The top 10 emerging influential blogs of 2008
Powered by MaxBlogPress  

Now and then an innocent man is sent to the legislature.
-Kin Hubbard

neri-v-senate
Your ad here

« After Sober Comes Mytob
» On Finding Forrester in Maksim’s New World

Tech Security

Phishing Attempt Targets Yahoo! Photos

11.30.05 | Comment?


If you're new here, you may want to subscribe to my RSS feed. Thanks for visiting!

Reminiscent of a previous Yahoo! phishing site (as blogged here), another phishing attempt has been discovered, this time spoofing the Yahoo! Photos login page.

Image hosted by Photobucket.com
(Click on the image to enlarge)

This time around, the URL is spammed through a Yahoo! Messenger instant message:

http://www.geocities.com/oxox0o_angel_oxox0o/ ^:)^ guess where
this pic was taken and guess who is behind me in the picture

When the link is clicked, you are redirected to the said site.

By looking at the HTML source, it seems that the login details are sent to a CGI server, for what purpose only Heaven knows.

Image hosted by Photobucket.com
(Click on the image to enlarge)

If you notice, the value of the ACTION attribute is encoded in HTML hexadecimal notation. It is a long one; suffice to say it is a link to a CGI server. (Alright, it’s http://www2.fiberbit.net/form/mailto.cgi.)

Again, we can only be too careful. When logging in to any site, make sure that the URL in the address bar is the correct one. And if possible, login using a secure process; Yahoo! offers a secure login, so use it. And when you receive an instant message like the one stated above - even if from a trusted friend - ignore it completely.

Like my article? Leave a tip! Or, treat me to a cup of coffee!

Visit the AWBHoldings.com Online Store!


If your comment is eaten by Akismet or just went somewhere else, please let me know. You can either leave a message at the chat box at the lower left, or via the contact page. Thanks!

RSS feed | Trackback URI

Comments »

No comments yet.

Name (required)
E-mail (required - never shown publicly)
URI
Subscribe to comments via email
Your Comment (smaller size | larger size)
You may use <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong> in your comment.

Comments will be sent to the moderation queue.


« After Sober Comes Mytob
» On Finding Forrester in Maksim’s New World