{"id":42,"date":"2011-02-14T01:50:53","date_gmt":"2011-02-14T01:50:53","guid":{"rendered":"http:\/\/darthjedi.logiodice.com\/2011\/02\/14\/InternetBewareItAllStartedWithTheLetterE.aspx"},"modified":"2011-02-14T01:50:53","modified_gmt":"2011-02-14T01:50:53","slug":"internet-beware-it-all-started-with-the-letter-e","status":"publish","type":"post","link":"https:\/\/darthjedi.logiodice.com\/?p=42","title":{"rendered":"Internet beware \u2013 it all started with the letter E"},"content":{"rendered":"<p>I started using the internet almost 20 years ago; and while I was a minor, with no job, I gained internet access in sometimes nefarious ways.&#160; I spent my time on the internet staying out of trouble (or not getting caught), but let\u2019s just say that I was no Angel, and my purpose for being on the internet was to learn as much as I could.&#160; <\/p>\n<p>As a result of the last 20 years of active involvement in security, I have learned to think like the criminals, and know how to attack and protect against their wily ways.&#160; As a result, you would have a very hard time finding someone as paranoid and cautious as I am on the internet. However, this afternoon, I was a victim of Internet fraud.&#160; Take a few minutes to listen to how I fell victim, and how I responded.&#160; <\/p>\n<p>Hopefully, the information presented here will help make you even more cautious as you fire up your browsers and go strolling down the streets of the ghetto at the midnight hour, in the pitch black.<\/p>\n<p>Victims of Internet fraud often fall into two categories: those who are not paying attention (inattentive), and those who are uninformed (ignorant).&#160; In my case, it was a combination of both.<\/p>\n<p>When working on the Internet, my fingers and I have this agreement:&#160; I think, and they type.&#160; There really isn\u2019t a lot of surface level communication that goes on between my fingers and brain.&#160; I can be talking to someone about one thing, thinking about something else, and typing a third, and completely unrelated thing.&#160; <\/p>\n<p><strong><font size=\"5\">The Inattentive phase<\/font><\/strong><\/p>\n<p>Sometime this afternoon while trying to deal with some online marketing things I have been doing, yelling at my boys to stop yelling at each other, and thinking through issues of regulations around export controls, I opened up my internet browser and typed in Facebook.com.&#160; The only problem is, My fingers rebelled, ever-so-slightly, and they misplaced the E.<\/p>\n<p>At the same time, as my fingers are misbehaving, somewhere out on the internet, an attacker is sitting and patiently waiting with a domain registered to a very slight variation on the name of Facebook.&#160; This server domain name (it\u2019s like the computers postal address) is registered in Tijuana Mexico but the traffic is forwarded to another domain registered in Panama City.&#160; That domain is hosted on a server in the Bahamas.&#160; <\/p>\n<p>As I\u2019m flipping through different browser windows, I come back to my \u201cFacebook\u201d page, and see that it is displaying a &quot;survey&quot; which purports (although never directly states) that it is from Facebook.&#160; The survey, a three question survey, was filled with questions like &quot;what do you think about social networking, do you think it brings you closer to friends, do you have any suggestions for us to make it better&quot;.&#160; After 30 seconds, I was complete, and ready to be directed back to Facebook (or so I thought), and then the site showed a screen that said &quot;put in your phone number to register for a giveaway&quot;.<\/p>\n<p>\u201cEh, I suppose if Facebook wants to spend $300 out of it\u2019s billions of dollars to give away an iPhone, my 3GS could be upgraded. Besides, what\u2019s sensitive about my phone number, it\u2019s on the do not call registry, and I could change it at any time for $30 dollars.\u201d&#160; This is what is going through my mind, as I\u2019m continuing to yell at my boys who are yelling at each other, and at this point almost coming to blows; while I work on some marketing material and skip back from the BIS page on export controls.&#160; After putting in the phone number, I got a text message saying &quot;this is the code you need&quot;, and subsequently the web page prompted me to enter the code.&#160; <\/p>\n<p>\u201cYeah, sure, I guess\u201d, \u2013 that\u2019s what went through my mind.&#160; I mean, really, what harm can come from putting in a code they just sent to my phone \u2013 there is nothing personally identifiable about that\u2026<\/p>\n<p><font size=\"5\"><strong>The Ignorance Phase<\/strong><\/font><\/p>\n<p>What I didn\u2019t realize is that in the world of Cell Phones there is a whole billing infrastructure with the cell phone companies that if someone text&#8217;s you a code through the phone company, and you then give them that code which they represent to the phone companies, that equates to an electronic signature, and the phone companies then assume that you are agreeing to be billed for a specified amount (or a reoccurring specified amount).<\/p>\n<p>So here I am, I have this \u201cdigital signature\u201d in my hand, and on the next page there is a big spot to put in your code and some tiny itty bitty print \u2013 that no one ever pays attention to, right?&#160; I typed in the code and hit submit; and the page came back and said \u201cI\u2019m sorry, this offer is full, would you like to see another one\u201d?&#160; At this point I was like \u201cWTF!&quot;?\u201d.<\/p>\n<p>I skimmed the page and saw the \u201cvery fine print\u201d that said, \u201cby entering this code you are registering for a monthly service plan for free ringtones\u201d.