Why do Yahoo give your eMail account to cybercriminals, no questions asked?

YahooMail, which has now merged with AOL to form OATH, part of Verizon, can allow others, including and most likely, cyber criminals who are out to hack your digital life, to permanently have your yahoo email address; and there is nothing you can do about it. Except get off their service as quickly as possible or don’t start to use them in the first place

Even though Yahoo has now been merged they have kept the terms and conditions, which some on the internet have called a privacy nightmare, largely the same.

The first part is the same as all other FREE email and social media companies, and that is that everything you put, send or receive belongs to you, BUT, you grant them a sublicense to do with your data whatever they please.

The second part is more worrying and that is the fact that, if, for any reason, your account is terminated; including because you didn’t have enough activity on it for a given length of time, which remains unspecified in the terms and conditions, so as they determine it, then they can and will make your username (email address) available for anyone else to register. Read More

A New Domain Name Scam

Domain names are big business, well if you hold a lot of them or the right ones they can be. We charge £2.99/year (plus VAT) for a co.uk domain name. I have seen people or companies that charge over £50/year for these same domain names. Unscrupulous or just business? I would say that it is just business. A company can charge what they like for a domain name, there is no real limit on it and the customer is free to choose where they purchase them from. We love domain names but we do not charge the Earth for them. People are able to choose whether or not they want to pay prices as high as that or pay our prices. I have not really looked in to many of these companies that charge a high premium beyond the information on their website and it appears to me that they do not really want more customers, they are happy with what they have and that’s that.

There of course, have been some domain name companies that try to scam people either out of their domain name or just to win the business. Whichever it is I do not agree with underhand tactics to get business. People come to us because we are honest and open and we do an excellent job, not because we conned them in to moving to us.

The one that most people have probably seen the most is a company, that I will not name but they have been conning people for years now and more recently have been trying to clean up their act to appear more professional. They send out postal letter and emails to the registrant (owner of the domain name) and in the beginning they said that if they did not pay this extortionate rate their domain name would be lost forever. Anyone dumb enough to fall for it could have fallen in to many problems, as they were effectively transferring their domain name to another company and their website, emails and everything else could easily have stopped working and been lost. On top of the fact that they have paid a lot more for the domain name renewal than was necessary.

Always know who you have registered your domain name with and check with them first before renewing anything with a third party. This particular company have been forced by trading standards, I believe, to clean up their act. They still send out ridiculous emails and letters to try to steal customers from other companies, in my opinion, by deception. Their latest one stating that if you do not take their offer of SEO and domain name then no-one will be able to find your website. I will not go in to the technically details of this but to anyone with any technical ability they know this is not true, but it must be fooling some unwitting domain name holders or they would stop.

Another long running scam is the Asia domain name company that tells you that someone is trying to register a domain name that is similar to yours and they are going to give you first refusal of the domain name. A scam as well that has forced thousands of people to buy domain names that they do not need or want.

The latest email to go to domain name owners is one that is intended to scare you though showing you a whole lot of technical information about your domain name. All of it is probably true but means nothing in the context. From what I can see their whole point of sending you a large font email telling you that your whois information has been updated (which is a lie) is to get you to purchase other domains from them. I have not been any further and I have only just seen this one going round so I am sure that we will see what devastation it causes in the coming weeks and months.

If you own a domain name make sure you know the basic information of who it is registered with and when it is due for renewal. Even if you have technical people to look after things like that for you, make sure you have basic information (read: http://www.cc-computers.biz/Blog/?p=228 to make sure you don’t lose your domain name)

Be vigilant with emails and letters that come in the post telling you that you need to do something, check with the right people first.

Support Team

CritchCorp Computers Ltd.

Prices correct at date of publish.

Update to Outbound email policy

Due to the recent increase in spam being sent out from customer PCs by viruses and the problems with our servers being blacklisted by some of the more well know blacklists because of these spam-bot, we have taken steps try to prevent this type of problem from occurring.

With immediate effect all outbound email (which is already authenticated), will also be subject to blacklist checking. If you have a virus on your network that is sending out spam it is likely that you will now not be able to send email yourself. We need to implement this because of the problems caused by being blacklisted for the majority of clients who are not infected. So, to protect everyone else we need to stop email from those who are infected from sending email (most probably spam) and causing disruption and problems for everyone else.

There is now also a limit of 50 emails per hour from the same IP address.

If you do find that you are unable to send email, and nothing has changed on our network, then after you have been through the usual checks (restarting the computer, restarting router, etc) then it is possible you have been blacklisted. You will need to start by trying to fin the virus by scanning all computers (Macs, PCs, Linux, Etc.)

