Showing posts with label Login Details. Show all posts
Showing posts with label Login Details. Show all posts

Monday, 31 August 2015

Security Company Claims Dozens Hacked Dating Sites


The US security Hold Security claims that hackers dozens of dating sites have been hacked, with particular dating-related information and login details are stolen. Hundreds of thousands of users would be at risk. However not know which dating sites it will leave the company.

The list was viewed by IDG. According to the news websites between July 4th and last week had been hacked, often via vulnerabilities such as SQL Injection. Hold Security came a year ago in the news when the attackers claimed that 1.2 million passwords were stolen. Even when the company wanted not to know where the data was captured. What the hackers with the now stolen data plan is unknown.

Wednesday, 7 January 2015

New Variant of Emotet Malware - "Microsoft Warns of Malware That Steals Passwords"


Microsoft warned their users about malware that steals passwords for various programs and login details for online banking. The Emotet malware is distributed via a spam campaign that is aimed primarily at German Internet users, although 2.3% of the infections was observed in the Netherlands. The email contains a link to a zip file with a known deposit of the bank.



In reality, the zip file contains an .exe file that malware. Once active Emotet tries to steal login details for several German banks. In addition, the passwords for Eudora, Google Desktop, Google Talk, IncrediMail, Mozilla Thunderbird, MSN or Windows Live Messenger, Netscape 6 and Netscape 7, Outlook 2000, Outlook 2002 and Outlook Express, Windows Mail and Windows Live Mail and Yahoo! Messenger sent back to the attackers.

The linked website can download a .zip file that contains an executable file with a long file name to hide its .exe extension such as:

  • de_0000239029_rechnung_scan_hp_28_0000000904_page_2_10_01_05_id_00291002098.exe
  • E-Card_zu_Weichnachten_scan_foto_2834792347_12_2014_21093812_000129_001_004_002910.exe
  • Informationen_Kontobewegung_dezember_2014_de_20_8139_237_90109238_000129_000028_05.exe

According to the software giant let the malware show that it is important to keep security software up-to-date. To share in the event Microsoft's security software is used, users taking the advice to data with the Microsoft Active Protection Service Community (MAPS).


Wednesday, 9 April 2014

Fake poll as a lure for Facebook Phishing Scam

The Facebook application asks users to register their votes

Cyber criminals have again found a new way to Facebook to trick users into entering their login details. They run a fake online poll for the purpose of luring. Potential victims to a phishing site.

A pop-up window requesting for user account information

Symantec reports that the scammers run an online poll with the question: "Who better boys or girls" Once the visitor has cast his vote will be prompted to log in to the Facebook account and asked whether the visitor is male or female. After logging the victim sees the message that his voice has been sent. Scammers host the site on a subdomain ([http://] Smart Apps. [deleted]. com) to indicate that it is an application and the to appear. matter professionally in this context is the number of voters also raised periodically.

A comparison of the previous vote count and the current vote count

While it does seem that way at first glance Facebook has nothing to do with the campaign. When visitors log in reality they give their login information to the cyber criminals.

The scammers probably realize only too well that many Facebook users, this kind of thing every day without too much thought do. It is not inconceivable that they have already succeeded in many account data store.

Prevent
To a victim of a Facebook scam to be, it is important that you never put your password on domain other than facebook.com enter. The real login page of Facebook is secured with an SSL certificate which can be used by the padlock in the address bar of the browser and the HTTPS recognized connection.