<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Anti spam and general email security in a business environment &#187; spammers</title>
	<atom:link href="http://www.allspammedup.com/tag/spammers/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.allspammedup.com</link>
	<description></description>
	<lastBuildDate>Tue, 07 Feb 2012 15:00:43 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>FBI Declares &#8216;Gameover&#8217;, Link to ZeuS</title>
		<link>http://www.allspammedup.com/2012/01/fbi-declares-gameover-link-to-zeus/</link>
		<comments>http://www.allspammedup.com/2012/01/fbi-declares-gameover-link-to-zeus/#comments</comments>
		<pubDate>Tue, 31 Jan 2012 17:00:27 +0000</pubDate>
		<dc:creator>Malcolm James</dc:creator>
				<category><![CDATA[anti spam]]></category>
		<category><![CDATA[Fighting spam]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[Spam news]]></category>
		<category><![CDATA[anti phishing]]></category>
		<category><![CDATA[antispam]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[cybercriminals]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[spam email]]></category>
		<category><![CDATA[spammers]]></category>

		<guid isPermaLink="false">http://www.allspammedup.com/?p=6964</guid>
		<description><![CDATA[Malware developers seem to appreciate a little humor when it comes to naming their schemes. One of the latest email scams to invade inboxes everywhere is no exception, it seems, and the FBI has been quick to let businesses know &#8230;<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br/><br/><a href="http://www.allspammedup.com/2012/01/fbi-declares-gameover-link-to-zeus/">FBI Declares &#8216;Gameover&#8217;, Link to ZeuS</a></p>
]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-medium wp-image-6967" style="padding-left: 5px; padding-bottom: 5px; border-width: 0px; border-color: black; border-style: solid; margin: 10px;" src="http://www.allspammedup.com/wp-content/uploads/2012/01/bigstock_Space_Invaders_Game_Over_5142602-400x299.jpg" alt="" width="400" height="299" /></p>
<p><strong>Malware developers seem to appreciate a little humor when it comes to naming their schemes. One of the latest email scams to invade inboxes everywhere is no exception, it seems, and the FBI has been quick to let businesses know that if they don’t keep their eyes open for a phishing scam originating in an email from FDIC, NACHA and the Federal Reserve, opening the mail’s attachment could be one of the most devastating choices in a young 2012. Worse yet, this new scheme appears to be linked to the Lord of the Greek gods – or its eponymous malware, anyway.</strong></p>
<p>‘Game over’ is never a good thing, whether it means that your last ship has been destroyed and your quarter spent, whether it’s a lame and overused witticism that yet again has found its way into the mouth of Hollywood’s action hero <em>du jour</em>, and yes, even when cyber criminals are searching for just the right name for their latest piece of malware. While we’re not averse to debating the first two, our interest here is firmly with the latter. It seems the U.S. Federal Bureau of Investigation shares that interest, as evidenced by a <a target="_blank" href="http://www.fbi.gov/news/stories/2012/january/malware_010612">security bulletin</a> earlier this month that identifies a new email scam, one which cyber criminals have decided to call – what else? – <em>Gameover</em>.</p>
<p><span id="more-6964"></span></p>
<p>Gameover is a phishing attack that appears in the form of spam emails spoofing the Federal Deposit Insurance Corporation (FDIC), the Federal Reserve Bank, or the National Automated Clearing House Association (NACHA). Like a multitude of others, the scheme preys on users’ fears and/or lack of vigilance, informing them that there has been a problem with their bank account or an ACH transaction (ACH stands for Automated Clearing House, a network for financial institutions in the U.S.). Sufficiently frightened, recipients are encouraged to click the included link, which instead of resolving the issue, takes the user to a malicious site where the Gameover malware is executed.</p>
<p>The malware has been identified as a variant of ZeuS, a notorious piece of malware which has been responsible for stealing financial information through the practice of keylogging for a number of years. Once activated, the cyber crooks can steal banking information such as account numbers and passwords.</p>
<p><strong>As if that wasn’t enough…</strong></p>
<p>More than just a keylogger, however, ZeuS (and coincidentally, Gameover) has an added payload. According to the FBI:</p>
<blockquote><p>“After the perpetrators access your account, they conduct what’s called a distributed denial of service, or DDoS, attack using a botnet, which involves multiple computers flooding the financial institution’s server with traffic in an effort to deny legitimate users access to the site — probably in an attempt to deflect attention from what the bad guys are doing.”</p></blockquote>
<p><strong>But wait &#8211; there’s more!</strong></p>
<p>In what sounds like a novel involving international intrigue, FBI investigations have been able to trace the attacks as far as to jewelers, as the stolen funds are used to purchase “precious stones and expensive watches from high-end jewelry stores”. The crooks contact the jeweler, tell them what they’d like to purchase and inform them that they will wire the money the following day. The following day, a “money mule” – a person involved in the money laundering part of the crime – shows up at the jewelry store to pick up the merchandise. The jeweler confirms that the money (the stolen money from the spam scheme) is in their account and upon doing so, turns the merchandise over to the mule, who in turn delivers the merchandise to the crooks or converts it into cash that upon being transferred, is effectively laundered.</p>
<p>Wow &#8211; It really is the stuff of imagination, but even more interesting is that the FBI has suggested that the mules could be unsuspecting victims of those omnipresent ‘work at home’ schemes that we see everywhere. While the federal agency has confirmed that many of the mules are willing participants, it has also noted that an increasing number are likely people who have succumbed to these schemes and have been unwittingly recruited into laundering money stolen from victims of the spam scheme.</p>
<p>Be on the lookout for this one and advise your staff ASAP. At very most, it could be a story worthy of a novel. At very least, it could save you and your users plenty of headaches and lost funds.</p>
<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br/><br/><a href="http://www.allspammedup.com/2012/01/fbi-declares-gameover-link-to-zeus/">FBI Declares &#8216;Gameover&#8217;, Link to ZeuS</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.allspammedup.com/2012/01/fbi-declares-gameover-link-to-zeus/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Week in Review: You Can’t Spell Twitter Without ‘Twit’</title>
		<link>http://www.allspammedup.com/2012/01/week-in-review-you-can%e2%80%99t-spell-twitter-without-%e2%80%98twit%e2%80%99/</link>
		<comments>http://www.allspammedup.com/2012/01/week-in-review-you-can%e2%80%99t-spell-twitter-without-%e2%80%98twit%e2%80%99/#comments</comments>
		<pubDate>Wed, 25 Jan 2012 15:00:24 +0000</pubDate>
		<dc:creator>Malcolm James</dc:creator>
				<category><![CDATA[anti spam]]></category>
		<category><![CDATA[Fighting spam]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Spam news]]></category>
		<category><![CDATA[anti phishing]]></category>
		<category><![CDATA[antispam]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[botnets]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[cybercriminals]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[spam email]]></category>
		<category><![CDATA[spammers]]></category>

		<guid isPermaLink="false">http://www.allspammedup.com/?p=6897</guid>
		<description><![CDATA[The year’s off to a rousing start, with all sorts of interesting security news this week: Wikipedia led a temporarily successful foray against SOPA and PIPA by joining numerous websites that went dark for a day; the founder of Megaupload &#8230;<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br/><br/><a href="http://www.allspammedup.com/2012/01/week-in-review-you-can%e2%80%99t-spell-twitter-without-%e2%80%98twit%e2%80%99/">Week in Review: You Can’t Spell Twitter Without ‘Twit’</a></p>
]]></description>
			<content:encoded><![CDATA[<p><strong><a href="http://www.allspammedup.com/wp-content/uploads/2012/01/QR-Code-LG.png"><img class="alignright size-full wp-image-6901" style="border-width: 0px; border-color: black; border-style: solid; margin: 10px;" src="http://www.allspammedup.com/wp-content/uploads/2012/01/QR-Code-LG.png" alt="" width="248" height="248" /></a>The year’s off to a rousing start, with all sorts of interesting security news this week: Wikipedia led a temporarily successful foray against SOPA and PIPA by joining numerous websites that went dark for a day; the founder of Megaupload had his hands slapped when law enforcement officials told him resoundingly, “no, you can’t pirate copyrighted material” – insult was heaped upon injury when dozens of expensive cars were towed away to show him they were right; and Koobface – the Facebook botnet that has been harassing Zuckerberg for years – was taken down by its own creators after the Facebook gang teamed up with <em>The</em> <em>New York Times</em> to uncover and publish the identities of the worm’s owners. To round off the week, QR codes (like the one in the image here) may just be the latest form of spam, and news out of the Twitterverse suggests that Darwin’s cardinal rule is not only true, it’s actually a dire prophecy of our impending extinction.<span id="more-6897"></span></strong></p>
<p>The year’s less than a month old and it may already be shaping up as ‘the year of anything goes’. Topping the headlines was a <a target="_blank" href="http://www.circleid.com/posts/website_go_dark_protesting_sopa_and_pipa_senators_change_course/">mass protest</a> against seemingly inevitable anti-piracy legislation <a target="_blank" href="http://politics.nytimes.com/congress/bills/112/hr3261">SOPA (Stop Online Piracy Act)</a> and <a target="_blank" href="http://politics.nytimes.com/congress/bills/112/s968">PIPA (Protect I.P. Act)</a>, as innumerable websites intentionally went dark on January 18. Led by students’ greatest friend and perpetual source of dubious information Wikipedia, the activist movement irritated web surfers across the globe and scored one for the little guy as the bureaucrats in Washington, DC backed off the proposed legislation and shelved the bills, albeit temporarily. It&#8217;s practically inevitable that some wily spammer will take advantage of this controversy, so keep your eyes open and watch your back.</p>
<p>In a related story and in the spirit of fishy timing (i.e., the same week as the aforementioned protests), Megaupload founder, Kim Dotcom, was carted off along with several other geniuses who figured they would get away with providing a conduit for copyrighted material, all the while skimming millions of dollars off the illegal activity and thumbing their noses at the FBI. German national Mr. Dotcom, lamented as his lavish New Zealand mansion was raided and <a target="_blank" href="http://www.autoblog.nl/image-gallery?file=0_Divers/Inbeslagname_Supercars_Kim_Schmitz/">dozens of vintage cars were hauled away</a> as the spoils of war. Again, <a target="_blank" href="http://www.computerworld.com/s/article/9223601/Anonymous_dupes_users_into_joining_Megaupload_attack?taxonomyId=85">there&#8217;s more here than meets the eye</a>, especially now that <a target="_blank" href="http://www.scmagazineuk.com/anonymous-plans-fresh-offensive-against-sony/article/224033/">Anonymous has its back up.</a></p>
<p>In an LMAO moment, individuals responsible for Koobface – a nasty piece of malware that has been frustrating Facebook and Twitter users for years – have <a target="_blank" href="http://www.theregister.co.uk/2012/01/18/koobface_prime_suspect_outed/">taken down </a>their own command and control server after Facebook teamed up with <em>The New York Times</em> to uncover and embarrass five of the founders &#8211; Russian nationals living in St. Petersburg, Florida. The named individuals have scrambled to scrub their online profiles, but it’s highly doubtful that erasing their cyber identities will have much of an effect in the real world, where police carry real guns and real handcuffs.</p>
<p>Are QR codes the newest spam threat? Some people <a target="_blank" href="http://blog.spamfighter.com/malware-2/qr-codes-spam-or-malware-a-threat.html">think so</a>. QR – or Quick Response – codes were developed in the automotive industry and have been used for a while. Slowly entering the mainstream  over the past couple of years, they are in wide use in Japan, the UK and the US, amongst other countries. Popular because of their fast readability and relatively high storage capacity (compared to bar codes), the increased use of smartphones with cameras and QR reading apps have made the codes a prime target for manufacturers and retailers; heck, even Google’s looking at getting into the game by using QR codes as a <a target="_blank" href="http://www.marketingvox.com/the-qr-code-as-secure-log-in-courtesy-of-google-050418">secure login method</a>.  The problem is that QR codes can contain virtually <em>any</em> information, meaning that they are <a target="_blank" href="http://www.spamfighter.com/News-17314-Spam-Messages-Connect-with-QR-Codes.htm">already being exploited</a> by scammers and spear phishers. Keep an eye on this one, folks – and think twice before you take a picture of that code staring you in the face.</p>
<p>Finally, from the Twitterverse, here’s one that, no matter how much you shake your head, won’t rid that sickening feeling that the human race is on a collision course with extinction. Perhaps a case of ‘you can’t spell Twitter without ‘twit’, <a target="_blank" href="http://www.securitynewsdaily.com/1419-email-sharing-twitter-scams.html">this recent article</a> shows just how careless – or ignorant, or both – web users really are. Get this: over a twenty-four hour period, more than 11,000 Twitter users shared their email addies with the rest of the world. A safe practice if we were living in Thomas More’s Utopia, but it&#8217;s not the case if you reside anywhere on Earth, which is rife with people who would just love to use that information against you. This is just a guess, but it looks like spear phishing season is open and Twitter is the local watering hole.</p>
<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br/><br/><a href="http://www.allspammedup.com/2012/01/week-in-review-you-can%e2%80%99t-spell-twitter-without-%e2%80%98twit%e2%80%99/">Week in Review: You Can’t Spell Twitter Without ‘Twit’</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.allspammedup.com/2012/01/week-in-review-you-can%e2%80%99t-spell-twitter-without-%e2%80%98twit%e2%80%99/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>US-CERT Hooked by US-CERT Phishing Attack</title>
		<link>http://www.allspammedup.com/2012/01/us-cert-hooked-by-us-cert-phishing-attack/</link>
		<comments>http://www.allspammedup.com/2012/01/us-cert-hooked-by-us-cert-phishing-attack/#comments</comments>
		<pubDate>Tue, 17 Jan 2012 15:00:34 +0000</pubDate>
		<dc:creator>Malcolm James</dc:creator>
				<category><![CDATA[anti spam]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[anti phishing]]></category>
		<category><![CDATA[antispam]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[botnets]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[cybercriminals]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[email spam]]></category>
		<category><![CDATA[Fighting spam]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[phishing scam]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[spam email]]></category>
		<category><![CDATA[Spam news]]></category>
		<category><![CDATA[spammers]]></category>

