<?xml version="1.0" encoding="UTF-8"?> <rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" ><channel><title>Marvin&#039;s Place &#187; instant messenging</title> <atom:link href="http://marvincruz.com/tag/instant-messenging/feed/" rel="self" type="application/rss+xml" /><link>http://marvincruz.com</link> <description>My reflections about God, Bible, life and other stuff.</description> <lastBuildDate>Thu, 29 Dec 2011 13:31:44 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=</generator> <xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" /> <item><title>Yahoo! Messenger Spam: Hacking or Malware? &#8211; Update</title><link>http://marvincruz.com/yahoo-messenger-spam-hacking-or-malware-update/</link> <comments>http://marvincruz.com/yahoo-messenger-spam-hacking-or-malware-update/#comments</comments> <pubDate>Thu, 09 Apr 2009 22:25:29 +0000</pubDate> <dc:creator>marvin</dc:creator> <category><![CDATA[Tech]]></category> <category><![CDATA[instant messenging]]></category> <category><![CDATA[malware]]></category><guid isPermaLink="false">http://www.marvincruz.com/?p=265</guid> <description><![CDATA[Here&#8217;s an update on my previous post regarding the diet pill spam lurking on Yahoo Messenger (and as I researched, on other IM networks as well) After further research, CA Security Advisor Research Blog tells that this is actually a phishing scam. I never clicked the links included on the spams I receive. But as [...]]]></description> <content:encoded><![CDATA[<p>Here&#8217;s an update on my <a href="http://www.marvincruz.com/yahoo-messenger-spam-hacking-or-malware/" target="_blank">previous post</a> regarding the diet pill spam lurking on Yahoo Messenger (and as I researched, on other IM networks as well)</p><p>After further research, <a href="http://community.ca.com/blogs/securityadvisor/archive/2009/02/26/spim-preys-on-obesity.aspx" target="_blank">CA Security Advisor Research Blog</a> tells that this is actually a phishing scam.</p><p><a rel="attachment wp-att-267" href="http://www.marvincruz.com/yahoo-messenger-spam-hacking-or-malware-update/spam_can/"><img class="alignleft size-medium wp-image-267" title="spam_can" src="http://www.marvincruz.com/wp-content/uploads/2009/04/spam_can-300x130.jpg" alt="spam_can" width="300" height="130" /></a>I never clicked the links included on the spams I receive. But as the article indicates, links on the spam (each message might contain a different link) points to a single IP and it is a website about the pills offering a free trial of the popular fruit. However, upon checkout, it is not using the &#8220;https://&#8221; or secure http, which definitely means phishing. So if the unfortunate victim clicks submit, his credit card information will be sent to someone so he/she can use it for fraud.</p><p>So how does this spam works? This is only my theory. Either a malware on our computers or from some net cafe we went to was able to catch our username and password. Due to reports that the spam is received from clients that are &#8220;logged off&#8221; from Yahoo (which is my experience), I believe that a certain spambot on some server (maybe the same server as the phishing website) logs in using the username and password, sends a buzz to the poor clients contacts then sends the spam message with the link. So the unsuspecting receipient thinks that the message is legitimate, clicks the link, attracted by the offer (since Acai berry was really promoted by Oprah Winfrey and Rachel Ray), takes the trial, fills the credit card info, hits submit, and his/her credit card details are now in the hands of the criminals for their use.</p><p>Some possible but reasonable tips on how to avoid/solve this problem (take note, this might not solve the problem, but you won&#8217;t lose anything if you try):</p><ul><li>Update your operating system, softwares, etc. with the latest patches from the manufacturers.</li><li>Update your security software (anti-virus) virus definitions.</li><li>Do a regular (on your own terms:)) full system scan.</li><li>Don&#8217;t trust files from the internet (unless you are sure, don&#8217;t run or install).</li><li>Change your YM password.