<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Advice on Omid Farhang</title><link>https://omid.dev/tags/advice/</link><description>Recent content in Advice on Omid Farhang</description><image><title>Omid Farhang</title><url>https://omid.dev/images/bio-photo-150x150.jpg</url><link>https://omid.dev/images/bio-photo-150x150.jpg</link></image><generator>Hugo -- 0.163.3</generator><language>en-US</language><copyright>2026 Omid Farhang | All rights reserved.</copyright><lastBuildDate>Thu, 14 Feb 2013 21:20:00 +0000</lastBuildDate><atom:link href="https://omid.dev/tags/advice/index.xml" rel="self" type="application/rss+xml"/><atom:link href="https://pubsubhubbub.appspot.com/" rel="hub"/><item><title>New Adobe Vulnerabilities Being Exploited in the Wild</title><link>https://omid.dev/2013/02/14/new-adobe-vulnerabilities-being-exploited-in-the-wild/</link><pubDate>Thu, 14 Feb 2013 21:20:00 +0000</pubDate><guid>https://omid.dev/2013/02/14/new-adobe-vulnerabilities-being-exploited-in-the-wild/</guid><description>&lt;p&gt;&lt;img loading="lazy" src="http://lh5.ggpht.com/-otQzf_U6G6Q/UR1OFgU5RTI/AAAAAAAAHwg/7N4Pyc1bSnA/s1600-h/adobe%252520reader%25255B6%25255D.jpg" alt="adobe reader" /&gt;
&lt;/p&gt;
&lt;p&gt;Adobe posted a &lt;a href="http://blogs.adobe.com/psirt/2013/02/adobe-reader-and-acrobat-vulnerability-report.html"&gt;vulnerability report&lt;/a&gt; warning that vulnerabilities in Adobe Reader and Acrobat XI (11.0.1) and earlier versions are being exploited in the wild. Adobe is currently investigating this issue.&lt;/p&gt;
&lt;p&gt;According to the &lt;a href="http://blog.fireeye.com/research/2013/02/in-turn-its-pdf-time.html"&gt;FireEye blog&lt;/a&gt; posted earlier today, the malicious file arrives as a PDF file. Upon successful exploitation of the vulnerabilities, two malicious DLL files are dropped.&lt;/p&gt;
&lt;p&gt;Symantec detects the malicious PDF file as &lt;a href="http://www.symantec.com/security_response/writeup.jsp?docid=2009-121708-1022-99"&gt;Trojan.Pidief&lt;/a&gt; and the two dropped DLL files as &lt;a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-021914-2822-99"&gt;Trojan Horse&lt;/a&gt;.&lt;/p&gt;</description></item><item><title>Internet Explorer security hole: Use other browser</title><link>https://omid.dev/2012/09/18/internet-explorer-security-hole-use-other-browser/</link><pubDate>Tue, 18 Sep 2012 16:22:00 +0000</pubDate><guid>https://omid.dev/2012/09/18/internet-explorer-security-hole-use-other-browser/</guid><description>&lt;p&gt;&lt;strong&gt;TheTelegraph: Internet Explorer users might want to consider upgrading or switching to another browser after a massive security hole was discovered in Windows&amp;rsquo; native web browser.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;img loading="lazy" src="http://lh3.ggpht.com/-0Bv3ALH0CoQ/UFiYtKVSU0I/AAAAAAAAHc8/1JyUQDPOw20/s1600-h/internetexplorer9logo%25255B3%25255D.png" alt="internetexplorer9logo" /&gt;
&lt;/p&gt;
&lt;p&gt;According to security forum, Rapid7 , Internet Explorer 7, 8 and 9 operating on Windows XP, Vista and Seven contains what is known as a “zero day exploit” which allows attackers to gain access to your personal data while you browse.&lt;/p&gt;
&lt;p&gt;The forum claimed the exploit would give cyber criminals “the same privileges as the current user”.&lt;/p&gt;</description></item><item><title>Oracle rushes out patch for critical 0-day Java exploit</title><link>https://omid.dev/2012/08/31/oracle-rushes-out-patch-for-critical-0-day-java-exploit/</link><pubDate>Fri, 31 Aug 2012 14:17:00 +0000</pubDate><guid>https://omid.dev/2012/08/31/oracle-rushes-out-patch-for-critical-0-day-java-exploit/</guid><description>&lt;p&gt;&lt;img loading="lazy" src="http://lh6.ggpht.com/-wPwb8KpcqAo/UEDAS4TObCI/AAAAAAAAHR4/xIkTWQH65oM/s1600-h/Java%25255B3%25255D.jpg" alt="Java" /&gt;