		<guid isPermaLink="false">http://www.allspammedup.com/?p=6838</guid>
		<description><![CDATA[This week, a phishing attack landed in the inboxes of several US government agencies, spoofing the US government’s cyber security watchdog and response agency. Complete with attachments, the e-mail’s payload was a nasty little virus that has already been tracked &#8230;<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br/><br/><a href="http://www.allspammedup.com/2012/01/us-cert-hooked-by-us-cert-phishing-attack/">US-CERT Hooked by US-CERT Phishing Attack</a></p>
]]></description>
			<content:encoded><![CDATA[<p><strong><a href="http://www.allspammedup.com/wp-content/uploads/2012/01/information-assurance-cyber-threat.jpg"><img class="alignright size-full wp-image-6842" style="border-width: 0px; border-color: black; border-style: solid; margin: 10px;" src="http://www.allspammedup.com/wp-content/uploads/2012/01/information-assurance-cyber-threat.jpg" alt="" width="398" height="297" /></a>This week, a phishing attack landed in the inboxes of several US government agencies, spoofing the US government’s cyber security watchdog and response agency. Complete with attachments, the e-mail’s payload was a nasty little virus that has already been tracked back to Mother Russia. To make matters a little embarrassing, perhaps, it’s not enough that the agency which was spoofed in the attack has reported a disruption of its own systems, but it’s also the government body responsible for identifying and mitigating just this type of thing.<span id="more-6838"></span></strong></p>
<p>On January 11, <a target="_blank" href="http://www.scmagazineuk.com/phishing-campaign-disrupts-us-cert/article/222649/">news</a> <a target="_blank" href="http://www.net-security.org/malware_news.php?id=1958">erupted</a> of a rather malicious little spoof email that circulated through the mail servers of several national, state and local government agencies and even private sector employees. The scam in question was an email pretending to be the product of US-CERT, the United States Computer Emergency Readiness Team, a division of the Department of Homeland Security.</p>
<p>Sent with fake source addresses that included <strong>soc@us-cert.gov</strong> and the subject line <strong>Phishing incident report call number: PH000000XXXXXXX</strong> and an attachment named <strong>US-CERT Operation Center Report XXXXXXX.zip</strong>, a nasty little file which was anything but a report. In fact, after some quick investigation, the attachment – which executes a file named <strong>US-CERT Operation CENTER Reports.eml.exe </strong>– was discovered to be a variant of the infamous Zeus virus known as ‘Ice-IX’, a keylogger that steals banking and other personal information. As if that isn’t enough, the worm also bypasses firewalls and other protection schemes.</p>
<p><strong>Oh, the Irony!</strong></p>
<p>US-CERT responding by doing what it’s supposed to do: it posted a <a target="_blank" href="http://www.us-cert.gov/current/#phishing_campaign_using_spoofed_us">bulletin</a> and notified agencies. And while not admitting that anyone at US-CERT actually opened the little bugger, an operator at the agency has stated</p>
<blockquote><p>“difficulty receiving emails due to the phishing campaign”</p></blockquote>
<p>according to <a target="_blank" href="http://www.scmagazineuk.com/phishing-campaign-disrupts-us-cert/article/222649/">SC Magazine</a>. A little embarrassing, considering that this is just the type of thing US-CERT has been mandated to protect against, it’s a forgivable fumble considering that the scam artists continue to get <a href="http://www.allspammedup.com/2011/08/phishin%E2%80%99-magicians-think-the-spammers-are-getting-smarter-you%E2%80%99re-right/">wilier</a> and more creative in their attacks.</p>
<p>In an ‘it never hurts to state the obvious’ moment, US-CERT included the following advisories in its security bulletin:</p>
<p>US-CERT encourages users to do the following to reduce the risks associated with this and other phishing campaigns:</p>
<ul>
<li>Do not open the attachments in email messages from unknown sources.</li>
<li>Install anti-virus software and keep virus signatures files up-to-date.</li>
<li>Refer to <a target="_blank" href="http://www.us-cert.gov/reading_room/emailscams_0905.pdf" target="_self">Recognizing and Avoiding Email Scams</a> (pdf) documents for more information on avoiding email scams.</li>
<li>Refer to the <a target="_blank" href="http://www.us-cert.gov/cas/tips/ST04-014.html" target="_self">Avoiding Social Engineering and Phishing Attacks</a> document for information on social engineering attacks.</li>
<li>Refer to <a target="_blank" href="http://www.us-cert.gov/cas/tips/ST05-006.html" target="_self">Recovering from Viruses, Worms, and Trojan Horses</a> document for additional information on how to recover from malware.</li>
</ul>
<p><strong>From Russia with Malice</strong></p>
<p>The story gets a little more interesting from here, when Nextgov.com <a target="_blank" href="http://cybersecurityreport.nextgov.com/2012/01/fake_us-cert_e-mails_contain_banking_virus_traced_to_russia.php">reported</a> on Wednesday that</p>
<blockquote><p>“Researchers outside of US-CERT traced the malicious software to a botnet – a remotely-controlled network of infected computers – that is taking commands from computers located in Russia.”</p></blockquote>
<p>It’s not clear why researchers <em>outside</em> of US-CERT traced the location – it would seem natural that US-CERT was capable of doing that sort of thing. Isn’t it logical to assume that’s what the “response” part of their name is for?</p>
<p>Regarding the attack and its location, there’s clearly no love here, only malice. So why <em>was</em> an e-mail from Russia so specifically targeted at and around US-CERT and US government agencies? It’s extremely unlikely that this was state sponsored – the method used and speed at which it was detected suggest something far too ham-handed to be anything <em>that</em> nefarious. So taking that into consideration, the incident still poses something of an oddity. If a group, say organized crime – which is alive and well in Mother Russia – was responsible for the attack, what could they possibly hope to gain by phishing government agencies in the US? And if it was some cyberdude named Boris, who figured he’d take time from his daily routine of scamming innocents to pry into US-CERT’s activities, he certainly isn’t the brightest cyberdude in cyberspace.</p>
<p>It’s very mysterious, this one, and it will be interesting to see what, if anything, comes from the follow-up investigations.</p>
<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br/><br/><a href="http://www.allspammedup.com/2012/01/us-cert-hooked-by-us-cert-phishing-attack/">US-CERT Hooked by US-CERT Phishing Attack</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.allspammedup.com/2012/01/us-cert-hooked-by-us-cert-phishing-attack/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Is 2012 the Year of Social Spam?</title>
		<link>http://www.allspammedup.com/2012/01/is-2012-the-year-of-social-spam/</link>
		<comments>http://www.allspammedup.com/2012/01/is-2012-the-year-of-social-spam/#comments</comments>
		<pubDate>Fri, 13 Jan 2012 15:00:18 +0000</pubDate>
		<dc:creator>Jeff Orloff</dc:creator>
				<category><![CDATA[Spam news]]></category>
		<category><![CDATA[anti spam]]></category>
		<category><![CDATA[antispam]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[Fighting spam]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[spammers]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://www.allspammedup.com/?p=6801</guid>
		<description><![CDATA[As the years pass, we often identify them with significant changes or events that occur of their span. Optimists often look for the most positive events over the year to attach to the label, The Year of…, realists however, take &#8230;<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br/><br/><a href="http://www.allspammedup.com/2012/01/is-2012-the-year-of-social-spam/">Is 2012 the Year of Social Spam?</a></p>
]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.allspammedup.com/wp-content/uploads/2012/01/spam2.jpg"><img class="alignright size-medium wp-image-6826" style="border-width: 0px; border-color: black; border-style: solid; margin: 10px;" title="spam2" src="http://www.allspammedup.com/wp-content/uploads/2012/01/spam2-400x262.jpg" alt="" width="320" height="210" /></a>As the years pass, we often identify them with significant changes or events that occur of their span.</p>
<p>Optimists often look for the most positive events over the year to attach to the label, <em>The Year of…</em>, realists however, take a different approach. And while 2012 is still young and holds a lot of promise, this year could very well be known as the year of social spam.<span id="more-6801"></span></p>
<p>Social spam is nothing new. In fact, spam first infiltrated Internet bulletin boards in 1994 to mark the first major commercial spam campaign when Laurence Carter and Martha Siegel, a husband and wife team of lawyers, posted bulk messages to Usenet groups advertising their immigration law services in what became known as Green Card spam.</p>
<p>Social interaction on today’s Internet is far more sophisticated than the simple posting of messages and hyperlinks however. Nowadays, spammers turn to social networks and guise their spam as links, content, video, audio and executable files.</p>
<p>The nature of social spam has also changed as the platforms that deliver these messages have also developed over time.</p>
<p>No longer is spam only used to deliver advertising and marketing messages alone. With a more sophisticated field on which to play, spammers have used social sites to not only deliver their advertising, but also malware that: steals credit card numbers, captures user names and passwords and turns computers into zombies.</p>
<p>But if social spam has been a problem for so long, why would 2012 be any different? Take a look and see…</p>
<h2>The Facebook Example</h2>
<p>On January 4, 2012 the Wall Street Journal reported that social spam is on the rise and to combat this, social networks are hiring more staff to help fight this problem. Facebook was named specifically because according to reports, the volume of spam on Facebook is growing faster than its user base.</p>
<p>On Facebook, spam usually spreads when users are tricked into liking, and then sharing, content that is spam. This practice, known as like-jacking, usually works when a user’s computer is infected with malware that allows the spammer to take control of the user’s Facebook account.</p>
<p>The spammer then posts a message on your friend’s profile that would be interesting to others. Commonly, free dinner coupons are used as the bait as are offers for free iPads or other give aways.</p>
<p>When the user’s friends click on the free offer, they are instructed to download the coupons. These coupons actually contain malware that infects the computers of the user’s friends thus continuing the cycle.</p>
<p>Of course the malware does more than just spread itself via Facebook. It can be used to deliver Trojan horses, keystroke loggers, or any other type of malware.</p>
<p>And just how prevalent are these messages? By Facebook’s own admission, they block over 200 million malicious actions every day. In 2008 the company employed four engineers working to fight malicious use of their site. The same department today, named site integrity, now has 31 team members. Additionally, there are 46 people working on security 300 focused on user issues and over 1,000 others (engineers, lawyers, risk analysts, etc.) who help to fight spam on the site in other ways.</p>
<h2>Others Not Immune</h2>
<p>Of course other social networks and content sharing sites are hardly immune to the problem of social spam. Twitter has long been a hot bed for spammy posts created by malicious users.</p>
<p>Twitter, by nature, set itself up for spam from the very beginning. As a great way to share content to other like-minded users, Twitter allowed people to share short messages that were less than 140 characters long; short, sweet and to the point.</p>
<p>Since URLs were often lengthy, companies – including Twitter – developed URL shorteners. Now, <a target="_blank" href="../../../../../">http://www.allspammedup.com</a> could become <a target="_blank" href="http://bit.ly/3KmvyZ">http://bit.ly/3KmvyZ</a> to save precious character space.</p>
<p>The problem is, no one really knows if <a target="_blank" href="http://bit.ly/3KmvyZ">http://bit.ly/3KmvyZ</a> will take you to All Spammed Up or a malicious web site.</p>
<p>Google also out how quickly spam could infiltrate even a carefully planned social network.</p>
<p>Originally opened through an invite only process, Google+ users found the site a welcome break from other social sites that had turned into spam havens. Since early adopters were tech savvy, spam was quickly reported and accounts spewing spam were shut down.</p>
<p>Then came the public release and the ability to create business pages and spammy comments and shares began to fold the network causing one well known legitimate marketing professional to comment:</p>
<p><em>Wow, Google+ must be taking off. Spotted not one but two pieces of comment spam today.</em></p>
<p>As users find it easier than ever to share content with their friends and family, spammers will find it easier to manipulate this process. Because we have become so trusting of the content our “friends” share with us, we never consider the fact that what may be the coolest thing on someone’s wall may just wind up infecting our computer.</p>
<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br/><br/><a href="http://www.allspammedup.com/2012/01/is-2012-the-year-of-social-spam/">Is 2012 the Year of Social Spam?</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.allspammedup.com/2012/01/is-2012-the-year-of-social-spam/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Bold Predictions for 2012 (Part 2)</title>
		<link>http://www.allspammedup.com/2012/01/bold-predictions-for-2012-part-2/</link>
		<comments>http://www.allspammedup.com/2012/01/bold-predictions-for-2012-part-2/#comments</comments>
		<pubDate>Wed, 11 Jan 2012 15:00:33 +0000</pubDate>
		<dc:creator>Malcolm James</dc:creator>
				<category><![CDATA[anti spam]]></category>
		<category><![CDATA[anti spam humor]]></category>
		<category><![CDATA[Fighting spam]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Spam news]]></category>
		<category><![CDATA[anti phishing]]></category>
		<category><![CDATA[antispam]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[botnets]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[cybercriminals]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[phishing scam]]></category>
		<category><![CDATA[scam]]></category>
		<category><![CDATA[scammers]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[spam email]]></category>
		<category><![CDATA[spammers]]></category>

