SEARCH
  • [:en]Recent Posts[:af]Onlangse bydraes

  • [:en]Categories[:af]Kategorieë

  • [:en]Archives[:af]Argiewe

phishing

New phishing e-mail causes confusionNuwe “phishing” e-pos veroorsaak verwarring

Tuesday, February 19th, 2013

If you receive an email claiming to be from the SU IT department (see example below), do not open it or click on any of the links or reply to the e-mail. The e-mail attempts to gain access to the university accounts using the sun.ac.za details that looks initially genuine.

This is a phishing email attempting to acquire your passwords and other information. Immediately delete the email and do not reply to it.

There are just a few of the obvious signs that this is a phishing e-mail designed to steal personal information from you. You should never respond to mail like this both at work and at home, and you should never reveal any personal details especially your username and password in an e-mail form or on a webpage that you access via an e-mail link.

IT will never request your username, password or other personal information by means of an e-mail.

  1. If it were a genuine message from Information Technology, there would be branding, and it would be in English and Afrikaans. This one has nothing like that in this e-mail.
  2. The grammar is particularly bad. (what is a “strong virus”?)
  3. We are university personnel and students or “users” we are not “subscribers”.
  4. Why would you have to enter your password in readable form in an insecure e-mail?
  5. There is no support@sun.ac.za e-mail address.
  6. If you do reply, you’ll see the default reply address is an unknown one and not a sun address.
  7. The links and the actual sender/server originate in Korea.

More information on phishing.

 

EXAMPLE OF “PHISHING” E-MAIL:

Dear sun.ac.za subscriber,

We are currently carrying out an upgrade on our system due to the fact that it has come to our notice that one or more of our subscribers are introducing a very strong virus into our system and it is affecting our network.We are trying to find out the specific person.

For this reason all subscribers are to provide their USER NAME AND PASSWORD for us to verify and have them cleared against this virus. Failure to comply will lead to the termination of your Account in the next 48 hours.

Information Required:
* User name: (…………….. )(Compulsory)
* Password: (……………………..)(Compulsory)
* Date of Birth: (……………………..) (optional)
* Country Or Territory: (………………) (optional)

http://webmail.sun.ac.za/owa/auth/logon.aspx

Hoping to serve you better.
Sincerely, Universiteit Stellenbosch University
********************************************************
This is an Administrative Message from sun.ac.za server. It is not spam.
From time to time, sun.ac.za server will send you such messages in
order to communicate important information about your subscription. *********************************************************

 

 

 

 

 

Indien u `n e-pos ontvang met onderstaande inhoud wat lyk of dit deur die US IT-afdeling gestuur is, moet onder geen omstandighede op die skakels kliek of daarop antwoord nie.

Hierdie is `n “phishing” e-pos wat poog om u wagwoord en ander inligting te oes. Verwyder dadelik die e-pos en moenie daarop reageer nie.

IT sal nooit gebruikers vra om hulle gebruikersname, wagwoorde of persoonlike inligting te verskaf deur middel van `n e-pos boodskap nie. Daar is ook `n paar ander tekens dat dit `n “phishing” e-pos is.

  1. As dit `n boodskap van IT was, sou dit sekere identifiseerbare kenmerke gehad het en dit sou in Engels en Afrikaans gewees het.
  2. Die grammatika is buitengewoon sleg. 
  3. Universiteitspersoneel is “users”, nie “subscribers” nie.
  4. Dis e-pos is `n leesbare, onsekure, maklik toeganklike formaat – hoekom sou IT vra dat jy jou wagwoord op so `n onsekure wyse verskaf? 
  5. Daar bestaan geen support@sun.ac.za e-pos adres nie.
  6. As jy wel op die “default reply” adres kliek, sal jy dadelik sien dis eintlik `n vreemde adres.
  7. Die skakels en die versender/bediener se oorsprong is in Korea. 

Meer inligting oor “phishing”.

 

 VOORBEELD VAN “PHISHING” E-POS:

Dear sun.ac.za subscriber,

We are currently carrying out an upgrade on our system due to the fact that it has come to our notice that one or more of our subscribers are introducing a very strong virus into our system and it is affecting our network.We are trying to find out the specific person.