</li><li>Inform your friends who are sending the spam to do the same thing.</li></ul><p>I have already changed my password and will be monitoring if someone will still receive a message from me.</p><p><em>Notes: (from www.wikipedia.org)<br /> </em></p><p>Spam &#8211; A collection of unsolicited bulk electronic messages</p><p>Phishing &#8211; the <span class="mw-redirect">criminally</span> fraudulent process of attempting to acquire sensitive information such as usernames, passwords and credit card details by masquerading as a trustworthy entity in an electronic communication.</p><p>Acai Berry (<strong>açaí palm</strong>) &#8211; a member of the genus <em>Euterpe</em>, which contains 8 species of palms native to tropical Central and South America, from Belize south to Brazil and Peru, growing mainly in floodplains and swamps. Recently, the açai &#8220;berry&#8221; has been touted and marketed as a highly beneficial dietary supplement. Companies sell açaí berry products in the form of <span class="mw-redirect">tablets</span>, juice, <span class="mw-redirect">smoothies</span>, instant drink powders, and whole fruit.</p><p>There can never be a &#8220;spam free world&#8221;, but at least we can do something to minimize it.<div class="fbconnect_share" style=""><div id="fbsharefooter" class="fbfootersharebutton"><fb:share-button class="url" type="button_count" href="http://marvincruz.com/yahoo-messenger-spam-hacking-or-malware-update/" /></div><div id="googlesharefooter" class="fbfootersharebutton"><g:plusone href="http://marvincruz.com/yahoo-messenger-spam-hacking-or-malware-update/" size="medium"></g:plusone></div><div id="twittersharefooter" class="fbfootersharebutton"><a href="http://twitter.com/share" class="twitter-share-button" data-url="http://marvincruz.com/yahoo-messenger-spam-hacking-or-malware-update/" data-text="Yahoo! Messenger Spam: Hacking or Malware? - Update" data-count="horizontal" data-via="dodimar" data-lang="en"></a></div><div id="linkedinsharefooter" class="fbfootersharebutton"><script type="IN/Share" data-url="http://marvincruz.com/yahoo-messenger-spam-hacking-or-malware-update/" data-counter="right"></script></div><div id="fblikefooter" class="fbfootersharebutton"><fb:like send="true" href="http://marvincruz.com/yahoo-messenger-spam-hacking-or-malware-update/" show_faces="false" layout="button_count"></fb:like></div></div><p class="buymebeer"><form action="https://www.paypal.com/cgi-bin/webscr" target="paypal" method="post"><input type="hidden" name="cmd" value="_xclick" /><input type="hidden" name="business" value="marvin@marvincruz.com" /><input type="hidden" name="return" value="" /><input type="hidden" name="item_name" value="If you liked this article, please consider buying me a cup of coffee. for Yahoo! Messenger Spam: Hacking or Malware? - Update" /><input type="hidden" name="currency_code" value="USD" /><input type="hidden" name="amount" value="1" /><input type="image" src="http://marvincruz.com/wp-content/plugins/buy-me-beer/icon_cafe.gif" align="left" alt="If you liked this article, please consider buying me a cup of coffee." title="If you liked this article, please consider buying me a cup of coffee." hspace="3" /></form><a href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=marvin@marvincruz.com&amp;currency_code=USD&amp;amount=1&amp;return=&amp;item_name=If+you+liked+this+article,+please+consider+buying+me+a+cup+of+coffee.+for+Yahoo!+Messenger+Spam:+Hacking+or+Malware?+-+Update" target="paypal">If you liked this article, please consider buying me a cup of coffee.</a></p>]]></content:encoded> <wfw:commentRss>http://marvincruz.com/yahoo-messenger-spam-hacking-or-malware-update/feed/</wfw:commentRss> <slash:comments>1</slash:comments> </item> <item><title>Yahoo! Messenger Spam: Hacking or Malware?