Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Monday, April 14, 2008

Always Check your Spelling


Did you know that if you misspell the URL you are going to, you have a 1 in 14 chance of opening a rogue website? You run the risk of being infected somehow. And you will be helping a criminal to make money by fraud!

For the past several years, the cyber-villains have been "cyber-squatting" and "typo-squatting" - which is "the practice of registering domains that are usually common misspellings of popular brands, products, and people in order to profit from consumer typing errors."

Here are some of the more common ways people misspell:
  • swapped letters - yuotube.com
  • replaced letters - wschovia.com
  • inserted letters - mysspace.com
  • deleted letters - cartonnetwork.com
  • missing dot - wwwmicrosoft.com
The "bad" guys buy misspelled domain names of popular heavily trafficked sites. They usually buy from the registrars that offer "5-day free trial" domain names. They wait and see which ones generate the most traffic and then register them. They cancel the others and then sit back and wait on their clicks (and money) to start rolling in!

When you misspell a common URL, you will be directed to a site that is hoping you will click on one or more of its links. These links have been set up not to look like an ad but rather a necessary link related to the URL. Google's AdSense system of pay-per-click will eventually suffer from the negative publicity caused by this new fraud scheme. Users will stop clicking on those little Google ads common on websites.

These cybervillains tend to prey on the types of sites the naive and careless use, especially young children and teenagers. An intelligent person or an experienced user would never fall for it, right? Believe me, there is always that person who is more experienced and/or more intelligent than you. AND has a criminal mind and agenda!

In other words, be careful. You can never be too careful. Nowadays, the Internet creeps have forced us not to trust anyone any more and rightly so. I don't know one single person who regularly uses the Internet who hasn't been infected in some way.

The best advice is to be sure you have up-to-date security utilities in place. And USE them - run your scans, do your clean-ups, de-frag your system - I know it's a pain in the neck sometimes, but do it anyway!

<<<<<<<<<<<<<<<<>>>>>>>>>>>>>>>>

McAfee conducted a very thorough test regarding the presence of squatters. The top 22 types of websites targeted for this fraud scheme are:
  • games
  • mainstream media
  • airlines
  • adult
  • technology
  • auto
  • security
  • children
  • music
  • shopping
  • news
  • entertainment
  • financial
  • fortune 500
  • gadgets
  • popular
  • travel
  • dating
  • celebrity
  • advertising
  • sports
  • fashion
They determined the following popular or common websites are particularly targeted due to their popularity. It's not that you need to avoid these sites - not at all - just be wary of the links you click while there. You may be fueling a criminal empire!

(NOTE: they are in no particular order)
Most search engines are trying to protect us by offering "did you mean..." when it suspects a misspelling. Yahoo even went so far as to buy/register all of its common variants in 1994 - it redirects the user to their home page instead. Microsoft offers a free tool that allows interested individuals the opportunity to find and analyze squatters.

Once again, my whole purpose of this blog is to keep us alert and teach us to be a lot less careless when using the Internet.

Sunday, February 3, 2008

Don't get mad; get glad!

I know some of you are probably upset about some of the web sites I said to avoid.

I, personally, am disappointed that several are sites I used to love to frequent are deemed to be "dangerous."
I was an extremely loyal fan of gamerival, even during their change of ownership. Now, I do not go there anymore at all. Others, such as myspace, grab, facebook, youtube, and metacafe, I refuse to give up on.
  • (I lied - I have Myspace set up in my "restricted" zones and refuse to go there for any reason, even though my kid, using her own PC, lives and breathes for MySpace - go figure!)
I'm just super careful - I say don't click anything and definitely don't download anything, especially if it's free! Not to mention, I double check that my security is functioning correctly.

(Another thing I like to do before visiting questionable sites (which I've accidentally done in order to write this blog) is I create a system restore point, just in case!)
But, there are people, like my teenager, who think they are invincible or that I'm being unnecessarily and overly cautious. Wait till you've had to spend hundreds of dollars on professional cleaning and/or complete reformatting of your system! Or wait until you've had to spend hours looking for the best way to scan and remove a "varmint" or had to wait for someone at a HiJack This-related forum to answer you and help you.

Better safe than sorry!
No truer words were ever spoken!

Installment #2 - Category: Random

Avoid these when possible, or at least have an excellent security system in place!

Note: The first 8 are all related to the same company, which is currently involved in a lawsuit against it for its invasive advertising practices.
  1. broadcaster.com
  2. movieland.com
  3. flicksplus.com
  4. mcaster.com
  5. medialoader.net
  6. mymedianetwork.com
  7. popcorn.net
  8. voddirect.com
  9. *facebook.com (subject of phishing attacks lately)
  10. googlemark.org
  11. zedo.com
  12. digg.com (several bad links)
  13. aptimus.com
  14. *metacafe.com (subject to several attacks lately)
  15. activevirusshield.com
  16. rollyo.com
  17. supercracks.net
  18. squidoo.com
  19. tickme.com
  20. *youtube.com (subject to attacks on users' downloads, phishing)
*When I tell you that they have been subject to various attacks lately, this is just to suggest extra caution at those sites, especially when downloading or clicking the links presented on their site. Get into the habit of checking with siteadvisor.