Showing posts with label identity theft. Show all posts
Showing posts with label identity theft. Show all posts

Tuesday, November 18, 2008

Is Sir Bonar one of Paul's aliases?

I just have to say that the article on ContactPoint written by Sir Bonar and quoted by Kim just feels like it was written by our one and only Paul.

Either Paul is writing under an alias, someone is working hard to emulate his ironic style, or somebody is writing seriously and just doesn't have an f***ing clue.

Interesting, very interesting....

Tags : / /

Tuesday, September 09, 2008

Identity Leakage

It's interesting to see how much information you can learn about people just sitting around at the airport.

This past Sunday, I flew out of Dulles airport and running a bit late I arrived just 45 minutes before my flight (so I wasn't sitting around there all that long). What I noticed while I was there:

  • I was able to observe the full name and address for 3 people as they had luggage tags on their carry on luggage which had their name/address visible to all. This doesn't count the other people who had tags, but they happened to be face down, so I don't know what information was on the tag. My recommendation is to either a) use a tag that covers the information, place the information inside of one of the exterior pockets (I put my business card into the top external pocket) or just don't put anything on carry on luggage as you don't need to.
  • I was able to observe the name, airline status and account number on several people as I stood in line for the flight. While this isn't as much information as your complete address, I could easily wreak havoc with your travel plans calling the airline to cancel or rearrange flights or otherwise do interesting things with your airline points. What should you do: Remember that this information is on the boarding pass and don't show it off to everybody standing in line next to you. I keep my boarding pass in my shirt pocket printed side facing in or I keep it inside of the carrier until I'm up in front of the line. Note also that this information is printed on the portion of the pass they let you keep. Don't leave them lying about. Trash them like you would trash any other receipt.
  • Several people had those travel document/ID holders thinking that they are doing what frequent travelers do (which, of course, you never see a frequent traveler use). Problem is that they leak information like crazy. Most people that use them keep their driver's license in the clear holder. So all the way through the security line and while they are sitting around at the airport, anybody who wants to (and has good eyesight) can read all the information there (name, address, dob at least). Putting the passport in there just brags to the world that your a citizen of whatever country (yeah, for some of us that may be obvious, but there's no reason to confirm it for people who don't need to know it). I strongly recommend against using one of these things. If you just have to have such a holder, I would face all the documents in so that you control who gets to see them.

Moral of the story: Be aware of all the places that you leak information and minimize them just as you would want providers to minimize the amount of data they collected about you. Leaking such information opens you to potential stalking, identity theft or other non-fun activities.

Tags : / /

Saturday, July 07, 2007

They Just Don't Get It....

Received this email the other day from Chase (the banking folks who are frequent targets of phishing attacks).

I'm still amazed that financial institutions continue to send emails to their customers with active hyperlinks and directions to use those links. This encourages the exact behavior that makes their customers susceptible to a phishing attempt. After checking the links closely (I do like to study phishing attacks) as well as the rest of the content of the message, the only thing that provided any evidence to me that this was actually from Chase was the 4 digit portion of the account number (something buried deep down in the message).

What's especially interesting in this case is that I have already used their online payment system to make the payment for the current statement, so they are sending me an email to tell me to use a link to do something that I've already done.

We need to move away from these kinds of emails until there is some way for the average user to authenticate that they came from the real party with which they have a relationship with and not some phishing impostor. Yes, I can tell verify this because I'm the suspicious type but my mother would have a hard time with it.

Tags : / / /

Monday, June 18, 2007

Annual Credit Reports

Not sure what brought this up now, but for some reason I thought to go get the "free" annual credit reports that we are entitled to here in the US at least once every year. I started with AnnualCreditReport.com (the central clearing house setup by the 3 major credit reporting agencies) which asked me for the standard credit information (name, ssan, address, dob, etc.).

Once I entered that information they prompted me to select which of the 3 agencies I would like to review the report at (yes, you can select multiple). I selected all 3, but now, after thinking about it, perhaps I should have selected one only and rotated around the 3 agences throughout the year -- that way I can get a new checkup every 4 months rather than only one per year -- Oh well).

