<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Random and Irrelevant &#187; Malware</title>
	<atom:link href="http://sgp.me.uk/tag/malware/feed/" rel="self" type="application/rss+xml" />
	<link>http://sgp.me.uk</link>
	<description>Sam Pearson&#039;s weblog - irrelevant content randomly updated</description>
	<lastBuildDate>Fri, 18 Nov 2011 18:06:51 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Shoulder surfing trojan</title>
		<link>http://sgp.me.uk/2004/11/15/banker-aj/</link>
		<comments>http://sgp.me.uk/2004/11/15/banker-aj/#comments</comments>
		<pubDate>Mon, 15 Nov 2004 09:17:25 +0000</pubDate>
		<dc:creator>Sam</dc:creator>
				<category><![CDATA[Geekery]]></category>
		<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://sgp.me.uk/2004/11/15/banker-aj</guid>
		<description><![CDATA[This looks nasty: Banker-AJ, a trojan which shoulder-surfs as you browse your online banking account logging keystrokes and taking screenshots before sending the information to its distributors, potentially enabling someone to access your account and empty it. Keep those anti-virus &#8230; <a href="http://sgp.me.uk/2004/11/15/banker-aj/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>This looks nasty: <a href="http://www.sophos.com/virusinfo/articles/ukbanktrojan.html" title="UK online bank accounts put at risk by new Trojan, reports Sophos">Banker-AJ</a>, a trojan which shoulder-surfs as you browse your online banking account logging keystrokes and taking screenshots before sending the information to its distributors, potentially enabling someone to access your account and empty it.  Keep those anti-virus definitions up-to-date!  (<a href="http://www.theregister.co.uk/2004/11/12/banker_trojan/" title="Trojan targets UK online bank accounts">Via the Register</a>.)</p>
]]></content:encoded>
			<wfw:commentRss>http://sgp.me.uk/2004/11/15/banker-aj/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>BOFRA: email link virus</title>
		<link>http://sgp.me.uk/2004/11/12/bofra/</link>
		<comments>http://sgp.me.uk/2004/11/12/bofra/#comments</comments>
		<pubDate>Fri, 12 Nov 2004 13:08:21 +0000</pubDate>
		<dc:creator>Sam</dc:creator>
				<category><![CDATA[Geekery]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://sgp.me.uk/2004/11/12/bofra</guid>
		<description><![CDATA[The BBC covered this today. Here&#8217;s a Clue: don&#8217;t use HTML for email. Look at any links you are sent in emails very carefully before loading them in a browser &#8211; not at the text used to display the link, &#8230; <a href="http://sgp.me.uk/2004/11/12/bofra/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><a href="http://news.bbc.co.uk/1/hi/technology/4004125.stm" title="Toxic web links help virus spread">The BBC covered this today</a>.  Here&#8217;s a Clue: don&#8217;t use <abbr title="HyperText Markup Language">HTML</abbr> for email.  Look at any links you are sent in emails very carefully before loading them in a browser &#8211; not at the text used to display the link, but at the actual address targeted.  Disabling the display of HTML in your email client should reveal this information to you.  You should already be doing this anyway if you&#8217;ve been paying attention to the recent <a href="http://sgp.me.uk/weblog/computers/internet/ebay-phishing.html" title="Earlier post: Ebay phishing attempt">phuss about phishing</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://sgp.me.uk/2004/11/12/bofra/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ebay phishing attempt</title>
		<link>http://sgp.me.uk/2004/10/19/ebay-phishing/</link>
		<comments>http://sgp.me.uk/2004/10/19/ebay-phishing/#comments</comments>
		<pubDate>Tue, 19 Oct 2004 16:12:51 +0000</pubDate>
		<dc:creator>Sam</dc:creator>
				<category><![CDATA[Geekery]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://sgp.me.uk/2004/10/19/ebay-phishing</guid>
		<description><![CDATA[I received an email today purporting to be from the ebay security team requesting that I access my account. The email, in HTML format, kindly provided a link to a page hosted at disguised as a link to ebay&#8217;s site. &#8230; <a href="http://sgp.me.uk/2004/10/19/ebay-phishing/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>I received an email today purporting to be from the <a href="http://www.ebay.com/" title="The REAL site">ebay</a> security team requesting that I access my account.  The email, in <abbr title="HyperText Markup Language">HTML</abbr> format, kindly provided a link to a page hosted at <http://mail.indusnetworks.com/> disguised as a link to ebay&#8217;s site.  Since my mail client displays messages as plaintext (making it obvious where links actually go), this was a pretty obvious phishing attempt. (Hey! Another argument against HTML email, as if we needed one.)</p>
<p>In addition to this and the fact that I&#8217;m paranoid at the best of times, something else helped me spot that this was a fake: I don&#8217;t even <i>have</i> an ebay account, and never have.  So I forwarded it to <a href="mailto:spoof@ebay.com">spoof@ebay.com</a>, where they recommend you send abuse reports of this kind.  If you&#8217;re interested in seeing what the fake site looked like, here&#8217;s a <a href="http://sgp.me.uk/images/ebay-phishers.jpg">screenshot</a> &#8211; it&#8217;s a pretty good likeness.</p>
<p>Note that on the fake page, they say that you can use your &#8220;registered email&#8221; address instead of your ebay ID, which differs somewhat from the <a href="https://signin.ebay.com/ws2/eBayISAPI.dll?SignIn&#038;favoritenav=&#038;sid=&#038;ruproduct=&#038;pp=&#038;co_partnerId=2&#038;ru=&#038;i1=&#038;ruparams=&#038;pageType=&#038;pa2=&#038;bshowgif=&#038;pa1=&#038;pUserId=&#038;errmsg=&#038;UsingSSL=&#038;runame=&#038;siteid=0">real ebay sign-in page</a>.  There are a few other minor differences, but even so when you compare the two they do look very similar.  <em>Beware!</em></p>
