Share

Rick Robinson

Job title:
CTO and vice president, eSoft

Areas of expertise:
Applied cryptography, PKI, identity and access management (authentication, authorization, and auditing), secure data transport, and system hardening and protection

Biography:
Rick Robinson has over ten years of experience in the computer security sector, including development of secure embedded computers, secure remote access, secure networking design, and secure system architecture. Throughout his career, he has regularly worked with Fortune 500 customers, providing security strategy and guidance. Robinson is a recipient of the prestigious Avaya Labs Cup Award and has been named on four USPTO patents in the area of computer security with additional USPTO application submissions in process. He possesses CISSP and ISSAP certifications from (ISC)2. In addition, he is an IEEE Senior Member, Past-Chair of the IEEE-Denver Section, Member of IEEE Security and Privacy Society, Member of the IEEE Computer Society, and Member of the IEEE Critical Infrastructure Protection Committee. Robinson holds BS and MS degrees in electrical engineering from Montana State University with an emphasis in computer engineering, and is completing his Executive MBA from the University of Colorado.

Tag Cloud

Bloggers

Blog

Live.com Exploited as Pharma-Fraud Cover

The FDA crackdown on online pharmacy sites has driven a lot of attention to illegal and fraudulent online pharmacies and in particular to their methods for tricking people to visit their sites. These practices include prolific spam and search engine poisoning.

eSoft’s Threat Prevention Team has noticed that the search engine poisoning is now very actively making use of Microsoft’s Windows Live Spaces – a free blog hosting environment. By registering accounts and using those accounts solely to link to the pharma-fraud sites, the search engine ranking of the target sites goes up. Additionally, the spam emails now link to these fake blogs rather than directly to the pharma-fraud site in an effort to better evade spam filters that might otherwise detect the link to the fraudulent website.

The blog page shown here is typical of those seen by the Threat Prevention Team: It consists of a single blog entry with a single image that is linked to a classic 'Canadian Pharmacy' website using a template that eSoft has seen used on thousands of websites. eSoft worked with the ThreatChaos blog to shine the light and provide full details on these sites during a major outbreak in May. More details about this threat may be found in that posting.

Similar attacks have been reported recently using Yahoo and Blogger to draw users to fraudulent pharmacy sites. Google Job Spam has also reportedly infiltrated spaces.live.com.

Whatever the distribution method, it's clear these cybercriminals will stop at nothing and continue to evolve new ways of advertising their bogus sites. eSoft has excellent detection for pharma-fraud sites and detects thousands of these URLs month after month.  Exploited blogs on spaces.live.com are being flagged by the eSoft Threat Prevention Team as ‘Phishing & Fraud’.

Posted 23/12/2009 by Rick Robinson

Tagged under:Spam,Fraud,Pharma-Fraud

Comment on this blog

You must be registered and logged in to leave a comment about this blog.