Articles

Metasploit Framework Windows Tutorial
Remote Desktop Connection
Windows Processes That May Be Dangerous
How-To use NetCat a Tutorial
Common Linux Commands
Common Ports
Netcat Commands
HTTP Response Codes
War-Google Hack Terms
Wardriving
Avoiding Social Engineering and Phishing Attacks
Intrusion Detection on Linux
Linux Intrusion Detection
Penetration Testing Guide
Penetration Testing Tools
Social Engineering Fundamentals, Part I: Hacker Tactics
Social engineering (computer security)
The Psychology of Social Engineering

The Archives

General GSO
GovernmentSecurity.org News & Suggestions
In The News
Open Topic
General Security Information
Trash Can
Exploit & Vulnerability Mailing List Archives
Trial Member Forum
Product and Program Reviews GSO Tutorials
System Security
Windows Systems
Beginners Section
Linux & Unix Systems
File Downloads
Exploit Research & Discussion Trojan & Virus Errata
Networking Security / Firewall / IDS / VPN / Routers
System Hardening
E-Mail Security
Wifi Security
Trial Member Uploads
Upload discovered Trojans & Mal ware
GSO Programming Section
C , C++ , VC++
Visual Basic.NET
Perl /CGI
Java/Javascript
PHP/XML/ASP/HTML
Assembly + Other
The Cork Board
Network Security Consultant Directory
Network Security Jobs
The Archives
Encryption Information
General Network Security
Internet Anonymity
HTTP Protocol Security
Linux Security
MS IIS Information
Exploit Articles
Programming / Tool Design
GSO Software Projects
Public Downloads
Microsoft Security Questions and Papers

Full Version: Fruad Email
manu
It has been almost a month since this crap has come... Check the attachment and see the message..

Well, If you receive an e-mail similar to this, do nothing... Do not reply to the e-mail and do not give any personal details to the sender. If you do receive similar emails, or any email that you think may be fraudulent, please forward to FraudWatch International at: scams@fraudwatchinternational.com

Manu
dry.gif
Yorn
I have a habit of ignoring emails that compell me to do something like "change my password" and conveniently include a link.
Spookie
Thats like the 419 Scam with the twist of the cashiers check. People cash the check and send some of the money back only to find out that the check was false and now there left holding a 2-5K debt to their bank.

heres just one of the sites that talks about it.

Check Scam

Regarding this comment about the CitiBank Scam heres a link that might be of interest.

A.P.W.G.
Dominater
i get mails from citibank about once every week, once they asked for my pincode in that mail :S
tweakz20
blah.. my spam box has over 300 unread messages and i don't even want to look. spam is so lame:
Try these dog treats, if you don't like them, you get your money back! (real message)
SoulFly
QUOTE (tweakz20 @ Jul 20 2004, 01:13 PM)
blah.. my spam box has over 300 unread messages and i don't even want to look. spam is so lame:
Try these dog treats, if you don't like them, you get your money back! (real message)

Spam is some thing totaly useless just to bugg people or inplanting an cookie or exploit on some one's systemroot dir.
And making an P2P tracking server.
Symantec norton antispam shuld do the trick or just ignore and try to avoid watching e-mails by outlook!

-Fly
chris105
outlook should be banned. Downloading emails all your emails (including junk emails) is SCREAMING compromise me!
MsMittens
QUOTE
Downloading emails all your emails (including junk emails) is SCREAMING compromise me!


That in itself is not why Outlook should be banned. It's the fact that it pretty much is HTML only support (in certain versions you can't turn this off). The dumbass that made that part of email is the one who should be shot. Why on earth do I need HTML, javascript, etc. on my email? Anyways...

For "Phishing Concerns" (as pointed out in the first post) visit Anti-Phishing Working Group. You can check their archive to see if the questionable "change your password" type email has been reported before. If not, report it to them so they can shut down the site and if possible start legal action.

Since most spam is dependent on HTML if you have it turned off, their ability to detect whether the email was opened or not (thus a live email address) is greatly reduced. As I mentioned some Outlook programs have this hardwired in such a way that you cannot turn it off. noHTML for Outlook Express is a nifty little program that does turn it off. Other Outlook programs can have it turned off: Outlook 2002 and Outlook 2003.

You should also have the preview pane option turned off so that emails aren't immediately read and in some cases, launching viruses.

Honestly, just use another email program like Pegasus or Eudora that avoids these programs by default. Given the in-depth ties that Outlook has with the OS, it is a vulnerablity always waiting to happen.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2005 Invision Power Services, Inc.