Internet Safety Part Five- Phishing

Here’s another highly important rule which all internet users need to know.

NEVER CLICK ON A LINK IN ANY EMAIL SENT TO YOU.

Once you have memorised this rule, make sure you clue your family and friends in on it as well. This rule can save you serious money as well as heartache.

Why is it so important?

There’s bad people out there in the world who would like to get things from you and one way they can achieve this is by getting *you* to give them your username, login, and credit card information.

How do they do it?

They try to fool you. They send you emails from ebay, paypal, all kinds of banks, credit card companies, internet service providers (AOL has been a target for this since the early 90’s) as well as many other companies which tell you that you need to log in to do something – they might say your account has been compromised or that you need to log in to confirm your details or a truckload of other things. There’s so many variables on this that they can use, and they are working 24/7 to make their emails more believable so that more people fall for them.

What they are hoping is that you have an account with that company, and that you will panic and click on the link in the email. When you do, it takes you to a website the scammers have set up, not the actual website of the company you think sent you the email. Some of these can be so realistic that even people who *work* for that company cannot tell the difference between the real website and the fake one.

So how do I make sure I don’t fall for them?

If you follow the rule of never click on a link in your email you’ve got a very good chance of making sure you don’t fall for them. If you have an account with any company you receive an email from and you get one of these emails, type the URL of the company into your location bar yourself, and log in to the REAL website instead of their fake website.

NOTE – Just clicking on the link can install nasty software on your computer. So again, NEVER click on a link sent to your email, even if you think it is from friends or family!

What happens to the information people enter onto one of these fake sites?

Generally it is saved to a text file which is online at the website they have put up, every time someone submits information the text file is updated. From time to time, the victim support groups that I volunteer with are given text files from web hosts and legal authorities who have shut down these phishing sites and we are asked to pick through the text and warn the victims. I’ll tell you, this is a nightmare job and very time consuming. The text files are full of peoples personal information, from names, addresses, email addresses, passwords, credit card numbers.. and you would be surprised how many people get caught by this.

More on phishing and other scams can be found here – http://www.fraudwatchers.org and there is an excellent wikipedia on this topic here – http://en.wikipedia.org/wiki/Phishing – Also google is your friend. ;)

email safety, Internet Safety

Internet Safety Part 4 – Use BCC

From yesterday’s post, Em had a question –

What is your opinion of spam filters. My gmail one seems to work quite well and the spam doesn’t bother me because I don’t see it…

I’ve got about 40 gmail accounts actually. ;) Being a scambaiter, you tend to have a lot of email addresses. The spam stuff, like viagra and cialis and people trying to sell you stuff, gmail does reasonably well with. However, they do NOT do as well with the *scam* emails, and also phishing gets through on a regular basis.

You might not be getting much in the way of spam as yet, but if you have an email address which is anywhere out there on the internet, it will be coming to you as a surprise some time in the future. WHich leads me to an important point – *always* protect your email address by writing it like this – emailme at email dot com – mine you can see in the sidebar and it looks like this –

snoskred {at} gmail {dot} com

Here’s a screenshot from one of my email accounts which is on a scam blog. The people emailing it do not know it is on a scam blog because they use an email extractor program to get the addresses.

scamspam

The emails you see there arrived over the space of less than an hour. That account regularly receives around 40 emails per hour. That’s 960 emails a day. Can you imagine how this would mess up your inbox? ;)

For most people, a single gmail account with a spam filter might work just fine – until someone gives out your email address somewhere. It’ll start out being 3-4 spam emails a day, and keep going upwards until you want to throw things at people you’re getting so much of it. If you have one email account which you use for everything, it’s a real nightmare when that happens. And you would be surprised at whom is doing what with your email address as we speak.

I’ve done a lot of email warnings to scam victims over the years, and many times some of these people have decided I am their friend and added me to their forwards list. They then send me any “joke” or “inspirational” email that they stumble across during their interweb travels. The trouble is, they add all the email addresses as “cc” – carbon copy, which means me and everyone else who got the mail can see who it was sent to! That means, if a scammer or spammer gets their hands on it, they have a bunch of new targets to email.