For this reason all subscribers are to provide their USER NAME AND PASSWORD for us to verify and have them cleared against this virus. Failure to comply will lead to the termination of your Account in the next 48 hours.

Information Required:
* User name: (…………….. )(Compulsory)
* Password: (……………………..)(Compulsory)
* Date of Birth: (……………………..) (optional)
* Country Or Territory: (………………) (optional)

http://webmail.sun.ac.za/owa/auth/logon.aspx

Hoping to serve you better. 
Sincerely, Universiteit Stellenbosch University 
********************************************************
This is an Administrative Message from sun.ac.za server. It is not spam. 
From time to time, sun.ac.za server will send you such messages in 
order to communicate important information about your subscription. *********************************************************

 

 

 

 

 

No, SARS doesn’t really want to give you a refund and other phishing talesNee, SARS wil jou nie regtig betaal nie en ander skelmstories

Wednesday, February 6th, 2013

Every year we send out literally dozens of warning e-mails, and continue to do so, because despite the frequent warnings, people  still get caught falling for these tricks. 

Take note of the following scam from fraudsters claiming to be from SARS.
 
Emails are going out to university (and private addresses) seemingly coming from “SARS” informing them that they have a refund waiting for them.  (Wow! a tax refund) Clicking on the hyperlink in the email takes you to a fake “e-filing” site that has hyperlinks for the four big South African banks and instructions to log on to your Internet banking site for “confirmation of your details”.  When you follow the Nedbank link (as an example), you are taken to a copy of the Nedbank internet banking site that asks for profile, pin and password.  Supplying these takes you to a second page that asks you for your mobile number.  Submitting information on this page takes you to a page that requests the reference number sent to your cellphone.
 
Do not authorise any cellphone message that comes through if you end up in the above situation.  Furthermore, do not click on any hyperlinks in emails or divulge your account or mobile number details to anyone over the phone or via email.  Banks will never ask you to access internet banking through a link in an email, neither will banks ever ask for your mobile number when you access internet banking.

Another particulary sneaky phishing attack surfaced today. 

It comes from “Linda Perez” and has a subject line of “Administrator (Sorry for the inconvenience)” 

It asks you to contact the “sender” with your username and password so they can “expand your mailbox manually” 

Of course this is a phishing attack, and you should never respond to such mails. 

Do not respond, flag the sender as Junk Mail and delete the message.

ARTICLE BY DAVID WILES

Dwarsdeur die jaar stuur ons deurlopend waarskuwings aan personeel teen “phishing” e-posse en ongelukkig sal ons moet aanhou om dit te doen, aangesien vele personeel steeds, ten spyte van hierdie waarskuwings, telkens byt aan kuberkriminele se lokaas. 

Een hiervan is `n e-pos wat voorgee om van SARS te wees. 
 
E-posse wat lyk of dit vanaf SARS versend word, word gestuur aan universiteit  (en privaat) e-posse en beweer dat die ontvanger `n terugbetaling gaan kry. As jy kliek op die skakel, neem die e-pos jou na `n vals “e-filing” webwerf wat skakels het na vier groot Suid-Afrikaanse banke en instruksies om aan te teken op deur middel van internet bankdienste om jou details te “bevestig”.

As jy (byvoorbeeld) die Nedbank-skakel volg, word jy geneem na `n kopie van nie Nedbank internetdienste webwerf wat vra vir jou profiel, pin en wagwoord.  As jy hierdie inligting verskaf, word jy geneem na `n tweede blad waar daar vir jou selnommer gevra word. Deur die inligting te verskaf, word jy weereens na `n volgende blad geneem wat versoek dat die verwysingsnommer na jou selfoon gestuur word.   

Moet onder geen omstandighede enige magtiging gee per selfoonboodskap as jy in bogenoemde situasie beland nie. Moet ook nie kliek op enige skakels in e-posse of rekeningbesonderhede of selfoonnommer-details aan enigiemand verskaf per e-pos of telefonies nie.

Banke sal jou nooit versoek om hulle internetdienste deur middel van `n e-pos skakel te bereik nie en sal jou ook nie vra vir jou selnommer as jy internetbankdienste wil gebruik nie.  