The web site then forwards you to each of the agencies where you will go through a different process at each of them to further verify your identity and get access to your credit report. My experience at each of them:

  • The first agency I was sent to was TransUnion where I had to create an account in order to get my report. I was then prompted for 2 account numbers (which I had to go find) and then the tried to upsell me a copy of my credit score for $7.95 before they would let me see my credit report. When I was done, the process had taken so $#@%ing long that my session at AnnualCreditReport.com had expired and I had to start all over for the remaining two agencies.
  • On to Equifax, where they wanted to know which provider I opened an account with in 2005 and what was the payment (much easier to deal with), then they too wanted to upsell me my credit score for $7.95. No need to create an account. Got my report and printed it.
  • And, finally, Experian ((the last of the 3). This time, I went back to AnnualCreditReport.com fairly quickly, so no need to re-enter all of my information. Experian started with verification of my ssan (last 4 digits), then they asked for verification of 2 accounts (who gave me a mortgage at a particular time and who gave me an auto loan at a different particular time) as well as the name of the county in which I live. Poof. I got to see my credit report. No need to create an account, no attempt to upsell me with the credit score (at least not as an intrusive click-through step -- it may have been there somewhere else on the page that I just ignored).

Moral of the story.... be tenacious and make them give you a copy of your report -- it IS free (as long as you don't fall for the upsell). Unless you think you have been a victim of identity theft, I would stagger the reports from each agency as many of them carry the same information as the others and this kind of gives you better coverage over the year (there's a lot someone can do in the 12 months between your annual reviews if you do all 3 at the same time).

Tags : / / / / / /

Wednesday, March 28, 2007

Free Software Update

Back in Dec, I wrote about the Almost Free Software offers that I kept receiving in the mail and how it clearly wasn't a smart or good deal. Since then, the parties pushing their "Downloadable Software" have gotten even more aggressive (I'm getting probably twice the number of offers today) and they have varied their approach considerably.

I still get the emails that have the list of software offers for like $79. I also get emails with images such as the one below:

Or

Or:

Or:

Office 2007 is available for enterprise users from November 30, 2006. The end user version is available from the beginning of 2007. The 2007 Microsoft Office System, also known as Microsoft Office 2007, is the most recent version of Microsoft's productivity suite. Formerly known as Office 12 in the initial stages of its beta cycle, it was scheduled to be made available to volume license customers on November 30, 2006, with general availability following in early 2007. Office 2007 contains a number of new features, the most notable of which is the entirely new graphical user interface called the Ribbon, replacing the menus and toolbars that have been the cornerstone of Office since its inception. Office 2007 also includes new applications and server-side tools. Chief amongst these is Groove, a collaboration and communication suite for smaller businesses which was originally developed by Groove Networks before being acquired by Microsoft in 2005. Also included is Office Sharepoint Server 2007, a major revision to the server platform for Office applications, which supports "Excel Services", a client-server architecture for supporting Excel workbooks that are shared in real time between multiple machines, and are also viewable and editable through a web page. While Office 2007 includes many new features, one has been removed entirely: Microsoft FrontPage is no longer being developed; its successor is the Microsoft Expression line of products. Microsoft Office 2007 Enterprise
Retail Price $899.00
Our Price $79.95
You save $819.05

Or:

Downloadable Software (DS) is a rapidly growing company with a high quality software. You've come to the right place if you need professionally implemented programming solutions for your usage. Thousands of contented customers have already benefited from our software and solutions. Hundreds are joining this community every day.
We deliver superior software products and services that empower our partners and customers to dramatically improve their development, deployment, integration and management of quality applications all over the world.

Most popular OEM products:

Microsoft Windows Vista Business
Retail Price $299.00
Our $79.95

Microsoft Office 2007 Enterprise
Retail Price $899.00
Our $79.95

....

These offers come from all kinds of people (most likely falsified) with subjects tell me that Carysoft, michelsoft, Jefferysoft, Jinnysoft, sanitysoft, etc., etc. have great "80% offers off MICROSOFT/ADOBE SOftware". I've even gotten some "sóftwáre dównIóád cóúpón" (again, the special characters are an attempt to squeeze by spam filters).

The domains/hosts where you are asked to go include:

  • www.sobaka-oem.com (currently the most popular)
  • daikal2.eu
  • www.laga-soft.com
  • cl.rmsofto.eu
  • lloemd.eu
  • buratinopedorino.eu
  • nasdaqkrutchert.com
  • kozel-oem.com
  • ektroem.com
  • kvaka-soft.com

What should you do?

