Technology, Data Recovery, Cell Phones, Latest Gadgets, Game Reviews

Computer Tricks, Internet Tips, Latest Gadgets, Latest Software, Tips and Tricks,Latest Reviews, Cell Phones Review, Data Recovery, Game Reviews.......


I am never quite sure that I understand the point of computer viruses.
Perhaps I am not alone in that it is frequently presumed that hackers
hold virus writers in low regard due to the perceived lack of skills
that the latter have and the indiscriminate damage caused by viruses.
Perhaps the very raison d’être of viruses is where I miss the point:
presumably the attraction in writing and unleashing viruses is the very
fact that you (as the writer) can do it, and then sit back and watch the
trail of havoc you have created. Some such trails are very long indeed.
Research has shown (surprise, surprise) that the majority of virus
writers are intelligent males between 15 and 23 years old who are
probably bored, curious, intent on testing what can be done or simply
vindictive. The main psychological buzz that viruses bring to their
writers is either the intellectual satisfaction of completing the challenge
they have set themselves or the fact that they are fighting the ‘system’.
The word ‘virus’ has itself mutated into more of a generic term which
is now used to cover a multitude of computer vermin (also known as
malicious software).
A virus, per se, is a manmade, independent program or piece of code
that is loaded onto your computer or system without your knowledge,
and runs in the same manner. Viruses usually spread by ‘infected’ files
that are passed between computers. Five years ago the largest risk was
probably users inserting floppy disks that were infected into their PC.
Now the infinitely more critical risk is viruses originating via the
Internet. Viruses can reproduce themselves, attach themselves to other
programs, create copies of themselves. Viruses normally damage or
corrupt data, use available memory, clutter up disk space and bring
the system to an abrupt halt. The most dangerous types of virusestransmit across networks, exploiting security flaws. Running a antivirus
program that isn’t up to date is almost worse than useless; even
the best fully up-to-date anti-virus programs cannot protect against
all viruses. Somewhat ironically, there is also a thriving market in hoax
viruses, mostly through e-mails that claim to have latest information
and demand that you pass them on.
Then there are worms. The use of the word in this sense was originated
in a 1982 research paper by John Shoch and Jon Hupp of the Xerox
Palo Alto Research Center. However, this paper derived the term from
‘The Shockwave Rider’ by John Brunner, published in the early 1970s
and now promoted as ‘a cyberpunk story from the days before cyberpunk
was a concept’. Normally a worm propagates/replicates itself
across a computer network causing malicious damage such as using
up resources (storage, processing time) and shutting the system down.
The worm may copy itself from one disk drive to another or via email.
Worms appear to be the computer infection of choice, accounting
for approximately half of the computer infections in 2000. Whereas in
the past some technical knowledge would have been required to create
worms, now worm generators can be downloaded from the Internet.
A typical transmission mechanism for worms is an ‘interesting e-mail
attachment’; other worms need no human intervention and infect
computers with specific security flaws and then seek out other computers
that have the same flaw. Because of the power to replicate it is
now being argued that worms have in effect caused denial of service
attacks on the Internet because of the bandwidth consumed by them.
In the roll call of infamous worms are:
 The Anna Kournikova virus – which was, in strict terms, not a
virus but a worm (2001).
 The Christmas Tree virus – possibly the first worm on a worldwide
network that spread across BITNET in December 1987.
 The Cornell Internet Worm – which exploited computer security
flaws in 1988 and infected about 5 per cent of those users
connected to the prototype Internet.
The key difference between a virus and a worm is the method by which
each replicates and spreads: a virus is dependent on a host file or
computer’s boot sector while a worm can run completely independently
and spread by itself through network connections.
Just like in Homer’s Iliad a Trojan horse is something that is apparently
harmless (or even beneficial) but once inside the gates turns outto be something else entirely. Trojan horses do not replicate like viruses
and worms, but can still be extremely destructive. Trojan horses rely
on users to install them, or they can be installed by intruders who
have gained unauthorized access by other means. Then, an intruder
attempting to subvert a system using a Trojan horse relies on other
users running the Trojan horse to be successful. Among various Trojan
horses that are common are anti-virus programs that actually install
viruses and software upgrades that are nothing of the kind, but when
loaded proceed to modify files and contact other remote systems.
A logic bomb will lay dormant in a system until triggered by some
event or specific system condition. When set off, the bomb will carry
out a malicious act, or set of acts such as changing random data or
making the disk unreadable, The trigger mechanism can be anything
– among favourites are a specific date, a specific event or the number
of times a certain thing is done (even the number of boot-ups). A logic
bomb does not replicate itself.
These various forms of malicious software are no joke: in September
2001 the Reuters news agency reported that the total global cost of
viruses was US $ 17.1 billion in 2000 and US $ 12.1 billion in 1999. The
main reasons for such phenomenal costs were:
 The Code Red Worm, which by September 2001 had already cost
US $2.6 billion, comprising US $1.5 billion in lost productivity
costs and US $1.1 billion in cleaning up computer systems.
 The Sircam virus, which cost US$1.04 billion in total including
US $575 million in lost productivity and US $460 in clean-up costs
 The Love Bug virus, which still remains the most financially
damaging virus ever, costing US $8.7 billion in lost productivity
and clean-up costs.
The Code Red worm itself is a fascinating example as to how the digital
world, once again, is really a very small place: its major inherent risks
are ever present in its fundamental global interconnectivity. This worm
is not aimed at Windows 3.1, Windows 95, Windows 98 or Windows
ME systems but attacks Windows NT 4.0 and Windows 2000 computers
and Web sites that use that technology. The world of viruses holds
a certain academic interest combined with curiosity value to see what
fascinating damage can be caused – useless beauty indeed. Examples
include:

