<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security and PrivacyPhishing</title>
	<atom:link href="http://hijack-this.co.uk/category/phishing/feed/" rel="self" type="application/rss+xml" />
	<link>http://hijack-this.co.uk</link>
	<description>My ramblings on how to protect yourself online</description>
	<lastBuildDate>Thu, 12 Aug 2010 07:31:02 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>FBI credit card scam spam</title>
		<link>http://hijack-this.co.uk/2009/12/fbi-credit-card-scam-spam/</link>
		<comments>http://hijack-this.co.uk/2009/12/fbi-credit-card-scam-spam/#comments</comments>
		<pubDate>Fri, 04 Dec 2009 15:51:36 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=272</guid>
		<description><![CDATA[The lengths that scammers will go to try to convince a possible victim is quite unbelievable The following email dropped in my spam box I really can&#8217;t believe anyone will think the FBI issue or verify credit cards/ATM cards &#38; charge you $95 insurance fee for the privilege Once again the advice is, if it [...]]]></description>
			<content:encoded><![CDATA[<p>The lengths that scammers will go to try to convince a possible victim is quite unbelievable<br />
The following email dropped in my spam box</p>
<p>I really can&#8217;t believe anyone will think the FBI issue or verify credit cards/ATM cards &amp; charge you $95 insurance fee for the privilege</p>
<p>Once again the advice is, if it doesn&#8217;t look right, then it isn&#8217;t right so delete these scam emails and don&#8217;t reply to them or phone the numbers given. All that will do is get you a big phone bill from dialling a premium rate international phone number</p>
<p><a href="http://hijack-this.co.uk/wp-content/uploads/2009/12/fbi_cc.PNG"><img class="alignnone size-medium wp-image-273" title="fbi_cc" src="http://hijack-this.co.uk/wp-content/uploads/2009/12/fbi_cc-300x234.PNG" alt="fbi_cc" width="300" height="234" /></a></p>
Here is no comments yet by the time  your rss reader get this, Do you want to be the first commentor? Hurry up <p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2009/12/fbi-credit-card-scam-spam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Beware of fake shopping sites</title>
		<link>http://hijack-this.co.uk/2009/11/beware-of-fake-shopping-sites/</link>
		<comments>http://hijack-this.co.uk/2009/11/beware-of-fake-shopping-sites/#comments</comments>
		<pubDate>Sun, 29 Nov 2009 10:55:16 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[mozilla]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[fake adverts]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=261</guid>
		<description><![CDATA[With the seasonal shopping season well underway, watch out for fake shopping sites and phishing emails trying to get your identity &#38; credit card details. A slightly different approach came into my inbox today which asked me to confirm the item in my shopping basket. Now I haven&#8217;t shopped with Littlewoods online but you can [...]]]></description>
			<content:encoded><![CDATA[<p><br />
With the seasonal shopping season well underway, watch out for fake shopping sites and phishing emails trying to get your identity &amp; credit card details.</p>
<p>A slightly different approach came into my inbox today which asked me to confirm the item in my shopping basket. Now I haven&#8217;t shopped with Littlewoods online but you can be sure that thousands of people have and the same scam will be applied to just about every well known online shopping site this season.</p>
<p>The email looks quite believable<br />
<a href="http://hijack-this.co.uk/wp-content/uploads/2009/11/littlewoods_email.PNG"><img class="alignnone size-medium wp-image-262" title="littlewoods_email" src="http://hijack-this.co.uk/wp-content/uploads/2009/11/littlewoods_email-300x258.PNG" alt="littlewoods_email" width="300" height="258" /></a></p>
<p>The website if you follow the link looks exactly like the real Littlwoods shopping site Account sign in page <strong>EXCEPT</strong> that the real Littlewwoods or ALL reputable shopping sites will have a Padlock icon and the  site address will start with<strong> HTTPS</strong> and the address bar will turn green to show that you are on a secure site</p>
<p>This screenshot shows the fake site and I have blanked out the address for safety reasons<br />
<a href="http://hijack-this.co.uk/wp-content/uploads/2009/11/littlewoods_web.PNG"><img class="alignnone size-medium wp-image-263" title="littlewoods_web" src="http://hijack-this.co.uk/wp-content/uploads/2009/11/littlewoods_web-300x231.PNG" alt="littlewoods_web" width="300" height="231" /></a></p>
