<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments on: I am in Nigeria, please send me $3000</title>
	<atom:link href="http://www.248am.com/mark/internet/i-am-in-nigeria-please-send-me-3000/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.248am.com/mark/internet/i-am-in-nigeria-please-send-me-3000/</link>
	<description>A blog by Mark and Nat, a married couple who are living in Kuwait. Mark works in Advertising while Nat works in TV.</description>
	<pubDate>Thu, 08 Jan 2009 01:45:08 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Just Jay</title>
		<link>http://www.248am.com/mark/internet/i-am-in-nigeria-please-send-me-3000/#comment-446772</link>
		<dc:creator>Just Jay</dc:creator>
		<pubDate>Mon, 29 Sep 2008 22:44:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.248am.com/?p=5353#comment-446772</guid>
		<description>Rain, it's cool. I work in IT, so I get a kick out of the cat/mouse game. I employ a few tricks to keep my side of the house clean. Trend Micro also has a program called. R U Botted... it's pretty good too.
http://www.trendsecure.com/portal/en-US/tools/security_tools/rubotted
I encrypt, surf anonymously, use proxies (not free ones, either) and do what I need to do to keep my less honest friends at bay.</description>
		<content:encoded><![CDATA[<p>Rain, it&#8217;s cool. I work in IT, so I get a kick out of the cat/mouse game. I employ a few tricks to keep my side of the house clean. Trend Micro also has a program called. R U Botted&#8230; it&#8217;s pretty good too.<br />
<a href="http://www.trendsecure.com/portal/en-US/tools/security_tools/rubotted" rel="nofollow">http://www.trendsecure.com/portal/en-US/tools/security_tools/rubotted</a><br />
I encrypt, surf anonymously, use proxies (not free ones, either) and do what I need to do to keep my less honest friends at bay.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: RainQ8</title>
		<link>http://www.248am.com/mark/internet/i-am-in-nigeria-please-send-me-3000/#comment-446771</link>
		<dc:creator>RainQ8</dc:creator>
		<pubDate>Mon, 29 Sep 2008 22:32:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.248am.com/?p=5353#comment-446771</guid>
		<description>Omar you really are feeding the forum too much info which will result in me experimenting - I think thats the same as counter security?

Rainbow is limited at the moment and all my passwords are longer than 8 characters, contain case change, numbers, and symbols.

If caught experimenting I will tell them some bloke called Omar set me up with all these ideas! :-P</description>
		<content:encoded><![CDATA[<p>Omar you really are feeding the forum too much info which will result in me experimenting - I think thats the same as counter security?</p>
<p>Rainbow is limited at the moment and all my passwords are longer than 8 characters, contain case change, numbers, and symbols.</p>
<p>If caught experimenting I will tell them some bloke called Omar set me up with all these ideas! :-P</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Omar</title>
		<link>http://www.248am.com/mark/internet/i-am-in-nigeria-please-send-me-3000/#comment-446770</link>
		<dc:creator>Omar</dc:creator>
		<pubDate>Mon, 29 Sep 2008 22:16:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.248am.com/?p=5353#comment-446770</guid>
		<description>@RainQ8.  Hehe, I don't target anyone.  I learn all of this just for counter security.  By the way, cracking SSL using brute force has gotten tremendously easier since the development of Rainbow Tables earlier in the year.  Check it out: Rainbow Tables Brute Hash Cracking http://en.wikipedia.org/wiki/Rainbow_table</description>
		<content:encoded><![CDATA[<p>@RainQ8.  Hehe, I don&#8217;t target anyone.  I learn all of this just for counter security.  By the way, cracking SSL using brute force has gotten tremendously easier since the development of Rainbow Tables earlier in the year.  Check it out: Rainbow Tables Brute Hash Cracking <a href="http://en.wikipedia.org/wiki/Rainbow_table" rel="nofollow">http://en.wikipedia.org/wiki/Rainbow_table</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: RainQ8</title>
		<link>http://www.248am.com/mark/internet/i-am-in-nigeria-please-send-me-3000/#comment-446768</link>
		<dc:creator>RainQ8</dc:creator>
		<pubDate>Mon, 29 Sep 2008 21:48:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.248am.com/?p=5353#comment-446768</guid>
		<description>Just Jay, you are right with the simple stuff, but be warned about the wireless free spots and not using SSL sites as you will be easy targets for Frankie and Omar.</description>
		<content:encoded><![CDATA[<p>Just Jay, you are right with the simple stuff, but be warned about the wireless free spots and not using SSL sites as you will be easy targets for Frankie and Omar.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: RainQ8</title>
		<link>http://www.248am.com/mark/internet/i-am-in-nigeria-please-send-me-3000/#comment-446766</link>
		<dc:creator>RainQ8</dc:creator>
		<pubDate>Mon, 29 Sep 2008 21:45:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.248am.com/?p=5353#comment-446766</guid>
		<description>Sheep, it could have been a bot generating addresses by replying to the email you have just confirmed to it that you are a real live recipient that would like to receive even more junk email.</description>
		<content:encoded><![CDATA[<p>Sheep, it could have been a bot generating addresses by replying to the email you have just confirmed to it that you are a real live recipient that would like to receive even more junk email.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: RainQ8</title>
		<link>http://www.248am.com/mark/internet/i-am-in-nigeria-please-send-me-3000/#comment-446764</link>
		<dc:creator>RainQ8</dc:creator>
		<pubDate>Mon, 29 Sep 2008 21:42:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.248am.com/?p=5353#comment-446764</guid>
		<description>Omar, yep you are right about WEP cracking but the nice data you want to look at is not easy to hack in minutes or low volume data capture, and if they are using wireless WPA then it is time consuming to even get connected. 

