<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Block Spam in Exchange</title>
	<atom:link href="http://junkmailscan.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://junkmailscan.com</link>
	<description>Enterprise level Spam Blocking for microsoft exchange</description>
	<lastBuildDate>Mon, 06 Feb 2012 15:00:52 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Spam Fighting Boot Camp Week 1: Know Your Enemy</title>
		<link>http://junkmailscan.com//spam-fighting-boot-camp-week-1-know-your-enemy/</link>
		<comments>http://junkmailscan.com//spam-fighting-boot-camp-week-1-know-your-enemy/#comments</comments>
		<pubDate>Mon, 06 Feb 2012 15:00:52 +0000</pubDate>
		<dc:creator>Casper Manes</dc:creator>
				<category><![CDATA[Fighting spam]]></category>
		<category><![CDATA[Stop Spam]]></category>
		<category><![CDATA[anti spam]]></category>
		<category><![CDATA[spamfighting bootcamp]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[spam gov]]></category>
		<category><![CDATA[stop spam]]></category>

		<guid isPermaLink="false">http://www.allspammedup.com/?p=7009</guid>
		<description><![CDATA[All right, sweethearts, what are you waiting for? Breakfast in bed? Another glorious day in the Corps! A day in the Spam Corps is like a day on the farm. Every meal&#8217;s a banquet! Every paycheck a fortune! Every formation &#8230;<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br /><br /><a href="http://www.allspammedup.com/2012/02/spam-fighting-boot-camp-week-1-know-your-enemy/">Spam Fighting Boot Camp Week 1: Know Your Enemy</a></p>]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.allspammedup.com/wp-content/uploads/2012/02/SgtApone-Aliens.jpg"><img class="alignright size-full wp-image-7077" src="http://www.allspammedup.com/wp-content/uploads/2012/02/SgtApone-Aliens.jpg" alt="" width="190" height="228" /></a>All right, sweethearts, what are you waiting for? Breakfast in bed? Another glorious day in the Corps! A day in the Spam Corps is like a day on the farm. Every meal&#8217;s a banquet! Every paycheck a fortune! Every formation a parade! Welcome to week one of Spamfighting Bootcamp. We’re going to look at how spammers think, how they act, what their motivations are, and the cunning tricks that they play in their unending attempts to compromise our users’ inboxes. We’ll look at our own fortifications infrastructures through the eyes of a spammer, so that we can see the weaknesses that our enemy will attempt to exploit. I have seen the enemy, and he is us. He is our misconfigured relays, our slack attitudes towards secondary systems, and our disregard for technologies that are available now. He is our wide open whitelists, and our overly trusting users. He is our co-worker in marketing who CCs his entire contact list, our MTA that responds to VRFY commands. In short, to know your enemy is to know yourself.<span id="more-7009"></span></p>
<p>Spammers don’t fill our inboxes with junk because they have nothing better to do; they send out tens of thousands of messages every day because somewhere someone is going to click a link, or buy some junk proffered in that message. It’s a numbers game, and when it costs the spammer nothing more than a little time, some CPU cycles, and a cheap Internet connection to spew out garbage, spew it they will. Even if only one message in ten thousand gets all the way through from sender to unwitting recipient, who then clicks that link because they really believe they can solve any problems with their own physicality, or that they really might get a cut of some dead millionaires foreign fortune, or they really need that timeshare on a beach for pennies a day, the spammer wins.</p>
<p>The spammer fights an ongoing underground campaign because he can. We let him. Our mission this week is to stop doing the very things that the enemy exploits. He turns our own resources against us because we let him. It’s an insurgency campaign we’re up against, but today is the day we can start to turn the tide. Here are some of the tricks spammers use to get their messages into your users’ inbox.</p>
<h2>Reconnaissance</h2>
<p>Information can be a very effective weapon, and nobody knows this better than the spammer. The enemy will use bots to scrape your company’s websites for email addresses, will run directory harvesting attacks against your MTAs trying to discover valid users, and will buy and sell mailing lists whenever and wherever they can. Too often we make it easy for them, by CC-ing dozens of unrelated users with marketing emails of our own, sharing out all those email addresses with who knows who. Unless you like revealing sensitive information to the enemy, it’s time to 86 that and now.</p>
<p>Configure your MTAs to reject VRFY queries and to ban source addresses that attempt multiple VRFY commands or attempt to send more than a small number of messages to invalid recipients. Set maximum recipient limits on all outgoing messages to stop your users from sending out messages that could carry too many valid addresses outside the company, and train your users on the benefits of BCC. Set any distribution lists you have that can be mailed to from the outside or that contain external recipients to moderated, and reject any messages that contain too many internal email accounts. Finally, keep your head down by not posting email addresses on the websites. Either use a contact form, or encode email addresses so that real humans can use them, but so bots cannot automatically harvest them.</p>
<h2>Probing your perimeter</h2>
<p>The enemy is probing our lines for weakness, so too must we. Port scans for systems listening on TCP port 25 can quickly identify any system capable of receiving emails. Too often those are not a part of the corporate email system, but can relay email in to internal users. They also will look at your MX records and try to send email to systems with higher weights, on the too frequently correct premise that those are valid, and not as up to date as your primary systems. Probe your own lines by setting up regular port scans on all IP address space, whether a part of your primary datacenter, your DR site, or your remote offices. Verify that each and every host that accepts a connection on TCP port 25 is a valid mail server, and is properly configured with the appropriate anti-spam measures at your disposal. Make sure that every host with an MX record in your DNS is appropriately configured as well.</p>
<h2>Camouflage</h2>
<p>Spammers will also try to get past your defenses, and your users’ own suspicions, by obfuscating links using a variety of methods including encoding, URL shorteners, and  redirects. Your message filtering system should already be filtering that sort of thing out, but make sure you set low thresholds for the numbers of links that are in an email. Educate users on the dangers attachments present, and quarantine any encrypted attachments until you can confirm they are legitimate business communications.</p>
<h2>Covert operations</h2>
