CudaMail Solutions

 Wednesday, July 09, 2008
Wednesday, July 09, 2008 4:43:08 PM (Mountain Daylight Time, UTC-06:00) ( Storm Worm | US-CERT )
 Just a heads up that the storm worm is up to the same tricks again with a war theme this time.
As always watch out for these kinds of tactics.

- Shaun



US-CERT Current Activity: New Storm Worm Variant Spreading

Original release date: July 9, 2008 at 8:48 am Last revised: July 9, 2008 at 8:48 am

US-CERT has received reports of new Storm Worm activity. The latest activity uses messages that refer to the conflict in the Middle East.

This Trojan is spread via unsolicited email messages that contain a link to a malicious website. The website is noted as having the following malicious characteristics which may be used to infect the user's system with malicious code.
  • A video that, when opened, may run the executable file "iran_occupation.exe."
  • A banner add that, when clicked, may run the executable file "form.exe."
  • A hidden iframe linked to "ind.php."
Reports, including a posting by Sophos, indicate that the following subject lines are being used. Please note that subject lines can change at any time.
  • 20000 US soldiers in Iran
  • Iran USA conflict developed into war
  • More than 10000 Iranians were murdered
  • Negotiations between USA and Iran ended in War
  • Occupation of Iran
  • Plans for Iran attack began
  • The Iran's Leader Mahmoud Ahmadinejad declared Jihad to USA
  • The World War III has already begun
  • The begining of The World War III
  • The military operation in Iran has begun
  • The secret war against Iran
  • Third War in Iran
  • Third World War has begun
  • US Army crossed Iran's borders
  • US Army invaded Iran
  • US army is about 20 kilometers from Tegeran
  • US soldiers occupied Iran
  • USA attacked Iran
  • USA declares war on Iran
  • USA occupeid Iran
  • USA unleashed war on Iran
  • War between USA&Iran
  • War with Iran is the reality now
  • Washington prefers to shoot first
US-CERT encourages users and administrators to take the following preventative measures to help mitigate the security risks:
  • Install anti-virus software, and keep its virus signature files up-to-date.
  • Do not follow unsolicited web links received in email messages.
  • Refer to the Recognizing and Avoiding Email Scams (pdf) document for more information on avoiding email scams.
  • Refer to Avoiding Social Engineering and Phishing Attacks document for more information on social engineering attacks.


Relevant Url(s):
http://www.us-cert.gov/cas/tips/ST04-014.html

http://www.sophos.com/security/blog/2008/07/1569.html

http://www.us-cert.gov/reading_room/emailscams_0905.pdf



This entry is available at:

www.us-cert.gov/current/index.html#new_storm_worm_varient_spreading

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.7 (GNU/Linux)

iQEVAwUBSHS1LXIHljM+H4irAQIHjQf/VmTJlMuebVWbXRIHH5D8xXw6zU5Ma9Yg
t0RqZlMIT7o5ILoNXlDNs9mmoq0fYrQeQz7WkW3hoV/E+H8ip4VX0XeOZerxxpGr
fpSwXaVcmwGxyD8XImelDOOa4fBAVPL6MOr1/40zg8Fc83ZSr6WRzwNoTGZc0OFR
0eyVe3D4hRGHiJSwtgRH79KoD1QjKli1i75R1brn2AiG2N2Z1OC2/03FJbhgo1mO
yIN6LsKCaEzMaUta3kqL0sGhUnzPWcpDbBaz7NlWCBXhs8bq11LAyuQ1iq5fBIDu
OXxJJa1BjNXvBuZBGPpRSLU0h7qSJykc5/6GiVrDgxYp+oHIw9qmcw==
=UYty
-----END PGP SIGNATURE-----

Comments [0] | Trackback | # 
 Monday, June 30, 2008
Monday, June 30, 2008 3:34:52 PM (Mountain Daylight Time, UTC-06:00) ( Barracuda Spam Firewalls | CudaMail | Spam Filtering Service )
I just wanted to start a thread on some of the tools I have been using to help us (Support@CudaMail.com) manage a cluster of Barracuda Spam Firewall 600's over the last few years. I hope these techniques will help you!