&#160; No big deal though, right; the page said that I couldn\u2019t be entered because the deal was already full, and I should try signing up for another one.<\/p>\n<p><font size=\"5\"><strong>The Response<\/strong><\/font><\/p>\n<p>So, I wasn\u2019t paying attention, and I didn\u2019t know how cell phone companies support billing services through text messaging.&#160; But at this point, I already knew I had fallen for a scam.&#160; So what did I do?<\/p>\n<p>The first thing I did was get right on the phone to AT&amp;T.&#160; To hell with this company that just told me they couldn\u2019t sign me up because they\u2019re register was full (and I do not mean that euphemistically either) \u2013 I knew I couldn\u2019t trust that as far as I could throw it.&#160; <\/p>\n<p>I immediately got on the phone with AT&amp;T and had them reverse the charges and cancel the reoccurring charges.&#160; I have an appointment with their fraud department tomorrow (they were closed today), so that I can give them as much information as possible so that they can prevent this from happening to other people.&#160; Which leads me to my second step \u2013 I told everyone I know about it.&#160; Sure, in the end, there might be someone who is going to say \u201cHaha, you gots pWned\u201d \u2013 but my response would be STFU (that\u2019s more euphemistically). <\/p>\n<p>You see, these people prey on the lack of communication; they prey on the fact that by jumping through multiple international boundaries they are all but assured they will never be pursued.&#160; They prey on the fact that the cell phone company can just write off a couple million dollars in fraudulent charges.&#160; And yet, the worst thing I could do is not tell everyone I know to keep an eye out, so that they too, are not victimized.<\/p>\n<p>Which comes to the third and final thing I did.&#160; I went to the Internet Crime Complaint Center (<a title=\"http:\/\/www.ic3.gov\/default.aspx\" href=\"http:\/\/www.ic3.gov\/default.aspx\">http:\/\/www.ic3.gov\/default.aspx<\/a>) and the FTC Complaint Center (<a title=\"https:\/\/www.ftccomplaintassistant.gov\/\" href=\"https:\/\/www.ftccomplaintassistant.gov\/\">https:\/\/www.ftccomplaintassistant.gov\/<\/a>) and filled out their complaint forms.&#160; Sure, as small as this fraud attempt was, they could care less; however, perhaps these people have been defrauding individuals out of millions of dollars, perhaps every little bit of evidence they collect increases the chance that that\u2019ll go after these guys.&#160; But in reality, it just gave me a great feeling to tell on them!&#160; LoL<\/p>\n<p><font size=\"5\"><strong>So Remember<\/strong><\/font><\/p>\n<p>In the end, as a consumer surfing the internet (as you likely do \u2013 if you are reading this), keep the following in mind:<\/p>\n<ul>\n<li>Suspect everyone;<\/li>\n<li>Trust no one;<\/li>\n<li>Verify, verify and Verify;<\/li>\n<li>Pay attention;<\/li>\n<li>Educate yourself on the technology you use;<\/li>\n<li>Decrease the possibility that the crime lords will collect anymore money: tell everyone;<\/li>\n<li>If you think you were the victim of internet crime, act immediately!<\/li>\n<\/ul>\n<p>You know, these guys are smart, they\u2019re never going to catch them, even if they go after them.&#160; So in the end, I just tell myself that somewhere in the world, there is an internet crime lord who is having a beer on me.&#160; Drink it up buddy, because it\u2019s going to be awfully hot in hell!&#160; <img decoding=\"async\" style=\"border-bottom-style: none; border-right-style: none; border-top-style: none; border-left-style: none\" class=\"wlEmoticon wlEmoticon-winkingsmile\" alt=\"Winking smile\" src=\"https:\/\/darthjedi.logiodice.com\/blog\/content\/binary\/Windows-Live-Writer\/530af07f5d90_111ED\/wlEmoticon-winkingsmile_2.png\" \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>I started using the internet almost 20 years ago; and while I was a minor, with no job, I gained internet access in sometimes nefarious ways.&#160; I spent my time on the internet staying out of trouble (or not getting caught), but let\u2019s just say that I was no Angel, and my purpose for being &hellip; <a href=\"https:\/\/darthjedi.logiodice.com\/?p=42\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Internet beware \u2013 it all started with the letter E&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[25,28],"tags":[],"class_list":["post-42","post","type-post","status-publish","format-standard","hentry","category-security","category-technology"],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/darthjedi.logiodice.com\/index.php?rest_route=\/wp\/v2\/posts\/42","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/darthjedi.logiodice.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/darthjedi.logiodice.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/darthjedi.logiodice.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/darthjedi.logiodice.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=42"}],"version-history":[{"count":0,"href":"https:\/\/darthjedi.logiodice.com\/index.php?rest_route=\/wp\/v2\/posts\/42\/revisions"}],"wp:attachment":[{"href":"https:\/\/darthjedi.logiodice.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=42"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/darthjedi.logiodice.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=42"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/darthjedi.logiodice.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=42"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}