Monday, April 25, 2011

Women like silent men. They think they're listening. ~Marcel Achard, Quote, 4 November 1956 http://bit.ly/gl656q

Don't play dirty consultant tricks

Takeaway: Chip Camden offers his take on an article that characterizes consultants as vampires who are opponents of their clients’ best interests. He also shares tips on how to avoid playing dirty consulting tricks.



In 7 dirty consultant tricks (and how to avoid them), Dan Tynan adopts a highly mistrustful view of consultants as predators who are looking for any excuse to take your money in exchange for results that are less than you expected. Tynan offers suggestions for remedying each of the seven foul practices that he discusses, but I take exception to the characterization of consultants as opponents of their clients’ best interests. Therefore, I’ll examine each item in Tynan’s list from the perspective of the consultant, with the aim of preventing the problem altogether.


15 Top Android Security Apps

t appears hackers are taking advantage of Android's open source platform, as there has been an astonishing increase in exploits involving the mobile OS over the past year. With the number of Android phones in use increasing daily, it’s essential that users protect their data. With that in mind, we’ve compiled a list of the top security apps in the Android Marketplace.


Convert Your Facebook Profile

How To Convert Your Facebook Profile To A Business Fan Page:



Facebook started off as a pure social network. As time passes, its creators and users both begin to realize its value proposition in the business world. So, Facebook launched “Pages” for business users analogous to “profiles” for personal users. In the business world, profiles became pages, followers became fans, the user interface changed to have a more business-centric appeal but the essence remained the same.



The launch of Facebook pages left many businesses wondering if they should now build a page or a profile? Those with existing profiles had a dilemma of whether to abandon their profile and build a page, have both a page and a profile or perhaps look for a means to migrate their existing profile into a business page.



Facebook recently launched a migration tool that converts a Facebook profile to an official Page with the click of a button, transforming friends to fans in the process. This is a welcome change to the cryptic process of creating a page from scratch and starting with an empty friends list.


Reminder about your invitation from Dani

Hi,



This is a reminder that on April 10, Daniel Wentzel (dkwline@gmail.com) sent you an invitation to become part of his or her professional network at BizOppers.



Follow this link to accept Daniel Wentzel's invitation.



http://bizoppers.com/r/61850?utm_campaign=imported_contact_invitation_reminder&utm_content=et_1_text_1&utm_medium=email&utm_source=user_mailer



Signing up is free and takes less than a minute.



On April 10, Daniel Wentzel wrote:



> To: d2ba05 [d2ba05@wentzeldk.amplify.com]

> From: Daniel Wentzel [dkwline@gmail.com]

> Subject: Daniel Wentzel wants to stay in touch on BizOppers



> Hey,



I'd like to add you to my wealth network on BizOppers. Like Facebook but pays :)



- Daniel

>

> - Daniel



The only way to get access to Daniel Wentzel's professional network on BizOppers is through the following link:



http://bizoppers.com/r/61850?utm_campaign=imported_contact_invitation_reminder&utm_content=et_1_text_2&utm_medium=email&utm_source=user_mailer



You can remove yourself from Daniel Wentzel's network at any time.





If you don't know Daniel Wentzel you can report this member and unsubscribe:

http://bizoppers.com/unsubscribe/1591560/87c90?utm_campaign=imported_contact_invitation_reminder&utm_content=et_1_text_3&utm_medium=email&utm_source=user_mailer

Saturday, April 23, 2011

Please support this young boy:



Jack, is 5, he is battling cancer/brain tumour, Jacks mum gives you a daily insight into this brave/funny/loving little mans life on Twitter, please follow & support Jack on Facebook as well.



Watch this video on YouTube of Jack really laughing at his dog Louis singing:



Louis, Jacks dog singing, Jack is sadly terminally ill, and we are raising brain tumour awareness at www.jacksfund.co.uk on facebook "Jack Marshall Brain Tumour Fund" or Twitter @jack_marshall_ thank you for visiting and your supporting and Jack is really laughing!! http://www.youtube.com/watch?v=afebiZjXZJY



http://www.jacksfund.co.uk



Follow Jack's Tweets over here:



http://twitter.com/#!/Jack_Marshall_ http://bit.ly/eEoseQ

Live Our Dream

This is a true song written about a fallen friend. Written and performed by Tyler Toliver a US Marine currently deployed himself.

