Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.sys.mac.system > #117606 > unrolled thread

Question about Safari security (spam/malware)

Started byJF Mezei <jfmezei.spamnot@vaxination.ca>
First post2018-08-06 15:43 -0400
Last post2018-08-06 21:06 -0400
Articles 14 — 8 participants

Back to article view | Back to comp.sys.mac.system


Contents

  Question about Safari security (spam/malware) JF Mezei <jfmezei.spamnot@vaxination.ca> - 2018-08-06 15:43 -0400
    Re: Question about Safari security (spam/malware) Alan Baker <nunya@ness.biz> - 2018-08-06 12:47 -0700
    Re: Question about Safari security (spam/malware) nospam <nospam@nospam.invalid> - 2018-08-06 15:53 -0400
      Re: Question about Safari security (spam/malware) JF Mezei <jfmezei.spamnot@vaxination.ca> - 2018-08-06 17:20 -0400
    Re: Question about Safari security (spam/malware) Savageduck <savageduck1@{REMOVESPAM}me.com> - 2018-08-06 14:12 -0700
    Re: Question about Safari security (spam/malware) JF Mezei <jfmezei.spamnot@vaxination.ca> - 2018-08-06 17:23 -0400
      Re: Question about Safari security (spam/malware) Wade Garrett <wade@cooler.net> - 2018-08-06 18:26 -0400
      Re: Question about Safari security (spam/malware) Alan Browne <bitbucket@blackhole.com> - 2018-08-06 21:07 -0400
    Re: Question about Safari security (spam/malware) Jolly Roger <jollyroger@pobox.com> - 2018-08-06 22:27 +0000
      Re: Question about Safari security (spam/malware) JF Mezei <jfmezei.spamnot@vaxination.ca> - 2018-08-06 23:00 -0400
        Re: Question about Safari security (spam/malware) Jolly Roger <jollyroger@pobox.com> - 2018-08-07 03:35 +0000
          Re: Question about Safari security (spam/malware) JF Mezei <jfmezei.spamnot@vaxination.ca> - 2018-08-07 10:56 -0400
    Re: Question about Safari security (spam/malware) Lewis <g.kreme@gmail.com.dontsendmecopies> - 2018-08-06 23:18 +0000
    Re: Question about Safari security (spam/malware) Alan Browne <bitbucket@blackhole.com> - 2018-08-06 21:06 -0400

#117606 — Question about Safari security (spam/malware)

FromJF Mezei <jfmezei.spamnot@vaxination.ca>
Date2018-08-06 15:43 -0400
SubjectQuestion about Safari security (spam/malware)
Message-ID<Yx1aD.12364$XA2.11193@fx38.iad>
I received spam recently which :
###
 xxxxxxxx is your pass. Lets get directly to the purpose. Nobody has
paid me to investigate you. You do not know me and you're probably
wondering why you're getting this mail?

actually, I actually setup a malware on the X streaming (porn) web-site
and do you know what, you visited this website to have fun (you know
what I mean). While you were viewing video clips, your web browser
started out functioning as a Remote Desktop that has a key logger which
gave me accessibility to your screen as well as web cam. Right after
that, my software gathered every one of your contacts from your
Messenger, FB, as well as e-mail . Next I made a double-screen video.
1st part displays the video you were viewing (you have a fine taste
haha), and next part shows the recording of your webcam, yeah it is u.
###

Where xxxxxx is a password I have used in the past for accounts
associated with my name, and still use on some accounts not associated
with my name.  So obviously, that email got my attention.

I just want a reality check here.

It is possible that this stems from some old database theft where they
got my email address and password to some store etc, and that this
password has long ago ceased to be in used for serious service, but
still used for porn.

BUT, as a reality check:

Could a malware ad running in a window on Safari:
	-access list of contacts ?
	-obtain my identity/email address ?
	-capture keystrokes from Safari to capture a password entry?


I know that with the next OS-X, Apple announced that it would act like
IOS in terms of limitiung what information each app can access, which
would lend one to believe that Safari might have the power to access my
contacts right now. Is that a correct assumption?


These guys claim to have captured my webcam, but I have no webcam
connected to my machine. Yet, they got my email address and an old
password right.