</title><link>http://marvincruz.com/yahoo-messenger-spam-hacking-or-malware/</link> <comments>http://marvincruz.com/yahoo-messenger-spam-hacking-or-malware/#comments</comments> <pubDate>Wed, 25 Mar 2009 22:43:38 +0000</pubDate> <dc:creator>marvin</dc:creator> <category><![CDATA[Tech]]></category> <category><![CDATA[computer]]></category> <category><![CDATA[instant messenging]]></category> <category><![CDATA[malware]]></category> <category><![CDATA[network]]></category><guid isPermaLink="false">http://www.marvincruz.com/?p=246</guid> <description><![CDATA[I&#8217;ve been a long time Yahoo! Messenger (YM) user. Yahoo was my first e-mail account and most of my contacts are Yahoo!. I won&#8217;t make the intro long. So here&#8217;s what&#8217;s I want to post. There are times before where I receive an instant message from an unknown Yahoo! ID. Well, simply, that was spamming. [...]]]></description> <content:encoded><![CDATA[<div id="attachment_226" class="wp-caption alignleft" style="width: 310px"><img class="size-full wp-image-226  " title="Spam Messenger under a Yahoo ID" src="http://marvincruz.com/wp-content/uploads/yahoo_messenger_spam.jpg" alt="Spam Messenger under a Yahoo ID" width="300" height="440" /><p class="wp-caption-text">Spam Messenger under a Yahoo ID</p></div><p>I&#8217;ve been a long time Yahoo! Messenger (YM) user. Yahoo was my first e-mail account and most of my contacts are Yahoo!.<br /> I won&#8217;t make the intro long. So here&#8217;s what&#8217;s I want to post. There are times before where I receive an instant message from an unknown Yahoo! ID. Well, simply, that was spamming. I suspect the spammers were able to get my email address from forums or at the Yahoo! Chatrooms. But then lately (I believe it started last year), I am receiving &#8220;wierd&#8221; IMs from my yahoo buddies (those are my friends). The first one, as I recalled, was in a different language (Korean or something). I then asked that friend if some one else was using here computer. She told me nobody&#8217;s using her PC aside from her, I suspected an account hacking.</p><p>I then asked some &#8220;pro&#8221; regarding this and they told me that most probably, this was caused by a malware or a &#8220;worm&#8221;. I asked my friend to do a virus scan. She wiped out her hard drive and made a fresh install. Since then, there were no more &#8220;spam&#8221; from her.</p><p>However, another buddy got &#8220;infected&#8221; by this and sends out IMs also on a different language. But lately, I was surprised because one of my buddies were sending me IMs (in English) regarding a &#8220;diet pill&#8221; (sample of the message below). I thought he was just promoting something. But when almost 5 buddies were sending the message, I was alarmed that they might be infected by a worm or malware.</p><p>Yesterday, I asked my brother if he was receiving messages like that and he said yes. I the asked if he received one from me, I believe he said no but when I came to office, he had sent me an email with a message coming from me. We talked in the morning and the message was timestamped at 10:35 in the evening.. I left home 10 in the evening.<br /> Before the message reach you, your &#8220;buddy&#8221; will first &#8220;buzz&#8221; (hitting ctrl+g on yahoo messenger client will buzz or shake the other contacts IM window to get attention) you and then send out the message. If you could notice in the image, the buzz was made 10:35:01pm and the message was sent at the exact same second. With the length of that message, it is imposible to type it in split second, unless you copy &#8211; paste very quickly. The worst thing is, I am using Pidgin, an opensource, multi platform/protocol (you can have AIM, Gtalk, YM, IRC, multiple accounts on same protocol) instant messenging client. And this program doesn&#8217;t have the &#8220;buzz&#8221; feature. I am sure my wife didnt&#8217; use YM cause she knew about Pidgin. (Thought I&#8217;m not going to make this long??)</p><p>So the question is, is my account being &#8220;hacked&#8221;. Was someone able to figure out the passwords of these users (including me) and then send spam to all our contact on our list? Or it is a worm the controls not the IM client, but the connection itself so it can send messages and command without opening an IM windows and execute a feature (the &#8220;buzz&#8221;) even if it is not supported by your client. Most probably it is a worm or malware.