31 July 2013 | 10:23

Online sharing helps hackers sharpen 'spears'

viewings icon comments icon

ПОДЕЛИТЬСЯ

whatsapp button telegram button facebook button
Photo courtesy of techbadi.com Photo courtesy of techbadi.com

Sharing on social media helps hackers sharpen "spear phishing" attacks they use to trick their way into computers, AFP reports citing security experts. Spear phishing refers to individualizing deceptive messages sent to people in order to trick them into clicking on links or opening files booby-trapped with viruses. Public posts on Twitter, Facebook, Instagram, Foursquare and other online venues give hackers fodder to mimic the way people write and the words they use, said Ulisses Albuquerque of the security firm Trustwave. "I don't think people have any idea what kind of insight that gives to a potential hacker," Albuquerque told AFP. He and colleague Joaquim Espinhara are at a premier Black Hat security conference in Las Vegas this week to present a talk titled "Using Online Activity As Digital Fingerprints To Create A Better Spear Phisher." The Trustware security consultants created a software tool that "fingerprints" the way people communicate by analyzing online posts. The tool scrutinizes posts at social networks such as Twitter, Facebook and LinkedIn to ascertain writing styles, right down to hashtags added to indicate subjects of online posts. A hacker unable to break into a company's computer network could write a convincing email pretending to be from a friend of an employee and include an attachment or link that, once clicked, unleashes malicious code. "Say a CEO has a Twitter or LinkedIn account and I am able to see those posts," Albuquerque said. "Then I could produce content that looks like it came from him and send it to his staff, who will be less suspicious of clicking a link." He said the Trustwave-developed tool was not designed to extrapolate insights into people's conduct or personalities, but that such observations could be made if desired. "Absolutely, you can show what the people posting are like," Albuquerque said. The tool provides "spear phishers" with outlines for creating messages likely to hook prey. It is intended for "ethical hackers" such as security professionals working with companies or organizations to find and patch weak spots in computer network defenses, according to Albuquerque. It can also be used to help prove when posts claiming to be written by someone are bogus, he said.

whatsapp button telegram button facebook button copyLink button
Иконка комментария блок соц сети
Sharing on social media helps hackers sharpen "spear phishing" attacks they use to trick their way into computers, AFP reports citing security experts. Spear phishing refers to individualizing deceptive messages sent to people in order to trick them into clicking on links or opening files booby-trapped with viruses. Public posts on Twitter, Facebook, Instagram, Foursquare and other online venues give hackers fodder to mimic the way people write and the words they use, said Ulisses Albuquerque of the security firm Trustwave. "I don't think people have any idea what kind of insight that gives to a potential hacker," Albuquerque told AFP. He and colleague Joaquim Espinhara are at a premier Black Hat security conference in Las Vegas this week to present a talk titled "Using Online Activity As Digital Fingerprints To Create A Better Spear Phisher." The Trustware security consultants created a software tool that "fingerprints" the way people communicate by analyzing online posts. The tool scrutinizes posts at social networks such as Twitter, Facebook and LinkedIn to ascertain writing styles, right down to hashtags added to indicate subjects of online posts. A hacker unable to break into a company's computer network could write a convincing email pretending to be from a friend of an employee and include an attachment or link that, once clicked, unleashes malicious code. "Say a CEO has a Twitter or LinkedIn account and I am able to see those posts," Albuquerque said. "Then I could produce content that looks like it came from him and send it to his staff, who will be less suspicious of clicking a link." He said the Trustwave-developed tool was not designed to extrapolate insights into people's conduct or personalities, but that such observations could be made if desired. "Absolutely, you can show what the people posting are like," Albuquerque said. The tool provides "spear phishers" with outlines for creating messages likely to hook prey. It is intended for "ethical hackers" such as security professionals working with companies or organizations to find and patch weak spots in computer network defenses, according to Albuquerque. It can also be used to help prove when posts claiming to be written by someone are bogus, he said.
Читайте также
Join Telegram Последние новости
The Moon is calling: New lunar mission
Wolf attacked man in Atyrau region
Euronews office opened in Astana
Earthquake recorded in Zhambyl region
Tokayev sent telegram to Qatar’s Emir
A New Year gift guide for her
Tokayev expressed condolences to Macron
Bitcoin exchange rate hit a new record
EU expanded sanctions against Belarus
Kazhydromet warned residents of Almaty
Лого TengriNews мобильная Лого TengriSport мобильная Лого TengriLife мобильная Лого TengriAuto мобильная Иконка меню мобильная
Иконка закрытия мобильного меню
Открыть TengriNews Открыть TengriLife Открыть TengriSport Открыть TengriTravel Открыть TengriGuide Открыть TengriEdu Открыть TengriAuto

Exchange Rates

 523.95  course up  543.16  course up  5.1  course up

 

Weather

 

Редакция Advertising
Социальные сети
Иконка Instagram footer Иконка Telegram footer Иконка Vkontakte footer Иконка Facebook footer Иконка Twitter footer Иконка Youtube footer Иконка TikTok footer Иконка WhatsApp footer