		<guid isPermaLink="false">http://www.allspammedup.com/?p=6787</guid>
		<description><![CDATA[In Part 2 of our look at what you can expect in the coming year, faint rumblings out of Japan suggest that one prediction from Part 1 of this article has already come true. If the very real prospect of &#8230;<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br/><br/><a href="http://www.allspammedup.com/2012/01/bold-predictions-for-2012-part-2/">Bold Predictions for 2012 (Part 2)</a></p>
]]></description>
			<content:encoded><![CDATA[<p><strong><a href="http://www.allspammedup.com/wp-content/uploads/2012/01/2012_energy_conservation.jpg"><img class="alignright size-medium wp-image-6791" style="padding-left: 5px; border-width: 0px; border-color: black; border-style: solid; margin: 10px;" src="http://www.allspammedup.com/wp-content/uploads/2012/01/2012_energy_conservation-400x250.jpg" alt="" width="400" height="250" /></a>In Part 2 of our look at what you can expect in the coming year, faint rumblings out of Japan suggest that one prediction from <a href="http://www.allspammedup.com/2012/01/looking-back-at-2011-and-bold-predictions-for-2012-part-1/">Part 1</a> of this article has already come true. If the very real prospect of becoming an innocent casualty of war isn’t enough to make you run backward toward the year that just passed, these bold predictions reveal how hackers will develop an even stronger sense of camaraderie, and how mobility is sure to become a four-letter word. And if you thought spamming and Internet scams made it personal in 2011, you ain’t seen nuthin’ yet.<span id="more-6787"></span></strong></p>
<p>How about that? 2012 wasn’t even seven days old when news out of Japan this week revealed some eerie premonitions of the things to come and earmarks of a bold prediction made one week ago.  <a target="_blank" href="http://www.engadget.com/2012/01/06/japan-working-on-powerful-cyber-weapon-knows-best-defense-is-a/">Engadget</a>, <a target="_blank" href="http://www.zdnet.com/news/japan-develops-malware-cyberweapon/6335855">ZD Net</a> and other media outlets are reporting that the Japanese government has been working in concert with Fujitsu since 2008 to develop a powerful ‘cyber weapon’ – a piece of software that, upon the detection of a cyber attack (such as DDoS, for example) tracks the attack back to the source.</p>
<p>Sounds pretty straightforward, right? Sure, until you consider that the software also attacks and disables every machine it finds along the trail. The goal, Engadget reports:</p>
<blockquote><p>“is to stop the spread of a malicious piece of code by finding and shutting down, not just the source, but all middleman PCs that are also now potential hosts. In some admittedly extreme scenarios this weapon could potentially spiral out of control, taking out far more computers than intended.”</p></blockquote>
<p>Hmm&#8230; Botnets are nothing more than large numbers of unsuspecting computers carrying out their attacks at the behest of the infector and ignorance of the computer’s owner. Japan’s little toy, while it sounds like it might be fun to take for a spin, could have the unpleasant and unprecedented effect of being the cause of some serious collateral damage. Casualties of war? Here’s a tip for everyone: while you still have a chance, give that fave desktop or laptop of yours a great big hug before it’s too late.</p>
<p><strong>1. Hackers of the World, Unite</strong></p>
<p>Robin Hood met Mafia Boy last year as hacktivism took center stage. Indeed, 2011 was an entertaining year for anyone who followed the exploits of <a target="_blank" href="http://techland.time.com/2011/09/28/hack-collective-anonymous-tries-journalism-with-analytics-site/">Anonymous</a> and <a target="_blank" href="http://www.allspammedup.com/2011/06/hatriot-games-sony-hacked-again-nintendo-a-wii-bit-compromised/">LulzSec</a>. The drama unfolded like a kabuki play born in the mind of Ken Kesey and brought to life by a troupe of mimes with Tourette Syndrome, and there were even a few <a href="http://techland.time.com/2011/09/23/f-b-i-busts-lulzsec-anonymous-suspects-across-u-s/">arrests</a> along the way to make this reality show really…ahem… arresting.</p>
<p><strong>Prediction</strong>: We will see some new hacking activity from these groups, with some high profile web takedowns in the process. While that’s not a stretch, this is: hacker groups like Anonymous and LulzSec will grow in size substantially, resembling an ‘occupy’ type movement that will take the war online. The civil and social unrest of 2011 will turn to face the financial behemoth that is the Internet.</p>
<p><strong>2. Mobility Means Vulnerability</strong></p>
<p>If we learned anything about spam in 2011, it’s that spam is like that proverbial bum of a brother-in-law who’s been living in your basement for the past two years. It’s not going away, good luck making it work for you, and you <em>will</em> be out-of-pocket at some point. Spammers continued to use every means at their disposal in 2011, with SMS spam becoming a real pain in the neck. Security flaws in the two most popular smartphone platforms – iOS and Android – just accented what we already suspected: that spammers and purveyors of malware had taken their show on the road.</p>
<p><strong>Prediction:</strong> 2012 will see a massive increase in mobile spam, and mobile devices will become the swords upon which we will live or die unless we get mobile security under control.</p>
<p><strong>3. It’s Nothing Personal…Well, Actually, It Is</strong></p>
<p>A significant development in spam and phishing in 2011 was the way in which the scam artists were getting <a href="http://www.allspammedup.com/2011/08/phishin%E2%80%99-magicians-think-the-spammers-are-getting-smarter-you%E2%80%99re-right/">smarter</a>; you know, smarter in much the same way that a chunk of igneous rock living at the bottom of a fetid riverbed is smarter than a rotting patch of lichen hanging for dear life to the side of an oak tree. Like it or not, the scambags are wilier, finding new and innovative ways to pick your pocket without actually residing in the same time zone.</p>
<p><strong>Prediction:</strong> The scambags will become even cleverer in their assaults, finding new methods to lull people into a false sense of security. How this will occur remains to be seen, but our bold prediction is that it will most likely involve highly targeted, multilevel campaigns where the scammer will use detailed knowledge of the targets, and multiple contact methods like email, phone, SMS and even snail mail to enact their evil schemes.</p>
<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br/><br/><a href="http://www.allspammedup.com/2012/01/bold-predictions-for-2012-part-2/">Bold Predictions for 2012 (Part 2)</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.allspammedup.com/2012/01/bold-predictions-for-2012-part-2/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Looking Back At 2011 And Bold Predictions for 2012 (Part 1)</title>
		<link>http://www.allspammedup.com/2012/01/looking-back-at-2011-and-bold-predictions-for-2012-part-1/</link>
		<comments>http://www.allspammedup.com/2012/01/looking-back-at-2011-and-bold-predictions-for-2012-part-1/#comments</comments>
		<pubDate>Thu, 05 Jan 2012 15:00:59 +0000</pubDate>
		<dc:creator>Malcolm James</dc:creator>
				<category><![CDATA[anti spam]]></category>
		<category><![CDATA[Fighting spam]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Spam news]]></category>
		<category><![CDATA[anti phishing]]></category>
		<category><![CDATA[antispam]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[botnets]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[cybercriminals]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[spam email]]></category>
		<category><![CDATA[spammers]]></category>