Stay away from those sites. As Robert Heinlein often said: TANSTAAFL -- Their Ain't No Such Thing As A Free Lunch. If it sounds too good of a deal, it is too good of a deal.

I haven't dug deep enough into the site to figure out if they are just trying to steal your identity or to sell you bogus software, but I'm convinced that it's one or the other.

Tags : / / / / / / /

Sunday, February 18, 2007

Amex isn't exactly helping...

Speaking of phishing, while I was off attending the RSA Security Conference, American Express called and left a message on our home phone asking me to call them about some charges on my account. They added that this was not a sales call -- they weren't trying to sell me anything.

So, I pulled out my handy AmEx card and called the number on the back of the card. After wading through the "we want our computer to talk to you" menus and finally getting to a person, the customer service agent, who was very nice, was unable to tell me why they called and said everything looked alright, so the problem must have been fixed.

Later that week, I received another call from them. This time they left an 800 number that they wanted me to call and again were clear about this not being a sales call (not sure what they expect me to interpret that as since most sales guys would say the same). Of course, following good guidelines for identity theft prevention I would not call a number left on my answering machine, so I again called the number on my card.

Again, they had no clue why I was calling and told me I should call the number that was left on the message. I told them that I wouldn't call a number left on my answering machine. They asked for the number and after about 5 mins on hold, they connected me through the people who were calling and leaving messages. Apparently it's a different branch of Amex that looks at strange merchant transactions vs strange member transactions.

I pointed out that there was a problem with their system and that I wouldn't call a number left on an answering machine, but they said it would be ok... I don't understand that and I questioned them saying that if I called them they would ask me for information that identifies myself and that's exactly what a phisher would want... "Oh we wouldn't do that"...

Clearly they need to fix this as this is the exact behavior that leads to consumers having the identity stolen. At the minimum, I should be able to call the number on my card to resolve any problems/queries they might have.

Tags : / / /

Saturday, February 17, 2007

Using Ebay to phish Ebay...

In what I think is the best phishing attempt I have seen for an eBay account, I received a question about my currently running eBay auction (and this question was sent to me via eBay's messaging system and viewable directly online in their messaging system)...

I want to know if this is the same item with the item listed at this address: http://members.ebay.com/aboutme/**********
From: imabrit! (1246)

Now, I know I did not list the same item under some other user, and I noticed that the sender of this message was someone who had a rating of 1246 (for real), so I went to look at the item to see what's up and I got to the following page:

This looks like a normal eBay login page. This is hosted on eBay (the URL for the page is on eBay). One might even expect to be prompted for authentication before they could look at another user's profile. However, I knew I already had a live authentication session at eBay and therefore shouldn't be prompted for credentials. So, I started to wonder if this was a phish attempt.

First I checked the URLs and the links and they all looked fine (yes this page was coming from eBay's site. Then I checked the page by walking to the page through the member profile lookup on the Community page. I still ended up with the same page that looks legit and is hosted by eBay.

But, it still didn't feel right, so I pulled up the source for the HTML page and much of it was the normal eBay page. However, the data entry form had the following code:

<form ... action="http://us.1.p10.webhosting.yahoo.com/forms?login=....." onSubmit="return checkForm0()">

This submits the form data to a web server hosted at Yahoo (not one of Yahoo's own services, but they allow others to pay for hosting).

I don't know how the average user could ever figure this out and I would expect that many, if not most, phishing aware technologists would also fall prey to this one (yeah, I do think I'm special :-)).

UPDATE (2/17): It's actually easier to tell than I thought (after looking closely at the real sign-in page): The URL for any eBay login MUST start with https://signin.ebay.com. Now, I've been an eBayer since 1998 and I pay close attention to phishing attempts, but I couldn't have quoted that to you until I looked for it today, so I'm not sure how many others will know.

Tags : / / / /

Thursday, February 08, 2007

Identity, Microsoft, OpenID, and SAML

I've been attending the RSA Security Conference over the past week and sat through the keynote from Bill Gates and Craig Mundie on Tuesday.

I was quite happily surprised when they started to talk about identity issues. It was gratifying to see that the stuff I and many of my cohorts have been working on for years has come to the forefront in everybody's mind -- although I still have trouble explaining to my mother exactly what I do at work.

