<?xml version="1.0" encoding="ASCII"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Secure by Design &#187; Security Alerts</title>
	<atom:link href="http://www.secure-by-design.com/category/security-alerts/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.secure-by-design.com</link>
	<description>Helping You Make Sense of the Internet.</description>
	<lastBuildDate>Wed, 21 Dec 2011 00:12:55 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>New Phishing Scam &#8211; New Secure Mail Regarding Your Net Idea Webmail.</title>
		<link>http://www.secure-by-design.com/2011/10/phishing-new-secure-mail-regarding/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=phishing-new-secure-mail-regarding</link>
		<comments>http://www.secure-by-design.com/2011/10/phishing-new-secure-mail-regarding/#comments</comments>
		<pubDate>Mon, 17 Oct 2011 23:22:07 +0000</pubDate>
		<dc:creator>Kirk</dc:creator>
				<category><![CDATA[Security Alerts]]></category>

		<guid isPermaLink="false">http://www.secure-by-design.com/?p=991</guid>
		<description><![CDATA[If you get an email that looks like the following, do not click on the link. There&#8217;s nothing wrong with our webmail, and we never need to email you and ask for your password. Our spam filter has been picking this up, so not many people will actually see it. Regards, Kirk From: Net Idea [...]]]></description>
			<content:encoded><![CDATA[<p>If you get an email that looks like the following, do not click on the link. There&#8217;s nothing wrong with our webmail, and we never need to email you and ask for your password. Our spam filter has been picking this up, so not many people will actually see it.</p>
<p>Regards,</p>
<p>Kirk</p>
<div style="background: #eee; border: 1px solid black; padding: 1em;width:90%;">
<div><strong>From: </strong>Net Idea Webmail Service &lt;<a href="mailto:online.service@netidea.com">online.service@netidea.com</a>&gt;</div>
<div><strong>Date: </strong>October 17, 2011 12:39:16 PM PDT</div>
<div><strong>To: </strong><a href="mailto:valhaljb@netidea.com">user@netidea.com</a></div>
<div><strong>Subject: </strong><strong>New Secure Mail Regarding Your Net Idea Webmail.</strong></div>
<p>You have 1 important mail alert!</p>
<p>We strongly advise you should update your account and resolve the problem.</p>
<p><a href="http://propzonenainital.com/cp/mail.netidea.com.htm">Click here</a> to proceed</p>
<p><strong>Failure to do this will lead to your account been suspended or de-activated.</strong></p>
<p>Thanks for your co-operation.</p>
<p>Yours Sincerely</p>
<p>Net Idea Webmail Service</p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.secure-by-design.com/2011/10/phishing-new-secure-mail-regarding/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New &#8216;MACDefender&#8217; Malware Threat for Mac OS X</title>
		<link>http://www.secure-by-design.com/2011/05/macdefender-malware-threat-mac-os/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=macdefender-malware-threat-mac-os</link>
		<comments>http://www.secure-by-design.com/2011/05/macdefender-malware-threat-mac-os/#comments</comments>
		<pubDate>Thu, 05 May 2011 20:24:00 +0000</pubDate>
		<dc:creator>Kirk</dc:creator>
				<category><![CDATA[Security Alerts]]></category>
		<category><![CDATA[MacOS]]></category>
		<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://www.secure-by-design.com/?p=888</guid>
		<description><![CDATA[There is a malware (malicious software) threat that can affect all Mac OS X systems.  ﻿Users running with Administrator level accounts with Safari set to open safe files automatically are particularly at risk.  This program pretends to be an AntiVirus program for Mac OS, but isn&#8217;t really.  If you see this on your screen, close [...]]]></description>
			<content:encoded><![CDATA[<p>There is a malware (malicious software) threat that can affect all Mac OS X systems.  ﻿Users running with Administrator level accounts with Safari set to open safe files automatically are particularly at risk.  This program pretends to be an AntiVirus program for Mac OS, but isn&#8217;t really.  If you see this on your screen, close it immediately:</p>
<div id="attachment_889" class="wp-caption aligncenter" style="width: 310px"><a rel="lightbox" href="http://www.secure-by-design.com/wp-content/uploads/macdefender.jpg"><img class="size-medium wp-image-889 " title="MacDefender Malware Screenshot" src="http://www.secure-by-design.com/wp-content/uploads/macdefender-300x212.jpg" alt="" width="300" height="212" /></a><p class="wp-caption-text">MacDefender Malware Screenshot</p></div>
<p>Those responsible for spreading the malware are exploiting users&#8217; interest in late breaking news about Bin Laden&#8217;s death, however, other avenues are possible.</p>
<p>For more information see the following bulletins:</p>
<p><a title="MacDefender Malware Article - macrumors.com" href="http://www.macrumors.com/2011/05/02/new-macdefender-malware-threat-for-mac-os-x/">http://www.macrumors.com/2011/05/02/new-macdefender-malware-threat-for-mac-os-x/</a></p>
<p><a title="MacDefender Info from SANS ISC" href="http://isc.sans.edu/diary.html?storyid=10813">http://isc.sans.edu/diary.html?storyid=10813</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.secure-by-design.com/2011/05/macdefender-malware-threat-mac-os/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Scam: Secure by Design / Account User&#8230;</title>
		<link>http://www.secure-by-design.com/2010/10/scam-secure-by-design-account-user/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=scam-secure-by-design-account-user</link>
		<comments>http://www.secure-by-design.com/2010/10/scam-secure-by-design-account-user/#comments</comments>
		<pubDate>Fri, 29 Oct 2010 22:31:11 +0000</pubDate>
		<dc:creator>Kirk</dc:creator>
				<category><![CDATA[Security Alerts]]></category>

