Thoughts Media.com

 





Go Back   Thoughts Media Forums > Thoughts Media Off Topic

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 03-08-2007, 02:20 AM
Contributing Editor
Jon Westfall's Avatar
Join Date: Aug 2006
Posts: 2,714
Default The Top 25 Most Common Mistakes in Email Security

http://www.itsecurity.com/features/...istakes-022807/

"Someone recently pointed me to this article which describes the 25 Common Email Security mistakes people make.... It's an interesting read and one section really did make me smile! About making people aware that when they receive email from unknown sources...
  • You have not won the Irish Lotto, the Yahoo Lottery, or any other big cash prize.
  • There is no actual Nigerian King or Prince trying to send you $10 million.
  • Your Bank Account Details do not need to be reconfirmed immediately.
  • You do not have an unclaimed inheritance.
  • You never actually sent that "Returned Mail".
  • The News Headline email is not just someone informing you about the daily news.
  • You have not won an Ipod Nano."



Jason Langridge points out a very useful article that I enjoyed reading through. If there is one rule I could make others obey it would surely be "Never trust the From: line"! Clients at the Hosting company I consult for continually have issues with that one simple rule, most often complaining to us that "Someone has hacked my account" when they get returned mail or get spam from themselves. Oh how I wish people would spend some time and learn how to talk to a SMTP server - then they'd see just how easy it is to change the "From" line!
__________________
Jon Westfall
Contributing Editor, MS MVP, MCSE, ABD, and More.

 
Reply With Quote
  #2 (permalink)  
Old 03-08-2007, 04:11 AM
Editor Emeritus
Brad Adrian's Avatar
Join Date: Sep 2006
Posts: 3,020
Send a message via AIM to Brad Adrian Send a message via MSN to Brad Adrian Send a message via Skype™ to Brad Adrian

I'm probably the only person here who doesn't know this, but how do spammers and phishers provide a link that takes you to their spoof site, but which appears to have a legitimate domain name?
 
Reply With Quote
  #3 (permalink)  
Old 03-08-2007, 04:42 AM
Sage
Join Date: Mar 2005
Posts: 810
Send a message via Yahoo to Patrick Y.

call me crazy, but I acutally enjoy those spam sometimes. They're actually comical to read. Lol!
__________________
Got my first Pocket PC when I was 12! Acer n10> Dell x50v with WM5 Beta> Dell Axim x51v3 year warranty
 
Reply With Quote
  #4 (permalink)  
Old 03-08-2007, 04:46 AM
Intellectual
Join Date: Mar 2002
Posts: 120
Send a message via Yahoo to kaiden.1

Funny :lol: And the absolute truth!!!!!! I think that we have all recieved those e-mails.
 
Reply With Quote
  #5 (permalink)  
Old 03-08-2007, 06:27 AM
News Editor
Darius Wey's Avatar
Join Date: Aug 2006
Posts: 12,547

Quote:
Originally Posted by Patrick Y.
call me crazy, but I acutally enjoy those spam sometimes. They're actually comical to read. Lol!
Well, okay, I receive hundreds a day. You're welcome to take a good portion of it for bedtime reading.
__________________
Want the latest news, views, rants and raves? Visit our portal. Wish to contact me? Send me a private message or e-mail.
 
Reply With Quote
  #6 (permalink)  
Old 03-08-2007, 06:31 AM
News Editor
Darius Wey's Avatar
Join Date: Aug 2006
Posts: 12,547

Quote:
Originally Posted by Brad Adrian
I'm probably the only person here who doesn't know this, but how do spammers and phishers provide a link that takes you to their spoof site, but which appears to have a legitimate domain name?
Plain old HTML. They simply wrap the seemingly legitimate address in a fake one, like so:

http://www.pocketpcthoughts.com/
__________________
Want the latest news, views, rants and raves? Visit our portal. Wish to contact me? Send me a private message or e-mail.
 
Reply With Quote
  #7 (permalink)  
Old 03-08-2007, 05:51 PM
Contributing Editor
Jon Westfall's Avatar
Join Date: Aug 2006
Posts: 2,714

Quote:
Originally Posted by Darius Wey
Quote:
Originally Posted by Brad Adrian
I'm probably the only person here who doesn't know this, but how do spammers and phishers provide a link that takes you to their spoof site, but which appears to have a legitimate domain name?
Plain old HTML. They simply wrap the seemingly legitimate address in a fake one, like so:

http://www.pocketpcthoughts.com/
Another old trick is the @ symbol or user credentials in the URL string. An old method of allowing a person to specify access credentials inline with the URL was http://usernameassword@domain.com (This allowed you to jump past pesky login pop-ups). However, this can be used with sites that don't require authentication in the following ways:

http://www.microsoft.com:bunchofjunkhere@REALDOMAIN.COM

or

http://www.microsoft.com@REALDOMAIN.COM/

those both don't take you remotely near microsoft.com, but look like they will.
__________________
Jon Westfall
Contributing Editor, MS MVP, MCSE, ABD, and More.

 
Reply With Quote
  #8 (permalink)  
Old 03-08-2007, 07:53 PM
Thinker
Steve Jordan's Avatar
Join Date: Jun 2003
Posts: 438

All good tips. I noticed that the article assumes the user is using Outlook for e-mail (based on the commands and backup tools he references), but says nothing about Outlook's status as most-hackable e-mail program. I would have expected a mention of other e-mail apps that are a bit more secure.
__________________
www.SteveJordanBooks.com The e-book is the 21st Century.
 
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT +1. The time now is 08:00 AM.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0 RC7
Copyright Thoughts Media Inc. 2007