ts0

ts0

tentative smile

follow me on Twitter!

Criminal Genius

I saw a bit of Ed Gibsons impromptu talk at DDD on security, he's a bit of a caricature of the hard case FBI guy, quite funny though (some people were a bit upset about him hijacking others sessions). One of the points he made was that the criminals out there today aren't interested in your personal details, they don't want to login in to your bank, they want your bandwidth. If they can get a trojan horse on your machine then they can use you as a spam relay. You might think "hangon a minute, I get loads of phishing emails after my personal details", but where do those phishing emails come from? Compromised PCs. Hijacking your bandwidth is just the first step though, they then need to turn that in to money. The people who control the trojan horses simply hire them out to anyone who wants to spam, so then how do the spammers make money? Well a lot of it is just marketing some products, something they can sell easily and make plenty of profit on, like cheap drugs. There are quite a few new tactics on the rise though, like stock spamming. The spammers choose a target company with cheap stock, buy a load up, then spam millions of people telling them about this hot stock tip, for some reason people buy it (maybe they think if they're quick they can make money a long with the spammer), the spammer sells high and the stock quickly crashes. The genius of this technique is that there is no direct link between the spamming, and the money making, there is no need to launder the money or try and move it between countries, you can sit in your aparment in Liverpool and buy up stock online, then hire a spambot network from some Russians. There is another tactic that people are using to extract money from stolen credit cards, this is even more incredible! The person simply creates an account with a stolen card on a betting site, and creates another account with their own card. Then they bet on a sports event on one account, and bets against that event on the other account. If they win on their own card, they withdraw the money, if they win on the stolen card they bet again until it's in their favour. This is called bet matching, and it allows the criminal to withdraw massive amounts of cash from a card, over the internet with absolutlely no traceability! It never ceases to amaze me how money can inspire people to come up with such things, this is the ongoing arms race and it looks like us law abiding folk are loosing! One last thing, lots of betting sites offer some free cash when you setup a new account, which you can't withdraw. It's possible to get that money out though using bet matching, I've heard of quite a few people doing it. Doesn't seem worth the effort to me but if anyones had any success with it let me know!

Labels: , , ,

3 Comments
ts0
Thom Shannon's background in making chips gives him a unique insight into the web development industry. As the Technical Director of Glow New Media he works with clients across the UK to deliver high quality web marketing solutions using the latest techniques, accessibility practices, and web standards in both straight and crinkle cut.


Download a vCard (for Outlook)

Friends



Find Me (and my Social Graph)



RSS Feed

Archives 08.06 09.06 10.06 11.06 12.06 01.07 02.07 03.07 04.07 05.07 06.07 07.07 08.07 09.07 10.07 11.07 12.07 01.08 02.08 03.08 04.08



Thomas Shannon-Smith
Tom Shannon-Smith
Tom Shannon
Thom Shannon-Smith