On CBS MoneyWatch: 6 things NOT to do on Twitter, Facebook
BNET Business Network:
BNET
TechRepublic
ZDNet

December 12th, 2006

Online email accounts held hostage for blackmail

Posted by George Ou @ 10:30 pm

Categories: Browsers, Mobile/Wireless, Security

Tags:

Websense is reporting that a new form of cyber-extortion has emerged in recent days that exploits the promiscuous nature of cyber-cafes and PC-terminals.  By stealing email credentials from unsuspecting shared-terminal users, the attackers steal all the victim's emails and contacts and then sends a single message in the email account basically asking for ransom in a note written in Spanish.  The ransom note translates to "If you want to know where your contacts and your emails are then pay us or if you prefer to lose everything then don't write soon!"

This sort of attack illustrates the dangerous using browser based applications even when SSL is properly implemented because of the effectiveness of key-loggers.  Many browser based remote access solutions (referred to as a form of SSLVPN) attempt to scan for the existence of key-loggers, rootkits, and malware though this can only detect known threats with known signatures.  Other more clever implementations will attempt to use an OTP (One Time Password) sent to the user via text message on their cell phones so that a stolen password is worthless within a minute.

While these security measures reduce the risks, the danger of the untrusted PC-terminal remains.  Ultimately there is nothing to prevent a PC-terminal from recording the entire screen session if the attacker is determined.  Users and IT departments need to ultimately weigh the convenience of not having to carry a personal laptop or other personal digital communication device with the risk of using a public PC-terminal.

Even when using a personal laptop with public hotspots, be mindful of how easy it is to attack your user credentials with lack of or improperly implemented SSL.  Cyber criminals will only become more cunning and aggressive in the new digital age.

George Ou is Technical Director of ZDNet. See his full profile and disclosure of his industry affiliations.

  • Talkback
  • Most Recent of 33 Talkback(s)
Yes that happened at a time when people ignored the FreeBSD and Linux Wi-Fi
Yes that happened at a time when people ignored the FreeBSD and Linux Wi-Fi flaws that allowed ARBITRARY CODE EXECUTION using SSID Beacons and Probes. That news didn't get covered, something silly ab... (Read the rest)
Posted by: georgeou Posted on: 12/14/06 You are currently: a Guest | | Terms of Use
Though this doesn't follow my normal line of thought,  nucrash | 12/13/06
Even if they removed admin access, that doesn't stop user processes  georgeou | 12/13/06
I've already proposed this before  Scrat | 12/14/06
Nature of the hack  RestonTechAlec | 12/13/06
I mentioned wireless hacks  georgeou | 12/13/06
Explain the yahoo issue.  techboy_z | 12/13/06
I linked to the Banks not using proper SSL technology  georgeou | 12/13/06
SSL Improperly Implemented?  KTHernandez | 12/13/06
If you see HTTPS for the login and you don't get certificate warnings  georgeou | 12/13/06
Hotmail certificate warning  RestonTechAlec | 12/14/06
Insecure POP access  RestonTechAlec | 12/14/06
I wonder how they hold it for Ransom  voska | 12/13/06
If I were the attacker  nucrash | 12/13/06
there can be money involved in this  RIAAsucks | 12/13/06
Well then, screw the Ransom  nucrash | 12/13/06
The content might be more dangerous as blackmail  georgeou | 12/13/06
And that is why I am not a Criminal  nucrash | 12/14/06
Improper links  yyuko@... | 12/13/06
Try Google or Wikipedia  voska | 12/13/06
Sorry, wordpress problems  georgeou | 12/13/06
They'd be doing me a favour  NonZealot | 12/13/06
That's why  CobraA1 | 12/13/06
SOUNDS LIKE A JOB FOR LAW ENFORCEMENT  BALTHOR | 12/13/06
Sounds like a job for a live CD  TripleII | 12/13/06
Correction  TripleII | 12/13/06
Get a ?  Graham Fluet | 12/13/06
AaaaaK!!!  Graham Fluet | 12/13/06
But the real question is....  MGP2 | 12/13/06
I've never heard of an email provider restoring data, especially the "free"  georgeou | 12/14/06
Here's something to research  nucrash | 12/14/06
OT - MS "non-vulnerability" quitely patched  Richard Flude | 12/14/06
Link to original blog  Richard Flude | 12/14/06
Yes that happened at a time when people ignored the FreeBSD and Linux Wi-Fi  georgeou | 12/14/06

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

Click Here
advertisement

Recent Entries

Top Rated

    Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
    advertisement

    Archives

    ZDNet Blogs

    White Papers, Webcasts, and Downloads

    • Smart Tech Expert advice on innovations in healthcare and the green technologies that make it happen. Find out more
    • Smart Business Discussion and advice on management issues that revolve around making your world smarter and more useful. More Smart Advice
    • Smart People The best and worst moves in the management and strategy trenches. Learn More