<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: helpdesk]]></title>
    <link>http://securityratty.com/tag/helpdesk</link>
    <description></description>
    <pubDate>Wed, 30 Jan 2008 21:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[A Costly Crush]]></title>
      <link>http://securityratty.com/article/cafa2263c602a0dce807786d68e28098</link>
      <guid>http://securityratty.com/article/cafa2263c602a0dce807786d68e28098</guid>
      <description><![CDATA[I've seen a few blog posts over the last couple of days, with people complaining about an application on Facebook charging them crazy amounts of money. Certainly, there's a lot of angry Facebook users...]]></description>
      <content:encoded><![CDATA[
        I've seen a few <a href="http://www.sokhodom.com/2008-09-02-bad-facebook-application-lead-to-heavy-phone-bill/">blog posts</a> over the last couple of days, with people complaining about an application on Facebook charging them crazy amounts of money. Certainly, there's a lot of angry Facebook users out there:<br /><br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/crushtracker01.html" onclick="window.open('http://blog.spywareguide.com/images/crushtracker01.html','popup','width=387,height=448,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/crushtracker0-thumb-287x332.gif" alt="crushtracker0.gif" class="mt-image-none" style="" height="332" width="287" /></a></span>
<br />Click to Enlarge<br /></div><br />Some more complaints? Sure, I can do that:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="hugecrush1.gif" src="http://blog.spywareguide.com/images/hugecrush1.gif" class="mt-image-none" style="" height="347" width="309" /></span></div><br /><br /><div align="left">There are many, many more like the above comments out there. One slight problem with all of this is that the complaints are scattered across a whole range of different Crush application forums - in short, they're <i>all</i> being blamed, but they can't <i>all</i> be doing this, can they? What's the alternative, though?<br /><br />A short while ago, I wrote about <a href="http://blog.spywareguide.com/2008/07/interesting-advert-placements.html">deceptive advert placements</a> with regards another facebook application. It seems we have a similar situation here, where an "enterprising" Ad network is placing Facebook-style buttons onto installer pages and hoping people will be fooled. As it turns out, it seems to be working. While attempting to install one randomly selected Crush application, I noticed the following advert at the top of the installer splash (highlighted in red):<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/hugecrush3.html" onclick="window.open('http://blog.spywareguide.com/images/hugecrush3.html','popup','width=660,height=320,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/hugecrush3-thumb-360x174.gif" alt="hugecrush3.gif" class="mt-image-none" style="" height="174" width="360" /></a></span><br />Click to Enlarge<br /></div><br />It's easy to imagine a regular Facebook user thinking this is part of the application install and clicking "Ok". Do that, and you're taken to a site called Amazingchat(dot)net that throws up a fake message regarding you having "7 New Crush Messages" (and uses geolocational technology to point a targeted message your way). If you look like you're in the UK, you'll see this:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/hugecrush41.html" onclick="window.open('http://blog.spywareguide.com/images/hugecrush41.html','popup','width=662,height=404,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/hugecrush4-thumb-362x220.gif" alt="hugecrush4.gif" class="mt-image-none" style="" height="220" width="362" /></a></span><br />Click to Enlarge<br /></div><br />Wow, FOUR of my (fake and non-existent) messages are from Sheffield! How about if I look like I'm in the States? You've guessed it....<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="hugecrush5.gif" src="http://blog.spywareguide.com/images/hugecrush5.gif" class="mt-image-none" style="" height="42" width="318" /></span></div>
<br /><br />Windy City, here I come!<br /><br />Not. It's looking promising so far, though. If we can just go to the next screen and see something utterly useless advertised in exchange for lots of money....<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/hugecrush666.html" onclick="window.open('http://blog.spywareguide.com/images/hugecrush666.html','popup','width=552,height=371,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/hugecrush666-thumb-352x236.gif" alt="hugecrush666.gif" class="mt-image-none" style="" height="236" width="352" /></a></span><br />Click to Enlarge<br /></div><br />Horoscopes for only ?9 / $15 a week? WOW!<br /><br />Also, there go your savings.<br /><br />Could this be the site at the heart of so many complaints? Well, let's quickly check who runs it...<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="hugecrush7.gif" src="http://blog.spywareguide.com/images/hugecrush7.gif" class="mt-image-none" style="" height="140" width="587" /></span><br /><br />"Sms-helpdesk", eh? I do believe I've seen a <a href="http://www.facebook.com/topic.php?uid=4874299673&amp;topic=3908">long thread</a> concerning people having issues with large bills for phone messages. Indeed, a rep from sms-helpdesk actually appears to be posting there:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="hugecrush8.gif" src="http://blog.spywareguide.com/images/hugecrush8.gif" class="mt-image-none" style="" height="479" width="370" /></span></div><br /><br />Shame it seems some people can't even get through to the supposed helpline. Perhaps "Denise" would be better off tackling the deceptive placement of adverts made to look like installer buttons, not to mention non-existent crush messages based around geolocational targeting?<br /><br />Just a thought...<br /></div>
        