&lt;/p&gt;
&lt;p&gt;TheRegister: In an uncommon break with its thrice-annual security update schedule, Oracle has released a patch for three Java 7 security flaws that have recently been targeted by web-based exploits.&lt;/p&gt;
&lt;p&gt;“Due to the high severity of these vulnerabilities, Oracle recommends that customers apply this Security Alert as soon as possible,” Eric Maurice, the company&amp;rsquo;s director of software security assurance, said in a &lt;a href="https://blogs.oracle.com/security/entry/security_alert_for_cve_20121"&gt;blog post&lt;/a&gt; published on Thursday.&lt;/p&gt;
&lt;p&gt;Maurice said that the vulnerabilities patched only affect Java running in browsers, and not standalone desktop Java applications or Java running on servers. According to Oracle&amp;rsquo;s &lt;a href="http://www.oracle.com/technetwork/topics/security/alert-cve-2012-4681-1835715.html"&gt;official advisory&lt;/a&gt; on the flaws:&lt;/p&gt;</description></item><item><title>Java zero day vulnerability actively used in targeted attacks</title><link>https://omid.dev/2012/08/27/java-zero-day-vulnerability-actively-used-in-targeted-attacks/</link><pubDate>Mon, 27 Aug 2012 19:50:00 +0000</pubDate><guid>https://omid.dev/2012/08/27/java-zero-day-vulnerability-actively-used-in-targeted-attacks/</guid><description>&lt;p&gt;&lt;a href="http://www.zdnet.com/java-zero-day-vulnerability-actively-used-in-targeted-attacks-7000003233/"&gt;&lt;img loading="lazy" src="http://lh4.ggpht.com/-Z71qqXKB38g/UDvIjUWvYyI/AAAAAAAAHPQ/S_hkki2ZjnU/Java%25255B9%25255D.jpg?imgmax=800" alt="Java" /&gt;
ZDNet&lt;/a&gt;: Security researchers from &lt;a href="http://blog.fireeye.com/research/2012/08/zero-day-season-is-not-over-yet.html"&gt;FireEye&lt;/a&gt;, &lt;a href="http://labs.alienvault.com/labs/index.php/2012/new-java-0day-exploited-in-the-wild/"&gt;AlienVault&lt;/a&gt;, and &lt;a href="http://www.deependresearch.org/2012/08/java-7-0-day-vulnerability-information.html"&gt;DeependResearch&lt;/a&gt; have intercepted targeted malware attacks utilizing the latest Java zero day exploit. The vulnerability affects Java 7 (1.7) Update 0 to 6. It does not affect Java 6 and below.&lt;/p&gt;
&lt;p&gt;Based on &lt;a href="https://community.rapid7.com/community/metasploit/blog/2012/08/27/lets-start-the-week-with-a-new-java-0day"&gt;related reports&lt;/a&gt;, researchers were able to reproduce the exploit on Windows 7 SP1 with Java 7 Update 6. There&amp;rsquo;s also &lt;a href="https://community.rapid7.com/community/metasploit/blog/2012/08/27/lets-start-the-week-with-a-new-java-0day"&gt;a Metasploit module&lt;/a&gt; available.&lt;/p&gt;
&lt;p&gt;Upon successful exploitation, the campaign drops &lt;a href="https://www.virustotal.com/file/09d10ae0f763e91982e1c276aad0b26a575840ad986b8f53553a4ea0a948200f/analysis/1346055031/"&gt;MD5: 4a55bf1448262bf71707eef7fc168f7d&lt;/a&gt; – detected by 28 out of 42 antivirus scanners as Gen:Trojan.Heur.FU.bqW@a4uT4@bb; Backdoor:Win32/Poison.E&lt;/p&gt;</description></item><item><title>Bogus anti-hacking tool targets Syrian activists</title><link>https://omid.dev/2012/08/19/bogus-anti-hacking-tool-targets-syrian-activists/</link><pubDate>Sun, 19 Aug 2012 09:01:00 +0000</pubDate><guid>https://omid.dev/2012/08/19/bogus-anti-hacking-tool-targets-syrian-activists/</guid><description>&lt;p&gt;&lt;img loading="lazy" src="http://lh3.ggpht.com/--Ib-1XvHins/UDCkRRX5xpI/AAAAAAAAG_0/tqI4jgZbpD8/s1600-h/Facebook_Anti-Hacker_screenshot%25255B10%25255D.png" alt="At one point, the AntiHacker malware even had its own Facebook group - now offline" /&gt;