]]></content:encoded>
			<wfw:commentRss>http://sgp.me.uk/2004/10/19/ebay-phishing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Security</title>
		<link>http://sgp.me.uk/2004/09/16/windows-security/</link>
		<comments>http://sgp.me.uk/2004/09/16/windows-security/#comments</comments>
		<pubDate>Thu, 16 Sep 2004 12:39:41 +0000</pubDate>
		<dc:creator>Sam</dc:creator>
				<category><![CDATA[Geekery]]></category>
		<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://sgp.me.uk/2004/09/16/windows-security</guid>
		<description><![CDATA[I&#8217;d just been having a bit of an email/phone conversation with my Dad about some unpleasant bits of malware that&#8217;ve infected his XP box when I came across a potentially useful Windows security checklist. So Dad, when your machine&#8217;s fixed &#8230; <a href="http://sgp.me.uk/2004/09/16/windows-security/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>I&#8217;d just been having a bit of an email/phone conversation with my Dad about some unpleasant bits of malware that&#8217;ve infected his XP box when I came across a potentially useful <a href="http://www.kottke.org/04/09/windows-security-checklist" title="Windows security checklist at kottke.org">Windows security checklist</a>.  So Dad, when your machine&#8217;s fixed up, it might be worth taking a look.</p>
]]></content:encoded>
			<wfw:commentRss>http://sgp.me.uk/2004/09/16/windows-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>txt spam</title>
		<link>http://sgp.me.uk/2003/08/28/txt_spam/</link>
		<comments>http://sgp.me.uk/2003/08/28/txt_spam/#comments</comments>
		<pubDate>Thu, 28 Aug 2003 12:13:18 +0000</pubDate>
		<dc:creator>Sam</dc:creator>
				<category><![CDATA[Geekery]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[mobiles]]></category>
		<category><![CDATA[SMS]]></category>
		<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://sgp.me.uk/2003/08/28/txt_spam</guid>
		<description><![CDATA[If the email spam plague and the <a href="http://www.symantec.com/avcenter/venc/data/w32.sobig.f@mm.html" title="Symantec information on sobig-F">sobig virus</a> weren't enough, the quantity of unsolicited txt msgs I receive on my mobile phone seems to be creeping up recently. <a href="http://sgp.me.uk/2003/08/28/txt_spam/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>If the email spam plague and the <a href="http://www.symantec.com/avcenter/venc/data/w32.sobig.f@mm.html" title="Symantec information on sobig-F">sobig virus</a> weren&#8217;t enough, the quantity of unsolicited txt msgs I receive on my mobile phone seems to be creeping up recently.  For example, I got this last night:</p>
<blockquote><p>
From: 6655442</p>
<p>As a valued customer, I am pleased to advise you that following recent review of your Mob No. you are awarded with a &#163;1500 Bonus Prize, call 09066364589</p>
<p>Sent: 27-Aug-2003 22:41:04
</p></blockquote>
<p>09* Numbers are Premium Rate, and cost <em>&#163;&#163;&#163;</em> to call, and I&#8217;m sure I remember a factoid that this information had to accompany any solicitation to call one.  No such information in this message.  Also, the &#8216;From:&#8217; number looks forged to me, but I didn&#8217;t dare call it.  If this were an email, we&#8217;d call it spam, because that&#8217;s what it is.  I think that this kind of promotion of premium rate services is underhand &#8211; I can&#8217;t believe the claims that I&#8217;ve won lots of cash from someone who doesn&#8217;t even have the courtesy to identify themselves.  It&#8217;s clearly an attempt to get me to call their expensive phoneline.  Now I wouldn&#8217;t usually bother, but it annoyed me enough to make me want to complain to someone.</p>
<p>I should probably start by informing my service provider, <a href="http://www.o2.co.uk/" title="Formerly known as BT CellNet">mmO2</a>.  A bit of digging through their website brings up some advice on how to deal with nuisance calls, which seems to cover text messages as well.  Searching for &#8216;spam&#8217; brings up nothing.  Before calling customer care, I&#8217;m going to do a bit more checking around.</p>
<p>I recall seeing something on this topic at the <a href="http://news.bbc.co.uk/" title="BBC News Front Page">BBC</a> recently, and a search over there pulls up <a href="http://news.bbc.co.uk/1/hi/technology/3181959.stm" title="Text service fights mobile spam">an item</a> discussing measures being taken by <a href="http://www.vodafone.co.uk/" title="Vodafone UK Homepage">vodafone</a> to combat txt spam.  Not much use for me, but they also mention the <a href="http://www.icstis.org/">ICSTIS</a> (the Independent Committee for the Supervision of Standards of Telephone Information Services (phew!)) &#8211; which is &#8220;the industry-funded regulatory body for all premium rate charged telecommunications services&#8221;.  Looks good, so let&#8217;s surf on over.</p>
<p>The <a href="http://www.icstis.org/icstis2002/pdf/Guideline%2017.pdf">ICSTIS FAQ on unsolicited promotions</a> (<acronym title="Portable Document Format">PDF</acronym>) states clearly that:</p>
<blockquote><p>
Call charge details and any other information, which is likely to affect a decision to<br />
participate, should be clearly stated. In the case of text messages, information required<br />
under the Code of Practice should be stated before the premium rate number.