Even if you sniff packets at starbucks, and the surfer is connected to a SSL site it would take you donkey years to brute force the encryption on the packets to get the credit card, you would have to sit and gather (Not that I do)! 

But I never use the local wi-fi spots. Good to get the key to surf for free, but expose your computer to others?

It sounds like a script with simply the reply-to changed before/after harvesting (SMTP masking is easy). Mark pastes the Nigerian guys blurb and he didn't actually confirm if she can't get back into her account. 

The reason I mention the script is one of my friends had the same thing happen, but it was not that her account got taken over (although she thought they had) it was just a script (Sent to her in another email, subject: RE: ) harvested her contacts address book. 

She changed her password just in case and unless there's a trojan key logger on her machine knocking out to some server in China its pretty much safe now. Although she is still looking for tools to protect herself from herself.

Not sure how you can have your email password reset by Yahoo unless you specified another email address when you signed up to have it sent to. How do they know its 100% you?

Omar is right with CC's, my rule is no httpS then no card!</description>
		<content:encoded><![CDATA[<p>Omar, yep you are right about WEP cracking but the nice data you want to look at is not easy to hack in minutes or low volume data capture, and if they are using wireless WPA then it is time consuming to even get connected. </p>
<p>Even if you sniff packets at starbucks, and the surfer is connected to a SSL site it would take you donkey years to brute force the encryption on the packets to get the credit card, you would have to sit and gather (Not that I do)! </p>
<p>But I never use the local wi-fi spots. Good to get the key to surf for free, but expose your computer to others?</p>
<p>It sounds like a script with simply the reply-to changed before/after harvesting (SMTP masking is easy). Mark pastes the Nigerian guys blurb and he didn&#8217;t actually confirm if she can&#8217;t get back into her account. </p>
<p>The reason I mention the script is one of my friends had the same thing happen, but it was not that her account got taken over (although she thought they had) it was just a script (Sent to her in another email, subject: RE: ) harvested her contacts address book. </p>
<p>She changed her password just in case and unless there&#8217;s a trojan key logger on her machine knocking out to some server in China its pretty much safe now. Although she is still looking for tools to protect herself from herself.</p>
<p>Not sure how you can have your email password reset by Yahoo unless you specified another email address when you signed up to have it sent to. How do they know its 100% you?</p>
<p>Omar is right with CC&#8217;s, my rule is no httpS then no card!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Just Jay</title>
		<link>http://www.248am.com/mark/internet/i-am-in-nigeria-please-send-me-3000/#comment-446759</link>
		<dc:creator>Just Jay</dc:creator>
		<pubDate>Mon, 29 Sep 2008 21:30:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.248am.com/?p=5353#comment-446759</guid>
		<description>People, listen. You are playing a cat and mouse game that has been going on for years. Simple countermeasures go a long way...like a password that has letters, numbers, and special symbols. Make it long too. Change it every now and then. Use software that protects you to a degree, and finally... Don't FALL FOR IT!!! Would you open up mail sent to you, if you had NO IDEA who the sender was? Then again, don't answer that...</description>
		<content:encoded><![CDATA[<p>People, listen. You are playing a cat and mouse game that has been going on for years. Simple countermeasures go a long way&#8230;like a password that has letters, numbers, and special symbols. Make it long too. Change it every now and then. Use software that protects you to a degree, and finally&#8230; Don&#8217;t FALL FOR IT!!! Would you open up mail sent to you, if you had NO IDEA who the sender was? Then again, don&#8217;t answer that&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sheep</title>
		<link>http://www.248am.com/mark/internet/i-am-in-nigeria-please-send-me-3000/#comment-446752</link>
		<dc:creator>Sheep</dc:creator>
		<pubDate>Mon, 29 Sep 2008 20:48:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.248am.com/?p=5353#comment-446752</guid>
		<description>i've gotten an email like that once. I knew it was a scam but I simply replied with "Dude, I'm sorry about whatever happened to you, but if I had $3,000 I'd be out shopping right now not reading this stupid email from you :)"

