Pages

Recent Posts

Showing posts with label Cybercrime. Show all posts
Showing posts with label Cybercrime. Show all posts

Thursday, May 5, 2011

LastPass Gets Hacked For 1.25 Million Passwords

 

computer_thief

By: Kareem@techsual.com

In what would seem like the cyber equivalent of turning someone upside down and shaking all the money out of their pockets, some unscrupulous hackers took LastPass for an estimated 1.25 million passwords.

LastPass is a service which allows users to store login information for different websites under one, ‘secure’ password which is kept safe by LastPass and makes it easier for people to create crazy passwords without having to worry about remembering them.

That was, up until yesterday, when apparently someone got behind their firewalls and stole the aforementioned 1.25 million passwords. That’s quite a few passwords, especially considering that since those are taken, whoever has them can login to the users accounts and everything they have linked to it. That means that a lot of people have good reason to check their bank accounts and other sensitive online data.

If your concerned about how much might have been taken, then you should go ahead and change all your passwords ASAP and the email and other info related to your LastPass account.

I would also suggest that you don’t use single login services like LastPass, it’s kind of a bad idea to put all that information under one account, your best bet for safety is creating choke points for everything. Say for instance you want to start a Facebook account, you should have one specific email account for that Facebook account, that way if someone hacks your Facebook and gets your email through it they won’t have a real addy, it’s a choke point it ends with (preferably) totally false data. By creating multiple accounts for things like that you can focus on making your personal email secure and change those passwords daily. Remember to make those other accounts as real as possible, use pictures you find on the internet, make the name as real as possible. Basically what your doing is creating multiple false identities so that you can waste as much of someone who is trying to get your info’s time as possible. If they think it’s real they’ll keep going until thy realize it’s not, and if they do hack or steal anything at least it wont be real, and for the love of god don’t let any of those accounts link to any real personal info. Don’t give an alternate email (unless it too is fake).

I think it works best if I give you an example of what goes through the mind of someone trying to get your personal information via Facebook. For the sake of me not getting carpal tunnel today let’s skip to them already having your Facebook login info, first person mode GO!.

OK so I’m logged in as you, maybe watching you chat with a friend (oh you didn’t know I could do that…maybe I’ll tell you how later Winking smile  but for now, maybe you shouldn’t use FB chat), but that’s boring and I’m not getting much info, I’ll keep monitoring it to see if anything good comes up. I go through your info and find out where you work, went to school, your friends etc.… I can do something with that but I’m not in the mood for that much work, I just want your name, (you were smart enough to make a fake one for Facebook right?) maybe that will pop up in chat, but I don’t feel like sitting here all day waiting for someone to type your name. I’m going to go check out your email since Facebook is looking like it’s going to take some time to get what I need from (I could trick one of your friends or use the information to start building a profile but hopefully if I cared that much you’d know why and be keeping yourself off Facebook altogether). Of course I already have your fake email but what I need is your real one, I’m hoping to find a hole in the only access I currently have. Thanks to the fake email, and fake Facebook info I don’t know your real name, address, phone number or anything. Just your Facebook account login info, which I will lose once it alerts you by email that someone logged in from a computer that wasn’t yours, you change that password, or delete the account altogether and start another and I’m back to square one.

So you see how this works?, it’s the old ‘don’t put all your eggs in one basket’ spiel. If you work for a company and have a responsibility to protect sensitive data then it’s the least you could do to keep yourself a little more safe, stop being so lazy about logging into multiple sites.

Related Stuffs:

Source: Bloomberg Buisnessweek

Wednesday, April 6, 2011

All about Phising

TechsualLogo1

There have been reports lately of huge numbers of people falling for all sorts of what I think are easy to avoid traps by cybercriminals. In an attempt to maybe help some of you who might not have the time or care to look into all the different ways unscrupulous persons can steal sensitive information from you. I am going to try to explain in a series of posts ways in which you can practice better common sense and avoid getting pwned.

Before I start with anything  I really want to emphasize my feelings about the definition of a hacker. A hacker in my view and most other people who are interested in the phenomenon is someone who has an obsession with a piece of technology to the point they have to understand every single part of it, someone who is determined to achieve difficult technical tasks because the are a challenge and out of curiosity. Hackers, sometimes are criminals. But that should not tarnish the label at all. Hackers have created some of our most amazing technologies and services. We would not have the world we live in if it weren’t for their tireless efforts and obsessive compulsion to challenge themselves. Judging hackers by the few bad apples is akin to saying all police are bad just because a few are dicks, or racism or sexism or any other ism. I try my best (even though I don’t always make a point of it) to use the term cybercriminal rather than hacker when it fits because I want to try and make people more aware of the difference. Hackers are curious and although sometimes not in tune with the law, I sincerely believe that looking at information should never ever ever land anyone in jail, stealing it on the other hand I don’t know…

Now that that’s out of the way on to the article.