`n Tweede “phishing”-aanval is ook tans in omloop. 

Dit kom van “Linda Perez” met die onderwerp “Administrator (Sorry for the inconvenience)” 

Die e-pos versoek dat jy bogenoemde persoon kontak met jou gebruikersnaam en wagwoord sodat hulle jou e-posbus “met die hand” kan vergroot.  Natuurlik is hierdie `n “phishing”-geval en jy moet nooit reageer op hierdie tipe e-posse nie. 

Moenie reageer nie, “flag” die versender as gemorspos en verwyder die boodskap. 

ARTIKEL DEUR DAVID WILES

Warning: New SARS, ABSA & eBucks phishing emailWaarskuwing: Nuwe SARS, ABSA & eBucks “phishing” e-pos

Tuesday, September 18th, 2012

If you receive an email claiming to be from ABSA regarding a payment from SARS or eBucks (see examples below), do not open it or click on any of the links. These are phishing emails attempting to acquire your passwords and other information. Immediately delete these emails and do not reply to them.


From: Absa Bank [mailto:lis@absa.co.z]
Sent: 18 September 2012 08:29 AM
To: …
Subject: SARS E-filing Payment Received

Dear Client,

A payment has been made into your account from SARS e-filing
In other to process and confirm this payment please do click here to login.
During this process, your RVN will be checked and verified.

Regards,


 

From: Absa Internet Banking [mailto:payment@absa.co.za]
Sent: 19 September 2012 15:01
To:
Subject: Payment Made To Your Online Banking!!

Absa Bank


Online Payment Made

Dear Customer,

A payment has been made to your account. To view the details of the payment, please click here to login. and enter the RVN that will be sent to your cellphone. please contact our support centreon 0860 123 000 . If you are calling from outside South Africa, call +27 11 299 4701 .

Our consultants are available between 8am and 9pm on weekdays, and 8am and 4pm on weekends and public holidays. 

The Internet banking Team

Moving Forward

Copyright Absa. All rights reserved.
Absa of South Africa Limited (Reg. No. 1962/000738/06). Authorised financial services provider. Registered credit provider (NCRCP15).

Disclaimer and confidentiality note:
Everything in this email and any attachments relating to the official business of Absa Group Limited is proprietary to the group.
It is confidential, legally privileged and protected by law. Absa does not own and endorse any other content.
The person addressed in the email is the sole authorised recipient.
Please notify the sender immediately if it has unintentionally reached you and do not read disclose or use the content in any way.

Absa cannot assume that the integrity of this communication has been maintained nor that it is free of errors, virus, interception or interference.
For our privacy policy or information about the Absa group visit our website at www.absa.co.za.

Absa email disclaimer and confidentiality note

Please go to http://www.absabank.co.za/ site/homepage/emaildisclaimer. html to read our email disclaimer and confidentiality note. Kindly email disclaimer@absabank.co.za (no content or subject line necessary) if you cannot view that page and we will email our email disclaimer and confidentiality note to you.


From: eBucks Credit [mailto:credit@ebucks.com]
Sent: 25 September 2012 11:56 AM
To:
Subject: eBucks Reward: You have earned a eBucks points !!!

Alert

We have detected unusual activity on this account and for your security are temporarily blocking access. To regain access to this account, please click here.

If you are unable to login, contact Member Services at 1-877-786-0722 for further assistance.

Indien jy `n e-pos ontvang wat lyk of dit van ABSA kom insake `n betaling van SARS of oor eBucks, moet onder geen omstandighede op die skakels kliek nie. Hierdie is `n “phishing” e-pos wat poog om jo wagwoord en ander inligting te oes. Verwyder dadelik die e-pos en moenie daarop reageer nie.


From: Absa Bank [mailto:lis@absa.co.z]u

Sent: 18 September 2012 08:29 AM

To: …

Subject: SARS E-filing Payment Received

Dear Client,

A payment has been made into your account from SARS e-filing

In other to process and confirm this payment please do click here to login.

During this process, your RVN will be checked and verified.