Amplify’d from www.youtube.com
 

Friday, April 22, 2011

Home Biz Enthusiasts, Forget Facebook!

This is NEW! Home Biz Goes Social!



Who Else Wants To Connect To Over 125 000 Home Biz Enthusiasts?



Forget Facebook! Get Paid Big Cash for Socializing with Bizoppers



Get Paid Big Cash for Socializing.



New Social Site...BizOppers.com pays you money for socializing and getting the word out.



3 x 10 matrix that can pay up to $103,000 a Month...Plus 8 Other Ways To Earn



Top Positions Going Fast - Snooze and You'll Lose Big On This One



Think of it as a Facebook for Home business people.



In Pre-Launch Now... Commissions Paid in 30-Days!



Perfect for a second or full-time income



FREE to join; From the Founders of SWOM



http://www.leadsleap.com/go/37186



See the video: http://www.staged.com/video?v=GJc


Wednesday, April 20, 2011

DOWNLOAD Stuff Happens

Our latest PDF manual is out now and it's a good one.



Disasters happen. Unless you're okay with losing all of your data, you need a good

backup system. If you know this but haven't got around to setting up backup on

your PC, this is the guide to read.



DOWNLOAD Stuff Happens: The Backup & Restore Guide

http://www.makeuseof.com/tag/download-stuff-backup-restore-guide/



"Stuff Happens: The Backup and Restore Guide" outlines everything you need

to regularly back up your PC. Author Tina Sieber outlines backup strategies,

what to backup and what tools to use for the job.



DOWNLOAD Stuff Happens: The Backup & Restore Guide

http://www.makeuseof.com/tag/download-stuff-backup-restore-guide/



Protect these priceless files. Back them up. This guide can teach you how.



Like all MakeUseOf manuals, this is completely free.



If you find this guide interesting, please share it with your friends on Facebook and Twitter

by using this link: http://www.makeuseof.com/tag/download-stuff-backup-restore-guide/



Enjoy!



MakeUseOf Limited

105 Collingwood Road

Colchester, C03 9BB

Essex / UK

Amplify’d from www.makeuseof.com

DOWNLOAD Stuff Happens: The Backup & Restore Guide

posted on April 20, 2011 by Justin Pot

Disasters happen. Unless you’re okay with losing all of your data, you need a good backup system. If you know this but haven’t got around to setting up backup on your PC, this is the guide to read.

“Stuff Happens: The Backup and Restore Guide” outlines everything you need to regularly back up your PC. Author Tina Sieber outlines backup strategies, what to backup and what tools to use for the job.

Backups are necessary because data has value. Whether this is sentimental, commercial, or legal value, a backup is a way of securing valuable information. The worst loss would be files of which we own the only copy in existence, such as personal documents or photos.

Protect these priceless files. Back them up. This guide can teach you how.

This guide explains:

  • How to use the built-in Windows 7/Vista backup tool.
  • Which files you should backup.
  • Putting your data and your operating system on separate partitions or disks.
  • The various kinds of backups you can run.
  • The costs and benefits of local, optical and online backups.
  • The benefits of syncing your files.
  • Alternative backup programs.

DOWNLOAD Stuff Happens: The Backup and Restore Guide
(take a moment and share this guide with friends on Facebook and Twitter
using the social network sharing buttons below)

or

Justin Pot
Justin Pot is a freelance journalist, blogger and IT professional based in Boulder, Colorado. Find all his work at JustinPot.com or chat with him on Twitter.

Similar Stuff

Read more at www.makeuseof.com
 

Monday, April 18, 2011

An open letter to Facebook about safety

Dear Facebook,



As you know, for some years we have been discussing with your security team our concerns about safety and privacy on Facebook.



Every day, victims report to us numerous incidents of crime and fraud on Facebook. They have been personally affected and are desperate for advice on how to deal with the consequences.



A frequent refrain from users who contact us is, ‘Why doesn’t Facebook do more to protect us?’



