Be careful, there's a very effective trojan on the loose.
You click a link in an email, it sends you to a spoof website where the trojan first determines which browser/os you're running before deciding which exploit to use to plant its code. You don't have to download anything, and apart from a 4 second delay while the browser redirects, you are totally unaware that you've been infected.
I've got about ten of these emails so far today, and they all look very convincing. Thankfully I haven't clicked the link.
I've been getting some e-mails from several people lately with links. They come from people I know, but the subject lines are out of the ordinary of what I expect to get from these people, and the body is never anything other than a link. Sets off my B.S. detector right away, but some people may assume it's trustworthy, coming from someone they know. The tip-off is that it is not the kind of message you would normally get from these people. My sister in law is bringing me her laptop to run some malware removal on later today.
My brother was infected by one of these fake LinkedIn emails earlier. It surprised me, as he's a techie. He was running Opera browser on fully patched Win7. So even less common browsers running on the latest OS versions are susceptible.
He downloaded Microsoft Security Essentials which *appears* to have got rid of it.
Zeus is on the loose! LOL! Not that it's funny. I've seen a bunch of spoof links being posted on facebook recently. Someone posts something along the lines of "I got free such & such" with a link. Then later, that person will post to say they didn't post that. I wonder if this is also a variation?
The facebook 'like' scam is not as malicious - It uses a weakness in facebook to hide some javascript which means you don't have to actually click the 'like' button for it to register as a 'like' click - All you have to do is hover over the page.
Zeus is used to plant a trojan on your PC - This is then controlled by criminal gangs to steal your userids and passwords (for banking sites, paypal etc.) They can also use your PC to send out more trojan emails, which is how it spreads.
Someone running hidden code on your PC is a very bad thing - And the longer you're not aware of it, the more likely it is that they'll grab a password or two...
Fortunately the facebook 'like' trick doesn't fall into this category; all it does is spam your wall with 'likes' you don't like... :)
The facebook 'like' scam is not as malicious - It uses a weakness in facebook to hide some javascript which means you don't have to actually click the 'like' button for it to register as a 'like' click - All you have to do is hover over the page.
Which is why I like to recommend installing a scriptblocking extension to your browser. It's a hassle to use it at first, but by only allowing the Javascript needed for a web site to work, a major point of entry for malware is blocked.
Thanks for that, yo_spiff - I'll give it a spin later.
Incidentally - I'm still receiving these fake LinkedIn emails at the rate of 1 every half hour - They're also by-passing my gmail spam filter and going straight to my inbox.