="http://tekblog.teksquisite.com/wp-content/uploads/2009/12/deadlyisgreat.gif" alt="deadlyisgreat" width="655" height="211" /></p>
<p><img class="aligncenter size-full wp-image-1998" title="otherdomains" src="http://tekblog.teksquisite.com/wp-content/uploads/2009/12/otherdomains.gif" alt="otherdomains" width="496" height="116" /></p>
<p>Domain ID:D30737265-LRMS<br />
Domain Name: TWTKINGZ.INFO<br />
Created On:10-Dec-2009 15:10:50 UTC</p>
<p>Last Updated On:10-Dec-2009 15:10:59 UT</p>
<p><strong>There is something big going down on Twitter</strong></p>
<p><img class="aligncenter size-full wp-image-2013" title="logintoanysite" src="http://tekblog.teksquisite.com/wp-content/uploads/2009/12/logintoanysite1.gif" alt="logintoanysite" width="587" height="585" /></p>
<p>Any website hosted at <strong>Piradius.net in Kuala Lumpur, Malaysia</strong> should immediately raise  a red flag.</p>
<p style="text-align: center;">
<p><strong>Update:  12-15-09  8:13 pm EDT</strong></p>
<p style="text-align: left;"><strong><img class="aligncenter size-full wp-image-2017" title="using-IP" src="http://tekblog.teksquisite.com/wp-content/uploads/2009/12/using-IP1.gif" alt="using-IP" width="463" height="489" /><br />
</strong></p>
<p><strong>Update:  12-16-09 </strong></p>
<p><strong><img class="aligncenter size-full wp-image-2022" title="shot-1-tf" src="http://tekblog.teksquisite.com/wp-content/uploads/2009/12/shot-1-tf.gif" alt="shot-1-tf" width="445" height="79" /><img class="aligncenter size-full wp-image-2023" title="Shot2-tf" src="http://tekblog.teksquisite.com/wp-content/uploads/2009/12/Shot2-tf.gif" alt="Shot2-tf" width="451" height="78" /></strong><strong>Update:  12-17-09 </strong></p>
<p><strong><img class="aligncenter size-full wp-image-2024" title="tweeterfollow-12-17-09" src="http://tekblog.teksquisite.com/wp-content/uploads/2009/12/tweeterfollow-12-17-09.gif" alt="tweeterfollow-12-17-09" width="275" height="205" /></strong></p>
<p><strong>Update:  12-22-09 </strong></p>
<p><strong><a href="http://tekblog.teksquisite.com/wp-content/uploads/2009/12/ak.gif"><img class="aligncenter size-full wp-image-2028" title="ak" src="http://tekblog.teksquisite.com/wp-content/uploads/2009/12/ak.gif" alt="" width="567" height="71" /></a></strong></p>
<p><strong><a href="http://tekblog.teksquisite.com/wp-content/uploads/2009/12/scam.gif"><img class="aligncenter size-full wp-image-2029" title="scam" src="http://tekblog.teksquisite.com/wp-content/uploads/2009/12/scam.gif" alt="" width="428" height="316" /></a></strong></p>
<p><strong><strong>Test account data:</strong></strong></p>
<p><strong><span style="text-decoration: underline;">December 18:</span></strong><br />
5 tweets Total</p>
<p><span style="text-decoration: underline;">Timing:</span><br />
2 tweets @8:08  pm from API<br />
1 tweet  @9:54  pm from API<br />
1 tweet  @9:55  pm from API<br />
1 tweet  @10:25 pm from API</p>
<p><span style="text-decoration: underline;">URL Breakdown:</span><br />
3 tweets to twtfollow[TOX] info via ohurl.com<br />
1 tweet to twtfollow[TOX] info via retwt.me<br />
1 tweet = &#8220;This site just gave me 100 followers using&#8221; no URL</p>
<p><strong><span style="text-decoration: underline;">December 19:</span></strong><br />
9 tweets Total</p>
<p><span style="text-decoration: underline;">Timing:</span><br />
1 tweet   @6:09  am from API<br />
1 tweet   @8:33  am from API<br />
1 tweet   @2:10  pm from API<br />
1 tweet   @4:34  pm from API<br />
4 tweets  @7:09  pm from API<br />
1 tweet   @10:10 pm from API</p>
<p><span style="text-decoration: underline;">URL Breakdown:</span><br />
1 tweet to youtube.com [generic]<br />
1 tweet to twtspeedy[TOX] info [via retwt.me]<br />
2 tweets to twtfollow[TOX] info [via Safe.mn = flagged as a "Dangerous website: Phishing/Malicious Content"]<br />
2 tweets to twtspeedy[TOX] info [via TinyUrl]<br />
1 tweet to twtfollow[TOX] info [kiwiurl.com]<br />
1 tweet to twtfollow[TOX] info [via shorten.ws]<br />
1 tweet to twtfollow[TOX] info [via snipr.com]</p>
<p><strong>December 20:</strong><br />
15 tweets Total</p>
<p><strong><span style="text-decoration: underline;">Timing:</span></strong><br />
1 tweet   @12:34 am from API<br />
1 tweet   @1:10  am from API<br />
1 tweet   @6:11  am from API<br />
1 tweet   @7:12  am from API<br />
1 tweet   @8:34  am from API<br />
2 tweets  @1:31  pm from API<br />
2 tweets  @1:32  pm from API<br />
1 tweet   @1:33  pm from API<br />
1 tweet   @2:11  pm from API<br />
1 tweet   @6:36  pm from API<br />
1 tweet   @7:29  pm from API<br />
1 tweet   @7:33  pm from API<br />
1 tweet   @10:12 pm from API</p>
<p><span style="text-decoration: underline;"><strong>URL Breakdown</strong></span> is getting spammy, so for the sake of brevity &#8211; here goes:<br />
The shorl you requested has been disabled due to abuse. We&#8217;re sorry for the inconvenience.<br />
lu.mu disabled<br />
kiwiurl.com disabled<br />
nvg8.it disabled<br />
twtfollows {TOX] Info still online<br />
twtlimit {TOX] Inf still online<br />
retwt.me = .twtspeedy[TOX] info</p>
<p><strong>December 21:</strong><br />
26 tweets Total</p>
<p>Currently pushing the following Toxic URLs:</p>
<p>twtfollows[TOX] info<br />
twtlimit[TOX] info<br />
twtspeedy[TOX] info</p>
<p><a href="http://tekblog.teksquisite.com/wp-content/uploads/2009/12/hacked-tweeterfollow.gif"><img class="aligncenter size-full wp-image-2033" title="hacked-tweeterfollow" src="http://tekblog.teksquisite.com/wp-content/uploads/2009/12/hacked-tweeterfollow.gif" alt="" width="547" height="805" /></a></p>
<p><strong>Stay Safe Online!</strong></p>
<p><strong><br />
</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://tekblog.teksquisite.com/2009/12/15/tweeterfast-tweeterfollow-twtkingz-the-never-ending-twitter-scam/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>FacebookAgent is a Backdoor Bot &amp; Trojan Dropper</title>
		<link>http://tekblog.teksquisite.com/2009/12/03/facebookagent-is-a-backdoor-bot-trojan-dropper/</link>
		<comments>http://tekblog.teksquisite.com/2009/12/03/facebookagent-is-a-backdoor-bot-trojan-dropper/#comments</comments>
		<pubDate>Fri, 04 Dec 2009 02:15:59 +0000</pubDate>
		<dc:creator>Teksquisite</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[backdoor.bot]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[botnets]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[facebookagent]]></category>
		<category><![CDATA[green card]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[scam]]></category>
		<category><![CDATA[trojan]]></category>