We have identified three simple steps you can take to better protect your users:



1) PRIVACY BY DEFAULT



No more sharing of information without your users’ express agreement (OPT-IN). Whenever you add a new feature to share additional information about your users, you should not assume that they want this feature turned on.



2) VETTED APP DEVELOPERS



It is far too easy to become a developer on Facebook. With over one million app developers already registered on the Facebook platform, it is hardly surprising that your service is riddled with rogue applications and viral scams. Only vetted and approved third-party developers should be allowed to publish apps on your platform.



3) HTTPS FOR EVERYTHING



We welcome you recently introducing an HTTPS option, but you left it turned off by default. Worse, you only commit to provide a secure connection “whenever possible”. Facebook should enforce a secure connection all the time, by default. Without this protection, your users are at risk of losing personal information to hackers.



Why wait until regulators force your hand on privacy? Act now for the greater good of all.



Your users tell us that these are issues they want resolved. So our question is simple: when do you plan to act?



Sincerely,



Naked Security


Tuesday, April 12, 2011

Microsoft readies Godzilla-sized patch

Microsoft has lined up for Windows users this coming Patch Tuesday a staggering 17 security bulletins (nine of which have been given Microsoft's highest severity rating of "critical"), addressing 64 security vulnerabilities. Read more now, and make sure you are prepared.


Sunday, April 10, 2011

This thing is new



 bizoppers.com
Daniel Wentzel
Daniel has:
60 contacts
0 activities

This thing is new



Hey, heads up. This is new and hot right now. http://bizoppers.com/?r=61850 TTYL, Daniel








WHY MIGHT CONNECTING WITH DANIEL WENTZEL BE A GOOD IDEA?



Users Daniel Wentzel knows can discover your profile
Connecting to Daniel Wentzel will attract the attention of other BizOppers users.

This e-mail was sent on behalf of Daniel Wentzel by BizOppers. If you do not wish to receive future commercial mailings from BizOppers, click here. BizOppers's registered offices are located at The Courtyard, Goldsmith Way, Eliot Business Park, Nuneaton, CV10 7RJ

Tuesday, April 5, 2011

Android malware against software piracy

A Trojan horse that attempts to protect developers of an Android app from piracy and punish users of cracked software has been discovered by SophosLabs. Vanja Svajcer investigates.


Thursday, March 31, 2011

Download the Facebook Marketing Guide

It's time for us to bring you a new PDF manual.



Anyone trying to market a business, product, band or some other public figure knows this, and that they need to "get a Facebook presence" because "Facebook is huge". That's great, but how do you get started?



Get the latest free MakeUseOf manual, You Like This: The Facebook Marketing

Guide. This guide explains everything you need to know about promoting yourself, your business or your ideals on Facebook.



DOWNLOAD You Like This: The Facebook Marketing Guide

http://www.makeuseof.com/tag/download-facebook-marketing-guide



In order to make the best of Facebook for marketing, you'll need to understand the tools

available, how they're used, best practices and how to set the tools up. But that's just

the start. Once you start piecing together this puzzle, you'll be able to manage your

marketing efforts across multiple Facebook products with ease and style. Angela's

guide outlines all this and more, so download now.



DOWNLOAD You Like This: The Facebook Marketing Guide

http://www.makeuseof.com/tag/download-facebook-marketing-guide



Like all MakeUseOf manuals, this is completely free.



Make sure to share it with your friends on Facebook and Twitter (or via email) by

using this link: http://www.makeuseof.com/tag/download-facebook-marketing-guide



In addition, you might also want to check out a previously published PDF guide on

Facebook security to help protect your privacy:

http://www.makeuseof.com/pages/download-the-very-unofficial-facebook-privacy-guide



Enjoy!



MakeUseOf Limited

105 Collingwood Road

Colchester, C03 9BB

Essex / UK


Tuesday, March 29, 2011

Android tablets for the Enterprise

Takeaway: Samsung has taken notice of the fact that business professionals are driving a lot of Apple iPad sales and it is taking steps to make its Android tablets very friendly to the enterprise.