		<guid isPermaLink="false">http://www.secure-by-design.com/?p=644</guid>
		<description><![CDATA[The following message is a phishing scam and should be deleted on sight.  Whoever it is is after your password, most likely to send out more of the same. From: &#8220;Secure by Design Service&#8221; &#60;dbricket@colby.edu&#62; Friday, October 29, 2010 2:36 PM Subject: Secure by Design / Account User Upgrading Exercise! Attn: Mail-Box User Quarantine Notification: This [...]]]></description>
			<content:encoded><![CDATA[<div>
<div><strong><br />
</strong></div>
<div><strong>The following message is a phishing scam and should be deleted on sight.  Whoever it is is after your password, most likely to send out more of the same.</strong></div>
<div><strong><br />
</strong></div>
<div>From: <span style="font-family: Consolas, Monaco, 'Courier New', Courier, monospace; line-height: 18px; font-size: 12px; white-space: pre;">&#8220;Secure by Design Service&#8221; &lt;<a class="linkification-ext" title="Linkification: mailto:dbricket@colby.edu" href="mailto:dbricket@colby.edu">dbricket@colby.edu</a>&gt;</span></div>
<div>Friday, October 29, 2010 2:36 PM</div>
<div>Subject: Secure by Design / Account User Upgrading  Exercise!</div>
</div>
<p>Attn: Mail-Box User Quarantine Notification:</p>
<p>This is to inform you that the <a href="http://www.netidea.com">www.netidea.com</a> Web Mail is migrating to a new  spam filtering service, which improves the ability to identify and block  spam,“phishing” attempts and other undesirable messages  that flood our  email system on a daily basis. and also a mail box user quarantine exercise is  currently going on. we are carrying out a (inactive email-accounts / spam  protecting) clean-up process to enable service upgrade efficiency.</p>
<p>Please be informed that  we  will delete all mailbox account user  that do not adhere to this notice. You are to provide your email account details  as requested by <span style="text-decoration: underline;">Clicking Here</span> for  Quarantine exercise and  protection against spam and for secure  upgrading.<br />
This will confirm your <a href="http://www.netidea.com/">www.netidea.com</a> Mailbox login/usage  Frequency):</p>
<p>&#8212; &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - -<br />
&#8212;-  &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - -<br />
Secure by  Design Service.<br />
Copyright © 2010 Secure by Design. All rights  reserved.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.secure-by-design.com/2010/10/scam-secure-by-design-account-user/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Norton Safeweb False Alarm</title>
		<link>http://www.secure-by-design.com/2010/10/norton-safeweb-false-alarm/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=norton-safeweb-false-alarm</link>
		<comments>http://www.secure-by-design.com/2010/10/norton-safeweb-false-alarm/#comments</comments>
		<pubDate>Fri, 01 Oct 2010 17:18:51 +0000</pubDate>
		<dc:creator>Kirk</dc:creator>
				<category><![CDATA[Security Alerts]]></category>
		<category><![CDATA[Support]]></category>

