Tuesday, January 21, 2020

UGLY EXPLOIT: Sneaky Phisher Goes for Google, Microsoft, Office 365 on PC, Smartphones too?

I received a bogus email from my spouse, sent to my @msn.com email address.  It arrived on my Google Pixel (shown arriving by each of my phone's Outlook and Gmail apps).  It also arrived on my PC in Office 365 desktop Outlook.

Here is a facsimile I created by forwarding the message to myself, changing the names and email accounts accordingly to protect the identification of the exploited victim.

Beware of Any eMail that resembles this, with just the names changed




  • In the actual exploit emails, the "To:" entry is empty.
  • There is no attachment.  The Adobe icon is an image, not a link.
  • The exploit is via the Original URL of the link "Open"
  • The URL is not wrapped for checking as a Safe Link.  The copy I mailed to myself has a safe-link-check wrapper URL; that's not the case with the ones received from the attackers.
IF YOU SEE ONE OF THESE, DO NOT CLICK THE "Open" LINK.

Background

On January 20 (a US holiday, always a good day for exploits), my spouse received an email on the same pattern as the one fabricated above.  
  • It was from someone known to my spouse, but not a regular correspondent.
  • It was from that person's @hotmail.com email address.
  • The bottom line was "Sent from my iPhone" rather than "Get Outlook ... ".
  • The link ending "0ogctna2j3" is the same.
  • My spouse did attempt the "Open" 
  • Doing that now opens a fake "Google Drive" login page on my spouse's PC.
    • The fake I see is at a sercin.co.mz page for a site that has likely been compromised.
    • The Google Drive login handily accepts Google Mail, Microsoft, Office 365, and Other Email logins.
    • It is a phishing for credential attack at this point, and offering a login will have awful consequences, depending on which one is chosen and submitted.
  • At that point, a glance at the browser address bar should reveal that there is something awful at hand.
I learned of this exploit by receiving the exploit email to my @msn.com address from my wife's @msn.com address.  This is also the Microsoft Account that is tied to her Windows 10 PC.

It also appears that there has been scraping of my spouse's Contacts @msn.com (essentially, Hotmail now named outlook.com) that are shared on her Pixel 3, along with the Outlook.com calendar.  Those contacts are no longer accessible from her Office 365 Outlook contacts screen.

In addition, she has since received an apparent "Security advisory" email from Google.  This may be legitimate, except it is asking for confirmation using an email address password that has nothing to do with Google.  We will see.

Precautions

If you ever receive an email that offers you an attachment, whether an image, a PDF, or anything else, AND YOU WERE NOT ALREADY EXPECTING IT, DO NOT ATTEMPT TO OPEN IT WITHOUT CONFIRMATION FROM THE ALLEGED SENDER.

There are other clues.  Brief and innocuous content with no explanation.  Strangeness in the salutation or ending name.  IF YOU MISTAKENLY CLICK AND END UP AT WHAT SEEMS LEGITIMATEDO NOT LOG IN.  JUST DON'T.  On your desktop machine the browser should show you a URL (in the address window) that seems completely unrelated to what the page you are viewing is identified as being.  That's another clue:



Wednesday, December 11, 2019

Uncomfortable Truth: Links Are Not Forever

If You Can Read This …

You’ve followed a link where the original target has gone missing and there is no meaningful substitute.  Link rot won.  When I find and mend such broken links, the substituted link brings you here when there is no meaningful alternative.  I can do no more.

What this is about.

Enduring Visibility

From time to time, I receive an email from some cyberspace denizen to report a broken link on an ancient in blog-years post of mine. 

It is gratifying that someone is examining such material.  I recognize that the link explorers are looking for places to propose substitution of links that they want promoted.  And the reports are valuable.  I trust this is satisfying and rewarding gig-economy effort.

Sometime, the report inspires me to find an appropriate substitute link,  not always one offered by the reporter unless there is context suitability.  In other cases, I cannot find any meaningful substitution whatsoever.

That was the case with this post from 2005-03-24.  There’s nothing to be done for it. 

In that and other cases, removing the hyperlinks makes the post somehow meaningless.  Maybe it is anyhow.  My alternative is to implement the present page as a target for all the cases where the target of links was essential to a blog narrative and the vanished linkees are subjects of discussion.

An Awkward Persistence

It’s pleasing to me that I can still repair all of those old blog posts and other web content of mine.  They were posted onto a web-hosting site of my own and backed up onto a local PC.  I’d adopted a site-server model implemented with a local installation of IIS Server integrated with FrontPage extensions and Visual Source Safe.  Synchronizing transfers and backups were, and still are, with WS_FTP.  I never relied on the Site Server product, but its deployment model, a remarkable form of source-controlled continuous integration supporting private review before public publishing.

The arrangement has been remarkable durable yet all of the software that I rely upon has been obsoleted.  With the failure of a Tablet PC running Windows XP that I access via XP clients under VirtualBox on Windows 10, this too might finally pass.

The Recent Items sidebar links on the page that inspired this post were all  broken for some other reason.  I suspect it was a Blogger hiccup.  That was another reason I used the no-longer-supported Blogger provision for publishing to my own site.

Note to Self: It would be valuable to replace the home pages of legacy/retired blogs with something that indicates where any continuation can be found.  While I have the technology.

Thursday, November 14, 2019

Spanner Wingnut Respawned

I rebooted Spanner Wingnut’s Muddleware Lab on Blogger to assist me in Blogger template choice and customization.  That is the 4th incarnation.