Amplify’d from www.techrepublic.com

Samsung has big plans to sell Android tablets to the enterprise

Takeaway: Samsung has taken notice of the fact that business professionals are driving a lot of Apple iPad sales and it is taking steps to make its Android tablets very friendly to the enterprise.

If we could do a scientific poll to find out how many of the people who have purchased the Apple iPad so far got it primarily to use for business, I suspect the number would be at least 50%.


That doesn’t mean that the professionals who buy the iPad are only using it for email and business meetings. They also use it to read books and watch movies, especially on business trips. The point is that business is driving a lot more of the iPad’s success than you’d think by watching Apple’s promo videos and reading the iPad coverage in the media — or, at least most of the media.


However, the iPad’s business story is not lost on everyone. I got a reliable report recently that shows how much Apple understands this dynamic. And, this week at CTIA Wireless 2011 I found out that Samsung gets it, too, because Samsung is putting a lot of resources on the line in order to get its newly-expanded line of Android tablets in the hands of business users.


In terms of Apple, I’ve recently heard from reliable sources that Apple has been holding a series of meetings and training sessions with systems integrators about helping businesses deploy and/or support the iPad. Apple has never been particularly friendly with businesses (Steve Jobs even famously explained what he hates about the enterprise), so this is a significant step for Apple that has been preluded by the steps it has taken in recent years to make the iPhone a lot more enterprise-friendly.


On the other hand, Samsung isn’t hiding its tablet strategy for the enterprise in private meetings or back rooms. It’s going after it with all the resources it can throw at the problem, and it gave enterprise integration and business-friendly features a prominent treatment in the CTIA presentation of its new 8.9-inch and 10.1-inch tablets.


We can break down Samsung’s enterprise plans into three categories:

  1. Enterprise middleware that it’s building into TouchWiz
  1. Business development with enterprise partners
  1. Development of a sales infrastructure for the enterprise

One of the first things Samsung is doing is building software into TouchWiz that makes Samsung tablets easy to connect to backend enterprise systems. That’s not just to support IT deployments but to make it easy for the tablets that consumers purchase and want to use for business to connect with corporate software and be palatable to IT.


“We think there’s the need to support the acceptability of these devices into the enterprise,” said Gavin Kim, Vice President of Mobile Content and Services at Samsung. Kim said the stuff Samsung is building into its Android tablets via its TouchWiz software is akin to enterprise middleware.


At its CTIA press conference on Tuesday, Samsung made the enterprise-friendly features of the new Samsung tablets a big part of the presentation.


  • Built-in support for Cisco SSL VPN (the first Android devices to offer that)

  • Device management with Exchange ActiveSync

  • Hardware encryption (Samsung has also added a separate processor to its tablet just to handle the encryption and decryption of data)

  • Lots of support for enterprise software, including Citrix, Polycom, Sybase, SAP, and more

“It’s not bullet-proof, but it’s a good step, and we’re just getting started,” said Kim.


In addition to the software partners just mentioned, Samsung’s Ken Daniels, Director of Strategic Alliances for Enterprise Mobility, said the company is talking to virtually “everybody” in the enterprise software space about making their stuff work with Samsung tablets.


Samsung is also reaching out to much smaller developers of business software, including vendors who focus on vertical markets and line-of-business apps, to help educate them about Android 2.3 (Gingerbread) and 3.0 (Honeycomb) and encourage them to develop apps for Android tablets and find ways to make their systems work with Samsung tablets.


Right now, when big companies want to buy smartphones and tablets in large quantities they are typically going through the telecom carriers that they already have contracts with. Samsung is going to support that with a sales force that will serve as advisers and evangelists for companies that want to do large-scale deployments of Samsung tablets. Samsung will help them make the right product choices and then let them buy the tablets from their carriers of choice.


On the other hand, Samsung sees a new opportunity developing where large companies will want to purchase Wi-Fi-only tablets directly from Samsung — for example, a hospital system buying 10,000 Wi-Fi tablets that don’t need mobile broadband because they will only be connecting to the hospital’s campus-wide WLAN. Samsung is setting up a program to make it easy to drop-ship large numbers of tablets directly to these types of enterprises.


