Two Scams to be aware of…..

I have come across two scams this week targeting small regional charities, one about domain registration, I came across several years ago, but it looks like it is still going on. The first is encouraging you to call a premium rate number.

Scam #1  Contact me message

You all have forms on your websites, and you usually get legitimate enquiries on these forms. Do however check the contents in a message and if the only way you can contact someone is via a premium rate number then don’t bother calling. If the content is virtually non existent like this one below, it is encouraging you to call a premium rate number. In this particular case I checked the number through a web search. This individual is sending messages to websites through contact forms.  So if 10 people call back then that is £1+ they have made depending on how long they keep you on the phone, you would not know what their premium rate is prior to calling.

If you are not sure, type in the following into a Google Search form:  who called me 08712771062  (Obviously substitute the number you wish to check. In this particular case it took me to this page: http://who-called.co.uk/Number/08712771062 if you read the reported cases there, you can see the depth of the scam and other people’s comments.

Normally anyone contacting your organisation will provide more information in the form for you to process and not leave a short message like this.

Scam #2  About your domain name

In many cases I am looking after your domain names, so if you get anything like this send it to me, it is a bit more subtle than the previous one. In general domain names are registered to organisations and that registered information can be located on the internet. So a determined third party can find it and then contact you. This is how the domain scam works: Continue reading Two Scams to be aware of…..

Group Calendar

I have been asked on a number of occasions is it possible to have a group or office shared calendar. The problem is generally those people who are used to using Outlook in a business context have used an Exchange Server which managed all of the calendaring functions for you. In a charity situation, particularly a small regional one, it is not very likely that your charity uses a Microsoft Exchange server. The calendar management needs to be handled at a central point such as a server.

I received a request about a group calendar a few days ago and did some digging and have come up with a solution. So if you are interested in having an office calendaring system that is online, that your volunteers and office staff can log into then this may be for you. Continue reading Group Calendar

Good Catch ESET

Here it is a bit closer:

I have recommended to quite a few of my clients the benefit of using both an antivirus program and a personal firewall. The products I have used for around 20yrs now are from ESET.  I currently use Smart Security.

It simply runs in the background and checks things for you. I frequently use mxtoolbox.com to check out information relating to websites. I went to one just now and in my haste typed in mextoolbox.com (there is an e in there that should not be in there). A sharp hacker has taken out that domain name and used it to hide a virus. It was detected as I opened the webpage.

If you just use a free AV product, this would not have been detected. Many of the charities I work with have no AV, or free AV products. I consider myself to be very careful on the web. But even I can make a mistake.

I recommend Eset Smart Security to protect your Windows computer. You can find out about here:  https://www.eset.com/uk/home/smart-security/

As a charity you can get it heavily discounted, and if you buy more than one or multiple licenses then it is even lower cost.

Wannacry Ransomware

On Friday the 12th of May a large cyber attack occurred infecting computers all around the world. In the UK, many NHS systems were affected bringing IT systems to a halt. Researchers indicate it is not clear why this particular event occurred so quickly, it is unlikely to simply be people clicking on links in emails, which is one way these viruses end up on computers. One researcher accidentally found a “Kill Switch” for this virus on Friday afternoon which stopped computers encrypting disks around the world. So while this last major event stopped pretty soon after it started, other variants have already appeared, but have not propagated as quickly as the one on Friday.

I have visited a few of my clients over the years, because of the nature of the business and the low IT budget, computers are often old and frequently not up to date. Another feature is some do not have any anti-virus software running on them either. These circumstances can leave you open to an attack of this type and many other less crippling viruses.  Continue reading Wannacry Ransomware

Hosting Move News (May 2017)

While preparing the newsletter for May, I thought I would place a quick summary here for those that are interested.

At the beginning of May 2017, I am around 75% of the way through moving everyone from their former hosting to the new hosting.  For most people the move required little more than a change to where they were picking up email from. For those using 3rd party email services, or not using mail associated with their domain name, they did not need to do anything.