If you need help with any of this then please get in contact with us.

We also have a paid outbound SMTP service. This service rarely gets blocked by spam filters due to it nature. Accounts start at £50/year. Please contact us if you need more information.

CritchCorp Support Team

 

New PayPal Phishing Emails

I recently received an email from PayPal that said that I had just completed a payment to someone I had never heard of for an amount that gave me the shivers (some 2 or 3 hundred dollars). I did not want to pay someone I had not heard of any amount of money for something I had not ordered. Whats more this had completed from my bank account. My first reaction, in the panic of the moment, was to click on the link that invited me to check out the transaction in my account, so that I could see if I could get this revesed.

Before I clicked it I took a moment to calm down and think logically. I have a suitably strong password on my account so it is unlikely someone would have been able to guess it. You can’t make a payment unless you have the password. Is it possible someone could have got it from my PC with a keystroke logger and then used it; possible but not likley. I then took a moment to read the email more carefully and noted a couple of things that I should have picked up on straight away.

Firstly the email was addressed to me, but not in the normal way. Secondly it came to an address that was not the one I used for PayPal. These two facts alone were proof enough that this was a phishing email. I check out the links that I was about to click and sure enough they were not to the PayPal website but something that was meant to look like the PayPal website as it had www.paypal.com in the address but was not their site. (I will write another posting about what to look out for in the URL to make sure you are going to the right place).

What struck me about this one was the fact that it was very well written, not like most of them that give themselves away instantly with the bad grammar or spelling mistakes.

What you need to learn form this is to be extra vigilant when it comes to any message in email. NEVER EVER click the link in an email, go to the website by typing in the address yourself. Read the content of the email over again before jumping to conclusion. PayPal in particular use the correct greeting in their email which makes it harder (although not impossible) for people to pretend to be PayPal. The same goes for some banks and other financial institutions.

Phishing emails have been around for a long time and are clearly very successful so be extra vigilant on emails that you expect and ones you are not!

Be on the look out for the latest batch of PayPal phishing emails as they have clearly copied the contents of real PayPal emails and just changed a few details.

I have had several more since the first one of these.

CritchCorp Support Team.

Viruses and you

Viruses. This tends to be incorrectly used for all types of malicious software. There are in-fact several categories of this evil software: Virus, Mal-ware, Ad-ware, Spy-ware, Root-kit and Trojan Horses. I am not going to explain what all of these do or what makes them different to each other in any great detail, there is a great article in Wikipedia that has a very detailed and technical explanation of all this: http://en.wikipedia.org/wiki/Computer_virus – Read it for more information and some great trivia on early viruses. Some of the first viruses from 1971, before the Internet we know today! I will just explain some real life facts about viruses today and what they are used for and some ways they get in. With some basic knowledge of what they are after you can be more prepared when online or looking at email.

Beware the email virus. Someone you know sends you a link or attachment, or it comes form someone you consider reputable. When you open or click the link, it doesn’t always show you anything, sometimes you open the attachment and it just says there was an error accessing the file and sometimes there is nothing, just a blank page, or there is a document that just doesn’t make any sense or appears to not be for you. In all these cases the virus may well have been delivered silently in the background and you are now infected with one of thousands of different virus’. Many more of them will come in through web sites that do not know they are infected yet. (Some statistics suggest that 1000 website get infected every day!) In all cases the goal tends to be the same: Take control of your computer to extort money from you or someone else.

There are many different types of virus and they will all have a different part to play in the overall scheme. A few of the worst and their general purpose are noted here.

Trojan Horses (Trojans) – they will get in to your system and not necessarily do any damage except for disabling antivirus software, hiding itself and opening your computer up for other nasty things to come in. Often selling space on your computer to other virus manufactures (or programmers). They are often included with a root-kit. (See below).

Root-kits – These are a particularly cleaver type of virus. They hide themselves from Windows and everything else. The will usually get in to your system and load before Windows loads. They will then be sitting there behind Windows so that, for instance, if you view all the files in a folder you will not see the virus files there. This is because when Windows is enumerating (making the list) of files in the folder the Root-kit is watching and when Windows reaches one of its files the Root-kit will block Windows from seeing it. The Root-kit can also do this with system services so that when you look in Task Manager it’s services do not appear there either, making it very difficult to detect. This will be the same if your antivirus software is looking for it, because it has a position in the root it can hide itself from anything. The only way to detect their presence is in the very small added delay between file names when enumerating a folder (or directory). By looking at the time between each item to be enumerated any added delay of millionths of a second can be detected and then you can presume the existence. To actually find them and remove them requires very special techniques.