<p>Spammers will frequently spoof the sender address in email to get past filters. They may even use a recipient’s address or another in the same domain as the sender address so it looks more legitimate. To defend against such attacks, use the technologies available to you. Ensure your own SPF records are up-to-date, and set to hard fail (-) to protect others from spammers who try to masquerade as you, and reject any email you receive that fails an SPF check. Use DNS black lists to refuse mail from known spammers and address ranges that belong to residential and mobile services. You can always whitelist a partner but your default posture should be to reject any mail that fails to pass the sniff test.</p>
<p>Ultimately, if the spammer finds even a fraction of a percent of his efforts are successful, he will remain motivated to attempt more attacks. We have to take the financial incentive out of the equation, and that means spreading the word to our user base, our friends, our families, and the social groups we interact with. If no one responded to a spam message, or clicked a link in a piece of UCE, there’d be no financial motivation for a spammer to continue his campaigns against us. Will we get the word out to every single email user in the world? Of course not. But if we can educate our users to stop the activities that make all the <em>user@ourdomain.com </em>addresses pop up in the cross hairs of the spammer, and we take appropriate cautions and set proper configurations on our systems, in the long term we should see a marked downtick in the volume of spam heading our way.</p>
<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br/><br/><a href="http://www.allspammedup.com/2012/02/spam-fighting-boot-camp-week-1-know-your-enemy/">Spam Fighting Boot Camp Week 1: Know Your Enemy</a></p><img src="http://feeds.feedburner.com/~r/Allspammedup/~4/ht1d6aFmpOQ" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://junkmailscan.com//spam-fighting-boot-camp-week-1-know-your-enemy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Banks and Top Websites Develop New Spam Fighting Techniques</title>
		<link>http://junkmailscan.com//banks-and-top-websites-develop-new-spam-fighting-techniques/</link>
		<comments>http://junkmailscan.com//banks-and-top-websites-develop-new-spam-fighting-techniques/#comments</comments>
		<pubDate>Fri, 03 Feb 2012 15:00:52 +0000</pubDate>
		<dc:creator>Sue Walsh</dc:creator>
				<category><![CDATA[Fighting spam]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Spam news]]></category>
		<category><![CDATA[Stop Spam]]></category>
		<category><![CDATA[anti spam]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[spam gov]]></category>
		<category><![CDATA[stop spam]]></category>

		<guid isPermaLink="false">http://www.allspammedup.com/?p=7030</guid>
		<description><![CDATA[In a new effort to fight spam, major financial firms such as Bank of America, FidelityInvestments, and Paypal are partnering with popular internet fixtures Facebook, Google, and Microsoft to create new industry standards designed to make it more difficult for &#8230;<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br /><br /><a href="http://www.allspammedup.com/2012/02/banks-and-top-websites-develop-new-spam-fighting-techniques/">Banks and Top Websites Develop New Spam Fighting Techniques</a></p>]]></description>
			<content:encoded><![CDATA[<p><a  href="http://www.allspammedup.com/wp-content/uploads/2012/01/spam-fighting.jpg"><img class="alignright size-medium wp-image-7085" style="border-width: 0px; border-color: black; border-style: solid; margin: 10px;" title="spam-fighting" src="http://www.allspammedup.com/wp-content/uploads/2012/01/spam-fighting-400x270.jpg" alt="" width="360" height="243" /></a>In a new effort to <a href="http://www.moneycontrol.com/news/wire-news/banks-internet-companies-teamto-fight-spam_658892.html">fight spam</a>, major financial firms such as Bank of America, FidelityInvestments, and Paypal are partnering with popular internet fixtures Facebook, Google, and Microsoft to create new industry standards designed to make it more difficult for spammers to brandjack for their spam campaigns and phishing attacks.<br />
The companies have formed a group called DMARC.org (Domain-based Message Authentication, Reporting, and Conformance). They hope that by using Sender Policy Framework (SPF) and DomainKeys Identifed Mail (DKM), businesses can turn the tables on spammers by making email spoofing next to impossible. Paypal uses them, but only those with Yahoo and Gmail addresses can benefit at this time. The group would like to see that expand so that all users are protected.</p>
<blockquote><p>What we need is an Internet standard that allows this level of protection to work at scale &#8211; without any discussion, without any partner agreements,&#8221; said Brett McDowell, a security manager at PayPal who serves as chairman of the group. “That is what DMARC does.”</p></blockquote>
<p>Setting industry standards is an important step, but still more important is getting the corporate world to adopt them. There will probably be some protesting and the inevitable excuses such as <em>“I don’t have the time to implement them/train my IT department”</em> and the most popular excuse <em>“cost too much in time/productivity/money”</em>. It may take some time to get most businesses aboard, but I think once they are, it will make a dramatic difference in the amount of spam and phishing attacks sent from corporate addresses or exploting popular brands.</p>
<p>What do you think? Will your company adopted the new standards? If not, why?</p>
<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br/><br/><a href="http://www.allspammedup.com/2012/02/banks-and-top-websites-develop-new-spam-fighting-techniques/">Banks and Top Websites Develop New Spam Fighting Techniques</a></p><img src="http://feeds.feedburner.com/~r/Allspammedup/~4/x2jTRiJdSag" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://junkmailscan.com//banks-and-top-websites-develop-new-spam-fighting-techniques/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>5 Ways Your Users Can Help You Fight Spam</title>
		<link>http://junkmailscan.com//5-ways-your-users-can-help-you-fight-spam/</link>
		<comments>http://junkmailscan.com//5-ways-your-users-can-help-you-fight-spam/#comments</comments>
		<pubDate>Thu, 02 Feb 2012 15:00:35 +0000</pubDate>
		<dc:creator>Jeff Orloff</dc:creator>
				<category><![CDATA[CAN-SPAM Act]]></category>
		<category><![CDATA[E-mail filtering]]></category>
		<category><![CDATA[Email address]]></category>
		<category><![CDATA[Fighting spam]]></category>
		<category><![CDATA[Hotmail]]></category>
		<category><![CDATA[Mail]]></category>
		<category><![CDATA[Stop Spam]]></category>
		<category><![CDATA[iPad]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[spam email]]></category>
		<category><![CDATA[spam gov]]></category>
		<category><![CDATA[stop spam]]></category>

		<guid isPermaLink="false">http://www.allspammedup.com/?p=7014</guid>
		<description><![CDATA[Just about every company is all too aware of the problems that spam can lead to. This has prompted a majority of IT departments to employ some sort of anti-spam, or spam filtering, solution to assist in keeping the inboxes &#8230;<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br /><br /><a href="http://www.allspammedup.com/2012/02/5-ways-your-users-can-help-you-fight-spam/">5 Ways Your Users Can Help You Fight Spam</a></p>]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.allspammedup.com/wp-content/uploads/2012/01/email-spam.gif"><img class="alignright size-medium wp-image-7015" style="border-image: initial; border-width: 0px; border-color: black; border-style: solid; margin: 10px;" src="http://www.allspammedup.com/wp-content/uploads/2012/01/email-spam-400x381.gif" alt="" width="240" height="229" /></a>Just about every company is all too aware of the problems that spam can lead to.</p>