Regards,


From: Absa Internet Banking [mailto:payment@absa.co.za]

Sent: 19 September 2012 15:01

To:

Subject: Payment Made To Your Online Banking!!

Absa Bank

Online Payment Made

Dear Customer,

A payment has been made to your account. To view the details of the payment, please click here to login. and enter the RVN that will be sent to your cellphone. please contact our support centreon 0860 123 000 . If you are calling from outside South Africa, call +27 11 299 4701 .

Our consultants are available between 8am and 9pm on weekdays, and 8am and 4pm on weekends and public holidays. 

The Internet banking Team

Moving Forward

Copyright Absa. All rights reserved.

Absa of South Africa Limited (Reg. No. 1962/000738/06). Authorised financial services provider. Registered credit provider (NCRCP15).

Disclaimer and confidentiality note:

Everything in this email and any attachments relating to the official business of Absa Group Limited is proprietary to the group.

It is confidential, legally privileged and protected by law. Absa does not own and endorse any other content.

The person addressed in the email is the sole authorised recipient.

Please notify the sender immediately if it has unintentionally reached you and do not read disclose or use the content in any way.

Absa cannot assume that the integrity of this communication has been maintained nor that it is free of errors, virus, interception or interference.

For our privacy policy or information about the Absa group visit our website at www.absa.co.za.

Absa email disclaimer and confidentiality note

Please go to http://www.absabank.co.za/ site/homepage/emaildisclaimer. html to read our email disclaimer and confidentiality note. Kindly email disclaimer@absabank.co.za (no content or subject line necessary) if you cannot view that page and we will email our email disclaimer and confidentiality note to you.


From: eBucks Credit [mailto:credit@ebucks.com]

Sent: 25 September 2012 11:56 AM

To:

Subject: eBucks Reward: You have earned a eBucks points !!!

Alert

We have detected unusual activity on this account and for your security are temporarily blocking access. To regain access to this account, please click here.

If you are unable to login, contact Member Services at 1-877-786-0722 for further assistance.

Spam – not just processed meatSpam – meer as net `n blikkie vleis

Friday, September 14th, 2012

Spam, or junk mail is defined as identical, disruptive e-emails sent to a large amount of e-mail or cellphone users.  When a receiver clicks on one of the links in the message, he/she is diverted to a phishing website or websites containing malware.  Spam e-mails can also contain hidden malware scripts. The opposite of spam is, believe it or not, ham. In other words e-mails you WANT to receive.

The origin of the meaning of spam in this context, can be laid at the feet of the obscure British comedians known as Monty Python. In a 1970 sketch a group of Vikings in a restaurant starts chanting the word “spam” so incessantly that no-one else can have a conversation. Click here if you’d like to see the original Monty Python sketch where the word “spam” is mentioned 132 keer times in a mere three and a half minutes.

Even Google is amused by die word. The company once hid a surprise in their gmail users’ spam folder. When you clicked on your Spam folder, a webclip containing a variety of recipes for the original variety of spam. Amongst others recipes for  “Spam Primavera”, “Spam Swiss Pie”, “Creamy Spam Broccoli Casserole” and “Spam Veggie Pita Pockets”. The first spam was sent on 3 May 1978 to advertise a new computer system. It was sent to 600 ARPANET users and all 600 names were typed in by hand from a printed document. You can read the original e-mail here.

It is estimated that, from August 2010, 200 billion spam messages are sent per day. Lucky for Stellenbosch campus users, we have a fairly strict spam filer and huge amounts of spam bypass your inbox every day. If you still receive unnecessary spam, there are ways to decrease it even more. If it makes you feel any better though – according to Steve Ballmer, Microsoft CEO, Bill Gates receives four million e-mails a year and most of it’s spam.

