<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>john munoz dot com &#187; geekstuff</title>
	<atom:link href="http://www.johnmunoz.net/blog/category/geekstuff/feed" rel="self" type="application/rss+xml" />
	<link>http://www.johnmunoz.net</link>
	<description>our faith in zeros and ones</description>
	<lastBuildDate>Sat, 28 Aug 2010 17:46:29 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>over the river and on the wall&#8230;</title>
		<link>http://www.johnmunoz.net/blog/over-the-river-and-on-the-wall</link>
		<comments>http://www.johnmunoz.net/blog/over-the-river-and-on-the-wall#comments</comments>
		<pubDate>Tue, 11 May 2010 00:35:16 +0000</pubDate>
		<dc:creator>john</dc:creator>
				<category><![CDATA[geekstuff]]></category>

		<guid isPermaLink="false">http://www.johnmunoz.net/blog/over-the-river-and-on-the-wall</guid>
		<description><![CDATA[<p></p> <p>I got a facebook wall-to-wall from someone i’ve never gotten a face book message from before.&#160; Being the overly suspicious person i am, i queried the domain name,</p> <p>Domain name: &#160;&#160;&#160;&#160;&#160; BK9WH.TK &#160;&#160; Organisation: &#160;&#160;&#160;&#160;&#160; BV Dot TK &#160;&#160;&#160;&#160;&#160; Dot TK administrator &#160;&#160;&#160;&#160;&#160; P.O. Box 11774 &#160;&#160;&#160;&#160;&#160; 1001 GT&#160; Amsterdam &#160;&#160;&#160;&#160;&#160; Netherlands &#160;&#160;&#160;&#160;&#160; [...]]]></description>
			<content:encoded><![CDATA[<p><img alt="http://www.facebook.com/profile/pic.php?uid=AAAAAQAQVN6kRM9mqox7tq25CgtE7AAAAAqpiRKkgQr4uj7WRadnB1M1" src="http://www.facebook.com/profile/pic.php?uid=AAAAAQAQVN6kRM9mqox7tq25CgtE7AAAAAqpiRKkgQr4uj7WRadnB1M1" /></p>
<p>I got a facebook wall-to-wall from someone i’ve never gotten a face book message from before.&#160; Being the overly suspicious person i am, i queried the domain name,</p>
<p>Domain name:   <br />&#160;&#160;&#160;&#160;&#160; BK9WH.TK    <br />&#160;&#160; Organisation:    <br />&#160;&#160;&#160;&#160;&#160; BV Dot TK    <br />&#160;&#160;&#160;&#160;&#160; Dot TK administrator    <br />&#160;&#160;&#160;&#160;&#160; P.O. Box 11774    <br />&#160;&#160;&#160;&#160;&#160; 1001 GT&#160; Amsterdam    <br />&#160;&#160;&#160;&#160;&#160; Netherlands    <br />&#160;&#160;&#160;&#160;&#160; Phone: +31 20 5315725    <br />&#160;&#160;&#160;&#160;&#160; Fax: +31 20 5315721    <br />&#160;&#160;&#160;&#160;&#160; E-mail: abuse: <a href="http://www.domaintools.com/registrant-search/?email=a454bf9280e7fc6bfd26dd4ba538ef0f"><img border="0" align="middle" src="http://source.domaintools.com/email.pgif?md5=a454bf9280e7fc6bfd26dd4ba538ef0f&amp;face=arial&amp;size=9&amp;color=000000&amp;bgcolor=FFFFFF&amp;face=arial&amp;size=9&amp;color=0000FF&amp;bgcolor=FFFFFF&amp;format[]=underline&amp;format[]=transparent&amp;format[]=transparent" /></a>, copyright infringement: <a href="http://www.domaintools.com/registrant-search/?email=1382952a07f500333b628e4a5b68b22f"><img border="0" align="middle" src="http://source.domaintools.com/email.pgif?md5=1382952a07f500333b628e4a5b68b22f&amp;face=arial&amp;size=9&amp;color=000000&amp;bgcolor=FFFFFF&amp;face=arial&amp;size=9&amp;color=0000FF&amp;bgcolor=FFFFFF&amp;format[]=underline&amp;format[]=transparent&amp;format[]=transparent" /></a>    <br />&#160;&#160; Domain Nameservers:    <br />&#160;&#160;&#160;&#160;&#160; NS01.DOT.TK    <br />&#160;&#160;&#160;&#160;&#160; NS02.DOT.TK    <br />&#160;&#160;&#160;&#160;&#160; NS03.DOT.TK    <br />&#160;&#160;&#160;&#160;&#160; NS04.DOT.TK</p>
<p>I then looked at her wall and saw that she posted similar messages to over 20 other people’s wall.. each with a similar message..</p>
<p>&#160;<a href="http://www.johnmunoz.net/wp-content/uploads/image25.png"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" border="0" alt="image" src="http://www.johnmunoz.net/wp-content/uploads/image_thumb20.png" width="141" height="443" /></a> </p>
<h5></h5>
<h6>with one of these three variants:</h6>
<h6>This seems like a good deal, what do you think? www.bk9wh.tk</h6>
