Skip to main content

Of Phishing and Spam

I dont usually use my Yahoo! Mail anymore but still, I occasionally check if there are still important emails arriving at that address. From time to time, I also check the spam folder just incase Yahoo! wrongly classifies an email as spam.


But then again, there are really spam emails and one particular email caught my attention. It was allegedly from Amazon pertaining to an order I made. It was an email receipt for that 'item'.

Click for larger view

There are things that are pretty much obvious for the trained eye but for those people who are a bit clueless, its a big problem.

For example, if you see the complete snapshot above, you could see that my name and my email are spelled wrong. I am not Allan Muigai, nor my email is not allanmuigai@yahoo.com .. Some people might react to this as an innocent typo error.. Well, ITS NOT. If its a typo, the email wont be able to get delivered to your inbox.


Heres another tricky one, when you check the sender.. At first glance, you could tell that the email came from Amazon.. Sadly, those stuff could be faked.


 The last and important bit of information could be checked from the clickable links on the email. When I put my mouse over the Amazon logo, it should be a link going to their official website (http://www.amazon.com) but then again, if you see the status bar, its going to take you to another website.. Which could either be a website planting a malicious software on your computer or a site which looks like amazon and will ask you to log in.


Careful, if you fall for these traps, once you enter your login information.. Your account is already compromised.

Stay safe, the internet is a warzone.

Comments

Popular posts from this blog

Self Signed SSL Certificates

Ever wondered how to enable SSL or HTTPS on your site? If you dont want to pay for commercial SSL certificates, you could create self signed certificates for your site by following the instructions here: https://www.digitalocean.com/community/articles/how-to-create-a-ssl-certificate-on-apache-for-ubuntu-12-04 The instructions in the site above will make your default site HTTPS enabled. If you prefer having a commercial SSL, save your certificate files and key files in your server and edit the location on the /etc/apache2/sites-enabled/default to point to the directory where you stored those files.

Moving to a New Linux Web Based Torrent Client

For years, I have been using TorrentFlux (url here) as my primary torrent client situated in my Ubuntu download server. But as time went on, the developers completely abandoned the development of TorrentFlux which led to several forks which I think is still insufficient for my needs. Main GUI of TorrentFlux Ive checked several options which runs on a GUI-less environment. Since my Ubuntu server is just running on command line to save precious memory, I needed something bare, simple and is packed with features. Installing uTorrent Server is pretty straight forward. Download. Uncompress. Run. This is better than the approach of TorrentFlux which you need to setup LAMP server and create a database. More often than not, it happens to me that some of the data in the DB gets corrupted. I normally just reinstall the whole thing again. Main GUI of uTorrent Server To further elaborate on the setup process, I've gotten an excerpt from this thread which, quite simply discusses ho...

Modernizing Qwtlys Database Part 1

Its been years since I have last updated Qwtly and I was given the opportunity to play around and modernize the database for my application. I wanted to try the cloud offering of MongoDB called Atlas being that its free for a small database.  With this in mind and considering that Qwtly doesn't get traffic after I have disabled the add, edit and delete quote function along with the login, I don't see the application getting to that limit of 5GB anyway. Well, that is considering if I can even get this to work.  The first order of business was to see if we can import the MySQL export painlessly to MongoDB Atlas. I have searched for MongoDB tools, external tools, scripts, only to find old abandoned projects which would not be ideal given my situation. I have considered writing a PHP script to do it but that too would cost time. I was looking for something that consists of using existing tools or features I am familiar with along with some manual eyballing and checking. Luckily, ...