A recently disclosed fraud involving hundreds of thousands of people on the Monster.com jobs Web site reveals the perils of leaving detailed personal information online, security analysts say.
Before the scheme was uncovered last week by researchers at Symantec Corp., con artists had filched legitimate user names and passwords from recruiters who search for job candidates on Monster. Then with access into the Monster system, the hackers grabbed resumes and used information on those documents to craft personalized ''phishing'' e-mails to job seekers.
''What phishers are trying to do these days is make them as realistic as possible, by adding specific information,'' said Patrick Martin, a Symantec product manager. ''If they know you've submitted a resume to Monster, that makes it (seem) a little more legitimate.''
If the recipients took the bait, they had spyware or other malicious programs secretly installed on their computers. But even if the phishing attempt wasn't successful, the names, addresses and other details on the resumes can themselves be lucrative.
A server in the Ukraine used in the scheme held 1.6 million entries. Because of duplications, Symantec said those files actually held personal information for ''several hundred thousand'' job seekers. Another antivirus firm, Authentium Inc., said it parsed the same data and counted 1.2 million people.
Symantec said it relayed details to Monster.com so it could disable the compromised recruiter accounts. But the security company also advised Web users to limit their exposure to such frauds by reducing the amount of personal information they post on the Internet.
That advice was echoed in other corners. Ron O'Brien, senior security analyst for Sophos PLC, suggested that job seekers provide only minimal details about themselves on job sites, and then reveal deeper information only for queries that prove to be legitimate.
The same standards should apply on social networking sites such as Facebook that ask for a wealth of information, O'Brien said.
''With very little effort, I could put together a profile of you that includes such information as your home address, your home phone number, your e-mail address, your birthday,'' O'Brien said. ''We need to kind of take a step back and decide whether it's really required for us to provide all the information requested of us. ... We have become a nation of people who want to be cooperative.''
Other security specialists said Monster might share the blame if it doesn't ensure that people with access to its system use ''strong'' passwords that are frequently changed or hard to guess.
''They have a major responsibility when they have this information,'' said Laura Yecies, a vice president of Check Point Software Technologies Ltd.
Representatives for Monster Worldwide Inc., the New York-based parent company of the jobs site, did not return messages seeking comment.
On its Web site, the company advises its members to be extremely cautious about e-mails purporting to be from recruiters - advice that goes for all unsolicited messages.
To spot phishing attempts, look for misspellings or grammatical mistakes in the messages. Even if an e-mail passes that smell test, don't click on links in the e-mail or fill out forms asking for information. And if the message offers a deal that is too good to be true - such as easy money - it probably is.
Phishing Attack Plunders Monster.com
By: AP
| Aug 23,2007
| Ads by Google | ||
Why don't you post one?
LATEST NEWS
- Creators of Scrabble Knockoff on Facebook Sued
- Asus Launches Eee PC 1000H, 904H Netbooks in India
- Motorola Launches Ferrari Edition V9 in India
- Nokia, Qualcomm Settle Long-running Dispute
- Samsung Launches 8MP Camera Phone
- Microsoft Reorganizes its Online Services
- Google Launches Wikipedia Competitor, knol
- Sony Opens Up e-book Reader to Other Booksellers
- Facebook to Help Some Programmers, Punish Others
- Our C902 Cyber-shot Contest Goes Live!
| Ads by Google | ||
RELATED
| Ads by Google |
Hot Searches & Keywords :
AMD
ATI
Adobe
Apple
Asus
Benq
Blackberry
Blizzard
Blu-Ray
Bluetooth
CES 2007
CES 2008
Canon
Capcom
China
Creative
DVD
Dell
E3 2007
E3 2008
EA
Electronic Arts
Gears of War
Google
HP
Halo
IBM
ITunes
Intel
Internet
Ipod
LCD
LG
Linux
Logitech
Microsoft
Mobile
Mobile Phone
Mobile Phones
Motorola
Mp3
Myspace
Nintendo
Nokia
Nvidia
PC
PMP
PS2
PS3
PSP
Philips
Reliance Communications
Samsung
Sandisk
Search Engine
Skype
Smartphone
Sony
Sony Ericsson
Toshiba
Ubisoft
Valve
Vista
Voip
Website
Wi-Fi
Wii
Windows
Windows Mobile
Windows Vista
Xbox 360
Xbox Live
Xbox360
Yahoo!
Youtube
Zune
digicam
digital camera
iPhone
mp3 player
printer
social networking site
test
yahoo
| Ads by Google | ||
|
|
Sections
Products
Camcorders |
Controllers |
CPUs |
Desktop PCs |
Digital Cameras |
Digital Video Recorders |
DVD Players |
Games |
Gaming Consoles |
General |
GPS Systems |
Handhelds / PDAs |
Hard Drives |
Headphones & Headsets |
HiFi Audio Systems |
Home Theater Systems |
Input Devices |
Internet |
Laptops |
Low Level Components |
Mac Systems |
Mobile Phone Accessories |
Mobile Phones |
Monitors |
Motherboards |
MP3 / Audio Players |
Multi-Function Devices |
Networking |
Optical Drives |
PC Accessories |
PC Add-on Cards |
PC Cabinets |
PC Games |
Printers |
Projectors |
RAM Modules |
Scanners |
Software |
Speakers |
Telecom |
TVs |
Video Players |