		<guid isPermaLink="false">http://www.allspammedup.com/?p=6717</guid>
		<description><![CDATA[In a turn of events appropriate for the most tumultuous year in cybercrime, 2011’s body is barely cold and we’re already smelling something suspicious from its decomposing carcass. Rumors of two worms, one well-known and the other relatively new on &#8230;<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br/><br/><a href="http://www.allspammedup.com/2012/01/looking-back-at-2011-and-bold-predictions-for-2012-part-1/">Looking Back At 2011 And Bold Predictions for 2012 (Part 1)</a></p>
]]></description>
			<content:encoded><![CDATA[<p><strong><a href="http://www.allspammedup.com/wp-content/uploads/2012/01/2011_2012.jpg"><img class="alignright size-medium wp-image-6767" style="border-width: 0px; border-color: black; border-style: solid; margin: 10px;" title="2011_2012" src="http://www.allspammedup.com/wp-content/uploads/2012/01/2011_2012-400x400.jpg" alt="" width="320" height="320" /></a>In a turn of events appropriate for the most tumultuous year in cybercrime, 2011’s body is barely cold and we’re already smelling something suspicious from its decomposing carcass. Rumors of two worms, one well-known and the other relatively new on the scene, have some of us wondering what will happen next in 2012, and the year has only just begun. In an attempt to put the preceding year into perspective, we take a look at what might be in store for the new year and beyond with some bold and not so far-fetched predictions for 2012.<span id="more-6717"></span></strong></p>
<p><strong>PREDICTION: A Shiny New Worm with Every Census Report, Tax Return and Piece of Monetary Currency</strong></p>
<p><em>First up for 2012 is a prediction that all bets will be off when it comes to understanding the nature – and source – of some of the most insidious malware in the known universe. In fact, the threat and very nature of the state-sponsored malware will only get more confusing, and most likely more disturbing, as we discover where and how it’s being used.</em></p>
<p>Discovered in 2010, Stuxnet was in the news again in 2011. A worm designed to target and damage industrial control systems (like the kind found in nuclear plants), it has been a source of great debate over who created it and what its ultimate purpose represented; but few could argue that with more than forty percent of Stuxnet’s infections landing in Iran, the nation was most likely the target from the get-go. Russia and others wasted no time pointing the finger squarely at the United States and Israel as the benefactors of the worm, which surely must be state-sponsored.</p>
<p>It seemed inconceivable that anything could top the news that broke late in the year about <a href="http://www.allspammedup.com/2011/12/conficker-linked-to-stuxnet-conspiracy-theory-activity-up-530/">Stuxnet’s connection to Conficker</a>, suggesting that the latter, a notorious botnet, was used to deliver the payload for Stuxnet. If rumors are true that Stuxnet <em>is</em> state-sponsored, the implication that spam might have been part of the delivery method can and must only leave a bad taste in people’s mouths.</p>
<p>As 2011 wheezed out its last few painful breaths however, a new development occurred in this bizarre tale, as it was <a target="_blank" href="http://www.pcmag.com/article2/0,2817,2398201,00.asp">revealed</a> that ongoing research by Kaspersky Labs on Stuxnet uncovered a direct link between Stuxnet and Duqu – a worm, discovered only in September, which shares many of the attributes of Stuxnet. In fact, media outlets are reporting that the worms are suggestive of an ‘arsenal’ of malware that has been in development as early as 2007. The code kernel has been dubbed ‘Tilded’, in recognition of the author’s habit of using filenames that begin with ‘~d’.</p>
<p><strong>The Prediction:</strong> Keep your eyes open for Tilded. We will continue to see new pieces of the puzzle unveil, and they will point at the government of a country – or perhaps multiple countries working in concert – all but providing conclusive proof of the party (or parties) responsible for this new and nefarious form of warfare. What will make this story even more notorious, however, is when it becomes clear that an unsuspecting public has been a major delivery mechanism for this 21<sup>st</sup> century warfare, through the use of spam, malware, and botnets. And if that is true, it could very well be the case that some of those spammers you curse on a daily basis are actually nation states using spam to mask their cyber intelligence activities.</p>
<p><strong>PREDICTION: The Cloud Will Get Stormy</strong></p>
<p>While the Cloud was one of those recurring themes that flew, for the most part, under the radar in 2011, companies like Apple and Microsoft continued to push it like it is a silver bullet and a cure-all for everything that ails small companies to major corporations.</p>
<p><strong>The Prediction:</strong> 2012 will see at least three Cloud-based security events, most likely linked in some way to spam, malware, hack attacks or compromised mobile devices. Furthermore, they will be high profile events, targeting Fortune 1000 or Global 1000 companies, or less likely a government agency. Anonymous will take credit for at least one of the breaches, and there will be a link with one of the breaches to North Korea and/or China.</p>
<p><strong>Next week, in Part 2 of this story, we’ll take a look at some other bold and controversial predictions for 2012, and how we can learn something from 2011 &#8211; but only if we&#8217;re ready and willing to listen to it.</strong></p>
<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br/><br/><a href="http://www.allspammedup.com/2012/01/looking-back-at-2011-and-bold-predictions-for-2012-part-1/">Looking Back At 2011 And Bold Predictions for 2012 (Part 1)</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.allspammedup.com/2012/01/looking-back-at-2011-and-bold-predictions-for-2012-part-1/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Coffee, the New York Times and Spam</title>
		<link>http://www.allspammedup.com/2012/01/coffee-the-new-york-times-and-spam/</link>
		<comments>http://www.allspammedup.com/2012/01/coffee-the-new-york-times-and-spam/#comments</comments>
		<pubDate>Wed, 04 Jan 2012 15:00:58 +0000</pubDate>
		<dc:creator>Jeff Orloff</dc:creator>
				<category><![CDATA[Spam news]]></category>
		<category><![CDATA[anti spam]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[cybercriminals]]></category>
		<category><![CDATA[Delivery (commerce)]]></category>
		<category><![CDATA[E-mail spam]]></category>
		<category><![CDATA[Email address]]></category>
		<category><![CDATA[Fighting spam]]></category>
		<category><![CDATA[New York Times]]></category>
		<category><![CDATA[spammers]]></category>
		<category><![CDATA[Subscription business model]]></category>
		<category><![CDATA[Times]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[WikiPedia]]></category>

		<guid isPermaLink="false">http://www.allspammedup.com/?p=6702</guid>
		<description><![CDATA[Most of us have come to recognize spam when it shows up in our inbox. To many people, the easiest way to determine if an email message can be trusted enough to warrant opening and reading it is to look &#8230;<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br/><br/><a href="http://www.allspammedup.com/2012/01/coffee-the-new-york-times-and-spam/">Coffee, the New York Times and Spam</a></p>
]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.allspammedup.com/wp-content/uploads/2012/01/New-York-Times.jpg"><img class="alignright size-medium wp-image-6711" src="http://www.allspammedup.com/wp-content/uploads/2012/01/New-York-Times-400x267.jpg" alt="" width="280" height="187" /></a>Most of us have come to recognize spam when it shows up in our inbox.</p>
<p>To many people, the easiest way to determine if an email message can be trusted enough to warrant opening and reading it is to look at the sender. Unfortunately, the inboxes of our family and friends can be compromised rather easily and used to send spam.</p>
<p>But surely the email of a large, respectable news organization would be immune to the trickery and masquerades of spammers, right?<span id="more-6702"></span></p>
<p>Apparently not.</p>
<p>On December 28, 2011 subscribers to the New York Times received an email from the news company. The email informed these recipients that although their recent request to cancel their home delivery subscription for the newspaper had been received, the Times was appealing to them to reconsider their decision and remain on as a customer:</p>
<blockquote><p>Our records indicate that you recently requested to cancel your home delivery subscription. Please keep in mind when your delivery service ends, you will no longer have unlimited access to NYTimes.com and our NYTimes apps.</p>
<p>We do hope you’ll reconsider.</p>
<p>As a valued Times reader we invite you to continue your current subscription at an exclusive rate of 50% off for 16 weeks. This is a limited-time offer and will no longer be valid once your current subscription ends.*</p>
<p>Continue your subscription and you’ll keep your free, unlimited digital access, a benefit available only for our home delivery subscribers. You’ll receive unlimited access to NYTimes.com on any device, full access to our smartphone and iPad<sup>®</sup> apps, plus you can now share your unlimited access with a family member.<sup>†</sup></p>
<p>To continue your subscription call <a target="_blank" href="1-877-698-0025" target="_blank">1-877-698-0025</a> and mention code 38H9H (Monday–Friday, 8:30 a.m. to 8:30 p.m.; Saturday, 9 a.m. to 3 p.m. E.D.T.).</p></blockquote>
<p>In a day and age where a majority of people get their news from electronic sources instead of traditional newsprint, this doesn’t sound like anything out of the ordinary.</p>
<p>However shortly after these emails went out, a tweet from the Times’ account went out stating:</p>
<p><em>If you received an email today about canceling your NYT subscription, ignore it. It’s not from us.</em></p>
<p>Instead of a few people being asked to reconsider their choice to cancel newspaper delivery services, the email went out 8 million people. All of them subscribers to services of the New York Times, but some of them only subscribed to the digital edition of the newspaper. They weren’t even customers of the home delivery service.</p>
<h2>Spreading the News Over Twitter</h2>
<p>As soon as the tweet was released, the speculation started. Although the New York Times claimed that they were, “working to coordinate a response,” many on Twitter pointed the finger at Epsilon, the email firm that was compromised last spring.</p>
<p>When asked by BetaBeat if this was a result of the recent breach, Epsilon spokesperson Jessica Simon stated:</p>
<blockquote><p>“This is the first I’ve heard of it. Let me talk with our email group and get back to you.”</p></blockquote>
<h2>Jumping the Gun</h2>
<p>Once the smoke had cleared and the fingers had been pointed and redirected, it turned out that the email actually was sent from the New York Times’ email servers. They immediately released the following statement:</p>
<blockquote><p>An email was sent earlier today from The New York Times in error. This email should have been sent to a very small number of subscribers, but instead was sent to a vast distribution list made up of people who had previously provided their email address to The New York Times. We regret this error and we regret our earlier communication noting that this email was SPAM.</p></blockquote>
<p>It is nice that they regret their error, however they shouldn’t regret calling their errant mass mailing spam, because that is exactly what it is.</p>
<p>According to WikiPedia, Spam is unsolicited bulk, or unsolicited commercial, email. It is the practice of sending unwanted email messages, frequently with commercial content, in large quantities to an indiscriminate set of recipients.</p>
<p>Companies, especially larger ones, need to understand that when someone trusts them with their email address they are assuming that this information is safe. Safe from cyber-criminals looking to harvest these addresses and safe from trusted employees accidentally sending out indiscriminate emails causing panic.</p>
<p>Had this incident in fact been caused by a security breach, the result would have been similar. Customers would have been hassled by illegitimate messages, people would have been less productive as they were forced to deal with this fake warning and resources were spent dealing with the mess.</p>
<p>Just because it was an email that was sent by mistake doesn’t mean the effects are any less irritating or costly.</p>
<p>If it walks like a duck, and sounds like a duck… well, you get the point.</p>
<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br/><br/><a href="http://www.allspammedup.com/2012/01/coffee-the-new-york-times-and-spam/">Coffee, the New York Times and Spam</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.allspammedup.com/2012/01/coffee-the-new-york-times-and-spam/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>5 New Year&#8217;s Resolutions For Spammers</title>
		<link>http://www.allspammedup.com/2011/12/5-new-years-resolutions-for-spammers/</link>
		<comments>http://www.allspammedup.com/2011/12/5-new-years-resolutions-for-spammers/#comments</comments>
		<pubDate>Fri, 30 Dec 2011 15:00:09 +0000</pubDate>
		<dc:creator>Sue Walsh</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[botnets]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[spammers]]></category>

		<guid isPermaLink="false">http://www.allspammedup.com/?p=6676</guid>
		<description><![CDATA[2011 is coming to a close and that means it’s time to make resolutions for 2012. Here’s a look at what types of resolutions spammers might be making for the new year. Although overall spam volumes dropped this year, there’s really &#8230;<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br/><br/><a href="http://www.allspammedup.com/2011/12/5-new-years-resolutions-for-spammers/">5 New Year&#8217;s Resolutions For Spammers</a></p>
]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.allspammedup.com/wp-content/uploads/2011/12/2012.jpg"><img class="alignright size-medium wp-image-6691" style="border-width: 0px; border-color: black; border-style: solid; margin: 10px;" title="2012" src="http://www.allspammedup.com/wp-content/uploads/2011/12/2012-400x267.jpg" alt="" width="320" height="214" /></a>2011 is coming to a close and that means it’s time to make resolutions for 2012. Here’s a look at what types of resolutions spammers might be making for the new year. Although overall spam volumes dropped this year, there’s really no telling what 2012 will bring, and you can count on scammers and spammers being as busy as ever!</p>
<p><strong>1. Create new botnets and find new ways to increase and strengthen existing ones.</strong><br />
2011 saw the takedown of several major botnets as Microsoft teamed up with the FBI and went on the warpath, determined to crack down on spam.</p>
<p><strong>2. Find new ways to exploit social media for gain and profit.</strong><br />
With Facebook still refusing to vet apps before letting them be released on the site, the possibilities for rogue apps are endless.</p>
<p><strong>3. Work on new Black Hat SEO techniques.</strong><br />
Thanks to Google’s new Panda algorithm, which has put many so-called “content mills” out of business and made traditional search engine spam techniques such as blog scraping and splogs useless, spammers will need to come up with new ways to exploit Google’s search engine results.</p>
<p><strong>4. Continue to refine spear phishing techniques</strong>.<br />
Spammers have found that targeted attacks are more effective than the traditional phishing techniques that used a large and random group of addresses. They&#8217;ve also been finding new ways to make their fake phishing sites look more and more legit.</p>
<p><strong>5. Continue to look for more loopholes and security vulnerabilities to exploit.</strong> This includes finding new ways to crack anti-spam tools like CAPTCHA and ways to hijack social media accounts and websites.</p>
<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br/><br/><a href="http://www.allspammedup.com/2011/12/5-new-years-resolutions-for-spammers/">5 New Year&#8217;s Resolutions For Spammers</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.allspammedup.com/2011/12/5-new-years-resolutions-for-spammers/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Pizza Spam Delivers Malware</title>
		<link>http://www.allspammedup.com/2011/12/pizza-spam-delivers-malware/</link>
		<comments>http://www.allspammedup.com/2011/12/pizza-spam-delivers-malware/#comments</comments>
		<pubDate>Wed, 28 Dec 2011 15:00:23 +0000</pubDate>
		<dc:creator>Sue Walsh</dc:creator>
				<category><![CDATA[Spam news]]></category>
		<category><![CDATA[malicious sites]]></category>
		<category><![CDATA[malicious spam]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[spammers]]></category>