<h6>Do you know anyone that has tried this? <a href="http://www.bk9wh.tk">www.bk9wh.tk</a></h6>
<h6>Do you think this stuff works? <a href="http://www.bk9wh.tk">www.bk9wh.tk</a></h6>
<p>The link takes you to a redirect that then reinfects you with the same bug and on and on it goes.&#160; </p>
<p><strong>Common Sense:</strong>&#160; Don’t click on links directly, and especially not suspicious ones from someone you know wouldn&#8217;t send you one otherwise.&#160; </p>
]]></content:encoded>
			<wfw:commentRss>http://www.johnmunoz.net/blog/over-the-river-and-on-the-wall/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Facebook assuming you want to share your information</title>
		<link>http://www.johnmunoz.net/blog/facebook-assuming-you-want-to-share-your-information</link>
		<comments>http://www.johnmunoz.net/blog/facebook-assuming-you-want-to-share-your-information#comments</comments>
		<pubDate>Fri, 23 Apr 2010 03:15:56 +0000</pubDate>
		<dc:creator>john</dc:creator>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[geekstuff]]></category>

		<guid isPermaLink="false">http://www.johnmunoz.net/blog/facebook-assuming-you-want-to-share-your-information</guid>
		<description><![CDATA[<p>Under account, Privacy Settings, Applications and Websites you’ll find a new option:</p> <p></p> <p>Facebooks states:</p> <p>Allowing instant personalization will give you a richer experience as you browse the web. If you opt-out, you will have to manually activate these experiences. Please keep in mind that if you opt out, your friends may still share [...]]]></description>
			<content:encoded><![CDATA[<p>Under account, Privacy Settings, Applications and Websites you’ll find a new option:</p>
<p><a href="http://www.johnmunoz.net/wp-content/uploads/image23.png"><img style="display: inline; border: 0px;" title="image" src="http://www.johnmunoz.net/wp-content/uploads/image_thumb18.png" border="0" alt="image" width="481" height="298" /></a></p>
<p>Facebooks states:</p>
<blockquote><p>Allowing instant personalization will give you a richer experience as you browse the web. If you opt-out, you will have to manually activate these experiences. Please keep in mind that if you opt out, your friends may still share public Facebook information about you to personalize their experience on these partner sites unless you block the application. <a href="http://www.facebook.com/help/?page=1068">Learn more.</a></p></blockquote>
<p>By default they have this option ON.  If you don’t want your information automatically shared with 3rd party sites uncheck this option.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.johnmunoz.net/blog/facebook-assuming-you-want-to-share-your-information/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sometimes it&#8217;s like they aren&#8217;t even trying</title>
		<link>http://www.johnmunoz.net/blog/sometimes-its-like-they-arent-even-trying</link>
		<comments>http://www.johnmunoz.net/blog/sometimes-its-like-they-arent-even-trying#comments</comments>
		<pubDate>Fri, 09 Apr 2010 04:13:59 +0000</pubDate>
		<dc:creator>john</dc:creator>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[geekstuff]]></category>

		<guid isPermaLink="false">http://www.johnmunoz.net/blog/sometimes-its-like-they-arent-even-trying</guid>
		<description><![CDATA[<p>This was in my inbox today…</p> <p></p> <p>The email address it was sent to isn’t the email address i use for my fb account.  And seriously, is there any legitimate use for zip files inside of email anymore?</p> <p>Common Sense:  Don’t even bother with zip files as attachments in email messages.  If you need [...]]]></description>
			<content:encoded><![CDATA[<p>This was in my inbox today…</p>
<p><a href="http://www.johnmunoz.net/wp-content/uploads/image22.png"><img style="display: inline; border: 0px;" title="image" src="http://www.johnmunoz.net/wp-content/uploads/image_thumb17.png" border="0" alt="image" width="549" height="305" /></a></p>
<p>The email address it was sent to isn’t the email address i use for my fb account.  And seriously, is there any legitimate use for zip files inside of email anymore?</p>
