How safe is your password on other’s hand?

November 15, 2007 at 7:40 pm | In Good to know, IT Security, Security | 3 Comments

 The other day, I received a forwarded email as follows, (it’s quite lengthy from an irritated person with good intention though) If you’re in a rush, my conclusion is at the end, right after the email. However, please do note that I have no way to verify the authenticity of this email and I bear no liability by posting this whatsoever.

Subject :FW: MSN Cheat on fund transfer to Maybank a/c: Please beware!

Content:

    It happened around 1125am on 19th October 2007 . When i was busy
with
    work, a friend suddenly ‘IM’ed me using MSN messenger. She used to
be
    my roomate and i am very close with her. So, she asked if i could
log
    in to maybank2u account because she couldn’t. As I’ve tried, i
could
    log in. She asked me for a favor saying that she owed a friend
money
    and been delaying him very long and its kind of urgent to return
the
    money and asked if i could help her to transfer money to her friend
    first and saying that she’ll definitely bank in the money back to
me
    after work that day. The amount she asked was initially RM800, but
    since i got not that much money in that bank account, she told me
to
    wait as she will ask her friend if its okay paying him RM400 first.
    So, sensing some kind of emergency here, i without any hesitation
    (this friend once asked me to lend money to her the same way), I’ve
    banked in the amount to the bank account she gave me. The account
no.
    is 1111-1428-6194 and the owner’s name is KEW MIN TECK. Well, at
the
    end of the day, after working hour, i still yet to receive any call
    from my friend regarding the money. So, i smsed her regarding the
    money. She was shocked about it and asked if she still owe me
money.
    (We stayed together for the past few months, so, sometimes she owes
    me money for bills…)So, with the thought that she forgot bout it,
i
    mentioned to her that she asked for my help to transfer RM400 to
her
    friend first. With that, she’s even more surprised and gave me a
    call. When i told her about it, she said it must be her email
account
    being hacked already. (FYI – MSN uses email account to login)
because
    she received a SMS from an unknown number saying that he’s matthew
    and he hacked her email and asked her if she wants him to restore
for
    her. This guy’s number is 012-2141405 which is a prepaid number. I
    was so shocked with the news and immediately went to Maybank to see
    if the transfer could be stopped. It was already 720pm at that
time,
    offices already closed down. I’ve called the maybank hotline and
they
    asked me to make a police report and bring back to Maybank
tomorrow.
    So, i quickly went to the nearest police station and make a report
    believing that with the guy’s bank account number and name, police
    force could at least track him down or get evidence on him for the
    crime he’s committing. I told my friend to do the same thing and
tell
    her to sms all her friends regarding her account being hacked. At
the
    police station, there’s this policewoman at the counter. She asked
me
    where did i do the transaction and i told her at my office. she
told
    me that i must go to another police station to make the report as
    that is not under their district. I was like ‘huh?’ Ho wever, i
    managed to make a police report. That policewoman did not even
listen
    properly to the incident i was telling and she started to type on
her
    own. Since she did not attentively listen to what i was saying, she
    got things wrong and asked us to write the story down. I was lucky
    that i got a friend to accompany me to the police station. (i don’t
    even know where’s the police station is… i’m a KL ppl in Penang
    now). Eve n though I’ve made a police report, the case wasn’t open.
To
    no avail, nothing has been done. The policewoman then called
another
    officer (it seems that this officer has the higher rank) and he
    talked to me. I was asked by him ‘why do i need the police report’,
    the reason of getting a police report? (is that suppose to be a
    question? i wouldn’t have trouble myself to lodge a report if i
find
    it not necessary)By telling him that at least could get details on
    the guy from the bank, he told me to go to Maybank and get the
guy’s
    particulars and hopefully i could talk to that guy and it’ll be
good
    if he returns the money else, i’ll need to treat it as a wrong
    investment. (wrong investment!!???) So, particularly, nothing has
    been done.