		<guid isPermaLink="false">http://www.allspammedup.com/?p=6614</guid>
		<description><![CDATA[A new spam campaign is using fake pizza order confirmations to distribute malware. The message informs the recipient that their order has been received and gives them the option to either pay for it, to the tune of $100 or so, &#8230;<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br/><br/><a href="http://www.allspammedup.com/2011/12/pizza-spam-delivers-malware/">Pizza Spam Delivers Malware</a></p>
]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-6672" style="border-width: 0px; border-color: black; border-style: solid; margin: 10px;" src="http://www.allspammedup.com/wp-content/uploads/2011/12/1196125_italian_pizza.jpg" alt="" width="300" height="225" /></p>
<p>A new spam campaign is using<a target="_blank" href="http://www.spamfighter.com/News-17189-Pizza-Order-Spam-Spreads-Malicious-Software.htm"> fake pizza order confirmations </a>to distribute malware. The message informs the recipient that their order has been received and gives them the option to either pay for it, to the tune of $100 or so, or to cancel it by clicking the provided “Cancel Order Now” button. The scammers are hoping the recipients will panic and click the cancel button. Doing so will lead them to one of several infected websites that will attempt to download malware onto their computer.</p>
<p>The site first uses a script to determine exactly what OS the visitor is running and then downloads the appropriate variant of malware. It recognizes Windows, Mac, iOS for the iPad, iPod Touch, and iPhone, Windows Mobile, WinCE, and more. It also checks to see what browser they have and if they have Flash, Adobe Acrobat, and Javascript. Presumably it is looking for specific programs in order to exploit any security vulnerabilities they may contain.</p>
<p>It’s not yet clear what happens if a recipient actually chooses to pay the bill. Will the scammers get some free money or does the link lead to same malicious website the order cancelation button does?</p>
<p>The scammers do try to keep the messages fresh, using different pizzas and items in the orders and using different restaurant names. However, it’s pretty easy to spot these scam emails. They won’t be addressed to you by name, and most pizza places require payment right away unless you chose to pay in cash. Plus, the pizzerias the fake confirmations come from are fake themselves.</p>
<p>&nbsp;</p>
<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br/><br/><a href="http://www.allspammedup.com/2011/12/pizza-spam-delivers-malware/">Pizza Spam Delivers Malware</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.allspammedup.com/2011/12/pizza-spam-delivers-malware/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Lump of Coal Edition: When Scammers Attack</title>
		<link>http://www.allspammedup.com/2011/12/lump-of-coal-edition-when-scammers-attack/</link>
		<comments>http://www.allspammedup.com/2011/12/lump-of-coal-edition-when-scammers-attack/#comments</comments>
		<pubDate>Mon, 26 Dec 2011 15:00:31 +0000</pubDate>
		<dc:creator>Malcolm James</dc:creator>
				<category><![CDATA[anti spam]]></category>
		<category><![CDATA[anti spam humor]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Spam news]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[antispam]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[cybercriminals]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[scammers]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[spammers]]></category>

		<guid isPermaLink="false">http://www.allspammedup.com/?p=6647</guid>
		<description><![CDATA[While the fat man in the red suit has already signed-off on his naughty or nice list, there’s one nasty little child holed up somewhere in Russia who needs to get a large lump of coal in his stocking this &#8230;<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br/><br/><a href="http://www.allspammedup.com/2011/12/lump-of-coal-edition-when-scammers-attack/">Lump of Coal Edition: When Scammers Attack</a></p>
]]></description>
			<content:encoded><![CDATA[<p><strong><a href="http://www.allspammedup.com/wp-content/uploads/2011/12/coal.jpg"><img class="alignright size-medium wp-image-6652" style="border-width: 0px; border-color: black; border-style: solid; margin: 10px;" src="http://www.allspammedup.com/wp-content/uploads/2011/12/coal-400x266.jpg" alt="" width="400" height="266" /></a>While the fat man in the red suit has already signed-off on his naughty or nice list, there’s one nasty little child holed up somewhere in Russia who needs to get a large lump of coal in his stocking this year. Or if not a lump of coal, then a shiny new pair of law enforcement-grade handcuffs.</strong></p>
<p>What is it about this time of the year that brings out the worst in people? Religious beliefs aside, there’s something about this time of the year that should make all people take a deep breath, send a little good will out to fellow humans, and, well… just smile, dammit. Unfortunately, for spammers and scammers, it appears that there’s no room for taking time off over the holidays and treat others with the dignity and respect that most people recognize as a necessary element of a living, breathing society.</p>
<p><strong>Case in point: </strong><em>The Register</em> <a target="_blank" href="http://www.theregister.co.uk/2011/12/12/anti_scam_sites_ddos_blitz/">reported</a> earlier this month that three anti-scam sites were inundated with a massive Distributed Denial of Service (DDoS) attack over several days, effectively rendering the sites useless. According to <em>The Register:</em></p>
<blockquote><p><em></em>“The sites &#8211; 419eater.com, scamwarners.com and aa419.org (Artists Against 419) &#8211; were swamped with junk traffic for several days. During the attack the sites&#8217; administrators turned to blogs, Facebook and other alternative channels to distribute news of newly detected fake payment sites and other urgent anti-fraud information.”</p></blockquote>
<p>According to an anonymous <em>Register</em> reader:</p>
<blockquote><p>“These websites and their users provide excellent exposure for online fraud activities and have been responsible for allowing thousands of prospective victims to detect a scam in play, and get out before losses are incurred They also work actively to kill fake bank sites, fake freight forwarding sites and other criminal resources.”</p></blockquote>
<p>The Register reported that two of the three sites were back in working order in a few days, but the story takes a nefarious turn from here. Early speculation was that a Russian scam artist was responsible for the attacks, and not long afterwards, someone over at ScamWarners contacted <em>The Register</em> and divulged that the attack:</p>
<blockquote><p>“was perpetrated by a scammer who became angry at a topic posted on 419Eater, which exposed his scam. 419Eater.com was first attacked and ScamWarners began to publicise it via Twitter and Facebook. The next day [Thursday], ScamWarners was also attacked. The scammer then sent an email to me, threatening both ScamWarners and 419Eater. We were told to cease exposing their information and reporting their Amazon sites or we would both be eradicated from cyberspace.”</p></blockquote>
<p>If that last sentence didn’t outrage you at least a little bit, go back and read it again. Is it necessarily foolish and naïve to believe that even scammers – scumbags who invest a significant amount of time into developing malware designed to bilk little old ladies living on fixed incomes out of their precious savings – might take a little time off during Christmas, Kwanzaa, Hanukah, Ashura, or whatever religious observance you prefer to…uhm…observe? Absolutely it is. One could assume that’s what bulbous men in red tights with fist-sized lumps of coal are for. But acceptance isn’t enough. This is a time of the year “when want is keenly felt, and abundance rejoices”, as Dickens pointed out; yet the inhumanity of the deeds of a few are enough to make this writer wonder how we continue to survive the ravages of human nature – in other words, ourselves.</p>
<p>It’s been a year fraught with cyber crime and cyber busts, with malicious attacks and new forms of spam; with new scams and chilling suggestions of things to come. For this week, anyway, most of us will rejoice at the presence of family and friends, and sadly, many will go hungry. Here’s hoping that in 2012, we will have a chance to see more of these scammers on our little blue-green orb find the other side of steel bars.</p>
<p><strong>Next week:</strong> tune in for our top 10 list of popular torture methods for 2012.</p>
<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br/><br/><a href="http://www.allspammedup.com/2011/12/lump-of-coal-edition-when-scammers-attack/">Lump of Coal Edition: When Scammers Attack</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.allspammedup.com/2011/12/lump-of-coal-edition-when-scammers-attack/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>New Spam Campaign Uses Google Docs</title>
		<link>http://www.allspammedup.com/2011/12/new-spam-campaign-uses-google-docs/</link>
		<comments>http://www.allspammedup.com/2011/12/new-spam-campaign-uses-google-docs/#comments</comments>
		<pubDate>Fri, 23 Dec 2011 15:00:43 +0000</pubDate>
		<dc:creator>Sue Walsh</dc:creator>
				<category><![CDATA[Spam news]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Google Docs]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[spammers]]></category>

		<guid isPermaLink="false">http://www.allspammedup.com/?p=6618</guid>
		<description><![CDATA[A new spam campaign has been detected and it’s using Google Docs as part of its scheme. That spammers are exploiting Google Docs is nothing new, but in the past, they spammed by using the share feature to send spam &#8230;<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br/><br/><a href="http://www.allspammedup.com/2011/12/new-spam-campaign-uses-google-docs/">New Spam Campaign Uses Google Docs</a></p>
]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-1954" style="border-width: 0px; border-color: black; border-style: solid; margin: 10px;" src="http://www.allspammedup.com/wp-content/uploads/2009/12/1_google_logo.jpg" alt="" width="280" height="197" /></p>
<p>A <a target="_blank" href="http://elie.im/blog/security/google-docs-used-in-a-spam-campaign/">new spam campaign</a> has been detected and it’s using Google Docs as part of its scheme. That spammers are exploiting Google Docs is nothing new, but in the past, they spammed by using the share feature to send spam filled docs. In this new campaign, they use email instead. The emails contain a link to a Google Doc that is filled with spam hawking fake degrees for sale. It’s not clear who is behind this new campaign but whoever it is, he/she is clearly experienced enough to have been able to get around Gmail’s spam filter.</p>
<p>While overall spam volumes have dropped, new spam campaigns are still being unleashed. One that landed in my inbox a few days ago had the subject line “Woow!” and a link that said “Click here to see attached photos”.  When I hovered my cursor over the link, the underlying URL was gibberish but did have my email address embedded in it. A little more research revealed the URL led to a fake Windows Live login page. Yep, it’s a phishing attack. It looks like the attacker is hoping to collect lots of Windows Live login credentials for some sort of future attack, or maybe to sell to another cybercriminal. The email came from my aunt’s Hotmail account, so it looks like the attacker has already managed to hijack some accounts and is using them to keep the attack going.</p>
<p>It’s relatively easy to spot a phishing attack. Just hover your cursor over an URL in an email and the real address will show in the info bar. There are other red flags as well. If a company you do business with emails you, they will always address you by your name or screen name, never as “Dear User” or “Dear Customer”.  Also, no legit company will email you and ask for personal info such as your password or credit card number.</p>
<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br/><br/><a href="http://www.allspammedup.com/2011/12/new-spam-campaign-uses-google-docs/">New Spam Campaign Uses Google Docs</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.allspammedup.com/2011/12/new-spam-campaign-uses-google-docs/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>India: King of Spam?</title>
		<link>http://www.allspammedup.com/2011/12/india-king-of-spam/</link>
		<comments>http://www.allspammedup.com/2011/12/india-king-of-spam/#comments</comments>
		<pubDate>Wed, 21 Dec 2011 15:00:15 +0000</pubDate>
		<dc:creator>Sue Walsh</dc:creator>
				<category><![CDATA[Fighting spam]]></category>
		<category><![CDATA[Spam news]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[spammers]]></category>