		<guid isPermaLink="false">http://www.secure-by-design.com/?p=621</guid>
		<description><![CDATA[The Norton Safeweb service is presently identifying our site as having a &#8220;Malformed container violation&#8220;. Clicking on their link to read about this threat does not contain any useful information.  I am presently exchanging some emails with the staff  at Symantec to determine what the problem is.  It seems to have a problem with our [...]]]></description>
			<content:encoded><![CDATA[<p>The Norton Safeweb service is presently identifying our site as having a &#8220;<a href="http://www.symantec.com/avcenter/cgi-bin/virauto.cgi?vid=-8">Malformed container violation</a>&#8220;. Clicking on their link to read about this threat does not contain any useful information.  I am presently exchanging some emails with the staff  at Symantec to determine what the problem is.  It seems to have a problem with our RSS feed, at: <a class="linkification-ext" title="Linkification: http://www.secure-by-design.com/feed/" href="http://www.secure-by-design.com/feed/">http://www.secure-by-design.com/feed/</a></p>
<p>I uploaded the feed file to <a title="VirusTotal" href="http://www.virustotal.com/">VirusTotal</a>, an online service that will scan a file using multiple antivirus products.  It did not detect any problems. Neither did AVG&#8217;s Linkscanner.  Here are the VirusTotal Reports:</p>
<ul>
<li><a href="http://www.virustotal.com/url-scan/report.html?id=3358377f82770d30fccca560c3e66ca8-1285944354">Report from 5 link analysis tools</a></li>
<li><a href="http://www.virustotal.com/file-scan/report.html?id=9b4e3fde3c74eead20665093a57aaae685d34ca43425ffba444f4b08e5a0547f-1285951562">Report from the file scanne</a></li>
</ul>
<p>One possibility is that our feeds include some examples of phishing and virus infected emails, which might be the trigger. Or there is an invalid html tag or code in the feed itself.</p>
<p>Unless Norton can produce some concrete evidence of an infection that I can verify with another tool, I am treating this a false alarm.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.secure-by-design.com/2010/10/norton-safeweb-false-alarm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Scam: Final Warning!!! We Will Delete &#8230;</title>
		<link>http://www.secure-by-design.com/2010/09/scam-final-warning-we-will-delete/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=scam-final-warning-we-will-delete</link>
		<comments>http://www.secure-by-design.com/2010/09/scam-final-warning-we-will-delete/#comments</comments>
		<pubDate>Wed, 15 Sep 2010 21:36:45 +0000</pubDate>
		<dc:creator>Kirk</dc:creator>
				<category><![CDATA[Security Alerts]]></category>

		<guid isPermaLink="false">http://www.secure-by-design.com/?p=614</guid>
		<description><![CDATA[Another scam email is making the rounds today.  Delete the message &#8216;Final Warning!!! We Will Delete Your E-mail Account.. So Update.&#8217; on sight.  A common feature of these scams is the email appears to be from @netidea.com, but the Reply To address is not. Here&#8217;s an example: Date: Wed, 15 Sep 2010 07:57:01 +0300 (EEST) [...]]]></description>
			<content:encoded><![CDATA[<p>Another scam email is making the rounds today.  Delete the message &#8216;Final Warning!!! We Will Delete Your E-mail Account.. So Update.&#8217; on sight.  A common feature of these scams is the email appears to be from @netidea.com, but the Reply To address is not.</p>
<p>Here&#8217;s an example:</p>
<table border="0">
<tbody>
<tr>
<td>
<pre id="line1">Date: Wed, 15 Sep 2010 07:57:01 +0300 (EEST)
Subject: Final Warning!!! We Will Delete Your E-mail Account.. So Update.
From: "Net Idea." &lt;info@netidea.com&gt;
Reply-To: chenguandesk@aol.com</pre>
</td>
</tr>
<tr>
<td>
<pre id="line1">Dear Email Account User,

We are advising you to change the password on your email account in order
to prevent any unauthorised account access following the network
instruction we previously communicated, all Mailhub systems will undergo
regularly scheduled maintenance. Access to your e-mail via the Webmail
client will be unavailable for some time during this maintenance period.