<p>This has prompted a majority of IT departments to employ some sort of anti-spam, or spam filtering, solution to assist in keeping the inboxes of their users as spam free as possible.</p>
<p>But notice that the word assist is used in that previous sentence.</p>
<p>This is because no spam filter is going to completely eliminate spam. There are some out there that will do a great job of drastically reducing the amount of junk email that is successfully delivered, but despite the anti-spam solution’s best efforts there are users in every organization that will find a way to attract spam like ants to a picnic.</p>
<p>To help reduce the number of pharmaceutical advertisements and promises of great riches that fill the inboxes of your co-workers, try these hints to help involve them in the fight against spam:<span id="more-7014"></span></p>
<p><strong>1. There is no one giving you a iPad for free.</strong></p>
<p>When you click on those advertisements that proclaim you the lucky winner of an iPad, XBox, smart phone, etc. understand that they are just collecting your email address and other personal information to sell off to spammers.</p>
<p><em>Instruct your users to avoid clicking on any advertisements when they using computer resources at work to avoid falling for scams that collect their email addresses and to stay away from sites that may install malware on their computer.</em></p>
<p><strong>2. Social games harvest more than virtual crops. </strong></p>
<p><strong></strong>When a game boasts over 70 million players, people take notice. Some of those people are spammers.</p>
<p>Social games are fun ways to pass the time, and most are free to play. And while the makers of these games will often charge for level-ups or other premium services they also make money other ways. When you register, you provide your email address, your age, your income and a host of other information that can help advertisers (and spammers) better target you for mass mailings.</p>
<p><em>Users should understand that they should only play games on sites that legitimately protect their personal information and that their work email should never be used to register on any site. Also, they can cut down on spam and advertisements by reading the fine print when signing up and opting not to receive product information from the company or its partners.</em></p>
<p><strong>3. Unsubscribing tells spammers you are alive.</strong></p>
<p>According to the CAN-SPAM Act, all email marketing must contain a way for recipients to remove their name from the mailing list. Spammers know this and use this for two things. First, it helps legitimatize them. People see this and think that it is merely an innocent advertisement. Secondly, it lets the spammer know that they have found an active email address instead of one that has long been abandoned.</p>
<p><em>Teach users how to block emails so that when they receive newsletters and advertisements that they don’t pay attention to, they can simply block them rather than opt-out.</em></p>
<p>Make it easy for users to help identify spammers. One organization I work with has an email address set up for users who receive spam or other suspicious mail. They simply forward the email message in question to that account and someone from the IT security team addresses the problem. Not only does this help feed the spam filter with more data to use, but it brings the users into the fight. They feel like they are helping to solve the problem.</p>
<p><em>Users can be one of the best weapons in fighting spam, if you make it easy enough for them to help. A simple email address where they can forward suspicious emails beats having them fill out a form or filing a formal report.</em></p>
<p><strong>4. Never register for forums, websites, chats or newsletters using your work email address.</strong></p>
<p>Many times, we sign up for things with our work address because it is something legitimately used for work. This can lead to users being comfortable with this process and eventually, they will post that address to a less than ethical site.</p>
<p><em>Make it a policy that company email addresses should not be used to register for anything other than with a trusted vendor, customer or partner.</em></p>
<p><strong>5. Clean out your inbox regularly.</strong></p>
<p>When forced to clear junk mail out of their inbox, most people will be more cognizant of how much spam is sent to them on a daily basis. When they find this process to be tedious, they will likely do a better job at managing their email address out in the wild.</p>
<p><em>Most companies have policies that address email inboxes, and just as many don’t really enforce these policies. Make sure that users know that this, or any other policy regarding email, will be enforced.</em></p>
<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br/><br/><a href="http://www.allspammedup.com/2012/02/5-ways-your-users-can-help-you-fight-spam/">5 Ways Your Users Can Help You Fight Spam</a></p><img src="http://feeds.feedburner.com/~r/Allspammedup/~4/_5siRNP-hZA" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://junkmailscan.com//5-ways-your-users-can-help-you-fight-spam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>5 Tips to Keep Your Emails Out Spam and Junk Folders</title>
		<link>http://junkmailscan.com//5-tips-to-keep-your-emails-out-spam-and-junk-folders/</link>
		<comments>http://junkmailscan.com//5-tips-to-keep-your-emails-out-spam-and-junk-folders/#comments</comments>
		<pubDate>Wed, 01 Feb 2012 15:00:41 +0000</pubDate>
		<dc:creator>Sue Walsh</dc:creator>
				<category><![CDATA[Anti-spam techniques]]></category>
		<category><![CDATA[Fighting spam]]></category>
		<category><![CDATA[Stop Spam]]></category>
		<category><![CDATA[anti spam]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[spam blacklist]]></category>
		<category><![CDATA[spam gov]]></category>
		<category><![CDATA[stop spam]]></category>

		<guid isPermaLink="false">http://www.allspammedup.com/?p=7041</guid>
		<description><![CDATA[I do business with quite a few online retailers and services and most of them send me marketing emails and newsletters. Without fail, a few always wind up flagged as spam and redirected to my spam folder. I found out that &#8230;<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br /><br /><a href="http://www.allspammedup.com/2012/02/5-tips-to-keep-your-emails-out-spam-and-junk-folders/">5 Tips to Keep Your Emails Out Spam and Junk Folders</a></p>]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.allspammedup.com/wp-content/uploads/2012/01/spam1.jpg"><img class="alignright size-medium wp-image-7081" style="border-width: 0px; border-color: black; border-style: solid; margin: 10px;" title="spam" src="http://www.allspammedup.com/wp-content/uploads/2012/01/spam1-400x265.jpg" alt="" width="320" height="212" /></a>I do business with quite a few online retailers and services and most of them send me marketing emails and newsletters. Without fail, a few always wind up flagged as spam and redirected to my spam folder. I found out that even though they come from different senders, they tend to have a few things in common. Below are five reasons why they ended up in the spam and junk folders, and tips on how to avoid having your marketing emails meet the same fate:</p>