		<guid isPermaLink="false">http://www.teksquisite.com/blog/?p=1841</guid>
		<description><![CDATA[
			
				
			
		
There has been chattering the past few days about unknown rogue software available for download on the Internet that lets you view private Facebook profiles.  I can assure you that this new software called FacebookAgent is old news wagging a new wrapper.  This is not just another scam!  This rogue application also [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Ftekblog.teksquisite.com%2F2009%2F12%2F03%2Ffacebookagent-is-a-backdoor-bot-trojan-dropper%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Ftekblog.teksquisite.com%2F2009%2F12%2F03%2Ffacebookagent-is-a-backdoor-bot-trojan-dropper%2F&amp;source=teksquisite&amp;style=normal&amp;service=is.gd" height="61" width="50" /><br />
			</a>
		</div>
<p>There has been chattering the past few days about unknown rogue software available for download on the Internet that lets you view private Facebook profiles.  I can assure you that this new software called <strong>FacebookAgent</strong> is old news wagging a new wrapper.  This is not just another scam!  This rogue application also has  a back door along with Trojans droppers put together by cyber-criminals to elicit financial information via social engineering techniques. Prior to examining FacebookAgent on a VM earlier today I ran Malwarebytes and had a clean scan with no infected files.  After installation of Facebook Agent and testing in a VM I ran Malwarebytes again and had 159 infected files!   (the results will be posted at the end of this article.) <strong>Domain:</strong> www.facebookagent[DOT]com  <strong>Current IP:</strong> 74.208.137.211 131 1&amp;1 Internet Inc<strong> PA</strong></p>
<p style="text-align: center;"><strong><img class="aligncenter size-full wp-image-1855" title="Shot6" src="http://tekblog.teksquisite.com/wp-content/uploads/2009/12/Shot6.gif" alt="Shot6" width="519" height="419" /> </strong></p>
<p style="text-align: left;"><span id="more-1841"></span>Facebookagent.com website provides this Disclamer:</p>
<p style="text-align: left;"><em>&#8220;Facebook Agent is an automated help manual that guides you through the process of gaining a legal view of the desired profile. This process is completely legal and is achieved through the other party’s aproval and acknowledgement. This software and/or methods should not be used in any other case that is not mentioned above. All facebook trademarks are copyrighted to facebook.com. All actions taken through and in this application are on full responsibility of the user. Facebook Agent is in no condition responsible of any harm, damage or violations done while using this application. If at any stage of the process any party will find violation of law against them, the process should immidiately be terminated and reported to the administration team of the application. By clicking the Start button you agree to take full responsibility of the actions done by this application. All rights are copyrighted to facebook Agent 2009 &#8211; 2010. All trademarks found in this application belong to facebook Agent apart from facebook trademarks which are copyrighted to facebook.com. By clicking on the Start button you accept this terms and conditions.&#8221;</em></p>
<p style="text-align: left;">Most of the links at the <strong>FacebookAgent </strong>website result in saving or downloading <strong>setup.msi</strong>.  The msi installer loads Facebook Agent.exe and a database file in the Program Files directory.  The installer also loads Perflib_Perfdata640.dat into the local user profile temp directory and runs the database file under svchost. </p>
<p style="text-align: center;"><img class="size-full wp-image-1843 aligncenter" title="programfiles" src="http://www.teksquisite.com/blog/wp-content/uploads/2009/12/programfiles.jpg" alt="programfiles" width="379" height="53" /></p>
<p style="text-align: center;"><img class="size-full wp-image-1844 aligncenter" title="files" src="http://www.teksquisite.com/blog/wp-content/uploads/2009/12/files.jpg" alt="files" width="307" height="144" /></p>
<p style="text-align: left;">When you first run <strong>Facebook Agent </strong>there is no exit from the program.  Bad code and even worse downloads and toxic URLs await you. Since I did not choose to install the <strong>IWON toolbar</strong> featuring the <strong>MyWebSearch</strong> default search provider I had to participate in the Green Card Scam that is listed below. </p>
<p style="text-align: center;"><img class="aligncenter size-full wp-image-1852" title="step-1-free-prize" src="http://www.teksquisite.com/blog/wp-content/uploads/2009/12/step-1-free-prize.jpg" alt="step-1-free-prize" width="668" height="399" /></p>
<p style="text-align: left;"><span style="font-size: x-small;"><span style="font-size: small;">According to the flimsy interface above you have to click to claim what you have won!  Your prize is located at: </span></span>hXXp://html.usagc[DOT]org/step1landing_eng[DOT]html?afk=ranygnewcplcmp0309eng.  Then you have to fill out a form that includes your full name, email address, country of birth, marital status, and telephone number. You also have to answer this dropdown menu question:</p>