&lt;/p&gt;
&lt;p&gt;h-online: Syrian activists, journalists and opposition group members are &lt;a href="https://www.eff.org/deeplinks/2012/08/syrian-malware-post"&gt;reportedly&lt;/a&gt; under attack by malware claiming to be a security tool that will help protect them against hackers. The fake “AntiHacker” tool is being spread through targeted phishing emails and via sites such as Facebook, and claims to provide “Auto-Protect &amp;amp; Auto-Detect &amp;amp; Security &amp;amp; Quick scan and analyzing” functionality.&lt;/p&gt;</description></item><item><title>Ladies with few clothes tend to cause a lot of trouble on PCs – and now on Android devices too</title><link>https://omid.dev/2012/08/02/ladies-with-few-clothes-tend-to-cause-a-lot-of-trouble-on-pcs-and-now-on-android-devices-too/</link><pubDate>Thu, 02 Aug 2012 14:21:00 +0000</pubDate><guid>https://omid.dev/2012/08/02/ladies-with-few-clothes-tend-to-cause-a-lot-of-trouble-on-pcs-and-now-on-android-devices-too/</guid><description>&lt;p&gt;Cross-posted from Surelist&lt;/p&gt;
&lt;p&gt;The appearance of a new Android malware family is not that surprising at all today. Especially when we talk about SMS Trojans which are one of the most popular and oldest type of threats created for extracting money from users. A new family of SMS Trojans named &lt;strong&gt;Vidro&lt;/strong&gt; appeared a few days ago but we’ve already collected a lot of APK files with very similar functionality. At the moment all the samples we have found target users only from Poland.&lt;/p&gt;</description></item><item><title>Android Forums hacked: 1 million user credentials stolen</title><link>https://omid.dev/2012/07/13/android-forums-hacked-1-million-user-credentials-stolen/</link><pubDate>Fri, 13 Jul 2012 09:08:00 +0000</pubDate><guid>https://omid.dev/2012/07/13/android-forums-hacked-1-million-user-credentials-stolen/</guid><description>&lt;p&gt;&lt;strong&gt;ZDNet:&lt;/strong&gt; &lt;em&gt;Phandroid&amp;rsquo;s AndroidForums.com has been hacked. The database that powers the site was compromised and more than 1 million user account details were stolen. If you use the forum, make sure to change your password asap.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;img loading="lazy" src="http://lh6.ggpht.com/-RquPsbR9PwE/T__eZBP2xvI/AAAAAAAAGbU/jhfQsOu8alY/s1600-h/androidforums%25255B4%25255D.png" alt="androidforums" /&gt;
&lt;/p&gt;
&lt;p&gt;Read the whole story at ZDNet: &lt;a href="http://www.zdnet.com/android-forums-hacked-1-million-user-credentials-stolen-7000000817/"&gt;http://www.zdnet.com/android-forums-hacked-1-million-user-credentials-stolen-7000000817/&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Yahoo! Voice reportedly compromised, over 453,000 credentials exposed</title><link>https://omid.dev/2012/07/12/yahoo-voice-reportedly-compromised-over-453000-credentials-exposed/</link><pubDate>Thu, 12 Jul 2012 08:39:00 +0000</pubDate><guid>https://omid.dev/2012/07/12/yahoo-voice-reportedly-compromised-over-453000-credentials-exposed/</guid><description>&lt;p&gt;&lt;img loading="lazy" src="http://lh4.ggpht.com/-gVQEO5lHFc0/T_6GN1uqvfI/AAAAAAAAGa8/UP3m7Jys0zk/s1600-h/compromised_passwords%25255B4%25255D.jpg" alt="compromised_passwords" /&gt;
&lt;/p&gt;