</p></blockquote>
<p>So I filled in their online <a href="http://www.icstis.org/icstis2002/default.asp?node=34">complaint form</a>.  Wonder if that&#8217;ll do any good?  They say it might take up to 12 weeks to reply!  I&#8217;ll probably never find out, because I gave &#8216;em my work email, and I&#8217;m gone in five weeks&#8230; Still, it&#8217;s the thought that counts.</p>
<p>(Hmm.  Interesting way to spend one&#8217;s lunch break.)</p>
]]></content:encoded>
			<wfw:commentRss>http://sgp.me.uk/2003/08/28/txt_spam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The computer virus</title>
		<link>http://sgp.me.uk/2003/01/28/mobile_viri/</link>
		<comments>http://sgp.me.uk/2003/01/28/mobile_viri/#comments</comments>
		<pubDate>Tue, 28 Jan 2003 23:31:07 +0000</pubDate>
		<dc:creator>Sam</dc:creator>
				<category><![CDATA[Geekery]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://sgp.me.uk/2003/01/28/mobile_viri</guid>
		<description><![CDATA[This perennial favourite has been back in the news lately with last weekend&#8217;s M$ SQL worm which apparently nearly brought the net to it&#8217;s knees. Can&#8217;t say that I noticed, and I spent a lot of time online over the &#8230; <a href="http://sgp.me.uk/2003/01/28/mobile_viri/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>This perennial favourite has been back in the news lately with last weekend&#8217;s <a href="http://news.bbc.co.uk/2/hi/technology/2697517.stm">M$ SQL worm</a> which apparently nearly brought the net to it&#8217;s knees.  Can&#8217;t say that I noticed, and I spent a lot of time online over the weekend.</p>
<p>On a related note, the BBC website ran <a href="http://news.bbc.co.uk/2/hi/technology/2690253.stm">this article</a> on the possibility that as mobile telephone technology advances those pesky viruses will start infesting our handsets.  This inspired me to do a little surfing, and although it seems that warnings of this sort of thing on the past have been largely groundless (discussion <a href="http://www.computeruser.com/news/00/06/24/news5.html">here</a> and <a href="http://www.vmyths.com/hoax.cfm?id=115&amp;page=3">here</a>, via a post at <a title="epicycle, a blog" href="http://www.cix.co.uk/~dominict/dominic/weblog/2003/jan2003-1.htm#11">epicycle</a>) , it now appears to be a lot more feasible.</p>
<p>This bout of surfing also brought to my attention <a href="http://vmyths.com/">vmyths.com</a>, who have this to say <a href="http://vmyths.com/resource.cfm?id=56&amp;page=1">about</a> themselves:</p>
<blockquote><p>Vmyths fights computer security hysteria with a comprehensive A-Z list of popular virus hoaxes. We also tackle persistent virus myths. And we dispel misconceptions about real viruses&#8230;</p></blockquote>
<p>Brilliant.  I&#8217;m sure that if you&#8217;re like me you regularly receive email from people warning you against one or other hysterical virus-related panic and possibly even advising you to delete files like <a href="http://www.symantec.com/avcenter/venc/data/jdbgmgr.exe.file.hoax.html">jdbgmgr.exe</a> or <a href="http://www.symantec.com/avcenter/venc/data/sulfnbk.exe.warning.html">sulfnbk.exe</a>.  Here&#8217;s a potential resource for dealing with that, independent from the anti-virus software vendors who have <a href="http://vmyths.com/rant.cfm?id=279&amp;page=4">allegedly behaved questionably</a> in the past.  vmyths.com certainly qualify for a spot on my links list, anyway.</p>
]]></content:encoded>
			<wfw:commentRss>http://sgp.me.uk/2003/01/28/mobile_viri/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