While I have a Windows PC as my daily desktop I have grown fond of lots of the classic *nix utilities such as , sort and uniq and one of the first things I do on a new power pc is to download and install the Cygwin utilities available at:
(just run the setup and let it do a default install - you can always re-run setup to update or add additional tools)
Once you have Cygwin installed you get a new DOS prompt like shell that is great at working with text file and one thing I do on a fairly regular basis is to look at the inbound / outbound queues especially when they are high and I want to know where all the messages are coming from or going to.

From the Basic / Status page click on the number that corresponds to the in or out queue. This will open a report showing the details on all messages but there is no easy way to sort them so I do a select all and copy the information to the clipboard.

I paste the information into Excel using paste special - plain text and then select all the e-mail addresses in the To: column. I copy them out and paste them into a plain text file called ‘list.txt’ in the C:\cygwin\home\username folder.

In the Cygwin shell issue the following command:

    -o -E \@.+$ list.txt | sort | uniq -c | sort

Let's break this command down:

   -o -E \@.+$ list.txt
 
This command looks through the file 'list.txt' for the section of the e-mail address that starts with the '@' sign and selects everything from the '@' sign to the end of the address. This results in a new list showing just the domain portion of the e-mail address with one entry per original line.

    | sort | uniq -c | sort

Pipe (|) the output of the command through sort to put all the same domain names together then run the output of that command (pipe again) through the uniq command asking it to count (-c) the number of uniq matching entries and then sort that list out from small to large before displaying the list like this sample:

     3 @thousand.com
     5 @ccim.org
     5 @s2.savvyconsumertoday.com
    13 @CUSTOMER.ORG
    27 @www.howtokeep.com
   294 @customer.org

    Voila! I have a list of number of messages per domain in the outbound queue!

So ... how does this help me?


This tells me at a glance that there is something wrong with the mail server for 'customer.com' and that I need to start looking there. This has helped me so much I wish there was a button at the top of each column in the in/out queue that would do the same thing - return a top 10 like list.
 
You can see that this sorts out the upper and lower case variations differently and while I thought that I would like to add in a command to change everything to lowercase first I do find some problems by not changing the case first. I can go back to the Excel spread sheet and find the 13 messages sending to the upper case variation of the customer and check them - this may be a new campaign that I can stop by adding these IP's to the 'IP Block / Accept tab.'

If you do want to combine the UPPER CASE and Lower case variations into one line then you would use the following series of commands.

    grep -o -E \@.+$ list.txt |tr 'A-Z' 'a-z' | sort | uniq -c | sort

Anyone else have a tip like this?

    - Shaun

Comments [0] | Trackback | # 
 Friday, June 27, 2008
Friday, June 27, 2008 9:24:17 AM (Mountain Daylight Time, UTC-06:00) ( False Spam | Postini | False Positives )
Which would be more damaging to your business, a few spam messages that get through to your Inbox, or one legitimate business email getting blocked by your spam filter?

We wanted to take a moment to share the following excerpts of an article from yesterday's issue of the Wall Street Journal.  The reporter takes an in-depth look at his company's spam filtering service - Postini, in this case - by sorting through all of the email messages sent directly to his spam folder.  In his search he discovers that of the 192 messages tagged as spam "46% were legitimate messages that had been flagged as spam."  Clearly this is an incredible and unacceptable false positive rate.

This article clearly validates Barracuda Networks' decision to prioritize a low false positive rate over blocking every single spam message. As you know, the Barracuda Spam Firewall has one of the lowest false positive ratings (.01%) of all solutions available today, while still maintaining a very high spam block rate of 95-99%.  With such ratings, chances are very good that customers will see the benefits of both a spam-free Inbox as well as feel confident that no legitimate messages are being blocked.  