1) CIH or the Chernobyl virus. This was created by a student in
Taiwan in 1998 and struck up to a million PCs on April 26 1999
as well as cropping up at various times after that date until now.
This virus only attacks Windows 95 and 98 systems and is
triggered when the date is 26 April (or if you have a PC that shows
the wrong date it strikes when your system states it is this date).
The virus overwrites critical information on your hard disk, and
in some cases deletes information stored in the PC’s bios memory,
which then makes it impossible to boot the PC. Just to confuse
the situation some variants of this virus trigger on the 26th day
of other months.

2) The FunLove virus. To their embarrassment in April 2001 Microsoft
e-mailed their key support customers to inform them that
they may have been infected with the FunLove virus. The reason
for the infection? One of Microsoft’s Servers did not have antivirus
software installed – the server that provides updates and
bug fixes to Microsoft’s premier customers.

3) The Sircam worm. This can potentially create more damage than
wrecking your system by random mailings of documents on
the users’ hard drive. Sircam arrives by mass e-mailing using
Outlook Express to distribute itself. The e-mail arrives with a
fairly innocuous attachment, reading something along the lines
of ‘Hi how are you? I send you this file in order to have your
advice. See you later! Thanks’. This message is helpfully also
available in Spanish. Once the attachment is opened Sircam
gathers files from the user’s hard drive and all the e-mail
addresses in Windows address book. The virus then sends copies
of itself to all of the addresses it has obtained – together with a
randomly chosen file. Additionally Sircam computes a random
number that has a 1 in 33 chance of triggering the PC to fill up
all of the remaining space on the hard disk by adding text at each
start up to a system file that the worm has installed in the recycle
bin. The choice of Windows Recycle Bin for the location of this
file was interesting, as most virus checkers did not check the
Recycle Bin. Then the worm checks to see if the date is October
16; if it is and the PC is using the European date format the worm
will generate another random number – this time it has a 1 in 20
probability of success. Success being a relative term: as victory
for the worm will result in the machine deleting all of the files
on its hard drive.



The wonderful world of viruses is further complicated by hoax viruses
together with various e-mail security bulletins which purport to alert
the user to new viruses but in fact contain a virus themselves. One
such e-mail tells users that their PC contains a virus called sulfnbk.exe,
which should be deleted – the drawback being that this is a perfectly
legitimate file in Windows, which is a utility that restores long file
names. The Web site www.vmyths.com contains many more examples
of similar incidents.
The best response towards viruses is to adopt common sense policies
and procedures regarding the following key topics:
 Don’t use illegal or counterfeit software, and never run an
unknown disk without virus checking it.
 Always back up your files.
 Delete e-mail attachments, specifically where the sender is
unknown to you.
 Do not let others borrow program disks – if you do virus check
them before you use them again.
 Always run an anti-virus program, and just as importantly make
sure that it is updated frequently.
 If you download software from the Internet always do it to a
diskette, not directly to your hard drive (for further security you
can write protect your hard drive during this operation).
 Disable Word Macros and ensure that, depending which version
of Word you are using, macro virus protection (if present) is
running.
 Be aware of strange occurrences on your system (although most
systems appear to have such events on a daily basis without it
necessarily indicating that a virus is present!). Watch out for:
– your system slowing down;
– files that disappear (although by its very nature this is easier
said than done);
– attempts to access the hard disk to read or write when there
should be no such activity;
– strange display corruption and/or unusual visual occurrences;
– unusually large program file;
– decreases in memory or reduced disk space.
 Educate users about computer viruses, what they do, how to
recognize them, how they can be prevented and what actions to
take immediately one is discovered

Welcome to Techno - blogg. This time I have a collection of Tips and Tricks which no body normally knows, the secrets which Microsoft is afraid to tell the people, the information which you will seldom find all gathered up and arranged in a single file. To fully reap this Manual you need to have a basic understanding of the Windows Registry, as almost all the Tricks and Tips involve this post.