<p>These show how a genuine site will appear in Internet Explorer 8 on left and Firefox on right. Both show the padlock icon and a green safe address bar. A genuine shopping site will always start <strong>HTTPS</strong> to show a secure site when you are asked to put in any details. The front page of the site might be a normal http:<br />
Unfortunately a lot of well known shopping sites haven&#8217;t yet signed up to the Extended Valuation green bar very secure system yet so watch for the closed padlock and HTTPS in the address bar to show a secure site. In Firefox browser the closed padlock is on the bottom right hand corner of the page, not in the browser address bar </p>
<table border="0">
<tbody>
<tr>
<td><a href="http://hijack-this.co.uk/wp-content/uploads/2009/11/littlewoods_IE.PNG"><img class="alignnone size-medium wp-image-264" title="littlewoods_IE" src="http://hijack-this.co.uk/wp-content/uploads/2009/11/littlewoods_IE-300x193.PNG" alt="littlewoods_IE" width="300" height="193" /></a></td>
<td><a href="http://hijack-this.co.uk/wp-content/uploads/2009/11/real_littlewoods.PNG"><img class="alignnone size-medium wp-image-265" title="real_littlewoods" src="http://hijack-this.co.uk/wp-content/uploads/2009/11/real_littlewoods-300x232.PNG" alt="real_littlewoods" width="300" height="232" /></a></td>
</tr>
</tbody>
</table>
<p style="text-align: left;"><strong>I strongly recommend using <a href="http://www.roboform.com/php/land.php?affid=dvk01&amp;frm=frame17" target="_blank">ROBOFORM </a>which keeps all passwords in a secure encrypted database that only you (not a keylogger or malware) can access and use it to create safe secure passwords</strong></p>
<p><a href="http://www.roboform.com/php/land.php?affid=dvk01&amp;frm=frame17" target="_blank"><img src="http://www.roboform.com/affiliates/banners/728x90-warning3-free.gif" border="0" alt="RoboForm: Learn more..." width="728" height="90" /></a></p>
By the time  your rss reader get this post here is <strong> 2 </strong>comments ,Welcome you come to leave your opinion !<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2009/11/beware-of-fake-shopping-sites/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>WOW  wowmatrix keylogger</title>
		<link>http://hijack-this.co.uk/2009/11/wow-keylogger/</link>
		<comments>http://hijack-this.co.uk/2009/11/wow-keylogger/#comments</comments>
		<pubDate>Wed, 25 Nov 2009 11:00:42 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Rogue Software]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>
		<category><![CDATA[games]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[fake adverts]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[keylogger]]></category>
		<category><![CDATA[trojans]]></category>
		<category><![CDATA[world of warcraft]]></category>
		<category><![CDATA[wowmatrix]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=227</guid>
		<description><![CDATA[I was notified of a google advert for a fake wowmatrix site. The original genuine wowmatrix is seen by many games players as not completely within the rules of the games Wowmatrix is an addon that makes it easier to update and install other tweaks and addons to your game. Obviously using a fake version [...]]]></description>
			<content:encoded><![CDATA[<p><br />
I was notified of a google advert for a fake wowmatrix site. The original genuine wowmatrix is seen by many games players as not completely within the rules of the games<br />
Wowmatrix is an addon that makes it easier to update and install other tweaks and addons to your game. Obviously using a fake version that downloads false addons &#038; tweaks and installs them leaves you open to a lot of problems. </p>
<p>The advert on google looks like a search listing and it is only apparant that it is a sponsored listing or advert on close inspection</p>
<p><a href="http://hijack-this.co.uk/wp-content/uploads/2009/11/wowmatrix.PNG"><img class="size-medium wp-image-228 aligncenter" title="wowmatrix" src="http://hijack-this.co.uk/wp-content/uploads/2009/11/wowmatrix-300x148.PNG" alt="wowmatrix" width="300" height="148" /></a><span id="more-227"></span></p>
<p>if you look at the screenshots of the 2 sites, you will see that there is very little difference between them and an unwary visitor can soon get infected</p>
<p>Don&#8217;t get caught out by it and get your passwords stolen. The downloads on the fake site are recognized by several antiviruses as a password stealer and downloads lots of other trojans and malware</p>
<p>the genuine site is on the left, the fake site on the right</p>
<table border="0">
<tbody>
<tr>
<td><a href="http://hijack-this.co.uk/wp-content/uploads/2009/11/genuine_wowmatrix.PNG"><img title="genuine_wowmatrix" src="http://hijack-this.co.uk/wp-content/uploads/2009/11/genuine_wowmatrix-300x297.PNG" alt="genuine_wowmatrix" width="300" height="297" /></a></td>