So there’s the lesson for today – use BCC when you want to email to more than one person. *Blind* carbon copy – it means nobody else can see who you sent that mail to.

The reason I am suggesting the email plan rather than just one gmail account is because if you break it down into groups it is much less of a hassle when that account is compromised. I say when because it is highly likely to happen. :( Spam and Scam is getting worse, and there really isn’t much that can be done to stop it, so it is much better to be prepared. ;)

I hope that answers the question. :)

email safety, internet, Internet Safety, scams, spam, www safety

Part Three – The IP address.

I’m not going to get all technical on you. I’ll try to keep this as simple as possible. It’s not really a huge deal but it’s good info to know.

As you cruise around the internet, you are giving some basic information to the sites that you visit. Generally, it is stuff that will not identify you personally in any way, like what kind of web browser you use, what kind of operating system your computer runs. However, there is one thing that you can be “traced” by – your IP address.

When you connect to the internet, you login with your username and password (you may not do this manually anymore, but it still happens) and then your internet service provider (ISP) gives you an IP number from their pool of numbers.

So realistically the closest anyone can get to you personally is to know what ISP you are using, and which state/country that ISP is in. Each time you send an email, your IP address goes out with that email, which makes you traceable back to your ISP. When you post on a forum, the forum logs your IP address.

For most this is a reasonable level of security. If you did something wrong, the police could ask your ISP for your details, I’m no legal expert but they’d need some kind of court order as far as I know. ISPs have to keep logs of who is using what IP address when, so you can be identified later on. Otherwise, that information is supposed to remain strictly confidential. People who work for the company could probably out who you are, but that would be about it.

For a scambaiter like me, it’s not really enough given that the people I’m emailing are criminals, and I don’t know anyone personally at my ISP – so who knows how safe my real info is? But thankfully free email providers like gmail and fastmail *hide* your IP address for you. Which is yet another reason I recommend gmail – if it’s secure enough for me, it’s secure enough for anyone. ;)

Do you want to see your IP address? Click here. It may also give you a location, and the location might be close or it might be way off. ;)

I guess the important thing to remember is, people can be traced if they do enough wrong to get the police interested and a court order issued. It’s good to keep that in mind.

email safety, Internet Safety

Part Two – The Email Plan.

Email is important.

In this day and age, it is one major way that we keep in touch with each other. If you have never received a spam or scam email, you are extremely lucky. Imagine trying to wade through hundreds of spam trying to find the important emails you need to read. It happens every day to people who aren’t expecting it. Here’s a screenshot from one of my now abandoned email accounts –

spam

So what do you do when you are bombarded with spam? You don’t really have much choice but to open a new email account and start again. It’s very frustrating and extremely annoying not to mention time consuming. But spam is only an annoyance. Scam can lose you money, and there’s so many of them on the internet it is virtually impossible to keep up to date on the latest scams which are out there.

Why have an email plan? Because if you only have one email account, and that gets bombarded with spam and scam mails, it can be a real pain in the rear. So how does it work? It will seem complicated but it is actually very simple.

Basically you make one central gmail account. Let’s call it Snoskred1, for example. This email address is NEVER given to anyone. Nobody. Not even your closest family. Why? Because you can’t trust them. Trust me on that. ;)

Then you make an email account that you use for signing up for things on the internet. Let’s call it Snoskred2. It’s handy to have all that in one place for many reasons. You can’t trust any place on the internet to keep your email address to themselves because they earn money for selling email addresses and it is impossible to know which places will do that, and which places won’t, so it is easier just to treat them all as if they’re going to sell your email address.

However, you *can* trace how people got your email address by using another great gmail trick. There is a feature in GMail where you can add a + to the address and it will get to your email address. So if you sign up to an internet forum, you can put the name of the forum into the actual email address itself, exactly like this – snoskred2+forumname@gmail.com – which means if you start to get spam on that email address, you then know where the spammers got your email address from. And it does work, I have tested it.

Gmail allows you to forward mail to another account, so you simply forward Snoskred2 to Snoskred1. *ALL* mail sent to Snoskred2 will be forwarded except for mail gmail thinks is spam – and most of the time gmail gets it right. It’s as easy as putting in an email address.