Another thing Samsung is doing to make its tablets more business-friendly is developing its own line of accessories aimed at professionals — desktop docks, hardware keyboards, bluetooth accessories, and cases — and partnering with companies like Belkin to make professional accessories for Samsung tablets.


Clearly, Samsung sees a huge opportunity for tablets in the enterprise and is making a lot of smart moves to grease the wheels for business adoption. Apple looks like it’s ready to avoid the mistakes it made with the Macintosh and be a lot more proactive about working with the enterprise on iPad adoption. And, don’t forget about Motorola. Even though the Xoom still needs to be refined, Motorola has a long history of building strong relationships in the enterprise. RIM, of course, wants a piece of this space as well with its forthcoming BlackBerry PlayBook, but it’s facing an uphill battle since it is badly losing the mobile ecosystem game to Apple and Android.


Ultimately, the enterprise tablet race is going to be an important undercurrent to watch in 2011.

Samsung’s new 8.9 and 10.1 inch tablets were headliners at CTIA Wireless 2011. Photo credit: Jason Hiner

Also read



Jason Hiner


About Jason Hiner


Jason Hiner is the Editor in Chief of TechRepublic. He is a former IT manager and an award-winning journalist.




Read more at www.techrepublic.com
 

Tuesday, March 22, 2011

Adobe fans - get ready for the patch

Adobe fans - get ready for the patch but watch out for the scams.



Don't pay for free software. You're giving scammers money and undermining the reputation of the free software.

Amplify’d from nakedsecurity.sophos.com

Adobe fans - get ready for the patch but watch out for the scams

Adobe has been in the news this week after alerting Flash, Acrobat and Reader users about a forthcoming out-of-band patch for its products.

By wrapping a Flash file in an Excel spreadsheet, potential attackers have demonstrated a remotely-exploitable vulnerability.

(The attack doesn't seem to be in-the-wild, and the exploit files I've heard of seem to rely on a sequence of already-known and already-detectable malicious operations, so there is no cause for alarm. But do look out for the Flash patches when Adobe publish them next week.)

One of the side-stories to this Flash-in-Excel risk is the suggestion that the creators of the exploit chose Excel as the container, instead of the more common PDF, because the exploit couldn't be made to work on computers running Adobe Reader X.

The good news, says Adobe proudly, is that the new Adobe X security sandbox would prevent this attack. On Windows, anyway. Mac and Linux users aren't sandboxed yet.

The bad news is that any broadly-publicised good news about product Y is easily exploited by scammers. If people are positive about Y, and a new version of Y is being talked about in the same breath, then scammers rush to offer you Y, but under false pretences.

And that's just what Naked Security reader Wez reported to us today. He received an email offering him the very latest releases of the amazing Acrobat X:

The email explicitly claimed to come from Adobe in Ontario:

It didn't, of course. This scam is similar to a Fake Anti-Virus (FakeAV) ripoff, except that the hokum product is a program to process PDF files.

Like FakeAV, the site is very thin and shallow, consistingly of little more than a home page, a generic "privacy policy" which gives no company information at all, and a range of download options that all lead to the same page:

The next page, of course, is where you pay:

Who knows what you'll get? You certainly don't get a download link if you don't pay, so there's no evaluation period for this product. But if you do pay, you're promised - for two days only - a FREE GIFT!!!

Guess what? The free gift software you're being offered is OpenOffice. It really is free. Always. In fact, you can download it free right now from the openoffice.org website.

It's no big leap to assume, in fact, that the whole deal you are being offered is OpenOffice. After all, OpenOffice itself lets you edit and create PDFs. In that case, you'd be buying OpenOffice and getting it for free at the same time.

Don't pay for free software. You're giving scammers money and undermining the reputation of the free software.




About the author


Paul Ducklin is Sophos's Head of Technology, Asia Pacific. He won the inaugural AusCERT Director's Award for Individual Excellence in Computer Security in 2009. (Try saying that quickly.)

Email him in the Sydney office or follow him on Twitter at @duckblog.

Read more at nakedsecurity.sophos.com
 

Twitter goes secure

Twitter goes secure - say goodbye to Firesheep with "Always use HTTPS" option



Good news on the social networking security front is that Twitter has finally got its act together to offer an Always use HTTPS option.