SOURCES: http://blog.emailaddressmanager.comhttp://mashable.com & www.wikipedia.org

Gemorspos, of te wel “spam”, is wanneer identiese, meestal steurende,  boodskappe na `n groot hoeveelheid e-pos- of selfoongebruikers gestuur word. As `n ontvanger kliek op een van die skakels in die boodskap, word hulle herlei na strikroof webwerwe of webwerwe wat “malware” huisves. “Spam” e-posse kan ook versteekte “malware” skripte bevat. Die teenoorgestelde van “spam” – met ander woorde e-posse wat jy WIL ontvang, word natuurlik “ham” genoem. (ja regtig)  

Die eintlike oorsprong van die woord “spam” hou verband net die oorspronklike, geprosesseerde variasie en ons het die obskure Britse groep komediante van Monty Python om te blameer daarvoor. In die 1970 skets sing-praat `n groep Vikings die woord “spam” so onophoudelik in `n restaurant dat niemand anders kan praat nie. Kliek hier as jy die oorspronklike Monty Python skets wil sien waar die woord “spam” 132 keer gebruik word in 3 en `n half minute!

Selfs Google vind die woord interessant. Die maatskappy het op `n stadium `n verrassing versteek vir hulle gmail-gebruikers. As jy jou se “spam” leêr sou oopmaak, het dit omgeskakel na `n webinsetsel met `n verskeidenheid resepte vir regte spam. Onder andere resepte vir “Spam Primavera”, “Spam Swiss Pie”, “Creamy Spam Broccoli Casserole” en “Spam Veggie Pita Pockets”. Die eerste gemorspos is reeds op 3 Mei 1978 gestuur om `n nuwe rekenaarstelsel te adverteer. Dis gestuur vir 600 gebruikers van ARPANET en al 600 adresse is met die hand ingetik vanaf `n uitgedrukte dokument. Jy kan die e-pos hier lees.

Vanaf Augustus 2010 word daar geskat dat daagliks ongeveer 200 biljoen gemorspos boodskappe gestuur word.  Gelukkig gebruik ons op kampus redelike streng gemorspos filters om groot hoeveelheide onnodige e-posse uit ons posbusse te hou. As jy egter nogsteeds te veel kry na jou sin, gaan lees gerus hier. As dit jou enigsins beter laat voel – volgens Steve Ballmer, CEO van Microsoft, kry Bill Gates vier miljoen e-posse per jaar, waarvan die meeste gemorspos is.

SOURCES: http://blog.emailaddressmanager.comhttp://mashable.com & www.wikipedia.org

Money gone phishing?Slagoffer van strikrowery?

Friday, May 11th, 2012

The second you connect to the internet you put yourself at risk. Scary thought, but we tend to forget just how vulnerable we are and the easy targets we become when we’re not careful about our safety on the internet.

As an internet user you expose yourself on a daily basis to malicious software and the possibility of data theft. This includes phishing. Phishing scams use bogus e-mails and Web sites that seem legitimate but are actually designed to trick users into revealing personal and financial information. Computer criminals can then use the data to spy on or blackmail users, hijack their online accounts (including bank accounts), spread rumors, or operate under the victim’s identity.

According to our local Stellenbosch ABSA branch there are still some Stellenbosch University staff who fall prey to cybercriminals by clicking on phishing emails. To make sure you don’t become a victim, read more on phishing on IT’s self help wiki.

SOURCE: www.cnet.com

Die oomblik wanneer jy aanlyn is, loop jy sekere risikos. Dit klink miskien oordrewe, maar ons is geneig om te vergeet hoe blootgestel en watter maklike teikens ons is vir kuberkriminele as ons nie bedag is op ons aanlynveiligheid nie.

As `n internetgebruiker stel jy jou daagliks bloot aan kwaadaardige sagteware en die moontlikheid van datadiefstal. Dit sluit kuberstrikroof (“phishing”) in. Hierdie tipe elektroniese rooftogte gebruik skelm e-posse en webwerwe wat wettig lyk, maar eintlik so opgestel is om gebruikers te mislei sodat hulle persoonlike en finansiële inligting onthul. Kuberkriminele gebruik dan die data om, onder andere, toegang te kry tot aanlynrekeninge  (insluitende bankrekeninge) of die persoon se identiteit oor te neem.

Volgens die plaaslike Stellenbosch ABSA-tak is daar steeds Stellenbosch Universiteit personeel wat  in die slaggat val en slagoffers word van kuberkriminele deur op “phishing” e-posse te kliek. Om seker te maak jy word nie een van hulle nie, lees meer oor “phishing” op IT se selfhelp wiki.

BRON: www.cnet.com