    ]]></content:encoded>
      <pubDate>Tue, 02 Sep 2008 11:24:54 +0000</pubDate>
      <category domain="http://securityratty.com/tag/application">application</category>
      <category domain="http://securityratty.com/tag/facebook application">facebook application</category>
      <category domain="http://securityratty.com/tag/crush application">crush application</category>
      <category domain="http://securityratty.com/tag/facebook">facebook</category>
      <category domain="http://securityratty.com/tag/application install">application install</category>
      <category domain="http://securityratty.com/tag/regular facebook user">regular facebook user</category>
      <category domain="http://securityratty.com/tag/crush application forums">crush application forums</category>
      <category domain="http://securityratty.com/tag/angry facebook users">angry facebook users</category>
      <category domain="http://securityratty.com/tag/crush messages">crush messages</category>
      <source url="http://blog.spywareguide.com/2008/09/a-costly-crush.html">A Costly Crush</source>
    </item>
    <item>
      <title><![CDATA[12 Signs that Your Company is Already in the Cloud]]></title>
      <link>http://securityratty.com/article/a94cc4fdd9f7e59addfde334e0a08d2a</link>
      <guid>http://securityratty.com/article/a94cc4fdd9f7e59addfde334e0a08d2a</guid>
      <description><![CDATA[What are the telltale signs that your company is already Computing in the Cloud
Is it when the CIO makes a big announcement at the monthly IT meeting
Is it when the IT newsletter drops a reference to...]]></description>
      <content:encoded><![CDATA[<p><a title="building_gap" href="http://www.flickr.com/photos/74471232@N00/506202234/" target="_blank"><img src="http://farm1.static.flickr.com/227/506202234_636bc16be9_m.jpg" border="0" alt="building_gap" /></a></p>
<p>What are the telltale signs that your company is already Computing in the Cloud?</p>
<p>Is it when the CIO makes a big announcement at the monthly IT meeting?</p>
<p>Is it when the IT newsletter drops a reference to pilot testing of some &#8216;web based&#8217; software?</p>
<p>Or, is it when the secretary whips out the boss&#8217;s Corporate Credit Card and <a href="http://www.mindtouch.com/blog/2008/04/07/">signs up</a> to a Cloud Service?</p>
<p>Here are 12 indicators that your company is *already* part of the Cloud:</p>
<ol>
<li>Your internal helpdesk reports fewer password resets.</li>
<li>Finance contacts you to confirm all the DVD readers are disabled - they are puzzled by the number of recurring credit card charges for Amazon (are the secretaries spreading out their orders for &#8220;Lost&#8221; DVDs again?).</li>
<li>You are asked to authorise a network change ticket to send all outbound network traffic via the perimeter firewall, before being routed back to the internal server room (for performance reasons). </li>
<li>You walk into the Data Center and it feels cooler than usual.</li>
<li>When the builders next door accidentally saw through the company Internet connection, people complain there must be a DoS attack going on as they can&#8217;t get to their files.</li>
<li>During physical inspections, you notice unexplained gaps in server cabinets.</li>
<li>Login failures go down, in fact login &#8220;attempts&#8221; in general go down but the company car park is full.</li>
<li>As you walk through the office, you notice all the &#8220;Security Awareness&#8221; posters have been replaced with pictures of <a href="http://images.businessweek.com/mz/04/51/0451_18innova.jpg">Jeff Bezos</a> (!)</li>
<li>You are asked to authorise a visit from the local environment group.  Fearing protesters, you are surprised to learn that your company has won a prize for reducing its Carbon Footprint</li>
<li>Your Intrusion Prevention System is preventing the call center from uploading contracts stored as GIF files.</li>
<li>You detect the presence of &#8216;malware&#8217; in the form of unexplained &#8216;Machine Images&#8217; on IT&#8217;s desktops.</li>
<li>You stop finding Windows passwords under keyboards, instead you find random hex digits next to the words &#8216;Access Key&#8217; and &#8216;Secret Key&#8217;.  You sigh, but at least they are setting difficult to guess passwords now!</li>
</ol>
<p>If you are charged with IT security in your company, you may want to start checking your web proxy logs for telltale signs that people are talking to the Cloud&#8230;or just talk to finance.</p>
<p> </p>
<p> </p>
<p> </p>
<img src="http://feeds.feedburner.com/~r/CloudSecurity/~4/277808874" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 25 Apr 2008 15:14:19 +0000</pubDate>
