dslreports logo
 story category
Identity Theft Trojan on Monster.com
Trying to get work could get you in trouble

Watch out when applying for jobs online, particularly if you’re a user of the popular Monster.com job site. Security researchers recently found that the site was being widely used for identity theft. Hackers are placing fake ads on the site; the ads are infected with a Trojan that takes information that job seekers place online which includes social security numbers. The scam is one of the biggest of its kind and could affect over 100,000 identities.

view:
topics flat nest 

Dan48
Trailer Park Supervisor
Premium Member
join:2002-12-17
Eh?

Dan48

Premium Member

ahem

Monster you are responsible! Fix this.
--
Karma

Joeblow43
@embarqhsd.net

Joeblow43

Anon

Re: ahem

Monster.com is pretty much useless. I can't remember the last time I found any good jobs on it. I deleted my account just a few weeks ago.
makaze
Premium Member
join:2004-02-23
USA

makaze

Premium Member

Re: ahem

I got my current job via Monster, I simply had my resume posted on it.

POB
Res Firma Mitescere Nescit
Premium Member
join:2003-02-13
Stepford, CA

2 edits

POB

Premium Member

.

NM

n2jtx
join:2001-01-13
Glen Head, NY

n2jtx

Member

Why?

Why on earth would you supply any personal information, other than what you have in your resume, to a firm online? If they want that information, they call you in for an interview and you fill out the requisite forms at that time.
--
I support the right to keep and arm bears.

FFH5
Premium Member
join:2002-03-03
Tavistock NJ
kudos:5

2 edits

FFH5

Premium Member

Re: Why?

said by n2jtx:

Why on earth would you supply any personal information, other than what you have in your resume, to a firm online? If they want that information, they call you in for an interview and you fill out the requisite forms at that time.
They don't have to. Once your PC is infected with the trojan, it captures ALL browser activity. Including those you have with banks, insurance companies, etc.

The mere act of going to the bogus job ad site does the infecting. After that you are open to having all your online activity capturd and sent to the hacker.

»www.informationweek.com/ ··· IWK_News
"When a user views or clicks on one of the malicious ads, their PC is getting infected and all the information they are entering into their browser, including financial information being entered before it reaches the SSL-protected sites, is being captured and sent off to the hacker's server in Asia Pacific."
You didn't read the linked story, did you?
--
--
Internet News
My BLOG
My Web Page
Headtalk
join:2001-08-17

Headtalk

Member

Re: Why?

This issue has been going on for at least 6 months. I have been sent 3 or 4 phishing e-mails and notified them at least two times. Monster has some real security problems with there code on there site.

-G
Joe12345678
join:2003-07-22
Des Plaines, IL

Joe12345678 to n2jtx

Member

to n2jtx
said by n2jtx:

Why on earth would you supply any personal information, other than what you have in your resume, to a firm online? If they want that information, they call you in for an interview and you fill out the requisite forms at that time.
some firms make you there online system to enter you info and upload a resume.

aurgathor
join:2002-12-01
Lynnwood, WA
kudos:2

aurgathor

Member

Re: Why?

And what personal information is in a resume? Name, address, and email address. Nothing about SSN, banks, password, etc.
NGOwner
join:2000-11-21
Leawood, KS

NGOwner to n2jtx

Member

to n2jtx
I have little sympathy for those who do not know enough to keep their systems up to date.

The Trojan is designed to exploit several different software flaws, including vulnerabilities -- all of which have been patched by the vendors -- in Microsoft's Internet Explorer browser, WinZip and Apple's QuickTime.
[NG]Owner
--
It is impossible to create an idiot-proof product. Humanity is simply too adept at churning out better idiots.

FFH5
Premium Member
join:2002-03-03
Tavistock NJ
kudos:5

1 edit

FFH5 to n2jtx

Premium Member

to n2jtx
After investigation, the number of stolen records has now grown to 1.6 million.

»www.computerworld.com/ac ··· _ts_head
The 46,000 people reportedly infected by ads on job sites may be only a fraction of the victims of an ambitious, multistage attack that has stolen data belonging to several hundred thousand people who posted resumes on Monster.com, a researcher said this weekend.

According to Symantec Corp. security analyst Amado Hidalgo, a new Trojan horse called Infostealer.Monstres by Symantec has stolen more than 1.6 million records belonging to several hundred thousand people from Monster Worldwide Inc.'s job search service.
--
--
Internet News
My BLOG
My Web Page

antdude
A Ninja Ant
VIP
join:2001-03-25
United State
kudos:5
·Time Warner Cable

antdude

VIP

Re: Why?

»www.symantec.com/enterpr ··· jan.html from »digg.com/security/Monste ··· m_Hacked ...
amungus
Premium Member
join:2004-11-26
America
kudos:1
·Cox HSI

amungus

Premium Member

I wonder

Very serious question - would AdBlock(plus?) have blocked this (these?) ads???

...Where are all the naysayers against ad blocking now???
IMHO, most of the reason for blocking ads is for EXACTLY this kind of reason - not totally to block out legit ads from people, but to kill the crappy ones...

devrandom
I got a pot, full of random stuff here
Premium Member
join:2003-06-28

devrandom

Premium Member

Re: I wonder

Heh, thats what I was thinking. "Where is the Adblock guy now?"

Jigsaw
Stardust We Are
Premium Member
join:2000-10-21
Cleveland, OH

Jigsaw

Premium Member

Re: I wonder

said by devrandom:

Heh, thats what I was thinking. "Where is the Adblock guy now?"
He's looking for a job on Monster.com .
--
»www.auralmoon.com/ Stimulating ears for 7 years

AlphaOne
I see
Premium Member
join:2004-02-21
kudos:1

AlphaOne to devrandom

Premium Member

to devrandom
said by devrandom:

Heh, thats what I was thinking. "Where is the Adblock guy now?"
He works for this scambugs (adds provider).
my4k9s
join:2007-08-20
Republic, MO

my4k9s

Member

Monster.com Identity Theft

How about Career.com and other sites? Better security or SSDD?


How about ..