<p style="text-align: center;"><img class="aligncenter size-full wp-image-1855" title="highschool" src="http://www.teksquisite.com/blog/wp-content/uploads/2009/12/highschool.jpg" alt="highschool" width="261" height="49" /></p>
<p style="text-align: left;">After I filled out the online form with false information, I received this response:</p>
<p style="text-align: center;"><img class="aligncenter size-full wp-image-1856" title="sue-dogears" src="http://www.teksquisite.com/blog/wp-content/uploads/2009/12/sue-dogears.jpg" alt="sue-dogears" width="444" height="64"/></p>
<p style="text-align: left;">Canada, Mexico, and the United States are ineligible.  On the same page I was also given the option to select another country if I were a native of a qualifying country or if my parents were born in a qualifying country.  I opted for Australia and was quickly promoted to step 2 in the process!</p>
<p style="text-align: center;"><img class="aligncenter size-full wp-image-1858" title="prize" src="http://www.teksquisite.com/blog/wp-content/uploads/2009/12/prize.jpg" alt="prize" width="526" height="385" /><img class="aligncenter size-full wp-image-1859" title="prize2" src="http://www.teksquisite.com/blog/wp-content/uploads/2009/12/prize2.jpg" alt="prize2" width="498" height="370" /></p>
<p style="text-align: left;"> I had a good smirk over the warning &#8220;using a stolen or fraud credit card number will automatically disqualify you from participating forever!!  USAGC will immediately cancel your application and pursue legal remedies.&#8221;</p>
<p style="text-align: left;"><strong>USAGC is a scam! </strong>Don&#8217;t fall victim to <strong>this Green Card  lottery scam!</strong> The <a title="green card" href="http://travel.state.gov/visa/immigrants/types/types_1322.html" target="_blank">DV-2011 Diversity Visa Lottery</a>( run by The U.S. Department of State)  online entry registration period ended on <strong>November 30, 2009</strong></p>
<p style="text-align: left;">I was soon bored with the Green card lottery scam so proceeded to install the <strong>IWON Toolbar</strong> and failed.   <img class="aligncenter size-full wp-image-1861" title="iwon" src="http://www.teksquisite.com/blog/wp-content/uploads/2009/12/iwon.jpg" alt="iwon" width="583" height="307" /></p>
<p style="text-align: left;">After finishing the installation of IWON, I had to go to iwon.com to register for a free account.  Overall, you can only get to step 1 in Facebook Agent because you can&#8217;t get to step 2 without filling out credit card information.</p>
<p style="text-align: left;">Finally I ran Malwarebytes again to see what nasties Facebook Agent had installed.</p>
<div>Memory Processes Infected: 2</div>
<div>Memory Modules Infected: 1</div>
<div>
<div>Registry Keys Infected: 142</div>
<div>Registry Values Infected: 9</div>
<div>Registry Data Items Infected: 0</div>
<div>Folders Infected: 20</div>
<div>Files Infected: 86</div>
</div>
<div>
<div>Memory Processes Infected:</div>
<div>C:\Documents and Settings\test\Application Data\Microsoft\Network\svchost.exe (Trojan.Dropper) -&gt; Unloaded process successfully.</div>
<div>C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE (Adware.MyWebSearch) -&gt; Unloaded process successfully.</div>
<div>Memory Modules Infected:</div>
<div>C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL (Adware.MyWebSearch) -&gt; Delete on reboot.</div>
</div>
<div>Files Infected:</div>
<div>C:\Documents and Settings\test\Application Data\Microsoft\Network\wuauclt.exe (Backdoor.Bot) -&gt; Delete on reboot.</div>
<div>
<div>Registry Values Infected:</div>
<div>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\microsoft network service (Trojan.Dropper) -&gt; Delete on reboot.</div>
</div>
<div><strong>You can view the full Malwarebytes log <a title="here" href="http://docs.google.com/View?id=dch6xcnj_359jsthc8h" target="_blank">here</a>.</strong></div>
<div><strong> </strong></div>
<div>I did not have much time to pursue this today but have high hopes that other security experts will jump in and take a look at this backdoor!</div>
<div><strong>Until next time &#8212; Stay safe online!</strong></div>
<div><strong> </strong></div>
]]></content:encoded>
			<wfw:commentRss>http://tekblog.teksquisite.com/2009/12/03/facebookagent-is-a-backdoor-bot-trojan-dropper/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Tech highlights from November 2009</title>
		<link>http://tekblog.teksquisite.com/2009/11/30/tech-highlights-from-november-2009/</link>
		<comments>http://tekblog.teksquisite.com/2009/11/30/tech-highlights-from-november-2009/#comments</comments>
		<pubDate>Mon, 30 Nov 2009 08:19:08 +0000</pubDate>
		<dc:creator>Teksquisite</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Asperger's syndrome]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[English]]></category>
		<category><![CDATA[Gary McKinnon]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[NASA]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://www.teksquisite.com/blog/?p=1818</guid>
		<description><![CDATA[
			
