Experts Round Table Network
Navigate
Home
ArticleWiki
Forum
Journal
Search
Newsletter
Links
Tech News
expertsrt.com
Welcome Guest.
Username:
Password:
Remember me
Forgot your password?
Register
Blue Security "Blue Frog"
Welcome,
Guest
. Please
login
or
register
.
December 02, 2008, 07:23:40 PM
11304
Posts in
1248
Topics by
498
Members
Latest Member:
katCheeme
Home
Help
Search
Login
Register
Experts Round Table Network
|
Community Affairs
|
Soapbox
|
Blue Security "Blue Frog"
« previous
next »
Pages:
[
1
]
2
3
Print
Author
Topic: Blue Security "Blue Frog" (Read 1707 times)
seandelaney
Mentor
Offline
Posts: 119
Blue Security "Blue Frog"
«
on:
May 02, 2006, 02:33:55 AM »
[Edited by Matt to fix the typo in Rod's name]
A few months ago I signed up to Blue Security.
(I found out about it on Rod's site - rodsdot.com)
I registered a few email addresses and my domain name, plus my girlfriends domain name hoping to stop :scratch: minimise SPAM...
At the beginning I recieved no more SPAM emails.
But yesterday, I got this email soposely from Blue Security.
After I opened it, I noticed it wasnt! I continued to read the email and to short a long story short, it basically said, "I'm XYZ, and i've got access to all the Blue Security email addresses in the Blue Security database and that XYZ will be sending me 20-40 spam emails everyday as im a members.... blah blah blah...
I though it was a joke, ignored the email and deleted it, but today, when I checked my email.. guess what....?
Kinda thinking XYZ is telling the truth now?
Is anybody else a member of Blue Security and got this email?
Logged
Sean
Mentor Written Articles:
http://www.expertsrt.com/articles/index.shtml
seandelaney
Mentor
Offline
Posts: 119
Blue Security "Blue Frog"
«
Reply #1 on:
May 02, 2006, 02:39:56 AM »
And i've just noticed that the Blue Security site is down at the moment...
Logged
Sean
Mentor Written Articles:
http://www.expertsrt.com/articles/index.shtml
rdivilbiss
Governing Council Member
Offline
Posts: 414
Blue Security "Blue Frog"
«
Reply #2 on:
May 02, 2006, 08:02:26 AM »
It is Ro
d
not Rob, and therefore rodsdot.com not ro
b
sdot.com.
That being said, there is an active lounge thread about BlueSecurity including some info about their web site being under constant DDOS attack by some spammers.
Lounge Post:
http://www.suspendedexpert.com/forum/forum_posts.asp?TID=871&PN=1
Logged
Rod
seandelaney
Mentor
Offline
Posts: 119
Blue Security "Blue Frog"
«
Reply #3 on:
May 02, 2006, 08:08:38 AM »
Yes i did notice the typos. I would have fixed it but can edit.
OK i will take a look...
Logged
Sean
Mentor Written Articles:
http://www.expertsrt.com/articles/index.shtml
nicholassolutions
Administrator
Offline
Posts: 133
Blue Security "Blue Frog"
«
Reply #4 on:
May 02, 2006, 08:26:04 AM »
If I'm not mistaken, there is a large percentage of fakes in the email database (there might be ways to get around this), and if so, it's fairly likely that whomever is doing this will be tracked closely and caught.
I'll tell you what though: this kind of crap makes me almost violent with rage. I keep meaning to sign up for that, and this only bolsters that urge. As soon as their site is back up I'm getting it.
Logged
CrYpTiC_MauleR
Site Builder
Offline
Posts: 489
Blue Security "Blue Frog"
«
Reply #5 on:
May 02, 2006, 10:12:52 AM »
Have we though of using PGP/GnuPG for emails from ERT? So can be signed and be authenticated so less likely to be a fake ERT email from admin saying such and such. Have a page on site showing PGP keys for various admins and one key that the site itself uses to send emails.
Fake emails from sites makes the real site look bad, as you can see from the Blue Frog site's fake emails making Sean not know if its real message or not. Can really hurt in my opinion, especially if someone sends emails out saying site is being discontinued and all accounts have been removed. People will likely just not come back to site again thinking the email was true.
Just my 2 cents. =oP
Logged
[
x
]
Fight
|
www.crypticmauler.com
"You must be
nicholassolutions
Administrator
Offline
Posts: 133
Blue Security "Blue Frog"
«
Reply #6 on:
May 02, 2006, 10:20:57 AM »
I'm certainly not against it, although the average user probably doesn't know how to use PGP or have it installed. I'm not exactly sure how we'd implement it either, but none of that means we can't or shouldn't do it. If you'd be interested in working on it, let me know. I'm fooling around with the phpBB mailing code, so it would probably have to wait until after that, but it's definitely worth exploring.
On a related note, I was mistaken when I said the host offers free SSL certs (you have to buy them, they won't install self-signed ones). Right now I'm not willing to spend the extra money to get on (~$50), but if there's a need in the future we can talk about it again.
Logged
rdivilbiss
Governing Council Member
Offline
Posts: 414
Blue Security "Blue Frog"
«
Reply #7 on:
May 02, 2006, 10:50:48 AM »
Also you have three domains (if you include the forum) to deal with.
Logged
Rod
VGR
Mentor
Offline
Posts: 682
Blue Security "Blue Frog"
«
Reply #8 on:
May 03, 2006, 01:34:01 AM »
all valid points above.
