Twitter Spam and the OAuthcalypse

in

Twitter discontinued support for basic user authentication in third-party applications yesterday morning.

Good. It's always best to never share your password with a third-party. Even if you trust them, their database could be compromised, and your password along with it. The discontinuation of basic user authentication also removes the vector of brute force password attacks via Twiter's API.

All third-party applications must now use Twitter's OAuth.

When do 258 tweets equal nearly half a million dollars?

Wikipedia's affiliate marketing entry includes the following sentence: "Although many affiliate programs have terms of service that contain rules against spam, this marketing method has historically proven to attract abuse from spammers."

This is very true — affiliate marketing methods definitely attract abuse from spammers.

Phishing Attempt Alert!

Someone has been trying to pose as us again, and is sending out an e-mail that looks like this:

From: Account Support
Date: Saturday, August 28, 2010 4:33 AM
To: none
Subject: Account Alert!!!


CPAlead Spam on YouTube

One of our Safe and Savvy bloggers, Melody-Jane, recently asked me about some "free" offers for F-Secure Internet Security 2010 that she spotted on YouTube. She thought the videos, and their associated links, looked just a bit more than suspicious. So I decided to check them out.

DLL Hijacking and Why Loading Libraries is Hard

In the past days, a class of exploits that fall under the category of DLL hijacking (or "binary planting") have gotten a lot of attention. Apple's iTunes had problems, and a lot of other applications seem to be falling for the same thing.

Corporate Identity Theft Used to Obtain Code Signing Certificate

Last week, the lab identified a curious set of spammed malware; files signed with a valid Authenticode code signing certificate.

Company X's stolen certificate

This is something we've seen before. But this case seemed odd because the contact information appeared very genuine. Usually a valid but malicious certificate uses clearly bogus or dubious details.

I May Never Text Again: More Facebook Spam

Today we have an example of yet another Facebook spam (YAFS).

This particular spam links to a Facebook Page called "I May NEVER T�XT AGAIN After Reading THI$!!".

I May NEVER T�XT AGAIN After Reading THI$!!

As you can see, there are over 200 thousand likes.

The Facebook user must click the Like button in order to continue.

What's the success rate of Facebook spam?

Facebook spam (erroneously called scams) has been making headlines recently…

And with all the attention on "virally spreading" links, we wondered, just how effective is it? What's the conversion rate? Links spread virally — but so what? That's only one step in the process. How many people actually fill out the CPA surveys that make the money?

Here's one recent example of spam attempting to use English football player Peter Crouch as bait.

PS3 Jailbreak Trojan

For those of our readers who follow PlayStation 3 discussions, it would have been hard to miss the discussion about a new "jailbreak" for PS3. News of a USB dongle that breaks the security model of the game console to enable execution of third party software (as well as pirated games) have been going around like wildfire.

Malware and Critical Infrastructure

"Computer viruses may have contributed to the Spanair passenger plane crash which killed 154 people in Madrid two years ago", reports the Spanish newspaper El Pais.

El Pais


Syndicate content