Why are they always Nigerian?</description>
		<content:encoded><![CDATA[<p>i&#8217;ve gotten an email like that once. I knew it was a scam but I simply replied with &#8220;Dude, I&#8217;m sorry about whatever happened to you, but if I had $3,000 I&#8217;d be out shopping right now not reading this stupid email from you :)&#8221;</p>
<p>Why are they always Nigerian?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Omar</title>
		<link>http://www.248am.com/mark/internet/i-am-in-nigeria-please-send-me-3000/#comment-446750</link>
		<dc:creator>Omar</dc:creator>
		<pubDate>Mon, 29 Sep 2008 20:21:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.248am.com/?p=5353#comment-446750</guid>
		<description>RainQ8, Frankie is 100% correct.  What are u talking about 1GB to hack WEP?  Are you mad? Wep takes less than a min to crack nowadays with the correct tools.  I have a script on my N80 that cracks WEP in about 7 mins (and thats a tiny phone!)  WPA and WPA2 (esp. Radius) can take longer, but again neither require 1GB of data.  

Also the script you are describing is not what happened to Mark's friend.  He clearly states that the password of the account was changed (so that the Nigerians can have back and forth communication with anyone that actually believes the emails,

Guys it is soooo extreemly easy for someone to totally see every bit of data going to and from ur pc when connected to a public hotspot.  Next time u are there at Starbucks, look over and try to spot the hacker checking out everything you are doing =)

On YouTube check out Hak5Darren.  It will show you how to do all I just mentioned.  It will also show you the best ways to protect yourself.  Stay safe people, and be very careful when using credit cards.</description>
		<content:encoded><![CDATA[<p>RainQ8, Frankie is 100% correct.  What are u talking about 1GB to hack WEP?  Are you mad? Wep takes less than a min to crack nowadays with the correct tools.  I have a script on my N80 that cracks WEP in about 7 mins (and thats a tiny phone!)  WPA and WPA2 (esp. Radius) can take longer, but again neither require 1GB of data.  </p>
<p>Also the script you are describing is not what happened to Mark&#8217;s friend.  He clearly states that the password of the account was changed (so that the Nigerians can have back and forth communication with anyone that actually believes the emails,</p>
<p>Guys it is soooo extreemly easy for someone to totally see every bit of data going to and from ur pc when connected to a public hotspot.  Next time u are there at Starbucks, look over and try to spot the hacker checking out everything you are doing =)</p>
<p>On YouTube check out Hak5Darren.  It will show you how to do all I just mentioned.  It will also show you the best ways to protect yourself.  Stay safe people, and be very careful when using credit cards.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: RainQ8</title>
		<link>http://www.248am.com/mark/internet/i-am-in-nigeria-please-send-me-3000/#comment-446737</link>
		<dc:creator>RainQ8</dc:creator>
		<pubDate>Mon, 29 Sep 2008 17:01:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.248am.com/?p=5353#comment-446737</guid>
		<description>Its probably not been taken over, more like she opened an email with a script which went through her contacts list and emailed all her friends with the same script and CC's the original sender, thus they know that all the emails have real people at the other end.

Then her friends open up the email sent from her (As its a trusted or marked safe email address) - then the script runs again, and the loop goes on. The original sender ends up harvesting a load of real email addresses -  which can then be used/sold anywhere they like.

