23
Using Social Networks to Harvest Email Addresses Reporter: Chia-Yi Lin Advisor: Chun-Ying Huang Mail: [email protected] 06/14/22 1

Using Social Networks to Harvest Email Addresses Reporter: Chia-Yi Lin Advisor: Chun-Ying Huang Mail: [email protected] 9/14/2015 1

Embed Size (px)

Citation preview

Page 1: Using Social Networks to Harvest Email Addresses Reporter: Chia-Yi Lin Advisor: Chun-Ying Huang Mail: m98570015@ntou.edu.tw 9/14/2015 1

Using Social Networks to Harvest Email Addresses

Reporter: Chia-Yi LinAdvisor: Chun-Ying HuangMail: [email protected]

04/21/23

1

Page 2: Using Social Networks to Harvest Email Addresses Reporter: Chia-Yi Lin Advisor: Chun-Ying Huang Mail: m98570015@ntou.edu.tw 9/14/2015 1

Reference

• I. Polakis, G. Kontaxis, S. Antonatos, E. Gessiou, T. Petsas, and E. P. Markatos, “Using social networks to harvest email addresses,” in WPES ’10: Proceedings of the 9th annual ACM workshop on Privacy in the electronic society

04/21/23

2

Page 3: Using Social Networks to Harvest Email Addresses Reporter: Chia-Yi Lin Advisor: Chun-Ying Huang Mail: m98570015@ntou.edu.tw 9/14/2015 1

Outline

•Introduction•Social network harvest email•Facebbok informaition•Conclusions

04/21/23

3

Page 4: Using Social Networks to Harvest Email Addresses Reporter: Chia-Yi Lin Advisor: Chun-Ying Huang Mail: m98570015@ntou.edu.tw 9/14/2015 1

Introduction

•Social networking is one of the most popular Internet activities▫Facebook has more than 400 million users ▫Twitter has more than 40 million users

•Privacy leakage is one of the biggest problems of social networking

04/21/23

4

Page 5: Using Social Networks to Harvest Email Addresses Reporter: Chia-Yi Lin Advisor: Chun-Ying Huang Mail: m98570015@ntou.edu.tw 9/14/2015 1

•http://www.checkfacebook.com/

04/21/23

5

Page 6: Using Social Networks to Harvest Email Addresses Reporter: Chia-Yi Lin Advisor: Chun-Ying Huang Mail: m98570015@ntou.edu.tw 9/14/2015 1

Social network

•Used for malicious purposes▫name, nickname

https://www.facebook.com/btaylor

•How names extracted from social networks ▫harvest email addresses

•Names collected▫Facebook and Twitter networks

•Query terms for the Google search engine▫harvest almost 9 million unique email

04/21/23

6

Page 7: Using Social Networks to Harvest Email Addresses Reporter: Chia-Yi Lin Advisor: Chun-Ying Huang Mail: m98570015@ntou.edu.tw 9/14/2015 1

Current Methodologies

•Give a brief overview of the current methodologies used by spammers to harvest email addresses▫Web crawling▫Crawling mailing list archives sites▫Malware▫Malicious sites▫Dictionary attacks

04/21/23

7

Page 8: Using Social Networks to Harvest Email Addresses Reporter: Chia-Yi Lin Advisor: Chun-Ying Huang Mail: m98570015@ntou.edu.tw 9/14/2015 1

Two approaches

•Present two different approaches to harvesting▫Blind harvesting▫Targeted harvesting

•Social network▫Facebbok and Twitter

•Google search engine▫gather email addresses

•Facebook▫personal information

04/21/23

8

Page 9: Using Social Networks to Harvest Email Addresses Reporter: Chia-Yi Lin Advisor: Chun-Ying Huang Mail: m98570015@ntou.edu.tw 9/14/2015 1

Find name and nickname

•Crawlers for extracting names▫Facebook

fan pages▫Twitter

crawled the accounts the user follows

04/21/23

9

Page 10: Using Social Networks to Harvest Email Addresses Reporter: Chia-Yi Lin Advisor: Chun-Ying Huang Mail: m98570015@ntou.edu.tw 9/14/2015 1

Google search engine

•Once the names have been harvested▫8 different combinations

"[email protected]", "term“, "[email protected]", "term at “,"[email protected]", "term@", "[email protected]", "[email protected]"