Again, I am interested in reality check of what is technically possible
or not.

[toc] | [next] | [standalone]


#117607

FromAlan Baker <nunya@ness.biz>
Date2018-08-06 12:47 -0700
Message-ID<pka8kb$cf8$1@gioia.aioe.org>
In reply to#117606
On 2018-08-06 12:43 PM, JF Mezei wrote:
> I received spam recently which :
> ###
>   xxxxxxxx is your pass. Lets get directly to the purpose. Nobody has
> paid me to investigate you. You do not know me and you're probably
> wondering why you're getting this mail?
> 
> actually, I actually setup a malware on the X streaming (porn) web-site
> and do you know what, you visited this website to have fun (you know
> what I mean). While you were viewing video clips, your web browser
> started out functioning as a Remote Desktop that has a key logger which
> gave me accessibility to your screen as well as web cam. Right after
> that, my software gathered every one of your contacts from your
> Messenger, FB, as well as e-mail . Next I made a double-screen video.
> 1st part displays the video you were viewing (you have a fine taste
> haha), and next part shows the recording of your webcam, yeah it is u.
> ###
> 
> Where xxxxxx is a password I have used in the past for accounts
> associated with my name, and still use on some accounts not associated
> with my name.  So obviously, that email got my attention.
> 
> I just want a reality check here.
> 
> It is possible that this stems from some old database theft where they
> got my email address and password to some store etc, and that this
> password has long ago ceased to be in used for serious service, but
> still used for porn.

Yes. That is almost certainly what this is.

They got your email and an old password from some database hack where 
the data is available online.

Check here:

<https://haveibeenpwned.com/>

> 
> BUT, as a reality check:
> 
> Could a malware ad running in a window on Safari:
> 	-access list of contacts ?
> 	-obtain my identity/email address ?
> 	-capture keystrokes from Safari to capture a password entry?
> 
> 
> I know that with the next OS-X, Apple announced that it would act like
> IOS in terms of limitiung what information each app can access, which
> would lend one to believe that Safari might have the power to access my
> contacts right now. Is that a correct assumption?

No. That is an ignorant assumption.

> 
> 
> These guys claim to have captured my webcam, but I have no webcam
> connected to my machine. Yet, they got my email address and an old
> password right.
> 
> Again, I am interested in reality check of what is technically possible
> or not.
> 

[toc] | [prev] | [next] | [standalone]


#117608

Fromnospam <nospam@nospam.invalid>
Date2018-08-06 15:53 -0400
Message-ID<060820181553192327%nospam@nospam.invalid>
In reply to#117606
In article <Yx1aD.12364$XA2.11193@fx38.iad>, JF Mezei
<jfmezei.spamnot@vaxination.ca> wrote:

> I received spam recently which :
> ###
>  xxxxxxxx is your pass. Lets get directly to the purpose. Nobody has
> paid me to investigate you. You do not know me and you're probably
> wondering why you're getting this mail?
>
> actually, I actually setup a malware on the X streaming (porn) web-site
> and do you know what, you visited this website to have fun (you know
> what I mean). While you were viewing video clips, your web browser
> started out functioning as a Remote Desktop that has a key logger which
> gave me accessibility to your screen as well as web cam. Right after
> that, my software gathered every one of your contacts from your
> Messenger, FB, as well as e-mail . Next I made a double-screen video.
> 1st part displays the video you were viewing (you have a fine taste
> haha), and next part shows the recording of your webcam, yeah it is u.
> ###
>
> Where xxxxxx is a password I have used in the past for accounts
> associated with my name, and still use on some accounts not associated
> with my name.  So obviously, that email got my attention.

<https://krebsonsecurity.com/2018/07/sextortion-scam-uses-recipients-hac
ked-passwords/>

[toc] | [prev] | [next] | [standalone]


#117610

FromJF Mezei <jfmezei.spamnot@vaxination.ca>
Date2018-08-06 17:20 -0400
Message-ID<RY2aD.27953$_Y1.11950@fx33.iad>
In reply to#117608
On 2018-08-06 15:53, nospam wrote:
> <https://krebsonsecurity.com/2018/07/sextortion-scam-uses-recipients-hac
> ked-passwords/>


Savaduck wrote:
<https://www.usatoday.com/story/money/business/2018/08/05/porn-email-
scam/903000002/>


Alan Baker wrote:
<https://haveibeenpwned.com/>


Thanks guys.