</p><p>I tried searching the net but not enough info. My brother gave me a link to a forum (on a different language). But when I try google&#8217;s transaltor, it is filtered in our office. So my resolution is to do a full system scan. Also run anti-malware/spyware scan. Then reformat and reinstall everything (which I will be doing anyway since my partitioning sucks), and delete any programs I downloaded from the net that I don&#8217;t need (well, those are clean programs, but I don&#8217;t need it).</p><p>Another question is, how did I get that malware/worm. Honestly, I don&#8217;t know. There are actually 3 computers at home. Two desktops and a laptop. The other desktop, is owned by my wife&#8217;s sister. I used to secure that computer but my wife&#8217;s nephew wants to do it &#8220;his way&#8221;. I turned of file and print sharing then. However the laptop was being used by my father-in-law and other people. File and print sharing is active on that one. In any case, some worm/malware can penetrate other computers on the network even if file and print sharing is off. And there are viruses, worms, and malware on the other desktop.</p><p>The laptop&#8217;s LCD is broken, and I already disconnected the other desktop from the network. Maybe this time, everything will be fine after reinstall.</p><p>Lesson to learn: Don&#8217;t trust everything on the net (websites/files/etc.) and always do a system scan (anti malware/spyware etc&#8230;.) once in a while. And buy a good router with good firewall settings (that&#8217;s what I&#8217;m going to do).</p><p>NOTE: I&#8217;ve already written an update for this <a href="http://marvincruz.com/yahoo-messenger-spam-hacking-or-malware-update/">here</a>.<div class="fbconnect_share" style=""><div id="fbsharefooter" class="fbfootersharebutton"><fb:share-button class="url" type="button_count" href="http://marvincruz.com/yahoo-messenger-spam-hacking-or-malware/" /></div><div id="googlesharefooter" class="fbfootersharebutton"><g:plusone href="http://marvincruz.com/yahoo-messenger-spam-hacking-or-malware/" size="medium"></g:plusone></div><div id="twittersharefooter" class="fbfootersharebutton"><a href="http://twitter.com/share" class="twitter-share-button" data-url="http://marvincruz.com/yahoo-messenger-spam-hacking-or-malware/" data-text="Yahoo! Messenger Spam: Hacking or Malware?" data-count="horizontal" data-via="dodimar" data-lang="en"></a></div><div id="linkedinsharefooter" class="fbfootersharebutton"><script type="IN/Share" data-url="http://marvincruz.com/yahoo-messenger-spam-hacking-or-malware/" data-counter="right"></script></div><div id="fblikefooter" class="fbfootersharebutton"><fb:like send="true" href="http://marvincruz.com/yahoo-messenger-spam-hacking-or-malware/" show_faces="false" layout="button_count"></fb:like></div></div><p class="buymebeer"><form action="https://www.paypal.com/cgi-bin/webscr" target="paypal" method="post"><input type="hidden" name="cmd" value="_xclick" /><input type="hidden" name="business" value="marvin@marvincruz.com" /><input type="hidden" name="return" value="" /><input type="hidden" name="item_name" value="If you liked this article, please consider buying me a cup of coffee. for Yahoo! Messenger Spam: Hacking or Malware?" /><input type="hidden" name="currency_code" value="USD" /><input type="hidden" name="amount" value="1" /><input type="image" src="http://marvincruz.com/wp-content/plugins/buy-me-beer/icon_cafe.gif" align="left" alt="If you liked this article, please consider buying me a cup of coffee." title="If you liked this article, please consider buying me a cup of coffee." hspace="3" /></form><a href="https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=marvin@marvincruz.com&amp;currency_code=USD&amp;amount=1&amp;return=&amp;item_name=If+you+liked+this+article,+please+consider+buying+me+a+cup+of+coffee.+for+Yahoo!+Messenger+Spam:+Hacking+or+Malware?" target="paypal">If you liked this article, please consider buying me a cup of coffee.</a></p>]]></content:encoded> <wfw:commentRss>http://marvincruz.com/yahoo-messenger-spam-hacking-or-malware/feed/</wfw:commentRss> <slash:comments>2</slash:comments> </item> </channel> </rss>
<!-- Served from: marvincruz.com @ 2012-02-11 19:31:45 by W3 Total Cache -->