Amplify’d from nakedsecurity.sophos.com

Twitter goes secure - say goodbye to Firesheep with "Always use HTTPS" option

Good news on the social networking security front is that Twitter has finally got its act together to offer an Always use HTTPS option.

If you turn on this option, all of your personalised interaction with Twitter will be encrypted - not only while you are logging in, but also while you are posting tweets.

A lot of people fail to recognise the value of using HTTPS on Twitter. As long as your username and password are sent over HTTPS, so no-one can sniff them out of the ether, who cares if your tweets go over plain HTTP? After all, a tweet is meant to be public.

The problem is that once you have logged in, Twitter sends your browser a session cookie. This is a one-time secret. It is unique to your account and the current session.

Because your browser retransmits this session cookie in all future requests to the Twitter site, Twitter can see that it's you coming back for more. So you don't need to put in your username and password for every single tweet you send. You login once, and the session cookie identifies you for the rest of the current session.

Unfortunately, if you login to Twitter over unencrypted WiFi - e.g. at a coffee shop or an airport lounge - then anyone who can sniff your session cookie can pretend to be you. That means they can post tweets as you. And you don't want that. (It happened to Mr Demi Moore, a.k.a. Ashton Kutcher, recently, no doubt to his considerable embarrassment.)

Turning on full-time Twitter HTTPS keeps your session cookie encrypted throughout your login session. This is definitely what you want.

Don't forget that it's not just experienced hackers who can sniff Twitter cookies and use them to impersonate you.

The infamous Firesheep plugin to Firefox automates this cookie-stealing process - known as "sidejacking" - so that anyone who can use a browser can do it.

To enable this new Twitter option, go to your Settings page.

At the bottom is the new Always use HTTPS option. Turn it on and click [Save], and then [Save changes].

Do it today.

(Note: as a commentator below points out, it's not clear if, or how, non-web-browser Twitter clients will support this new option. If in doubt, please ask the vendor of your Twitter client, or follow the Simplicity Principle and stick to using your browser when tweeting.)





About the author


Paul Ducklin is Sophos's Head of Technology, Asia Pacific. He won the inaugural AusCERT Director's Award for Individual Excellence in Computer Security in 2009. (Try saying that quickly.)

Email him in the Sydney office or follow him on Twitter at @duckblog.

Read more at nakedsecurity.sophos.com
 

Monday, March 21, 2011

“ Nothing splendid has ever been achieved except by those who dared believe that something inside themselves was superior to circumstance. ”



Bruce Barton (1886–1967)

American advertising executive

U.S. congressman http://bit.ly/hw8ewO

Tuesday, March 15, 2011

It's a Facebook clickjack scam

Japanese Tsunami Launches Whale Into Building? It's a Facebook clickjack scam

Amplify’d from nakedsecurity.sophos.com

Japanese Tsunami Launches Whale Into Building? It's a Facebook clickjack scam

WhaleSick-minded scammers are up to their dirty tricks again, trying to make a quick buck out of the Japanese earthquake and subsequent tsunami which has shocked people around the world.

Many people are shocked by the TV news reports, showing the devastation wrought on the people of Japan, and some of the video footage taken by media agencies and individuals in the country is truly extraordinary.

And it is against this backdrop that scammers have launched their latest campaign.

Whale
Japanese Tsunami Launches Whale Into Building


Japanese Tsunami Launches Whale Into Building

You won't believe this! Crazy Footage!

Other versions read:


GRAPHIC VIDEO.. Japans Tsunami Sends WHALE Smashing Into A Building!

Of course, this is just the latest FouTube clickjacking attack to hit Facebook, and sure enough if you click on the link you are taken to a webpage which tries to trick you into clicking (which will silently say to all of your Facebook friends that you "Like" the page).

Japanese Tsunami Launches Whale Into Building video

Will you get to see a video of a whale launched into a building by the Japanese tsunami? No, of course not.

Instead, you're asked to complete a survey which earns commission for the scammers.

Tsunami whale survey

When I tried it, the survey attempted to tempt me with the offer of a purple iPad. Funny, I thought Steve Jobs only made them in black and white.