      <category domain="http://securityratty.com/tag/company">company</category>
      <category domain="http://securityratty.com/tag/company car park">company car park</category>
      <category domain="http://securityratty.com/tag/signs">signs</category>
      <category domain="http://securityratty.com/tag/cloud">cloud</category>
      <category domain="http://securityratty.com/tag/company internet connection">company internet connection</category>
      <category domain="http://securityratty.com/tag/telltale signs">telltale signs</category>
      <category domain="http://securityratty.com/tag/credit card">credit card</category>
      <category domain="http://securityratty.com/tag/credit card charges">credit card charges</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <source url="http://feeds.feedburner.com/~r/CloudSecurity/~3/277808874/">12 Signs that Your Company is Already in the Cloud</source>
    </item>
    <item>
      <title><![CDATA[Can I get your Username and Password ?]]></title>
      <link>http://securityratty.com/article/b1d846ec11b45907f460ce019921c20e</link>
      <guid>http://securityratty.com/article/b1d846ec11b45907f460ce019921c20e</guid>
      <description><![CDATA[A while back, I got a call from someone claiming to be from a major benefits provider and said &quot; Hello Sir. We noticed that you have a security flag on your account. Could you please give us your...]]></description>
      <content:encoded><![CDATA[A while back, I got a call from someone claiming to be from a major benefits provider and said  "<em>Hello Sir. We noticed that you have a security flag on your account. Could you please give us your username and password to reset the flag.</em>?"<br /><br /><em>"Wow!" </em>I almost yelled in excitement "<em>A real live telephone scammer!"  </em>I quickly noted the possibly-fake telephone number (yeah - Nitesh alerted me about spoofcard.com a long time ago!) and attempted to get a number where I could call him back. Surprisingly - he was fine with letting me call him back at the number list on my callerID - and he told me to ask for helpdesk/customerservice/security desk something.. I forget.. I said "Sure - Let me call you right back".<br /><br />I quickly looked up the benefit provider's number on the internet intending to alert them of this scam - guess what ?<em>  It was the same number.</em>  I called that number and explained that they probably have a scammer on the inside asking for userids and passwords - On explaining in detail what happened - the girl at the other end was perplexed on how I could jump to that conclusion and exclaimed that <em>that was the only way they could clear these security flags. They login as the user and clear it out.  !!!</em><br /><br />So much for expecting a little security from a company that was managing my 401k, pension plan and other benefits!]]></content:encoded>
      <pubDate>Mon, 24 Mar 2008 14:25:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security flags">security flags</category>
      <category domain="http://securityratty.com/tag/major benefits provider">major benefits provider</category>
      <category domain="http://securityratty.com/tag/security flag">security flag</category>
      <category domain="http://securityratty.com/tag/benefits">benefits</category>
      <category domain="http://securityratty.com/tag/call">call</category>
      <category domain="http://securityratty.com/tag/flag">flag</category>
      <category domain="http://securityratty.com/tag/quickly">quickly</category>
      <category domain="http://securityratty.com/tag/quickly noted">quickly noted</category>
      <source url="http://securitycoin.blogspot.com/2008/03/hewitt.html">Can I get your Username and Password ?</source>
    </item>
    <item>
      <title><![CDATA[Hottest tech events for March: IT Roadmap, VoiceCon, VON.x, BrainShare]]></title>
      <link>http://securityratty.com/article/33494285d543ea8e098341a297a71db3</link>
      <guid>http://securityratty.com/article/33494285d543ea8e098341a297a71db3</guid>
      <description><![CDATA[VoIP, wireless and mobility, everything Novell and SUSE Linux, security and Google Android are among key themes at IT industry conferences coming in March (heres Februarys list). For those of you...]]></description>
      <content:encoded><![CDATA[VoIP, wireless and mobility, everything Novell and SUSE Linux, security and Google Android are among key themes at IT industry conferences coming in March (here’s February’s list). For those of you thinking you could use a business trip and some education, what follows is a quick rundown of what’s ahead. Add your comments at the end of this story regarding other events this month.
			
