Tuesday, April 27, 2021

Researcher gets banned for stress testing Linux supply chain by easily adding backdoors to Linux kernel


I guess, even in the intelligent coding/open source community, whistle blowers are not revered but are cast outs. Linux open source team decided to ban University of Minnesota outright for research how easy it is to introduce a Linux kernel backdoor vulnerability into the delivery supply chain. Opps, to close to comfort. Really a sophomoric/moronic response. 


However you feel about what these researchers did (Chris Gaun, for example, argued, "A researcher showed how vulnerabilities can EASILY make it through [the] approval process"), this isn't really about Linux, or open source, security. It's always been the case that it's possible to get bad code into good open source projects. Open source software isn't inherently secure. Rather, it's the open source process that is secure, and while that process kicks in during development, it's arguably most potent after vulnerabilities are discovered.

Source : Greg Kroah-Hartman bans University of Minnesota from Linux development for deliberately buggy patches | ZDNet

Research Paper : qiushiwu.github.io/OpenSourceInsecurity.pdf at main · QiushiWu/qiushiwu.github.io


Tuesday, April 20, 2021

UPS Phishing Email with subject Please note: UPS 2021 | Schedule Confirmation Process | Item no.xxxxxxx


For the record, this is 
UPS phishing email attempt that is recently going around, with subject "Please note: UPS 2021 | Schedule Confirmation Process | Item no.xxxxxxx"


What to do?  Report them, goto bottom of page. 


From : UPS-Canada Schedule Confirm®<atiliofranzoni@hotmail.com>
Subject : 
Please note: UPS-{country} 2021 | Schedule Confirmation Process | Item no.xxxxxxx {date}



                 If you mistakenly click any link, it brings you to a very convincing fake page.







PHISHING LINKs;

Click image by mistake
1. https://difpt.org/.activate/serverxxxxxxUPS.html

How to tell this is a Phishing email ?

  1. Check email address in full, if it's not from originating company then it's phishing.
  2. Hover over all links in email, if it's not from the  company's website then forget it.
  3. The best way is to 

How to examine Email Message Source ?

Now lets look at message source
  1. Outlook.com->Actions->View Message Source. 
  2. Gmail.com->More (down arrow to top right)->Show original.
Check for suspicious links, anything that does not originate from original domain, like apple.com.


Report Phishing Email (not as Spam)

  1. Outlook.com->Junk (at Top)->Phishing Scam
  2. Gmail.com->More (down-arrow to top right)->Report Phishing 

Report Phishing

If you have received this email take further 

  1. https://www.google.com/safebrowsing/report_phish/


Report phishing at Microsoft and government agencies

  1. http://www.microsoft.com/security/online-privacy/phishing-faq.aspx

Sunday, April 11, 2021

Amazon Phishing Email with subject Re: Amazon has a surprise for you


For the record, this is 
Amazon phishing email attempt that is recently going around, with subject "Re: Amazon has a surprise for you"


What to do?  Report them, goto bottom of page. 


From : Welcome <contact@smartlinkshare.com>
Subject : 
Re: Re: A.m.a.z.o.n has a surprise for you











PHISHING LINKs;

Click image by mistake
1. http://masterymail.com/xxxxx.shtml?xxxxxxxxxxxxxxx

How to tell this is a Phishing email ?

  1. Check email address in full, if it's not from originating company then it's phishing.
  2. Hover over all links in email, if it's not from the  company's website then forget it.
  3. The best way is to 

How to examine Email Message Source ?

Now lets look at message source
  1. Outlook.com->Actions->View Message Source. 
  2. Gmail.com->More (down arrow to top right)->Show original.
Check for suspicious links, anything that does not originate from original domain, like apple.com.


Report Phishing Email (not as Spam)

  1. Outlook.com->Junk (at Top)->Phishing Scam
  2. Gmail.com->More (down-arrow to top right)->Report Phishing 

Report Phishing

If you have received this email take further 

  1. https://www.google.com/safebrowsing/report_phish/


Report phishing at Microsoft and government agencies

  1. http://www.microsoft.com/security/online-privacy/phishing-faq.aspx