So then you make an email address which you give to friends and family. Let’s call it Snoskred3. But these are your friends and family, and surely they won’t give your email address to spammers and scammers, right? Wrong. How many times have you got a mail from them with FWD in the title? If you look closely at that mail, you’ll probably see a bunch of email addresses in the CC field.

There are companies on the internet which try to trick your friends and family into giving out your email address by giving them a free Ipod for every 10 email addresses of friends and family that they “refer” – though they never give them the Ipod. And if your friends and family sign up for a new service, they are offered the option to let others know about it by email, which puts your email address out there and at risk.

Again, you can use the gmail trick to trace which of your friends and family are giving out your email address – snoskred3+friendname@gmail.com – and if you start to get spam to that email address you’ll know, next time don’t give them your email address. ;)

Gmail allows you to forward mail to another account, so you simply forward Snoskred3 to Snoskred1. *ALL* mail sent to Snoskred3 will be forwarded except for mail gmail thinks is spam – and most of the time gmail gets it right. It’s as easy as putting in an email address.

So by now you’re probably starting to get the idea but you’re still not sure why we’re doing this? Because if snoskred3 gets bombarded with spam, you turn the forwarding to snoskred1 off, and then you’re back to a spam free email account. You can make a new snoskred3 account which you personally give to the friends and family who didn’t give your address to scammers, forward that one to snoskred1, and once a week or so manually log in to check the old snoskred3 account to make sure you aren’t missing any important mail.

I recommend having two more email accounts, one for official stuff, one for work colleagues and acquaintances, but it’s up to you.

Confused yet? I hope not. ;) I’ll post this and you can let me know if you found it too confusing, I’ll try again. ;) But also have a look at this chart, and if you understand that you can turn any of the pink arrows off anytime you like then this post may make more sense. ;)

emailplan

email safety, Internet Safety

Internet Safety Part One.

Em from Three Times Three had a little scare the other day, and it’s inspired me to write some blogs on internet security. I thought rather than trying to cover everything in one day, I’d do a week’s worth – your basic guide to keeping safe on the internet. So to start with, a little info about me and how I know anything at all about internet safety.

I’ve been on the Internet since 1992, in fact before the internet was as you know it. When I first got onto the net, I knew a girl who was “stalked” before stalking became popular. She made the mistake of using her real full name on a bulletin board. A guy took her real full name and found out where she lived, and turned up on her doorstep. Lucky for her nothing serious happened because of it, but it taught me right from the word go, the most important rule of being on the internet.

NEVER EVER USE YOUR REAL LAST NAME.

This is majorly important. You can be traced, even if you do not have your last name listed in the phone book. There are many ways it can be done and there are even companies on the internet who sell information about people, especially in the USA.

I started out using my first name and a made up last name. As time went on, I decided that even though my first name was the same as millions of other people, if I am going to use an alias on the internet I might as well choose another first name. After all, your parents choose that for you and nobody is ever really happy with it, so why not use the first name you’ve always longed to have?

There’s some other really basic important rules which I follow, so let’s cover them off right away.

1. Don’t give out any information about yourself on the internet. This includes phone number, address, shoe size, bank account details, social security number, passport information, car registration, anything which could be traced back to you or could be used to “steal” your identity.

2. Passwords are majorly important. Use lots of them. Write them down in a book.

If you use one password for everything, and your password is stolen, whoever stole it now has access to everything you signed up for on the internet. How often do passwords get stolen? A fair bit actually. There are scammers on the internet who “phish” for passwords. Many internet cafes have programs running on them which send your password to criminals. Have you ever used an internet cafe to check your email?

Not only that, but most people on the internet *join* things like forums, websites, blogs, all kinds of things. You don’t always know who has access to the information you put in when you register on a forum. For example, phpbb is one popular type of internet forum. It is also full of security holes and many such forums show your passwords to the *owner* of the forums. If you use the same password for a forum as you do for your email which you signed up with, you’ve just given someone the password to your email account.