Clever these little cyber kiddies!

Frankie are you mad? Hacking WEP and wireless protected networks are time consuming, you have to gather 1GB worth of data before running the algorithm! SSL with Yahoo is a choice at sign in, if you do not choose to then its your problem not Yahoo's!

Computers are not stupid, they do their masters bidding, if the master is stupid then there isn't much the computer can do about it!</description>
		<content:encoded><![CDATA[<p>Its probably not been taken over, more like she opened an email with a script which went through her contacts list and emailed all her friends with the same script and CC&#8217;s the original sender, thus they know that all the emails have real people at the other end.</p>
<p>Then her friends open up the email sent from her (As its a trusted or marked safe email address) - then the script runs again, and the loop goes on. The original sender ends up harvesting a load of real email addresses -  which can then be used/sold anywhere they like.</p>
<p>Clever these little cyber kiddies!</p>
<p>Frankie are you mad? Hacking WEP and wireless protected networks are time consuming, you have to gather 1GB worth of data before running the algorithm! SSL with Yahoo is a choice at sign in, if you do not choose to then its your problem not Yahoo&#8217;s!</p>
<p>Computers are not stupid, they do their masters bidding, if the master is stupid then there isn&#8217;t much the computer can do about it!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: TanGo</title>
		<link>http://www.248am.com/mark/internet/i-am-in-nigeria-please-send-me-3000/#comment-446731</link>
		<dc:creator>TanGo</dc:creator>
		<pubDate>Mon, 29 Sep 2008 15:38:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.248am.com/?p=5353#comment-446731</guid>
		<description>@ Frankie, I wish you were writing English..</description>
		<content:encoded><![CDATA[<p>@ Frankie, I wish you were writing English..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pure</title>
		<link>http://www.248am.com/mark/internet/i-am-in-nigeria-please-send-me-3000/#comment-446716</link>
		<dc:creator>Pure</dc:creator>
		<pubDate>Mon, 29 Sep 2008 13:56:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.248am.com/?p=5353#comment-446716</guid>
		<description>@7ussien, i did get something like that from my friend as well but i don't really remember if it is the same company .. !</description>
		<content:encoded><![CDATA[<p>@7ussien, i did get something like that from my friend as well but i don&#8217;t really remember if it is the same company .. !</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: 7ussien</title>
		<link>http://www.248am.com/mark/internet/i-am-in-nigeria-please-send-me-3000/#comment-446705</link>
		<dc:creator>7ussien</dc:creator>
		<pubDate>Mon, 29 Sep 2008 11:38:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.248am.com/?p=5353#comment-446705</guid>
		<description>a month ago my friend's hotmail account got taken and the person who took it sent an email to all his contacts advertising a chinese company selling electronics called GVCCN i checked their website and its pretty funny they have the Sony Ericsson Xperia on sale which is not even out yet !:D,at least if you want to scam people try to be smart about it !:D and everything on the website is listed for way less than its original price :D</description>
		<content:encoded><![CDATA[<p>a month ago my friend&#8217;s hotmail account got taken and the person who took it sent an email to all his contacts advertising a chinese company selling electronics called GVCCN i checked their website and its pretty funny they have the Sony Ericsson Xperia on sale which is not even out yet !:D,at least if you want to scam people try to be smart about it !:D and everything on the website is listed for way less than its original price :D</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Q8GEEK</title>
		<link>http://www.248am.com/mark/internet/i-am-in-nigeria-please-send-me-3000/#comment-446700</link>
		<dc:creator>Q8GEEK</dc:creator>
		<pubDate>Mon, 29 Sep 2008 10:07:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.248am.com/?p=5353#comment-446700</guid>
		<description>oldies goldies =P</description>
		<content:encoded><![CDATA[<p>oldies goldies =P</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Frankie</title>
		<link>http://www.248am.com/mark/internet/i-am-in-nigeria-please-send-me-3000/#comment-446699</link>
		<dc:creator>Frankie</dc:creator>
		<pubDate>Mon, 29 Sep 2008 09:59:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.248am.com/?p=5353#comment-446699</guid>
		<description>Cain &#38; Abel is soo 2007 :)</description>
		<content:encoded><![CDATA[<p>Cain &amp; Abel is soo 2007 :)</p>
]]></content:encoded>
	</item>
</channel>
</rss>
