High-grade Ni-Cu-Pt-Pd-Au-Ag-Rh-Cr-V discoveries in the "Ring of Fire"
NI 43-101 Update (March 2011): 11.0 Mt @ 1.78% Ni, 0.98% Cu, 0.99 gpt Pt and 3.41 gpt Pd and 0.20 gpt Au (M&I) / 9.0 Mt @ 1.10% Ni, 1.14% Cu, 1.16 gpt Pt and 3.49 gpt Pd and 0.30 gpt Au (Inf.)
  • Demo Video
  • Private Messages
  • Edit My Profile
  • View/Edit Portfolio

AGORACOM News Flash

AGORACOM Wire - Wednesday February 15th, 2012

Breaking News ....

Lomiko (LMR: TSX-V) to Complete 43-101 Report on Previous Drilling at the Quatre Milles Graphite Property *CLIENT* Read More

Top Sector Stories ....

Strike Graphite Corp. (TSXV:SRK) Acquires Wagon Graphite Project in Quebec in Vicinity of Timcal's Lac des Iles Graphite Mine *CLIENT* Read More  |  Profile

Strike Graphite goes "Beyond the Press Release"

McLaren Resources (CNSX:MCL) Drills 7.0 Grams Gold Over 7.4 Metres at the TimGinn Property Located Adjacent to the Hollinger Mine *CLIENT* Read More | Watch Beyond the Press Release

 AGORACOM Launches GraphiteStocksBlog.com

We're proud to announce the launch of GraphiteStocksBlog.com a website dedicated to the needs of investors and companies in the fast growing Graphite industry.

INAUGURAL GRAPHITE SPONSORS

Message: Zeus Trojan, detection and removal.

Noord aa
Rank: [?]
President
Points: [?]
11750
Rating: [?]
Votes: 129 Score: 3.7
  • Currently 3.7/5 Stars.
Did you know? You can earn activity points by filling your profile with information about yourself (what city you live in, your favorite team, blogs etc.

Re: Zeus Trojan, detection and removal.- get a Mac!

posted on Sep 25, 09 12:55AM

I didn't see the link to the orignal article, here it is:


Security Fix - Brian Krebs on Computer Security
Search This Blog
ferma.JPG

In mid-July, computer crooks stole $447,000 from Ferma Corp., a Santa Maria, Calif.-based demolition company, by initiating a large batch of transfers from Ferma's online bank account to 39 "money mules," willing or unwitting accomplices who typically are ensnared via job search Web sites into bogus work-at-home schemes.

Ferma President Roy Ferrari said he learned of the fraud not from his bank but from a financial institution at which several of the mules had recently opened accounts. Ferma employees worked extensively with that bank and several others to reverse the fraudulent transfers before the mules could withdraw the funds, and Ferrari said they were able to block at least $232,000 worth of bogus transfers.

But Ferrari says his bank is withholding at least $50,000 in additional funds it recovered on its own, until he agrees to sign a document saying he won't sue the bank for for the remaining losses

"We're at a bit of an impasse -- kind of a shoving match -- with our bank," Ferrari said. "We've threatened to sue them, so that's probably one of the things that caused them to raise this indemnity agreement."

The fraudsters were able to slip past two-factor authentication used by Ferma's bank, which requires that -- in addition to their user names and passwords -- customers enter a unique code from a supplied USB key fob that generates a new six-digit code every 60 seconds.

The exact type of malicious software that was used in the attack is unknown (Ferrari said the affected computer's hard drive is currently in possession of the FBI). But Ferma manager Rich Parodi said the company's security software found a banking Trojan horse program on the internal system, which had been hacked by the fraudsters and used to initiate the bogus transfers.

Some types of malware, particularly a type of data-stealing Trojan horse programs known as "Zeus," allow the attackers to change the display of a bank's login page as a victim is entering their credentials. For example, when a victim submits his one-time password along with his credentials, the malware may force the browser to return a counterfeit page (still showing the bank's domain name in the URL bar) stating that the bank's site is down for maintenance, please try back again in 15 minutes. Meanwhile, those credentials are not submitted to the bank but instead sent to the attackers.

This tactic is remarkably effective: When an unwitting customer waits as instructed, the thieves use those intercepted credentials to log in as the victim and initiate unauthorized transfers from that account.

Parodi recalled that an employee who handles the company's online account had trouble logging in just hours before the fraudulent transfers were discovered.

"The employee eventually had to reset his password, but by the time we figured out what was happening, the hacker had already withdrawn the money," Perodi said.

Over the past few days, I have interviewed nearly two dozen companies, universities and school districts that have been attacked in the same fashion. While their stories were remarkably similar, each seemed to highlight a different weakness in the modern online commercial banking environment. I will be writing about their experiences in the coming days and weeks, but in the meantime I'd like to offer a few basic security tips for companies that bank online.

-Reconcile your accounts daily. The victimized companies I have interviewed so far that have been most successful in retrieving stolen funds have by and large been those who quickly spotted the fraudulent transfers.

-Ask your bank if you can set up a notification procedure - perhaps approval by phone -- for any transfers that fall outside of your normal online banking activity.

-For employees who need to access your accounts online, consider setting them up with a Mac or Linux system -- or perhaps even a Live CD Distribution of Linux - to minimize the chances of data-stealing malware swiping your company's crown jewels.


New Message

Please login to post a reply

AGORACOM Quick Tips

AGORACOM 100 - The Top 100 Small Caps ... Find Your Next Investment

President's D.D.

PDF, 22.4 MB ! read more