&lt;p&gt;&lt;cite&gt;Übergizmo wrote: &lt;/cite&gt;If you use Yahoo! Voice a lot – Yahoo’s VoIP service via its Yahoo! Messenger instant messaging application, then you will definitely need to hear this report. Earlier today, more than 453,000 user accounts from an unidentified service owned by Yahoo were posted on a hacker site. The hackers reportedly said that they infiltrated the subdomain by using a union-based &lt;a href="http://hakipedia.com/index.php/SQL_Injection"&gt;SQL injection&lt;/a&gt;. But the group responsible for the security breach added that the data breach was intended to be a wake-up call for Yahoo.&lt;/p&gt;</description></item><item><title>Important: Today is your last chance to keep your internet connection</title><link>https://omid.dev/2012/07/08/important-today-is-your-last-chance-to-keep-your-internet-connection/</link><pubDate>Sun, 08 Jul 2012 15:41:00 +0000</pubDate><guid>https://omid.dev/2012/07/08/important-today-is-your-last-chance-to-keep-your-internet-connection/</guid><description>&lt;p&gt;&lt;img loading="lazy" src="http://lh6.ggpht.com/-lra1MhQaWNs/T_mjIjxGARI/AAAAAAAAGak/An-IiSoRXj0/s1600-h/March8Internet_main_0227%25255B4%25255D.jpg" alt="March8Internet_main_0227" /&gt;
&lt;/p&gt;
&lt;p&gt;Tomorrow, &lt;strong&gt;July 9th&lt;/strong&gt;, the FBI will shutdown the DNS servers which allow the computers infected with this malware to use the Internet.&lt;/p&gt;
&lt;p&gt;If you want to make sure you will keep your internet working, act today and check your computer to see if it’s infected by DNS Changer or not, here is a very easy to use tool: &lt;a href="http://www.avira.com/en/support-for-home-knowledgebase-detail/kbid/1199"&gt;Tool available for those affected by the DNS-Changer&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Password leaks bigger than first thought</title><link>https://omid.dev/2012/06/09/password-leaks-bigger-than-first-thought/</link><pubDate>Sat, 09 Jun 2012 12:48:00 +0000</pubDate><guid>https://omid.dev/2012/06/09/password-leaks-bigger-than-first-thought/</guid><description>&lt;p&gt;&lt;img loading="lazy" src="https://omid.dev/images/2012/06/screenshot-08Jun12.png" alt="The published password hashes do not contain any email addresses or usernames" /&gt;
The H-Online: There have still been no official statements on the causes and extent of the recent password leaks at &lt;a href="https://omid.dev/2012/06/linkedin-passwords-in-circulation.html"&gt;LinkedIn&lt;/a&gt;, &lt;a href="http://www.h-online.com/news/item/eHarmony-admits-to-leaking-1-5-million-passwords-1612654.html"&gt;eHarmony&lt;/a&gt; and &lt;a href="https://omid.dev/2012/06/millions-of-lastfm-passwords-leaked.html"&gt;Last.fm&lt;/a&gt;. A credible source is now reporting that the published 2.5 million Last.fm MD5 hashes, for example, are just the tip of a 17 million hash iceberg. That iceberg has reportedly been circulating since summer 2011.16.4 million of these – 95 per cent – have, the source claims, already been cracked, a claim which, for unsalted hashes, is entirely credible.&lt;/p&gt;</description></item><item><title>Millions of Last.fm passwords leaked</title><link>https://omid.dev/2012/06/09/millions-of-last-fm-passwords-leaked/</link><pubDate>Sat, 09 Jun 2012 12:43:00 +0000</pubDate><guid>https://omid.dev/2012/06/09/millions-of-last-fm-passwords-leaked/</guid><description>&lt;p&gt;&lt;img loading="lazy" src="http://lh6.ggpht.com/-S3R_neFyA6k/T9M95dipghI/AAAAAAAAGNg/ySAo5xvDO0U/s1600-h/lastfm_red%25255B2%25255D.gif" alt="lastfm_red" /&gt;
