Path: csiph.com!news.redatomik.org!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail From: Jolly Roger Newsgroups: comp.sys.mac.system Subject: Re: Question about Safari security (spam/malware) Date: 6 Aug 2018 22:27:25 GMT Organization: People for the Ethical Treatment of Pirates Lines: 73 Message-ID: References: X-Trace: individual.net zwPySU1a7+3hFBysL3ZMtQMbgFGU17anQnUI0YKjYAPFUeYIkn Cancel-Lock: sha1:GBv9VEGoUEJgwKvTXaYXdujxTjY= X-No-Archive: Yes MMail-Copies-To: nobody X-Face: _.g>n!a$f3/H3jA]>9pN55*5<`}Tud57>1Y%b|b-Y~()~\t,LZ3e up1/bO{=-) User-Agent: slrn/1.0.1 (Darwin) Xref: csiph.com comp.sys.mac.system:117613 On 2018-08-06, JF Mezei wrote: > I received spam recently which : > ### > xxxxxxxx is your pass. Lets get directly to the purpose. Nobody has > paid me to investigate you. You do not know me and you're probably > wondering why you're getting this mail? > > actually, I actually setup a malware on the X streaming (porn) web-site > and do you know what, you visited this website to have fun (you know > what I mean). While you were viewing video clips, your web browser > started out functioning as a Remote Desktop that has a key logger which > gave me accessibility to your screen as well as web cam. Right after > that, my software gathered every one of your contacts from your > Messenger, FB, as well as e-mail . Next I made a double-screen video. > 1st part displays the video you were viewing (you have a fine taste > haha), and next part shows the recording of your webcam, yeah it is u. > ### > > Where xxxxxx is a password I have used in the past for accounts > associated with my name, and still use on some accounts not associated > with my name. So obviously, that email got my attention. > > I just want a reality check here. > > It is possible that this stems from some old database theft where they > got my email address and password to some store etc, and that this > password has long ago ceased to be in used for serious service, but > still used for porn. That's exactly it. It's a well-known practice. > BUT, as a reality check: > > Could a malware ad running in a window on Safari: > -access list of contacts ? No. > -obtain my identity/email address ? Only if you actively input it in a form. > -capture keystrokes from Safari to capture a password entry? See above. > I know that with the next OS-X, Apple announced that it would act like > IOS in terms of limitiung what information each app can access, which > would lend one to believe that Safari might have the power to access my > contacts right now. Is that a correct assumption? Nope. Take a look at System Preferences > Security & Privacy > Privacy. The only apps that can access your contacts (and other things) are listed there. If an app isn't listed there and asks to access your contacts, you'll see a message from the system asking you if it's okay to grant access to that app. > These guys claim to have captured my webcam, but I have no webcam > connected to my machine. Form mail phishing schemes have to make assumptions like that to scare people into doing their bidding. Social engineering like that obviously works on a lot of people. > Yet, they got my email address and an old password right. Some service you used in the past was compromised. -- E-mail sent to this address may be devoured by my ravenous SPAM filter. I often ignore posts from Google. Use a real news client instead. JR