Showing posts with label spam. Show all posts
Showing posts with label spam. Show all posts

Monday, May 5, 2014

Email spam - sniffing out the bad, even from trusted sources

This post is a follow-up, of sorts, to the previous "Twitter spam" and "Phishing" posts. In making the slide deck about Twitter spam I realized there were a few different variations of spam in general, especially within emails.

This post deals specifically with email, and more to the point emails you receive from trusted sources that contain questionable material and links.

When a user gets hacked or compromised as a result of a phishing scheme, the people involved will use the users contacts list to send out emails in hopes of getting more users to give up their usernames and passwords.



This scam is particularly effective since you get an email from someone you know and trust, so your guard is down. The idea is to lull you into a false sense of security that the content of the email is safe since it got sent from someone you know and you recognize both the name and email address.

Once you click the links and enter your password you then turn your account over to the hackers who in turn send emails from your address to your contacts in an attempt to get even more users to give up their passwords.

A lot of email spam originates as "phishing" scams. These are emails designed to get the user to voluntarily offer up their username and password. These emails convince the recipient they need to pride details, or log in, to prevent something bad from happening. Once the user replies or logs in the scammers have their passwords and can use their accounts to send out spam to a users address book.

I created this quick tutorial for my colleagues to help them recognize and identify emails sent from compromised accounts:




We will never be immune from phishing scams and spam, and everyone will be compromised at one point or another (through their actions of those of others) but as GI Joe always said, knowing is half the battle...

Friday, May 2, 2014

Phishing: not the hook you're looking for

This post is a follow-up, of sorts, to the previous "Twitter spam" post. In making the slide deck about Twitter spam I realized there were a few different variations of spam in general, especially within emails.

This post deals specifically with "phishing"

Another post will address email arriving from trusted sources but smelling particularly spammy due to phishing...


If Twitter has it's moments of Costco-sized spam deliveries than email is the place where Costco shops. 

A lot of email spam originates as "phishing" scams. These are emails designed to get the user to voluntarily offer up their username and password. These emails convince the recipient they need to pride details, or log in, to prevent something bad from happening. Once the user replies or logs in the scammers have their passwords and can use their accounts to send out spam to a users address book.

I created this quick tutorial for my colleagues to help them recognize and identify phishing scams:





We will never be immune from phishing scams and spam, and everyone will be compromised at one point or another (through their actions of those of others) but as GI Joe always said, knowing is half the battle...

Thursday, May 1, 2014

Know your Twitter spam

Periodically I try to create & post resources that I hope the entire PS 10 community; students, staff, and parents alike, find valuable. This is one of those posts. Spam comes in many forms but since we use Twitter so extensively here at PS 10 I wanted to create a Twitter-specific resources for recognizing and protecting yourself from Twitter-related spam.


Twitter has it's moments of Costco-sized spam deliveries.

We've all seen it. Or more to the point you got a Direct Message (DM) saying "wow, have you seen this post about you?" with a on-so-not-suspicious link attached. Or the ego enhancing "I've lost weight with this, and you could too!"

When this spam comes through I immediately delete it and let the sender know they most likely have been compromised. It's not always the users fault, though. Recently Pinterest was compromised and was sending out tweets to those users who had connected their Pinterest and Twitter accounts.

I created this quick tutorial for the PS 10 community to help everyone recognize and identify suspicious DMs and tweets:






We will never be immune from spam, and everyone will be compromised at one point or another (through their actions of those of others) but as GI Joe always said, knowing is half the battle...