				
			
		



Proper use of English could get a virus past security 
Hackers could evade most existing antivirus protection by hiding malicious code within ordinary text, according to security researchers.
One of the most common ways of hijacking other people&#8217;s computers is to use &#8220;code-injection&#8221; attacks, in which malicious computer code is delivered to and then run on [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Ftekblog.teksquisite.com%2F2009%2F11%2F30%2Ftech-highlights-from-november-2009%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Ftekblog.teksquisite.com%2F2009%2F11%2F30%2Ftech-highlights-from-november-2009%2F&amp;source=teksquisite&amp;style=normal&amp;service=is.gd" height="61" width="50" /><br />
			</a>
		</div>
<p style="text-align: center;"><strong><img class="aligncenter size-full wp-image-1857" title="english" src="http://tekblog.teksquisite.com/wp-content/uploads/2009/11/english.jpg" alt="english" width="480" height="188" /><br />
</strong></p>
<p style="text-align: center;">
<p style="text-align: center;"><strong>Proper use of English could get a virus past security</strong> <a href="http://www.newscientist.com/"></a></p>
<p>Hackers could evade most existing antivirus protection by hiding malicious code within ordinary text, according to security researchers.</p>
<p>One of the most common ways of hijacking other people&#8217;s computers is to use &#8220;code-injection&#8221; attacks, in which malicious computer code is delivered to and then run on victims&#8217; machines. Current security measures work on the assumption that the code used has a different structure to plain text such as English prose.</p>
<p>Now a team of researchers has highlighted a potential future theatre in the virus-security arms race by working out how to hide malware within English-language sentences.</p>
<p>Hackers call the part of a code-injection attack that is used to gain control of a vulnerable computer &#8220;shell code&#8221;. Because this is usually written in machine code, Mason and colleagues dubbed their technique &#8220;English shell code&#8221;.</p>
<p>They presented their research (PDF) at the ACM Conference on Computer and Communications Security in Chicago earlier this month, being careful to leave out some of their methodology to avoid helping malicious hackers. &#8211;<a title="New Scientist" href="http://www.newscientist.com/article/dn18211-proper-use-of-english-could-get-a-virus-past-security.html" target="_blank">New Scientist</a></p>
<p><a title="Newscientist" href="http://twitter.com/Newscientist" target="_blank">@Newscientist</a> on <a title="Twitter" href="http://www.twitter.com" target="_blank">Twitter</a></p>
<p style="text-align: center;">
<p style="text-align: center;">
<p style="text-align: center;">
<p style="text-align: center;"><strong><span id="more-1818"></span>Hacker to be sent to face trial in US despite relatives&#8217; suicide fear</strong></p>
<p style="text-align: left;">
<p>LONDON: A British computer hacker who has Asperger&#8217;s syndrome is at serious risk of suicide, relatives say, after a last-ditch attempt to prevent his extradition to the US was rejected.</p>
<p>In a letter the Home Secretary, Alan Johnson, ordered Gary McKinnon&#8217;s removal to the US on charges of breaching American military and NASA computers, despite claims by his lawyers that extradition would make the 43-year-old&#8217;s death &#8221;virtually certain&#8221;.</p>
<p>The decision, described by lawyers as callous, has prompted fresh fears about Mr McKinnon&#8217;s wellbeing. Thursday&#8217;s letter rejected new expert medical evidence that Mr McKinnon&#8217;s health had deteriorated dramatically since he lost his case in the High Court in July, and meant that extradition would<br />
violate his right to life.  &#8211;<a title="GNews" href="http://www.smh.com.au/technology/hacker-to-be-sent-to-face-trial-in-us-despite-relatives-suicide-fear-20091127-jwxa.html" target="_blank">Guardian News &amp; Media</a></p>
<p><a title="GuardianNews" href="http://twitter.com/GuardianNews" target="_blank">@GuardianNews</a> on <a title="twitter" href="http://www.twitter.com" target="_blank">Twitter</a></p>
<p>Please follow computer engineer <a title="Brian_Howes" href="http://twitter.com/Brian_Howes" target="_blank">@Brian_Howes</a> on <strong>Twitter </strong>who fights illegal extradtion for All to the DEATH.</p>
<p style="text-align: center;">
<p style="text-align: center;"><strong>Vendor rages after iPhone hacker given job</strong><br />
<em>The code was rubbish too, says <a title="Sophos" href="http://www.sophos.com/" target="_blank">Sophos</a>.</em></p>
<p style="text-align: left;">A security firm has expressed incredulity at the news that the Australian prank hacker who wrote a program targeting Apple iPhone users has been given a job by an application developer.</p>
<p>The writer of the Ikee worm, Ashley Towns, sprang to prominence only two weeks ago after his creation was found to be changing the desktop wallpaper on some ‘jailbroken&#8217; or unlocked iPhones to display a picture of 1980&#8217;s British pop-star Rick Astley. Now, fellow-Australian software company mogeneration is reported to have offered Towns a paid job after hearing of his efforts.</p>
<p>&#8220;Yey, I got the job. I&#8217;m now an iPhone application developer,&#8221; says the 21-year old&#8217;s Twitter feed, adopting a nonchalant attitude that has seriously annoyed more than one security company. Currently, only one is willing to go on the record.</p>
<p>&#8220;What disheartens me is that Towns has shown no regret for what he did. He admitted specifically infecting 100 iPhones himself, letting his worm loose in the process. Now his utterly irresponsible behaviour appears to have been rewarded,&#8221; said Graham Cluley of software outfit Sophos, in an emailed press statement. &#8211;<a title="techworld" href="http://news.techworld.com/security/3207476/vendor-rages-after-iphone-hacker-given-job/" target="_blank">Techworld</a></p>
<p style="text-align: left;"><span><em>John E. Dunn/<a title="dourscot" href="http://twitter.com/dourscot" target="_blank">@</a></em></span><a title="dourscot" href="http://twitter.com/dourscot" target="_blank">dourscot</a> on <a title="Twitter" href="http://www.twitter.com" target="_blank">Twitter</a><span><br />
</span></p>
<p style="text-align: center;">
<p style="text-align: center;"><strong>Shadowserver to Take Over as Mega-D Botnet Herder</strong></p>
<p style="text-align: left;">An effort is underway to clean up tens of thousands of computers infected with malicious software known for churning out thousands of spam messages per hour.  The infected computers are part of a botnet called Ozdok or Mega-D, which at one time was sending out around 4 percent of the world&#8217;s spam messages.</p>
<p>Last week, security vendor <a title="FireEye" href="http://www.fireeye.com/" target="_blank">FireEye</a> launched a drive to dismantle the botnet. The infected computers receive instructions and information for new spam campaigns through command-and-control servers. FireEye contacted network providers which hosted those servers, and most were shut down.</p>
<p>That meant that the people controlling the hacked PCs, known as botnet herders, couldn&#8217;t contact most of their bots anymore. Spam from Mega-D almost stopped entirely. FireEye also cut off a second redundancy mechanism the herders programmed into Mega-D&#8230;FireEye has now handed control of those bots over to <a title="shadowserver" href="http://shadowserver.org/wiki/" target="_blank">Shadowserver</a>, a volunteer-run organization that tracks botnets.</p>
<p>Shadowserver has taken over the administration of a &#8220;sinkhole,&#8221; or a computer running custom software that acts as a command-and-control server that the Mega-D bots will call on, said Andre&#8217; M. DiMino, Shadowserver&#8217;s co-founder.&#8211; <a title="Networkworld" href="http://www.networkworld.com/news/2009/111709-shadowserver-to-take-over-as.html" target="_blank">Networkworld</a></p>
<p><a title="networkworld" href="http://twitter.com/networkworld" target="_blank">@networkworld</a> on <a title="twitter" href="http://www.twitter.com" target="_blank">Twitter</a></p>
<p><strong>Until next time &#8212; Stay safe Online!</strong></p>
<p><strong><br />
</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://tekblog.teksquisite.com/2009/11/30/tech-highlights-from-november-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>An affiliate marketer shows you how to go phishing&#8230;</title>
		<link>http://tekblog.teksquisite.com/2009/11/26/an-affiliate-marketer-shows-you-how-to-go-phishing/</link>
		<comments>http://tekblog.teksquisite.com/2009/11/26/an-affiliate-marketer-shows-you-how-to-go-phishing/#comments</comments>
		<pubDate>Thu, 26 Nov 2009 05:55:32 +0000</pubDate>
		<dc:creator>Teksquisite</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[affiliate marketing]]></category>
		<category><![CDATA[Blackhat]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[social engineering]]></category>
		<category><![CDATA[Zbot]]></category>

		<guid isPermaLink="false">http://www.teksquisite.com/blog/?p=1725</guid>
		<description><![CDATA[
			
				
			
		

