Showing posts with label cyberstalker. Show all posts
Showing posts with label cyberstalker. Show all posts

Swimming With the Cyber Sharks

By Carl Weiss

It is said that the only sure things in life are death and taxes. While this pearl of wisdom has stood the test of time, in the not too distant future there could be an addition to that list: Cyberattack. That's because cyberattacks on businesses and individuals are up nearly 50% in the past year alone. Where cybercriminals used to almost exclusively target big businesses with deep pockets, now that ransomware has become so prolific, small businesses and even individuals are finding their online assets and machines being hijacked. And why not, since most individuals and small businesses offer little in the way of resistance.

Enter the Cyber Sharks
Image courtesy of worth1000.com

Who can forget the opening music to the movie Jaws.  In it’s day, the novel and subsequent blockbuster motion picture was enough to keep people on the beaches and out of the surf.  But as paranoid as many moms became about letting their kids frolic in the waves back in 1975, forty years later we should all be hearing the strains of da-da-dum-dum every time we surf the web.  That’s because while Jaws was a work of fiction, the arrival of schools of Cyber Sharks is all too real.

Just like the real deal, there is no 100% reliable cyber shark repellent that can keep someone from putting the byte on your computer, tablet and/or smartphone.  Even worse is the fact that while individuals are woefully unprepared to be hacked, what’s even worse is the fact that many of the devices connected to the Internet of Everything have absolutely no protection whatsoever.

Literally everything from appliances to medical devices to automobiles are rapidly becoming web-enabled.  While this provides the public with even more interactivity, it also provides hackers with more ways to get to consumers and business owners. Just as most people make the mistake of thinking their smartphone is a phone instead of a computer that you can talk on, nearly everyone doesn’t realize that the average automobile being built today have 100 lines of code onboard.  Many are now Wi-Fi enabled as well. You don’t have a car with q computer onboard. You have a computer that drives.  Soon, these computer cars will do most of if not all of the driving.  So if a hacker can take control of your car, what does that mean for the passengers and driver?  (On a recent 60-Minutes telecast, hackers gained access to the car in which Leslie Stahl was driving, turning on the lights and windshield wipers.  So this is not a hypothetical possibility.)

Who’s Watching Who?

Courtesy of Samsung.com
Smart Houses and appliances are also becoming more and more commonplace.  They’re also becoming easy pickings for hackers.  If a hacker can crack your home’s security system, this makes breaking and entering child’s play.  Don’t even get me started on what a hacker can do to your web-enabled Nanny Cam.  The same smart TV that you just installed in your living room can be hacked with ease, since most contain little or no security.   

A February 24, 2015 blog by CNN reported: Earlier this week, we learned that Samsung televisions are eavesdropping on their owners. If you have one of their Internet-connected smart TVs, you can turn on a voice command feature that saves you the trouble of finding the remote, pushing buttons and scrolling through menus. But making that feature work requires the television to listen to everything you say. And what you say isn't just processed by the television; it may be forwarded over the Internet for remote processing. It's literally Orwellian.

What’s really scary is the fact that last year alone more than 10,000 smart appliances were hacked, according to leading US security firm Proofpoint.  Once inside your smart TV or refrigerator, hackers can then gain access to other web-enabled devices.  Believe it or not, your refrigerator can spam your smartphone, laptop or tablet once infected.  Even if your device does come with some semblance of security, unless the protection is updated on a regular basis, it’s only a matter of time before a hacker will prevail.

How Do I Hack Thee?  Let Me Count the Ways.

So many smart devices…So little time.  Everything from wearables to medical devices are becoming vulnerable to hacking.  Symantec reported on March 12 that: “All of the devices failed to check whether they were communicating with an authorized server, leaving them open to man-in-the-middle attacks. One out of five devices did not encrypt communications and many did not lock out attackers after a certain number of password attempts, further weakening their security. All of the potential weaknesses that could afflict Internet of things systems, such as authentication and traffic encryption, are already well known to the security industry, but despite this, known mitigation techniques are often neglected on these devices”

Image by culturedigitally.org
While Symantec’s report was referring to smart appliances, in October of 2014, the US government told the FDA to start taking medical device security seriously while citing the same problems that smart appliances were facing.  The next time you go to the hospital for a dialysis treatment or to get your pacemaker checked out, you might like to ask your physician about the inherent hacking vulnerabilities of these systems.