****************

Important Note: Before you read on, you need to keep one thing in mind. Whenever you make changes to the Windows Registry you need to Refresh it before the changes take place. Simply press F5 to refresh the registry and enable the changes. If this does not work Restart your system

****************

Exiting Windows the Cool and Quick Way

Normally it takes a hell lot of time just Shutting down Windows, you have to move your mouse to the Start Button, click on it, move it again over Shut Down, click, then move it over the necessary option and click, then move the cursor over the OK button and once again (you guessed it) click.This whole process can be shortened by creating shortcuts on the Desktop which will shut down Windows at the click of a button. Start by creating a new shortcut( right click and select New> Shortcut). Then in the command line box, type (without the quotes.)

'C:\windows\rundll.exe user.exe,exitwindowsexec'

This Shortcut on clicking will restart Windows immediately without any Warning. To create a Shortcut to Restarting Windows, type the following in the Command Line box:

'c:\windows\rundll.exe user.exe,exitwindows'

This Shortcut on clicking will shut down Windows immediately without any Warning.

Ban Shutdowns : A trick to Play on Lamers

This is a neat trick you can play on that lamer that has a huge ego, in this section I teach you, how to disable the Shut Down option in the Shut Down Dialog Box. This trick involves editing the registry, so please make backups. Launch regedit.exe and go to

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer

In the right pane look for the NoClose Key. If it is not already there then create it by right clicking in the right pane and selecting New > String Value.(Name it NoCloseKey ) Now once you see the NoCloseKey in the right pane, right click on it and select Modify. Then Type 1 in the Value Data Box.

Doing the above on a Win98 system disables the Shut Down option in the Shut Down Dialog Box. But on a Win95 machine if the value of NoCloseKey is set to 1 then click on the Start > Shut Down button displays the following error message:

This operation has been cancelled due to restrictions in effect on this computer. Please contact your system administrator.

You can enable the shut down option by changing the value of NoCloseKey to 0 or simply deleting the particular entry i.e. deleting NoCloseKey.

Instead of performing the above difficult to remember process, simply save the following with an extension of .reg and add it's contents to the registry by double clicking on it.

REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]

"NoClose"="1"

Disabling Display of Drives in My Computer

This is yet another trick you can play on your geek friend. To disable the display of local or networked drives when you click My Computer go to :

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer

Now in the right pane create a new DWORD item and name it NoDrives. Now modify it's value and set it to 3FFFFFF (Hexadecimal) Now press F5 to refresh. When you click on My Computer, no drives will be shown. To enable display of drives in My Computer, simply delete this DWORD item. It's .reg file is as follows:

REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]

"NoDrives"=dword:03ffffff

Take Over the Screen Saver

*(Not Check) To activate and deactivate the screen saver whenever you want, goto the following registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ScreenSavers

Now add a new string value and name it Mouse Corners. Edit this new value to -Y-N. Press F5 to refresh the registry. Voila! Now you can activate your screensaver by simply placing the mouse cursor at the top right corner of the screen and if you take the mouse to the bottom left corner of the screen, the screensaver will deactivate.

Pop a banner each time Windows Boots

To pop a banner which can contain any message you want to display just before a user is going to log on, go to the key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WinLogon

Now create a new string Value in the right pane named LegalNoticeCaption and enter the value that you want to see in the Menu Bar. Now create yet another new string value and name it: LegalNoticeText. Modify it and insert the message you want to display each time Windows boots. This can be effectively used to display the company's private policy each time the user logs on to his NT box. It's .reg file would be:

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Winlogon]

"LegalNoticeCaption"="Caption here."

Delete the Tips of the Day to save 5KB

Windows 95 had these tips of the day which appeared on a system running a newly installed Windows OS. These tips of the day are stored in the Windows Registry and consume 5K of space. For those of you who are really concerned about how much free space your hard disk has, I have the perfect trick.

To save 5K go to the following key in Regedit:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Tips

Now simply delete these tricks by selecting and pressing the DEL key.

