SEARCH
  • [:en]Recent Posts[:af]Onlangse bydraes

  • [:en]Categories[:af]Kategorieë

  • [:en]Archives[:af]Argiewe

Security

SARS e-mail may fool usersSARS e-pos mag gebruikers bedrieg

Tuesday, October 15th, 2013

For some lucky people, it is time for the tax returns from SARS. The criminals know it too and every year at this time, users will get emails allegedly from SARS promising tax returns and asking you to click on a link, log in and provide your bank account details and password so they can pay you money!

This is a scam, and you should never respond or go to the site or open up the attached file, as this could compromise your banking security.

  1. SARS has your banking details on record and these are stored in secure and encrypted form. They do not need you to confirm or enter your banking details.
  2. SARS would always either SMS or send you a registered letter in the post to inform you of tax returns, etc. They would never contact you via unsecured e-mail, and furthermore they have enough of your data to address the mail to you PERSONALLY and not via some vague “Dear Taxpayer” salutation.
  3. There is no returnfund@sars.co.za address
  4. The attached file is usually a html (webpage) file that gives you a forged webpage sitting on the criminals server somewhere overseas.
  5. The amount that they promise to pay you is always something like R9,250.75
  6. Unless you have added your university e-mail address as the primary contact address on the SARS system you should never get mail on your university account.

If you do go to this site and you do enter in your banking account details, credit card details, passwords etc, this will allow the criminals to log into your bank account via the internet, and take control over your bank account. They will create themselves as beneficiaries and then transfer all your money to their account, and then delete all the evidence pointing to their account.

These scam e-mails will never stop. It is always difficult to block them too because scammers change their addresses, details and methods on a daily basis. So it is always best to dump these mails in the junk mail folder, blacklist the sending domain and delete the mail immediately.

Why do these criminals continue to send their mail? Because they catch people regularly. In 2012 South Africa was the 5th most phished country in the world behind India, Canada, the USA and the UK, with estimated figures of R14 million being stolen from South Africans last year alone.

 

[ARTICLE BY DAVID WILES]

Vir die gelukkiges onder ons, is dit weer tyd vir SARS se belastingopgawes. Ongelukkig weet die kriminele elemente dit ook en telkens die tyd van die jaar, ontvang gebruikers e-posse wat klaarblyklik deur SARS gestuur word en `n belasting terugbetaling belowe. Al wat jy moet doen is om op `n skakel te kliek, aan te teken, jou bankrekeningdetails en wagwoord te gee en jy kry jou geld!

Natuurlik is dit `n klassieke geval van “phishing”. Moenie eers reageer, na die webwerf gaan of die aangehegte leêr oopmaak nie, aangesien dit jou banksekuriteit sal blootstel. Hier is `n voor-die-hand-liggende redes hoekom jy dit as `n swendelary moet herken:

1. SARS het jou bankdetails op rekord en dit word op `n sekure bediener en in geënkodeerde formaat gestoor. Hulle het nie nodig om jou weer te vra om jou bankdetails te bevestig of te verskaf nie.

2. SARS sal jou altyd SMS of aan jou `n geregistreerde brief  deur middel van pos stuur om jou in kennis te stel van enige betalings. Hulle sal jou nie kontak d.m.v. `n onsekure medium soos e-pos nie. Buitendien het hulle ook genoeg inligting om jou persoonlik aan te spreek en nie met `n vae  “Dear Taxpayer” nie. 

3. Daar bestaan nie `n returnfund@sars.co.za adres nie.

4. Die aangehegde leêr is gewoonlik `n html (webblad) leêr wat lei na `n vervalste webwerf op `n onwettige bediener erens oorsee.

5. Die bedrag is altyd in die omgewing van R9 250.75

6. SARS sal jou nie op jou universiteitsadres kontak tensy jy dit gegee het as jou primêre adres nie.

Indien jy wel na die webwerf gaan, moenie jou bankrekening-details, kredietkaart-details of wagwoord invoer nie – dit sal aan skelms die kans gee om op jou bankrekening aan te teken deur die internet en beheer te neem oor jou bankrekening. Hulle kan dan hulself as begunstigdes byvoeg, al jou geld in hul rekeninge oorplaas en die bewyse wat hulle impliseer uitvee.