I was even slack-jawed with the mention and discussion of OpenID. At first I was a bit shocked, later a bit jealous (how come they didn't talk about my stuff :-() and finally happy -- both for the OpenID guys and for the industry. I congratulate the OpenID guys with their success at getting into the limelight and making what appears to be real progress forward.

I'm not so impressed with the discussion about the phishing-resistant flag as it really doesn't add much value today. My problems with the flag include:

  • A relying party (RP) would be hard-pressed to require a phishing-resistant credential nowadays given that only something like 0.000000001% (yes, I made that up, but I'm thinking I'm not far off there) of people today have phishing-resistant credentials that can be used for SSO transactions (yeah, many of us have cell phones with SIMs -- very phishing-resistant -- but the cellular providers severely restrict access to the SIMs to protect their own security).
  • There's no definition about what it means to be "phishing-resistant" and from the discussions I have had with people (some of them very smart) who thought they had come up with a new solution for phishing, I think that many parties will think they have added phishing resistance when they haven't.
  • Phishing isn't an issue of the OP or RP doing good authentication. It's an issue of the user being fooled into thinking they are talking to the OP when they really aren't. That won't be solved by a flag on the insecure request from the RP to the OP.

That aside, I think the most significant statement made in this area was the statement that Microsoft would work towards integrating better with OpenID in a future release of their products. I read this as Microsoft has recognized that there are other reasonable SSO protocols out there that they need to work with and this is a great step forward for the industry.

I now wait for Microsoft to recognize the other major player in the area of SSO and federation protocols: SAML 2.0. SAML is a convergence of work done in several areas including OASIS, Shibboleth/Internet2, and the Liberty Alliance and has a number of very large deployments throughout the industry.

If I had my druthers, I'd like to see SAML's ECP protocol support added to Cardspace so that a SAML relying party could make use of the Cardspace identity selector, so the user would have a single consistent place for local management of their identity information.

Perhaps I'm just a wishful thinker. I hope not.

Tags : / / / / / / / / /

Friday, January 26, 2007

Social Security Numbers

Sitting in the Mobile Identity Workshop in San Francisco the subject of Social Security numbers came up and how you're stuck with one for life. I brought up that you can get the number changed in cases of identity theft. This was met with some skepticism around the table, so I had to go do some research.

As I suspected, I was right :-). You can get your social security number changed if you can show that you are an ongoing victim of identity theft. You can read more of this on the Social Security Administrations web site (on this page).

Of particular interest were the various reasons why you can get your number changed:

I was surprised with the 3rd one. I guess I could object to a 13 in the middle of the SSAN or one that starts with 666. Others would probably brag.

My twin daughters have sequential numbers and so far this hasn't caused any problems, but that may be because they are only 13 -- we get much more problems with them having the same date of birth (health insurance systems frequently have problems when we have a claim for the two of them on the same day since they use the DOB as a differentiator).

I should note that changing your SSAN isn't a easy process and don't recommend it unless you really, really need to. Just think that you are going to have to start all over with your credit history and update your SSAN at all of your existing credit suppliers not to mention employers, tax records, etc. This isn't something to take on lightly.

Tags : / / / /

Saturday, December 16, 2006

Almost free software...... NOT!

Over the past few days I've received a rash of offers for unbelievable pricing on various products including Microsoft Office, Vista, Adobe Acrobat, etc..

Clearly this is another SCAM attempt to rip off the user that you need to be very careful to NOT succumb to.

The mail has two basic subject lines:

At Dylan's webshop get 0ffice 2OO7, Acrobat 8 pro & ms-vista under 8O
ACR0BAT 8 PR0 & 0FFICE 2OO7 $79 N0W at Jingbai's WebShop

Although the name changes with every spam (Dylan, Karl, Gary, etc.) and looks like the following (note that I purposely broke the links so that they were not easily clickable -- no need to advertise for them):

All Titles 0n S@le.