			<div style="margin-top:20" />
			<table border="1" BORDERCOLOR="#0033CC" cellspacing="0" cellpadding="2">
				<tr valign="top" align="left">
					<td>
						<table border="0" cellspacing="3" cellpadding="2" width="100%">
			
			
		  
		<tr> 
		<tr>
      <td width="*">
				<font face="Arial,Helvetica,Geneva,Sans-serif,sans-serif" size="-1">
				<p>	
			
			<a href="http://rsslinks.industrybrains.com/click?sid=93&scid=10069&rqctid=460&lid=399445&cid=73693&pr=2&tstamp=20080214000000&url=http://manageengine.adventnet.com/products/service-desk/index.html%3fibadfin" target=_blank><strong>IT HelpDesk & Customer Support Software</strong></a></p>
				<td align="right">
					<font face="Arial,Helvetica,Geneva,Sans-serif,sans-serif" COLOR="#0033CC" size="-1"><p>Advertisement</p></font>
				</td>
				</tr>
				<tr><td colspan="2"><font face="Arial,Helvetica,Geneva,Sans-serif,sans-serif" size="-1"><p>Internal IT HelpDesk Software with Asset Mgmt. Customer Support Software with Account & Contact Mgmt
			
				</p>
				</font>
		 	</td>
     </tr>
		 
		 
			
						</table>
					</td>
				</tr>
			</table>
			<div style="margin-top:20" />
			
			]]></content:encoded>
      <pubDate>Tue, 12 Feb 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/customer support software">customer support software</category>
      <category domain="http://securityratty.com/tag/helpdesk software">helpdesk software</category>
      <category domain="http://securityratty.com/tag/helpdesk">helpdesk</category>
      <category domain="http://securityratty.com/tag/asset mgmt">asset mgmt</category>
      <category domain="http://securityratty.com/tag/business trip">business trip</category>
      <category domain="http://securityratty.com/tag/key themes">key themes</category>
      <category domain="http://securityratty.com/tag/google android">google android</category>
      <category domain="http://securityratty.com/tag/suse linux">suse linux</category>
      <category domain="http://securityratty.com/tag/march">march</category>
      <source url="http://www.networkworld.com/news/2008/021308-march-events.html?fsrc=rss-security">Hottest tech events for March: IT Roadmap, VoiceCon, VON.x, BrainShare</source>
    </item>
    <item>
      <title><![CDATA[IT events to attend in February ]]></title>
      <link>http://securityratty.com/article/c549d44ead752da36440992649347f0f</link>
      <guid>http://securityratty.com/article/c549d44ead752da36440992649347f0f</guid>
      <description><![CDATA[HelpDesk or Customer Support

Advertisement

Web based IT HelpDesk with Asset Mgmt or Customer support Software with Account &amp; Contact...]]></description>
      <content:encoded><![CDATA[
			
			<div style="margin-top:20" />
			<table border="1" BORDERCOLOR="#0033CC" cellspacing="0" cellpadding="2">
				<tr valign="top" align="left">
					<td>
						<table border="0" cellspacing="3" cellpadding="2" width="100%">
			
			
		  
		<tr> 
		<tr>
      <td width="*">
				<font face="Arial,Helvetica,Geneva,Sans-serif,sans-serif" size="-1">
				<p>	
			
			<a href="http://rsslinks.industrybrains.com/click?sid=93&scid=10069&rqctid=460&lid=399445&cid=73695&pr=2&tstamp=20080204000000&url=http://manageengine.adventnet.com/products/service-desk/index.html%3fibadfin" target=_blank><strong>HelpDesk or Customer Support</strong></a></p>
				<td align="right">
					<font face="Arial,Helvetica,Geneva,Sans-serif,sans-serif" COLOR="#0033CC" size="-1"><p>Advertisement</p></font>
				</td>
				</tr>
				<tr><td colspan="2"><font face="Arial,Helvetica,Geneva,Sans-serif,sans-serif" size="-1"><p>Web based IT HelpDesk with Asset Mgmt or Customer support Software with Account & Contact mgmt.
			
				</p>
				</font>
		 	</td>
     </tr>
		 
		 
			
						</table>
					</td>
				</tr>
			</table>
			<div style="margin-top:20" />
			
			]]></content:encoded>
      <pubDate>Wed, 30 Jan 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/customer support software">customer support software</category>
      <category domain="http://securityratty.com/tag/customer support">customer support</category>
      <category domain="http://securityratty.com/tag/asset mgmt">asset mgmt</category>
      <category domain="http://securityratty.com/tag/web based">web based</category>
      <category domain="http://securityratty.com/tag/contact mgmt">contact mgmt</category>
      <category domain="http://securityratty.com/tag/helpdesk">helpdesk</category>
      <category domain="http://securityratty.com/tag/advertisement">advertisement</category>
      <category domain="http://securityratty.com/tag/account">account</category>
      <source url="http://www.networkworld.com/news/2008/013108-february-it-events.html?fsrc=rss-security">IT events to attend in February </source>
    </item>
  </channel>
</rss>