The full article is below for your convenience.



www.WSJ.com
Wall Street Journal
*Real Message About Spam
June 18, 2008; Page B6*
Lee Gomes

We all hate the idea of doing anything that will end up making us deal with even more email than we have to manage now. But this is one of those situations where what you don't know can hurt you.

Dow Jones, like all big organizations, has been forced to subscribe to an antispam service to keep a firehouse of illicit and offensive mail messages from reaching its employees, reporters included. When the service was first turned on, Outlook inboxes were suddenly free of offers for prescription medicines, mortgage refinances, crude erotica and all the other mainstays of the spam economy. Regular email life could resume -- spam-free. It looked like another victory for technology in the hands of the good guys. If it seemed too good to be true, well, that happens all the time in the tech world.

But after a while, some of my colleagues and I began to wonder where all that spam was going, and whether there was a chance that maybe, just maybe, some of the emails being flagged as spam and sent to an email gulag were actually just innocent communications. (For the longest time, regular access to those files had been blocked by IT policy.)

I asked IT managers for access to what was being caught in our spam filters -- the messages held back in quarantine and not delivered to our inboxes. When access finally was granted to me, and others in the rank and file here, you could hear the gasps from cubicles when we all saw what we had been missing.

The antispam system had been so effective because it had labeled as spam just about everything that was even remotely suspect. It was acting a bit like a police department that, in an effort to curb juvenile delinquency, was hauling in all teenagers without "A" averages.

Naturally, a huge percentage of the emails weren't spam at all. Our freedom from spam had come at a stiff price -- a very high false-positive rate.

How bad was it?

I took a good long look at a few days' worth of messages in my spam bucket. There were 192 in all. Sorting them by hand into "real mail" and "actual spam," I figured that some 46% were legitimate messages that had been flagged as spam. Of these, most were news releases from companies, including VMWare, Dell and Hewlett-Packard. Notices from Purdue University, the Semiconductor Industry Association and Forbes Magazine also were blocked, though maybe that last one wasn't such a bad call after all.

I can live without the occasional news release. But what about when real readers take the time to sit down and write to me? That's a message I want to see.

Alas, of the 150 readers to write about a recent column, 20% were sent to the spam bucket and would never have been seen by me if I hadn't bothered to ask to take a look.

Other reporters who had taken advantage of the more-open access policy had similar tales. One colleague said his spam bucket contained a note from a friend he had assumed was angry with him because he hadn't written. Another found a crucial message from the company's official health-care provider announcing an important change in a health plan.

Spam researchers say this sort of thing is happening all the time at companies everywhere. "Your experience is not at all unique," says David Dagon, who studies spam detection at Georgia Tech. "Antispam technology has become pretty mature in the last few years, but a lot of innovation still has to occur because the problem is so dynamic."

The antispam software at my shop is provided by Postini, and we can assume it's at least as good as anyone else's by virtue of the fact that Google bought Postini last year.

Postini President Scott Petry seemed surprised that so much of my good mail was being flagged as spam. He said the software uses a number of different variables to score a message; those above a certain threshold get tagged as spam.

Those news releases, for example, were being sent from a single mailbox that had been configured in a way similar to the method spammers like to use. And one of the readers who had written to me had mentioned hospitals and charity work. A lot of spam involves charity scams, which is probably why that message got flagged, he said.

Mr. Petry then proceeded to explain aspects of our antispam software that I never knew about and that could be used to shrink the spam net.

Specifically, Postini allows individual users to determine how aggressive its spam's filters should be. By default, our filters had been set to a vigilance level of four on a 1-to-5 setting, with five being the most exclusionary.

It turned out -- and this was news to most of us -- that the spam filter could be set by each user to be as aggressive or as permissive as each of us wished. I could lower the rating, Mr.Petry said, and start to see some of the messages that I had previously been missing.