<p><strong>1. Bad Subject Lines</strong><br />
Most spam filters are programmed to look for words like “free”, “sale”, “deal” and “discount” in subject lines. Since spammers love to use such words in an attempt to lure people into reading their messages, more often than not, legit emails with those words in the subject line will end up flagged as spam. It’s also important to check and double check before you hit send. I’ve received marketing emails with blank subject lines or “Type Headline Here” as the subject, indicating the person in charge of sending the marketing blast was either careless or inexperienced. Not only does this make your company look very unprofessional, but it can get your messages flagged as spam.</p>
<p><strong>2. Careless Use of the CC Feature</strong><br />
You should never send emails to a large group using CC. This not only exposes your customer’s email addresses, but if one of them decides to respond and chooses to hit the &#8216;reply all&#8217;, it will end up causing an unintentional spam loop and a lot of unhappy customers. Emails with huge CC lists are also a common feature of spam generated via dictionary attacks. Use BCC or a mailing list manager like Constant Contact.</p>
<p><strong>3. Sending Attachments</strong><br />
There should never ever be a reason for you to send your customers attachments, but I’ve gotten a couple of marketing emails with them. It was almost always caused by a poorly formatted HTML message which included the graphics as attachments. A big no-no!</p>
<p><strong>4. Bad IPs</strong><br />
It’s important to check your IP addresses regularly to make sure they haven’t been placed on blacklist. False positives aren’t uncommon and it’s also possible to have your server compromised without knowing it. Email sent from a blacklisted IP will never make it to any recipient whose IP subscribes to that blacklist.</p>
<p><strong>5. Buried Unsubscribe Instructions</strong><br />
There will always be people who subscribed and then changed their minds, and many will become easily frustrated and simply report your newsletter as spam instead of doing the right thing. Don’t rely on a tiny link buried at the end of the email. Make sure your unsubscribe link is easy to find.</p>
<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br/><br/><a href="http://www.allspammedup.com/2012/02/5-tips-to-keep-your-emails-out-spam-and-junk-folders/">5 Tips to Keep Your Emails Out Spam and Junk Folders</a></p><img src="http://feeds.feedburner.com/~r/Allspammedup/~4/V-xk6IpJ9GQ" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://junkmailscan.com//5-tips-to-keep-your-emails-out-spam-and-junk-folders/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>FBI Declares ‘Gameover’, Link to ZeuS</title>
		<link>http://junkmailscan.com//fbi-declares-%e2%80%98gameover%e2%80%99-link-to-zeus/</link>
		<comments>http://junkmailscan.com//fbi-declares-%e2%80%98gameover%e2%80%99-link-to-zeus/#comments</comments>
		<pubDate>Tue, 31 Jan 2012 17:00:27 +0000</pubDate>
		<dc:creator>Malcolm James</dc:creator>
				<category><![CDATA[Fighting spam]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Spam news]]></category>
		<category><![CDATA[Stop Spam]]></category>
		<category><![CDATA[anti phishing]]></category>
		<category><![CDATA[anti spam]]></category>
		<category><![CDATA[antispam]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[cybercriminals]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[spam email]]></category>
		<category><![CDATA[spammers]]></category>
		<category><![CDATA[spam gov]]></category>
		<category><![CDATA[stop spam]]></category>

		<guid isPermaLink="false">http://www.allspammedup.com/?p=6964</guid>
		<description><![CDATA[Malware developers seem to appreciate a little humor when it comes to naming their schemes. One of the latest email scams to invade inboxes everywhere is no exception, it seems, and the FBI has been quick to let businesses know &#8230;<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br /><br /><a href="http://www.allspammedup.com/2012/01/fbi-declares-gameover-link-to-zeus/">FBI Declares &#8216;Gameover&#8217;, Link to ZeuS</a></p>]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-medium wp-image-6967" style="padding-left: 5px; padding-bottom: 5px; border-width: 0px; border-color: black; border-style: solid; margin: 10px;" src="http://www.allspammedup.com/wp-content/uploads/2012/01/bigstock_Space_Invaders_Game_Over_5142602-400x299.jpg" alt="" width="400" height="299" /></p>
<p><strong>Malware developers seem to appreciate a little humor when it comes to naming their schemes. One of the latest email scams to invade inboxes everywhere is no exception, it seems, and the FBI has been quick to let businesses know that if they don’t keep their eyes open for a phishing scam originating in an email from FDIC, NACHA and the Federal Reserve, opening the mail’s attachment could be one of the most devastating choices in a young 2012. Worse yet, this new scheme appears to be linked to the Lord of the Greek gods – or its eponymous malware, anyway.</strong></p>
<p>‘Game over’ is never a good thing, whether it means that your last ship has been destroyed and your quarter spent, whether it’s a lame and overused witticism that yet again has found its way into the mouth of Hollywood’s action hero <em>du jour</em>, and yes, even when cyber criminals are searching for just the right name for their latest piece of malware. While we’re not averse to debating the first two, our interest here is firmly with the latter. It seems the U.S. Federal Bureau of Investigation shares that interest, as evidenced by a <a  href="http://www.fbi.gov/news/stories/2012/january/malware_010612">security bulletin</a> earlier this month that identifies a new email scam, one which cyber criminals have decided to call – what else? – <em>Gameover</em>.</p>
<p><span id="more-6964"></span></p>
<p>Gameover is a phishing attack that appears in the form of spam emails spoofing the Federal Deposit Insurance Corporation (FDIC), the Federal Reserve Bank, or the National Automated Clearing House Association (NACHA). Like a multitude of others, the scheme preys on users’ fears and/or lack of vigilance, informing them that there has been a problem with their bank account or an ACH transaction (ACH stands for Automated Clearing House, a network for financial institutions in the U.S.). Sufficiently frightened, recipients are encouraged to click the included link, which instead of resolving the issue, takes the user to a malicious site where the Gameover malware is executed.</p>
<p>The malware has been identified as a variant of ZeuS, a notorious piece of malware which has been responsible for stealing financial information through the practice of keylogging for a number of years. Once activated, the cyber crooks can steal banking information such as account numbers and passwords.</p>
<p><strong>As if that wasn’t enough…</strong></p>