Change the Default Locations

To change the default drive or path where Windows will look for it's installation files, go to the key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Setup\SourcePath

Now you can edit as you wish.

Secure your Desktop Icons and Settings

You can save your desktop settings and secure it from your nerdy friend by playing with the registry. Simply launch the Registry Editor go to:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer

In the right pane create a new DWORD Value named NoSaveSettings and modify it's value to 1. Refresh and restart for the settings to get saved.

CLSID Folders Explained

Don't you just hate those stubborn stupid icons that refuse to leave the desktop, like the Network Neighborhood icon. I am sure you want to know how you can delete them. You may say, that is really simple, simply right click on the concerned icon and select Delete. Well not exactly, you see when you right click on these special folders( see entire list below)neither the rename nor the delete option does not appear. To delete these folders, there are two methods, the first one is using the System Policy Editor(Poledit in the Windows installation CD)and the second is using the Registry

This is a techno - blogg exclusive post

When I opened my e-mail inbox yesterday morning I was gratified to
see that I had ‘won’ a voucher for free petrol that could be used at any
petrol station of major oil companies. Or to be strictly correct, I could
claim my free US $10 worth of petrol at any gas station in the United
States within the next seven days. This might prove to be a problem,
as I am based in the UK. Welcome to the world of spam – but I probably
don’t need to welcome you, as I am certain that you are already knee
deep in it already (and if you’re not, and use e-mail, please tell me
how you’ve managed to avoid it). I try to do everything that I can to
limit spam, and am very conscious of the dangers that lurk in the
attachments of unsolicited e-mails, but that hasn’t stopped the following
wonderful missives being received by me in the last few days:

Powerpoint productivity tips
A circular on .info domain names
A circular on a credit management newsletter
A message about free fax services
Only two weeks to get one month free and no setup fee’.
Access your PC from anywhere – free download
Up to US $150 free at xyzonlinecasino.com
Win $100 in domain names
Increase sales and revenues
Get up to 2 per cent cash back on your purchases
Solutions for buying or selling your business
Free printer, scanner or digital camera



Thankfully I have not had any e-mails offering me free pornography,
but somewhat ironically I have had one headed ‘Mail pile getting you
down?’. Spam is also known as unsolicited commercial e-mail (UCE),
unsolicited bulk mail (UBE) or make money fast (MMF). While spam
is now a universally used term which has been taken to cover each of
these different types of e-mail abuse, in fact each of these terms has,
strictly speaking, a different meaning. The exact reason for the use of
the term spam has never been entirely clear, but obviously it refers to
the tinned luncheon meat of the same name that was made a cult item
by the famous Spam song from Monty Python’s Flying Circus. Originally
spam was used to describe a particular type of Usenet posting, but
has now been accepted as a generic term to describe a whole range of
inappropriate Web events, predominantly related to e-mail. The term
encompasses the following:


Unsolicited bulk e-mail (UBE): messages with the same (or almost
the same) content sent to many addresses that did not ask to
receive it. Before e-mail if a company or individual wished to
carry out a bulk mail shot they had to compile or buy a mail list,
print leaflets or circulars, stuff them in envelopes, mail frank the
envelopes (or lick thousands of stamps) then post them. This was
a laborious and time consuming task – not to mention the most
important factor – the expense involved. E-mail removed all of
these problems – as long as you had an e-mail circulation list, all
you have to do is write something and press the ‘send’ button.
Best of all it’s free! Well kind of: in fact it may be free for the
sender but bulk spammers actually can cause horrendous bandwidth
problems when automated e-mail programs can send millions of messages each day. Then there are the consequent
costs such as the time (and money) wasted in the workplace by
dealing with such e-mails – and also, it must be said, on occasions,
replying to them and sending money! UBE, by its very title, implies
large numbers of messages

Unsolicited commercial e-mail (UCE) is virtually the same as UBE
but can be a single e-mail to one user