&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The H-Online:&lt;/strong&gt; A list with several million passwords belonging to users of the music community site &lt;a href="http://www.last.fm/"&gt;Last.fm&lt;/a&gt; has been posted on the internet. The site owners have posted &lt;a href="http://www.lastfm.de/passwordsecurity"&gt;a statement&lt;/a&gt; saying that the company is investigating the leak and that all users of the service should change their passwords immediately. This is the third major compromise of a popular web site&amp;rsquo;s passwords in as many days.&lt;/p&gt;
&lt;p&gt;The H&amp;rsquo;s associates at heise Security are in possession of a list containing approximately 2.5 million password hashes. Like the recently leaked data from &lt;a href="http://www.h-online.com/news/item/eHarmony-admits-to-leaking-1-5-million-passwords-1612654.html"&gt;eHarmony&lt;/a&gt;, these are unsalted MD5 hashes that are trivial to crack in today&amp;rsquo;s world of fast CPU and GPU hardware and specialised techniques such as using &lt;a href="http://www.h-online.com/security/features/Cheap-Cracks-Of-dictionaries-and-rainbows-746217.html"&gt;rainbow tables&lt;/a&gt;. At least one million of these hashes have already been cracked and the clear text passwords have also been posted on the internet. The hashes that were leaked from &lt;a href="https://omid.dev/2012/06/linkedin-passwords-in-circulation.html"&gt;LinkedIn&lt;/a&gt; were generated using the SHA-1 algorithm.&lt;/p&gt;</description></item><item><title>LinkedIn passwords in circulation</title><link>https://omid.dev/2012/06/06/linkedin-passwords-in-circulation/</link><pubDate>Wed, 06 Jun 2012 16:42:00 +0000</pubDate><guid>https://omid.dev/2012/06/06/linkedin-passwords-in-circulation/</guid><description>&lt;p&gt;&lt;img loading="lazy" src="https://omid.dev/images/2012/02/LinkedIn_logo_initials-150x150.png" alt="LinkedIn_logo_initials" /&gt;
&lt;/p&gt;
&lt;p&gt;H-Online: Internet forums are currently circulating a list containing over six million password hashes which allegedly originate from &lt;a href="https://www.linkedin.com/"&gt;LinkedIn&lt;/a&gt;. The passwords are being cracked collaboratively with about 300,000 passwords already published as plaintext.&lt;/p&gt;
&lt;p&gt;The list contains pure SHA1 hashes with no name or email addresses. If decrypted, the passwords will not easily give access to an appropriate account. However, it is probable that the person who captured the hashes also has the corresponding email addresses. In an initial sampling, &lt;strong&gt;The H&lt;/strong&gt;‘s associates at heise Security didn&amp;rsquo;t find any known LinkedIn passwords in the list, but with over 160 million members that doesn&amp;rsquo;t mean a lot. The already cracked passwords often contain “linked” or even “linkedin” in the form, for example, of “lawrencelinkedin”. This suggests that the passwords actually come from the LinkedIn social network. However, this has not yet been confirmed.&lt;/p&gt;</description></item><item><title>Avira AV update hangs systems</title><link>https://omid.dev/2012/05/15/avira-av-update-hangs-systems/</link><pubDate>Tue, 15 May 2012 14:46:00 +0000</pubDate><guid>https://omid.dev/2012/05/15/avira-av-update-hangs-systems/</guid><description>&lt;p&gt;&lt;a href="http://www.h-online.com/security/news/item/Avira-AV-update-hangs-systems-1575974.html"&gt;&lt;strong&gt;H-Online Says:&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;img loading="lazy" src="http://lh5.ggpht.com/-7eHRK6IOMGc/T7JlKIRe20I/AAAAAAAAF-k/7kXaHLSMbYs/s1600-h/avira_logo_red_rgb%252520%2525282%252529%25255B3%25255D.jpg" alt="avira_logo_red_rgb (2)" /&gt;
&lt;/p&gt;