<p><strong>Common Sense:  Don’t even bother with zip files as attachments in email messages.  If you need to move data try dropbox or iFolder or some other transport system.</strong></p>
<p>My wife pointed out that facebook wouldn’t address me as “Dear user of facebook” they would say “Dear John”, they wouldn&#8217;t sign it “Your facebook”, and they would ask me to log in and change my password, not send me a new password.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.johnmunoz.net/blog/sometimes-its-like-they-arent-even-trying/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Facebook&#8217;s gone phishing</title>
		<link>http://www.johnmunoz.net/blog/facebooks-gone-phishing</link>
		<comments>http://www.johnmunoz.net/blog/facebooks-gone-phishing#comments</comments>
		<pubDate>Wed, 07 Apr 2010 22:08:52 +0000</pubDate>
		<dc:creator>john</dc:creator>
				<category><![CDATA[geekstuff]]></category>

		<guid isPermaLink="false">http://www.johnmunoz.net/blog/facebooks-gone-phishing</guid>
		<description><![CDATA[<p>I just got this group message from someone i know (but never gotten a message from before)</p> <p></p> <p>asking me to go “check out this interesting article”  DANGER WILL ROBINSON.  This is a common way of saying let me scam your money.</p> <p>Their wasn’t a link on this but a typed out website.  So [...]]]></description>
			<content:encoded><![CDATA[<p>I just got this group message from someone i know (but never gotten a message from before)</p>
<p><a href="http://www.johnmunoz.net/wp-content/uploads/image20.png"><img style="display: inline; border: 0px;" title="image" src="http://www.johnmunoz.net/wp-content/uploads/image_thumb15.png" border="0" alt="image" width="524" height="270" /></a></p>
<p>asking me to go “check out this interesting article”  DANGER WILL ROBINSON.  This is a common way of saying let me scam your money.</p>
<p>Their wasn’t a link on this but a typed out website.  So i typed that website which was a spoof from a common reputable news source. With a character added to the address.  Firefox immediately told me not to go any further, it was a scam.  Ok.. so i tried on IE (because i knew it wouldn&#8217;t block me) and this is what i saw.</p>
<p><a href="http://www.johnmunoz.net/wp-content/uploads/facebookscam2.jpg"><img style="display: inline; border: 0px;" title="facebook scam2" src="http://www.johnmunoz.net/wp-content/uploads/facebookscam2_thumb.jpg" border="0" alt="facebook scam2" width="248" height="357" /></a></p>
<p>They scraped the site from the reputable news agency, and added some links “Google Pay Day” Which takes you to what looks like a very well done version of an advertisers page.  Allot of time and money went into this one.  Obviously they are making quite a bit from it to justify the expense.  Don’t be fooled into adding to their pockets.</p>
<p><strong>Common Sense: If something looks suspicious, take extra caution to be sure your getting what your want to get to.  Only use websites you recognize, not only by look but by URL too. </strong></p>
<p>The actual site seams to be owned by someone in China.  (Darn Chinese Hackers (inside joke))</p>
<blockquote><p>Registrant Contact:<br />
YAN HUA<br />
HUA YAN <a href="http://www.domaintools.com/registrant-search/?email=732dae60e810f494ec8f4a0c22c4bbcc"><img src="http://source.domaintools.com/email.pgif?md5=732dae60e810f494ec8f4a0c22c4bbcc&amp;face=arial&amp;size=9&amp;color=000000&amp;bgcolor=FFFFFF&amp;face=arial&amp;size=9&amp;color=0000FF&amp;bgcolor=FFFFFF&amp;format[]=underline&amp;format[]=transparent&amp;format[]=transparent" border="0" alt="" align="middle" /></a><br />
053182149514 fax: 053182149514<br />
LONGSHANLU18<br />
JN SD 250019<br />
cn<br />
Administrative Contact:<br />
HUA YAN <a href="http://www.domaintools.com/registrant-search/?email=732dae60e810f494ec8f4a0c22c4bbcc"><img src="http://source.domaintools.com/email.pgif?md5=732dae60e810f494ec8f4a0c22c4bbcc&amp;face=arial&amp;size=9&amp;color=000000&amp;bgcolor=FFFFFF&amp;face=arial&amp;size=9&amp;color=0000FF&amp;bgcolor=FFFFFF&amp;format[]=underline&amp;format[]=transparent&amp;format[]=transparent" border="0" alt="" align="middle" /></a><br />