Hierdie tipe e-posse sal nooit ophou nie en dis bykans onmoontlik om dit te blok, omdat die kriminele hulle adresse, details en metodes op `n daaglikse basis aanpas. Die beste verweer is om hierdie e-posse in die junk mail leêr te sit, die domain waarvan dit gestuur word op die swartlys te sit en die e-pos dadelik uit te vee. 

Hoekom hou hierdie kuberskelms aan om hulle e-posse te stuur? Want mense val telkens daarvoor. In 2012 was Suid-Afrika die 5de hoogste land wat “phising” betref, net na Indië, Kanada, Amerika en Brittanje en `n beraamde  R14 miljoen is verlede jaar van Suid-Afrikaners gesteel.

 

[ARTICLE BY DAVID WILES]

ABSA eStatement phishingABSA eStaat phishing

Sunday, September 22nd, 2013

The only thing that must be more annoying than us constantly warning you of e-mail scams, is the persistence that is shown by the criminals and scam artists to attempt to con you, and steal your personal data and money.

The problem is they will continue to send phishing mails because they continue to catch people, even within an academic institution like the University.

Recently another ABSA eStatement landed in our e-mail box, this time a little more sophisticated, but armed with a few basic tips you will be able to spot the scam quickly.

Keep an eye out for these mails in your mailbox and delete then or add then to your Junk-Mail filters to block them in future.

Here’s how you spot can them:

1. Did you give your @sun.ac.za work address as your primary contact for Internet Banking?

2. Do you bank with (in this case) ABSA?

3. Is the salutation addressed to you personally, or is it just “Dear Customer”?

4. Is there a .pdf or an .html file attached? (phishers almost always use .html – a forged web-page)

5. Is the Subject of the e-mail “important” sounding? (In this case “Absa Cheque Account Statement”)

6. If you click on (or open by mistake) the attachment, does the web page look like the bank’s normal login page but does it LACK the https:// text at the front of the address and is the normal http://?

Answering these questions, it will be easy to establish whether an e-mail is clearly a phishing scam and can be deleted. Be vigilant and alert. Anyone can be caught out – even you.

[ARTICLE BY DAVID WILES]

 

Die enigste ding meer irriterend as ons wat jou voortdurend waarsku teen e-pos skelmstreke, is die deursettingsvemoë van kriminele en kuberswendelaars om jou te probeer uitvang en jou data en geld te steel.

Ongelukkig sal die probleem nie verdwyn solank as wat hierdie metodes telkens suksesvol is nie –  selfs binne `n akademiese instelling soos die Universiteit.

Onlangs het nog `n ABSA eStaat in ons posbusse beland, hierdie keer `n bietjie meer gesofistikeerd, maar gewapen met `n paar wenke, kan jy dit baie maklik herken. 

Kyk uit vir hierdie e-posse, vee hulle uit of skuif dit na jou Junk-Mail filters sodat dit volgende keer geblok word.

Hier is hoe jy dit kan uitken:

1. Het jy jou @sun.ac.za werkadres as primêre kontakadres vir jou internetbankdiens gegee? 

2. Doen jy jou banksake by ABSA?

3. Is die aanhef aan jou persoonlik gerig of is dit net `n vae “Dear Customer”? 

4. Is daar `n .pdf of ‘n .html leêr aangeheg? (kuberkrakers gebruik graag .html omdat dit jou herlei na `n vervalsde webblad) 

5. Klink die onderwerp van die e-pos “belangrik” of amptelik? (In die geval “Absa Cheque Account Statement”)

6. As jy kliek op die aanhangsel of dit per ongeluk oopmaak, lyk die webblad soos die bank se normale aantekenblad, maar sonder die https:// teks vooraan die adres? (https:// dui op `n veilige bediener, terwyl http:// `n oop webblad is)

Na aanleiding van bogenoeme vrae kan jy duidelik vasstel of `n  e-pos `n phishing-poging is en bloot uitgevee kan word. Wees waaksaam en op jou hoede. Enigiemand kan uitgevang word.