<td><a href="http://hijack-this.co.uk/wp-content/uploads/2009/11/fake_wowmatrix1.PNG"><img title="fake_wowmatrix" src="http://hijack-this.co.uk/wp-content/uploads/2009/11/fake_wowmatrix1-300x291.PNG" alt="fake_wowmatrix" width="300" height="291" /></a></td>
</tr>
</tbody>
</table>
<p style="text-align: left;"><strong>I strongly recommend using <a href="http://www.roboform.com/php/land.php?affid=dvk01&amp;frm=frame17" target="_blank">ROBOFORM </a>which keeps all passwords in a secure encrypted database that only you (not a keylogger or malware) can access and use it to create safe secure passwords</strong></p>
<p><a href="http://www.roboform.com/php/land.php?affid=dvk01&amp;frm=frame17" target="_blank"><img src="http://www.roboform.com/affiliates/banners/728x90-warning3-free.gif" border="0" alt="RoboForm: Learn more..." width="728" height="90" /></a></p>
Here is no comments yet by the time  your rss reader get this, Do you want to be the first commentor? Hurry up <p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2009/11/wow-keylogger/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Lottery Spam</title>
		<link>http://hijack-this.co.uk/2009/11/microsoft-lottery-spam/</link>
		<comments>http://hijack-this.co.uk/2009/11/microsoft-lottery-spam/#comments</comments>
		<pubDate>Wed, 18 Nov 2009 11:01:04 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[fake software]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=221</guid>
		<description><![CDATA[We seem to have a new batch of the Microsoft lottery spam emails again These have a @live.com email address with what at first glance looks like it could be a proper microsoft or MSN email address ( they of course are not genuine Microsoft or associated with Microsoft in any way) DO NOT fall [...]]]></description>
			<content:encoded><![CDATA[<p>We seem to have a new batch of the Microsoft lottery spam emails again</p>
<p>These have a @live.com email address with what at first glance looks like it could be a proper microsoft or MSN email address ( they of course are not genuine Microsoft or associated with Microsoft in any way)</p>
<p>DO NOT fall for the scam &amp; try to ring the 070240****** number . it is a premium rate number that will have along recorded message on it and cost you £0.50 per minute</p>
<p>You won&#8217;t get any money from these scammers but they will get money from you</p>
<p>I have blanked out the full email address and phone number from the image to save the unwary</p>
<p><a href="http://hijack-this.co.uk/wp-content/uploads/2009/11/MSlotteryscam.PNG"><img class="aligncenter size-medium wp-image-222" title="MSlotteryscam" src="http://hijack-this.co.uk/wp-content/uploads/2009/11/MSlotteryscam-247x300.PNG" alt="MSlotteryscam" width="247" height="300" /></a></p>
Here is no comments yet by the time  your rss reader get this, Do you want to be the first commentor? Hurry up <p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2009/11/microsoft-lottery-spam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Phishing</title>
		<link>http://hijack-this.co.uk/2009/11/phishing/</link>
		<comments>http://hijack-this.co.uk/2009/11/phishing/#comments</comments>
		<pubDate>Sun, 08 Nov 2009 11:49:39 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=214</guid>
		<description><![CDATA[I mentioned previously HERE that the criminals doing these phishing attacks are changing tactics to make it harder for the antiphishing measures to block them We are seeing many more phishing attempts using the same technique of sending an HTML page as an attachment to an email and asking you, the victim, to fill in the [...]]]></description>
			<content:encoded><![CDATA[<p>I mentioned previously <a href="http://hijack-this.co.uk/?p=176">HERE</a> that the criminals doing these phishing attacks are changing tactics to make it harder for the antiphishing measures to block them</p>
<p>We are seeing many more phishing attempts using the same technique of sending an HTML page as an attachment to an email and asking you, the victim, to fill in the form</p>
<p>Many people are falling for this, even more than those who click on  link in an email. <span id="more-214"></span></p>
<p>Once again we warn that Banks, Building Societies, HMRC, Finance Companies, Ebay, Paypal and Government Departments will not send an email with a PDF to fill or a web page form to fill in asking for user name, password, date of birth, address, Mothers maiden name, Place of birth, favorite color or anything else that can be used to steal your identity. Most of all they <strong>NEVER, NEVER, NEVER</strong> ask for your credit or debit card details, pin number or log in password.</p>