Self hiding/restoring viruses – These types of virus are often confused and also labeled by antivirus companies as root-kits but they tend to lack the hiding effects in the same way and use other methods to hid themselves. They will, as many do, also replace themselves when discovered. Firstly, they will often tell Windows that their files are part of the system and should be protected by the system. This has the effect of hiding them from normal users and can get Windows to replace any files that are removed. They sometimes also mark themselves as needed for Safe Mode, the special start-up mode to help remove virus’ and fix other issues with Windows. When Windows starts up in this mode it only start those programs which are essential to the system starting up. There is usually more than one part to this type of virus as well. It is the job of each to look after the other parts, so when you find one of them and remove it one of the other parts will put it back again, sometimes with a different name!

Bot-Nets. These are little viruses that are controlled by someone else and use your system resources like your computer processor, memory, Internet connection. They tend to be quiet, just sitting there not doing much until they are told to attack. Most commonly they are used to take down Internet sites for some kind of monetary gain. They can be hired to take down a competitors site at a critical time or by the organised crime syndicates to extort money out of companies in the old fashioned “protection racket”.

For Example, someone says to a betting site, “wouldn’t it be a shame if your website was not available for the big match coming up? If you pay a fee of £50,000 we can make sure you will be online at that time, otherwise we can not guarantee it!” If the site doesn’t pay first time round they will next time because at the time of the big game your computer and tens of thousands of others received instructions to attempt to connect to the betting site servers at the same time and to continue trying until the stop time, typically after the match/race has finished. With all this additional traffic going to the site and not doing anything the legitimate traffic cannot get through so the site then appears “offline” with a “404 page cannot be displayed” error or an error saying that the site cannot be reached. The site will not want the bad publicity; allowing people to find out that they have been compromised is very bad for business, so they end up paying. Your computer was used to help criminals extort money from someone else!

Another type of virus, actually mal-ware or increasingly know in the industry as ransom-ware, that comes in, often through a PDF or Adobe Flash exploit, is the current and very common one that will hold you to ransom. There are several different variants to this one depending on who is controlling it but they all do essentially the same thing and that is try to take your money off you with a type of protection racket or threat of some bad thing happening.

You will first notice a pop-up box that says you have hundreds or even thousands of viruses on your system (in some cases it is a corrupt hard drive/memory, porn or some other thing is very wrong with your computer) it will state that you need something in order to fix this. You are usually presented with a dialog box to confirm you want it or not. which ever button you press the answer is yes, go ahead and install the virus. The only way to get round this is to cancel the box (best done by using Task Manager to kill the program and everything to do with it). Another common one is a page that says that the FBI are stopping you from using your computer due to inappropriate content on your computer. You are then instructed to pay a fine or risk jail if it goes to court. Once you have install the virus you will be held to ransom, not able to use your computer at all in some cases, until you pay or remove the virus.

Worms. These are more commonly used as a method of transport. They are used to get their payload to your computer in any number of ways. They self replicate, usually to many different forms of media and methods. IE Across the Internet directly to your computer, through floppy disks, USB pen drives, external drives, emails, through the network to other computers on your local network. Once in they will begin to look for the next computer to infect, some also phone home to pickup instructions, such as what payload to deliver to the computers at the moment.

Viruses are a very very big money these days, both for the virus manufacturers and the antivirus manufacturers and on all forms of operating systems.  Although Windows is still the majority platform, Apple Macs are gaining market share and so now present a nice target with people who are not so use to viruses so are more susceptible to being infected. So which ever platform you are on, be careful, even phones, which are small computers, can be infected with things that cost you money!

Beware the antivirus that is a virus! Know which antivirus you use on your system and what it looks like to help reduce the chance of getting stung by a fake one, which will then hold you to ransom as above.

When surfing the Internet remember this: If you didn’t ask for it, don’t install it! many viruses will come packaged as something nice and appealing but, if you were not looking for that exact thing then do not be tempted to install it!

A good computer maintenance regime is to not install something unless you absolutely need it. If you think you need it, make sure you check it our fully before installing it, and make sure you download it from a known good source. Where possible go to the manufacturer’s website to get it, not from someone else offering it, unless directed there by the manufacture. If it turns out that you do not need or want it, then remove it. Although removing something is not as good as not installing it in the first place, it is better than leaving it there.

Watch out for viruses, they will come and get you any way they can. It is up to you to be careful, not your antivirus, after all you can override your antivirus if the virus is cleaver enough to trick you in to believing it is good for you.

Chris.