[ARTIKEL DEUR DAVID WILES]

 

Subscribe, unsubscribe Teken in, teken uit

Friday, September 20th, 2013

Once of the most common questions we get asked by users is –  How do these spammers get my e-mail address? Previously we looked at Rumpelstiltskin attacks, bots, trojans and zombies. This time around we focus at a third method – by using Subscribe/Unsubscribe newsletter services.

In the 21st century it can be said that “Knowledge and not Money is Power”. The two are closely linked. Knowledge or “data” is a hot commodity on the Internet. Facebook, for instance, has over 1.2 billion users. Just think of the value of that data if Mark Zuckerberg (the founder of Facebook) decided to sell that information. 

Many times you might receive e-mail in the form of a newsletter with a button down below that’s marked “Unsubscribe”, but will the newsletters really stop if you click on it?

There are many unscrupulous newsletter senders who will sell your e-mail address for a commission. A very common unsubscribe tactic is to send millions of people a false “you have joined a newsletter” e-mail. When users click on the “unsubscribe” link, they are not actually unsubscribing but unwittingly confirming that they are a real person with an active e-mail address. This results in getting more spam and soon the spam flood will spiral out of control. Furthermore the spammers will then sell their database (containing your “confirmed” e-mail address) to other spammers and unscrupulous marketing firms.

Another vector that spammers use to obtain your e-mail address is through legitimate newsletters. You may often subscribe to a legitimate newsletter service and receive newsletters, but as soon as your personal information and contact details are placed into the care of a third party (the legitimate newsletter service) you are relying on the fact that their system and database security is adequate and not vulnerable to hacking and identity theft. Hackers could break in and steal the database of e-mail address of the original newsletter service, and very quickly your e-mail address could be in the hands of spammers and scammers throughout the world.

Often marketers and newsletter services gather e-mail addresses and sell this to a third party. Often this is mentioned in the “Terms & Conditions” when you originally subscribe, giving them the rights to give your details to their “partners” so they can contact you. This way you become the unwitting victim in the business of selling and exchanging data.

Remember these important tips:

  • Survey Sites tend to generate a lot of junk mail. While many people use surveys as a great part-time source of extra income, signing up for surveys, free gifts, free drawings, etc. often distributes your e-mail to many unwanted mailing lists.
  • Try to keep your junk mail to a minimum by not giving your e-mail address to anybody that you don’t know, trust, or use for business purposes like your bank, business websites, etc.
  • Many different junk e-mails can come from the same source. Once you start “unsubscribing” from these e-mails, you’ll begin to notice that some of the unsubscribe pages look the same.
  • If trying to get information from sites requiring an email address try abc@123.com or similar rather than your own email address. By entering a non existent email address yours doesn’t get logged & targeted.
  • If you cancel a subscription and e-mail keeps coming, it may be necessary to add the junk mail’s sender or domain to your blocked list.

[ARTICLE BY DAVID WILES]

Een van die algemeenste vrae wat gebruikers vir ons vra is – Hoe kry gemorsposversenders my e-posadres? Vorige kere het ons gekyk na Repelsteeltjie-aanvalle, robotte, trojane en zombies. Hierdie keer fokus ons op `n derde metode – die inteken/uitteken opsie van nuusbriewe.
 
In die 21ste eeu kan daar gesê word “Kennis is mag, nie geld nie“. Hierdie twee is egter baie naby aan mekaar. Kennis of “data” is `n gewilde gebruiksartikel op die internet. Facebook het byvoorbeeld meer as 1.2 biljoen gebruikers. Dink net aan die waarde van al daardie data as Mark Zuckerberg (stigter van Facebook) besluit om die inligting te verkoop?

Jy sal dikwels `n e-pos ontvang in die vorm van `n nuusbrief met `n skakel onderaan wat gemerk is met “Unsubscribe” en aan jou die geleentheid gee om uit te teken, maar gaan die e-posse ophou as jy daarop kliek?