<p>More than just a keylogger, however, ZeuS (and coincidentally, Gameover) has an added payload. According to the FBI:</p>
<blockquote><p>“After the perpetrators access your account, they conduct what’s called a distributed denial of service, or DDoS, attack using a botnet, which involves multiple computers flooding the financial institution’s server with traffic in an effort to deny legitimate users access to the site — probably in an attempt to deflect attention from what the bad guys are doing.”</p></blockquote>
<p><strong>But wait &#8211; there’s more!</strong></p>
<p>In what sounds like a novel involving international intrigue, FBI investigations have been able to trace the attacks as far as to jewelers, as the stolen funds are used to purchase “precious stones and expensive watches from high-end jewelry stores”. The crooks contact the jeweler, tell them what they’d like to purchase and inform them that they will wire the money the following day. The following day, a “money mule” – a person involved in the money laundering part of the crime – shows up at the jewelry store to pick up the merchandise. The jeweler confirms that the money (the stolen money from the spam scheme) is in their account and upon doing so, turns the merchandise over to the mule, who in turn delivers the merchandise to the crooks or converts it into cash that upon being transferred, is effectively laundered.</p>
<p>Wow &#8211; It really is the stuff of imagination, but even more interesting is that the FBI has suggested that the mules could be unsuspecting victims of those omnipresent ‘work at home’ schemes that we see everywhere. While the federal agency has confirmed that many of the mules are willing participants, it has also noted that an increasing number are likely people who have succumbed to these schemes and have been unwittingly recruited into laundering money stolen from victims of the spam scheme.</p>
<p>Be on the lookout for this one and advise your staff ASAP. At very most, it could be a story worthy of a novel. At very least, it could save you and your users plenty of headaches and lost funds.</p>
<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br/><br/><a href="http://www.allspammedup.com/2012/01/fbi-declares-gameover-link-to-zeus/">FBI Declares &#8216;Gameover&#8217;, Link to ZeuS</a></p><img src="http://feeds.feedburner.com/~r/Allspammedup/~4/XIG4G_xdjXg" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://junkmailscan.com//fbi-declares-%e2%80%98gameover%e2%80%99-link-to-zeus/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>January Spam Roundup</title>
		<link>http://junkmailscan.com//january-spam-roundup/</link>
		<comments>http://junkmailscan.com//january-spam-roundup/#comments</comments>
		<pubDate>Mon, 30 Jan 2012 17:00:07 +0000</pubDate>
		<dc:creator>Sue Walsh</dc:creator>
				<category><![CDATA[Fighting spam]]></category>
		<category><![CDATA[Spam news]]></category>
		<category><![CDATA[Stop Spam]]></category>
		<category><![CDATA[anti spam]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[spam gov]]></category>
		<category><![CDATA[stop spam]]></category>

		<guid isPermaLink="false">http://www.allspammedup.com/?p=7048</guid>
		<description><![CDATA[Along with a new year, January brought with it a new wave of spam campaigns, most ofthem malicious in nature. Here&#8217;s a look at some of the top headlines for the month: Nokia Fined For Spamming Their Customers: http://arstechnica.com/gadgets/news/2012/01/nokia-fined-in-australia-for-spam-texting-its-own-customers.ars Top 9 Domains &#8230;<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br /><br /><a href="http://www.allspammedup.com/2012/01/january-spam-roundup/">January Spam Roundup</a></p>]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-157" style="border-width: 0px; border-color: black; border-style: solid; margin: 10px;" src="http://www.allspammedup.com/wp-content/uploads/2008/10/223094_latest_news.jpg" alt="" width="210" height="158" /></p>
<p>Along with a new year, January brought with it a new wave of spam campaigns, most ofthem malicious in nature. Here&#8217;s a look at some of the top headlines for the month:</p>
<p><strong>Nokia Fined For Spamming Their Customers:</strong></p>
<p><a  href="http://arstechnica.com/gadgets/news/2012/01/nokia-fined-in-australia-for-spam-texting-its-own-customers.ars">http://arstechnica.com/gadgets/news/2012/01/nokia-fined-in-australia-for-spam-texting-its-own-customers.ars</a></p>
<p><strong>Top 9 Domains Used to Send Spam:</strong></p>
<p><a  href="http://betanews.com/2012/01/25/what-are-the-top-domains-used-for-spam/">http://betanews.com/2012/01/25/what-are-the-top-domains-used-for-spam/</a></p>
<p><strong>New Wave of Spam Infects Just By Opening Email:</strong></p>
<p><a  href="http://www.darkreading.com/security/attacks-breaches/232500660/new-drive-by-spam-infects-those-who-open-email-no-attachment-needed.html">http://www.darkreading.com/security/attacks-breaches/232500660/new-drive-by-spam-infects-those-who-open-email-no-attachment-needed.html</a></p>
<p><strong>Global Spam Levels Drop, Malware Rises:</strong></p>
<p><a  href="http://www.zdnet.com/blog/btl/global-spam-declines-as-malware-encounters-pick-up-report/67858">http://www.zdnet.com/blog/btl/global-spam-declines-as-malware-encounters-pick-up-report/67858</a></p>
<p><strong>Man Accused of Running the Kelihos Botnet Says He’s Innocent:</strong></p>
<p><a  href="http://www.computerworld.com/s/article/9223820/Accused_Kelihos_botmaster_proclaims_innocence">http://www.computerworld.com/s/article/9223820/Accused_Kelihos_botmaster_proclaims_innocence</a></p>
<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br/><br/><a href="http://www.allspammedup.com/2012/01/january-spam-roundup/">January Spam Roundup</a></p><img src="http://feeds.feedburner.com/~r/Allspammedup/~4/2rZvlAeTTR8" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://junkmailscan.com//january-spam-roundup/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Spam Fighting Boot Camp: The Mission</title>
		<link>http://junkmailscan.com//spam-fighting-boot-camp-the-mission/</link>
		<comments>http://junkmailscan.com//spam-fighting-boot-camp-the-mission/#comments</comments>
		<pubDate>Mon, 30 Jan 2012 15:00:16 +0000</pubDate>
		<dc:creator>Casper Manes</dc:creator>
				<category><![CDATA[Fighting spam]]></category>
		<category><![CDATA[Stop Spam]]></category>
		<category><![CDATA[anti spam]]></category>
		<category><![CDATA[spamfighting bootcamp]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[spam gov]]></category>
		<category><![CDATA[stop spam]]></category>

		<guid isPermaLink="false">http://www.allspammedup.com/?p=6981</guid>
		<description><![CDATA[Please read the following post with the voice of a drill sergeant in your mind. Imagine something between R. Lee Ermey and Samuel L. Jackson if you can, or maybe Stephen Lang. Alright people, listen up! Welcome to Spam Fighting &#8230;<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br /><br /><a href="http://www.allspammedup.com/2012/01/spam-fighting-boot-camp-the-mission/">Spam Fighting Boot Camp: The Mission</a></p>]]></description>