1) the SSL certificate files could perhaps be uploaded ? :-#
2) PGP has greatly evolved towards better user-frendship since 1996 and the time I started using it on 2048 bits keys :oops:
Now people use "WinPGP" if I'm not mistaken. It also incorporates easily in any real email client, like my Eudora. It's simply clicking here and there to get the emails signed and/or encrypted, and the handfling of the key rings is a lot easier than with the original DOS version :D :D :D
I think this could be considered. An other solution is to add a "verification" link in each email sent by ERT, that validates the email against the database and answers "genuine" or "forged". This could even be a web service. This could even be an AJAX/JScript call from the HTML of the email (1) in an IMG tag, that would read "genuine" or "forged" directly in the email, after having vaidated at ERT's server. This can be worked around, though. There is no perfect solution.
The first step would be to recommend ERT users to use an "anti-phishing" browser and email client, like Firefox+Thunderbird, Firefox+Eudora (as I do) or - claimed - the new IE 7 beta2 + Outlook+some security add-on
(1) yes, I know this isn't active for everybody, but I guess people that deactivate JScript and/or HTML in their email client know better than the others how to handle suspicious emails and won't be phished as easily, so let's go on with this
Logged
techie overlord, answers all kind of questions on
http://www.europeanexperts.org
seandelaney
Mentor
Offline
Posts: 119
Blue Security "Blue Frog"
«
Reply #9 on:
May 03, 2006, 06:20:18 AM »
http://www.realtechnews.com/posts/3011
Logged
Sean
Mentor Written Articles:
http://www.expertsrt.com/articles/index.shtml
Batalf
Site Builder
Offline
Posts: 20
Blue frog and Javascript error reporting
«
Reply #10 on:
May 12, 2006, 07:52:46 AM »
Hi all,
I've also registered at Blue Security and installed the Blue Frog extension.
However, I had to uninstall Blue Frog because it seems that it disabled the Javascript error reporting in IE. We develop web applications for both IE and FF, so JS reporting is nescessary.
So, if someone have experienced the same kind of behaviour, it could be because of Bluefrog.
Logged
Batalf
rdivilbiss
Governing Council Member
Offline
Posts: 414
Blue Security "Blue Frog"
«
Reply #11 on:
May 12, 2006, 08:08:35 AM »
I haven't seen that problem.
Logged
Rod
Batalf
Site Builder
Offline
Posts: 20
Blue Security "Blue Frog"
«
Reply #12 on:
May 12, 2006, 08:14:24 AM »
Strange
I installed Blue Frog both on my work computer and at home. JS error reporting in IE stopped working on both of them. I uninstalled Blue Frog from my work computer earlier today and that solved the problem.
Logged
Batalf
rdivilbiss
Governing Council Member
Offline
Posts: 414
Blue Security "Blue Frog"
«
Reply #13 on:
May 12, 2006, 08:45:17 AM »
I certainly was not doubting what you said happened.
I was just not seeing the same behavior here. BlueFrog does claim to have a web mail reporting feature, but I don't use web mail. Possibly the browser helper is the problem.
Note in the picture above I have BHODemon installed and can disable any IE browser helpers, such as "BluefrogBho.IEHelper.1."
I do not have that browser helper disabled, but did make sure the options to enable script debugging were correct in the IE Options before testing it.
Logged
Rod
rdivilbiss
Governing Council Member
Offline
Posts: 414
Blue Security "Blue Frog"
«
Reply #14 on:
May 12, 2006, 08:47:20 AM »
Quote from: "rdivilbiss"
I do not have that browser helper (BluefrogBho.IEHelper.1) disabled ...
But I am going to disable it because I do not use web mail interfaces. I'll let you know if that causes and issue.
Logged
Rod
Pages:
[
1
]
2
3
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
ERT 1.5
-----------------------------
=> Round Table Learning Center
=> Bug reports
-----------------------------
Legacy
-----------------------------
=> The next level
=> History of ERT
-----------------------------
Community Affairs
-----------------------------
=> Introductions
=> Ballot Box
===> Closed Polls
=> Soapbox
=> Propose and Consult
===> Propose and Consult...CLOSED
-----------------------------
Bits and Bytes
-----------------------------
=> Tips, Tricks, Snippets, Tidbits And General Pearls Of Wisdom
-----------------------------
Serverside Technology
-----------------------------
=> PHP
=> ASP
-----------------------------
Webservers
-----------------------------
=> Apache
=> IIS
-----------------------------
Databases
-----------------------------
=> MySQL
=> Access
=> MS SQL Server
-----------------------------
Clientside Technology
-----------------------------
=> HTML
=> CSS
=> Javascript
=> Flash
=> WAP/WML
-----------------------------
Web Technologies
-----------------------------
=> General Web Dev
=> Web Standards
=> XML
=> Online Marketing
-----------------------------
Graphics
-----------------------------
=> Graphics Design and Animation
-----------------------------
Programming
-----------------------------
=> .NET
=> JAVA
=> MS DOS Batch Scripting
=> Mathematics
=> C & C++
=> VB
=> Delphi
=> Algorithm design
-----------------------------
Operating Systems
-----------------------------
=> Windows (General)
=> NT Based (2K, 2K-03, NT, XP, Vista)
=> Open Source (All)
-----------------------------
Hardware
-----------------------------
=> Hardware General
=> Gamers Hardware (Advanced)
-----------------------------
Networking
-----------------------------
=> Home (small)
=> Office (large)
=> Internet
-----------------------------
Security
-----------------------------
=> General Security Issues
-----------------------------
Rants/Opinions/Proposals
-----------------------------
=> Site operation
Powered by SMF 1.1 RC2
|
SMF © 2001-2005, Lewis Media
Joomla Bridge by
JoomlaHacks.com