		<guid isPermaLink="false">http://www.allspammedup.com/?p=6616</guid>
		<description><![CDATA[New statistics on spam have revealed that India has shot ahead of the United States and South Korea to claim the title of biggest spam producer in the world. 12% of the spam in the world comes from India. This is &#8230;<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br/><br/><a href="http://www.allspammedup.com/2011/12/india-king-of-spam/">India: King of Spam?</a></p>
]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-33" style="border-width: 0px; border-color: black; border-style: solid; margin: 10px;" src="http://www.allspammedup.com/wp-content/uploads/2008/06/kcaptcha_with_crowded_symbols.gif" alt="" width="290" height="60" /></p>
<p>New<a target="_blank" href="http://www.thehindubusinessline.com/industry-and-economy/info-tech/article2695606.ece?homepage=true&amp;ref=wl_home"> statistics on spam </a>have revealed that India has shot ahead of the United States and South Korea to claim the title of biggest spam producer in the world. 12% of the spam in the world comes from India. This is largely because India is a popular home for botnets and the amount of botnets whose origins lead to India is increasing.</p>
<blockquote><p>In a written reply in the Lok Sabha, the Minister of State for Communications and IT, Mr Sachin Pilot, said that Indian Computer Emergency Response Team in co-ordination with the industry and service providers is working towards disablement of ‘spam bots&#8217; located in India to curb spam sources.</p></blockquote>
<p>India is also home to a thriving economy based on human CAPTCHA solving. These companies cater to spammers, who are happy to pay them to solve CAPTCHAs by the thousands. This allows them to set up email accounts on services like Gmail and Yahoo to pump out spam from and blogs on services like Blogger for distributing email and conducting Adsense and affiliate fraud.</p>
<p>Computers and the internet are increasingly affordable in India, and the number of internet users there have skyrocketed to over 110 million.</p>
<p>In better news, the United States, once one of the top three spam producers in the world, has dropped out of the top 10 altogether. This is attributed to the efforts Microsoft and the FBI have made over the past year to crack down on spammers and take down several major botnets. This is also credited for bringing the global spam volume down to 75% of all email sent.</p>
<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br/><br/><a href="http://www.allspammedup.com/2011/12/india-king-of-spam/">India: King of Spam?</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.allspammedup.com/2011/12/india-king-of-spam/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>If Dr. Seuss Was a Spammer</title>
		<link>http://www.allspammedup.com/2011/12/if-dr-seuss-was-a-spammer/</link>
		<comments>http://www.allspammedup.com/2011/12/if-dr-seuss-was-a-spammer/#comments</comments>
		<pubDate>Tue, 20 Dec 2011 15:00:01 +0000</pubDate>
		<dc:creator>Malcolm James</dc:creator>
				<category><![CDATA[anti spam humor]]></category>
		<category><![CDATA[anti phishing]]></category>
		<category><![CDATA[anti spam]]></category>
		<category><![CDATA[antispam]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[botnets]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[cybercriminals]]></category>
		<category><![CDATA[Fighting spam]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[phishing scam]]></category>
		<category><![CDATA[scam]]></category>
		<category><![CDATA[scammers]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[Spam news]]></category>
		<category><![CDATA[spammers]]></category>

		<guid isPermaLink="false">http://www.allspammedup.com/?p=6574</guid>
		<description><![CDATA[It’s the most wonderful time of the year, and what better way to take a look back at the year in spam than poke a little fun at the moronic state of the crap that invades our inboxes? In a &#8230;<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br/><br/><a href="http://www.allspammedup.com/2011/12/if-dr-seuss-was-a-spammer/">If Dr. Seuss Was a Spammer</a></p>
]]></description>
			<content:encoded><![CDATA[<p><strong><a href="http://www.allspammedup.com/wp-content/uploads/2011/12/Grinch1.jpg"><img class="alignright size-full wp-image-6591" style="padding-left: 5px; border-width: 0px; border-color: black; border-style: solid; margin: 10px;" src="http://www.allspammedup.com/wp-content/uploads/2011/12/Grinch1.jpg" alt="" width="264" height="275" /></a>It’s the most wonderful time of the year, and what better way to take a look back at the year in spam than poke a little fun at the moronic state of the crap that invades our inboxes? In a year that saw major security breaches, several high profile botnet takedowns, and an unprecedented surge in personalized scams and mobile spam, we stop to reflect upon it all and submit a simple postulate: what if Dr. Seuss had been a spammer?</strong></p>
<p>As the year winds down to a close, it’s only basic human nature to look back at the year that just passed and reflect upon it. In the world of spamming and Internet scams, that’s bound to be a painfully long look, since this has been a year fraught with new scams, major cybercrime busts, and unprecedented levels of security threats. With mobile devices providing the newest threat opportunities, and SMS spam picking up a head of steam as scammers get creative, we must be even more vigilant when fighting spam-related threats.</p>
<p>What’s in store for 2012? One must shudder when imagining the possibilities. If anything like 2011, next year will represent an even more dangerous landscape, cluttered with mines and booby traps the likes of which we’ve never seen.</p>
<p>Dire prophecies and doomsday mentality aside, it doesn’t hurt to poke fun at spam once in a while, and during the holidays, no one is more fun than the venerable Theodor Seuss Geisel, known to adoring children and former children alike as Dr. Seuss. Like many households, it’s a holiday tradition around here to watch <em>How the Grinch Stole Christmas!</em>, an annual ritual which inspired this writer to wonder: what if Dr. Seuss was still with us, and what if, ahem, wait for it…Dr. Seuss was a spammer?</p>
<p>The thought itself is sure to bring a smile to the face of anyone who has endured the miserable drivel that infests inboxes like brown marmorated stink bugs. Poorly written and replete with ludicrous stories that must have been contrived during bad acid trips, these emails often frustrate us, and occasionally make us smile by virtue of their sheer stupidity. What they <em>do not</em> do, however, is give us any confidence that the human race is poised to survive much longer, if this epidemic of oafishness is representative of the current state of the gene pool.</p>
<p>So without further ado, here’s a humble attempt at imagining what spam might be like, if written by Dr. Seuss:</p>
<p>&nbsp;</p>
<p><strong>The Spammer Who Stole Christmas?</strong></p>
<p>Dear stranger, forgive me for this intrusion</p>
<p>I hope my letter will ease your confusion.</p>
<p>I will not, cannot state it enough</p>
<p>This is rough stuff, even a little tough.</p>
<p>There’s a Libyan prince who lost his good fortune</p>
<p>And my offer to you is a share of the portion.</p>
<p>I cannot get the funds out of my land</p>
<p>And I hope you will aid me by lending a hand.</p>
<p>You see, there are sums in excess of millions</p>
<p>If you give me your name, I&#8217;ll give you gazillions.</p>
<p>It’s okay to give me personal information</p>
<p>They don’t extradite criminals in my tiny nation.</p>
<p>Your bank account and credit cards are essential</p>
<p>They’re only for scamming and merely referential.</p>
<p>This is for good cause, I must admit</p>
<p>Send money now and show you commit.</p>
<p>I do not wish to enter a heated debate</p>
<p>Send it fast, send it now, it cannot wait.</p>
<p>The funds are for my stately Kenyan mansion</p>
<p>It’s in great need of a major expansion.</p>
<p>&nbsp;</p>
<p><strong>Happy Holidays to all!</strong></p>
<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br/><br/><a href="http://www.allspammedup.com/2011/12/if-dr-seuss-was-a-spammer/">If Dr. Seuss Was a Spammer</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.allspammedup.com/2011/12/if-dr-seuss-was-a-spammer/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>When Spam Comes From a Friend</title>
		<link>http://www.allspammedup.com/2011/12/when-spam-comes-from-a-friend/</link>
		<comments>http://www.allspammedup.com/2011/12/when-spam-comes-from-a-friend/#comments</comments>
		<pubDate>Mon, 19 Dec 2011 15:00:53 +0000</pubDate>
		<dc:creator>Jeff Orloff</dc:creator>
				<category><![CDATA[anti spam]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[antispam]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[cybercriminals]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[email spam]]></category>
		<category><![CDATA[Fighting spam]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[spam email]]></category>
		<category><![CDATA[spammers]]></category>

		<guid isPermaLink="false">http://www.allspammedup.com/?p=6604</guid>
		<description><![CDATA[Recently, I had to deal with the fact that my own email account was compromised and sending spam to everyone I had ever written and emailed to (you can read more about it here). Not a fun thing to deal &#8230;<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br/><br/><a href="http://www.allspammedup.com/2011/12/when-spam-comes-from-a-friend/">When Spam Comes From a Friend</a></p>
]]></description>
			<content:encoded><![CDATA[<p><a target="_blank" href="http://www.allspammedup.com/wp-content/uploads/2011/12/spam3.jpg"><img class="alignright size-medium wp-image-6605" style="border-width: 0px; border-color: black; border-style: solid; margin: 10px;" src="http://www.allspammedup.com/wp-content/uploads/2011/12/spam3-400x328.jpg" alt="" width="240" height="197" /></a>Recently, I had to deal with the fact that my own email account was compromised and sending spam to everyone I had ever written and emailed to (you can read more about it <a href="http://www.theemailadmin.com/2011/12/yes-my-email-account-was-compromised">here</a>).</p>
<p>Not a fun thing to deal with but it did get me thinking a bit more about how often individual accounts are compromised to send out spam.</p>
<p>Of the larger messaging services, Yahoo! Mail appeared to be the most susceptible according to an end-user survey by Commtouch with 27% of Yahoo’s users claiming to have had their account compromised. Facebook came in second with 23%, Gmail followed with 19% and Windows Live rounded out the list with 15% of people admitting that their accounts had been targeted at one time or another.<span id="more-6604"></span></p>
<p>The most frightening statistic from this survey was that 62% of these people had no idea how their email account was compromised. This does not reflect carelessness on the victim’s part but instead, shows how the threat landscape has increased in sophistication.</p>
<p>It used to be you downloaded a malicious program that infected your email client and sent out messages to everyone in your inbox however with the malicious links appearing in social network feeds, legitimate web sites hosting malware, drive by downloads and cyber criminals snooping in on public Wi-Fi narrowing down where your credentials were stolen is akin to finding a needle in a haystack.</p>
<h2>Why Your Personal Account is a Target</h2>
<p>You would think that large corporate email accounts would provide a much more lucrative target for spammers. After all, if they can compromise a good number of addresses they will have much more to work with.</p>
<p>However, cyber criminals have long abandoned the mass spam tactics of the past. This is evidenced by the fact that the amount of email spam has reduced over the years, and trends show that this will likely continue.</p>
<p>People have learned not to respond, or act, when they are sent an arbitrary email message from an unknown account. Over the years, they have been warned and trained that if you don’t know the sender don’t trust the message.</p>
<p>Personal email accounts, for this very reason, have become much more attractive to spammers and cyber criminals. Instead of blanketing mailboxes with spam that generates extremely small returns, their email campaigns have become much more targeted.</p>
<p>Harvesting smaller amounts of personal accounts to send their junk may not be able to hit the sheer numbers they used to use, but the odds of someone opening the email and taking action are greater because of the trust factor.</p>
<h2>What To Do When Your Account is Compromised</h2>
<p>First and foremost, don’t say your account was hacked. Security experts and people who understand the definition of hacking don’t appreciate that term. Explain that your account was compromised.</p>
<p>Next, don’t be like the 23% of people who admitted in the Commtouch survey that they did nothing when finding out that their account was being used for nefarious purposes.</p>
<p>When you finally realize that something fishy is going on with your account take the following steps:</p>
<p><strong>Update your anti-malware software.</strong></p>
<p>You are going to scan your computer but if your signature files, or definitions, are out of date your security software very well could miss files that have infected your computer.</p>
<p><strong>Boot your computer into safe mode and run scan your computer.</strong></p>
<p>Many people automatically assume that you should change the password to your account first. However, if whoever compromised your email account did so by means of a keystroke logger that is still running on your computer then they will be informed of your new password. Clean your computer of any malware in safe mode before you do anything else.</p>
<p><strong>Change your password.</strong></p>
<p>Once your computer is malware-free you need to log into your email account and change the password. However make sure that you avoid using passwords you use to log into web sites or other types of accounts. This could very well be the place your password was stolen from since criminals know that people frequently use the same passwords over and over. Add to that the fact that many accounts use your email address as the username and you have a perfect mix for disaster.</p>
<p>Of course, you are going to want to also make sure you use a strong password consisting of a combination of upper and lower case letters, numbers and symbols.</p>
<p>Taking precautions will never completely eliminate the possibility that your email account will be taken over, but being smart and aware will certainly minimize the risk.</p>
<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br/><br/><a href="http://www.allspammedup.com/2011/12/when-spam-comes-from-a-friend/">When Spam Comes From a Friend</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.allspammedup.com/2011/12/when-spam-comes-from-a-friend/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Russia and U.S. Celebrate an Early Festive Season</title>
		<link>http://www.allspammedup.com/2011/12/russia-and-u-s-celebrate-an-early-festive-season/</link>
		<comments>http://www.allspammedup.com/2011/12/russia-and-u-s-celebrate-an-early-festive-season/#comments</comments>
		<pubDate>Wed, 14 Dec 2011 15:00:52 +0000</pubDate>
		<dc:creator>Malcolm James</dc:creator>
				<category><![CDATA[anti spam]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Spam news]]></category>
		<category><![CDATA[anti phishing]]></category>
		<category><![CDATA[antispam]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[botnets]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[cybercriminals]]></category>
		<category><![CDATA[Fighting spam]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[spammers]]></category>