Micr0s0ft Vlsta 2OO7     $79 
Micr0s0ft 0ffice 2OO7    $79 
Ad0be Acr0bat 8 PR0   $79 
Wind0ws XP PR0 +SP2   $49 
Ad0be Premiere 2.O   $59 
Macr0media Studi0 8  $99 
Micr0s0ft Money 2OO7     $39 
Aut0desk Aut0cad 2OO7   $129 
C0rel Grafix Suite X3   $59 
Ad0be Creative Suite CS2 $149
Ad0be Illustrat0r CS2  $59 

http  ://rp1207.tuhloem.com/

See more:Micr0s0ft-Mac soft-Ad0be 

Micr0s0ft Vlsta 2OO7
Normal Price:  $399.00
0ur 0ffer:  $79.95
U-save:  $319.95 (75%)
Availability: Pay-and-download instantly.

http  ://rp1207.tuhloem.com/???.php

SalesRank: #1
Average Customer Review: *****
(based on 60465 reviews)

Micr0s0ft 0ffice 2OO7 Enterprise
Normal Price:  $899.00
0ur 0ffer:  $79.95
U-save:  $819.95 (89%)
Availability: Pay-and-download instantly.

http  ://rp1207.tuhloem.com/???.php

SalesRank: #2
Average Customer Review: *****
(based on 48341 reviews)

Ad0be Acr0bat 8.O PR0
Normal Price:  $449.00
0ur 0ffer:  $79.95
U-save:  $369.05 (80%)
Availability: Available for INSTANT-download.

http ://rp1207.tuhloem.com/???.php

Topten-ranked item.
Average Customer Review: *****
(based on 51489 reviews)

Macr0media Studi0 8
Normal Price:  $999.00
0ur 0ffer:  $99.95
U-save:  $899.05 (90%)
Availability: Can be downloaded-INSTANTLY.

http ://rp1207.tuhloem.com/???.php

Best choice for professional.
Average Customer Review: *****
(based on 52823 reviews)

rdist-1.3alpha rdist-1.3a     no strings like `alpha' allowed
o   Each nx= entry matches another gettytab capability name
C> XCOPY /S E:\FLOPPIES C:\FREEBSD\FLOPPIES\
  add 0 0 HISADDR
dispense with making the cua* devices.
 finished with bus, it de-asserts the DRQ line, and the DMA
editing the file /etc/host.conf. Do not call this file /etc/hosts.conf

I base my claim that this is a SCAM on the following factors:

  • TANSTAAFL - There Ain't No Such Thing As A Free Lunch -- the prices are just too good to be true.
  • The names of the products are all changed slightly (zeros for an O, mixed casing, etc.).
  • The products are only available via download -- these vendors frequently do not sell their products via download.
  • I checked the domain registration (using Network Solutions Whois server at http://www.networksolutions.com/whois/index.jsp):
    PacNames WHOIS Server Version 1.1.0
       Domain name: TUHLOEM.COM
       Registrar: PacNames
       Referral URL: http://www.pacnames.com/
       Domain Registrant: (Private Contact) (pws.4441a12478c3e85@shieldedwhois.com)
          Shielded Whois
          Shielded WHOIS
          PO Box 2076
          Arvada CO 80001
          US
          Telephone: +1.5016348793
          Fax:
       Administrative, Technical Contact: (Private Contact) 
    (pws.4441a12478c3e85@shieldedwhois.com)
          Shielded Whois
          Shielded WHOIS
          PO Box 2076
          Arvada CO 80001
          US
          Telephone: +1.5016348793
          Fax:
       Name Server: NS1.SRUL5.COM
       Name Server: NS2.SRUL5.COM
       Domain creaton date: 2006-12-15 18:22:36.0
       Domain expiration date: 2007-12-15 23:38:37.0
    
    This has several issues for me including:
    • It was only registered a few days ago (12/15/2006) - definitely a sign that they haven't been in business long -- something that should raise red flags.
    • The domain registrant used a shielded registration (where their actual name and address is hidden) -- something that's OK for an individual to use, but never used by a legitimate business.
  • I have received more then 30 different versions of this email in the past week all from different senders with a variety of domains in the link including:
    • otkudadeti.com
    • goloem.com
    • tuhloem.com
    • whichinfect.com
    • ispesti.com
    • votivse.com
    • nuujepoh.net
    • her-oem.com
    • hlopai-oem.com
    • hlopai-oem.net

    Yes, all of those domains have been seen on different versions of the same email.

  • The email had a bunch of anti-spam filter stuff in it to get it by spam filters. Legitimate emails typically do not go to such extents. This includes, slight changes in the names of the products in different emails, a bunch of junk at the end of each message that was random garbage designed to foil anti-spam filters.