Of course, I would also start seeing a lot more spam. And here you have the sad truth about the state of the art in spam protection. Set up your software to a low setting and you'll get most of your mail, but lots of spam. Ratchet up the controls and you'll see fewer stock picks, but you might miss the note from a long-lost friend.

Next time someone starts telling you about how smart computers have become, remind them about this situation, will you?

Comments [0] | Trackback | # 
 Tuesday, June 24, 2008
Tuesday, June 24, 2008 2:33:24 PM (Mountain Daylight Time, UTC-06:00) ( Anti-Spam | CudaMail | Threats | Adobe | PDF Malware )
PDF Flaw Exposes All to Botnet Attempts

Adobe revealed that a flaw exists even in fully up-to-date versions of Adobe Reader 8.1.2 that 'could potentially allow an attacker to take control of the affected system' This is similar to other bugs that have been utilized recently by the "Bot Herders" to take over Millions of PC's to add to their herds to later be used to send spam to you and your friends.


Adobe's bulletin and service patch:
http://www.adobe.com/support/security/bulletins/apsb08-15.html   

SANS Internet Storm Center (ISC) recommends that you update sooner rather than later.
http://isc.sans.org/diary.html?storyid=4616


While the SANS article mentions that the vulnerability will soon appear on a malware spreading website we at CudaMail expect the "Bot Herders" to start sending millions of messages with links to these malware sites and to use 'social engineering' to get you to interested enough to click on this unsolicited link.

So what can you do to protect yourself?

Update all your programs on a regular basis. Make sure you have a tested backup of all your important information for when - not if - you get infected and have to format and re-install your operating system (the only way to be 100% sure that you don't have a nasty infection) and don't click on links you are unsure about the origins of.

What else can we do as an anti-spam service to protect you?

While we do watch for outbreaks like this closely and will be blocking any messages that have links to known infected sites we always have to be careful to not step over the line and start blocking legitimate links. We could easily write a rule that blocks any PDF file or even any link to any PDF file but this format is used by billions of people to send all sorts of legitimate information every day and so we can't do that except in the case of a major outbreak and then for only a very short while.

So here is a question to you, our dear readers:

Would you prefer to have 100% protection from a new malware outbreak like we expect even if some legitimate messages may be blocked or would you like all your legitimate e-mail's to come through even if a few malware links also come through?

At CudaMail we have a third option - the per-user quarantine - where we can send every messages with a PDF attachment or a link to a PDF into your personal quarantine area. This would require that you take the effort to check this quarantine area and deliberately release the wanted PDF's. Is that a viable option for you?

We want to hear from you!
      
- Shaun

Comments [0] | Trackback | # 
 Thursday, June 19, 2008
Thursday, June 19, 2008 11:15:26 AM (Mountain Daylight Time, UTC-06:00) ( Anti-Spam | Barracuda Spam Firewalls | CudaMail | Phishing Scams | Spam | Spam Filtering Service | Spam Stats | Threats )
The US-Cert is warning people about a new storm worm surge that is taking advantage of peoples interest in what is happening in China with both the recent earthquake and the Olympics foremost on people's minds.

Of all the messages processed recently by CudaMail with the words 'China' or 'Olympics' in the subject line we were able to block, quarantine or tag this new spam surge with only a handful of them getting through to our customers. This was while at the same time allowing the legitimate messages through as some of our customers do a brisk business with partners in China and will not stand for false positives.

 
The warning from US-Cert is included below so you can see some of the variations of subject lines that are being used but this is not a complete list as the storm worm continues to change the subject line and links to try and evade the anti-spam measures in place such as CudaMail.

 - Shaun

US-CERT Current Activity

New Storm Worm Variant Spreading

Original release date: June 19, 2008 at 11:23 am Last revised: June 19, 2008 at 11:23 am

US-CERT has received reports of new Storm Worm related activity. The latest activity is centered around messages related to the recent earthquake in China and the upcoming Olympic Games. This Trojan is spread via an unsolicited email message that contains a link to a malicious website. This website contains a video that when opened may run the executable file "beijing.exe" to infect the user's system with malicious code.

