Brushing up my "In"-ter-nET Sec-xx-Urity knowledge. It's a scary
world out there. Thanks to the power of search engine and ease of use
of "canned" software. "Canned" software; that is, after you install
with the "default" configurations you are up and running in no time.
The convenient factor.
Go ahead and open up the G search that are so famous of late. In the
big square box, type in (without quotes) "resume filetype:doc" If you
want to do a more specific search, you can, after "doc" do a space and
then click the + sign and type in your keyword. Now
go ahead
and do you S-
earch
What you see is a list of rEsuMES on servers around the world. Scary
part is, these are WoRd documents you can just download. And once you
have it downloaded, you can edit it just your like your own document.
And since MS is so nice it stores extra information,
One can view the
"metadata" .... aka
additional information about the username of your system and the
company, etc.... from an option called "Properties..." under File.
Nice huh? Nope, Scary!
This is the first step of the latest technique in stealing identity
and h@cking a
target. I did a test this
morning and in 20 minutes,
I know more about a person including his appointment to Sa
$k gov with a 6-digit salary
All there for a person to see
The information is out there and too easy to get to with or without a
person knowing. I pull off a resume form a person who is living in
the M.E.
and he worked for an Indian company
and that Indian company, an IT firm was working under contract
for my former company doing
database upgrade in 2009. This person even wrote down every single
detail of the tools and products used during that period ....
Now, a h@ckER using technical information obtained can attempt access
to a company Ummm......
This contractor, the Indian company guy, even put in his DOB, his
dad's full name, and very private information about himself. Not too
good .... Now a h@ckEr can use the DOB to do something on F@CeB0oK to
start some identify thief activities.
Welcome to the technological age.
Just remember, when filling up an online form for a registration you
do not need to put in real data specially for websites. CC payment on
legit websites, you have to. Do not posting your actual Word
documents of personal info for submission.