Whoa, right? Yeah I bet you never thought of that. So how to fix it? Step one is change the password to your main email account ASAP, to something you haven’t used anywhere before. Step two is a bit more painful – the changing of *all* your passwords on forums and websites, and your blog, etc. Just take them one at a time.

3. Don’t use your internet service provider email account on the internet. There are plenty of free email providers, make use of those. Have one password for your ISP account and DO NOT DO NOT DO NOT EVER use that password for anything else on the internet.

This one is a biggie for me. Your ISP email account – ISP is how you connect to the internet, so it will end with the name of the company you are accessing the internet through, eg @bigpond.net.au @aol.com, should be given out rarely and never used as a contact email address for you on the internet.

Why?

This account identifies YOU to your internet company. Your internet company knows your real name, address and more than likely your billing information. There’s a lot of reasons why it isn’t a good idea to use it. I could go into them. The stories are long. So if you really want to know say so in the comments, I’ll blog it on its own.

So what email address should you be using on the internet? I think the best idea is to use several Gmail accounts. The reason I say that is, gmail allows you to forward to other email accounts for free. So I have a plan of how to use the accounts, which I will blog tomorrow, but here’s a sneak preview, a map.

emailplan

The reason for using so many accounts is, if one of them is compromised in some way (say one of your friends is silly enough to send out a forward with your email address along with 200 of her closest friends which means spammers get the email address) then you can shut the forward off for that one and make a new one. It does work, and if you’ve ever had spam coming to you at the rate of 10 per hour you can see the benefits of doing this. Especially if it is all viagra or enlarging the size of something you don’t have because you’re a woman. ;)

5. When making an email account, always expect the spanish inquisition. Or, expect spam. The way a lot of internet spammers work is, they use a “dictionary attack” – which means they send email to every word that is found in the dictionary, and every surname found in the telephone book, and every first name they can think of. You can outwit them simply by making your account two things – not a person, place or thing, and using numbers. I like words spelt backwards – sdrawkcab760 would be a great username.

Of course, doing the above will do you no good if you go and put sdrawkcab760@gmail.com as the contact me email address on your blog. Why? Because the spammers have access to email extractors which grab email addresses from the internet. But you want people to be able to email you, right? This is where my email plan (seen above) can really be of benefit.

That’s just the tip of the iceberg. It may have been a little overwhelming, but your security is important. More to follow in the days ahead, so keep checking back. ;) And if you have any questions or specific concerns or need me to explain something more clearly, you can email me or put it in the comments, and I will address it.

Here’s to staying safe on the internet ;)

email safety, Internet Safety

Scammer fun..

I’ve been really busy the last couple of weeks. A small group of baiters is trying to clean the scammer blacklist of dead email accounts, which means sending emails to them. We decided to combine this with gaining intelligence which is all being forwarded to the police. I can’t really get into detail there.

——————————

(Update 10 January 2015) –

It has been 8 years since I wrote this and enough time has gone by that I can tell you what we did.

We sent out what we like to call an ASEM – an accidentally sent email. In this email, we advise that went to the bank today to make a very large bank transfer – in the millions -to their bank account, however the account details they sent us were incorrect, and could they please send us the correct bank account details to make the transfer.

A lot of them came back asking for the money to be sent via Western Union. The email addresses of these lads were collated together and they were sent a second email saying “Have you lost your mind? We have already been through this and Western Union refused to send this large a sum. The money is sitting in my account ready to send. You can either send correct bank account details, or forget the deal, I’m done with you.”

As a result of these emails, a large amount of bank account details was passed on to a contact we had in law enforcement. Many of the accounts were eventually frozen and the funds seized. Any accounts that looked like they belonged to a scam victim, law enforcement investigated the account to see if any other scam transactions took place via it and also warned the owners of the accounts re these scams.

———–

I have been talking to a lot of scammers on my skype in over the last week, and the pick of the crop calls have been uploaded to scambaits for the general amusement of all. When I get a chance I’ll add some links to the calls here. They all contain a lot of language.. ;)

So in the meantime, I leave you with another T.A.T.U. song which has been in my head lately.. the lyric that stands out in this one is –

You shut your mouth how can you say I go about things the wrong way?

scambaiting

The Idiocy

You know what I love?