Subject lines can change at any time, but the following subject lines are noted as being used:

  * The most powerful quake hits China

  * Countless victims of earthquake in China

  * Death toll in China is growing

  * Recent earthquake in china took a heavy toll

  * Recent china earthquake kills million

  * China is paralyzed by new earthquake

  * Death toll in China exceeds 1000000

  * A new powerful disaster in China

  * A new deadly catastrophe in China

  * 2008 Olympic Games are under the threat

  * China's most deadly earthquake

US-CERT encourages users and administrators to take the following preventative measures to mitgate the security risks:

  * Install anti-virus software, and keep its virus signature files up-to-date.

  * Do not follow unsolicited web links received in email messages.

  * Refer to the Recognizing and Avoiding Email Scams (pdf) document for more information on avoiding email scams.

  * Refer to the Avoiding Social Engineering and Phishing Attacks document for more information on social engineering attacks.

US-CERT reminds users to beware of future phishing attacks that may target natural disasters and the Olympic Games.

Relevant Url(s):
http://www.us-cert.gov/cas/tips/ST04-014.html

http://www.us-cert.gov/reading_room/emailscams_0905.pdf

 ==== This entry is available at

http://www.us-cert.gov/current/index.html#new_storm_worm_variant_spreads2

Comments [0] | Trackback | # 
 Thursday, June 12, 2008
Thursday, June 12, 2008 2:12:53 PM (Mountain Daylight Time, UTC-06:00) ( CudaMail | Microsoft Exchange | Disaster Planning )
With email being such a significant part of most business peoples day having a backup plan in place should something happen to your mail server is time well spent.
A customer named Harold I was recently working with on his CudaMail filtering setup was explaining to me a very interesting way to do a form of Disaster Planning for Exchange Server, specifically the version included in Small Business Server (SBS).

While this method doesn't help Exchange be more robust it does keep the company working should there be a problem with the Exchange server and gives Harold time to work on his server without significant e-mail down time. 

What he does is have his e-mail hosted at an ISP and uses the POP3 connector in Exchange to pull off the e-mail on a regular basis. Now this is not new as the POP3 connector has been available since SBS 2003 as far as I know but his setup is unique.

While most people would use the POP3 connector as a temporary solution when migrating to the Exchange SMTP service, Harold is leaving it in place and looking for a replacement with additional features.

(any experience with good and or free replacements?)

Should his Exchange server go "belly up" then the ISP’s mail servers would continue to accept and deliver e-mail to the mailboxes they have on their mail server.

This is where Harold’s advanced planning comes into play. He has made sure that the users know that they can use the webmail feature from the ISP to check on and reply to messages while the Exchange server is off-line. This keeps the Company alive and working and gives Harold time to do his repairs or restore from backup.

There are some pro’s and con’s to this setup that I think need to be addressed.
  1. Delay in getting e-mail.  Because the POP3 Connector does a scheduled check of the ISP mailbox there will be a delay of up to 15 minutes in getting e-mail.  The response goes out from Exchange immediately but in this age of "instant everything" people want e-mail to be instant too. The average delay is going to be 7 ½ minutes so this is not a big issue unless there is a deadline your trying to meet.

  2. History. As far as I know the POP3 connector does not have the setting to leave x number of day’s worth of messages in the mailbox so the end users will have to use both the local copy of e-mail on their desktop and also remember to BCC themselves on any sent e-mail so they can maintain an accurate history of what is said via e-mail.

  3. Encryption. The POP3 connector in Exchange cannot encrypt the messages being pulled down via POP3. This is why Harold is looking for a better POP3 connector. Does anyone have any experience, good or bad, with the third party POP3 connectors?