Purple iPad offer

How to clean-up after a likejacking attack

If you made the mistake of clicking on a link spread via a scam message like the ones listed above, you should check your Facebook news feed and remove any offending links that you might have spammed out to your friends. Hover your mouse over the top right hand corner of the post and you should see a small "x" which will allow you to remove it.

And if you entered your mobile phone number, you should keep a close eye on your cellphone bill and notify your carrier to prevent bogus charges from stinging you in the wallet.

Remember to be wary of any links that look like this. If you really want to watch a video chances are that it's available for free - without you having to complete any surveys - on legitimate video sites like YouTube.

Going forward, it's essential that you stay informed about the latest scams spreading fast across Facebook and other internet attacks. Join the Sophos Facebook page, where more than 60,000 people regularly share information on threats and discuss the latest security news.

Hat-tip: Thanks to Naked Security readers Don, Rogi and Tripad who contacted us about this scam.




About the author


Graham Cluley is senior technology consultant at Sophos. In both 2009 and 2010, the readers of Computer Weekly voted him security blogger of the year and he pipped Stephen Fry to the title of "Twitter user of the year" too. Which is very cool. His awards cabinet bulging, he was voted "Best Security Blogger" by the readers of SC Magazine in 2011. You can contact Graham at gc@sophos.com, or for daily updates follow him on Twitter at @gcluley.

Read more at nakedsecurity.sophos.com
 

Bogus CNN video scams Facebook users

Japanese Tsunami RAW Tidal Wave Footage - Bogus CNN video scams Facebook users

Amplify’d from nakedsecurity.sophos.com

Japanese Tsunami RAW Tidal Wave Footage - Bogus CNN video scams Facebook users

Facebook users are being tricked into clicking on links which claim to be raw CNN footage of the Japanese tsunami by cold-hearted scammers - as part of a plot to earn money by driving web traffic to take online surveys.

The videos, which in the examples seen by Sophos exist on a website called spinavideo, purport to be footage of the horrifying tsunami which hit parts of Japan on Friday.

Japanese Tsunami RAW Tidal Wave Footage Facebook Message

Japanese Tsunami RAW Tidal Wave Footage

Clicking on the link takes unsuspecting users to a website which pretends to be YouTube, but is in fact designed to clickjack users into unwittingly agreeing to Facebook "Like" the page (which spreads the scam virally across the social network).

Bogus CNN video footage of Japanese tsunami

Users are then tricked into taking an online survey which earns commission for the scammers. No doubt the scammers are hoping that by pretending the video footage comes from CNN, more people might be tempted to click on it.

It's a sad reflection on human nature that a series of scams have appeared since the disaster in Japan, all trying to make commercial gain out of what is a horrific human tragedy.

Remember to always get your news from legitimate news websites, and if you're hunting for a video make sure that you go to the real YouTube website rather than a replica set up by scammers.

How to clean-up after a likejacking attack

If you made the mistake of clicking on a link spread via a scam message like the one listed above, you should check your Facebook news feed and remove any offending links that you might have spammed out to your friends. Hover your mouse over the top right hand corner of the post and you should see a small "x" which will allow you to remove it.

And if you entered your mobile phone number, you should keep a close eye on your cellphone bill and notify your carrier to prevent bogus charges from stinging you in the wallet.

Remember to be wary of any links that look like this. If you really want to watch a video chances are that it's available for free - without you having to complete any surveys - on legitimate video sites like YouTube.

Going forward, it's essential that you stay informed about the latest scams spreading fast across Facebook and other internet attacks. Join the Sophos Facebook page, where more than 60,000 people regularly share information on threats and discuss the latest security news.

Hat-tip: Thanks to Naked Security reader Kara who contacted us about this scam.





About the author


Graham Cluley is senior technology consultant at Sophos. In both 2009 and 2010, the readers of Computer Weekly voted him security blogger of the year and he pipped Stephen Fry to the title of "Twitter user of the year" too. Which is very cool. His awards cabinet bulging, he was voted "Best Security Blogger" by the readers of SC Magazine in 2011. You can contact Graham at gc@sophos.com, or for daily updates follow him on Twitter at @gcluley.

Read more at nakedsecurity.sophos.com