&lt;p&gt;A faulty update for &lt;a href="http://www.avira.com/en/index"&gt;Avira&lt;/a&gt;‘s paid-for anti-virus software blocks harmless processes and may in some cases stop computers from booting. The update results in the ProActiv behavioral monitoring component becoming oversensitive in its treatment of executable files.&lt;/p&gt;
&lt;p&gt;According to &lt;a href="http://forum.avira.com/wbb/index.php?page=Thread&amp;amp;threadID=144883&amp;amp;pageNo=1"&gt;user reports&lt;/a&gt;, ProActiv blocks trusted system processes such as cmd.exe, rundll32.exe, taskeng.exe, wuauclt.exe, dllhost.exe, iexplore.exe, notepad.exe and regedit.exe. In some cases this results in Windows failing to boot properly. It also appears to be blocking non-OS applications such as Microsoft Office, the Opera web browser and Google&amp;rsquo;s Updater program.&lt;/p&gt;</description></item><item><title>WikiPharmacy? Fake Notifications Spammed Out</title><link>https://omid.dev/2012/04/26/wikipharmacy-fake-notifications-spammed-out/</link><pubDate>Thu, 26 Apr 2012 15:03:00 +0000</pubDate><guid>https://omid.dev/2012/04/26/wikipharmacy-fake-notifications-spammed-out/</guid><description>&lt;p&gt;Symantec Connect: Symantec is intercepting a resurgence of spam attacks on popular brands. Spam messages that are replicas of the Wikipedia email address confirmation alert are the new vector for the present. The said spam messages pretend to be originating from Wikipedia, and are selling meds, with the following subject line: “&lt;em&gt;Subject:&lt;/em&gt; &lt;em&gt;Wikipedia e-mail address confirmation&lt;/em&gt;”.&lt;/p&gt;
&lt;p&gt;The spoofed Wikipedia page is a ploy to give legitimacy to the sale of meds online. The embedded URL in the message navigates to a fake online pharmacy site that is dressed up as a Wikipedia Web page. Furthermore, to give the email a legitimate look, the spammer has added the recipient’s IP address in the body of the spam mail. Needless to say this IP does not belong to the user.&lt;/p&gt;</description></item><item><title>Online forums hacked and misused on a large scale</title><link>https://omid.dev/2012/04/25/online-forums-hacked-and-misused-on-a-large-scale/</link><pubDate>Wed, 25 Apr 2012 20:20:00 +0000</pubDate><guid>https://omid.dev/2012/04/25/online-forums-hacked-and-misused-on-a-large-scale/</guid><description>&lt;p&gt;&lt;img loading="lazy" src="http://lh4.ggpht.com/-ugYDuGCnbtg/T5hVdq9BaKI/AAAAAAAAFsI/PLGFWSjJaKA/s1600-h/Forum_Ad_English%25255B2%25255D.jpg" alt="Forum_Ad_English" /&gt;
&lt;/p&gt;
&lt;p&gt;The H-Online: Online forums have, for some time, apparently been the target of hackers who inject additional code. However, the attackers aren&amp;rsquo;t interested in publishing cool slogans or political messages, they&amp;rsquo;re looking for money. They steal Google traffic from the forums and exploit this traffic via ads. Their main targets appear to be forums that are based on the &lt;a href="https://www.vbulletin.com/"&gt;vBulletin software&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Unlike the “Look how cool I am” crackers, these attackers have very discreet working methods. They hide their code deeply within the system and ensure that their redirections don&amp;rsquo;t attract much attention. Only users who visit forum pages for the first time via a search engine such as Google are redirected to a &lt;em&gt;url123.info&lt;/em&gt; URL. This site initially displays a strange blocking alert (“Access denied”) followed by some arbitrary text and then loads a full-page ad by InfinityAds. The ads are probably a direct source of income for the intruders even though each ad is only worth a few pennies. However, as some forum operators have reported that their &lt;a href="http://www.vbseo.com/f3/hacked-url123-info-53045/"&gt;traffic has dropped&lt;/a&gt; by more than 70 per cent, and the phenomenon seems to be a rather wide-spread one, the overall yield is likely to be considerable.