053182149514 fax: 053182149514<br />
LONGSHANLU18<br />
JN SD 250019<br />
cn<br />
Technical Contact:<br />
HUA YAN <a href="http://www.domaintools.com/registrant-search/?email=732dae60e810f494ec8f4a0c22c4bbcc"><img src="http://source.domaintools.com/email.pgif?md5=732dae60e810f494ec8f4a0c22c4bbcc&amp;face=arial&amp;size=9&amp;color=000000&amp;bgcolor=FFFFFF&amp;face=arial&amp;size=9&amp;color=0000FF&amp;bgcolor=FFFFFF&amp;format[]=underline&amp;format[]=transparent&amp;format[]=transparent" border="0" alt="" align="middle" /></a><br />
053182149514 fax: 053182149514<br />
LONGSHANLU18<br />
JN SD 250019<br />
cn<br />
Billing Contact:<br />
HUA YAN <a href="http://www.domaintools.com/registrant-search/?email=732dae60e810f494ec8f4a0c22c4bbcc"><img src="http://source.domaintools.com/email.pgif?md5=732dae60e810f494ec8f4a0c22c4bbcc&amp;face=arial&amp;size=9&amp;color=000000&amp;bgcolor=FFFFFF&amp;face=arial&amp;size=9&amp;color=0000FF&amp;bgcolor=FFFFFF&amp;format[]=underline&amp;format[]=transparent&amp;format[]=transparent" border="0" alt="" align="middle" /></a><br />
053182149514 fax: 053182149514<br />
LONGSHANLU18<br />
JN SD 250019<br />
cn<br />
DNS:<br />
ns1049.websitewelcome.com<br />
ns1050.websitewelcome.com<br />
ns1.lilil2iili.com<br />
ns2.lilil2iili.com<br />
Created: 2010-03-30<br />
Expires: 2011-03-30</p></blockquote>
<p>Update: 4/11/2010 Got the same message today this time asking for Local8News.net but the same scheme.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.johnmunoz.net/blog/facebooks-gone-phishing/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Is my antivirus actually working?</title>
		<link>http://www.johnmunoz.net/blog/is-my-antivirus-actually-working</link>
		<comments>http://www.johnmunoz.net/blog/is-my-antivirus-actually-working#comments</comments>
		<pubDate>Wed, 07 Apr 2010 15:54:12 +0000</pubDate>
		<dc:creator>john</dc:creator>
				<category><![CDATA[geekstuff]]></category>

		<guid isPermaLink="false">http://www.johnmunoz.net/blog/is-my-antivirus-actually-working</guid>
		<description><![CDATA[<p>as more and more people become aware of all the bad things out there in the tangled mess of the interweb, most people just take for granted that their antivirus software is actually working.</p> <p>I have a stock pile of known virus’s but they are not what i would want to use to test [...]]]></description>
			<content:encoded><![CDATA[<p>as more and more people become aware of all the bad things out there in the tangled mess of the interweb, most people just take for granted that their antivirus software is actually working.</p>
<p><a href="http://www.johnmunoz.net/wp-content/uploads/viruspendrive.jpg"><img style="display: inline; border: 0px;" title="virus-pendrive" src="http://www.johnmunoz.net/wp-content/uploads/viruspendrive_thumb.jpg" border="0" alt="virus-pendrive" width="244" height="179" /></a>I have a stock pile of known virus’s but they are not what i would want to use to test an otherwise healthy computer with, hence the EICAR test virus is the perfect solution.  Back when i first started using EICAR it stood for European Institute for Computer Antivirus Research.  Now EICAR is just known for their name as an security company rather than just AV.</p>
<p>You can download the test virus’s from their website,</p>
<p><a title="http://www.eicar.org/anti_virus_test_file.htm" href="http://www.eicar.org/anti_virus_test_file.htm">http://www.eicar.org/anti_virus_test_file.htm</a>.</p>
<p>The signature of the file is designed to set off any virus and label it as the EICAR Test-Virus but no actual harm is done to your computer if the antivirus doesn’t catch it.  It does give you the chance to see if your antivirus is actually working and picking up treats.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.johnmunoz.net/blog/is-my-antivirus-actually-working/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Even my sister has joined the bad guys.</title>