Ongelukkig is daar vele gewetenlose nuusbrief-versenders wat jou adres vir `n lekker vet kommissie sal verkoop. `n Algemene “unsubscribe”  taktiek is om `n e-pos na miljoene mense te stuur met `n bedrieglike “you have joined a newsletter” e-pos. Wanneer gebruikers kliek op die “unsubscribe”-skakel, teken hulle nie uit nie, maar bevestig onwetend dat hulle `n regte persoon is met `n aktiewe e-posadres.

Hierdie aksie veroorsaak nog meer gemorspos en binnekort oorstroom jou posbus. Daarbenewens sal gemorspos-versenders ook hul databasis (wat jou “bevestigde “adres insluit) aan ander gemorspos-verspreiders en bemarkingsfirmas stuur.  

`n Ander metode om e-posadresse in die hande te kry is deur wettige nuusbriewe. Jy skryf dalk dikwels in vir `n regmatige nuusbriefdiens en ontvang die nuusbriewe op `n gereelde basis. Wanneer jy egter jou persoonlike inligting en kontakdetails in `n derde party (die nuusbrief-diens) se hande vertrou, maak jy staat daarop dat hulle stelsel en databasis sekuriteit voldoende is en nie kwesbaar is vir kodebreking of identiteitsdiefstal nie. Kodebrekers kan die nuusbriefdiens se e-pos databasis steel en sonder moeite is jou adres in die hande van gemorsposversenders en swendelaars.

In sommige gevalle samel bemarkers en nuusbriefdienste e-posadresse en verkoop dit aan `n derde party. Ongelukkig het jy waarskynlik vir hulle toestemming gegee toe jy ingestem het tot hulle voorwaardes, soos gestipuleer in die “Terms & Conditions” toe jy ingeskryf het vir die diens. Daar word dikwels aangedui dat jy aan die diens die reg gee om jou inligting met hulle vennote te deel, wat jou om die beurt weer mag kontak. 

Onthou hierdie paar belangrike wenke: 

  • Opnames genereer baie gemorspos. Menige mense neem deel aan opnames vir `n ekstra inkomste, gratis geskenke, ens, maar jou details word dikwels deurgegee aan bemarkers vir verdere gebruik.
  • Poog om jou gemorspos tot `n minimum te beperk deur nie jou adres vir enigiemand te gee wat jy nie ken of vertrou nie. Moet ook nie dieselfde adres wat jy vir besigheiddoeleindes, soos jou internetbankdienste gebruik vir nuusbriewe nie.  
  • Verskillende gemorspos kom dikwels vanaf dieselfde bron. Sodra jy begin uitteken, sal jy sien dat die uitteken-webblad telkens dieselfde lyk. 
  • Indien jy inligting op `n webwerf probeer kry en die blad vra vir `n e-posadres, probeer abc@123.com of iets soortgelyk aan jou adres eerder as jou regte adres.  Ten minste word JOU adres nie op rekord gehou en later misbruik nie.  
  • As jy jou inskrywing gekanselleer het en jy kry steeds gemorspos, blokkeer die stuurder se adres of domein by Outlook se “junk mail”-opsie.

[INLIGTING VERSKAF DEUR DAVID WILES]

Attack of the trojans, bots & zombiesDie trojane, bots & zombies val in

Friday, August 30th, 2013

Once of the most common questions we are asked by users is: How do these spammers get my e-mail address? Previously we looked at Rumpelstiltskin attacks and this week we will focus on the second of the methods –  by using Trojan Horses, Bots and Zombies. Now, thet may sound like something from a movie, but they do pose quite a serious threat to you as e-mail user.

Let us use a familiar example. You regularly exchange emails with your elderly mother who has a computer. Your mother uses Outlook or Thunderbird and has dozens of emails from you in her inbox. She even added you to her address book. She also has lots of emails from a distant family member – cousin Johan from Australia. You haven’t stayed in touch with Johan that closely over the years, but you definitely know who he is.

Last year, just before the Christmas, Johan downloaded and installed this really pretty Christmas screensaver that showed tranquil tree and candle scenes when he wasn’t using the computer. What he didn’t know was that the screen saver had a sinister hidden payload. While the candles flickered peacefully on his screen, the software went to work combing through his emails and address book, his browser’s cache of past webmail sessions and other files, storing every email address it would find in a separate list.

