Beware: Phishing and Spam in Social Networks

Trend Micro warns us today about how spam and phishing can hit you even in the closed ecosystem of a social networking system such as Facebook. Malware abounds. And in the social network arena, just like anywhere else, “using your account to send spam” is a common thing for the bad guys to want to do.
In Rik Ferguson’s investigation (which I read about on CNet News), he came across a link to a URL that asked for his Facebook credentials, supposedly necessary to allow installation of a specific Facebook application. Once the credentials were handed over, the app immediately spammed all of his Facebook friends, sending them a bogus notification, attempting to draw them into visiting the phishing/malware URL, with (one assumes) the hope of spreading the infection even wider.
He’s a researcher for Trend Micro, so he knows what he’s doing. But for the rest of us, this highlights how necessary it is to be careful with who you give your usernames and passwords to. In my opinion, it’s never safe to take your username and password from one site and hand it over to another site. Some social networking make the problem even worse by blurring the lines between safe and unsafe by asking for usernames and passwords to third party accounts, but you just can never know with 100% certainty which sites are legitimate and which ones aren’t.
— Al Iverson

Related Posts

Spam judgment not covered by insurance

Earlier this month a judge ruled that two insurance policies held by Scott Richter’s Media Breakaway were not liable to pay $6M in damages awarded in a previous case.
Myspace initially sued Media Breakaway in 2007 for allegedly using phished Myspace accounts to send emails advertising Media Breakaway websites. In summer 2008 and arbiter ruled in favor of Myspace and against Media Breakaway. After the ruling, Media Breakaway attempted to have insurance cover the fine. The insurance company denied the claims so Media Breakaway took them to court. Media Breakaway lost.
Scott has been around in the email marketing arena for a very long time. He’s had multiple run ins with the law, including a 2003 felony theft charge for stealing a number of things, including a Bobcat loader and a 2004 suit brought against him by the NY Attorney General’s office and Microsoft for spamming and deceptive advertising. That court case bankrupted his previous company, OptInRealBig. Scott has also appeared on the Daily Show, in a side-splittingly funny story about spam and email marketing…. er… high volume email deploying.

Read More

Contact addresses and spam

One of the challenges anyone doing business on the internet faces is how to provide contact information so that potential customers can reach you in a form that spammers can’t easily abuse. Contact forms are the classic method, but they can (and are) abused by spammers. We decided to try something different. About 2 months ago, we started using rotating contact addresses. Every day a new address is deployed on the contact form on our website. Each address is valid for a fixed period of time, and is then retired.
This seems to be working well for us. Spammers are harvesting the email addresses, but because they are only valid for a fixed period of time, the amount of spam in my mailbox is not overwhelming. I am spending less time searching for sales mails through spam. An interesting side effect is I can actually see who is harvesting addresses and spamming.
It’s not perfect, I’m still getting spam to that address. But it’s spam at a level where I’m not losing real mail.

Read More