		<guid isPermaLink="false">http://www.allspammedup.com/?p=6493</guid>
		<description><![CDATA[In a fine example of international relations, Russia and the United States exchanged gifts early this year when they announced that the two countries are entering a new level of cooperation on cyber threat analysis and the global war on &#8230;<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br/><br/><a href="http://www.allspammedup.com/2011/12/russia-and-u-s-celebrate-an-early-festive-season/">Russia and U.S. Celebrate an Early Festive Season</a></p>
]]></description>
			<content:encoded><![CDATA[<p><strong><a href="http://www.allspammedup.com/wp-content/uploads/2011/12/rockefeller-tree.jpg"><img class="alignright size-medium wp-image-6496" style="padding-left: 5px;" src="http://www.allspammedup.com/wp-content/uploads/2011/12/rockefeller-tree-400x260.jpg" alt="" width="400" height="260" /></a>In a fine example of international relations, Russia and the United States exchanged gifts early this year when they announced that the two countries are entering a new level of cooperation on cyber threat analysis and the global war on cyber crime. Reports have it that the event was a festive affair, with borscht and Philly cheese steaks for all. The Russian and American Santa Clauses only got into a tiff once, when Ded Moroz, the Russian version of the jolly old elf, made a comment about his counterpart’s excessive waistline and predilection for butting into the gumbo line for seconds and thirds. The gift exchange was equally revealing, with the American delegation reportedly bursting into tears when memories of a painful childhood were wiped away with carefully wrapped Easy Bake Ovens and Tickle Me Elmos. To make matters worse, since neither side could reach agreement on a real or artificial tree, Denny’s graciously provided a chocolate waterfall – a poor choice in hindsight, since the American delegation is still recovering from the sugar highs.<span id="more-6493"></span></strong></p>
<p>Who said it isn’t the season to be jolly? Not the U.S. and Russia, who announced this week that the two countries are entering an unprecedented level of cooperation in the war against cyber crime. Reuters is <a target="_blank" href="http://www.reuters.com/article/2011/12/10/us-russia-usa-cyber-idUSTRE7B901N20111210">reporting</a> that the countries are planning an exchange of information on “technical threats” coming from the two countries, an interesting development considering the increasing strain on relations between the two nations.</p>
<p>Reuters reports that Caitlin Hayden, spokeswoman for the White House National Security Council, explained that a series of mechanisms “aimed at confidence building and crisis prevention” are being developed to “cope with alarming events in cyberspace.” While not giving up the entire goose, she is quoted by Reuters as saying in an e-mail that new measures include:</p>
<blockquote><p>“regular exchanges on technical threats that appear to emanate from one another&#8217;s territory [and] no-fail communications mechanisms to help prevent crisis escalation and build confidence.”</p></blockquote>
<p><em>Whose</em> confidence exactly is a bit of a mystery, but perhaps the two nations will unveil that little gem at their New Year’s Eve gala in Vegas.</p>
<p>Admittedly, such partnerships have been in place for a while, such as the Nuclear Risk Reduction Center, but Hayden said that new initiatives are:</p>
<blockquote><p>“cyber-specific and [the U.S.] would begin working with Moscow for the first time.”</p></blockquote>
<p>Reuters points out that this development is nothing new, as U.S. Vice President Biden has been discussing potential joint ventures for the last month or so, but in a sound bite that will surely resonate through the ages, Biden stated:</p>
<blockquote><p>“It&#8217;s a great deal harder to assess another nation&#8217;s cyber-capabilities than to count their tanks.”</p></blockquote>
<p>So, what does it all mean? Well, even ill-informed cyber junkies know that Russia has been a significant source of problems in cyberspace, spam included. Whether this particular initiative will target spamming and scamming initiatives themselves or just the fallout from them – worms, botnets, phishing, and a litany of other unpleasantries – remains to be seen. Some might argue that spamming is a ‘white collar’ crime affecting Joe User and not befitting superpower focus and information sharing, but others would argue that the fallout from spam and its brethren actually rain hellfire down upon national security and international relations. At very least, they keep law enforcement agencies extremely busy and sometimes even <a target="_blank" href="http://gokill.com/2011/08/14/anonymous-hackers-target-bart-cyber-attacks-fullerton-police/">left holding the bag</a>. Recent suggestions that <a target="_blank" href="http://www.allspammedup.com/2011/12/conficker-linked-to-stuxnet-conspiracy-theory-activity-up-530/">Stuxnet was delivered on the back of Conficker</a> certainly leaves a bad taste in many mouths, not the least of which is Russia itself, which in September <a href="http://news.techworld.com/security/3306092/russia-blames-us-and-israel-for-stuxnet-worm/">called out the U.S. and Israel</a> over the insinuations.</p>
<p>From the get-go, this seems problematic, and it doesn’t get any better when one considers the strained relationship between the two nations purported to be partnering in this new initiative. On the heels of Russia’s accusations over Stuxnet, a Stuxnet-like attack occurred for the first time on U.S. soil when a <a target="_blank" href="http://www.theverge.com/2011/11/18/2572079/springfield-water-plant-scada-hacked-us-russia">water treatment plant in Illinois was attacked</a> in November, an attack that, curiously, originated in Russia. As Reuters points out, there’s no love lost between the two nations, and in October a U.S. Intelligence report to congress revealed that Russia’s Intelligence services are:</p>
<blockquote><p>“conducting a range of activities to collect economic information and technology from U.S. targets.”</p></blockquote>
<p>Ouch. Sounds like this is going to be one of those Christmases where the in-laws end up tearing down the tree, setting the family dog on fire, and where the neighbors end up calling-in a domestic dispute. Here’s hoping the U.S. included a gift receipt with those matryoshka dolls.</p>
<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br/><br/><a href="http://www.allspammedup.com/2011/12/russia-and-u-s-celebrate-an-early-festive-season/">Russia and U.S. Celebrate an Early Festive Season</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.allspammedup.com/2011/12/russia-and-u-s-celebrate-an-early-festive-season/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Family Tormented By Spam From Dead Relative&#8217;s Account</title>
		<link>http://www.allspammedup.com/2011/12/family-tormented-by-spam-from-dead-relatives-account/</link>
		<comments>http://www.allspammedup.com/2011/12/family-tormented-by-spam-from-dead-relatives-account/#comments</comments>
		<pubDate>Mon, 12 Dec 2011 17:00:38 +0000</pubDate>
		<dc:creator>Sue Walsh</dc:creator>
				<category><![CDATA[Fighting spam]]></category>
		<category><![CDATA[Spam news]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[spam email]]></category>
		<category><![CDATA[spammers]]></category>

		<guid isPermaLink="false">http://www.allspammedup.com/?p=6541</guid>
		<description><![CDATA[The family of a Florida woman who died two years ago have been tormented with spam messages originating from her account. A spammer hijacked Paula Chase’s Yahoo! Mail account months ago and has been pumping out spam to everyone including &#8230;<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br/><br/><a href="http://www.allspammedup.com/2011/12/family-tormented-by-spam-from-dead-relatives-account/">Family Tormented By Spam From Dead Relative&#8217;s Account</a></p>
]]></description>
			<content:encoded><![CDATA[<p><a target="_blank" href="http://www.allspammedup.com/wp-content/uploads/2011/12/shutterstock_60895975.jpg"><img class="alignright size-medium wp-image-6572" style="border-width: 0px; border-color: black; border-style: solid; margin: 10px;" title="spam from dead" src="http://www.allspammedup.com/wp-content/uploads/2011/12/shutterstock_60895975-400x267.jpg" alt="" width="320" height="214" /></a>The family of a Florida woman who died two years ago have been tormented with spam messages originating from her account. A spammer hijacked Paula Chase’s <a href="http://www.wtsp.com/news/national/article/224494/81/Family-horrified-by-dead-mothers-emails">Yahoo! Mail</a> account months ago and has been pumping out spam to everyone including those in her contact list. Her family contacted Yahoo! to get the account shut down since the spammer changed her password and the alternate email address linked to the account. At first they had difficulty reaching a human representative, and then they refused to help despite the fact the family says they had plenty of documentation to prove ownership of the account. Finally, Yahoo! agreed to close the account if the family provided a copy of Paula’s death certificate. For some reason her family doesn’t have one but says they are working on it.</p>
<p>While it’s despicable for a spammer to take over anyone’s account, and I can understand why Paula Chase’s family is upset, the situation does raise some questions. Why didn’t they close her account when she died? Many of my friends have a list of their online accounts and passwords stored with their wills, and I think this is an excellent idea. Another question I have is why didn&#8217;t they simply block their mother’s email address? Rather than let the spammer “torment” them, blocking her address might have saved a lot of stress.</p>
<p>This story illustrates the importance of making sure your online accounts are taken care of if something happens to you.  For example, Facebook will turn your account in a memorial page -all your loved ones have to do is contact them and request it.</p>
<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br/><br/><a href="http://www.allspammedup.com/2011/12/family-tormented-by-spam-from-dead-relatives-account/">Family Tormented By Spam From Dead Relative&#8217;s Account</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.allspammedup.com/2011/12/family-tormented-by-spam-from-dead-relatives-account/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Facebook Support Forum Hit With Massive Spam Attack</title>
		<link>http://www.allspammedup.com/2011/12/facebook-support-forum-hit-with-massive-spam-attack/</link>
		<comments>http://www.allspammedup.com/2011/12/facebook-support-forum-hit-with-massive-spam-attack/#comments</comments>
		<pubDate>Wed, 07 Dec 2011 17:00:01 +0000</pubDate>
		<dc:creator>Sue Walsh</dc:creator>
				<category><![CDATA[Spam news]]></category>
		<category><![CDATA[Social Networking]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[spammers]]></category>