Make money fast (MMF): In essence messages that guarantee
immediate (and ludicrous) profits. Such communications are in
the most part illegal, but more importantly (to use a technical
term) bull****. Just as with both UBE and UCE there is nothing
new in these communications as they have been sent by post for
decades, but once again the Internet gives the sender the ability
to dispatch thousands if not millions of these at the click of a
mouse. The obvious advantage to the sender is that a percentage
of recipients are always taken in by the ludicrous promises made
and send money: so the more e-mails that are sent out then the
higher number of people taken in, and thus the larger the illegal
profit for the criminals behind the scheme. There is some semantic
dispute as to whether multi-level marketing schemes fall into
this category, but as I prefer to refer to such offers as pyramid
schemes – with all the connotations that such a phrase implies,
then I think that they well and truly belong here.
In very simple terms, the usual technique used to compile mail lists
for such exercises involve the use of e-mail sniffers, which roam the
Internet searching for and then recording e-mail addresses posted on
Web sites, mailing list postings or anywhere else that e-mail addresses
can be found. Such programs can be downloaded very easily from
the Internet: at the moment I have on screen the details of a shareware
program (costing US $10) that ‘will extract valid e-mail addresses from
almost any type of file including HTML, ASCII and binary files,
handling up to 30,000 addresses per address list’.
Initially I thought that it would not be relevant to include details of
e-mail spam that was essentially fraudulent, as there was very little
(if any) possibility that anyone of a sane disposition would be taken
in by it. However, all the research into this subject and logic suggest
that people are taken in by it – otherwise what would be the point in
it being sent in such large numbers? Nevertheless, it is important to
distinguish between two types of spam. First is honest spam, which,
for want of a better term, is bulk mailing that does relate to a legitimate

product or service, but was not requested by the recipient. Then there’s
fraudulent spam: at the worst end of the make money fast syndrome,
which perhaps ought to be rebranded LMF – lose money fast.
And what better place to start with than Nigeria. Here is not the
place to discuss at length the vast and panoramic background of
Nigerian fraud: I have written at length on this subject in the past and
a White Paper on the many facets of this problem is on my firm’s Web
site at www.proximalconsulting.com. In essence, Nigerian fraudsters
have, for many years, been sending out letters by post offering recipients
the chance to be involved in a large financial transaction. The numbers
of letters sent in the traditional way have been enormous – on average
the US authorities receive at least 100 calls per day from victims or
potential victims of this fraud and 300 related pieces of correspondence
(per day!). In 1998 a UK police squad collected 150,000 Nigerian letters
in the first four months of the year. But here’s the rub: typically for
each 100 letters sent, one recipient responds and another sends money:
usually thousands of pounds. If there was ever a ‘service’ that begged
for bulk e-mail distribution, this was it. Thus it came with very little
surprise that in the last couple of months I have received a variety of
these unrepeatable offers, such as:


REQUEST FOR ASSISTANCE IN A FINANCIAL
TRANSACTION
I am contacting you based on information and esteem recommendation
I received of you from a high ranking official in the
commercial section of the Nigerian Chambers of Commerce and
Industry who guaranteed your reliability and trustworthyness in
business dealings. This business proposal I wish to intimate you
with is of mutual benefit and it’s success is entirely based on mutual
trust, cooperation and a high level of confidentiality as regard this
transaction.
I am the Chairman of the contract Advisory Committee (CAC) of
the Nigerian Federal Ministry of Works and Housing (FMWH). I
am seeking your assistance to enable me transfer the sum of US
$16,500,000.00 (Sixteen Million, Five Hundred Thousand United
States Dollars) into your private/company account.
The fund came about as a result of a contract awarded and
executed on behalf of my Ministry the Federal Ministry of Works
and Housing. The contract was supposed to be awarded to two foreign contractors to the tune of US $60,000,000.00 (Sixty Million
United States Dollars). But in the course of negotiation, the contract
was awarded to a Bulgarian contractor at the cost of US $43,500,000.00
(Forty-Three Million, Five Hundred Thousand United States Dollars)
to my benefit unknown to the contractor. This contract has been
satisfactorily executed and inspected as the Bulgarian firm is
presently securing payment from my Ministry, where I am the
Executive Director in-charge of all foreign contract payment approval.
As a civil servant still in active government service, I am forbidden
by law to operate an account outside the shores of Nigeria. Hence
this message to you seeking your assistance so as to enable me
present your private/company account details as a beneficiary of
contractual claims alongside that of the Bulgarian contractor, to
enable me transfer the difference of US $16,500,000.00 (Sixteen
Million, Five Hundred Thousand United States Dollars) into your
provided account.
On actualization, the fund will be disbursed as stated below:
 30 per cent of the fund will be for you as beneficiary.
 10 per cent for reimbursement to both parties for incidental
expenses that may be incurred during the course of the
transaction.
 60 per cent of the fund will be for me which I intend to invest
in your country with you as my partner.
All logistics are in place and all modalities worked out for a smooth
actualisation of the transaction within the next few working days
of commencement. For further details as to the workability of this
transaction, please respond by return mail on my confidential email
address: fmwhbakare@yahoo.com.or by fax .+234-1759-7154.
Thank you and God bless as I await your urgent response.
Yours sincerely,
Ali Bakare (Engr).
On almost the same day as we received our e-mail (actually we
received it twice – presumably just in case we ignored it first time
around), another Nigerian fraud came to light in Canada. Three
Toronto residents have been arrested as a result of a joint investigation
run by the Canadian Federal Bureau of Investigation and US Secret
Service. The three men are alleged to have taken part in a global fraud
involving more than 300 victims, who lost sums ranging from tens of
thousands to millions of dollars