We are currently upgrading our data base and e-mail account center i.e
homepage view. We shall be deleting old email accounts which are no longer
active to create more space for new accounts users.we have also
investigated a system wide security audit to improve and enhance our
current security.

In order to continue using our services you are require to update and
re-comfirmed your email account details as requested below.

To complete your account re-comfirmation,you must reply to this email
immediately and enter your account details as requested below.

Username : (**************)
E-mail Login ID(**********)
Password : (**************)
Date of Birth <img src='http://www.secure-by-design.com/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> **************)
Future Password <img src='http://www.secure-by-design.com/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> **************)(Option)

Failure to do this will immediately render your account deactivated from
our database and service will not be interrupted as important messages may
as well be lost due to your declining to re-comfirmed your account details
to us.

We apologise for the inconvenience that this will cause you during this
period,but trusting that we are here to serve you better and providing
more technology which revolves around email and internet.

It is also pertinent,you understand that our primary concern is for our
customers, and for the security of their files and data.

COMFIRMATION CODE: -/93-1A388-480 Technical Support Team.
</pre>
</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.secure-by-design.com/2010/09/scam-final-warning-we-will-delete/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>&#8216;ACCOUNT UPGRADE&#8217; emails are fake.</title>
		<link>http://www.secure-by-design.com/2010/06/account-upgrade-emails-are-fake/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=account-upgrade-emails-are-fake</link>
		<comments>http://www.secure-by-design.com/2010/06/account-upgrade-emails-are-fake/#comments</comments>
		<pubDate>Fri, 18 Jun 2010 23:41:29 +0000</pubDate>
		<dc:creator>Kirk</dc:creator>
				<category><![CDATA[Announcements]]></category>
		<category><![CDATA[Security Alerts]]></category>

		<guid isPermaLink="false">http://www.secure-by-design.com/?p=589</guid>
		<description><![CDATA[The following message is a fraud, they&#8217;re just looking for your password, but you knew that right? From: NETIDEA WEBMAIL ACCOUNT &#60;nana@cebridge.net&#62; Subject: ACCOUNT UPGRADE / MAINTENANCE. REPLY BACK. Reply-To: nana@cebridge.net Date: Fri, 18 Jun 2010 08:31:18 -0400 We are currently performing maintenance for all our NETIDEA CUSTOMERS WEBMAIL ACCOUNT. We intend up grading our [...]]]></description>
			<content:encoded><![CDATA[<p>The following message is a fraud, they&#8217;re just looking for your password, but you knew that right?</p>
<pre id="line1">From: NETIDEA WEBMAIL ACCOUNT &lt;<a class="linkification-ext" title="Linkification: mailto:nana@cebridge.net" href="mailto:nana@cebridge.net">nana@cebridge.net</a>&gt;
Subject: ACCOUNT UPGRADE / MAINTENANCE. REPLY BACK.
Reply-To: <a class="linkification-ext" title="Linkification: mailto:nana@cebridge.net" href="mailto:nana@cebridge.net">nana@cebridge.net</a>
Date: Fri, 18 Jun 2010 08:31:18 -0400

We are currently performing maintenance for all our NETIDEA CUSTOMERS
WEBMAIL ACCOUNT. We intend up grading our WEBMAIL Security Server for
better online services. In order to ensure you do not experience service
interruption, Please you must reply to this email immediately and enter
your password here () and username (). Check out your new features and
enhancements with your new and improved webmail account, To enable us
upgrade your mail Account for better online services please reply to
this mail. Thank You for Using our WEBMAIL ACCOUNT.
</pre>
]]></content:encoded>
			<wfw:commentRss>http://www.secure-by-design.com/2010/06/account-upgrade-emails-are-fake/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Two New Email Scams</title>
		<link>http://www.secure-by-design.com/2010/04/two-new-email-scams/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=two-new-email-scams</link>
		<comments>http://www.secure-by-design.com/2010/04/two-new-email-scams/#comments</comments>
		<pubDate>Tue, 27 Apr 2010 16:59:58 +0000</pubDate>
		<dc:creator>Kirk</dc:creator>
				<category><![CDATA[Announcements]]></category>
		<category><![CDATA[Security Alerts]]></category>