▫retrieve the first 50 results▫parse the two-line summary provided

04/21/23

10

Page 11: Using Social Networks to Harvest Email Addresses Reporter: Chia-Yi Lin Advisor: Chun-Ying Huang Mail: m98570015@ntou.edu.tw 9/14/2015 1

Blind Harvesting (1/2)

•Able to harvest, on average▫45 emails per name for the Facebook

names▫25 emails per name for the Twitter

nicknames

04/21/23

11

Page 12: Using Social Networks to Harvest Email Addresses Reporter: Chia-Yi Lin Advisor: Chun-Ying Huang Mail: m98570015@ntou.edu.tw 9/14/2015 1

Blind Harvesting (2/2)• Dictionary :http://wordnet.princeton.edu/• Surnames: http://www.census.gov/genealogy/www/data/

04/21/23

12

Page 13: Using Social Networks to Harvest Email Addresses Reporter: Chia-Yi Lin Advisor: Chun-Ying Huang Mail: m98570015@ntou.edu.tw 9/14/2015 1

Targeted harvesting (1/3)

•Traditional phishing contain generic terms▫“Dear user”, ”Dear customer”, ”Hello

subscriber”•Personalized phishing

▫Email look like they originate from a friend

04/21/23

13

Page 14: Using Social Networks to Harvest Email Addresses Reporter: Chia-Yi Lin Advisor: Chun-Ying Huang Mail: m98570015@ntou.edu.tw 9/14/2015 1

Targeted harvesting (2/3)

•Use the harvested email addresses in the Facebook search utility▫gain profile

•The first technique▫Uses information from the Facebook network

Successfully link 11.5% of the harvested names with their actual email address

•The second technique▫Uses information from the Twitter network

43.4% of the profiles returned

04/21/23

14

Page 15: Using Social Networks to Harvest Email Addresses Reporter: Chia-Yi Lin Advisor: Chun-Ying Huang Mail: m98570015@ntou.edu.tw 9/14/2015 1

Targeted harvesting (3/3)

•The third technique▫collected from other social networks▫harvest profiles from Google Buzz

40.5% valid Gmail addresses

04/21/23

15

Page 16: Using Social Networks to Harvest Email Addresses Reporter: Chia-Yi Lin Advisor: Chun-Ying Huang Mail: m98570015@ntou.edu.tw 9/14/2015 1

Fetch name

•Method▫facebook app▫friend

04/21/23

16

Page 17: Using Social Networks to Harvest Email Addresses Reporter: Chia-Yi Lin Advisor: Chun-Ying Huang Mail: m98570015@ntou.edu.tw 9/14/2015 1

Permissions

•Read Permissions•Write Permissions•Page Permissions

04/21/23

17

Page 18: Using Social Networks to Harvest Email Addresses Reporter: Chia-Yi Lin Advisor: Chun-Ying Huang Mail: m98570015@ntou.edu.tw 9/14/2015 1

Basic profile

04/21/23

18

Page 19: Using Social Networks to Harvest Email Addresses Reporter: Chia-Yi Lin Advisor: Chun-Ying Huang Mail: m98570015@ntou.edu.tw 9/14/2015 1

04/21/23

19

Page 20: Using Social Networks to Harvest Email Addresses Reporter: Chia-Yi Lin Advisor: Chun-Ying Huang Mail: m98570015@ntou.edu.tw 9/14/2015 1

Facebook profile

04/21/23

20

Page 21: Using Social Networks to Harvest Email Addresses Reporter: Chia-Yi Lin Advisor: Chun-Ying Huang Mail: m98570015@ntou.edu.tw 9/14/2015 1

Content categorization

04/21/23

21

Page 22: Using Social Networks to Harvest Email Addresses Reporter: Chia-Yi Lin Advisor: Chun-Ying Huang Mail: m98570015@ntou.edu.tw 9/14/2015 1

Conclusions

•We present how information, that is publicly available in social networking sites▫for harvesting email addresses▫deploying personalized phishing campaigns

•We present two different approaches to harvesting email▫greatly enhance the efficiency of a spam

campaign

04/21/23

22

Page 23: Using Social Networks to Harvest Email Addresses Reporter: Chia-Yi Lin Advisor: Chun-Ying Huang Mail: m98570015@ntou.edu.tw 9/14/2015 1

Thanks for Your AttentionQ & A

04/21/23

23