I think I have learned how to get reflow and margin extension working, at least on the default Blogger template.  It remains to confirm that the technique works here with what I suspect is a theme of the “Simple” family with no background.  I’ll now when I replicate it there and see if my discovered customizations succeed.

Saturday, November 9, 2019

Margin, Margin, Who Has the Margin

I was despairing over how the sidebar leaks over images that are too wide for the body column.  It was my main annoyance with how the current Blogger was handling my images.

Looking at the legacy Orcmid’s Lair, I realized that the solution I already knew was to put the sidebar on the left of the body, even though the body does not reflow well as the browser window is expanded/shrunk horizontally, thanks to “improvements” in the HTML specifications and the styling used by Blogger.  I don’t know if the level at which Blogger provides advanced formatting control will allow me to solve that problem.  Being a proud card-carrying member of Raymond Chen’s Backward Compatibility cult, this annoys me no end.

Notice that a new category/label, “Professor von Clueless” has been added along with this post.  That’s in homage to geeky, developer-related posts and another legacy Blogger blog.

Thursday, November 7, 2019

World Digital Preservation Day 2019

I’m not certain preserving media, whether floppy disks or CDs, is getting the job done, although it certainly can’t be done without that much. #WDPD2019

Orcmid’s Lair Rebooted

This is not the first Orcmid’s Lair.  Reconstitution here is an effort to make blogging easy to restore and continue, especially on behalf of the Miser Project, my career capstone effort.

The Conundrum

I am torn between using Blogger for reconstituted and continuing blogs and, for The Miser Project, using GitHub as a place for publishing blogs as well as  project code and other documentation. 

I expect I will continue casual use of Blogger in the manner of this post, and still look for something better for The Miser Project, probably based on GitHub.

GitHub Niceties

The advantage of using GitHub is having version control and a way of archiving everything. 

The disadvantage is having to use Markdown, not having the convenience of Live Writer, and needing to be devops for the blog creation and publishing process, likely based on Node.js with all that entails.  More freedom, many more dependencies, yet more control, maybe even having MathJax. 

Blogger Convenience

The advantage of Blogger is that I can use Live Writer, there is next to nothing in terms of devops, and I have all the Live Writer drafts on my PC for archiving any way I want, including via OneDrive.   And RSS feeds are also available as another form of preservation.

Definitive Miser Project materials are still version-controlled on GitHub and I can make Markdown pages there to have more-appealing technical documentation. 

The disadvantage of clinging to Blogger is the lack of version management and the tendency of Google to “improve” Blogger from time to time.  I am also quite restricted in terms of formatting and plug-in options.

Deja Vu All Over Again

The original Orcmid’s Lair blog was initiated via Blogger on 2002-10-28.  It took a while to figure things out. 

After having a number of posts lost due to disconnects and other interruptions in the midst of editing, I learned to use an early version of BlogJet as an authoring tool.

Later I came to know and love Windows Live Writer.  I am creating this post with Open Live Writer, despite some deficiencies with integration in its Blogger setup.

I also succeeded in using Windows Live Writer to recover some older posts and reconstitute them here under the Miser Project category.

The Preservation Urge

I have succeeded in preserving all of my old blogs, their archives, and the RSS feeds.  This was mainly possible by preservation on my own web sites.  I love that continuity.  And apparently, there are posts that still catch the attention of others.  I want to continue having that durability.

Wednesday, October 30, 2019

Well, That Didn’t Go Well

I was able to recover a Miser Project post to this blog using the original post date.
  1. I couldn’t just use the draft in Open LiveWriter that I used for the original post.  It just wouldn’t go. [2019-11-07T10:24 I have workarounds now.  Not entirely satisfying but good enough for casual blogging.]
  2. So I used the web-page creator for Blogger posts, with copy and paste of the original text, and reloading of the screen capture I used for the WordPress image.
    [2019-11-07T10:23 Once I get a post into Blogger, I can retrieve and update it using Live Writer though.]
  3. [2019-11-07T10:22 I have enough work-arounds for this, but the layout is not pleasing, especially when the sidebar becomes long enough to overlap images in the body text.]
  4. Unfortunately, the problem between LiveWriter and Blogger is that it doesn’t allow custom image scaling.  I had to use the largest size it does support that would not blow out of the page.  That’s not very readable on-line.  I also can’t make an image link to the original file so someone could get a direct view of that PNG image.
    [2019-10-30T12:28 OK, OK, I found the workaround for this.]
  5. I also included the wrong PNG image.  I will see if I can repair that.  Unfortunately, Blogger apparently doesn’t allow editing of existing pages (or I can’t find it).
    [2019-10-30T12:29 I found the edit-post link.  Just above where comments appear.  Sheesh.]

Tasks

  • Replace that post on Blogger with one having the correct image.
    [2019-10-30T12:26 Well, I learned how to edit a post and to redo the image.  I also learned that Blogger makes the image clickable to provide a right-sized view.  I made the image "original" size anyhow, before I discovered that.]
  • Create a Miser category and see if that is useful.
    [2019-10-30T12:33 I forgot they are called "labels" and I started using "Miser Project" for that sequence of posts.]
  • Think about what it takes to use GitHub as a blog host.  It means I need a Markdown-oriented blog creation procedure, but maybe that’s necessary after all. [2019-11-07T10:20 and I am still stuck about this.   The Blogger image-handling is becoming an annoyance.]