Then it sent the entire list to a server in Russia, where a criminal combined it with other such submissions to build the ultimate monster spam list that can be sold and resold over and over again.

But as if that wasn’t enough, when the “screensaver” sent the address list to Russia, it received some content in return – messages to be sent to all of Johan’s contacts. Then, unbeknownst to John, his computer started creating hundreds of emails randomly using the harvested email addresses in the To: and From: field along with the content from the Russian server and sent them out using Johan’s Internet connection. One of them used your mother’s email address as sender and yours as recipient.

Now you received some spam from your mother asking you to buy fake watches and you’re ready to speak to her telling her to stop. Well, don’t. Your mother has obviously nothing to do with the whole thing and you’ll never find out that it was actually Johan’s computer.

You just had a look into the really nasty underworld of the Internet where botmasters (the guy in Russia) control botnets (infected computers that all report to the same server) of remote-controlled zombies (Johan’s computer) that were compromised using trojan horses (the screensaver) or similar malware.

And it doesn’t even end there. The botmaster typically doesn’t spam for his own account but hires out his botnet to whoever pays the most. The equally shady factory in China wanting to sell more fake Rolexes can now hire the botmaster to blast their offers all over the internet. The guy in Russia doesn’t even care if you open or click on that email from your mother, he gets paid either way. And when he’s done with the watches, he’ll inform his entire mailing list that they all won the lottery and can pick up the prize if only they pay a small “transfer fee” up front. And after that, he’ll mail a Paypal phish for yet another “client”. And for good measure, he’ll sell his entire email address database, incl. yours, to a friend who is in the same line of “business”.

In other words, once your email address got picked up by a botnet, Pandora’s Box is wide open. The whole scheme is particularly wicked because now you have to depend on others to keep your address safe. Unfortunately, there is little you can do:

  • First of all, do your own share: NEVER open email attachments that you didn’t ask for, even if they appear to come from good friends like Johan. If you’re still curious, ask Johan or your mother first if they really sent it.
  • NEVER download anything where you can’t in­de­pend­ent­ly verify it’s safe. With“independently verify” I mean you can read about it in forums, blogs, news sites, your local “computer geek” etc. Facebook fan pages, even with 1000s of “fans”, do NOT count, they are way too easy to manipulate and are usually full of misinformation!
  • NEVER get fooled by fake “security scans” (they’re quite the opposite!) or“video codec updates” to see that funny kitten clip. If you think you need a new Flash player, type in flash.com by hand and update from there. If afterwards the site still says you need an “update” get out of there as fast as you can.
  • Then educate your friends and family about the same. Explain how trojans work. Send them a link to this blog page!
  • You can try having multiple private email addresses. Keep a super-private one, only for family and very few of your closest friends.  Use your university address for everyone you work with and don’t use this for private mail – EVER!  Get a semi-private one for your wider social circle. The latter two do get some spam, although it’s still manageable. GMail has a very good “spam filter”, and blacklisting spammers is very easy!

 

[ARTICLE BY DAVID WILES & MATERIAL BY BustSpammers.com]

Een van die algemeenste navrae wat ons by gebruikers kry, is – “Hoe kry gemorsposversenders my e-posadres?!”. By `n vorige geleentheid het ons gekyk na Repelsteeltjie-aanvalle en die keer kyk ons na `n tweede metode, die gebruik van Trojaanse perde, robotte en zombies. Dit klink nou wel soos iets uit `n fliek, maar ten spyte van hul belaglike name, hou al drie `n gevaar in vir jou as e-posgebruiker.

Kom ons gebruik `n bekende voorbeeld. Jy stuur gereeld e-posse aan jou ma wat onlangs `n rekenaar gekry het. Sy gebruik Outlook of Thunderbird en het dosyne e-posse van jou in haar posbus. Sy’t jou selfs bygevoeg as `n kontak in haar adresboek. Sy kry ook gereeld e-pos van `n verlangse familielid – neef Johan van Australië. Jy en Johan het nie regtig kontak nie, maar jy weet definitief wie hy is.

