Monday, August 12, 2013

Scam Words Crooks Use to Trick You

One of the biggest challenges cyber crooks face -- not that we have any sympathy for them! -- is coming up with words that'll most likely convince you to click on their troublesome links or attachments. But there's a catch. Security software that most of us have on our PCs is set up to look for suspicious words, so the crooks need to use words that will evade this first line of defense.

One of the main tricks they use is to create fake shipping notifications, especially if they're targeting businesses.  Experience suggests we're more likely to click on these than anything else.  More than a quarter of all words featured in malicious emails monitored by one security firm, FireEye, concerned shipments or postage.  FireEye actually compiled a table of those words;  they include the names of all the big shippers and mail organizations because, when we see those names, we're inclined to trust them. FireEye's Top 10 shipping scam words is as follows:

1. dhl
2. notification
3. delivery
4. express
5. (the date year)
6. label
7. shipment
8. ups
9. international
10. parcel

Also in the full charts are words like "alert," "urgent," "confirmation" and "usps."  Many of these shipping-related messages are used for spear phishing -- emails targeted at specific individuals.
When the messages have attachments, the most common form -- shown in the letters after the dot in the attachment name -- is ".zip," a compressed file that is difficult to inspect without opening it.  This accounts for three quarters of attachments in what FireEye calls "advanced malicious attacks." In second place is ".pdf" -- commonly used for documents readable on most PCs with the right software.

"Cybercriminals continue to evolve and refine their attack tactics to evade detection and use techniques that work. Spear phishing emails are on the rise because they work," says Ashar Aziz, founder and CEO, FireEye.

After shipping terms, the next most common word category used by cyber criminals is finance.  They often use the name of a bank, refer to transactions and have official-looking forms attached. Tax-related words are also popular, especially when they include "refund"!

Attachments named for things like airline tickets or invoices are another common feature of spear phishing.  The Internet Crime Complaint Center (IC3) says spear phishing emails are particularly effective because cybercriminals use information from social networking sites to personalize emails and make them look more authentic.  However, there are lots of other giveaways in scammers' choice of words that you can be on the lookout for.

As frequently reported, bogus messages from Nigeria or other countries where English is not the first language often give themselves away just by the use of wrong words and grammar.
Sometimes, they use quaint words and phrases no longer in use, seem over-polite or tell you they're "temporarily out of the country," or similar wording.  On dating sites, crooks also over-use abbreviations, some of them seemingly obscure even to seasoned surfers, and other just repeated too often -- like "cos."


More Scam Words Categories

Here are six word categories that suggest you could be on the receiving end of a scam attempt: Unlikely words: For example, an email with "business proposal" or another opportunity-related term as an attachment or subject heading would almost certainly be a scam.  After all, who initiates a business idea with you in this way?


Out of character: An email purports to come from someone you know but the words it uses just don't sound like they'd come from that person.  Claims of secrecy: Messages that claim to be "confidential," "for your eyes only" or based on "inside information," especially from someone you don't know, should arouse your suspicions.

If it's from someone you don't know, it's a scam. Who in their right mind would send a genuinely confidential item this way?  If it's from someone you do know, be really wary. Contact them first, if you can, to check that they sent it.

Promises of wealth: As in the aforementioned Nigerian scams. But let's not forget lottery wins (e.g., "claim," "prize," "awards office") and investment emails that use words like "guaranteed," "opportunity," "risk-free" and "fortune."

If it's not a scam, it's at least likely to be spam.

Sensation: Words like "shock," "sensation" and personalized phrases like "you gotta see this" or even "is this you?" are designed to make you want to click a link or an attachment.
Never do that without checking the source.  It's easy: Be cautious of words that suggest something you had imagined would be quite tough, is easy.