One of our contacts has also recently received another variant of
the Nigerian letter, this time from Mr Albert Sankarah in the Congo,
who quotes a South African telephone and fax number. His letter reads
as follows:
I am Mr Albert Sankarah from the Democratic Republic of Congo
and the special adviser to the late President Laurent Kabila.
On the first week of this year the late President assigned me to
the Republic of South Africa to conclude the Arms and Ammunitions
procurement negotiation with an arm dealing company right
here in South Africa as was a call of urgency. Before I left Congo,
the President and I were made aware of the plans of the opposition
to topple the government.
On the 15th of January 2001, I arrive to South Africa with the sum
of US $23 Million (Twenty Three Million United States Dollars)
through diplomatic means. To proceed on my mission I heard the
most shocking news of my life; the assassination of the President
who sent me on this mission. Having a thought of his death, I saw
it as a golden opportunity to enrich and reward myself for my
loyalty to him towards the overthrow of the late President Mobutu
Sese Seko. I decided to deposit the funds with a reputable Security
Company here in Johannesburg.
Knowing that since I am currently seeking asylum here in South
Africa, I have got a lot of financial limitations. Coupled with the
way in which this money was acquired, I cannot invest or use this
money in South Africa. That is why I thus decided to seek for a
God fearing person who can assist me in transferring these funds
into his company or personal account.
In anticipation of your assistance I have agreed to offer you:
– 25 per cent of the total funds for your assistance
– 5 per cent to be set aside for every reasonable expenses incurred
by both parties
– and the remaining 70 per cent will be for my investment in
your company.
I have done everything necessary that will lead to the success of
this transaction before contacting you, so all I want from your side
is sincerity. Remember that the keyword to this transaction is
confidentiality and I assure you that this transaction is 100 per cent
risk free. If you are interested in assisting me please notify me on


the above telephone and fax numbers. In case you cannot assist, do
keep it confidential.
Best regards.
The contents of this letter confirm additional information that suggests
that South Africa is becoming a centre of Nigerian activity, with many
fraudsters operating out of the country, trying to lure innocent
‘investors’ there. Another variation on the dead statesman theme is
the following letter, which is currently being sent by e-mail:
Dear Sir,
I am Mr. Varsadi Mobutu, the son of the late President Mobutu Sese
Seko of former Zaire now Democratic Republic of Congo. My family
and I now live in exile, in Morocco. Due to seizures/confiscation of
my late father’s properties as well as the frozen of all his bank
accounts including that of the family members and the recent
confiscation/seizure of his choice property châteaux in South of
France, which were all carried by the International Press, made us
not to make any meaningful investment without a sincere and
trusted front. In this line, therefore, it is the wish of my family to
solicit for a trustworthy and sincere person who will invest these
funds under trusteeship for the family. We have US $500m to put in
any meaningful investment that will yield good dividend.
Source of fund
Before the death of my father he deposited the above stated funds
with a Security Firm here in Morocco. Hence I am in asylum here
in Morocco therefore, I intend to have a front who will manage this
fund and invest it into property development, buying of shares/
stocks in multinational companies and engage in non-speculative
investments, and other related ventures.
As soon as I hear from you I will then arrange a face-to-face
meeting for us to deliberate on this investment. It will also, give me
the opportunity to assess your capability of handling this investment.
Please I will like you to send me your private telephone/fax
numbers, to allow us discuss privately and establish a voice contact.
Meanwhile reach me on the above stated e-mail. Please treat this
matter with utmost confidentiality.
Best Regards,
Varsadi Mobutu