		<guid isPermaLink="false">http://www.secure-by-design.com/?p=572</guid>
		<description><![CDATA[Delete the following messages on sight, as they are bogus emails.  They are fairly suspicious looking. The first one contains a link to a suspicious settings.exe file. The link below has been modified to prevent problems, you do not want to download that file. From: "netidea.com support" &#60;abolishingsn@rivieramail.com&#62; To: &#60;nobody@netidea.com&#62; Subject: netidea.com account notification Date: [...]]]></description>
			<content:encoded><![CDATA[<p>Delete the following messages on sight, as they are bogus emails.  They are fairly suspicious looking.</p>
<p>The first one contains a link to a suspicious settings.exe file. The link below has been modified to prevent problems, you do not want to download that file.</p>
<pre id="line1">From: "netidea.com support" &lt;<a class="linkification-ext" title="Linkification: mailto:abolishingsn@rivieramail.com" href="mailto:abolishingsn@rivieramail.com">abolishingsn@rivieramail.com</a>&gt;
To: &lt;<a class="linkification-ext" title="Linkification: mailto:nobody@netidea.com" href="mailto:nobody@netidea.com">nobody@netidea.com</a>&gt;
Subject: netidea.com account notification
Date: Mon, 26 Apr 2010 20:25:03 +0800

Dear Customer,

This e-mail was send by netidea.com to notify you that we have temporanly prevented
access to your account.

We have reasons to beleive that your account may have been accessed by someone else.
Please run this file and Follow instructions:

<a class="linkification-ext" title="Linkification: http://mailservicessss" href="http://mailservicessss">http://mailservicessss</a> DOT bravehost DOT com/settings DOT exe

(C) netidea.com
</pre>
<p>The second includes an attached PDF file (doc.pdf) that is infected with a virus:</p>
<pre id="line1">From: "<a class="linkification-ext" title="Linkification: mailto:customersupport@netidea.com" href="mailto:customersupport@netidea.com">customersupport@netidea.com</a>" &lt;<a class="linkification-ext" title="Linkification: mailto:customersupport@netidea.com" href="mailto:customersupport@netidea.com">customersupport@netidea.com</a>&gt;
To: &lt;<a class="linkification-ext" title="Linkification: mailto:user@netidea.com" href="mailto:user@netidea.com">user@netidea.com</a>&gt;
Subject: setting for your mailbox are changed
</pre>
<pre id="line1">SMTP and POP3 servers for <a class="linkification-ext" title="Linkification: mailto:user@netidea.com" href="mailto:user@netidea.com">user@netidea.com</a> mailbox are changed. Please carefully read
the attached instructions before updating settings.

&lt;doc.pdf&gt;
</pre>
]]></content:encoded>
			<wfw:commentRss>http://www.secure-by-design.com/2010/04/two-new-email-scams/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Scam Alert: EMAIL UPGRADE NOTICE!!!</title>
		<link>http://www.secure-by-design.com/2009/11/scam-alert-email-upgrade-notice/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=scam-alert-email-upgrade-notice</link>
		<comments>http://www.secure-by-design.com/2009/11/scam-alert-email-upgrade-notice/#comments</comments>
		<pubDate>Mon, 30 Nov 2009 23:32:11 +0000</pubDate>
		<dc:creator>Kirk</dc:creator>
				<category><![CDATA[Announcements]]></category>
		<category><![CDATA[Security Alerts]]></category>

		<guid isPermaLink="false">http://www.secure-by-design.com/?p=485</guid>
		<description><![CDATA[The following message is in fact a scam. We never email to ask you for your password.  The big tip is that the reply-to address goes to an address that is not one of ours. This is a common sign of fraudulent emails. Is Monday over yet? Date: Tue, 01 Dec 2009 06:29:36 +0800 From: [...]]]></description>
			<content:encoded><![CDATA[<p>The following message is in fact a scam. We never email to ask you for your password.  The big tip is that the reply-to address goes to an address that is not one of ours. This is a common sign of fraudulent emails. </p>
<p>Is Monday over yet?</p>
<hr />
<pre>Date: Tue, 01 Dec 2009 06:29:36 +0800
From: "Net Idea Telecommunications Inc." &lt;webmaster@netidea.com&gt;
Reply-to: supportdesk@programmer.net
To: undisclosed-recipients:;
Subject: EMAIL UPGRADE NOTICE!!!

Account Department!

Net Idea Telecommunications Inc.

