Fraudsters limber up for World Cup themed scams

0 comments

Posted on by admin in Spam Firewall |Web Filter |Web Site Firewall

, ,

An interesting article from The Register, on the upcoming FIFA World Cup, and how we can expect a whole variety of scams themed on the event.

Fraudsters as well as footballers are gearing up for this month’s World Cup extravaganza in South Africa.

Football governing body FIFA has already warned [1] supporters to be wary over various forms of scams that are likely to crop up in the run-up to the start of the tournament, which kicks off in ten days.

FIFA lottery, prize draw or competition scams are likely to abound. All represent types of advanced fee fraud where fraudsters attempt to trick people into paying "administrative fees" supposedly needed to secure non-existent World Cup tickets or cash prizes.

"Prize draws and competitions offering tickets to the 2010 FIFA World Cup can only be held by companies who are commercially affiliated with FIFA, such as, for example, sponsors," it said.

FIFA also used the notice to issue a warning against ticket touts and unauthorised agents, a more standard message that has preceded every recent World Cup.

Spam emails touting 419-lite lottery scams themed around the World Cup are already in circulation (as recorded by Trend Micro here and
here). More can be expected to follow as excitement builds toward the start of the tournament next month.

Security watchers report that scam emails seen thus far have not been sent through botnet networks of compromised PCs but via direct spamming from known Nigeria-based 419 scam-friendly IP addresses.

Search engine manipulation, themed around events at the World Cup and designed to divert users searching for video clips and news towards scareware portals, is also likely to crop up, among other types of malware attack, especially once the tournament kicks off.

MessageLabs, Symantec’s hosted security division, has already begun intercepting World Cup-themed email-borne malware attacks. Infected email blocked by MessageLabs were sent from an IP address in Macau, China, and composed in Portuguese (targeting fans of Brazil and Portugal). The infected messages posed as emails from one of the event’s soft drink sponsors.

Football fans receiving the email were encouraged to download a hacking tool that posed as a football-themed application.

“Once downloaded and activated, the malware produces files that generate pop-up messages and in the background collects information on what other machines are on the same network, enabling the attacker further access to the compromised networks,” explained Paul Wood, MessageLabs Intelligence senior analyst.

Symantec has set up a dedicated website that aims to track and warn football fans about net threats connected with the World Cup, as they arise. 2010NetThreat will also feature security advice, competitions and news on the tournament itself. ®

The original article is on The Register

Popularity: 11% [?]

Post to Twitter

Barracuda Web Site Firewall Garners SC Magazine Best Buy!

0 comments

Posted on by admin in Network Security |Web Site Firewall

, , , , ,

From SC Magazine:

The Web Site Firewall Model 460 is an application protection firewall, which resides on a single appliance device. The tool recognizes attacks by monitoring network traffic to and from the web server. The default configuration for the device is to run in bridge mode, but it can also be installed in a routed mode. Bridge mode allows the device to inspect traffic bi-directionally to the web server without the use of an IP address. The routed mode is similar to a traditional network configuration, whereby a separate IP address is installed on each interface of the website firewall. This configuration can cause a few problems, which the bridge avoids.

For example, the 460 becomes an inline device, which can cause a central point of failure. For this type of deployment, we recommend using the 460′s redundant configuration. In the default mode, the tool does not stop network traffic if the unit fails. However, all traffic to and from the website would be blocked in the routed mode. The routed configuration is what is known as a “fail secure” configuration. This means that if the Web Site Firewall Model 460 does not explicitly permit the traffic, it will be dropped. The logging on the tool is performed via the syslog protocol. Several different types of events can be configured to send traffic to the syslog server.

As an integrator of many types of systems, the Web Site Firewall Model 460 in bridge mode has “goes in to” and “goes out of” ports. The installation and configuration are as simple as it comes. The entire installation and configuration guide takes up only a single piece of paper. Additional documentation covers the routing installation method, as well as very detailed explanations of the events which triggered alerts.

Support is offered through phone, email and a website. Email support is available 24/7 for all customers, and additional support is available for a higher fee. Barracuda also provides a website with a knowledge base, FAQ and live chat options for support.

The Barracuda offering is priced at $8,999 with no “per user” fees on top of that price. This puts the cost of the device at the lower end of the spectrum.

..end of SC Magazine story. To see the original article, visit SC Magazine.

Pricing and Availability

The Barracuda Web Site Firewall is available in three models: Barracuda Web Site Firewall 360, 460 and 660. U.S. pricing starts at $4,999. International pricing and availability varies based on region. For more information, please visit http://www.barracudanetworks.ca/website-firewall.aspx.

About the Barracuda Web Site Firewall

The Barracuda Web Site Firewall is a complete and powerful security solution for Web applications and Web sites.

The Barracuda Web Site Firewall provides award-winning protection against hackers leveraging protocol or application vulnerabilities to instigate data theft, denial of service or defacement of your Web site.

Many applications are vulnerable to such attacks because application developers do not consistently employ secure coding practices. Barracuda Web Site Firewall is designed to combat all attack types that have been categorized as significant threats, including:

  • Cross Site Scripting (XSS)
  • SQL injection flaws
  • OS command injections
  • Site reconnaissance
  • Session hijacking
  • Application denial of service
  • Malicious probes/crawlers
  • Cookie/session tampering
  • Path traversal
  • Information leakage

To learn more about the Barracuda Web Site Firewall, see the product information pages on BarracudNetworks.ca.

Popularity: 46% [?]

Post to Twitter