&lt;/p&gt;</description></item><item><title>Fake Discount Cards</title><link>https://omid.dev/2012/04/24/fake-discount-cards/</link><pubDate>Tue, 24 Apr 2012 17:16:00 +0000</pubDate><guid>https://omid.dev/2012/04/24/fake-discount-cards/</guid><description>&lt;h4&gt;&lt;/h4&gt;
&lt;p&gt;Symantec Connect: Phishers are constantly developing new strategies in an effort to trick end users. In April 2012, phishers created sites spoofing the Apple brand with fake offers for Apple discount cards. In this phishing attack, customers were targeted by region: namely, the UK and Australia.&lt;/p&gt;
&lt;p&gt;&lt;img loading="lazy" src="http://lh6.ggpht.com/-y0RWmfJDCOE/T5bYwSnuk7I/AAAAAAAAFoo/dL0WLaBKomY/s1600-h/article%252520thumbnail%25255B4%25255D.jpg" alt="article thumbnail" /&gt;
&lt;/p&gt;
&lt;p&gt;The phishing sites mimicked the webpage of Apple and prompted customers for their Apple ID. The phishing page stated the customer’s long-term loyalty toward the brand gave them eligibility for an Apple discount card as a reward. Upon entering an Apple ID and clicking the “Next” button, the customer was redirected to a page that asked for more confidential information:&lt;/p&gt;</description></item><item><title>Sex Appeal Meter Scam and Execution Hoax Abound on Facebook</title><link>https://omid.dev/2012/03/29/sex-appeal-meter-scam-and-execution-hoax-abound-on-facebook/</link><pubDate>Thu, 29 Mar 2012 18:07:00 +0000</pubDate><guid>https://omid.dev/2012/03/29/sex-appeal-meter-scam-and-execution-hoax-abound-on-facebook/</guid><description>&lt;p&gt;&lt;em&gt;Cross posted from GFI, Sunbelt Blog:&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;There’s not a day when we don’t see a new &lt;strong&gt;scam&lt;/strong&gt; or &lt;strong&gt;hoax&lt;/strong&gt;—yes, even the old ones—being proliferated on &lt;strong&gt;Facebook&lt;/strong&gt;. I’ve seen both today. Let’s take a quick look at each one, shall we?&lt;/p&gt;
&lt;p&gt;First off, the scam:&lt;/p&gt;
&lt;p&gt;&lt;img loading="lazy" src="http://lh6.ggpht.com/-pjeLMZ_2TZY/T3SdYcrY3-I/AAAAAAAAFXA/RcYpdR6vU2I/s1600-h/01_sexappeal-fbwall%25255B3%25255D.jpg" alt="01_sexappeal-fbwall" /&gt;
&lt;/p&gt;
&lt;p&gt;The screenshot above is a post generated by the “&lt;strong&gt;Sexappeal Meter&lt;/strong&gt;” app that have spread within the social network. Clicking the &lt;em&gt;“How much Sexappeal you have”&lt;/em&gt; link, or sometimes a &lt;em&gt;bit.ly&lt;/em&gt; shortened URL, leads users to a page where it requests for permission just like any normal app. Allowing the app access to user profile, however, leads to two succeeding survey scam pages and, eventually, to a page where one can download a browser toolbar.&lt;/p&gt;</description></item><item><title>Free Stuff on Social Networks Not Free</title><link>https://omid.dev/2012/03/29/free-stuff-on-social-networks-not-free/</link><pubDate>Thu, 29 Mar 2012 15:22:00 +0000</pubDate><guid>https://omid.dev/2012/03/29/free-stuff-on-social-networks-not-free/</guid><description>&lt;p&gt;&lt;strong&gt;Symantec Connect:&lt;/strong&gt; In recent years, scammers have flocked towards social networking sites as they have grown and made it easier to access a large number of potential eyeballs to convert into dollars. Brands have found value in leveraging social media to know what their customers are talking about, so, naturally, scammers are doing the exact same thing.