Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
Posted 12 October 2012 - 04:53 AM
Posted 02 November 2012 - 02:21 AM
Participating in chat rooms or social networking sites
Posted 02 November 2012 - 07:27 PM
It appears you didn't read the article that the comment was excerpted from, which was in the original topic, and is explained.Participating in chat rooms or social networking sites
How this can be dangerous? Unless you are giving your passwords or other confidential information away.
10. Participating in chat rooms or social networking sites
The very same parents who frantically try to keep their kids off of MySpace are now flocking to business social networking sites like LinkedIn, either from home or at the office. They join a colleague's "network" on LinkedIn, post messages, and maintain their own presence on the site. That's much safer than MySpace, because it's just like a professional organization, right?
Wrong. Social networking sites are a social engineer's dream come true.
"The biggest security challenges businesses face with business social networking like LinkedIn is the sheer amount of information that a social engineer can learn by doing simple searches," says Matasano Security's Goldsmith. "Attackers can find out who your business partners, vendors, and clients are simply by viewing your shared connections."
There's simply no way for LinkedIn and other sites to validate a member's employment record, so an attacker can claim to work at Matasano and find out which current and past employees are on the site. "Services like LinkedIn try to guard sensitive employment information by restricting it to colleagues --- you have to have worked with Dave Goldsmith before to be able to click on him and see his work history, or have him come up in a search for 'Matasano,'" says Matasano's Ptacek. "But anyone can sign up to LinkedIn and claim to have worked for Matasano."
Users can also inadvertently leak sensitive company data in a message board post with a buddy, for instance. It may reach eyes for which it wasn't intended, or they may not realize that chatting about what they're doing at work today may lead to a corporate data breach. "It's different than having drinks with a buddy after work," says SecureWorks' Peck.
Aside from a chatty user, a browser can also be a weak link. "ActiveX controls and their browser can be used by an attacker to get into the corporate network," Peck says. "There are a lot of Web app vulnerabilities we've seen."
Even if you have a "closed circle," that doesn't mean you don't touch the outside world. Just clicking onto the site of a buddy's buddy can get you into security trouble. "Every subpage you go to in LinkedIn or MySpace is like going to a whole different Website," Peck says. "It's most risky when you're going to the sites of people you don't know."
Aside from the social engineering threat, there's also the very real threat of getting infected with XSS, keyloggers, worms, and spyware (just ask MySpace users). "There's going to be vulnerabilities in the software," Peck says.
If an enterprise allows access to social networking sites, it must ensure that users are wary of who they're communicating with and what type of sensitive information they may be exposing. The bad news is you may not know until it's too late.
"You should assume that anything you post to a social networking site is public," says Matasano's Ptacek.
The Internet is so big, so powerful and pointless that for some people it is a complete substitute for life.
Andrew Brown

A learning experience is one of those things that say, "You know that thing you just did? Don't do that." — Douglas Adams.
"Imagination is more important than knowledge. Knowledge is limited. Imagination circles the world." — Albert Einstein (1879-1955)
Posted 04 November 2012 - 07:55 PM
Edited by violetrose, 04 November 2012 - 08:00 PM.
Posted 19 February 2013 - 09:12 AM
This is quite a list I'm ashamed to know that I've done at least 5 of them D:
Edited by wantei, 19 February 2013 - 09:13 AM.
Posted 20 February 2013 - 01:22 PM
Just to digress slightly, when I bought a PC several years ago I found that the store who'd built it for me had plastered my name all over it, such as "Mr X's Documents", "Mr X Owner", "Mr X's Pictures" blah blah.
I raised hell with them on security grounds and managed to delete my name from some areas but not from others, so the moral is- tell whoever's building a computer for you NOT to put your name anywhere on the system.
Posted 20 February 2013 - 08:49 PM
Here is a story from last year. We may not be safe anywhere:
When it comes to computer viruses, you’re now more likely to catch one visiting a church website than surfing for porn.
Posted 22 February 2013 - 04:50 PM
What social networkinf sites are you referring to and why?
Posted 22 February 2013 - 07:50 PM
The Internet is so big, so powerful and pointless that for some people it is a complete substitute for life.
Andrew Brown

A learning experience is one of those things that say, "You know that thing you just did? Don't do that." — Douglas Adams.
"Imagination is more important than knowledge. Knowledge is limited. Imagination circles the world." — Albert Einstein (1879-1955)
0 members, 0 guests, 0 anonymous users