		<link>http://www.johnmunoz.net/blog/even-my-sister-has-joined-the-bad-guys</link>
		<comments>http://www.johnmunoz.net/blog/even-my-sister-has-joined-the-bad-guys#comments</comments>
		<pubDate>Tue, 06 Apr 2010 03:09:20 +0000</pubDate>
		<dc:creator>john</dc:creator>
				<category><![CDATA[geekstuff]]></category>

		<guid isPermaLink="false">http://www.johnmunoz.net/blog/even-my-sister-has-joined-the-bad-guys</guid>
		<description><![CDATA[<p>not willingly i hope though.&#160; Got this email from her a few moments ago.&#160; It was from someone i knew so i didn’t hesitate to open and investigate further.&#160; </p> <p> </p> <p>The email was also CC’d to other friends and family members i knew.&#160; It had these three thumbnails with links.&#160; I didn’t [...]]]></description>
			<content:encoded><![CDATA[<p>not willingly i hope though.&#160; Got this email from her a few moments ago.&#160; It was from someone i knew so i didn’t hesitate to open and investigate further.&#160; </p>
<p><a href="http://www.johnmunoz.net/wp-content/uploads/image19.png"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="Image of infected email" border="0" alt="Image of infected email" src="http://www.johnmunoz.net/wp-content/uploads/image_thumb14.png" width="566" height="319" /></a> </p>
<p>The email was also CC’d to other friends and family members i knew.&#160; It had these three thumbnails with links.&#160; I didn’t recognize the people in the images.&#160; There were not actual embedded attachments (kind of odd) i checked the link to see if it would actually go to an image and found it wanted to take me to: </p>
<p><a title="http://downx05.h12.ru/" href="http://downx05.h12.ru/">http://downx05.h12.ru/</a></p>
<p>Taking me to a Russian website.&#160; At the time i attempted to investigate the site further it was being overwhelmed by request to try and access that site.&#160; Those poor souls…</p>
<p><strong>Common Sense People:&#160; If your not expecting people to send you files, be weary.&#160; If it looks suspicious.. it probably is.</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://www.johnmunoz.net/blog/even-my-sister-has-joined-the-bad-guys/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Banking in my sleep?</title>
		<link>http://www.johnmunoz.net/blog/banking-in-my-sleep</link>
		<comments>http://www.johnmunoz.net/blog/banking-in-my-sleep#comments</comments>
		<pubDate>Mon, 05 Apr 2010 13:36:10 +0000</pubDate>
		<dc:creator>john</dc:creator>
				<category><![CDATA[geekstuff]]></category>

		<guid isPermaLink="false">http://www.johnmunoz.net/blog/banking-in-my-sleep</guid>
		<description><![CDATA[<p>I must have done it in my sleep because i don’t ever remember opening a checking account with Yorkshire Bank. Come to think of it.. i don’t even know where to find my local Yorkshire Bank.&#160; </p> <p> </p> <p>This should be the first sign of a bogus email.&#160; But for those who actually [...]]]></description>
			<content:encoded><![CDATA[<p>I must have done it in my sleep because i don’t ever remember opening a checking account with Yorkshire Bank. Come to think of it.. i don’t even know where to find my local Yorkshire Bank.&#160; </p>
<p><a href="http://www.johnmunoz.net/wp-content/uploads/image18.png"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" border="0" alt="image" src="http://www.johnmunoz.net/wp-content/uploads/image_thumb13.png" width="244" height="154" /></a> </p>
<p>This should be the first sign of a bogus email.&#160; But for those who actually DO have a Yorkshire account it may appear legitimate.&#160; Clicking on the link does not take you to the bank however.&#160; It goes</p>
<p><a title="http://mk.volina.ru/includes/patTemplate/patTemplate/Modifier/HTML/fullPassword.ctl.htm" href="http://mk.volina.ru/includes/patTemplate/patTemplate/Modifier/HTML/fullPassword.ctl.htm">http://mk.volina.ru/includes/patTemplate/patTemplate/Modifier/HTML/fullPassword.ctl.htm</a></p>
