Internet Security Zone Blog

Twitter Viruses, Scams and Attacks - How to Protect Yourself

By Daniel Armao, Security Advisor (Guest blogger)

 

Last weekend, Twitter users were the target of a “Best Video” scam in which they were tricked into clicking a link and sent to a website designed to download malware using an Adobe Acrobat PDF exploit. The malware installed was the scareware software called System Security. System Security is a fake antivirus product that is designed to trick the user into buying it by using scare tactics such as fake scanning results.

 

A week before that, Twitter users were affected by a phishing attempt called “Twittercut.” If a Twitter user clicked on the link the user was then redirected to a phishing website that asked for their username and password.

 

The increased popularity of social networking sites such as Twitter and Facebook have unfortunately led to an increase in social engineering attacks. Most importantly, these attacks are used to gain financial information, obtain a large number of credentials and leverage e-mail services for spamming activities. 

 

So, don’t be fooled. Let’s talk about the most common ways users are fooled on social networking sites.

 

-         Links can lead you to malicious material such as hidden drive-by downloads that attempt to silently install software onto your computer without you doing anything or knowing about it.

 

-         Links can also lead you to a phishing site designed by scammers to trick a user into revealing confidential information such as account passwords for banking or social networking sites.

-         There are downloads that seem perfectly safe, such as a video, screensaver (screensavers are the most notorious) or some even offer to give you security protection, but they are actually malware. 

 

-         A link from a friend might not be safe either.  Your friend’s computer could have been infected and now is part of a botnet being used to send malware and dangerous links. 

 

-         Tweeters often use URL shortening services such as tinyurl.com to obtain a shorter URL that fits within the 140 characters restriction.  This means you don’t know what site your are really going to until you are there.

How to protect yourself:

-         Do not click on suspicious links.

-         Be smart about what links to trust or not:

·         Confirm the link.  Hover your mouse over the link to see at the bottom of your browser window where it really goes – the text might say “Wells Fargo Bank” but the link might go somewhere else entirely (for example, the link looks like Google, but it’s not).

 

·         Make sure the URL is correct on the address bar of the browser. The safest thing to do if you are not sure is to type the correct website address manually. Be extra cautious if you receive the link via e-mail.

 

·         Do not download or install any software, not even codecs for viewing videos, from an untrusted site.

 

-         Last but not least, get protection for your computer and for your web browser.  These are two different things. 

 

·         ZoneAlarm ForceField provides a protective layer around your browser, shielding you from drive-by downloads, browser exploits and phishing attempts.

 

·         ZoneAlarm Extreme Security combines computer security and browser security into one.

 

-         If you are infected with malware, change your passwords immediately and download and scan your computer with a top security suite.  Always verify that the security you would like to download is legitimate by going to PC Magazine or other computer publications (if it is not well known or reviewed by a noted security publication, don’t get it.)

 

Enjoy the web, do what you want to do.  Just be smart about it and get the protection you need or your fun might come to a quick halt.

 

Posted by ZoneAlarm on June 12, 2009 at 10:37 AM in Social Networking Security | Permalink

Digg This | Save to del.icio.us

Search the Blog


  • Zone Blog Google

ZoneAlarm Help and Support

  • Visit Support or User Forums for help with your software.

Zone Blog Feeds

  • Zone Blog RSS feed

    Add Zone Blog feed to My Yahoo!

    Add Zone Blog feed to Google

    Subscribe to Zone Blog feed with Bloglines

Categories

  • Facebook Security
  • ID Theft
  • Malware, Spyware, Worms
  • PC Security
  • Phishing & Spam
  • Security Industry
  • Social Networking Security
  • Technology
  • ZoneAlarm

Recent Posts

  • Hey Doc, Do I Really Need HDE?
  • Give Your PC a “Flu Shot”
  • ZoneAlarm vs. Windows 7
  • Wait! Before Upgrading to Windows 7…
  • How to Travel Safely with Your Laptop this Thanksgiving
  • Windows 7 Security: What it Has, and What it Lacks
  • Windows 7 Through Security Goggles
  • Keeping Laptops Safe
  • Quick Safety Tips for Staying Connected While On-the-go
  • Protecting Your Privacy: Web 2.0 Security

Archives

  • November 2009
  • October 2009
  • September 2009
  • August 2009
  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009

Sites We Like

  • Virus Bulletin
  • SANS - Internet Storm Center

    Kaspersky Blog: Analyst's Diary

    digg / security

    Viruslist.com

    Consumer.gov

    World Privacy Forum

    Privacy Rights Clearinghouse (see how to Opt out from Online Data Vendor Databases)

ID Protection Services

  • ZoneAlarm partner Intersections provides helpful IdentityGuard® services for actively monitoring activity related to your identity:

    Identity Protection Center - Learn how to protect yourself from identity theft

Zone Links

  • Internet Security
  • ZoneAlarm Tech Support
  • Feedback
  • ID Protection Center
  • ZoneAlarm ForceField