			<content:encoded><![CDATA[<p><span style="color: #000000; font-family: Georgia, 'Times New Roman', 'Bitstream Charter', Times, serif;"><a href="http://www.allspammedup.com/wp-content/uploads/2012/01/DrillSergeant.jpg"><img class="alignright size-full wp-image-7023" style="border-width: 0px; border-color: black; border-style: solid; margin: 10px;" src="http://www.allspammedup.com/wp-content/uploads/2012/01/DrillSergeant.jpg" alt="" width="240" height="192" /></a><em>Please read the following post with the voice of a drill sergeant in your mind. Imagine something between R. Lee Ermey and Samuel L. Jackson if you can, or maybe Stephen Lang.</em> Alright people, listen up! Welcome to Spam Fighting Boot Camp, or what some mamby-pamby college puke might call Spamfighting 101!  Over the next nine weeks I&#8217;m going to take you through a series of briefings designed to turn you into a lean, mean, spam fighting machine. We will teach you to know your enemy, train you to anticipate, out think, outmaneuver, and out fight your opponent, and leave you with the skills necessary to defend your email systems to the last message. Our users must be protected from the enemy, and that enemy is spam!</span></p>
<p><span style="color: #000000; font-family: Georgia, 'Times New Roman', 'Bitstream Charter', Times, serif;">The best defence is a strong offence, but as much fun as a search and destroy mission behind enemy lines might be, our field of battle must remain within our users’ inboxes. Our goal is zero casualties people, and no mailbox gets left behind. Here’s what you can look forward to over the next several weeks:<span id="more-6981"></span></span></p>
<h2><strong><span style="color: #000000; font-family: Georgia, 'Times New Roman', 'Bitstream Charter', Times, serif;">Week 1: Know your enemy</span></strong></h2>
<p><span style="color: #000000; font-family: Georgia, 'Times New Roman', 'Bitstream Charter', Times, serif;">We’re going to look at how spammers think, how they act, what their motivations are, and the cunning tricks that they play in their unending attempts to compromise our users’ inboxes. We’ll look at our own infrastructures&#8217; fortifications through the eyes of a spammer, so that we can see the weaknesses that our enemy will attempt to exploit.</span></p>
<h2><strong><span style="color: #000000; font-family: Georgia, 'Times New Roman', 'Bitstream Charter', Times, serif;">Week 2: Beware of friendly fire</span></strong></h2>
<p><span style="color: #000000; font-family: Georgia, 'Times New Roman', 'Bitstream Charter', Times, serif;">While our mission is to oppose the enemy wherever we may find him, we don’t want to become the victim of friendly fire, and we don’t want anyone else mistaking us for a spammer. We’ll look at the proactive measures and policies that will prevent these sorts of accidents from happening.</span></p>
<h2><strong><span style="color: #000000; font-family: Georgia, 'Times New Roman', 'Bitstream Charter', Times, serif;">Week 3: Improvise, adapt, overcome</span></strong></h2>
<p><span style="color: #000000; font-family: Georgia, 'Times New Roman', 'Bitstream Charter', Times, serif;">Budgets are tight, and sometimes you must make do with what is at hand at the moment. We’ll look at the anti-spam technologies that are available to you in some of the most popular email systems.</span></p>
<h2><strong><span style="color: #000000; font-family: Georgia, 'Times New Roman', 'Bitstream Charter', Times, serif;">Week 4: A well-regulated militia</span></strong></h2>
<p><span style="color: #000000; font-family: Georgia, 'Times New Roman', 'Bitstream Charter', Times, serif;">Try as we might, sometimes the enemy slips behind the line, and arming our users’ workstations adds a layer of security to halt those spams that might get past our sentries.</span></p>
<h2><strong><span style="color: #000000; font-family: Georgia, 'Times New Roman', 'Bitstream Charter', Times, serif;">Week 5: The last line of defence</span></strong></h2>
<p><span style="color: #000000; font-family: Georgia, 'Times New Roman', 'Bitstream Charter', Times, serif;">Spammers continue their campaign against us because, at the end of the day, there’s always someone who will buy whatever line they’re selling. Here we’ll look at winning the hearts and minds of our users, educating them against the threats spam presents.</span></p>
<h2><strong><span style="color: #000000; font-family: Georgia, 'Times New Roman', 'Bitstream Charter', Times, serif;">Week 6: Gearing up </span></strong></h2>
<p><span style="color: #000000; font-family: Georgia, 'Times New Roman', 'Bitstream Charter', Times, serif;">To shore up our defenses, we have many options available. During this training mission, we’re going to look at the options available for shoring up our defences with bolt-on software solutions.</span></p>
<h2><strong><span style="color: #000000; font-family: Georgia, 'Times New Roman', 'Bitstream Charter', Times, serif;">Week 7: Allied Forces </span></strong></h2>
<p><span style="color: #000000; font-family: Georgia, 'Times New Roman', 'Bitstream Charter', Times, serif;">Some campaigns may require us to interact with allied forces. Understanding them completely can make the difference between a quick victory and a protracted campaign, and we’ll look at strategies for combining our strengths into an effective spam smashing force.</span></p>
<h2><strong><span style="color: #000000; font-family: Georgia, 'Times New Roman', 'Bitstream Charter', Times, serif;">Week 8: Forward operations</span></strong></h2>
<p><span style="color: #000000; font-family: Georgia, 'Times New Roman', 'Bitstream Charter', Times, serif;">The closer we can bring the fight to the enemy, the further away they are from our users, and cloud-based solutions move the fight from our datacenter to the Internet. We’ll examine strategies for success.</span></p>
<h2><strong><span style="color: #000000; font-family: Georgia, 'Times New Roman', 'Bitstream Charter', Times, serif;">Week 9: Good to go</span></strong></h2>
<p><span style="color: #000000; font-family: Georgia, 'Times New Roman', 'Bitstream Charter', Times, serif;">Training complete, you’re  ready to engage the enemy. We’ll go over some last minute tactics and strategies to make you the complete spam killing machine.</span></p>
<p><span style="color: #000000; font-family: Georgia, 'Times New Roman', 'Bitstream Charter', Times, serif;">Well alright then. Gear up, strap in, and get ready for some action! Spamfighting bootcamp is about to begin!</span></p>
<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br/><br/><a href="http://www.allspammedup.com/2012/01/spam-fighting-boot-camp-the-mission/">Spam Fighting Boot Camp: The Mission</a></p><img src="http://feeds.feedburner.com/~r/Allspammedup/~4/ifGtSgwLMhw" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://junkmailscan.com//spam-fighting-boot-camp-the-mission/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Phishing Scam Targets Victims Using Better Business Bureau</title>
		<link>http://junkmailscan.com//phishing-scam-targets-victims-using-better-business-bureau/</link>
		<comments>http://junkmailscan.com//phishing-scam-targets-victims-using-better-business-bureau/#comments</comments>
		<pubDate>Fri, 27 Jan 2012 17:00:10 +0000</pubDate>
		<dc:creator>Jeff Orloff</dc:creator>
				<category><![CDATA[BBB]]></category>
		<category><![CDATA[Better Business Bureau]]></category>
		<category><![CDATA[Fighting spam]]></category>