This feels like the same SCAM that I wrote about in Vacation Photos, but I have no evidence to tie the two SCAMs together other than my gut feeling.

This is a mail that should be ignored and deleted as soon as you get it. Ordering something from their site is the equivalent to having some guy walk up to you on the street asking for your credit card information for a fake rolex watch hanging inside his pocket. None of us would do that (at least I hope we wouldn't) and none of us should follow through on this SCAM either.

If you do/did fall for this offer, at the very best, you most likely get illegal software that you have no rights to use. At the worst, your identity is stolen and you spend several months trying to repair your credit history. I don't know which they are trying to do, but I'm pretty sure it's not something good for you.

UPDATE: 12/20/06 I've been getting a spate of these advertisements for Windows Vista for the same $79 price:

The most comprehensive edition of Windows Vista, Vista Ultimate Upgrade (DVD-ROM) is the first operating system that combines all of the advanced infrastructure features of a business-focused operating system, all of the management and efficiency features of a mobility-focused operating system, and all of the digital entertainment features of a consumer-focused operating system. For the person who wants one operating system that is great for working from home, working on the road, and for entertainment, Vista Ultimate is a no-compromise operating system that lets you have it all. Windows Vista Ultimate contains a number of new features, the most notable of which are: Windows Vista Ultimate combines all the features of a business-focused operating system, all the efficiency features of a mobility-focused operating system, and all of the digital entertainment features of a consumer-focused operating system; Remotely connect to business networks; Windows BitLocker Drive Encryption provides improved levels of protection against theft for your important business data whether you are at home, on the road, or in the office; Delivers all of the entertainment features available in Vista Home Premium; includes everything you need to enjoy the latest in digital photography, music, movies, analog TV, or even HDTV; Upgrade from your current edition of Microsoft Windows XP or Windows 2000 (including Windows XP Professional, Windows XP Home, Windows XP Media Center, Windows XP Tablet PC, Windows XP Professional x64, Windows 2000)
Windows Vista Ultimate Upgrade (DVD-ROM)
Retail Price $399.00
Our Price $79.95
You save $319.05
http://grinolt.com
Please note, that there will be more special offers available for our constant customers. Every effort has been made to ensure the accuracy of all information contained herein. DS Team makes no warranty expressed or implied with respect to accuracy of the information, including price, product editorials or product specifications. Product and manufacturer names are used only for the purpose of identification. We appreciate your cooperation with us and we'll be glad to see you as our clients in the future.

If you go to grinolt.com, you see what looks like a detailed page on Windows Vista. If you lookup grinolt.com in the WhoIs database, it looks like it's owned by a "gwynne bontempo" in New Jersey. However, if you look at the link in the add-to-cart button, you see it brings you to yoroem.com which is owned by our old friend "Alex Rodrigez" of Vacation Photos fame and, in my eyes, clearly linking all these scam emails together.

I recommend you stay way from these guys. A deal that sounds too good to be true is too good to be true, especially if coming from someone trying that hard to hide their tracks.

Tags : / / / / / / /

Monday, November 27, 2006

Opt-ing out

Even though I feel that I tend to keep up well with things related to Identity and Identity Theft, there are always things that slip through the cracks (some, even after I have gotten wind of them).

In the case of opting out of all of those pre-screened credit card offers, I vaguely remember a friend sending me an email about it a year or two ago, but that never made it above the line to actually have me take a look at it.

However, yesterday, when I was logging into Paypal to pay for an eBay auction, Paypal told me I was pre-qualified for one of their credit cards and I noted that they had some stuff about opting out, so I started digging into it. At first I thought it was a way to opt out of the stupid offers they have following the login, but was disappointed to find out it was just some info about opting out of pre-screened credit card offers.

Since I get something like 10 to 20 of these every week, getting rid of them would still be a good thing, so I dug further including a visit to the Federal Trade Commission's web site and some poking around in other sites to verify the authenticity of what I had read.

The good news is that there is a web site (www.optoutprescreen.com) where you can go and opt-out of prescreening at the 4 big credit agencies (Experian, Equifax, Innovis, and Trans Union).

You can opt-out for 5 years or permanently (depending upon whether you want to just fill in a form or also mail it in). The form does require all the information that one would need to steal your identity (name/address/DOB/SSAN, etc.) and so it did give me pause and caused me to do some secondary research, but everything I've found at a number of reputable sources convinced me they're on the up and up.