I am currently reading a read me from a recent .rar that I downloaded and extracted over at Tubnut (that is a pet name for  my virtual station that analyzes files.)  The one question in the read me  that consistently catches my attention is  &#8212;How can I get somebody to login to my [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Ftekblog.teksquisite.com%2F2009%2F11%2F26%2Fan-affiliate-marketer-shows-you-how-to-go-phishing%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Ftekblog.teksquisite.com%2F2009%2F11%2F26%2Fan-affiliate-marketer-shows-you-how-to-go-phishing%2F&amp;source=teksquisite&amp;style=normal&amp;service=is.gd" height="61" width="50" /><br />
			</a>
		</div>
<p style="text-align: center;"><img class="aligncenter size-full wp-image-1859" title="phishing-pages-download" src="http://tekblog.teksquisite.com/wp-content/uploads/2009/11/phishing-pages-download.jpg" alt="phishing-pages-download" width="599" height="686" /></p>
<p>I am currently reading a <strong>read me</strong> from a recent .rar that I downloaded and extracted over at Tubnut (that is a pet name for  my virtual station that analyzes files.)  The one question in the <strong>read me</strong><em> </em> that consistently catches my attention is  <strong>&#8212;How can I get somebody to login to my phisher&#8212; </strong>The answer: &#8220;That&#8217;s for you to find out, use your mind. Probably the simplest way is <strong>Social Engineering</strong> and some<strong> phishing skill. </strong> Here is an example : hXXp://imgdevil.com/pfiles/11140/munged&#8221;</p>
<p>The one commonality between affiliate marketers and cyber-criminals is that they are both highly adept in the art of <em>social engineering. </em><a title="Michigan.gov" href="http://www.michigan.gov/cybersecurity/0,1607,7-217-34415---,00.html" target="_blank">Michigan.gov</a> defines social engineering as &#8220;<em>an approach to gain access to information, primarily through misrepresentation, and often relies on the trusting nature of most individuals.&#8221; </em></p>
<p>Most affiliate marketers remain in the gray area of social engineering.  They also hold a strong emphasis on scam-type marketing campaigns in order to promote traffic to their website, specifically for the purpose of financial gain.  In comparison, Cyber-criminals fully embark in blackhat social engineering techniques, developing fake &#8220;phishing&#8221; sites in order to gain access to financial accounts.</p>
<p><span id="more-1725"></span></p>
<p>Today I found an affiliate marketer on Twitter who participates in both forms of social engineering.  Though his account is not listed in Twitter search, I assume that he is from Pakistan and that he only uses anonymous accounts/sites to post content.  I am not posting his information here at the Tekblog.  For the purpose of this post I will refer to the affiliate marketer/phisher as <strong>P-man. </strong>So lets now move on to disclose some of the findings from P-mans phishing .rar.</p>
<p style="text-align: center;"><img class="aligncenter size-full wp-image-1749" title="phishing1" src="http://www.teksquisite.com/blog/wp-content/uploads/2009/11/phishing1.jpg" alt="phishing1" width="516" height="436" /></p>
<p style="text-align: center;"><strong>I was 100% amazed to not find a Twitter Phisher here!</strong></p>
<p style="text-align: center;"><img class="aligncenter size-full wp-image-1750" title="phishing2" src="http://www.teksquisite.com/blog/wp-content/uploads/2009/11/phishing2.jpg" alt="phishing2" width="527" height="369" /></p>
<p style="text-align: left;">
<p style="text-align: left;">The major points that <strong>P-man </strong>promotes is that a phisher must:</p>
<p>1- Find a web host that supports php<br />
2- Have a plan in place to send victims to the Index page<br />
3- Learn how to hide links in forums<br />
4- Seek free hosting/free domains (all anonymous)<br />
5- What email spamming service to use<br />
6- The use of URL shortening services to hide the phish<br />
7- Proxies</p>
<p style="text-align: left;">There are also text files in many of the phishing folders that direct you to other underground technology websites.  You will be instructed to register at these sites before you are allowed access.  I believe that these underground sites will also be looking at your IP, OS vulnerabilities, etc in order to asses your intentions in registering.  You can anticipate that there will be many sites that will also redirect you to set up a meeting in mIRC, regarding more complex phishing site configurations.</p>
<p style="text-align: left;"><strong>Paypal</strong></p>
<p style="text-align: left;">While perusing the Paypal directory I noticed that there was a possible paypal phishing tutorial located at  the free domain of DaveDaDon.  His motto: <strong>Touch ME? Neva. </strong>His domain is now suspended&#8230;<strong> </strong></p>
<p style="text-align: left;">
<p style="text-align: left;"><strong><br />
</strong></p>
<p style="text-align: center;"><img class="aligncenter size-full wp-image-1751" title="paypal" src="http://www.teksquisite.com/blog/wp-content/uploads/2009/11/paypal.jpg" alt="paypal" width="356" height="171" /></p>
<p style="text-align: center;">
<p style="text-align: left;">Ironically <strong>Touch ME? Neva</strong> guy who goes by the online name of DAVEDADON,  had the balls last year to post at the <a title="Fóruns do Visual Studio" href="http://social.msdn.microsoft.com/Forums/pt-BR/category/visualstudio">Microsoft Fóruns do Visual Studio</a>.  Perhaps ego rides a wild donkey too?</p>
<p style="text-align: left;"><img class="aligncenter size-full wp-image-1766" title="suspended" src="http://www.teksquisite.com/blog/wp-content/uploads/2009/11/suspended.jpg" alt="suspended" width="604" height="310" /></p>
<p style="text-align: left;">
<p style="text-align: left;"><strong>Freewebs</strong></p>
<p style="text-align: left;">DAVEDADON also allegedly provided a Freewebs phishing tutorial at his now defunct site. This was the one and only folder in the .rar that included a WARNING.</p>
<p style="text-align: center;"><img class="aligncenter size-full wp-image-1794" title="freewebs1" src="http://www.teksquisite.com/blog/wp-content/uploads/2009/11/freewebs1.jpg" alt="freewebs1" width="379" height="115" /></p>
<p style="text-align: center;">
<p style="text-align: left;">This warning, apparently intended to pose as a disclaimer against holding DaveDaDon liable for anything that smacked of criminal intent:</p>
<p style="text-align: center;"><img class="aligncenter size-full wp-image-1795" title="freewebs2" src="http://www.teksquisite.com/blog/wp-content/uploads/2009/11/freewebs2.jpg" alt="freewebs2" width="426" height="128" /></p>
<p style="text-align: left;">DaveDaDon is not playing nice with his phishing students either!</p>
<p style="text-align: center;"><img class="aligncenter size-full wp-image-1803" title="zbot" src="http://www.teksquisite.com/blog/wp-content/uploads/2009/11/zbot.jpg" alt="zbot" width="488" height="243" /></p>
<p style="text-align: center;">
<p style="text-align: left;"><strong>P-man is anonymous&#8230;He uses Twitter and Facebook to push traffic back to an anonymous website.  P-man has myriad Pakistani friends.  P-man affiliates with phishers, may be phishing,  and emulates  viral marketing.<br />
</strong></p>
<p style="text-align: left;"><strong>Online age:</strong> 13-21</p>
<p style="text-align: left;"><strong>Country:</strong> Pakistan</p>
<p style="text-align: left;"><strong>Twitter:</strong> 1007 followers (affiliate marketer, filtered from Twitter search)</p>
<p style="text-align: center;"><img class="aligncenter size-full wp-image-1808" title="Shot1" src="http://www.teksquisite.com/blog/wp-content/uploads/2009/11/Shot1.jpg" alt="Shot1" width="483" height="154" /></p>
<p style="text-align: left;"><strong>Facebook: </strong>Fan page, 104 followers (most download links lead back to P-mans blog)</p>
<p style="text-align: left;">
<p style="text-align: left;"><strong>Until Next time &#8212; Stay safe online!</strong></p>
<p style="text-align: left;">
<p style="text-align: left;">
<p style="text-align: center;">
<p style="text-align: center;">
<p style="text-align: left;">
<p style="text-align: center;">
<p style="text-align: left;">
<p style="text-align: center;">
]]></content:encoded>
			<wfw:commentRss>http://tekblog.teksquisite.com/2009/11/26/an-affiliate-marketer-shows-you-how-to-go-phishing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>My USB flash stick is broken!</title>
		<link>http://tekblog.teksquisite.com/2009/11/25/my-usb-flash-stick-is-broken/</link>
		<comments>http://tekblog.teksquisite.com/2009/11/25/my-usb-flash-stick-is-broken/#comments</comments>
		<pubDate>Wed, 25 Nov 2009 23:17:53 +0000</pubDate>
		<dc:creator>ITTekTips</dc:creator>
				<category><![CDATA[Hardware]]></category>
		<category><![CDATA[TekTips]]></category>
		<category><![CDATA[disk space]]></category>
		<category><![CDATA[flash drive]]></category>
		<category><![CDATA[format]]></category>
		<category><![CDATA[USB disk]]></category>
		<category><![CDATA[USB stick]]></category>