<p><a href="http://hijack-this.co.uk/wp-content/uploads/2009/11/barclay_phish.png"><img class="alignleft size-medium wp-image-215" title="barclay_phish" src="http://hijack-this.co.uk/wp-content/uploads/2009/11/barclay_phish-229x300.png" alt="barclay_phish" width="229" height="300" /></a></p>
Here is no comments yet by the time  your rss reader get this, Do you want to be the first commentor? Hurry up <p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2009/11/phishing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>More HMRC Phishing and very difficult to block</title>
		<link>http://hijack-this.co.uk/2009/10/more-hmrc-phishing-and-very-difficult-to-block/</link>
		<comments>http://hijack-this.co.uk/2009/10/more-hmrc-phishing-and-very-difficult-to-block/#comments</comments>
		<pubDate>Mon, 19 Oct 2009 12:51:26 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=176</guid>
		<description><![CDATA[I am getting concerned at the latest phishing attacks aimed at UK citizens who have to submit tax returns by November The Anti-phishing sites are unable to block the sites or warn you that you are on a phishing site  because the html is a web page on your computer so NEVER checked Even if [...]]]></description>
			<content:encoded><![CDATA[<p>I am getting concerned at the latest phishing attacks aimed at UK citizens who have to submit tax returns by November</p>
<p>The Anti-phishing sites are unable to block the sites or warn you that you are on a phishing site  because the html is a web page on your computer so NEVER checked</p>
<p>Even if you press submit, it bounces immediately to the genuine HMRC site so isn&#8217;t blocked <span id="more-176"></span><br />
Currently spreading in UK are emails pretending to come from HMRC ( Inland Revenue/Tax Office) telling you of a tax refund due to you. For a change they don&#8217;t ask you to follow a link directly but to open the attached HTML file ( web page) on your local computer to fill in the form</p>
<p><a href="http://hijack-this.co.uk/wp-content/uploads/2009/10/hmrc_email2.PNG"><img class="aligncenter size-medium wp-image-177" title="hmrc_email2" src="http://hijack-this.co.uk/wp-content/uploads/2009/10/hmrc_email2-300x243.PNG" alt="hmrc_email2" width="300" height="243" /></a></p>
<p>The webpage looks like</p>
<p><a href="http://hijack-this.co.uk/wp-content/uploads/2009/10/hmrc2.PNG"><img class="aligncenter size-medium wp-image-178" title="hmrc2" src="http://hijack-this.co.uk/wp-content/uploads/2009/10/hmrc2-276x300.PNG" alt="hmrc2" width="276" height="300" /></a></p>
<p>As usual the advice is be very wary, don&#8217;t save or open attached HTML files from anybody especially those that pretend to come from a Government department or  bank. They will <strong>ALWAYS</strong> be fraudulent</p>
<p>If you have unwittingly made a mistake &amp; entered your details:  get in touch with your bank immediately and inform them that your credit/debit card details have been stolen and  immediately report it to the police. Don&#8217;t let the police fob you off with &#8221; we don&#8217;t deal with that sort of thing&#8221;. Insist on a crime being reported and take &amp; keep the crime reference number</p>
Here is no comments yet by the time  your rss reader get this, Do you want to be the first commentor? Hurry up <p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2009/10/more-hmrc-phishing-and-very-difficult-to-block/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Outlook Web Access Social Engineering Malware Scam &#8211; Security Labs Alert</title>
		<link>http://hijack-this.co.uk/2009/10/outlook-web-access-social-engineering-malware-scam-security-labs-alert/</link>
		<comments>http://hijack-this.co.uk/2009/10/outlook-web-access-social-engineering-malware-scam-security-labs-alert/#comments</comments>
		<pubDate>Thu, 15 Oct 2009 06:33:59 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[Antivirus]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>
		<category><![CDATA[microsoft]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=156</guid>
		<description><![CDATA[Websense® Security Labs™ ThreatSeeker™ Network has discovered a new wave of malicious attacks claiming to be an update for Microsoft Outlook Web Access (OWA). Victims receive a message leading to a site to apply mailbox settings which were supposedly changed due to a &#8220;security upgrade.&#8221; The especially dangerous thing about these messages is that they [...]]]></description>
			<content:encoded><![CDATA[<p>Websense® Security Labs™ ThreatSeeker™ Network has discovered a new wave of malicious attacks claiming to be an update for Microsoft Outlook Web Access (OWA). Victims receive a message leading to a site to apply mailbox settings which were supposedly changed due to a &#8220;security upgrade.&#8221;<span id="more-156"></span></p>