  4. Passwords. The users need to keep track of the passwords used for e-mail at the ISP. How good are your users at remembering passwords?

  5. Training and reminders. The old adage ‘use it or lose it’ comes to mind. Will the users remember how to use the Webmail in a time of crisis? With e-mail down how will you be able to remind them they have this option?

  6. What happens to his e-mail if the ISP has a problem? How can he modify his setup to get the best of both worlds?

Can you think of any other issues or gotcha’s with this setup? Would an IMAP connector be a better option? Is there such a beast for Exchange?

- Shaun

Comments [0] | Trackback | # 
 Monday, June 02, 2008
Monday, June 02, 2008 3:18:20 PM (Mountain Daylight Time, UTC-06:00) ( Anti-Spam | Spam | Spam Stats | Regional Based IP List )


Source: Technology Review

The above is a wonderful chart shows that China, Brazil and Turkey lead in generating the most unwanted messages. The graph generated by data from Team Cymru is a lot easier to read than their default Hilbert Curve graph.




Source: Team Cymru

But they also have some nice graphs as well.

www.team-cymru.org/Monitoring/Graphs/

(Warning – the above graphs are Flash based.)

How can we use this information?

Well, if you are based in one country and only expect to get e-mail from only a handful of other countries then you can use a region to IP address list to block all e-mail from the countries you don’t plan on getting any e-mail from.  You should, however, have an alternate method of contact like a web form so that people from these blocked regions can still reach you.

One great region based IP list can be found at http://countries.nerd.dk/ in a format suitable to use as a real time black list (RBL) via most mail server software.

- Shaun

Comments [1] | Trackback | # 
 Friday, May 30, 2008
Friday, May 30, 2008 5:54:15 PM (Mountain Daylight Time, UTC-06:00) ( Anti-Spam | Spam | Threats )
Here's what's went on this week in the blogosphere in the anti spam world:


Backscatter

Use a service or server based anti spam system. Such systems employ measures that block spam and are hardened to large quantities of spam and will provide some protection from backscatter in and of themselves, however the spam ...


How much longer will anti-spam captchas be useful?

Luis von Ahn, an inventor of the anti-spam tool known as "captchas," talks with Jon Gordon about how much longer the squiggly line challenge-response tools will be useful.


TypePad launches new anti-spam tool for bloggers

TypePad AntiSpam is the product of the antispam technology Six Apart has been using in their TypePad hosted blogs since May 2007. Now the service, which is in beta, is available to anyone, open source, and free -- regardless of how ...


MySpace wins $230 million anti-spam judgment

Just saw this over at namepros, although I don't use myspace but I like to think that spammers (not only the ones spamming myspace) will think twice before doing spamming again Excite News - MySpace wins $230 million anti-spam judgment.


Social Networking Sites Also Popular With Spammers

Popular networking sites have become one of the latest targets in recent spam attacks. Cloudmark, an anti-spam enterprise, revealed that social networking sites have seen a huge rise in spam in the 6 months to March 2008. ...


Enjoy!

- Shaun

Comments [0] | Trackback | # 
 Wednesday, May 21, 2008
Wednesday, May 21, 2008 9:47:40 AM (Mountain Daylight Time, UTC-06:00) ( Anti-Spam | CudaMail | Memorial Day | Spam | Threats )
With the down turn in the US economy more people are turning to the web for the best deal so expect vendors to be even more aggressive in their approach to getting eyeballs on ads and this includes sending more e-mail marketing as this is the least cost advertising venue.

The spammers have been using e-mail for years now because it works and the big marketers have joined in as a scan of some of the recent subject lines processed by CudaMail shows.

Some of these are spam and some are just marketing messages:


Alarm systems.
"5 Horrible Home-Invasion Statistics."
"Secure your home today"

Pharma
"Live Life to the fullest"
"May 21st - Ready to Process Reorder"
"Cleanse your digestive system and feel great."
"Side effects include: Increased libido, decreased cellulite, and ..."