		<guid isPermaLink="false">http://www.allspammedup.com/?p=6485</guid>
		<description><![CDATA[Facebook was hit with another spam attack recently. This one took place over the Thanksgiving weekend and affected the site’s community forums, where users go to get tech help from other users. The attack, which flooded the forum with links for &#8230;<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br/><br/><a href="http://www.allspammedup.com/2011/12/facebook-support-forum-hit-with-massive-spam-attack/">Facebook Support Forum Hit With Massive Spam Attack</a></p>
]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-1398" src="http://www.allspammedup.com/wp-content/uploads/2009/08/facebook_logo.jpg" alt="" width="300" height="112" /></p>
<p>Facebook was hit with <a target="_blank" href="http://www.pcworld.com/businesscenter/article/245090/facebook_community_forum_swamped_by_spam_during_thanksgiving_weekend.html">another spam attack</a> recently. This one took place over the Thanksgiving weekend and affected the site’s community forums, where users go to get tech help from other users. The attack, which flooded the forum with links for supposedly free live streaming sports events, was so huge that it prevented those users from getting help. Spam was appearing on the forum at the rate of roughly one per minute. While some experts believe the timing was meant to take advantage of holiday and the reduced staff coverage that resulted, anyone who is a regular user of Facebook knows that the site refuses to offer any tech support or customer service aside from a not-very-useful “Help Center”. Reaching a live person is simply not possible, and requests for help posted on their “Known Facebook Issues” page are ignored. Therefore I’m not convinced the attack’s timing was meant to take advantage of scant staff coverage. I suspect it was more likely meant to take advantage of the holiday itself and the increased traffic it brought to the site thanks to people being off work and school.</p>
<p>The Facebook accounts that posted the spam may have been created specifically for that purpose or hijacked in one of the previous spam attacks that have hit the site this year. It appears many of the affected users had rogue apps with innocent sounding names like Notes and Discussions installed on their accounts, so hijacked accounts are a very likely scenario.</p>
<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br/><br/><a href="http://www.allspammedup.com/2011/12/facebook-support-forum-hit-with-massive-spam-attack/">Facebook Support Forum Hit With Massive Spam Attack</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.allspammedup.com/2011/12/facebook-support-forum-hit-with-massive-spam-attack/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Spammers Take Advantage of Yahoo! Messenger Security Hole</title>
		<link>http://www.allspammedup.com/2011/12/spammers-take-advantage-of-yahoo-messenger-security-hole/</link>
		<comments>http://www.allspammedup.com/2011/12/spammers-take-advantage-of-yahoo-messenger-security-hole/#comments</comments>
		<pubDate>Tue, 06 Dec 2011 15:00:31 +0000</pubDate>
		<dc:creator>Sue Walsh</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Spam news]]></category>
		<category><![CDATA[drive-by attacks]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[spammers]]></category>

		<guid isPermaLink="false">http://www.allspammedup.com/?p=6466</guid>
		<description><![CDATA[Spammers have been taking advantage of a vulnerability in Yahoo! Messenger that allows them to take over user’s accounts and post spam as their status messages. The hole is found in the application’s file share API and allows them to send &#8230;<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br/><br/><a href="http://www.allspammedup.com/2011/12/spammers-take-advantage-of-yahoo-messenger-security-hole/">Spammers Take Advantage of Yahoo! Messenger Security Hole</a></p>
]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-6486" style="border-width: 0px; border-color: black; border-style: solid; margin: 10px;" src="http://www.allspammedup.com/wp-content/uploads/2011/12/yahoo_logo_2.jpg" alt="" width="245" height="172" /></p>
<p>Spammers have been taking advantage of<a target="_blank" href="http://www.computerworlduk.com/news/security/3322726/yahoo-messenger-hole-allows-spam-via-status-messages/"> a vulnerability in Yahoo! Messenger </a>that allows them to take over user’s accounts and post spam as their status messages. The hole is found in the application’s file share API and allows them to send automatically executed malformed requests without the user knowing or doing a thing. It’s not clear if the security hole allows any other malicious actions to be performed as well.</p>
<p>Spammers find such spamming attractive for the same reason they love spamming Facebook and other social networking sites. When spam links come from people’s friends and contacts, that built in trust factor makes the click through rate skyrocket. Spammers trying to exploit affiliate programs and pay-per-click advertising programs like Adsense know this could mean a tidy profit.</p>
<p>These types of attacks are the most popular way to distribute malware, and similar vulnerabilities have been found in Adobe Acrobat, Java, Flash Player, and other browser plug-ins. These attacks are popular because they don’t require the victim to do much of anything, unlike traditional spam and malware distribution methods which require tricking them into installing a Trojan or virus onto their system.</p>
<p>Yahoo! has been notified of the vulnerability but has not yet responded or repaired it. If you use Yahoo! Messenger you can protect yourself by simply making sure your account is set to block anyone who is not on your contact list, something that you should do anyway. It won’t protect you from attacks by your current contacts, obviously, but hopefully if you see a spammy sounding status update you’ll ask your contact about it rather than click on the link it contains! If you use version 11.5, keep an eye on your tabs as they may be hiding attacks.</p>
<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br/><br/><a href="http://www.allspammedup.com/2011/12/spammers-take-advantage-of-yahoo-messenger-security-hole/">Spammers Take Advantage of Yahoo! Messenger Security Hole</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.allspammedup.com/2011/12/spammers-take-advantage-of-yahoo-messenger-security-hole/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>5 Ways To Make a Spammer Hate You</title>
		<link>http://www.allspammedup.com/2011/12/5-ways-to-make-a-spammer-hate-you/</link>
		<comments>http://www.allspammedup.com/2011/12/5-ways-to-make-a-spammer-hate-you/#comments</comments>
		<pubDate>Mon, 05 Dec 2011 15:22:16 +0000</pubDate>
		<dc:creator>Sue Walsh</dc:creator>
				<category><![CDATA[anti spam]]></category>
		<category><![CDATA[Fighting spam]]></category>
		<category><![CDATA[CAPTCHA]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[spammers]]></category>

		<guid isPermaLink="false">http://www.allspammedup.com/?p=6426</guid>
		<description><![CDATA[A spammer’s worst enemy is an educated user. Here are five easy ways to make sure you’ll never be a spammer’s best friend: 1.  Don’t display your email address as plain text on your website. A contact form is best, since &#8230;<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br/><br/><a href="http://www.allspammedup.com/2011/12/5-ways-to-make-a-spammer-hate-you/">5 Ways To Make a Spammer Hate You</a></p>
]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-311" style="border-width: 0px; border-color: black; border-style: solid; margin: 10px;" src="http://www.allspammedup.com/wp-content/uploads/2009/01/classroom11.jpg" alt="" width="309" height="217" /></p>
<p>A spammer’s worst enemy is an educated user. Here are five easy ways to make sure you’ll never be a spammer’s best friend:</p>
<p><strong>1.  Don’t display your email address as plain text on your website</strong>. A contact form is best, since it protects your email address from harvesting bots, but if you must display your actual email address, display it as an image. The bots can’t “see” text in images so they won’t be able to grab your address.</p>
<p><strong>2. Don’t sell your mailing list.</strong> It may seem tempting as a way to bring in some extra income, but think twice. Even though your customers may have opted in and consented to having their email addresses given to third parties, you can’t control what those third parties might do with it.</p>
<p><strong>3. Don’t respond to spam.</strong> Resist the urge to tell them off and ignore any unsubscribe links. If your email doesn’t bounce, it will simply tell the spammers that your address is active and responsive to spam.</p>
<p><strong>4. Invest in a throwaway email address.</strong> Sign up for a free account on Yahoo, Hotmail, Gmail or other free provider. Use it instead of your main account for registering on websites, shopping online, and so on; then ignore it. This keeps your main inbox free of spam.</p>
<p><strong>5. Watch your ports and relays.</strong> If your company isn’t using it, block port 25 and make sure your network isn’t hosting any open relays. This will eliminate two popular spam tools and keep your domain from ending up on a blacklist.</p>
<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br/><br/><a href="http://www.allspammedup.com/2011/12/5-ways-to-make-a-spammer-hate-you/">5 Ways To Make a Spammer Hate You</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.allspammedup.com/2011/12/5-ways-to-make-a-spammer-hate-you/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Top 5 Christmas Themed Spams</title>
		<link>http://www.allspammedup.com/2011/12/top-5-christmas-themed-spams/</link>
		<comments>http://www.allspammedup.com/2011/12/top-5-christmas-themed-spams/#comments</comments>
		<pubDate>Fri, 02 Dec 2011 15:54:35 +0000</pubDate>
		<dc:creator>Sue Walsh</dc:creator>
				<category><![CDATA[Spam news]]></category>
		<category><![CDATA[email spam]]></category>
		<category><![CDATA[Fighting spam]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[spam email]]></category>
		<category><![CDATA[spammers]]></category>

		<guid isPermaLink="false">http://www.allspammedup.com/?p=6414</guid>
		<description><![CDATA[Following yesterday&#8217;s post, ‘Tis the Season for Holiday Spam by Casper, if you haven’t gotten any holiday themed spam yet, you probably will. While last year spam volumes actually dropped around Christmas time due to the take down of a major botnet &#8230;<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br/><br/><a href="http://www.allspammedup.com/2011/12/top-5-christmas-themed-spams/">Top 5 Christmas Themed Spams</a></p>
]]></description>
			<content:encoded><![CDATA[<p><a target="_blank" href="http://www.allspammedup.com/wp-content/uploads/2011/11/christmas-spam.jpg"><img class="alignright size-medium wp-image-6431" style="border-width: 0px; border-color: black; border-style: solid; margin: 10px;" title="christmas-spam" src="http://www.allspammedup.com/wp-content/uploads/2011/11/christmas-spam-400x295.jpg" alt="" width="320" height="236" /></a>Following yesterday&#8217;s post, <em><a href="http://www.allspammedup.com/2011/12/tis-the-season-for-holiday-spam/">‘Tis the Season for Holiday Spam</a></em> by Casper, if you haven’t gotten any<a href="http://www.heathernesbittltd.co.uk/top-5-christmas-scams-to-be-aware-of/"> holiday themed spam</a> yet, you probably will. While last year spam volumes actually dropped around Christmas time due to the take down of a major botnet among other things, don’t expect the same gift this year. Spammers have returned in force hoping to take advantage of the still shaky economy and shoppers desperate for deals. Let&#8217;s take a look at the major types of spam expected:</p>
<ol start="1">
<li><strong>Counterfeit Goods:</strong> Designer bags, watches, and other knock-offs are a favorite of spammers. They hope to lure shoppers in with hard to resist deals on sought after brand names such as Rolex, Louis Vuitton, and Prada. Some of these spams are honest and actually brag about being high quality “replicas” while others do all they can to convince buyers they are getting the real thing. Remember, if it sounds too good to be true &#8211; it is!</li>
</ol>
<ol start="2">
<li><strong>Fake Delivery Notifications:</strong> This malicious spam has been around for a while and to keep right on going. Since this is the time of year people tend to ship lots of packages to distant friends and family, it’s a sure bet spammers will try and take advantage of that to trick people into downloading Trojans that will add their computers to  botnets.</li>
</ol>
<ol start="3">
<li><strong>Pharmaceutical Spam:</strong> This old favorite is still going strong as well. Expect lots of cheesy subject lines with holiday themed innuendo designed to sell a variety of male enhancement products.</li>
</ol>
<ol start="4">
<li><strong>Fake Auction Notices:</strong> This phishing scam uses emails designed to look like they’ve come from eBay. Usually they say you’ve won an item or that a buyer is trying to get in touch with you. Naturally you’ll have no idea what they are talking about because you haven’t bought or sold anything  and want to check your account. Don’t follow the links in the message! They’ll lead to a fake eBay page and when you submit your login details, they’ll go straight to a scammer, who will likely use them to hijack your account and rip people off.</li>
</ol>
<ol start="5">
<li><strong>Fake Greeting Cards:</strong> Perhaps the most popular holiday spam of all are fake, virus ridden electronic greeting cards. A good rule of thumb is if the notification doesn’t tell you who it’s from, it’s probably fake. All the major e-card sites will tell you the name of the person who sent the card in the notification email.</li>
</ol>
<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br/><br/><a href="http://www.allspammedup.com/2011/12/top-5-christmas-themed-spams/">Top 5 Christmas Themed Spams</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.allspammedup.com/2011/12/top-5-christmas-themed-spams/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