		<guid isPermaLink="false">http://www.teksquisite.com/blog/?p=1717</guid>
		<description><![CDATA[
			
				
			
		
Maybe not! I have an 8 GB USB stick that is only showing 950 mbs of available disk space.  After doing a bit of Google research I decided to visit http://files.extremeoverclocking.com/file.php?f=197 and download HP USB Disk Storage Format Tool &#8211; v2.1.8, a nifty little USB format utility that is free to use.
Note: Be sure to [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Ftekblog.teksquisite.com%2F2009%2F11%2F25%2Fmy-usb-flash-stick-is-broken%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Ftekblog.teksquisite.com%2F2009%2F11%2F25%2Fmy-usb-flash-stick-is-broken%2F&amp;source=teksquisite&amp;style=normal&amp;service=is.gd" height="61" width="50" /><br />
			</a>
		</div>
<p>Maybe not! I have an 8 GB USB stick that is only showing 950 mbs of available disk space.  After doing a bit of Google research I decided to visit <a href="http://files.extremeoverclocking.com/file.php?f=197" target="_blank">http://files.extremeoverclocking.com/file.php?f=197</a> and download <strong>HP USB Disk Storage Format Tool &#8211; v2.1.8, </strong>a nifty little USB format utility that is free to use.</p>
<p><strong>Note: </strong>Be sure to download from the <strong>Primary Download Site</strong></p>
<p style="text-align: center;"><strong><br />
</strong></p>
<p style="text-align: center;"><img class="aligncenter size-full wp-image-1861" title="reformat-usb" src="http://tekblog.teksquisite.com/wp-content/uploads/2009/11/reformat-usb.jpg" alt="reformat-usb" width="348" height="466" /></p>
<p style="text-align: center;">
<p style="text-align: left;">As you can see from the screen capture above, I did not use the <strong>quick format </strong>option.  Formatting took almost an hour to complete, and this fabulous utility was able to retrieve all lost disk space.</p>
<p style="text-align: center;"><img class="aligncenter size-full wp-image-1863" title="retrieve" src="http://tekblog.teksquisite.com/wp-content/uploads/2009/11/retrieve.jpg" alt="retrieve" width="363" height="327" /></p>
<p style="text-align: left;">If you have a USB stick that is missing disk space, give this HP USB Disk Storage Format Tool a shot.</p>
<p style="text-align: left;"><strong>Until next time &#8211; Stay safe online!</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://tekblog.teksquisite.com/2009/11/25/my-usb-flash-stick-is-broken/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Part II: Intruder Defense – Use Ubuntu to secure financial transactions online</title>
		<link>http://tekblog.teksquisite.com/2009/11/25/part-ii-intruder-defense-%e2%80%93-use-ubuntu-to-secure-financial-transactions-online/</link>
		<comments>http://tekblog.teksquisite.com/2009/11/25/part-ii-intruder-defense-%e2%80%93-use-ubuntu-to-secure-financial-transactions-online/#comments</comments>
		<pubDate>Wed, 25 Nov 2009 09:21:20 +0000</pubDate>
		<dc:creator>Teksquisite</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[online banking]]></category>
		<category><![CDATA[ubuntu]]></category>

		<guid isPermaLink="false">http://www.teksquisite.com/blog/?p=1673</guid>
		<description><![CDATA[
			
				
			
		

Last month Brian Krebs wrote an interesting and informative article about E-Banking on a Locked Down (Non-Microsoft) PC for business owners, and outlined a tutorial on how to accomplish security online.
&#8220;In past Live Online chats and blog posts, I&#8217;ve mentioned any [sic] easy way to temporarily convert a Windows PC into a Linux-based computer in [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Ftekblog.teksquisite.com%2F2009%2F11%2F25%2Fpart-ii-intruder-defense-%25e2%2580%2593-use-ubuntu-to-secure-financial-transactions-online%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Ftekblog.teksquisite.com%2F2009%2F11%2F25%2Fpart-ii-intruder-defense-%25e2%2580%2593-use-ubuntu-to-secure-financial-transactions-online%2F&amp;source=teksquisite&amp;style=normal&amp;service=is.gd" height="61" width="50" /><br />
			</a>
		</div>
<p style="text-align: center;"><img class="aligncenter size-full wp-image-1865" title="Desktop" src="http://tekblog.teksquisite.com/wp-content/uploads/2009/11/Desktop.png" alt="Desktop" width="800" height="600" /></p>
<p>Last month <a title="Brian Krebbs" href="http://blog.washingtonpost.com/securityfix/2005/03/about_this_blog_1.html" target="_blank"><strong>Brian Krebs</strong></a> wrote an interesting and informative article about <a href="http://voices.washingtonpost.com/securityfix/2009/10/e-banking_on_a_locked_down_non.html" target="_blank">E-Banking on a Locked Down (Non-Microsoft) PC</a> for business owners, and outlined a tutorial on how to accomplish security online.</p>
<p><em>&#8220;In past Live Online chats and blog posts, I&#8217;ve mentioned any </em>[sic]<em> easy way to temporarily convert a Windows PC into a Linux-based computer in order to ensure that your online banking credentials positively can&#8217;t be swiped by password-stealing malicious software. What follows is a brief tutorial on how to do that with Ubuntu, one of the more popular bootable Linux installations.&#8221; </em>&#8211; Washington Post, Security Fix blog</p>
<p>Receiving strong reactions from his readers, Krebs posted a rebuttal titled <a href="http://voices.washingtonpost.com/securityfix/2009/10/e-banking_on_a_locked_down_pc.html" target="_blank">E-Banking on a Locked Down PC, Part II</a>.  He further demonstrated that the initial article was not directed at consumers, but at<em> &#8220;small to mid-sized companies that may not have a full-time IT/security staff, and who rely on one or two people to handle their bank accounts and payroll online.&#8221;</em></p>
<p>Detective Inspector Bruce van der Graaf from the Computer Crime Investigation Unit (NSW Police) uses two rules to protect himself from cybercriminals when banking online:   Never click on URLs to the banking site and  avoid Microsoft Windows.   &#8212; <a href="http://www.itnews.com.au/News/157767,nsw-police-dont-use-windows-for-internet-banking.aspx" target="_blank">ITNews</a> Great advice during the onslaught of  Zeus and the the Clampi Trojan&#8230;</p>
<p><span id="more-1673"></span></p>
<p>Adrian Kingsley of ZDNet upped the malware  alert a few notches when he stated  &#8220;It’s time to <a href="http://blogs.zdnet.com/hardware/?p=5813" target="_blank">ditch Windows for online banking and shopping</a>. There, I’ve said it.&#8221;</p>
<p>You can have all the security preventatives lined up in a row and quacking, but you can&#8217;t protect ducklings that choose to cross the freeway during rush hour traffic.  Windows is currently the primary target of global malware authors.  Tomorrow it could be Linux.  Next week it could be Mac.  Any operating system that connects to the Internet and conducts financial transactions is fair game.  Since a larger % of Internet users employ the windows platform to do online banking, it is obvious that windows would be the operating system of choice for cyber-criminals to pursue today.</p>
<p>Recently I restricted online financial transaction access to one workstation and to specific websites on a standalone Ubuntu computer.</p>
<p>Read <a href="http://tekblog.teksquisite.com/wp-admin/post.php?action=edit&amp;post=1328" target="_blank">Part I: Intruder Defense</a> – Become part of a Solid Internet Security Solution (SISS)</p>
<p><strong>Until next time &#8212; Stay safe online!</strong></p>
<p><strong><br />
</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://tekblog.teksquisite.com/2009/11/25/part-ii-intruder-defense-%e2%80%93-use-ubuntu-to-secure-financial-transactions-online/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Dinner_Guest:  Viral PR or the Real Thing?</title>
		<link>http://tekblog.teksquisite.com/2009/11/17/dinner_guest-viral-pr-or-the-real-thing/</link>
		<comments>http://tekblog.teksquisite.com/2009/11/17/dinner_guest-viral-pr-or-the-real-thing/#comments</comments>
		<pubDate>Wed, 18 Nov 2009 00:25:52 +0000</pubDate>
		<dc:creator>Teksquisite</dc:creator>
				<category><![CDATA[social networking]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[PR]]></category>