The number of ways that hackers can get into your devices is staggering. Below are some of the most popular tools of the hacker’s trade:

  1.    Sniffers are programs or device that monitors all data passing through a computer network. It sniffs the data and determines where the data is going, where it's coming from, and what it is. In addition to these basic functions, sniffers might have extra features that enable them to filter certain types of data, capture passwords, and more. 
  2.     The Hex Dump (aka Voodoo) - When an electronic device is manufactured, it is programmed with firmware.  Hacking firmware is simply a matter of buying a programmer that can receive the memory dump and transmit it to a computer where the code can be altered.  Then transmit the modified code back to the device.
  3.    Attacking Defaults – Virtually every piece of hardware on the market comes with a set of standard defaults, including username and password that provide access to the system.  Since most people do not change these default settings, this is the easiest way to exploit a system.
  4.    SQL Injection – While it sounds like a medical procedure, what an SQL Injection attack are conducted by entering unexpected entries into a database and then probing the returned error messages to reveal information that can be used to hack the system.  For instance, by entering metacharacters like #$%^ into a field that processes only alphanumeric information, the database could be tricked into revealing the contents of the database, or in some other way compromise an SQL server. 
5. DDoS Attacks - Directed Denial of Service Attacks occur when hackers flood a targeted website with so much bogus traffic that it brings the victim's server to a halt.  This is usually followed by a demand for payment in order to restore service.
6. Data Extortion - Most people aren't aware that their data can be hijacked and held for ransom.  This can take a number of different forms, including threatening to release sensitive information stolen from a machine, to locking a legitimate user out of their own website or machine by changing the password.  Just as with DDos attacks, all too many extorted users don't realize they've been hacked until a ransom note appears demanding payment.  Even worse than DDos attacks, non-payment in this case can result in your website or data being erased.  (Lately, online extortion has also extended to threats of having one's reputation smeared online unless payment is rendered.)
7. Ratting - Remote Administration Tools are an increasingly popular and insidious means of hacking everything from laptops to tablets and smartphones.  Once successfully deployed, a ratted machine is literally under the control of the hacker.  Ratted machines can not only be rifled for information, but their webcams and built-in microphones can be surreptitiously turned on, allowing the rat to become the equivalent of a cyber peeping Tom.  (There have been a number of high profile celebrities who have been ratted, resulting in compromising photos and videos making the rounds online.

Courtesy itunes.apple.com
While all of the abovementioned tactics require a bit of technical knowhow, there are many other hacking programs and devices that can be bought online.  There are also online forums, hacking blogs and clubs that teach hackers the tools of the trade.  There are also annual hacker conventions and hackathons such as the one held yearly in Las Vegas.  If you don’t believe me, simply google, Hacking devices available online.”

The real danger is that the Cyber Sharks have the upper hand since detection, much less prosecution is hit and miss at best.  Meanwhile hacking continues to proliferate nearly unchecked.  CNN recently reported that in 2014 hackers exposed the personal information of 110 million Americans, roughly half of the nation’s adults.

 So the next time you turn on your Smart TV or start your web-enabled car, don’t be surprised if the sound you hear emanating from your surround speakers is something like, “Da-da, dum-dum.”

 Carl Weiss is president of Working the Web to Win, an award-winning digital marketing agency based in Jacksonville, Florida.  You can listen to Carl live every Tuesday at 4 p.m. Eastern on BlogTalkRadio   



Is There a Cyberstalker in Your Future?

By Carl Weiss

Like it or not, the age of the cyber stalker is upon us.  Whether you are an employee, are married or have just ended a relationship, there are apps that make it all too easy for a third party to know a great deal of intimate personal knowledge about you.  Worse still is the fact that for a few bucks any cyberstalker can acquire a sophisticated array of software that makes it child’s play to track your location in real time and listen or look in on what you are doing and with whom you are doing it.    


Cyber-Bullying-Infographic
Cyber-Bullying-Infographic (Photo credit: Social Media Max)
While this sounds like a plot for a sci-fi movie or novel it has become all too real for victims of this 
twenty-first century scourge.  During the past few months everyone from ex-boyfriends to a Seattle police officer have been prosecuted for spying on and/or posting sexually explicit photos of their former lovers online.  Even children have been portrayed recently in the media for using the Internet to cyberbully classmates with sometimes tragic results.

The bad news is that in spite of recent legislation that can impose serious jail time on cyberstalkers, this is a crime that is on the rise, currently affecting one in six women and ten percent of all men.  The good news is that there are steps that you can take to defend yourself in this all too wired world.


Is Facebook Becoming Cyberstalker Central?