		<category><![CDATA[Spam news]]></category>
		<category><![CDATA[Stop Spam]]></category>
		<category><![CDATA[Website]]></category>
		<category><![CDATA[anti phishing]]></category>
		<category><![CDATA[anti spam]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[phishing scam]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[spam gov]]></category>
		<category><![CDATA[stop spam]]></category>

		<guid isPermaLink="false">http://www.allspammedup.com/?p=6913</guid>
		<description><![CDATA[This past holiday season showed that spending in brick and mortar stores was significantly off targeted projects. People just weren’t spending as much money in the malls and department stores. However every single study of consumer spending did show that &#8230;<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br /><br /><a href="http://www.allspammedup.com/2012/01/phishing-scam-targets-victims-using-better-business-bureau/">Phishing Scam Targets Victims Using Better Business Bureau</a></p>]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.allspammedup.com/wp-content/uploads/2012/01/BBB_7469-blue-torch.jpg"><img class="alignright size-medium wp-image-6914" style="border-width: 0px; border-color: black; border-style: solid; margin: 10px;" src="http://www.allspammedup.com/wp-content/uploads/2012/01/BBB_7469-blue-torch-264x400.jpg" alt="" width="185" height="280" /></a>This past holiday season showed that spending in brick and mortar stores was significantly off targeted projects.</p>
<p>People just weren’t spending as much money in the malls and department stores.</p>
<p>However every single study of consumer spending did show that companies with a strong online presence had a significant boost in sales this past year, including the holiday shopping season. In fact during December alone, non-store sales rose 10.6 percent from the same time one year ago. Even automobile sales online boasted a 9.5 percent increase.</p>
<p>To make sure they can stay competitive in the online retail sector, businesses must strive to build, and at the same time maintain, a solid reputation on the Internet.</p>
<p>Of course it was only a matter of time before spammers realized this as an opportunity to take advantage of this trend to dupe business owners into downloading dangerous malware.</p>
<p><span id="more-6913"></span></p>
<h2>How the Scam Works</h2>
<p>Businesses are sent an email branded with the Better Business Bureau logo that reads:</p>
<blockquote><p><em>“Thank you for supporting your Better Business Bureau (BBB). Your BBB receives more than 6,500 requests for information every day and provides reliability reports to consumers 365 days a year, 24 hours a day, and 7 days a week.</em></p>
<p><em>As a service to BBB Accredited Businesses, we try to ensure that the information we provide to potential customers is as accurate as possible. In order for us to provide the correct information to the public, we ask that you review the information that we have on file for your company.</em></p>
<p><em>We encourage you to use our ONLINE FORM to provide us with this updated information. The URL below will take you directly to this form on our website:</em></p>
<p><em>CLICK HERE</em><em> </em><em>to login to your BBB account</em></p>
<p><em>You may also complete the form on the reverse side of this letter and mail to PO Box 1000; DuPont, WA; 98327; or fax to (206)436-5496.</em></p>
<p><em>Please look carefully at your telephone and fax numbers on this sheet, and let us know any and all numbers used for your business (including 800, 900, rollover, and remote call forwarding). Our automated system is driven by telephone/fax numbers, so having accurate information is critical for consumers to find information about your business easily. In addition, many consumers may search our database using your e-mail and/or Web address, so please be sure to include this information as well. As a BBB accredited business, you receive a free hyperlink from your online reliability report to your company Web site if provided to us.</em></p>
<p><em>Thank you again for your support, and we look forward to receiving this updated information.</em></p>
<p><em>Sincerely,</em></p>
<p><em>Accreditation Services”</em></p></blockquote>
<p>Eager to keep their information and good standing current, business owners and managers who click the link are not taken to a legitimate site hosted by the BBB. Instead their computer downloads malware and their account credentials are compromised by the phisher.</p>
<p>Another version of the phishing scam informs the recipient of the email that a negative review of their company has been posted to the BBB site. To refute the claim, the recipient must click on the supplied URL and address the problem. Failure to do so would result in the complaint resulting in a bad report being filed.</p>
<p>The URL here also directs the victim to a malicious site and has the potential for account credentials being stolen.</p>
<h2>Fighting Back</h2>
<p>This newest scam is the third of its kind in the last three months targeted at business owners.</p>
<p>Businesses have been instructed, by the BBB, to contact them directly if they receive emails claiming that they have received a negative complaint or that their information is incorrect or incomplete.</p>
<p>The Better Business Bureau is also taking steps to fight the problem, enlisting the help of the FBI.</p>
<blockquote><p>&#8220;Our national organization in Arlington, Va. has been working for three months with the FBI, and I can tell you that they&#8217;ve closed down over 50 sites&#8221;, Katie Carrol, Director of Media Relations and Communications with the BBB, said.</p></blockquote>
<p>They have also asked for business owners to help them fight this growing problem by contacting them at <a  href="mailto:phishing@council.bbb.org">phishing@council.bbb.org</a> if they received these emails, or any others like them.</p>
<p>IT departments should also be aware of this scam and take necessary precautions.</p>
<p>In house steps that can help prevent problems related to this latest attack, as well as others, include:</p>
<ul>
<li>Keeping anti-malware software up-to-date.</li>
<li>Make sure anti-spam solutions are configured correctly and up-to-date.</li>
<li>Make sure that employees are aware of this scam.</li>
<li>Put procedures in place for employees who receive this email, or other spam messages, to report it.</li>
<li>Teach employees how to better recognize spam and phishing attempts.</li>
</ul>
<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br/><br/><a href="http://www.allspammedup.com/2012/01/phishing-scam-targets-victims-using-better-business-bureau/">Phishing Scam Targets Victims Using Better Business Bureau</a></p><img src="http://feeds.feedburner.com/~r/Allspammedup/~4/N-CUj74B4E0" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://junkmailscan.com//phishing-scam-targets-victims-using-better-business-bureau/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Go Phish Yourself?</title>
		<link>http://junkmailscan.com//go-phish-yourself/</link>
		<comments>http://junkmailscan.com//go-phish-yourself/#comments</comments>
		<pubDate>Fri, 27 Jan 2012 15:00:26 +0000</pubDate>
		<dc:creator>Sue Walsh</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Stop Spam]]></category>