		<guid isPermaLink="false">http://www.teksquisite.com/blog/?p=1649</guid>
		<description><![CDATA[
			
				
			
		

 Dinner_Guest
Twitter Bio: I can&#8217;t help myself and i need to tell someone. Love the kill
Joined: Tue 10 Nov 2009 21:41
Following: 1  &#124;  Followers: 100  &#124;  Updates: 41
Being an avid Techcrunch fan, I was intrigued with Mike Butchers article &#8220;Is @Dinner Guest a sick joke or a real murderer on Twitter?&#8221; Who is this Dinner_Guest [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Ftekblog.teksquisite.com%2F2009%2F11%2F17%2Fdinner_guest-viral-pr-or-the-real-thing%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Ftekblog.teksquisite.com%2F2009%2F11%2F17%2Fdinner_guest-viral-pr-or-the-real-thing%2F&amp;source=teksquisite&amp;style=normal&amp;service=is.gd" height="61" width="50" /><br />
			</a>
		</div>
<p><img class="aligncenter size-full wp-image-1867" title="dg-150x150" src="http://tekblog.teksquisite.com/wp-content/uploads/2009/11/dg-150x150.jpg" alt="dg-150x150" width="150" height="150" /></p>
<p style="text-align: center;"><strong> <a href="http://twitter.com/dinner_guest" target="_blank">Dinner_Guest</a></strong></p>
<p style="text-align: center;"><strong>Twitter Bio: </strong>I can&#8217;t help myself and i need to tell someone. Love the kill<br />
<strong>Joined:</strong> Tue 10 Nov 2009 21:41</p>
<p style="text-align: center;"><strong>Following:</strong> 1  |  <strong>Followers:</strong> 100  |  <strong>Updates:</strong> 41</p>
<p style="text-align: left;">Being an avid Techcrunch fan, I was intrigued with <a href="http://eu.techcrunch.com/2009/11/17/is-dinner_guest-a-sick-joke-or-a-real-murderer-on-twitter/" target="_blank">Mike Butchers article</a> <em>&#8220;Is @Dinner Guest a sick joke or a real murderer on Twitter?&#8221; </em>Who is this Dinner_Guest tweeter who has gone from 4 followers to over 100 followers as of this writing?</p>
<p style="text-align: left;">I&#8217;m watching this account now via Tweetdeck as Dinner_Guest plays a dumbed down version of a Twitter newbie.</p>
<p style="text-align: center;"><img class="aligncenter size-full wp-image-1869" title="follows" src="http://tekblog.teksquisite.com/wp-content/uploads/2009/11/follows.jpg" alt="follows" width="403" height="205" /></p>
<p style="text-align: left;">
<p style="text-align: center;"><strong>Why did Dinner_Guest choose to follow RACarter? </strong></p>
<ul>
<li id="bio"><span>Bio</span> <span>CFO for hire by the day to StartUps. Now myself a StartUp. I work a lot with the London tech scene. </span></li>
</ul>
<p style="text-align: center;"><strong>And what are the the social implications of such shockingly dark tweets?</strong></p>
<p style="text-align: center;">
<p style="text-align: center;">
<p style="text-align: center;"><span id="more-1649"></span></p>
<p style="text-align: center;"><img class="aligncenter size-full wp-image-1870" title="tweets-dg" src="http://tekblog.teksquisite.com/wp-content/uploads/2009/11/tweets-dg.jpg" alt="tweets-dg" width="503" height="703" /></p>
<p style="text-align: center;"><strong>Is this a PR stunt or ?</strong></p>
<p style="text-align: left;">I honestly think that this is a PR stunt.  I added this person to one of <a title="my lists" href="http://twitter.com/dinner_guest/lists/memberships" target="_blank">my lists </a>so that I can keep a close eye on tweets without having to follow the profile.</p>
<p style="text-align: center;"><img class="aligncenter size-full wp-image-1871" title="odd-strange" src="http://tekblog.teksquisite.com/wp-content/uploads/2009/11/odd-strange.jpg" alt="odd-strange" width="512" height="215" /></p>
<p style="text-align: center;">
<p style="text-align: center;"><strong>Stay tuned for future revelations as the plot thickens&#8230;</strong></p>
<p style="text-align: center;">
<p style="text-align: left;"><em>Twitter &#8217;serial killer&#8217; comes to Brighton </em><a href="http://www.brightonandhovenews.org/2009/11/twitter-serial-killer-comes-to-brighton/" target="_blank">Brighton and Hove News</a></p>
<p><a title="Why @Dinner_Guest is probably a fake" rel="bookmark" href="http://eu.techcrunch.com/2009/11/18/why-dinner_guest-is-probably-a-fake/">Why @Dinner_Guest is probably a fake</a></p>
<p>The mystery has ended.            <strong>Update 11/18/09 </strong></p>
<p><strong>New Bio:</strong> <span> </span><em>&#8220;<span>A fictional character born out of an artists mind. A meme experiment. &amp; analysis.&#8221;</span></em></p>
<p><em><span><strong>Until next time &#8212; Stay safe online!</strong></span></em></p>
<p><em><span><strong><br />
</strong></span></em></p>
<p><em><span><strong><br />
</strong></span></em></p>
<p style="text-align: center;">
<p style="text-align: center;">
<p style="text-align: left;">
]]></content:encoded>
			<wfw:commentRss>http://tekblog.teksquisite.com/2009/11/17/dinner_guest-viral-pr-or-the-real-thing/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>The Butterfly Effect:  Are You Smart Enough To Run a Website?</title>
		<link>http://tekblog.teksquisite.com/2009/11/17/the-butterfly-effect-are-you-smart-enough-to-run-a-website/</link>
		<comments>http://tekblog.teksquisite.com/2009/11/17/the-butterfly-effect-are-you-smart-enough-to-run-a-website/#comments</comments>
		<pubDate>Tue, 17 Nov 2009 06:55:04 +0000</pubDate>
		<dc:creator>Teksquisite</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[social responsibility]]></category>
		<category><![CDATA[webmaster]]></category>