Verlede jaar, net voor Kersfees, het Johan ‘n baie oulike Kersfees skermskut (“screensaver”) afgelaai wat `n feestelike boom en flikkerende kersies wys as hy weg is van sy rekenaar. Wat Johan egter nie geweet het nie, is dat, terwyl die kersies vrolik geflikker het, die skermskut op die agtergrond besig was met ander aktiwiteite. Die sagteware wat Johan installeer het, het stelselmatig deur sy e-posse, adresboek, webblaaier se kasgeheue en ander leêrs gesoek en elke e-pos adres wat dit kon opspoor, gebêre op `n lys.

Die program het daarna die saamgestelde lys na `n bediener in Rusland versend waar `n kuberkrimineel dit kombineer het met soortgelyke lyste om `n super-lys saam te stel wat oor en oor verkoop kan word. Asof dit nie genoeg was nie, het die program ook boodskappe aan al Johan se kontakte gestuur. Sonder dat Johan bewus was, het sy rekenaar honderde e-posse geskep deur middel van die ge-oeste adresse, saam met die inhoud van die Russiese bediener en dit uitgestuur via Johan se adres en internetkonneksie. Een hiervan het jou ma se e-posadres as versender en joune as ontvanger gebruik.

Ewe skielik kry jy nou e-pos van jou ma oor nagemaakte horlosies en verskeie ander gemorspos. Natuurlik het sy het niks daarmee te doen nie en jy sal waarskynlik nooit uitvind dat Johan se rekenaar eintlik die skuldige party is nie.

Dit was `n kykie in die nare onderwêreld van die Internet waar “botmasters” (die ou in Rusland) “botnets” (besmette rekenaars wat almal aan dieselfde rekenaar rapporteer) beheer of afstandbeheerde zombies (Johan se rekenaar) wat blootgestel is d.m.v. trojaanse perde (die skermskut) of soortgelyke “malware”.

En daar hou dit nie op nie. Die “botmaster” huur gewoonlik net die “botnet” uit aan wie ookal die meeste betaal. Die ewe verdagte fabriek in China wat nog meer nagemaakte Rolex-horlosies wil verkoop kan dit, onder andere, huur om hul e-posse te versprei. Daarna verkoop hy die lys ten duurste aan ander suspisieuse besighede, jou adres ingesluit. 

Met ander woorde, as jou adres opgetel word deur `n “botnet” is die deure wawyd oop. Ongelukkig is daar nie baie wat jy kan doen om dit te voorkom nie, maar jy kan op die volgende let:

  • Moet nooit e-pos aanhangsels oopmaak waarvoor jy nie gevra het nie – selfs al is dit van iemand wat jy ken. As jy wel nuuskierig is, vra vir die persoon of hulle dit gestuur het.  
  • Moet nooit iets aflaai as jy nie self kan verifieer dat dit veilig is nie. Lees eers op daaroor op forums, blogs, webwerwe of vind uit by kenners.
  • Moenie val vir sekuriteitswaarskuwings of video-opdaterings om daai oulike katprentjie te sien nie. As jy dink jy het `n Flash-speler nodig, laai dit af van die webwerf self.
  • Deel hierdie inligting met jou vriende en familie. 
  • Om veilig te speel kan jy meer as een e-posadres gebruik. Kry `n privaat adres vir jou naaste vriende, `n tweede een vir kennisse en gebruik jou sun-adres net vir jou kollegas, nie vir privaat aangeleenthede nie. GMail het byvoorbeeld `n baie goeie gemorsposfilter en dis maklik om ontslae te raak van ongewenste e-posse. 

[BRON: BustSpammers.com & David Wiles]

 

What does Rumplestiltskin and spam have in common?Wat het Repelsteeltjie en gemorspos in gemeen?

Friday, August 16th, 2013

Once of the most common questions we get asked by users is “How do these spammers get my e-mail address?” 

There are a number or methods that these spammers use, but today we will focus on one of the methods,  The “Rumplestiltskin” attack.

A dictionary or Rumplestiltskin attack is an attack where the spammer floods e-mail servers with usernames selected from a dictionary. The name of course, comes from the old Grimm’s fairytale.