		<category><![CDATA[anti phishing]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[spam gov]]></category>
		<category><![CDATA[stop spam]]></category>

		<guid isPermaLink="false">http://www.allspammedup.com/?p=6926</guid>
		<description><![CDATA[A new open source toolkit is designed to provide a way for companies to educate their employees on how to spot phishing scams, but it may give scammers a lot of help as well. The open source Simple Phishing Toolkit &#8230;<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br /><br /><a href="http://www.allspammedup.com/2012/01/go-phish-yourself/">Go Phish Yourself?</a></p>]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.allspammedup.com/wp-content/uploads/2012/01/phishing-yourself.jpg"><img class="alignright size-medium wp-image-6954" style="border-width: 0px; border-color: black; border-style: solid; margin: 10px;" title="phishing-yourself" src="http://www.allspammedup.com/wp-content/uploads/2012/01/phishing-yourself-400x200.jpg" alt="" width="360" height="180" /></a>A new open source toolkit is designed to provide a way for companies to educate their<a href="http://www.allspammedup.com/wp-content/uploads/2011/07/phishing-sml.jpg"><br />
</a> employees on how to spot phishing scams, but it may give scammers a lot of help as well. The open source <a  href="http://www.smh.com.au/it-pro/security-it/phishing-your-employees-in-the-name-of-security-20120118-1q5j8.html">Simple Phishing Toolkit</a> includes a scraper that will quickly clone any website and create a phishing lure. It also comes with tools that allow administrators to track how many employees click on the lure, what links they followed, when they did so, and even their IP addresses, browser info and operating systems.</p>
<p>Naturally, such tools would be very useful for IT departments and system administrators to educate employees on how to spot phishing scams. Employees falling for such scams are a leading cause of corporate data breaches, and such breaches can cost a company millions.</p>
<blockquote><p>&#8220;The whole concept with this project started out with the discussion of, &#8216;Hey, wouldn&#8217;t it be great if we could phish ourselves in a safe manner?&#8217;&#8221; said Will, one of the Toolkit&#8217;s co-developers. &#8220;It seems like in every organisation there is always a short list of people we know are phishable, who keep falling for the same thing every six to eight weeks, and some of this stuff is pretty lame.”</p></blockquote>
<p>While it appears the developers had honest intentions when they created the toolkit, the fact remains it could be pretty attractive to the bad guys and they have no way of controlling that. Right now it doesn’t record any data typed into the fake phishing sites it generates, but they said future versions of the kit will have that functionality. That may make it irresistible to scammers looking for a way to create phishing campaigns that’s fast and won’t eat into any profits.</p>
<p>What do you think? Are these toolkits helpful or just asking for trouble?</p>
<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br/><br/><a href="http://www.allspammedup.com/2012/01/go-phish-yourself/">Go Phish Yourself?</a></p><img src="http://feeds.feedburner.com/~r/Allspammedup/~4/bf7T3xzYj0U" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://junkmailscan.com//go-phish-yourself/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Several New Phishing Campaigns Going Strong</title>
		<link>http://junkmailscan.com//several-new-phishing-campaigns-going-strong/</link>
		<comments>http://junkmailscan.com//several-new-phishing-campaigns-going-strong/#comments</comments>
		<pubDate>Thu, 26 Jan 2012 17:00:06 +0000</pubDate>
		<dc:creator>Sue Walsh</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Spam news]]></category>
		<category><![CDATA[Stop Spam]]></category>
		<category><![CDATA[botnets]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[spam gov]]></category>
		<category><![CDATA[stop spam]]></category>

		<guid isPermaLink="false">http://www.allspammedup.com/?p=6922</guid>
		<description><![CDATA[Several new phishing campaigns have been spotted in the wild. The first one is a new incarnation of an old scam. Emails that look like they&#8217;ve come from your friends arrive with an urgent message about them being on a trip to &#8230;<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br /><br /><a href="http://www.allspammedup.com/2012/01/several-new-phishing-campaigns-going-strong/">Several New Phishing Campaigns Going Strong</a></p>]]></description>
			<content:encoded><![CDATA[<p><a  href="http://www.allspammedup.com/wp-content/uploads/2012/01/phishing1.jpg"><img class="alignright size-medium wp-image-6952" style="border-width: 0px; border-color: black; border-style: solid; margin: 10px;" title="phishing" src="http://www.allspammedup.com/wp-content/uploads/2012/01/phishing1-400x267.jpg" alt="" width="320" height="214" /></a>Several new <a href="http://gazebonews.com/2012/01/19/a-spam-a-rama-day/">phishing campaigns</a> have been spotted in the wild.</p>
<p>The first one is a new incarnation of an old scam. Emails that look like they&#8217;ve come from your friends arrive with an urgent message about them being on a trip to a far flung place such as Madagascar, London, or Berlin and needing help. You see, they were mugged/assaulted and all of their money and documents were stolen, and they really need to go home but there’s the matter of their hotel bill. The messages generally ask for about $1600 to be sent via Western Union. Of course it’s just a variation of a 419 scam. If you get one, no matter how convincing it sounds, try contacting your friend first. In 99.9% of cases you’ll find they are safe and sound at home.</p>
<p>Next is the Better Business Bureau, who has joined the ranks of the brandjacked as new spam messages claiming to be from them are making the rounds. The messages tell the recipient that a complaint has been filed against them and urges them to click the included link to read it and respond. Anyone who does so is taken to a malicious site that attempts to infect their computer with the infamous Zeus Trojan. Zeus, distributes by a botnet with the same name, installs a keylogger and several other nasty bits on to the infected system and steals banking info and other sensitive data.</p>
<p>Finally, popular companies such as Facebook, American Airlines, Paypal, and several major banks are also being brandjacked by scammers. In some cases the phishing messages are receipts for fake purchases or reservations and in others, fake message or fraud notifications. In almost all cases, the attachments and links in the messages deliver malware. It looks like the spammers are hard at work building up their botnets!</p>
<p>Liked this post? Get more <a href="http://www.allspammedup.com">anti-spam</a> related news from AllSpammedUp.com!<br/><br/><a href="http://www.allspammedup.com/2012/01/several-new-phishing-campaigns-going-strong/">Several New Phishing Campaigns Going Strong</a></p><img src="http://feeds.feedburner.com/~r/Allspammedup/~4/C7v0cqU4fgA" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://junkmailscan.com//several-new-phishing-campaigns-going-strong/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