		<guid isPermaLink="false">http://www.teksquisite.com/blog/?p=1530</guid>
		<description><![CDATA[
			
				
			
		
 
The butterfly effect: &#8220;Small variations of the initial condition of a dynamical system may produce large variations in the long term behavior of the system.&#8221;
In the realm of Internet security, webmasters (hosting service providers) are pivotal in reducing the impact of compromised/malware-laden websites.  Once a compromised site becomes known to a webmaster (or hosting [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Ftekblog.teksquisite.com%2F2009%2F11%2F17%2Fthe-butterfly-effect-are-you-smart-enough-to-run-a-website%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Ftekblog.teksquisite.com%2F2009%2F11%2F17%2Fthe-butterfly-effect-are-you-smart-enough-to-run-a-website%2F&amp;source=teksquisite&amp;style=normal&amp;service=is.gd" height="61" width="50" /><br />
			</a>
		</div>
<p><img class="alignleft size-full wp-image-1534" title="Butterfly" src="http://www.teksquisite.com/blog/wp-content/uploads/2009/11/Butterfly.png" alt="Butterfly" width="300" height="300" /><strong> </strong></p>
<p><strong>The<a href="http://en.wikipedia.org/wiki/Butterfly_effect" target="_blank"> butterfly effect</a></strong><a href="http://en.wikipedia.org/wiki/Butterfly_effect" target="_blank">:</a> <em>&#8220;Small variations of the initial condition of a dynamical system may produce large variations in the long term behavior of the system.&#8221;</em></p>
<p>In the realm of Internet security, webmasters (hosting service providers) are pivotal in reducing the impact of compromised/malware-laden websites.  Once a compromised site becomes known to a webmaster (or hosting service provider) it should <span style="text-decoration: underline;"><strong>immediately</strong></span> be disconnected from the Internet.</p>
<p>As a webmaster (hosting services provider) you play an integral role in guarding the integrity of site code and maintaining upgrade compliance. One neglectful action on your part &#8211; such as failure to acknowledge a website vulnerability can seriously effect all site visitors.  An iframe exploit may seem small and insignificant at first, until a payload is dumped and eventually herds hundreds, or even thousands of innocent victims into the bowels of a stealthy botnet.</p>
<p><span id="more-1530"></span></p>
<p>As a webmaster (hosting service provider) when using social networking sites such as Twitter and Facebook, you are also responsible for the health of your profile URL that links back to your website. If a social networking site filters your profile link, you should take the warning seriously.</p>
<p>Recently, I was astonished and alarmed by a website owner on <a title="twitter" href="http://www.twitter.com" target="_blank">Twitter</a>.  She disguised her profile link with another domain that redirected visitors back to the initial infected domain.  She was able to <strong>trick</strong><em> Twitter</em> <em>filtering</em>, but at what cost to website visitors?  Her reasoning for switching the URL was &#8220;yeah i thought maybe i could trick it but i guess not. i&#8217;ll have to remove the links for now.&#8221;  The new link was never removed from her profile, though her site was eventually cleaned up.  How many people became infected during the interim <em>trick</em>?  Irresponsible actions, as noted above, are all too prevalent when it comes to taking social responsibility for compromised websites.</p>
<p><strong>Are you smart enough to run a website?</strong></p>
<p>Taking responsibility for Internet security is something that we all should be taking seriously. From home user levels to corporate user levels &#8211; there is no room for feigning technological stupidity.  If you are a small business owner and operating a company website, you need to become educated on how to properly secure and maintain your website.  If you are unable to take Internet security seriously, you will need to hire a professional.</p>
<p><em>Cyber-crooks are relentless in their pursuit of your money and “It’s all about the money,” according to <a title="GC blog" href="http://www.sophos.com/blogs/gc/" target="_blank">Graham Cluley</a>, senior technical consultant at Internet security firm <a title="Sophos" href="http://www.sophos.com/" target="_blank">Sophos.</a> In the worst case scenario, your identity and your financial security can be severely compromised. </em>&#8211;Source:<a title="Bill Mullins" href="http://billmullins.wordpress.com/2008/07/" target="_blank"> Bill Mullins</a></p>
<p>Running a website is a huge responsibility and should not be taken lightly. Today, cybercrime rules the Internet highways.  If you don&#8217;t know how to drive, park the car and get out now!</p>
<p><em>Being involved in computer security, I am amazed and frankly frustrated, at the lack of personal responsibly</em><em> [SIC] exhibited by most typical computer users, and most importantly, the lack of commitment to acquiring the knowledge necessary to ensure personal safety on the Internet. In a word, becoming “educated”. </em> &#8211;Source: <a title="Bill Mullins" href="http://billmullins.wordpress.com/2009/09/13/follow-the-3-magic-steps-to-internet-security-stop-think-click/" target="_blank">Bill Mullins</a><em> </em></p>
<p><strong>The <a title="butterfly effect" href="http://en.wikipedia.org/wiki/Butterfly_effect" target="_blank">butterfly effect</a></strong> is here to stay.  Even the smallest of actions can severely impact all of us.  One malware link to a .cn domain could compromise one computer.  One computer then joins a botnet.  Next on the agenda &#8212; ten housand computers join a botnet.  Why?  Because the computers already house severe vulnerabilities.  As webmasters (hosting service providers) do not downplay <span style="text-decoration: underline;">your </span>Internet security role as insignificant.</p>
<p><strong>Steps that you can take to secure your website:</strong></p>
<p>Kevin Roderick suggests <a title="seven essential resources" href="http://www.ojr.org/ojr/people/robert/200903/1683/" target="_blank">Seven essential resources </a>to help protect your website from technical attack:</p>
<p>1. Google&#8217;s <a title="webmaster tools" href="http://www.google.com/webmasters/tools/" target="_blank">Webmaster Tools</a><br />
2. Google&#8217;s Safe Browsing <a title="diagnostic tool" href="http://www.google.com/safebrowsing/diagnostic?site=http://www.yoururl.com" target="_blank">Diagnostic Tool</a><br />
3. Google&#8217;s <a title="online security blog" href="http://googleonlinesecurity.blogspot.com/" target="_blank">Online Security Blog</a><br />
4. Stop Badware&#8217;s <a title="Link Clearinghouse" href="http://stopbadware.org/home/clearinghouse" target="_blank">Link Clearinghouse</a><br />
5.<a title="webmaster world" href="http://www.webmasterworld.com" target="_blank"> Webmaster World</a><br />
6. <a title="Matt Cutt's Blog" href="http://www.mattcutts.com/blog/" target="_blank">Matt Cutts&#8217; Blog</a><br />
7. <a title="Search Engine Land" href="http://searchengineland.com/" target="_blank">Search Engine Land</a></p>
<p><strong>Until next time &#8212; stay safe online!</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://tekblog.teksquisite.com/2009/11/17/the-butterfly-effect-are-you-smart-enough-to-run-a-website/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