When someone pretends to be all nice to you to your face, and says all the right things, you think they are a friend of yours.. and then you find out the real truth about what they say about you when you’re not around.

I think most scambaiters would tell you this. Don’t take on Snoskred head to head, because you will lose. Especially if you’re not smart with computers. She’s not smart with computers either, not for the most part, but she has a “group of one” as her partner that IS smart with computers.

But me, and my “group of seven”, are not going to roll over, so why don’t you just quit while you’re ahead? Because we’re miles ahead of you. ;) We’ll leave you alone as long as you don’t fuck with us. Fuck with us? You’re fucked before you even start.

This is actually so freaking hilarious and completely sarcastic and ironic, to those who aren’t baiters reading this. There is no group of seven. A sad old man in Queensland who has mental issues and a grudge against some people who run two different websites which (wisely, it turns out) kicked and banned him from their boards, has been going around making threats and saying stupid things. One of the things he said was that there was this group of seven, and he liked to tell people I was one of the group of seven!

Well, I’m not. I was nice to him, a couple of times. I helped him out with a technical thing. When he had run ins with people, I simply gave him some advice when I thought he could use it – as in, stop holding this grudge. It’s no good for you, and it’s no good for them. Why not use your energy more usefully? Build a bridge. Do some work. Learn how to use some of the stuff we have. In fact learn how to use your computer, and stop freaking out and thinking people are hacking into yours all the time. They’re not. They have no interest in your computer, or you. They just want you to stop harassing them.

So back in December, he was going on holidays and he *swore* to me before he left that when he came back, he would have built the bridge, and he wouldn’t be holding the grudge anymore, and he’d be ready to help with some serious work. I’m not kidding, I have a lot of stuff on my plate that needs doing, and I’ll take any help I can get, even if it is someone who doesn’t know how to cut and paste or use a computer, though they’ll have to work that out to do most of the stuff I have that needs doing. Of course, no help came to me as a surprise. What did come to me as a surprise was the news, received just a few days ago, that the little old man was actually still harassing the people he had a grudge with.

So I have a little message for that little old man. Get help. You need it. I’m serious. And keep me out of your conspiracies, because I’ve got serious stuff that needs doing, and I don’t need to waste time on your insane bullshit. Ok? And it’s real adult behaviour to kick someone off your skype contacts. You’re an old man, act like a mature adult, would ya?

In closing, for anyone wondering if the group of seven exists, get it right here from the horse’s mouth – or from my skype chat history.

Little Old Man: 00:12:27 : first part true second as i have said the group of seven do not exist so the second part is false

And here ends the myth of the group of seven. Okie dokie then?

What serious stuff am I doing? At the moment I am baiting over 1,000 love scammers. When they send me a picture, I put it here along with the email they sent. I’m hoping I can put a list of love scammer telephone numbers there, too. In the hope that victims might google that kind of thing and find out it is a scam before they pay any money. Yes little old man, I could have used your help with this. But not now, because now I wouldn’t allow you to cut and paste anything, anywhere. So I’ll have to do it all myself though Sephy will help me, and I have ooh gosh, 814 unread love scam emails which I have to try and go through to drag out the info I need. And that’s not all, not by a long shot.

Annoyed Snoskred, people talking about you, scambaiting

A busy few days

It’s been like a call centre here, with scammers calling like there’s no tomorrow. I organised a few redirection numbers, actually 20 numbers which the lads can call, and it rings my skype in. And I have to be nice to them, which is really difficult for me!

On top of that, I have been really busy working on stuff for the baiting tool, which is now much improved.

So I have not had much time for blogging, or for watching the West Wing. :( Or painting, which I need to do more of soon, just to keep the sanity.

scambaiting

Fraudstars

This just in from a scammer –

SIR,

YOU ARE REQUESTED TO IGNORE THE MAIL.