For job hunters, "no experience necessary" should be a red flag. So should things like "I earned $xxx in just xx hours" -- you fill in the amount and time -- but we guarantee they'll be amazing.
Similarly, money plans that offer "instant loans" may turn out to be too good to be true.
So now that you have "inside information" on the scammers' dictionary, you should have a better idea of what to be on the lookout for.

Few of us might claim to be true students of language, but paying attention to scam words could at least give you a degree of security.

 Source: scambusters.com #551, 7/1/13

Wednesday, July 3, 2013

How to Beat Ransomware Crooks

For no identifiable reason, other than it's an easy and effective way of making money, 2013 has seen a huge surge in ransomware -- the malicious programs that seize control of your computer and then demand payment to unfreeze it. Its simplicity and the alarming implications of not being able to get at the valuable data in your computer triggers a panic reaction that still works extremely well for the crooks.

Although there are no overall official figures, in one instance alone, 700,000 machines in Spain were hijacked, so it's likely that tens of millions have been targeted worldwide. And in another incident, one gang was estimated to have netted $5 million from a single extortion racket.


How Ransomware Works

You're happily working away or surfing when a warning pops up on your machine. The most common current one claims to be from the FBI, the Department of Justice or other law enforcement agency, saying your machine has been locked because of illegal activity. Usually, it suggests you've been downloading "adult" images and, in recent instances, it even flashes up supposed examples of what it claims you've been viewing.

Or it may suggest you've violated copyright laws by downloading pirated videos or music. The ransomware may even activate your webcam, showing your image and implying that you're being watched. The warning says you've been fined -- usually $200 -- and tells you to send a money-wire for the charges to be dropped and for a password to unlock your machine.

In other cases, the warning simply says you have a virus on your machine and that, for safety's sake, it has been locked.  In this case, paying a "fee" is supposed to enable a piece of software to clean up your PC and then get it going again.

But there are many other variations. The bottom line is that if the machine freezes and you're asked to pay to unlock it, you've been hijacked. No legitimate software or law enforcement agency works this way.


How to Avoid or Deal with Ransomware

The most obvious way of beating the ransomware crooks is by avoiding getting the malware on your PC in the first place. Here's our 10-point defense formula.

1. Using reputable anti-virus software and keeping it up to date will stop it dead in its tracks in most cases.

2. Don't click on links and attachments that come from people you don't know.

3. Even if you do know the sender, be wary about clicking.

Is the wording of the message unusual, vague or impersonal? Is the subject line or message text dramatic or does it claim to be a bill or receipt of some sort?  These are red flags.

4. Don't visit dubious websites, including "adult" sites or any flagged up by your Internet security software as being questionable. That's where the malware most often lurks.

5. Keep your data (documents, photos etc.) on a separate disc or partition from your operating system (e.g. Windows), so that if your system is hijacked your data will remain intact no matter what you have to do next to get back in business.

6. Back up both your system and your data regularly -- at least daily for your data and weekly for your operating system.

7. Create an emergency boot disk or USB drive that will allow you to restart your PC if the machine has been hijacked.

How you do that depends on your operating system and is beyond the scope of this article, but most operating systems and backup software will enable you to do that. You'll need to check your software documentation or search on-line for information on how to do it.


If You're Hijacked...

If you get a ransomware message, switch off your machine. If your computer won't let you, hold down the power button until it goes off.

8. If you know how to do it, restart your machine and go to "safe" mode, and then try to use system restore or system refresh to turn back your machine to an earlier date.

From safe mode, you might also be able to download a ransomware removal tool (search online for it) and use that. But be very careful it's not more malware! Or use someone else's machine to search for and download a ransomware removal program onto a flash drive that you can boot from. Check your computer documentation on how to start your machine from an external device.

9. If these options are not available, use your emergency boot disk (Point #7) to restart your machine (again, you'll need to check your documentation on how to do this), and reinstate your system backup.

10. If that doesn't work, you may need to reinstall your operating system and rebuild your setup. But if you've followed our earlier advice, all your data will be unaffected and intact.