<p>The especially dangerous thing about these messages is that they are very deceiving.</p>
<p> The messages and attack pages are personalized for the To: email address to imply the message is being sent from tech support of the domain.</p>
<p>The URL in the email looks like it leads to the company&#8217;s own OWA system.</p>
<p> We have seen upwards of 30,000 of these messages per hour and they have low AV detection.</p>
<p>via <a href="http://securitylabs.websense.com/content/Alerts/3491.aspx">Outlook Web Access Social Engineering Malware Scam &#8211; Security Labs Alert</a>.</p>
Here is no comments yet by the time  your rss reader get this, Do you want to be the first commentor? Hurry up <p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2009/10/outlook-web-access-social-engineering-malware-scam-security-labs-alert/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Brazilian criminals create malicious proxies</title>
		<link>http://hijack-this.co.uk/2009/10/brazilian-criminals-create-malicious-proxies/</link>
		<comments>http://hijack-this.co.uk/2009/10/brazilian-criminals-create-malicious-proxies/#comments</comments>
		<pubDate>Sat, 10 Oct 2009 08:00:09 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=130</guid>
		<description><![CDATA[This post was originally  an automatic machine translation from http://www.linhadefensiva.org/2009/07/criminosos-brasileiros-criam-proxies-maliciosos/  a security blog written in Portugese (Brazillian). I have attempted to correct the translation and add a few other comments We see the same problems in English &#38; every other language  so please read &#38; follow the advice: Brazilian criminals create malicious proxies By changing the settings [...]]]></description>
			<content:encoded><![CDATA[<p>This post was originally  an automatic machine translation from<a href="http://www.linhadefensiva.org/2009/07/criminosos-brasileiros-criam-proxies-maliciosos/" target="_blank"> http://www.linhadefensiva.org/2009/07/criminosos-brasileiros-criam-proxies-maliciosos/</a>  a security blog written in Portugese (Brazillian). I have attempted to correct the translation and add a few other comments</p>
<p>We see the same problems in English &amp; every other language  so please read &amp; follow the advice:</p>
<p>Brazilian criminals create malicious proxies<br />
By changing the settings of the major browsers, criminals can direct users to false bank pages or false search engines</p>
<p>A  new technique of targeting using proxy services is being operated by  Brazilian and other cybercriminals. <span id="more-130"></span></p>
<h2>.PAC files</h2>
<p>The attack begins when the user opens infected  emails or attachments. From that moment the virus will change yourbrowser settings, adding network options in a URL to a file.</p>
<p> <a href="http://en.wikipedia.org/wiki/Proxy_auto-config" target="_blank">.PAC </a>(proxy auto-config) are legitimate, but can be used in a malicious manner, such as in these cases. They are made in JavaScript scripts that define which Internet pages will be answered by a given server, acting as proxy.<br />
On trying to access the pages of the main Brazilian and other  banks, you are directed to a fake site serving pages that look identical to the legitimate bank site and often with the correct bank URL in the address bar,  This allows the crimianls to steal your financial data.</p>
<p><strong>This affects any version of Internet Explorer,  Firefox,  Chrome, Safari and any other browser</strong>. Programs like instant messengers and web updaters that use the same settings as Internet Explorer are also affected.</p>
<h2>How do you know if you are infected</h2>
<p>In Internet Explorer, go to the Tools menu, click Internet options. Connection tab, click LAN settings. See in the box that opens if there are anyentries in &#8220;use automatic configuration script&#8221;. If any are there remove the entry, then uncheck &#8220;use automatic configuration script&#8221;. Also check lower down &#8220;use a proxy server&#8221; because different malwares can set a specific proxy there. If you didn&#8217;t set the proxy yourself ( many ISPs or corporate networks do set this proxy) then remove the entry and uncheck the &#8220;use proxy server&#8221; check, Press OK or Apply</p>
<p><img class="size-medium wp-image-131 alignnone" title="IE_proxy" src="http://hijack-this.co.uk/wp-content/uploads/2009/10/IE_proxy-300x274.png" alt="IE_proxy" width="300" height="274" /></p>