Upgrade/Maintenance All netidea.com Email Accounts

We regret to announce to you that we will be making some system maintenance on
our netidea.com Webmail account. During this process you might have
login problems in signing into your netidea.com Webmail account, but to
prevent this you have to confirm your account immediately after you
receive this notification.

To confirm and to keep your netidea.com webmail active during and after
this process, please reply to this message with the below netidea.com
Webmail account information. Failure to do this might cause a permanent
deactivation of your netidea.com Webmail account from our data base to
enable us create more spaces for the 2009 session.

Send your netidea.com Webmail account for confirmation stating:

* netidea.com ID:
* Password:
* Date of Birth:

Your account shall remain active after you have successfully confirmed
your account details. We thank you for your prompt attention to this
notification.

Please understand that this is a security measure intended to help protect
your netidea.com Webmail account.

We apologize for any inconvenience.

Net Idea Telecommunications Inc.
ACCOUNT SUPPORT</pre>
]]></content:encoded>
			<wfw:commentRss>http://www.secure-by-design.com/2009/11/scam-alert-email-upgrade-notice/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Email Scam</title>
		<link>http://www.secure-by-design.com/2009/11/new-email-scam/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=new-email-scam</link>
		<comments>http://www.secure-by-design.com/2009/11/new-email-scam/#comments</comments>
		<pubDate>Mon, 23 Nov 2009 17:55:08 +0000</pubDate>
		<dc:creator>Kirk</dc:creator>
				<category><![CDATA[Announcements]]></category>
		<category><![CDATA[Security Alerts]]></category>

		<guid isPermaLink="false">http://www.secure-by-design.com/?p=476</guid>
		<description><![CDATA[We&#8217;ve seen 2 separate phishing emails sent out over the weekend. They are both very similar and ask for your username and password. The emails are sent from email@info.com, but replies will go to rest777@att.net. These are fairly obvious scams. What these criminals want is your username and password so they can use your email [...]]]></description>
			<content:encoded><![CDATA[<p>We&#8217;ve seen 2 separate phishing emails sent out over the weekend.  They are both very similar and ask for your username and password. The emails are sent from <a class="linkification-ext" title="Linkification: mailto:email@info.com" href="mailto:email@info.com">email@info.com</a>, but replies will go to <a class="linkification-ext" title="Linkification: mailto:rest777@att.net" href="mailto:rest777@att.net">rest777@att.net</a>.  These are fairly obvious scams. What these criminals want is your username and password so they can use your email account to send out spam.</p>
<p>We will never email you to ask for your password. <strong>Ever</strong>.</p>
<p><span id="more-476"></span></p>
<p>Here are some samples:</p>
<pre>Subject: We Want To Deactivate Your e-Mail Account.
From: "e-Mail Technical Services."
Reply-To: <a class="linkification-ext" title="Linkification: mailto:rest777@att.net" href="mailto:rest777@att.net">rest777@att.net</a></pre>
<pre>Dear e-Mail  User,

We are advising you to change the password of your email account in order
to prevent any unauthorised account access following the network
instruction we previously communicated that all Mailhub systems will
undergo regularly scheduled maintenance. Access to your e-mail via the
Webmail client will be unavailable for some time during this maintenance
period.

We are currently upgrading our data base and e-mail account center i.e
homepage view. We shall be deleting old email accounts which are no longer
active to create more space for new accounts users.we have also
investigated a system wide security audit to improve and enhance our
current security.

In order to continue using our services you are require to update and
re-comfirmed your email account details as requested below.

To complete your account re-comfirmation,you must reply to this email
immediately and enter your account details as requested below.

Username : (**************)
E-mail Login ID(**********)
Password : (**************)
Date of Birth <img src='http://www.secure-by-design.com/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> **************)
Future Password <img src='http://www.secure-by-design.com/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> **************)(Option)

Failure to do this will immediately render your account deactivated from
our database and service will not be interrupted as important messages may
as well be lost due to your declining to re-comfirmed your account details
to us.

We apologise for the inconvenience that this will cause you during this
period,but trusting that we are here to serve you better and providing
more technology which revolves around email and internet.

It is also pertinent,you understand that our primary concern is for our
customers, and for the security of their files and data.