Good to know this is an old data breach.  Still scary though.

However, question linger:

Outside of this partucular event, it is possible for a web page with
malicious code running on Safari:
- to access my email address
- to access my contacts ?

[toc] | [prev] | [next] | [standalone]


#117609

FromSavageduck <savageduck1@{REMOVESPAM}me.com>
Date2018-08-06 14:12 -0700
Message-ID<0001HW.2118F13F001C026D700007EEB2CF@news.giganews.com>
In reply to#117606
On Aug 6, 2018, JF Mezei wrote
(in article <Yx1aD.12364$XA2.11193@fx38.iad>):

> I received spam recently which :
> ###
> xxxxxxxx is your pass. Lets get directly to the purpose. Nobody has
> paid me to investigate you. You do not know me and you're probably
> wondering why you're getting this mail?
>
> actually, I actually setup a malware on the X streaming (porn) web-site
> and do you know what, you visited this website to have fun (you know
> what I mean). While you were viewing video clips, your web browser
> started out functioning as a Remote Desktop that has a key logger which
> gave me accessibility to your screen as well as web cam. Right after
> that, my software gathered every one of your contacts from your
> Messenger, FB, as well as e-mail . Next I made a double-screen video.
> 1st part displays the video you were viewing (you have a fine taste
> haha), and next part shows the recording of your webcam, yeah it is u.
> ###
>
> Where xxxxxx is a password I have used in the past for accounts
> associated with my name, and still use on some accounts not associated
> with my name. So obviously, that email got my attention.
>
> I just want a reality check here.
>
> It is possible that this stems from some old database theft where they
> got my email address and password to some store etc, and that this
> password has long ago ceased to be in used for serious service, but
> still used for porn.
>
> BUT, as a reality check:
>
> Could a malware ad running in a window on Safari:
> -access list of contacts ?
> -obtain my identity/email address ?
> -capture keystrokes from Safari to capture a password entry?
>
> I know that with the next OS-X, Apple announced that it would act like
> IOS in terms of limitiung what information each app can access, which
> would lend one to believe that Safari might have the power to access my
> contacts right now. Is that a correct assumption?
>
> These guys claim to have captured my webcam, but I have no webcam
> connected to my machine. Yet, they got my email address and an old
> password right.
>
> Again, I am interested in reality check of what is technically possible
> or not.

This is just phishing with fresh bait.

<https://www.usatoday.com/story/money/business/2018/08/05/porn-email-
scam/903000002/>

-- 

Regards,
Savageduck

[toc] | [prev] | [next] | [standalone]


#117611

FromJF Mezei <jfmezei.spamnot@vaxination.ca>
Date2018-08-06 17:23 -0400
Message-ID<a%2aD.27954$_Y1.18119@fx33.iad>
In reply to#117606
BTW, you can thank my recent silence on my crank which broke on bicycle.
Ambulance ride to trauma centre, clavicle broken in 3 places, 3 broken
ribs, punctured lung.

Enjoy my reduced activity here while I recover :-)

[toc] | [prev] | [next] | [standalone]


#117612

FromWade Garrett <wade@cooler.net>
Date2018-08-06 18:26 -0400
Message-ID<pkahuj$917$1@news.albasani.net>
In reply to#117611
On 8/6/18 5:23 PM, JF Mezei wrote:
> BTW, you can thank my recent silence on my crank which broke on bicycle.
> Ambulance ride to trauma centre, clavicle broken in 3 places, 3 broken
> ribs, punctured lung.
> 
> Enjoy my reduced activity here while I recover :-)
> 

Why did the crank fail? If defective, you've got the makings of a pretty 
good product liability/personal injury case.