<p>FireFox, Chrome blocked the site, IE reported it as unsafe but brought it up</p>
<p>The site would then ask for your customer number, your password, all three of your security questions and answers as well as your email address.&#160; After entering such information and submitting would take you to the actual bank’s site, <a title="http://www.ybonline.co.uk/personal/ib-logout" href="http://www.ybonline.co.uk/personal/ib-logout">http://www.ybonline.co.uk/personal/ib-logout</a>&#160; but by then, it’s probably to late.&#160; you’ve just give all your sensitive information to the Russians.&#160; </p>
<p><strong>Common sense: If you bank does send you an email, log on to your banks site yourself.&#160; don’t use any enclosed links.&#160; That way you know your not being directed somewhere else without your knowledge.</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://www.johnmunoz.net/blog/banking-in-my-sleep/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The IRS is emailing me now?</title>
		<link>http://www.johnmunoz.net/blog/the-irs-is-emailing-me-now</link>
		<comments>http://www.johnmunoz.net/blog/the-irs-is-emailing-me-now#comments</comments>
		<pubDate>Wed, 31 Mar 2010 19:23:01 +0000</pubDate>
		<dc:creator>john</dc:creator>
				<category><![CDATA[geekstuff]]></category>

		<guid isPermaLink="false">http://www.johnmunoz.net/blog/the-irs-is-emailing-me-now</guid>
		<description><![CDATA[<p>I doubt the federal government would ever become that efficient. </p> <p> </p> <p>no paypload in the email itself.. but a few things to notice on this one.&#160; my email address isn’t in the to.&#160; The website at first glance looks like irs.gov but it’s actually eawsqu.pl registered to a guy in Germany:</p> <p>DOMAIN: [...]]]></description>
			<content:encoded><![CDATA[<p>I doubt the federal government would ever become that efficient. </p>
<p><a href="http://www.johnmunoz.net/wp-content/uploads/image14.png"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" border="0" alt="image" src="http://www.johnmunoz.net/wp-content/uploads/image_thumb9.png" width="244" height="155" /></a> </p>
<p>no paypload in the email itself.. but a few things to notice on this one.&#160; my email address isn’t in the to.&#160; The website at first glance looks like irs.gov but it’s actually eawsqu.pl registered to a guy in Germany:</p>
<p>DOMAIN: eawsqu.pl is releasing after termination   <br />created:&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; 2010.03.31 13:08:04    <br />last modified:&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; 2010.03.31 18:02:42    <br />expiration date:&#160;&#160;&#160;&#160;&#160;&#160;&#160; 2010.04.05 18:02:42    <br />no option    <br />REGISTRAR:    <br />Key-Systems GmbH    <br />Prager ring 4 &#8211; 12    <br />66482 Zweibrücken&#160; <br />Niemcy/Germany    <br />+49 6332791850    </p>
<p>Firefox gave me a big red warning when trying to visit the site.&#160; I much rather like FF’s warning rather than IE’s</p>
<p><a href="http://www.johnmunoz.net/wp-content/uploads/image15.png"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" border="0" alt="image" src="http://www.johnmunoz.net/wp-content/uploads/image_thumb10.png" width="244" height="154" /></a> </p>
<p>IE let the site come up but a tiny warning in the title bar</p>
<p><a href="http://www.johnmunoz.net/wp-content/uploads/image16.png"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" border="0" alt="image" src="http://www.johnmunoz.net/wp-content/uploads/image_thumb11.png" width="244" height="154" /></a> </p>
</p>
</p>
<p><a href="http://www.johnmunoz.net/wp-content/uploads/image17.png"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" border="0" alt="image" src="http://www.johnmunoz.net/wp-content/uploads/image_thumb12.png" width="244" height="72" /></a> </p>
<p>Telling me that the website may be unsafe.&#160; The site then ask users to download an EXE.&#160; I wonder what that could do…</p>
<p>Another case where common sense goes a long way.&#160; </p>
]]></content:encoded>