While the Nigerian 419 letter by e-mail is an important strand of
fraudulent e-mail spam, it is merely one of many types that hit both
individuals and businesses. Among other notable offers of instant
wealth are:
 Chain letters – the classic ‘get rich quick’ schemes that promise
unbridled wealth. The high tech variant of this perennial chestnut
is no different to its paper mail counterpart. Typically the email
includes the details of several individuals; you are instructed
to send US $5 to the person at the top of the list, cross that name
off and add your name to the bottom. You are then told to e-mail
this communication to other individuals, who will repeat the
process so that you name comes to the top of the list and you
will not be able to get to your post box because of the influx of
plain brown envelopes stuffed with cash.
 Free prize schemes – telling you that you have won a valuable
free prize, all you have to do is contact a phone number (usually
costing a premium rate) and then pay for the shipping of your
prize. It is not unusual for victims to be charged hundreds of
pounds or dollars for the shipping of a free car or other seemingly
valuable item. Of course, the prize never materializes.
 Free holidays – ‘Yes, you have won a completely free one week
holiday which can be taken at any time of the year (including
school holidays) at any location in the world’. All you have to
do is join a travel club, which may cost anything up to £300. When
you come to book your holiday, mysteriously the flights you want
will be fully booked, or if they’re OK the hotel you choose will
not be available, or if everything is available there will be some
obscure clause that can be invoked so that you pay a hefty surcharge.
And all of this actually presumes that you get this far:
many such free holiday offers by e-mail result in victims joining
‘travel clubs’ that mysteriously disappear completely before any
holidays can be booked.
 Advance fee frauds – the old favourite much favoured by
Nigerian fraudsters but well used by every other criminal. In its
simplest form the applicant pays a fee for a ‘guaranteed’ loan.
This raises the obvious question, in these days of cheap and
readily available finance, as to why anyone would need to pay a
fee to borrow money. The obvious answer is that such spam is
aimed at those who find it difficult to get credit and/or want to
borrow more than they can afford. Thus these groups are hit witha double whammy – no loan and handing over money that they
can’t afford.
 Investment fraud schemes – we could be here all day listing the
various types of such scams. However, beware in particular of
investment stock tips by e-mail (which involve investing that
capital) and anything at all that promises way above average
financial returns.
 The rest – and there are many. Junk any e-mails that you get
which are about distributorships and franchises; job opportunities;
work at home schemes; oil and gas investments; schemes
that charge money for services that your government or other
state bodies provide free (such as training, unclaimed tax refunds);
life saving medical products. For organizations one particular
type of spam can be particularly costly – e-mails that appear to
be invoices that a staff member might think are real and proceed
to pay. One particularly prevalent example relates to apparently
pre-agreed entries in business directories in print or Web site
format.
Just because someone has your e-mail address doesn’t mean that you
have somehow been magically chosen to be the only person on the
planet to receive this wonderful offer! At the risk of stating the obvious,
the often stated guidelines (equally applicable to normal mail) apply
to any such spam:
 When you are approached by any unknown person and/or
organization to establish any new business relationship you must
validate that person’s or organization’s claims and history. The
best advice (which means that you don’t have to read the rest of
this warning list) is that if you have never heard of the person/
company sending you the e-mail, delete it without even bothering
to read it – never vary from this dictum, even if your curiosity
tries to persuade you otherwise.
 Never forget: if any deal or offer appears to be too good to be
true, turn it down – because it is.
 There are no such things as ‘once in a lifetime opportunities’
‘guaranteed returns on investments’ – when the figures guaranteed
are astronomical.
 Be suspicious.
 Question all transactions.
Jealously guard all your personal and/or business information
such as bank account details, credit card numbers.
 Don’t sign any document before you have had it checked out.
 Find out if the individual or company exists, and is registered
with the necessary regulators or licensing authority.
 How long has the individual/company been trading – who are
the principals?
 Check out the filings of the subject company – it might be
registered somewhere, but is it trading? If so does its financial
status in any way reflect the deal being offered?
 Check out addresses and contact details of those approaching
you (it still surprise me how many of these people use dead lines
or business centres).
 Validate any documents presented for authenticity.
 Ask for references – but don’t take them at face value.
 Ask for a prospectus and brochure.
 Carry out a media and Internet search on the individuals.
 Don’t pay for anything upfront unless you have dealt with the
person/company before and know that the person/company is
reputable.
 Don’t be afraid to say ‘No’.
 Don’t be rushed – one key factor in many of these frauds is that
the criminals try to rush you, usually saying that you must act
quickly to take advantage of the unique opportunity.
 The Internet may be a great medium to promote fraud, but it is
also a brilliantly effective way to search for information and detail
on fraudsters. You may be surprised by what you find by searching
– details of earlier investors who have lost money, for example,
or investigations that are going on into the company/individual
that is offering you the wonderful investment opportunity. I
recommend searching on Dogpile, Google and Northern Light
at the very least.
 If you have any doubt whatsoever, walk away – even if you are
continually pressured to sign on the dotted line (in fact, particularly
if you are pressured to sign on the dotted line).
In many US states the issues relating to even ‘normal’ spam (ie circulars
offering legitimate services) have been the subject of legislation. In
Washington a law enacted in 1988 allows state residents to sue for
damages of up to US $500 for each unsolicited e-mail message received.
While such legislation is very worthy and well meaning it is, in practical terms, useless. If the sender is outside that state, or outside of the US,
how can it possibly be enforced? ISPs in virtually all cases have clauses
regarding e-mail abuse in your agreement with them. Which is all very
fine, but numerous and varied complaints have surfaced over the years
regarding the lack of response from ISPs over spam. The argument is
that as combating spam is not a revenue generator then ISPs are not
particularly quick or efficient in dealing with the problem. There is
also and inevitably the other side of the argument, that bulk e-mailing
gives small businesses (in particular) a valuable marketing tool, and
thus any ISPs that try to control and eradicate it are effectively antibusiness.
There are also various attempts to make search engines
prohibit the inclusion of sites that offer services and software relating
to spam. This has practical problems: at the very least the kind of search
terms that would have to be monitored would include the following
– and searches would need to allow for variations in spelling (for
example e-mail and email) and case sensitivity:
 spam;
 bulk mail/bulk e-mail;
 direct e-mail;
 unsolicited bulk e-mail;
 unsolicited commercial e-mail;
 UBE and UCE (which is a bit of a shame if your legitimate
company or organization is called either of these acronyms);
 e-mail software (banning, restricting or having a ‘health warning’
on this phrase is totally unworkable);
 bulk e-mail software;
 bulk e-mail service;
 e-mail marketing;
 e-mail advertising;
 online advertising;
 online marketing;
 Web site promotion;
 e-mail lists;
 e-mail address lists;
 stealth e-mail;
 extractor (another totally unworkable one – what about all the
other kinds of extractors?);
 harvester (another problem – what about, for example, the UK
restaurant chain with this name?).

