Avast WEBforum

Other => Viruses and worms => Topic started by: Omar on June 10, 2005, 05:29:25 PM

Title: michael jackson virus outbreak!
Post by: Omar on June 10, 2005, 05:29:25 PM
http://news.bbc.co.uk/1/hi/technology/4080786.stm
Title: Re: michael jackson virus outbreak!
Post by: RejZoR on June 10, 2005, 05:52:31 PM
And people are dumb enough to click the links over and over again ::)
Title: Re: michael jackson virus outbreak!
Post by: Omar on June 10, 2005, 06:20:28 PM
the above link, is quite safe! THAT LINK CONTAINS NO VIRUS!
Title: Re: michael jackson virus outbreak!
Post by: RejZoR on June 10, 2005, 07:30:54 PM
I know, i'm refering to links/attachements in such mails...
Title: Re: michael jackson virus outbreak!
Post by: polonus on June 10, 2005, 09:45:52 PM
Hello RejZoR,

Yes my friend, this is called "social engineering". People that fall for these tricks must read Kevin Mitnick's book "The Art of Deception". I have the polish version "Sztuka Podstepu". Fiction, but very believable fiction indeed. A must-read for every sys-admin.

pozdrawiam,

polonus
Title: Re: michael jackson virus outbreak!
Post by: RejZoR on June 11, 2005, 10:17:12 AM
I learned about it by myself. No need to read books.
All you need is some logical thinking. Also it's a lot easier for non US users, because we don't recieve that much mails in english(except maybe me hehe). But if you actually think what you're about to click, it doesn't matter what language is used in mail.
It's actually not that hard to fool users. Just make an attractive mail(like osama bin laden or m. jackson lately), attach malware file that uses icon of faked file with lot's of whitespace sequence in name and distribute it. People will click it for sure. People are too naive.
Title: Re: michael jackson virus outbreak!
Post by: kamulko on June 11, 2005, 11:33:21 AM
The risk is high also for the intranet users, employed of great companies, universities or government departments. I see every day many colleagues "fished" by emails with authentic addresses (like the real email address of a colleague). When you receive a email by your Director and you must execute quickly a work, in the most of cases you "click" the link and your mind (after over 100 emails in the day) is not a perfect watchdog ;D. Unfortunately in many cases people don't deactivate the html option.