IT IS CERTAINLY FROM FRAUDSTARS

YOUR NAME AND INFORMATION APPEARED ON THE FEDERAL GOVERNMENT OF NIGERIA APPROVED PAYMENT LIST. KINDLY RE-CONFIRM YOUR NAME, ADDRESS, PHONE – FAX NUMBERS. YOU ARE TO RECEIVE THE SUM USD16M IMMEDIATELY. KINDLY SEND YOUR BANK ACCOUNT WHERE YOU INTEND TO RECEIVE THE FUND TO ENABLE US PROCESS THE PAYMENT.

YOURS FAITHFULLY,

DR. SOLOMON

The scammers love to call everyone else a fraudstar, except themselves. That’s why I got the domain name I did and now have a site at the domain I got.

In other news, I am starting a few new paintings, and just started season 3 of WW, yeah that was fast! :)

scambaiting

Sleepless

It’s 1:30am and my mind is wide awake. The other half went to bed quite a while ago now, and I don’t want to go in and read till I’m tired because it will wake him up. Much of this post won’t make a lot of sense. It’s ok, I just need to get it out.

I’ve made many mistakes in my life, but the one that keeps annoying me today is why did I place my faith in other people when I should probably have struck out on my own and created what I wanted to create, especially when those other people suddenly decided they didn’t want me to be involved in things to the same extent I originally was.

Those people let me down and yet, I continue to support them. Those people say nasty things about me when they think nobody else is looking. Well, people are looking and whether you like it or not, they have no good reasons to treat me badly, so they let me know what is said. And I don’t say anything, and I probably should, but I figure for the good of everyone, it’s better just to let them talk and try to show them by my actions that I am not the person they think I am.

I know this – I have done a lot of good things. I don’t talk trash behind peoples backs – if I am going to say something about you I say it to you. Maybe I should have done what everyone was urging me to do – create my own empire, make my own site, do my own thing, but that would have taken the focus away from what is really important, and it would have meant a lot of the work I have put into things would have to have been put into creating the empire, and realistically that would have been a waste of my time and energy.

People think I’m holding grudges, but I don’t. I’ve put the past behind me, well behind me – they are the ones with the chips on their shoulder and no real desire to remove them. I was told to build a bridge, and I did. And let’s face it, someone who said some very nasty things about me, and continues to do so from what I am told, recently I put a fair bit of effort in to doing something nice for them – for the good of the bigger picture.

People ask me why, when I was treated so badly by certain people, I continue to stick around. It’s a good question and one I find myself asking myself today. I have a little piece of paper on my desk. You might have seen it in the doll pictures. Maybe you can’t make out what it says, but it is the answer, and that is why it sits there on my desk, right in front of me, day after day.

desk1

It’s entirely true. What it says is – sometimes taking the high road is no fun at all.

It hasn’t been fun. I’ll be honest with you. I don’t enjoy the way certain people treat me. But the good things that have come from me taking that high road are very worthwhile and one day, maybe, those people who have been so unpleasant will come around and see my actual actions instead of making sh*t up. They’ll look and see and maybe they will eventually think – damn, she did that, even while we were talking crap about her? Even when we kicked her in the teeth, and then kept kicking her in the teeth, over and over till most of her teeth were missing? What would I have done in her shoes? Would I have stuck around? Would I have stuck it out? No f*cking way. I’d have resigned publicly, made a huge fuss, gone off and made my own site, and split the community even further from what it already was.

Right now today, I am truly wondering if this has been worth it, when people won’t let go of the past, and they still seem to think kicking me in the teeth is a great idea. And maybe what I should do is exactly what *they* would have done in my place – resign publicly, cause a huge fuss, go off and make my own site, and split the community. But I can’t do that, not because I can’t go make my own site, I have in house technical support and my own server is finally back online etc, but because I believe the community is split enough already, and further fractures will only do more harm.

It’s time. People need to stop trying to hurt each other, and remember why they are involved in any of this at all.

Today I did go make my own site. It’s actually for all my stuff, because now my server is back online I’ve managed to get things into one place, and some kind of order. It’s got all my scambaiting audios there in one place, well a lot of them anyway. I’m going to get back into doing more of that stuff soon.

mistakes I made, moving forward, moving on, people talking about you, scambaiting, taking the high road