I am not a technical expert (as you might have gathered) and thus this
section probably stretches my technical knowledge as far as it goes.
The critical issue, though, is that most individuals and companies that
operate Web sites leave the security of that site to the hosting provider,
which is evidently a mistaken reliance, as the provider will not get
attacked or defrauded, you will! Thus you must consider:
 Can your data be accessible to other users of the Web server?
 Are the external and internal firewalls of the Web hosting
company configured correctly so that an attack can be recognized
and responded to?
 Does the Web hosting company continuously monitor (and act
upon) information about vulnerabilities?
 What tools does the Web hosting company use to monitor their
network?
 What levels of physical security does the Web hosting company
have? Online security is pointless if an attacker can get to your
Web site easily from the premises of the company.
 Does your Web hosting company have clearly defined policies,
procedures and standards for digital security? Do you get a copy
of such documents?

As I write this, there have been some examples, particularly in the
United States, of anthrax spores being delivered by normal terrestrial
mail. E-mail, which has always been perceived as a notorious insecure
way of communicating, has suddenly become a very sensible and
secure (in a wider sense) method of getting a message across. I’m sure
that all users would rather have a computer virus than a killer bacterial
disease. Nevertheless, the new reliance on e-mail (which may have
two diametrically opposite conclusions by either fading away or
becoming the norm) makes lax e-mail security even more critical Does your organization have a policy for e-mail use by employees
and what constitutes abuse?
 Do all your organization’s e-mails automatically include a
disclaimer stating that the contents of the e-mail are the views
and opinions of the sender and not necessarily those the company?
 Are employees instructed not to share e-mail passwords?
 Is what is acceptable e-mail use defined? Examples are business
messages to co-workers, customers and suppliers together with
short personal messages.
 Do you define exactly what unacceptable e-mail usage is?
Examples are those involving personal business activities of staff,
distributing chain letters or any messages containing lewd,
harassing, offensive and/or pornographic material.
 Are your staff trained to realize that e-mails can be used as
evidence in legal cases and thus any terms that imply or confirm
slander, defamation and/or discrimination of any kind must be
avoided?
 Are your staff trained to ensure that inappropriate messages,
which could cause embarrassment for the organization and/or
individual, are avoided? Remember the special advisor to a UK
government minister who sent an e-mail on the afternoon of
September 11 2001 suggesting that this would be a good day to
release ‘bad’ news relating to the government’s activities as it
would be ‘buried’.
 What are your procedures regarding sending confidential material
and information by e-mail?
 What instructions do you have in place regarding deletion of emails?
 Are all users running an up-to-date virus checker that checks both
incoming and outgoing e-mails and their attachments?

Subscribe to: Posts (Atom)