#SecChat $1 million guarantee 12 Scams of Christmas access to live fraud resolution agents Acquisition Alex Thurber Android antivirus Apple botnet Channel Partners cloud security Compliance Consumer counter identity theft credit card fraud and protection credit fraud alerts credit monitoring credit monitoring and resolution critical infrastructure Cyber Security Mom cyberbullying Cybercrime cybermom data breach data center data center security Data Protection Dave DeWalt DLP Email & Web Security embedded encryption Endpoint Protection enterprise facebook fake anti-virus software Family Safety Friday Security Highlights global threat intelligence google government Hacktivism how to talk to kids how to talk to teens identity fraud identity fraud scams identity protection identity protection $1 million guarantee identity protection fraud identity protection surveillance identity surveillance identity theft identity theft expert identity theft fraud identity theft protection identity theft protection product Identity thieves and cybercriminals intel iphone kids online behavior lost wallet protection malware McAfee McAfee Channel McAfee Family Protection McAfee Identity Protection McAfee Initiative to Fight Cybercrime McAfee Labs McAfee security products Mid-Market Mobile mobile malware mobile security monitor credit and personal information Network Security online personal data protection online safety Operation Aurora PCI personal identity theft fraud personal information loss personal information protection phishing privacy proactive identity protection proactive identity surveillance Public Sector restore credit and personal identity Risk and Compliance scam scams scareware security smartphones social media social networking social networks spam Stuxnet twitter vulnerability Web 2.0 work with victim restore identity
|
|
You can love ‘em or hate ‘em, but you can’t stop people sending them. So what are the risks of HTML e-mail?
With HTML-formatted e-mails anything goes, just like on the Web. Data can be invisible (using small or transparent text), obfuscated (using special tags), dynamic (formed inline during rendering), and scriptable (using client-side scripts such as JavaScript and VBScript).
Common malicious behaviour used in SPAM and Phishing e-mail attacks often use HTML anchor tags to obfuscate malicious URLs from victims–resulting in content where WYSI-most-certainly-NWYG.
Aside from these rather obvious problems, McAfee Avert Labs has seen a steady increase in malware capable of infecting HTML content. I say “content,” as most examples of such malware aren’t fussy about what they infect– ASP, JSP, PHP, and other types fall victim to this contemporary technique.
The infection particulars differ among malware families, but the most popular is simply appending an IFRAME tag to the content using the tag’s src= attribute to dynamically write remote content inline to the victim file. Thus far Downloader-AYJ, W32/Fujacks!htm, W32/Wuke!htm, and (most recently) vicious new Chinese virus W32/Xiaoho!htm use this technique.
Another form of this technique, used extensively by the W32/RAHack!htm family, includes the insertion of an OBJECT tag near the beginning of the Web content. This tag includes a CLASSID= attribute to reference executables files on disk via the system registry. Said executables were previously dropped on the victim’s system and are launched once the compromised Web content is rendered.
So, I hear you ask, what does this have to do with e-mails? Well, since the emergence of this technique we have received several submissions of HTML-formatted e-mails containing such infections! Some submissions were even multiply infected, in which every reply or forward on the thread added an infection. This twist on the distribution technique is one the malware author may not have intended, yet it could have spread his malware further and quicker than anyone may have imagined!
Look at the fictitious figure below and answer me this–Do you still want to have that fancy animated, multicoloured e-mail signature?
|
|
We’re moving from formatted (holiday, car, software, online trading) emails to .PDF attached files with (no subject) spam email and now the text emails that claims you need to (login, claim) something. I received several yesterday, and they seem to be coming through fast. The number of PDF emails has reduced. Surely the service provider should capture and block emails by content type. I have more spam emails than real ones.
Dear Member,
We are glad you joined Office Antics.
Confirmation Number: 71853973
Temorary Login: user2266
Your Password ID: oc669
Please Change your login and change your Login Information.
Follow this Link: http://xxx.xxx.xxx.xxx/
Welcome,
Membership Support Department
Office Antics
Submit your own comments / message for this post