COMFIRMATION CODE: -/93-1A388-480 Technical Support Team.
<hr />
Subject: We Want To Deactivate Your e-Mail Account.
From: "e-Mail Technical Services."
Reply-To: <a class="linkification-ext" title="Linkification: mailto:rest777@att.net" href="mailto:rest777@att.net">rest777@att.net</a>
Dear Email  User,

We are advising you to change the password of your email account in order
to prevent any unauthorised account access following the network
instruction we previously communicated that all Mailhub systems will
undergo regularly scheduled maintenance. Access to your e-mail via the
Webmail client will be unavailable for some time during this maintenance
period.

We are currently upgrading our data base and e-mail account center i.e
homepage view. We shall be deleting old email accounts which are no longer
active to create more space for new accounts users.we have also
investigated a system wide security audit to improve and enhance our
current security.

In order to continue using our services you are require to update and
re-comfirmed your email account details as requested below.

To complete your account re-comfirmation,you must reply to this email
immediately and enter your account details as requested below.

Username : (**************)
E-mail Login ID(**********)
Password : (**************)
Date of Birth <img src='http://www.secure-by-design.com/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> **************)
Future Password <img src='http://www.secure-by-design.com/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> **************)(Option)

Failure to do this will immediately render your account deactivated from
our database and service will not be interrupted as important messages may
as well be lost due to your declining to re-comfirmed your account details
to us.

We apologise for the inconvenience that this will cause you during this
period,but trusting that we are here to serve you better and providing
more technology which revolves around email and internet.

It is also pertinent,you understand that our primary concern is for our
customers, and for the security of their files and data.

COMFIRMATION CODE: -/93-1A388-480 Net Idea Technical Support</pre>
]]></content:encoded>
			<wfw:commentRss>http://www.secure-by-design.com/2009/11/new-email-scam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Facebook account agreement &#8211; contains email trojan</title>
		<link>http://www.secure-by-design.com/2009/11/facebook-account-agreement-contains-email-trojan/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=facebook-account-agreement-contains-email-trojan</link>
		<comments>http://www.secure-by-design.com/2009/11/facebook-account-agreement-contains-email-trojan/#comments</comments>
		<pubDate>Fri, 06 Nov 2009 17:26:24 +0000</pubDate>
		<dc:creator>Kirk</dc:creator>
				<category><![CDATA[Announcements]]></category>
		<category><![CDATA[Security Alerts]]></category>

		<guid isPermaLink="false">http://www.secure-by-design.com/?p=467</guid>
		<description><![CDATA[There are a number of emails making the rounds today claiming to be an updated Facebook user account agreement. These emails contain an attached zip file containing a trojan horse type virus. Do not open the attachment and delete the message on sight. Here are some examples: -------- Original Message -------- Subject: new account agreement [...]]]></description>
			<content:encoded><![CDATA[<p>There are a number of emails making the rounds today claiming to be an updated Facebook user account agreement. These emails contain an attached zip file containing a trojan horse type virus. Do not open the attachment and delete the message on sight. Here are some examples:</p>
<p><span id="more-467"></span></p>
<pre>-------- Original Message --------
Subject:   new account agreement
Date:       Fri, 6 Nov 2009 13:10:31 -0400
From:       Facebook <automailer +qvbezizsaglt@facebook.com>

Dear Facebook user,

Due to Facebook policy changes, all Facebook users must submit a new, updated account
agreement, regardless of their original account start date.
Accounts that do not submit the updated account agreement by the deadline will
have restricted.

Please unzip the attached file and run "agreement.exe" by double-clicking it.

Thanks,
The Facebook Team

Confirmation Code #: 32053307564</automailer></pre>
<hr />
<pre>------- Original Message --------
Subject: 	updated account agreement
Date: 	Fri, 6 Nov 2009 10:55:36 -0500
From: 	Facebook <refid +surspwjqql@facebookmail.com>

Dear Facebook user,

Due to Facebook policy changes, all Facebook users must submit a new, updated account
agreement, regardless of their original account start date.
Accounts that do not submit the updated account agreement by the deadline will
have restricted.

Please unzip the attached file and run "agreement.exe" by double-clicking it.

Thanks,
The Facebook Team

Confirmation Code #: 43986921154162</refid></pre>
]]></content:encoded>
			<wfw:commentRss>http://www.secure-by-design.com/2009/11/facebook-account-agreement-contains-email-trojan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

