Monday, June 19, 2006

Yahoo password phishing

This morning I came into work and there was this IM from an old colleague:
:) http://www.geocities.com/joke_of_the_day_3_3/ =))
Now the URL looks like its gonna give me a nice laugh and I click on it. Surprisingly I land up at a Yahoo! login page. I thought hmm, I need to login to read a joke? Oh well - the URL came from a friend it must be worth a read, here goes the login...
Wait a second, this is not the Yahoo site, its geocities! Then I realise its a really clever attempt at password phishing. My colleague was foxed into providing his login and password to a bogus website, and the attacker is using his buddy list to send the URL to even more people. Now that is clever. Next I submit a bogus username and password to the form, and I am given a message that says 'Page not found'.
So watch out guys, do not submit your passwords to random sites. If you have, change the password right away.

No comments: