- +
The Anytime, Anyplace Enterprise 03/06/2008 14:06:24
The interactive enterprise must be capable of providing access to its information and processes anytime and from anyplace over any network-connected device. Some CIOs are taking a phased approach in getting there.Customers, employees and partners expect to interact with their suppliers, employers and advisers when, where and how they like. Enterprise CIOs can deliver enhanced business performance and innovation for their firms by combining existing IT assets in conjunction with emerging consumer technologies. - +
SharePoint '07: Perfect Union of Info Management, IT? 03/06/2008 09:18:06
For companies that choose SharePoint, it makes sense for there to be a joined-up IT, knowledge and information functionMicrosoft Office SharePoint Server (MOSS 2007) merges workflow, search and collaboration into one enterprise-wide information management platform. In this environment, does it make sense for the professions of records management (RM) knowledge management (KM) and information management (IM) to continue to work independently in their niche roles? - +
Understanding the Project Management Office 05/02/2008 12:59:53
Excellence in project management is essential, but PMOs can do as much harm as good. Here we examine the fundamentals and scope a proper role for a PMOExcellence in project management is essential, but PMOs can do as much harm as good. Here we examine the fundamentals and scope a proper role for a PMO - +
Forget Everything You've Learnt About Project Delivery, Part 1: Scope Management 05/02/2008 12:58:54
Acknowledging the two types of scope can force some of the problems with scope management to disappearAcknowledging the two types of scope can force some of the problems with scope management to disappear - +
A Tale of Two Call Centres 04/02/2008 13:18:44
Happy belated 2008.Happy belated 2008. Holidays are over. School's back. Traffic sucks. The weeks off were not only welcome but refreshing, although I must admit there was the odd day or two that saw my "peace on earth, good will to men" disposition - well, shall we say - lacking
Read up on the latest ideas and technologies from companies that sell hardware, software and services. Understanding Email Marketing: A Guide for SMBs
Optimized Back-up and Recovery for VMWare for VMWare Infrastructure with EMC Avamar
Revolutionising Back-up and Recovery
Radicati Market Quadrant 2008 on Corporate Web Security
Still Sneaking In: The Threats Your Security Tools Aren't Telling You About
Choices in Storage Architecture for Oracle Environments
Realizing the Value of Unified Communications
Enterprise Wireless WLAN Security
Zones provide focussed content from Computerworld and leading technology partners.Newsletter Subscription
Users of the professional-oriented social networking site LinkedIn are being warned that scam artists are using the site to nab lucrative bank account information from naive victims, say security experts.
Advanced fee fraud — also known as "419 scams" after the relevant section of the Nigerian penal code — have become well-known to most e-mail users. The fraudster poses as a foreigner that has lucked into millions, but needs help to keep their money secure (one fraudster even pretended to bean African astronaut aboard the International Space Station).
As soon as someone is naive enough to share their bank account information, they find that money is withdrawn from their account — not deposited, as promised.
Stymied by corporate e-mail filters and buoyed by the trust that users are giving social networking sites, scammers are trying their old tricks in new channels, according to Graham Cluley, senior technology consultant at Abingdon, UK-based security vendor Sophos PLC.
"Now they're trying their scam with a network used by businesspeople," he says. "By using this mechanism, the criminals know they're talking to people who aren't 13-year-olds, but people with money in their pockets."
Cluley shares one example of the phishing attack that he received on LinkedIn. A user named Natasha Kone claims to be a 22-year-old woman from the Ivory Coast. Her message goes through the usual scam-artist routine of describing the US$6.5 million inheritance left to her by a deceased father, and why she's looking for a foreign partner to help secure the money.
It's a ploy most people would dismiss out of hand.
"The problem is that common sense isn't very common," Cluely says. Sophos knows of many examples of normally astute individuals suckered in by nicely formatted e-mails, and some have lost dollar sums in the millions.
Social networking sites are now the top phishing target,according to the most recent Internet Security Threat Report from Symantec Corp. The sites are the source of the most phishing attacks in the top three countries where phishing occurs — the US, China and Romania.
Overall, phishing messages went up by five per cent in the second half of 2007. There was a total of 207,547 unique messages identified — that's 1,134 different messages for each day.
Scammers are enjoying the trust that social networking users tend to give to the Web sites. Users feel a false sense of security due to being connected to a network of their peers.
"Promiscuous users are accepting friend and network requests from people they don't even know," says David Senf, director of research for Canadian security at Toronto-based IDC Canada. "The trouble is that no one wants to be rude."
But workers should be more stringent about who they add to their friends list, experts say. There's no guarantee that the person you're adding isn't an Internet impersonator. Once a scammer is on your friend's list, you've given them an open route to repeated attempts at nabbing your sensitive information.
One simple measure LinkedIn users can take is to only accept invitations from people who at least know your e-mail address, Cluley says.It's an option that can be simply turned on.
"It's just an extra little bit of effort that most criminals will not take," he says. "They can't just willy-nilly spam everyone on LinkedIn."
LinkedIn's user conduct agreement states that misrepresenting your identity on the network is a breach. So is the use of invitations to send messages to people you don't know.
ITBusiness.ca requested an interview with a LinkedIn spokesperson, but there was no response at the time of publication.
But companies can't be rest-assured that LinkedIn will delete the accounts of all the bad guys out there, says Jim Lippard, director of information security at Florham Park, N.J.-based IP network provider Global Crossing Ltd. There should be a policy in place to address how employees use social networks.
"Advise employees not to put the company's proprietary information onto their profiles," he says. "Just be aware the information can be read by anyone."
Even users who consider themselves careful about who they add as friends have to be careful, Lippard adds. Social networks are made more unsafe for everyone by those who accept every connection put forward to them.
Staff recruiters at large corporations often have large friend lists, for example. The presidential candidates in the US election also have profiles and will accept anyone as a friend to build their popularity showcase, the security expert says.
"They're operating their profiles like a MySpace bands page," Lippard says. "Once you have an indiscriminate group of people doing this, that means there are more unsecure links closer to all users."
For now, one fraudster's identity has been removed from LinkedIn. Natasha Kone has been deleted from the social network's database. But there's no telling how much damage the scammer has already done.
"I'm sure the only person who really knows that is the one lurking behind the identity of Natasha Kone," Cluley says.
Computerworld Member Login
Prioritizing Services with IT Service Management (ITSM)
Computerworld Live Webinar
Wednesday 20th, August 2008
11:00am EST (Sydney, Australia)
To be repeated on:
Thursday 4th, September 2008
11:00am EST (Sydney Australia)
Sign up and receive a free copy of The Forrester WaveTM Service Desk Management Tools, Q2 2008 at the conclusion of the Webinar.
Attend and discover:
- How to deliver value to your business through ITSM
- Best practice ITSM implementation
- Why emphasis is changing from optimizing IT management processes to better servicing customers and demonstrating real dollar value
- If service-oriented ITSM is best for your business
- +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future.
Viva la Verticals! Key to Vendor Growth is Through Vertical Market Opportunities, Says IDC 2008-09-05 11:05:00+10
F-Secure delivers fastest protection in the online world 2008-09-04 16:50:00+10
NETGEAR expands ProSafe team as business-class products take off in SME market 2008-09-04 16:27:00+10
Rogue security apps dominate Fortinet's Aug 2008 IT threat report 2008-09-04 16:00:00+10
Adaptec Intelligent Power Management Reduces Storage Power Consumption Up to 70 Percent 2008-09-04 11:28:00+10
Realizing the Value of Unified Communications
Discover how the integration of disparate technologies in your company can lead to greater user productivity, improved management, lower costs, higher efficiency, and easier risk mitigation.