If all of this is too tough for you, get professional help. Above all, don't pay the ransom or provide any personal information! There's no guarantee the crook or the software will provide the password to unlock it. Even if it does, it won't remove the ransomware from your PC; it could easily spring to life again.

Based on an article from scambusters.com



Wednesday, June 5, 2013

7 Tips to Help Reduce or Stop Spam

Many of us get thousands of spam messages a day. So, it's not surprising that people need relief -- they want to do whatever they can to stop spam. Unfortunately, many of us now spend so much time filtering and deleting spam that our biggest concern has become that we not lose messages we really want. 

Many double opt-in email newsletters are being incorrectly filtered, so recipients who sign up never know they've been sent. And even personal communication and one-on-one email is now regularly being filtered at the server level.

In fact, according to an article in Time Magazine, between 40% to 70% of all email is currently getting blocked by
spam filters! That means recipients never have a chance to read it.

So, the cure has become as bad as the disease. This is especially true of some filtering solutions with over-zealous criteria. Nevertheless, here are 7 good tips that will help you dramatically reduce the amount of spam you receive. Using these tips and resources, have in some cases to reduced the amount of spam by over 55%.

1. Use a separate email address when you post messages to any public forum, such as newsgroups and mailing lists. Never use your personal email address for this purpose -- or you'll be flooded with spam. Then, you can quickly go through the email in this account to see what's spam and what isn't. And your main personal email address won't be as clogged with spam.

For example,
AOL users can set up a special user name for free, and use that for their postings. Then, they can just discontinue that account if they start to get too much spam.

2. Consider acquiring
multiple email addresses for different purposes. This helps you to identify different sources and senders, and lets you filter more effectively.

For instance, you may have one for personal use only by friends, family or colleagues that is never used to request information or to subscribe to newsletters, discussion lists, etc.

Another might be used just for sales inquiries or orders, or for making online purchases. This can be arranged through
your ISP, web host or through any number of online email service providers.

Even free
mail services like Yahoo! Mail and GMail can be used for this purpose.

3. You can subscribe to services online that provide you with disposable addresses that can be deleted if they begin to attract spam messages.

You can create a unique address for each email newsletter or forum you subscribe to. Then, when an email address begins getting spam, you 'throw it away' and start using another email address.

This works because the disposable email addresses actually forward to a real email address of yours. The software lets you track which addresses are getting spam, and you can just resubscribe using a new, spam-free address.

For information on what you need to know about disposable addresses, visit:
http://email.about.com/library/weekly/aa072002a.htm

Our favorite company that offers disposable
email accounts is Sneakemail. It even has a free version:
http://sneakemail.com

4. Remove your email address from your website. If you list or link to your email address, you can expect to be spammed.

Address-harvesting robots will spider your site and extract them. So remove them wherever possible and use web-based forms instead. This will drastically cut down the amount of spam you receive if you have a website.

5. NEVER buy anything from a company that spams. Don't visit their sites or ask for more information. (If you respond to their spams, you're encouraging them to continue spamming -- they only need a tiny fraction of responses to be profitable.)

There's another reason not to buy anything from a company that spams: over 95% of spam offers are scams! In fact, not responding to spam is the single most effective way to not get scammed on the Internet.

6. Filter your email. Using filters is key to managing your email effectively. It may take a short time to figure out how to do this, but it's definitely worthwhile.

For more anti
-spam filtering information, visit: http://email.about.com/cs/spamfiltering/

7. Consider subscribing to a spam prevention service. We're not enthusiastic about these services, but many people find them invaluable. They range from the good to the bad to the downright ugly, and from free to fee-based.

Many of these services are "challenge response" services. This means they require that people who send you email to respond by clicking, visiting a website, and/or typing in a code that only a human (not a spam bot) could do correctly.

Unfortunately, many people -- and most newsletter publishers -- simply refuse to participate. That's because it requires people who are sending you legitimate email to take THEIR time to ensure YOU
get email.