Office Supplies
"Discount printer ink and toner plus extra 10% coupon"

Social Networking
"Someone is looking for you. Find out who."

Septic Tank Insurance
"Has your Septic Tank ever backed up on you?"

Hardware and Tools
'True Value: Weekly Merchandising Newsletter - 5.20.08"

Vacations
"World Series of Poker* Invitation in Vegas for You"

Men's Clothing
"20% Off + $4.95 Flat Rate Shipping"

Women's Clothing and Swimwear
"Memorial day event - 50 items at 50% off!"

Satellite TV
"Over 40 Digital Quality channels for $19.99/mo. Get more with DISH Network"

Wedding Decorations
"Wedding Accessories on Sale"

Business Cards
"MAY MADNESS LAST DAY!!!!!"

Big Fans
"Industrial Cooling...$99"

So a warning to everyone that from our Operations Center here at CudaMail we see the volume of e-mail marketing, both legitimate and unwanted spam, is being turned up to 11 as we get closer to the long weekend in the U.S.

- Shaun

Comments [0] | Trackback | # 
 Tuesday, May 20, 2008
Tuesday, May 20, 2008 9:11:29 AM (Mountain Daylight Time, UTC-06:00) ( Natural Disasters | Phishing Scams )
Fires and floods and earthquakes, oh my...

Great reminder from US Cert on protecting yourself from the opportunists that prey on the feelings and emotions of all when a natural disaster strikes. At times when your heart strings are being pulled on it is almost as if the brain get's switched off and this provides an opening for the scammers to strike and they will.

If you want to help out in a situation like this then go through the official channels and not allow yourself to be solicited via a message delivered in an e-mail even if it comes from one of your trusted friends or family.

- Shaun

> From the US Cert (Computer Emergency Readiness Team) Natural Disasters and Phishing Scams

Original release date: May 19, 2008 at 4:30 pm
Last revised: May 19, 2008 at 4:30 pm

In the past, US-CERT has received reports of an increased number of phishing scams that take advantage of natural disasters. Due to recent natural disasters, US-CERT would like to remind users to remain cautious when receiving unsolicited email that could be a potential phishing scam.

Phishing scams may appear as requests for donations from a charitable organizations asking users to click on a link that will take them to a fraudulent website that appears to be a legitimate charity. The users are then asked to provide personal information that can further expose them to future compromises.

Users are encouraged to take the following measures to protect themselves from this type of phishing scam:
  • Do not follow unsolicited web links received in email messages.
  • Review the Federal Trade Commission's Charity Checklist.
  • Verify the legitimacy of the email by contacting the organization directly through a trusted contact number. Trusted contact information can be found on the Better Business Bureau National Charity Report Index.

For additional information regarding phishing, US-CERT recommends reading the following documents:
  • Recognizing and Avoiding Email Scams (PDF)
  • Avoiding Social Engineering and Phishing Attacks

Relevant Url(s):

http://www.us-cert.gov/cas/tips/ST04-014.html

http://www.us-cert.gov/reading_room/emailscams_0905.pdf

http://www.ftc.gov/bcp/edu/pubs/consumer/telemarketing/tel01.shtm

http://charityreports.bbb.org/public/All.aspx?bureauID=9999

====

This entry is available at:

http://www.us-cert.gov/current/index.html#natural_disasters_and_phishing_scams

Comments [0] | Trackback | # 

About the author

Shaun Sturby, MCSE Shaun Sturby, MCSE
Technical Services Manager, and Optrics' point person for email security

  Navigation

  Search

  Tag Cloud

  Category Feeds

  Archive

  Blogroll

  Statistics

Total Posts: 46
This Year: 46
This Month: 0
This Week: 0
Comments: 5


Subscribe


Technology Blogs - BlogCatalog Blog Directory
 

© Copyright 2008, Optrics Inc.