			<wfw:commentRss>http://www.johnmunoz.net/blog/the-irs-is-emailing-me-now/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>UPS delivers everything, even virus&#8217;?</title>
		<link>http://www.johnmunoz.net/blog/ups-even-delivers-everything-even-virus</link>
		<comments>http://www.johnmunoz.net/blog/ups-even-delivers-everything-even-virus#comments</comments>
		<pubDate>Wed, 31 Mar 2010 04:12:13 +0000</pubDate>
		<dc:creator>john</dc:creator>
				<category><![CDATA[geekstuff]]></category>

		<guid isPermaLink="false">http://www.johnmunoz.net/blog/ups-even-delivers-everything-even-virus</guid>
		<description><![CDATA[<p>Well, they might deliver bio hazards but not via email.  Here’s a letter i got this evening.</p> <p></p> <p>symantec let the file go right through the email.</p> <p>extracted the zip,</p> <p></p> <p>scanned the file again with symantec and</p> <p></p> <p>doubled check the date on my definitions.  they are current.  I’ll test it against sophos [...]]]></description>
			<content:encoded><![CDATA[<p>Well, they might deliver bio hazards but not via email.  Here’s a letter i got this evening.</p>
<p><a href="http://www.johnmunoz.net/wp-content/uploads/image11.png"><img style="display: inline; border: 0px;" title="image" src="http://www.johnmunoz.net/wp-content/uploads/image_thumb6.png" border="0" alt="image" width="244" height="129" /></a></p>
<p>symantec let the file go right through the email.</p>
<p>extracted the zip,</p>
<p><a href="http://www.johnmunoz.net/wp-content/uploads/image12.png"><img style="display: inline; border: 0px;" title="image" src="http://www.johnmunoz.net/wp-content/uploads/image_thumb7.png" border="0" alt="image" width="180" height="244" /></a></p>
<p>scanned the file again with symantec and</p>
<p><a href="http://www.johnmunoz.net/wp-content/uploads/image13.png"><img style="display: inline; border: 0px;" title="image" src="http://www.johnmunoz.net/wp-content/uploads/image_thumb8.png" border="0" alt="image" width="244" height="166" /></a></p>
<p>doubled check the date on my definitions.  they are current.  I’ll test it against sophos tomorrow and see what they say.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.johnmunoz.net/blog/ups-even-delivers-everything-even-virus/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>another attempt</title>
		<link>http://www.johnmunoz.net/blog/another-attempt</link>
		<comments>http://www.johnmunoz.net/blog/another-attempt#comments</comments>
		<pubDate>Mon, 29 Mar 2010 21:16:54 +0000</pubDate>
		<dc:creator>john</dc:creator>
				<category><![CDATA[geekstuff]]></category>

		<guid isPermaLink="false">http://www.johnmunoz.net/blog/another-attempt</guid>
		<description><![CDATA[<p>I was originally going to ignore this spam but i got it twice today so might as well share.</p> <p>&#160;</p> <p>MICROWORD.COM CORPORATIONS</p> <p>CUSTOMER SERVICE: TARRAGONA ESPANA Email: </p> <p>ADDRESS: C/ L&#8217;ESTANY, PARC. 2, POST CODE &#8211; 43006 CITY &#8211; TARRAGONA &#8211; SPAIN.</p> <p>MICROWORD.COM RESOURCE ADVERTISING LINK: http://www.microword.com/</p> <p>Date: 03/03/2010.</p> <p>MICROWORD.COM CORPORATIONS MARCH 2010 (3RD [...]]]></description>
			<content:encoded><![CDATA[<p>I was originally going to ignore this spam but i got it twice today so might as well share.</p>
<p>&#160;</p>
<blockquote><p>MICROWORD.COM CORPORATIONS</p>
<p>CUSTOMER SERVICE: TARRAGONA ESPANA Email: </p>
<p>ADDRESS: C/ L&#8217;ESTANY, PARC. 2, POST CODE &#8211; 43006 CITY &#8211; TARRAGONA &#8211; SPAIN.</p>
<p>MICROWORD.COM RESOURCE ADVERTISING LINK: <a href="http://www.microword.com/">http://www.microword.com/</a></p>
<p>Date: 03/03/2010.</p>
<p>MICROWORD.COM CORPORATIONS MARCH 2010 (3RD TO 30TH) OFFICIAL WINNING NOTIFICATION.</p>
<p>Good day, we write to inform you that your email address has won, in the microword.com corporation internet March 2010 promotions. Your email address was selected randomly from the microword.com automatic computer generated machine, and your email address emerges as one of the online winners. This attracts a prize of Three hundred thousand Euros only (300,000.00 Euro) and an Apple 13.3&quot; Mac Book Pro Notebook laptop.</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</p>
