Showing posts with label computer fraud. Show all posts
Showing posts with label computer fraud. Show all posts

03 June 2010

Some useful e-mail utilities

Someone sends me a "crime report" of crimes that have taken place in our neighbourhood. I've thought of saving these in a database that would make it easier to refer to them -- to see if a car registration on a vehicle behaving suspiciously has been recorded as being involved in crimes elsewhere, for example. But what deters me is all the extraneous headers in the e-mails. All I want is the to, from and date lines, and not all the routing information and spam checks and the like.

And suddenly someone has pointed me to a utility that does just that, for Pegasus e-mail, the mail-reading program I use. And lots of other useful utilities too.

LEXACORP - Information Systems Development : Papua New Guinea:
Note that none of these utilities has a 'Setup' or 'Uninstall' procedure. They do not write to the Registry and do not put DLLs etc in other directories. To remove any of these utilities from your system just delete them.


I notice that Windows 7 doesn't have a built-in e-mail system. This is an improvement, since it gives the user a choice of what e-mail program to use, and I use and recommend Pegasus, partly because in its default setup it is immune to a lot of the spam and malicious e-mails that seem to go around.

Pegasus Mail:
Welcome to the North American Web Site for Pegasus Mail, the Internet's longest-serving PC e-mail system, and for the Mercury Mail Transport System, our comprehensive range of Internet Mail Server products. Pegasus Mail is a free product, dedicated to serving all who need it, while Mercury is a modestly-priced commercial system.

I suppose I am a bit old-fashioned about e-mail: I think e-mail is e-mail and web pages are web pages, and that HTML codes should be kept out of e-mail, and reserved for web pages. Using HTML in e-mails is wasteful of bandwidth and disk space. A two-line message in plain text can take 200 lines or more in HTML, yet the content is exactly the same. So I don't like HTML in e-mails, and Pegasus lets me send and read message in plain text.

Pegasus also, by default, blocks "lazy html". That is, HTML codes that refer to an external web site and not something in the message itself. It is something most often used by spammers, scammers and distributors of malicious software, designed for more tolerant and less protective mail readers like Outlook and Outlook Express. Pegasus by default blocks them and displays a warning, and anything in the message that refers to a remote site is displayed as a blank grey block. Sometimes such a message will display something like "Your mail reader cannot display this message" and tells me what hoops I need to jump through to read it. But such messages are almost invariably unsolicited spam anyway, which I don't want to read.

I prefer that if people want me to look at a web page, they describe it and give the URL. Then I can decide if I want go there or not. Pegasus displays the URLs in clickable form, so you click on them and it calls your web browser. But it also displays the real address at the bottom of the screen, both for e-mail and web addresses. That is useful for exposing phishing expeditions. When you are asked to send details of your bank account to an address like:

accounts@absabank.co.za

amd Pegasus displays it as

xyz@yahoo.com

you know something phishy is going on.

11 February 2009

Hotmail hacked?

A couple of days ago I got an e-mail purporting to come from an acquaintance.

It read:

How are you doing?hope all is well with you and family,I am sorry I didn't inform you about my traveling to England for a Seminar..

I need a favor from you because I misplaced my wallet on my way to the hotel where my money,and other valuable things were kept I will like you to assist me with a soft loan urgently with the sum of $2,500 US Dollars to sort-out my hotel bills and get myself back home.

I will appreciate whatever you can afford and i'll pay you back as soon as I return,Kindly let me know if you can be of help? so that I can send you the Details to use when sending the money through western union.

The style gave the game away, of course. It was written in the same style as most scam mail, and I could not imagine the real author writing like that.

What concerns me, however, is that it apparently came from the real address of the person concerned, and that the scammer was confident of being able to read any replies addressed to the real address.

My experience with Hotmail has been that it is very unreliable compared with, say, Gmail. Mail sent to my Hotmail account at hayesmstw@hotmail.com usually bounces, and I can no longer even get in to read it, so Hotmail is pretty useless.

But if it can be cracked like this it's even worse than I thought.

So if you have a Hotmail account, be careful, and if you receive e-mails from friends with Hotmail accounts, be extra careful, especially if they ask you for money.

06 February 2008

Crime-fighting organisation using criminal methods?

There is a crime-fighting outfit called eBlockwatch which has a web site and sends out warnings of criminal activity in one's neighbourhood.

It seems, on the surface, to be a good and public-spirited thing to do.

The only problem I have with it is that emails that come from them produce more warnings of fraudulent activity and threats to my computer than anything else. Even messages from obvious scammers and spammers don't produce as many warnings.

So I ask myself why an ostensibly crime-fighting outfit would persist in using methods used by scammers and distributors of viruses and malware?

The latest message I got from them produced the following warning:
MailScanner has detected a possible fraud attempt from
"www.eblockwatch.co.za" claiming to be SAFindit.co.za
And every message from them causes the following message to pop up in my reader:
Message contains potentially dangerous "Lazy HTML" data

This message contains data that includes references to items that are not present on your computer -- typically graphics or frames stored on a remote system on the Internet and accessed using HTTP URLs.

This type of message, called "Lazy HTML" can represent a privacy or security risk, for the following reasons:

* It can be used to gain information about you without your knowledge, including the fact that you read the message, when you read it, how often you read it, whether or not you forwarded it, your computer's IP address and more.

*It can be used to download unauthorised programs to your computer. This is a common vector of attack for viruses and Trojan horses.

Pegasus Mail protects you *completely* from any problems associated with this kind of data, because it never downloads remote-linked items by default. A side-effect of this is that that remote-linked graphics in the message will display as grey boxes in the Pegasus Mail message reader.

I suppose I could always turn that warning off, but the warning is there for a purpose, and I still wonder why a supposed crime-fighting organisation persists in sending messages that trigger such a warning in the first place. It seems counter-productive, and makes one doubt their bona fides.








MailScanner has detected a possible fraud attempt from "www.eblockwatch.co.za" claiming to be SAFindit.co.za

LinkWithin

Related Posts with Thumbnails