This is part one and is VERY simple, I am  going to, explain ways in which you might be compromised and offer some pretty simple and obvious changes you can make to be a little safer.

One of the more common points of attack is known as Phishing.

A phishing attack is when someone sends you an email claiming to be someone else in order to get you to open the link and give up information. Phishing can also be done by setting up fake websites with the same or similar domain names as ones you would trust in an attempt to get user login information.

I kind of like to organize the phishing attacks in two categories; there’s personal phishing and business phishing the way I see it.

An example of personal phishing would be to send someone an email claiming to be Facebook for example, the email can say you logged in from somewhere you don’t know and send you a link to a url to ‘fix’ your security settings. Once you click the link you’d be sent to a site that looks like the Facebook login site but isn’t, there you fill out your login information, maybe change a couple of pretend security settings (a good phisher will actually have you turn off any alerts rather than turn them on) and click next. At this point your sent directly to Facebook to avoid arousing suspicion and continue on about your day. Completely oblivious to the fact that you just gave your password away and turned off all your security emails. This is of course a simple example using something rather harmless in the scheme of things, phishers have been known to steal bank, social security and email login information among the many other much more dangerous threats to your security than losing a Facebook profile.

An example of a business spear phishing attack would be pretty much the same as above, you send an email, wait for someone to bait the hook, and then reel ‘em in the only real difference is motives, sometimes it’s access to a system, sometimes its wanting to wire millions of dollars to a fake account or steal proprietary information. Businesses' have a lot more to lose by phishing attacks and I think their best option would be to get phone verification with caller id before transferring any payments. It’s possible to get around that but it’s be a lot more technically than what I think most phishers are capable of.

The next form of attack I think is pretty common is social engineering, this involves more or less ‘hacking’ humans rather than machines.

Social engineering is a hard, if not impossible thing to completely protect yourself from. Social engineers will pretend to be people you know or you yourself in order to get access to otherwise confidential information. Social engineers usually don’t go through the internet but rather use phone calls or direct in person communication to achieve their goals.

An example of a social engineering attack would; someone phishing you and after getting your personal information, calling your bank or phone company and asking them to transfer money, cancel your account or pretty much do whatever the hell they want because the person on the phone thinks their you.

Another example. an attacker call him Jim, sees your friends will Bill Bob on Facebook. Jim looks at Bill Bobs profile and sees he has a public phone number on FB (Never ever ever post any real number you actually answer on Facebook or any other social networking site, no matter how much they ask or promise security.) Jim gives Bill a call and claims to be a paramedic and that you were beaten and robbed and that this was the first number he saw and so he’s calling Bill because he needs to know your last name just for a quick form. In a panic and not really thinking Bill gives the ‘paramedic’ your last name. This is a really simple and probably not to practical of an attack but I use it to show how social engineers tend to use people you know in order to get to you. This is doubly bad for people who work for companies as compromising their personal information usually gives hackers an ‘in’ to the companies networks.

The only two ways I see to avoid be ‘social engineered’ is to either not have a Facebook page at all, or create one with a completely false name but an avatar pic people would recognize is yours and send messages with all your friend requests explaining who you are and why you don’t use your real name. This will make it very difficult for social engineers to find the real you.

Another quick hint is to use a different email address for all your social networking accounts with completely different names, sometimes social engineers can find you by your email. I like to have one chain of fake name-fake mail-fake-social networking page so that no path leads to any legit information. Don’t forget that you never have to use real information online and the more random you are the harder you are to trace.

Thanks for reading hit the comments if you have any suggestions on things I should cover or want to add something I might have missed or not covered.

Tuesday, January 18, 2011

Match.com Sued For Fake/Dead Profiles


CIO.com posted an article today by PC world about a class action lawsuit being filed against match.com For not mentioning the apparently 60% of dead or fake accounts on their service in their ad's. They claim match.com allows dead profiles to sit on their site for months in order to pad their membersip numbers.

Click the link for the full article.
Article: Match.Com Sued By Sour Love Seekers

Sunday, January 16, 2011

Your Smartphone Your Life Your Loss


Cnn's Blake Ellis wrote an artice on how, since people smartphones nowadays contain so much personal information about them that it enables theives to not only steal their financial, but also their facebook, twiitter etc... accounts which they can then use to ruin the victims personal lives.
Hit the link to read the full article

Link: Your most dangerous possesion? Your smartphone

Stumble