Long, long ago when the university’s e-mail system was still very primitive and e-mail addresses were limited to 8 characters, most personnel at the university had simple names like ab@sun.ac.zaaa1@sun.ac.za, bv@sun.ac.za. It is relatively easy to make up a list of common letter combinations and just add @sun.ac.za onto it to create a e-mail list. Add to that common  role-based accounts, such as admin, help and support, as well as adding the latest Baby Names list and you have a list that can be used to launch a Rumplestiltskin attack.

If you send  E-mail to Unknown Users or address that do not exist, Why bother?

Firstly rather than spammers buying a list from other spammers, they can just spam to any possible name they can generate. It might seem rather inefficient but sending email is cheap.

The second reason – which is far more sinister – is that spammers use these techniques to generate lists of valid email accounts. They first send to a generated list and when they do get a response or the receiving mail server doesn’t answer back and say“unknown e-mail address”, this allows them to either sell these lists of “verified” emails or be more accurate in their other spamming activities.

With this second reason in mind, you should be able to see the danger of replying to these mails or filling in the “opt-out” option, that is commonly included in such mails, or by setting your “Send delivery receipt” to automatic on your e-mail. As soon as these spammers realize that there is a real person at the other end of the e-mail, they will increase their spam. They get paid to send out the mail, not for how many people respond to them.

In our next edition we will focus on a second way spammers harvest e-mail addresses in – Part 2 – Trojan Horses, Bots and Zombies

[ARTICLE BY DAVID WILES]

Een van die algemeenste vrae wat gebruikers vir ons vra is: Hoe kry hierdie gemorsposversenders my adres?! 

Daar is `n hele paar metodes, maar die keer fokus ons op die “Repelsteeltjie”-aanval.  

`n Woordeboek of Repelsteeltjie-aanval is `n aanval waar die gemorspos-versender e-pos bedieners oorval met gebruikersname uit `n woordeboek. Die naam is natuurlik afkomstig van die ou Grimm sprokiesverhaal.

Lank, lank gelede toe die universiteit se e-pos sisteeem nog primitief was en e-posadresse beperk tot 8 karakters, het die meeste personeel eenvoudige adresse gehad soos ab@sun.ac.zaaa1@sun.ac.za, bv@sun.ac.za.  

Dis redelik eenvoudig om `n lys van algemene letterkombinasies saam te stel en @sun.ac.za by te las en `n e-pos adreslys saam te stel. Voeg daarby algemene rolgebaseerde rekeninge soos admin, help en support, sowel as die nuuste babaname lys en jy het `n lys waarmee jy jou aanval kan loods. 

Hoekom sal jy `n e-pos stuur na onbekende gebruikers of `n adres wat nie bestaan nie?

Eerder as om `n lys te koop by ander gemorsposverspreiders, is dit makliker en natuurlik goedkoper om net gemorspos te stuur na enige moontlike naam wat gegenereer kan word. 

Die tweede rede – en `n meer oneerlike een – is dat versenders dit gebruik om juis `n lys van geldige adresse op te bou. Eers word `n gegenereerde lys gestuur en wanneer hulle `n antwoord kry of die e-pos bediener aan die ontvangkant nie terugantwoord en bevestig dat die adres ongeldig is nie, kry hulle die geleentheid om die lys te verkoop as “bevestigde” adresse of om meer akkuraat te wees met hul aktiwiteite.

Hiermee in gedagte, kan jy jouself indink hoe gevaarlik dit is om op hierdie e-posse te antwoord of te kliek op die “teken uit” opsie wat algemeen by die tipe e-posse ingesluit word. Selfs om “Send delivery receipt” op outomaties te stel hou `n gevaar in.

Sodra die skuldiges besef dat daar `n regte, lewendige persoon aan die ander kant van die e-pos is, sal die gemorspos net eenvoudig toeneem. Hulle word betaal om die e-posse suksesvol uit te stuur, nie noodwendig vir hoeveel mense daarop reageer nie.  

Volgende keer kyk ons na nog `n metode wat gebruik word om adresse te oes in Deel 2 – Trojaanse perde, Robotte en Zombies

[ARTIKEL DEUR DAVID WILES]