In fact, many of us consider it rude for you to even ask.

Imagine a newsletter publisher like ScamBusters with 100,000+ subscribers. If even 20% installed this kind of system, that would mean the publisher would have 20,000 challenge/response requests. If each took only half a minute, that would be 167 hours -- or more than four weeks to reply!

Tip: Make sure that any software or system you select gives YOU control of which email you get (and doesn't automatically erase messages).

On a related note, safeguard your newsletter and discussion list subscriptions. If you, your
ISP or web host use spam filters or white lists, be sure to let them know that you want to receive messages from any newsletters or discussion lists that you subscribe to.

Do it as soon as you sign up... otherwise, it's very easy not to notice that you're not receiving them.

While these 7 tips may not actually stop spam, they will certainly help you drastically reduce the amount of spam you get.
From ScamBusters.com



Thursday, May 2, 2013

Inspiring Quotes From Zig Ziglar


Zig Ziglar, one of the world's most famous salesmen, who inspired millions with his message of positivity and personal achievement, passed away in late November, 2012 at the age of 86.
He was known around the world as a performance trainer for major corporations, motivational speaker, and author of best-selling books such as See You at the Top and Secrets of Closing the Sale. In his autobiography Zig, published 10 years ago, he wrote, "If my life has had a theme, I suppose it has been a typical American theme in that, for most of it, I have been looking for happiness and success." But his life was remarkable in his dedication to helping others find the same.

The following are a dozen of Ziglar's most inspirational quotes for achieving personal and professional success.

  1. If you can dream it, you can achieve it. You will get all you want in life if you help enough other people get what they want.
  2. Building a better you is the first step to building a better America.
  3. People often say that motivation doesn’t last. Well, neither does bathing – that’s why we recommend it daily.
  4. An optimist is someone who goes after Moby Dick in a row boat and takes the tartar sauce with him.
  5. Remember that failure is an event, not a person.
  6. For every sale you miss because you are too enthusiastic, you will miss a hundred because you’re not enthusiastic enough.
  7. Success is dependent on the glands – sweat glands.
  8. Honesty and integrity are absolutely essential to be successful in life – all areas of life.  The really good news is that anyone can develop honesty and integrity.
  9. Timid salesmen have skinny kids.
  10. The most important persuasion tool you have in your entire arsenal is integrity.
  11. Money isn’t the most important thing in life, but it’s reasonably close to oxygen on the ‘gotta have it’ scale.
  12. Stop selling. Start helping.

Source: entrepreneur.com, Nov.,2012

Monday, April 8, 2013

SOME THOUGHTS TO LIVE BY


For a change of pace, some thoughts to live by :~)


1 - Accept the fact that some days you're the pigeon, and some    days you're the statue!
2 - Always keep your words soft and sweet, just in case you have to eat them.
3 - Always read stuff that will make you look good if you die in the middle of it.
4 - Drive carefully ... It's not only cars that can be recalled by their Maker.
5 - If you can't be kind, at least have the decency to be vague.
6 - If you lend someone $20 and never see that person again, it was probably worth it.
7 - It may be that your sole purpose in life is simply to serve as a warning to others.
8 - Never buy a car you can't push.
9 - Never put both-feet in your mouth at-the-same-time;-because then-you won't have a leg to stand on.
10 - Nobody cares if you can't dance well. Just get up and dance.
11 - Since it's the early worm that gets eaten by the bird
, sleep late.
12 - The second mouse gets the cheese.
13 - When everything's coming your way, you're in the wrong lane.
14 - Birthdays are good for you. The more you have, the longer you live.
16
- Some mistakes are too much fun to make only once.
17 - We could learn a lot from crayons. Some are sharp, some are pretty and some are dull. Some have weird names and all are different colors, but they all have to live in the same box.
18 - A truly happy person is one who can enjoy the scenery on a detour.
19 - Have an awesome day and know that someone has thought about you today.