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Free iPads and iPhones&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Every time Apple unveils a new iPad or iPhone, you can bet there are scammers out there trying to leverage the announcement for financial gain. In the days leading up to and after the announcement of the new third-generation iPad, Twitter users who tweet about the new tablet most likely will receive some targeted Twitter replies from scammers offering the new device for free:&lt;/p&gt;</description></item><item><title>Fake AICPA Mail Serves Blackholes and Rootkits</title><link>https://omid.dev/2012/02/21/fake-aicpa-mail-serves-blackholes-and-rootkits/</link><pubDate>Tue, 21 Feb 2012 20:29:00 +0000</pubDate><guid>https://omid.dev/2012/02/21/fake-aicpa-mail-serves-blackholes-and-rootkits/</guid><description>&lt;p&gt;&lt;strong&gt;Sunbelt:&lt;/strong&gt; Be wary of emails claiming to be from AICPA – as per their alert &lt;a href="http://www.aicpa.org/News/FeaturedNews/Pages/alert-fraudulent-email.aspx"&gt;here&lt;/a&gt;, these are not real and any mention of “unlawful tax return fraud” is just a bait to convince the end-user to open up a malicious attachment (in this case, a .doc file although there are rogue PDF files in circulation too).&lt;/p&gt;
&lt;p&gt;&lt;img loading="lazy" src="http://lh4.ggpht.com/-BT0lPZFhSho/T0P3SFbgmkI/AAAAAAAAE7Y/ZMG7VbhiSM4/s1600-h/aicpaexploitmails%25255B3%25255D.jpg" alt="aicpaexploitmails" /&gt;
&lt;/p&gt;
&lt;p&gt;As with many of the malicious spam campaigns doing the rounds at the moment, this one will use the Blackhole exploit kit to serve up zbot from multiple compromised domains. Worse, a Sakura kit (typical example &lt;a href="http://xylibox.blogspot.com/2012/01/sakura-exploit-pack-10.html"&gt;here&lt;/a&gt;) will download Sirefef / ZeroAccess , which as we’ve seen elsewhere is &lt;a href="http://www.cio.com/article/691811/Bing_and_Yahoo_Sponsored_Results_Lead_to_Hard_to_Remove_Rootkit"&gt;not a good thing to have on your system&lt;/a&gt;.&lt;/p&gt;</description></item><item><title>Facebook Hoax: Facebook will end on March 15th 2012</title><link>https://omid.dev/2012/02/13/facebook-hoax-facebook-will-end-on-march-15th-2012/</link><pubDate>Mon, 13 Feb 2012 16:30:00 +0000</pubDate><guid>https://omid.dev/2012/02/13/facebook-hoax-facebook-will-end-on-march-15th-2012/</guid><description>&lt;p&gt;&lt;strong&gt;&lt;img loading="lazy" src="http://lh4.ggpht.com/-l4ySGrcj0PI/TzkzCzrjPGI/AAAAAAAAEuI/3utZImzEKjY/s1600-h/facebook%252528low%252529%25255B2%25255D.jpg" alt="facebook(low)" /&gt;
SophosLabs:&lt;/strong&gt; Have you seen the news? Maybe your friends have shared it with you.&lt;/p&gt;
&lt;p&gt;Apparently, Facebook is going to shut down on March 15th, 2012. Mark Zuckerberg has reportedly found running the site just too stressful.&lt;/p&gt;
&lt;p&gt;Here&amp;rsquo;s the link that many Facebook users have been sharing with each other.&lt;/p&gt;
&lt;p&gt;&lt;img loading="lazy" src="http://lh3.ggpht.com/-v7ai9NG-qAI/TzkzKOPFnFI/AAAAAAAAEuY/MY8ELgAtZlg/s1600-h/facebook-will-end-link%25255B4%25255D.jpg" alt="facebook-will-end-link" /&gt;
&lt;/p&gt;
&lt;p&gt;Some worried Facebook users have even been sharing this photograph of a news report about the claimed closure of the world&amp;rsquo;s most popular social network:&lt;/p&gt;</description></item></channel></rss>