The newspost that motivated me to write this blog is entitled, “7 Things You Told Facebook Without
Facebook logo EspaƱol: Logotipo de Facebook Fr... Realizing It.”  Posted on April 29 by vox.com, the staggeringly detailed post details a number of creepy apps that are available to the general public that are designed to trawl through Facebook to guess your income, your location and your passwords, to apps that seek out men or women who have just ended a relationship or even scout the social net for revealing photos.  Like a virus, some of these apps are designed to jump from one post to another, burrowing into your list of friends in order to do the stalkers nefarious deeds.

Of course Facebook isn’t the only social net in vogue with cyberstalkers.  And not all cyber stalkers are interested in seeing your swimsuit photos.  A post from technorati.com points out that Facebook, Twitter and FourSquare are now being used by burglars to zero in on vacationing families.  The article points out that not only do 75% of convicted burglars admit that criminals use social media to find homes to victimize, but they also admit to using Google Earth to case the neighborhood.  (Let’s see the neighborhood watch foil these hi-tech thieves.)

The problem with most people is that they post way too much information on social sites.  Everything from where you live to what you own is many times revealed in stunning detail (complete with photos).  Then you casually post the fact that you are going to be leaving on that two week vacation and let everyone in cyberspace not only know how long you will be gone, but you also share photos of you at the airport waiting on your plane to pix of your vacation in real time.  If this sounds familiar, then don’t be surprised if upon your return you find that your house and/or business has been rifled by thieves. (Heck why not show the thieves where you keep the spare key?)

The Technorati piece goes onto advise readers that if they don’t want to be victimized while on vacation they need to start by taking a vacation from using social media before or during any extended trip.  They also advise you to consider sharing your vacation photos after the fact.  The article also advises the public to advise their friends to avoid posting tidbits about them while they are on vacation unless it is to post the fact that you have just acquired a vicious watchdog.

You Always Hurt the One You Love

Even software that was originally purposed to protect those we love can be coopted into working for the bad guys.  A blog on Motherboard.com points out the fact that spy software designed to help mothers keep tabs on their children has become popular fodder for those who wish to spy on others.

"We do have quite a large proportion of our customers who use mSpy specifically to catch a cheating spouse," mSpy communications director Tatiana Ameri told Komo News last year.  http://motherboard.vice.com/read/tor-is-being-used-as-a-safe-haven-for-victims-of-cyberstalking

More illuminating is the fact that the article goes onto point out that there is an entire online realm that caters to those looking to spy on others.

"Digital communities have sprung up where individuals teach each other how to compromise cell phones to track victim’s whereabouts, listen to conversations in a room, take pictures, and read texts and email so that they can learn about their victim’s behavior on a microscopic level."

BGFJ0R (CYBER ATTACK) ...item 2.. Watching the...
Even Spies Have Girlfriends

The piece also goes onto point out that even spies at the NSA aren’t above using top secret surveillance tools to keep tabs on loved ones.  The program was so pervasive that it even had its own codename: LOVEINT.  The revelation of this peccadillo so incensed Senator Chuck Grassley of Iowa that he petitioned the NSA to release information about LOVEINT.  The information revealed that at least a dozen of the NSA’s best and brightest were implicated in the program.

Of course for every spy there is a counterspy.  And in the age of cyberstalking there are a number of resources designed to help victims fight back.  While many of these sites provide checklists designed to help you avoid becoming a victim of cyberstalkers, there are a few that take a more proactive approach.  One of these is Tor Network, the same software employed by hackers, crackers, dissidents and whistleblowers to maintain online anonymity.

For several years, Tor, spearheaded by Tor Project executive director Andrew Lewman, has been tackling cyber stalking, working with domestic violence groups to set up countersurveillance programs to help victims evade online surveillance. The onion router can hide a victim’s identity long enough for them to research where to find help, and look up what data they can find about themselves without tipping off their stalker that they’re online, he said.
Remember that everything from your computer to your tablet and smartphone can be used against you.  Malware can be surreptitiously installed on any or all of these that can allow a cyberstalker to take control of the device even to the point of activating the unit’s webcam.  So aside from making sure you have one or more layers of software designed to detect and defeat spyware and malware also make sure that you don’t make it easy for cyberstalkers to get you in their clutches.  Never click on links or email from people you do not know.  Curtail your habit of sharing everything and anything about your personal life online.  Above all, be wary of posting any photos that could be used against you at a later date.
English: Rottweiler Head Deutsch: Rottweiler Kopf 
Hey!  Anybody want to see a picture of my new Rottweiler?


Carl Weiss is CEO of Working the Web to Win, a digital marketing agency in Jacksonville, Florida.  You can interface with Carl every Tuesday at 4 p.m. Eastern when he airs his radio show on Blog Talk Radio.

Enhanced by Zemanta