AND MOST IMPORTANTLY

20 - Save the earth ..... It's the only planet with chocolate! 

Tuesday, March 5, 2013

Webmail war: Gmail vs. Outlook.com vs. Yahoo Mail


This was the subject of a recent (March 1, 2013) Computerworld article by Serdar Yegulalp.  Here is my summary of this interesting article.

Google, Microsoft and Yahoo have all rolled out major changes to their free webmail services. Which now offers the best organization, message handling, mobile options and advanced features?

There's little question that Web-based email has captured a major portion of the user base. The conveniences of webmail -- all your messages in one place, few or no practical limits on storage, access from almost any client device -- make it all the more appealing to generations of users for whom client apps like Outlook are clunky relics.

In his roundup, he looks at what's changed for each email service during the past year -- both cosmetically and functionally -- and the ways each implements commonly used features: mail organization and searching, POP/IMAP access, handling of attachments and the mobile experience (including apps). His article includes a discussion on how to switch email accounts including moving email and moving contacts.

The article includes a “Bottom Line” comment for each of the three major free webmail services:

Gmail, from Google, continues as a fine choice for an email service, rich with meta-organizational features and external connectivity options.  However, gmail’s highly useful sync features for Outlook are now only available for paying customers.

Outlook.com, formerly Hotmail.com, is clean looking and works well, but the lack of IMAP support and the uncertain state of its mobile apps and mobile site is inconvenient.
NB: I’ll have a discussion on the phase out of Hotmail in an upcoming post.

Yahoo mail is easy to work with and approachable,  but all the features that would make it even more useful are either behind a paywall or absent entirely.

The article concludes by saying that Outlook.com is a welcome surprise, even if there's no support for IMAP and its mobile experience could still use some work. It's going to be one to watch, especially with Microsoft's growing push toward being a services outfit for end-users instead of just all-Windows, all the time. Meanwhile, Yahoo Mail is a decent entry-level product for undemanding users, but it's easy to see people outgrowing it quickly.
Folks who are uncomfortable with the way Gmail offers up ads based on the content of email might want one of the other services. Another big gripe with Gmail is how a key piece of its functionality -- client sync -- has been shunted out of the free product and into the for-pay tier. I hope this isn't a trend.
But in the end, it's hard to go wrong with Gmail. It's been broadly adopted, has a solid feature set and supports most of the popular mail protocols.

You can view the entire article at: 

-=#=-

Monday, February 4, 2013

Some Reasons to Update Your Website


We just celebrated the new year. If you haven’t already, it’s time to reflect on things and look forward.  It’s probably about that time to start thinking about your marketing plans for the new year. Just as recent years have proved, websites have become THE essential piece of your marketing puzzle and let’s face it, if you don’t have one then it’s beyond time to jump on this bandwagon. If your website has not been updated since 2010 (or dare I say earlier) then it is time to give it a face lift. It’s about 65 in website years.

Here are some things to help you understand the importance of getting yourself online or at least updating your online presence.


1. A website is the 24/7, 365 days a year FACE of your business. It’s always open and making an impression on your future clients/customers.

2. Your website should fit with your brand. Does your website match the style/feel of your business? Are you a classy boutique with a text driven, “rough” site? It has been said that customer’s make up their mind about a brand within the first 10 seconds of visiting. What is your site saying?
3. This year is not last year, nor is it the years before. Hence, times are changing! New trends are emerging, let’s lead them not follow!
4. Are you offering new products or services? Are they showcased on your site? If not, they should be!
5. Image is everything. Photos, galleries, sliders are a huge part of websites. If you have more than a couple sentences of text on your home page, your site is outdated. We are more visual now then ever.
Finally, there are considerations for mobile responsiveness along with social connectivity that you may want to consider in you attempt to keep your website refreshes and up with the times. In any case, it is very helpful for your Internet presence to do a periodic "refresh" of your website