Some Goodies for you

For many people that find the idea of editing a website to be a daunting prospect they are not generally interested in looking any deeper into the systems that are available through the hosting.  Things such as email set up, out of office messaging, forwarders etc. For this reason I have set up Control Panel users for the new system on the basis of whether they were accessing their control panels before the move or not. If you were not using it, I have not bothered to ask. If you are a “power user” then I have set you up on the new system.  Anyone wishing to have access to their hosting control panels can contact me and request to be added. I will need from you your contact details including address and telephone number. These are used in the form to set up the control panel user. Continue reading Hosting Move News (May 2017)

Obfuscated links – take care

One of the websites I look after was taking content provided by third parties and adding it into the website. I was working my way through some posts when I came across a strange looking link hidden under an innocent looking title.

The editor in this case had just cut and paste everything, and had not tested it. There were two cases, one went to a newsletter mailing website and then was diverted to the actual site. In this case the actual site was simply a holding page, and the fact that the link went to that site via a third party meant it was logged. Of course we do not know what else happened on the way.  The link text contained Yurts for Life, but the link was actually going to here:

http://manorfarm.us10.list-manage1.com/track/click=eea270f45b87b007e97fa644b&id=ebeb93cbe5&e=c391a34f71  

Which is not going to Yurts for Life. The behaviour of the link when clicked went somewhere, then to somewhere else.

The link was provided in good faith, however if nobody checks these things it can be simply passed down the chain. In this case it is probably completely innocent, however what if it wasn’t?  Would you know; the fact you have put this on your site, exposes it to all of your visitors.

Test it when you publish it

Continue reading Obfuscated links – take care

SSL to secure your website

Those sites I have moved to new hosting have a free SSL Security Certificate generated. When it is turned on and some changes are made to the website most of the accesses are now done over an HTTPS:// connection. (Like your bank.)

It has not been necessary or cost effective in the past, but as these certificates are free, we should be able to use them.

Another factor is Firefox has changed recently and puts this message up over a login box on any site that does not have an SSL or https:// connection:

There was no real requirement to make it secure. Those small number of sites I am aware that were compromised by hackers, the entry was gained because one of the administrators email accounts was hacked first.  However it remains a possibility that someone could grab your username and password.

I will make all sites run under SSL after they have moved over and have been checked. This means all sites will support encrypted connections to maintain security. You can find out more about security and SSL in this article.

Dating Sites; an example of what can go wrong

This is way outside of what I normally comment on in my site, but I thought it was worth pointing out to you all to show it can happen to anyone. Fortunately nobody was caught out in this scam, but it serves as an example of why trust needs to be developed when doing things online.

Firstly, the person seeking the services of the “Dating site” was not me, but a lady I know who asked my advice when she became suspicious. Continue reading Dating Sites; an example of what can go wrong

Working with your local IT consultant?

Do take care!

I had a situation several months back where an organisation bought in their local IT consultants and moved their mail system to Exchange/ Outlook 365, basically web based mail using Outlook. This in itself is not unusual, it has happened several times before and Outlook running in the cloud offers several benefits in terms of assisting people to work together, things like improved communications, shared calendar etc.

To get another mail server on line you need to change some of the settings in the hosting. I normally handle that, but in this case I passed the control panel user name and password to the consultant under the direction of the client.

Everything appeared to go smoothly, their mail came on line and we forgot about it and moved on. But……

Some months later the client tested and found out that mail was no longer being sent from the website to the email system. This had worked when it was set up but was not working now. I was called in at this point.  Continue reading Working with your local IT consultant?

Wingrove-Services
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

You can adjust all of your cookie settings by navigating the tabs on the left hand side.

My privacy policy can be located here: Wingrove Media Privacy Policy (opens in a new window)

My Cookies Policy can be found here: Wingrove Media Cookies Policy (opens in a new window)