-- 
The truth will become known eventually.
					- William Shakespeare

[toc] | [prev] | [next] | [standalone]


#117617

FromAlan Browne <bitbucket@blackhole.com>
Date2018-08-06 21:07 -0400
Message-ID<HeGdnTH7R5dIbfXGnZ2dnUU7-cGdnZ2d@giganews.com>
In reply to#117611
On 2018-08-06 17:23, JF Mezei wrote:
> BTW, you can thank my recent silence on my crank which broke on bicycle.
> Ambulance ride to trauma centre, clavicle broken in 3 places, 3 broken
> ribs, punctured lung.
> 
> Enjoy my reduced activity here while I recover :-)
> 

Get well - sounds like a drag.

-- 
"2/3 of Donald Trump's wives were immigrants.  Proof that we
  need immigrants to do jobs that most Americans wouldn't do."
                                           - unknown protester

[toc] | [prev] | [next] | [standalone]


#117613

FromJolly Roger <jollyroger@pobox.com>
Date2018-08-06 22:27 +0000
Message-ID<fss0adFipijU1@mid.individual.net>
In reply to#117606
On 2018-08-06, JF Mezei <jfmezei.spamnot@vaxination.ca> wrote:
> I received spam recently which :
> ###
>  xxxxxxxx is your pass. Lets get directly to the purpose. Nobody has
> paid me to investigate you. You do not know me and you're probably
> wondering why you're getting this mail?
>
> actually, I actually setup a malware on the X streaming (porn) web-site
> and do you know what, you visited this website to have fun (you know
> what I mean). While you were viewing video clips, your web browser
> started out functioning as a Remote Desktop that has a key logger which
> gave me accessibility to your screen as well as web cam. Right after
> that, my software gathered every one of your contacts from your
> Messenger, FB, as well as e-mail . Next I made a double-screen video.
> 1st part displays the video you were viewing (you have a fine taste
> haha), and next part shows the recording of your webcam, yeah it is u.
> ###
>
> Where xxxxxx is a password I have used in the past for accounts
> associated with my name, and still use on some accounts not associated
> with my name.  So obviously, that email got my attention.
>
> I just want a reality check here.
>
> It is possible that this stems from some old database theft where they
> got my email address and password to some store etc, and that this
> password has long ago ceased to be in used for serious service, but
> still used for porn.

That's exactly it. It's a well-known practice.

> BUT, as a reality check:
>
> Could a malware ad running in a window on Safari:
> 	-access list of contacts ?

No.

> 	-obtain my identity/email address ?

Only if you actively input it in a form.

> 	-capture keystrokes from Safari to capture a password entry?

See above.

> I know that with the next OS-X, Apple announced that it would act like
> IOS in terms of limitiung what information each app can access, which
> would lend one to believe that Safari might have the power to access my
> contacts right now. Is that a correct assumption?

Nope. Take a look at System Preferences > Security & Privacy > Privacy.
The only apps that can access your contacts (and other things) are
listed there. If an app isn't listed there and asks to access your
contacts, you'll see a message from the system asking you if it's okay
to grant access to that app. 

> These guys claim to have captured my webcam, but I have no webcam
> connected to my machine. 

Form mail phishing schemes have to make assumptions like that to scare
people into doing their bidding. Social engineering like that obviously
works on a lot of people.

> Yet, they got my email address and an old password right.

Some service you used in the past was compromised.

-- 
E-mail sent to this address may be devoured by my ravenous SPAM filter.
I often ignore posts from Google. Use a real news client instead.

JR

[toc] | [prev] | [next] | [standalone]


#117618

FromJF Mezei <jfmezei.spamnot@vaxination.ca>
Date2018-08-06 23:00 -0400
Message-ID<pX7aD.45525$oW2.21224@fx41.iad>
In reply to#117613
On 2018-08-06 18:27, Jolly Roger wrote:

> Nope. Take a look at System Preferences > Security & Privacy > Privacy.

Thanks.  Wioth Firefox having become unreliable at rendering certain web
sitres for me, I have increased my reliance on Safari but know little of
it.  Those settings tell me that no malware within Safari process should
have access to my contacts.


> Form mail phishing schemes have to make assumptions like that to scare
> people into doing their bidding. Social engineering like that obviously
> works on a lot of people.

Yep, I realize this. But since this one had a passwords which I have
used, I took it a but more seriously and wanted to find out if any of
their claims were possible. I knew the web cam wasn't because mine isn't
normally connected.