<p>*Your won cheque of three hundred thousand Euros (300,000.00 Euro) and Apple 13.3&quot; Mac Book Pro Notebook laptop will be presented to you on arrival to our office in Tarragona, within the period of 30 days. Your winnings will be cancelled, if you do not present yourself at our office, within the given period of 30 days.</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>*If you are unable to come to our office in Tarragona- Spain to claim your won prize, your won prize will be presented to you by courier delivery via the promotion board contracted courier company. Microword.com Corporation is not responsible for the delivery changes [charges?] to your location. You will pay for the cost of delivery yourself. Please do not respond to this option, if you know, you will not pay for the courier service delivery. [ got, enough, commas, in there?]</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>Please note: The draft certified cheque and all documents are packaged to be delivered under one way bill by the contracted courier company and are categorized as high priority &amp; express delivery under applicable laws and regulations. This shipment cannot be delivered to P.O. boxes or postal codes but only to you the receiver at your given address.</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>For more information&#8217;s, on how to claim your prize, do contact our promotions department via the email below or via telephone, and quote this reference number: MSTF/2010/XУNAJZ/MAR 3-30/KFYXQX as you contact our promotion department. This reference number is the security key to your winnings, we advice you keep the reference number to yourself.</p>
<p>Microword.com promotion department.</p>
<p>Tel: 0034- 634 176 053</p>
<p>Tel: 0034- 659 347 846</p>
<p>Email: <a href="mailto:promotion_department@micro-word.com">promotion_department@micro-word.com</a></p>
<p>This promotion is organized by microword.com to advertise and to promote our website, <a href="http://www.microword.com/">http://www.microword.com/</a> which is based on all kind internet companies, all kind of computer hardware and software product. This promotion is as well organized to encourage the use of the Internet user and to promote computer literacy worldwide.</p>
<p>Congratulations to you lucky winner!</p>
<p>Sincerely,</p>
<p>Mr. Golf . P Ivan.</p>
<p>CEO: MSFT Word Resource Tarragona.</p>
<p>Copyright © 1992-2010 Micro-word.Com All rights reserved.</p>
<p>===========================================================</p>
<p>NOTICE TO RECIPIENT: THIS E-MAIL IS MEANT FOR ONLY THE INTENDED RECIPIENT OF THE TRANSMISSION, AND MAY BE A COMMUNICATION PRIVILEGED BY LAW. IF YOU RECEIVED THIS E- MAIL IN ERROR, ANY REVIEW, USE, DISSEMINATION, DISTRIBUTION OR COPYING OF THIS E-MAIL IS STRICTLY PROHIBITED.</p>
<p>PLEASE NOTIFY CUSTOMER SERVICE: TARRAGONA ESPANA VIA EMAIL: <a href="mailto:info@micro-word.com">info@micro-word.com</a> IMMEDIATELY OF THE ERROR BY RETURN E-MAIL AND PLEASE DELETE THIS MESSAGE FROM YOUR SYSTEM. THANK YOU IN ADVANCE FOR YOUR CO-OPERATION.</p>
</blockquote>
<p>A few things to note, </p>
<ul>
<li>country code returns to spain.&#160; </li>
<li>the email address uses the domain micro-world.com but the web links provided use microworld.com</li>
<li>micro-world.com belongs to a company in Torrance, CA where the company in this email is from Spain.&#160; </li>
<li>the company wants you to pick up the “prize” in Spain or have them deliver it COD (for shipping expenses).&#160; I wonder how much that COD charge would be.&#160; </li>
<li>The lack of grammar is another good give away (no pun in intended)</li>
</ul>
<p>Basically, one of those deals where if you never entered a contest in spain, and they want you to pay up front, too good to be true.&#160; sorry.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.johnmunoz.net/blog/another-attempt/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
