Showing posts with label hacking. Show all posts
Showing posts with label hacking. Show all posts

Friday, 18 November 2011

Let's stop "crying wolf"

We've all seen the posts haven't we? Massed capital letters - usually copied and pasted complete with spelling mistakes. Something like this one:

ATTENTION!!!!! IF ANY OF YOU GET A PADLOCK ON TOP RIGHT HAND CORNER OF FB HOME PAGE SAYING YOUR SECURITY IS LOW.. IGNORE.. DO NOT, DO NOT, DO NOT ANSWER THE QUESTIONS.. IT IS SO HACKERS CAN ACCESS YOUR ACCOUNT COPY & PASTE PLEASE!


Or the ones that are appealing to your softer side:

BIKER DOWN!! MAY I ASK MY FACE BOOK FRIENDS, WHEREVER YOU MAY BE, TO KINDLY COPY, PASTE & SHARE THIS STATUS FOR 1 HOUR TO SUPPORT OUR FRIEND GEORGE WHO WAS IN A MOTORCYCLE ACCIDENT, LET HIM KNOW THAT PRAYERS ARE SENT HIS WAY. Do it for all of us, unfortunately no one is immune. I hope to see this on the wall of all my friends! JUST FOR MORAL SUPPORT!!! I KNOW SOME WILL...THANK YOU!!!


I'm making a plea for people to check out the validity of these "warnings" and " appeals" before they post them on their social media pages.

There are a number of excellent sites where you can find out if you're crying wolf if you post the information:



Apart from reducing the sheer number of false alerts, it should reassure you that most are just idiots trying to see how far they can get their hoax to go.

93% of people won't bother to check before they post - will you be one of the ones that does?

Friday, 15 July 2011

Avoiding the DM spam

With the current rash of compromised accounts it seems timely to remind people what sort of things to look for to avoid being phished. (not hacked - see previous post!)

Account harvesters rely on social engineering to get you to give them your ID and password. By making it seem that a contact is sending you the message it gives you a false sense of security. You're far more likely to sign in to a site your 'friend' has recommended.

When you get a random tweet in your public timeline with just a link on it, from someone you don't know, then it's easy to spot. When you receive a tweet or Direct message from someone you know it's less easy to spot. Here's a few things to think about:
  • Is it 'out of character'?
  • Would they normally use the public timeline and not Direct Message?
  • Is the spelling OK?
  • Have you seen any 'chatter' on Twitter about DM spam?
Sites such as Mashable often lead with stories of the latest phishing outbreaks (such as "is this you"). Take a look before you click.

If you've clicked on a link and are asked to 'sign in to twitter to see this page' (or similar) think carefully before you do. Check the web address: is it really an official twitter site? Chances are it's a disguised web address to try and fool you into parting with your log on details.

Sometimes, smartphones do take you to the twitter.com site rather than open the page in the app you're using - this is a rare occurrence and, in general, you're safer not logging in.

If you're in any doubt, tweet the person back and confirm whether or not it's really from them.


So, the worst happens and your account starts spewing spam, now what?

Change your password.

It's also a really good idea to go into the settings page on your Twitter account and revoke access as well.

Tuesday, 16 March 2010

Hacked and Phished are different!

Short post about a pet peeve of mine.

Many folks on Twitter have recently posted "Sorry - was hacked - all ok now" or similar.

Truth is this - they were NOT hacked.

They gave their details away, voluntarily, to a phishing scam. This is quite different to having someone hack your ID and password unaided - or indeed deliberately breach the security of the hosting service.

When you give your details away, however inadvertantly, you have been phished.

If you click on a link within Twitter that then requires your ID and password to "log in" again the chances are high that it's a dodgy link. Think before you type.