    The next amusement thing about this is that, i went to Maybank as
    told by the officer the next day along with the police report and
    hope that i could get details on that guy. And the only thing that
i
    found out is that they need an officer/personel to come along only
    authorised to view the details! (omg! how come no one told me bout
it
    at the police station?) The guy in maybank was very helpful. He
    managed to help me check (i got a peep on it) about that hacker’s
    bank account. To my surprise, there are alot of transcation to this
    guy account! Besides mine at 11.25am , at 11.30am there’s another
    transaction (RM620) transfered to his account. There are several
    more. And at that moment, his account only left RM146! Doesn’t it
    obvious that this guy is vigorously cheating others by hacking into
    other people’s account? Since, nothing can be done without an
    officer/personel, with much despair i decided to go home. Just on
the
    way back, i received a call from a friend from KL stating that the
    hacker the friend’s email account to online again and now talking
to
    him. That hacker uses the same tactic to him asking for help to
    transfer money using maybank2u. I asked my friend to entertain him
to
    see if it is the same guy,same bank account number. So, when i
    reached home. I tried to talk to that guy again. He’s using the
same
    conversation again! (omg! doesn’t he remember that he has already
    conned me?) by making it sounds like i’m talking to my friend, i
    talked to him again. So, as predicted. He asked the same question
    again and the whole lot conversations were the same. And without
any
    surprise, the name and the bank account number is the same! So, i
    called the police station where i make a report yesterday to tell
    them about it. The policeman who picked up the phone was so rude.
    Then, i told him bout the incident and my report number and told
him
    that this guy is in action again. And yet, another disappointment.
    The policeman said that there’s nothing he could do as he can’t get
    out of the police station and he then gave me a hp number to call.
I
    called that officer who’s responsible for this kind of cases but
only
    got ‘i’m busy at the moment. i’m taking some statement here’ as the
    answer. My KL friend who got the whole conversation which of
course,
    the same account number and the same name – went to make a police
    report and requested to open up a case for this. After waiting for
4
    hours at the police station and listening to the policemen saying
    that there’s nothing they can do, there’s no evidence and a more
    ridiculous question thrown to my friend is ‘Berapa Ribu kau
hilang?’
    (how many thousands you have lost?)

    Isn’t it the police’s responsibility to track this fella down? And
    why am i the one suppose to get the particulars from Maybank?
Doesn’t
    he knows that we’re not authorise to do any checking on people’s
    particulars unless there’s an officer/personel together with the
    police report only could do that? Why am i not told about it when
i’m
    at the police station lodging the report? And isn’t it the job of
the
    police to get evidences on this guy who is doing the crime? It
    doesn’t matter on how much we got cheated, it is still our money
and
    furthermore, what if that i’m not the only person being conned
here?
    Imagine, each person he conned RM400, so if he managed to con 10
    people, that would make it RM 4000 per day! I am seriuosly being
    dissappointed with the act of the police force. It’s as if they are
    imaginary since they claimed that they could do nothing about it.
And
    these kind of crimes will continue and it’ll be even worse as
there’s
    no action being take and these culprits will happily commit these
    crimes without being afraid of getting caught.

    So, people! What you can do now is be more extra careful when
you’re
    dealing with your money. Always verify with the people you’re
sending
    money to, no matter how close he/she to you. And don’t assume that
    your friend’s/family’s eamil account is not being hacked!

    p/s: this is part of the conversation I got (the day after when
he’s
    trying to con me again) And I got to know from maybank that he’s
    account is from kuching, Sarawak .
Moral of the story:

There are many ways a hacker can get your password but it aint easy for a real hacker to get your password.

Many a times, it is the user or YOU yourself provided your password to a 3rd party without yourself realizing.

It can range from phishing, duping you for your password and more advanced trojan horse or virus programs.

Phishing or duping your for your password is something that can easily be prevented.

Make sure you know the site your going to, a free site such as geocities used to be abused by people creating fake yahoo login screen and duping people for their yahoo passwords.

That way, those same people can login with your yahoo messenger. See how it goes?

It’s exactly one of those reasons that you should NEVER EVER give your email password to any website except for the legitimate ones.
I noticed many websites now (esp social networking sites) that ask you for your email password (Hotmail, Yahoo, Gmail, AOL) in the pretence of helping you to add friends directly for you.
They swore they never gonna use it, but how 100% sure are you?

When they use it, you have a lot of linked friends as easy targets! Not only you risks yourself, you’re risking your friends and their friends as well.
So the next time anybody or websites asking for your password as if for your CONVENIENCE, pls do NOT trust them.

Some examples (I’m not saying they are using your passwords, but you have no way to be sure that they are NOT storing it!):

Another one:

Another one:

Most of the social networking websites nowadays have this approach I’m not sure why, or even if it’s right to do it that way!
I have absolutely no idea why in the world they would ask for your password in the name of convenience. Can I have your ATM Pin so I can check your account balance?

I just choose to skip those “CONVENIENT” steps and take the hassle of adding friends manually.

Blog at WordPress.com. | Theme: Pool by Borja Fernandez.
Entries and comments feeds.