[toc] | [prev] | [next] | [standalone]


#117620

FromJolly Roger <jollyroger@pobox.com>
Date2018-08-07 03:35 +0000
Message-ID<fssibjFmb43U1@mid.individual.net>
In reply to#117618
On 2018-08-07, JF Mezei <jfmezei.spamnot@vaxination.ca> wrote:
> On 2018-08-06 18:27, Jolly Roger wrote:
>
>> Nope. Take a look at System Preferences > Security & Privacy > Privacy.
>
> Thanks.  Wioth Firefox having become unreliable at rendering certain web
> sitres for me, I have increased my reliance on Safari but know little of
> it.  Those settings tell me that no malware within Safari process should
> have access to my contacts.
>
>> Form mail phishing schemes have to make assumptions like that to scare
>> people into doing their bidding. Social engineering like that obviously
>> works on a lot of people.
>
> Yep, I realize this. But since this one had a passwords which I have
> used, I took it a but more seriously and wanted to find out if any of
> their claims were possible. I knew the web cam wasn't because mine isn't
> normally connected.

I highly recommend going to https://haveibeenpwned.com and then search
your keychain for any accounts using that account and change their
passwords ASAP.

-- 
E-mail sent to this address may be devoured by my ravenous SPAM filter.
I often ignore posts from Google. Use a real news client instead.

JR

[toc] | [prev] | [next] | [standalone]


#117625

FromJF Mezei <jfmezei.spamnot@vaxination.ca>
Date2018-08-07 10:56 -0400
Message-ID<XqiaD.24271$ZU.21595@fx02.iad>
In reply to#117620
On 2018-08-06 23:35, Jolly Roger wrote:

> I highly recommend going to https://haveibeenpwned.com and then search
> your keychain for any accounts using that account and change their
> passwords ASAP.

The association between my real email and that password was broken a
long time ago.  But that password still used for unimportant accounts
not associated with me (aka porn sites etc).

[toc] | [prev] | [next] | [standalone]


#117614

FromLewis <g.kreme@gmail.com.dontsendmecopies>
Date2018-08-06 23:18 +0000
Message-ID<slrnpmhlqa.1pj5.g.kreme@jaka.lan>
In reply to#117606
In message <Yx1aD.12364$XA2.11193@fx38.iad> JF Mezei <jfmezei.spamnot@vaxination.ca> wrote:
> I received spam recently which :
> ###
>  xxxxxxxx is your pass. Lets get directly to the purpose. Nobody has
> paid me to investigate you. You do not know me and you're probably
> wondering why you're getting this mail?

This is phishing spam.

> Where xxxxxx is a password I have used in the past for accounts
> associated with my name, and still use on some accounts not associated
> with my name.  So obviously, that email got my attention.

With the number of massive database dumps from many many companies, if
you reuse passwords, you will get hacked.

Get a password manager (I use 1Password, but Last Pass is good and
cheap) and use unique random passwords for every login.

> Could a malware ad running in a window on Safari:
> 	-access list of contacts ?

No.

> 	-obtain my identity/email address ?

No.

> 	-capture keystrokes from Safari to capture a password entry?

Yes, if it was running on the site.

-- 
Procrastination is the art of keeping up with yesterday.

[toc] | [prev] | [next] | [standalone]


#117616

FromAlan Browne <bitbucket@blackhole.com>
Date2018-08-06 21:06 -0400
Message-ID<HeGdnTb7R5cVbfXGnZ2dnUU7-cGdnZ2d@giganews.com>
In reply to#117606
On 2018-08-06 15:43, JF Mezei wrote:
> I received spam recently which :
> ###
>   xxxxxxxx is your pass. Lets get directly to the purpose. Nobody has
> 

Did you ever have a Yahoo account?

I received the same phish about 2 weeks ago - the password mentioned was 
(possibly) my Yahoo password from about 10 years ago.

I bailed on Yahoo a couple years ago - shut my account - but even /then/ 
when they managed to get attacked, closed account data was stolen as well.


-- 
"2/3 of Donald Trump's wives were immigrants.  Proof that we
  need immigrants to do jobs that most Americans wouldn't do."
                                           - unknown protester

[toc] | [prev] | [standalone]


Back to top | Article view | comp.sys.mac.system


csiph-web