<p> Firefox, go to the Tools menu, options. On the Advanced tab, go to the network option and click the &#8220;configure connection&#8221; button. In the box that open, look at the item &#8220;address&#8221; proxy auto-configuration if there is any URL. If any, remove it. Also check the manual proxy configuration and if not set by you, fix in the same  was as I previously described for internet explorer.</p>
<p><img class="aligncenter size-medium wp-image-133" title="ff_proxy" src="http://hijack-this.co.uk/wp-content/uploads/2009/10/ff_proxy1-291x300.png" alt="ff_proxy" width="291" height="300" /></p>
<p>The defensive line team notified the CERT Brazil to take reasonable precautions for the removal of malicious servers, because many of them are located in Brazil.</p>
<p>If you suspect you are infected by a banker trojan, suffer from any diverts, pop ups or other strange or worrying symptoms  please ask for help on our help forum <a href="http://thespykiller.co.uk" target="_blank">TheSpykiller</a></p>
By the time  your rss reader get this post here is <strong> 2 </strong>comments ,Welcome you come to leave your opinion !<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2009/10/brazilian-criminals-create-malicious-proxies/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Kaspersky 2010</title>
		<link>http://hijack-this.co.uk/2009/10/kaspersky-2010/</link>
		<comments>http://hijack-this.co.uk/2009/10/kaspersky-2010/#comments</comments>
		<pubDate>Fri, 09 Oct 2009 10:48:53 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[Antivirus]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=122</guid>
		<description><![CDATA[Here is no comments yet by the time your rss reader get this, Do you want to be the first commentor? Hurry up]]></description>
			<content:encoded><![CDATA[<p><br />
<center><object width="425" height="344"><param name="movie" value="http://www.youtube.com/v/kbRSQVsOX_Y&#038;color1=0xb1b1b1&#038;color2=0xcfcfcf&#038;feature=player_embedded&#038;fs=1"></param><param name="allowFullScreen" value="true"></param><param name="allowScriptAccess" value="always"></param><embed src="http://www.youtube.com/v/kbRSQVsOX_Y&#038;color1=0xb1b1b1&#038;color2=0xcfcfcf&#038;feature=player_embedded&#038;fs=1" type="application/x-shockwave-flash" allowfullscreen="true" allowScriptAccess="always" width="425" height="344"></embed></object></center></p>
Here is no comments yet by the time  your rss reader get this, Do you want to be the first commentor? Hurry up <p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2009/10/kaspersky-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>12345 the most popular phished Hotmail password</title>
		<link>http://hijack-this.co.uk/2009/10/12345-the-most-popular-phished-hotmail-password/</link>
		<comments>http://hijack-this.co.uk/2009/10/12345-the-most-popular-phished-hotmail-password/#comments</comments>
		<pubDate>Fri, 09 Oct 2009 08:59:37 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=117</guid>
		<description><![CDATA[The phishing attack that exposed the details of 10,000 Hotmail users has revealed that 12345 was the most popular password of those caught out, according to a security researcher. That&#8217;s alarming news given the glut of information and warnings that pepper the internet, especially given the fact that the second most popular password was 123456789. [...]]]></description>
			<content:encoded><![CDATA[<p>The phishing attack that exposed the details of 10,000 Hotmail users has revealed that 12345 was the most popular password of those caught out, according to a security researcher.</p>
<p>That&#8217;s alarming news given the glut of information and warnings that pepper the internet, especially given the fact that the second most popular password was 123456789. </p>
<p>The information was revealed by security research Bogdan Calin on his<a href="http://www.acunetix.com/blog/websecuritynews/statistics-from-10000-leaked-hotmail-passwords/" target="_blank"> blog</a>. Calin reviewed the list of 10,000 Hotmail accounts posted on PasteBin by hackers and discovered that of the 9,843 valid passwords, 82 of them used one of these two numbers.</p>
<p>Also popular, and equally weak, were the passwords 12345678, 1234567 and 111111 &#8211; which all featured in the top ten.</p>
<p>via <a href="http://www.itpro.co.uk/616039/12345-the-most-popular-phished-hotmail-password?CMP=NLC-Newsletters&amp;uid=16a73be7477c37f837f18728159fc893" target="_blank">&#8217;12345&#8242; the most popular phished Hotmail password | IT PRO</a>.</p>
Here is no comments yet by the time  your rss reader get this, Do you want to be the first commentor? Hurry up <p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2009/10/12345-the-most-popular-phished-hotmail-password/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
