Thursday, 27 October 2016

There is a lot of variations in evil e-mail the last couple of days.

I yearn for the days when evil e-mail was so easily identified "becuse it wuz ritten in, gud, inglish wit grate spellhng an pun.tation". ðŸ˜ƒ

In the last couple of days, the evil doers have been varying their scam e-mails fairly wildly and it's bound to catch out some people.

I'll run through three sneaky methods that have been attempted on others over the last 48 hours.

Wednesday, 26 October 2016

If you have Adobe Flash Player installed, read this now.


I really HATE Adobe Flash player. ðŸ˜¡ It is the internet equivalent of Typhoid Mary. If you don't need it, uninstall it. If you do need it, use Chrome as your browser. Why the rant?

Adobe has released a Critical update to Flash Player because of a vulnerability with it that has already been exploited in targeted attacks against Windows.
https://helpx.adobe.com/…/produ…/flash-player/apsb16-36.html


If you use Chrome or Microsoft's Edge or Internet Explorer 11, then the Flash player built in to these will get updated automatically. So concern yourself not.

However if you use Internet Explorer 10 or less (check Help->About) or other browsers and have Flash Player installed, then go to the following link and be sure to UNCHECK the "Optional Offers" and Click "Install Now" and follow the directions to upgrade your Flash Player.
https://get.adobe.com/flashplayer/

The sooner Flash goes away, the happier I will be. ðŸ˜‰

In the meantime ... Let's be careful out there.

The Internet of Evil Things continues to grow.

The first time I saw that cover picture Dr. Evil meme, I never thought that it might be possible for the numbers to reach those nonsensical values, but if Internet connected brooms are in our future (see below), we might be in serious trouble, if the manufacturers of such devices keep ignoring the need for easily configured security settings on their gear.

The Mirai Botnet, which was responsible for the historic attack on Brian Krebs website, amongst others last month has grown dramatically. I came across this Botnet tracking website, which gives details of the number of infected hosts in the Mirai Botnet a few hours ago. At that time the total number of hosts was 1,479,110. It is now showing 1,547,552 (it'll be higher by the time you read this 😭) That means on a Wednesday morning in late October, another 68,000 devices have been hacked and are ready to be used for evil purposes. It is believed that last Friday's massive attack on Dyn, which crippled such services as Twitter, Amazon, Spotify, PayPal and Netflix, was partly as a result of the Mirai Botnet according to Flashpoint.

Monday, 24 October 2016

Details emerge about the huge internet attack last Friday.


I'm sure you've all heard about the internet attack in the US last Friday, where sites such as Twitter, Amazon, Spotify, PayPal and Netflix (amongst others) were taken offline (effectively).

This was done by what is called a Distributed Denial Of Service (DDOS) attack and it targeted a company called Dyn, which provides all of those companies with a specific service. It is believed that this attack was carried out by a huge number of hacked security cameras and their associated Digital Video Recorders (DVRs), flooding the service with billions of requests which it could not handle. I talked about these hacked devices last month in this blog post.

Since then the hacker that created the computer code to take control of the cameras, has released it to the internet, so it looks like some new bad guys may have stepped it up a bit as there was mention of between 500,000 and 1,000,000 devices being used last Friday.

This is a very worrying situation, as that many devices could cause serious disruptions to businesses and people worldwide. There are anecdotal reports that some of these evil doers are attempting to bribe online service providers to pay them money not to launch an attack.

There is an excellent briefing by Dr. Johannes Ullrich of the SANS Institute in the following YouTube clip. This is a little tech jargon heavy, so only watch if you are really interested in learning more about this attack.