Update: As Pat pointed out in his comment, you don't have to enter the DOB/SSAN information. I'm not sure if this impacts how well the opt-out matches with the records in each system. I supplied it all as they have it all already.

If you're cautious about entering the data online (I wasn't), you can call toll-free 1-888-5-OPTOUT (1-888-567-8688).

I recommend that everyone opt out permanently (unless you like the idea of getting identity theft invitations in your mailbox every day).

Tags : / / / / / / / / /

Saturday, November 25, 2006

Vacation Photos

For the past few weeks, many people have been "leaving me song downloads on MySpace", but now I'm getting vacation photos from Bob, Anthony, Henry, Sally, Donald, etc.

It was interesting that I do know an Anthony who is on vacation and so the message below caught my attention:

Anthony has sent you a photo from Vacation!

Click here to view the photo Anthony has sent from vacation:
http://xxxxxxx

Click here to share your photos with a friend:
http://xxxxxxx

----------------------
At Vacation Photos Online we care about your privacy. We have sent you this 
notification to facilitate your use as a member of our service. If 
you don't want to receive emails like this to your email account 
in the future, please click below:
http://xxxxxxxx

Vacation Photos Online Inc. - 4598 River Glen Dr, Las Vegas, NV 89103 USA

©2006 VP Online Inc., All Rights Reserved.

o  3Com 3C507 Etherlink 16/TP
2.1.2.  Ethernet cards
The goal of the new ports collection is to make each port as `plug-
10.4.12.  * PCMCIA
0xd4 write  Single Mask Register Bit
... much more junk deleted here ....

The links in this email were within the tarx.net domain. The Whois information for this domain includes:

   Domain name: TARRX.NET
   Registrar: PacNames
   Referral URL: http://www.pacnames.com/
   Domain Registrant: TOTALNIC-128733 (XSALSA@GMAIL.COM)
      Alex Rodrigez
      Alex Rodrigez
      PO box 109 WP 1432
      Lappeenranta NA 53101
      FI
      Telephone: +358.207818027
      Fax: +358.207818027
...   
   Domain creaton date: 2006-11-07 17:15:00.0
   Domain expiration date: 2007-11-07 22:34:13.0

Which is pretty much the same information returned for mp3shest.com (the target site for the myspace.com attack I wrote about earlier). It's also the same info for several other domains received with this and they myspace attack including: gromko-oem.com, gromko-oem.net, mp3vosem.com, etc.

I followed the link in a fairly safe environment to a page that was offering to sell common software packages at like 10 cents on the dollar. Clearly a deal that's too good to be true.

I'm not sure whether this is simply plain old SPAM trying to get you to buy their stuff, a SCAM trying to get you to pay for something you aren't really going to get (the fact that thesoftwaree they are selling is only available via download) or, much more likely if you ask me, an attempt to get your credit card information to use for other identity theft related attacks.

UPDATE: 11/26 - today he started using a new domain that was registered Thanksgiving day (11/23): luk-soft.net

UPDATE: 11/28 - He just won't quit -- today he registered two more domains and has started using them for this scam: hlopai-oem.net and hlopai-oem.com

UPDATE: 11/30 - In another offer for vacation photos, the domain was tarrx.com (as opposed to the former tarx.net) and this time the domain was owned by:

Registrant:
   Wan-Fu China, Ltd. (TARRX-COM-DOM)
   P.O.Box CB-11901
   Nassau,  
   BS
   +32.70426163
   +32.70426163
   business@wanfuchina.com

   Domain Name: TARRX.COM
   Status: PROTECTED

..... duplicate info cut out here .....

   Record last updated on 27-Nov-2006.
   Record expires on 26-Nov-2007.
   Record created on 26-Nov-2006.

That site just throws up pop-up adds at you. I'm not sure if it's the same person doing this attack or is this another person using the same attack to get revenue from pushing pop-up adds.

In any case, beware... don't click on or follow links in these emails.

UPDATE: 12/20 - this attack seems to have picked up again given the junk in my inbox as well as the hits on this page. New domains being used include: ding-dong-oem.com, txrp.tuhloem.com (which is also used in another attack I wrote about), hlopai-oem.net, etc.

Tags : / / / / /