Twitter Hit By BZPharma LOL Phishing Attack
An anonymous reader writes "Twitter users are being warned not to click on messages saying "'ol, this is funny,' as they can lead to their account details being stolen. A widespread attack has hit Twitter this weekend, tricking users into logging into a fake Twitter page — and thus handing their account details over to hackers. Messages include Lol. this is me?? / lol , this is funny. / ha ha, u look funny on here / Lol. this you?? followed by a link in the form of http://example/ [dot] com/?rid=http://twitter.verify.bzpharma [dot] net/login, where 'example.com' can vary. Clicking on the link redirects users to the second-half of the link, where the fake login page is hosted. In a video and blog entry, computer security firm Sophos is warning users that it is not just Twitter direct messages (DMs) that carry the poisoned links, but they are appearing on public profiles due to services such as GroupTweet which republish direct messages. Sophos also reports that the site being used for the Twitter phishing has also been constructed to steal information from users of the Bebo social network. Affected users are advised to change their passwords immediately."
twits.
I could never have figured out their clever stratagem without you.
this is funny.
Seriously, anyone with more than a few functional neurons is not going to type their password into a page they reached by clicking on a link from "LOL this is funny!".
We need to let people like that sink or swim. People end up being as stupid as we let them be. If we expect complete idiocy, we will *get* complete idiocy, and that harms the experience for the rest of us.
I say let these people experience the consequences of their own actions.
...I just deliberately sought out this thing so I could see what it looked like - and amazingly, whatever it does, it manages to somehow hide the "Suspected phishing site" page in Google Chrome: It briefly appears but then the page seems to reload automatically and the page disappears
So not only is this a pretty sophisticated clone of Twitter's login, they've somehow managed to force their way past the attack warning too. Any ideas how they've done that?
wolves come out in force.
by TheSpoom (715771) Uncaring Linux user here. I have nothing to add to this but please continue. *munches popcorn*
Twitter phishing warnings on Slashdot? That's a new low.
I swear that my MSN messenger has messages "from my friends" saying "haha this you? -link to dodgy site-". Of course I've never clicked on one. In fact I talked about security to a "hey wanna see my webcam?" bot once.
This malicious domain doesn't bother me (I use DNS Redirector to block it and thousands others)
The best solution is to just not use any of this "social networking" crap and go make friends in the real world ...and no, I'm not 60 and don't understand it, I'm 24 and smart enough to know its hype and stupidity
A strange game. The only winning move is not to play. How about a nice game of chess?
"He's lost in a 'floyd hole"
Huh, where's the link? I need to log in.
Eh?
If Google really cared they would fix Android Chrome to reflow text, instead of discriminating
I've added that specific page and domain to the Phishtank, causing the page to appear in the first place. ( http://www.phishtank.com/user.php?username=alexanderpas ) Probaly they used some kind of exploit to bypass the attack warning. The best way, is not to only rely on your browser for protection, but take a multilayered approach, for Example, Using OpenDNS ensuring the request doesn't even hit the DNS system.
I piss off bigots.
I've always wondered why we don't see more phishing attacks with URL shortening services. Why not just tweet "Hey check out the pictures of my latest vacation at my picasaweb page"? I don't think forcing users to install yet another plugin which checks out the tinyurl link as there's more than enough companies that do shorten URLs to make this plugin be yet another one which has to have to phone home to get updates...
I guess I have a hard time understanding why these things are so hard to block (globally). Doesn't Twitter maintain some sort of global regex cookbook of spam-laden crap?
i lol'd
With Due Respect and Humanity, I was compelled to write to you under a humanitarian ground.. My name is Mrs. Jessica Meyer. I was born in Baltimore , Maryland ,I am married to Mr. Timothy Meyer director J.C Industries Cote d'Ivoire.We were married for 36 years without a child. He died after a Cadiac Arteries Operation.
And Recently, My Doctor told me that I would not last for the next six months due to my cancer problem (cancer of the lever and stroke). Before my husband died last year there is this sum $2.8 Million Dollars that he deposited in a bank here In Ivory Coast.Presently this money is still in the bank. Having known my condition I decided to donate this fund to any good God fearing brother or sister that will utilize this fund the way I am going to instruct herein. I want somebody that will use this fund according to the desire of my late.
Husband to help less privileged people, orphanages, widows and propagating the word of God. I took this decision because I don't have any child that will inherit this fund, And I don't want in away where this money will be used in an ungodly way. This is why I am taking this decision to hand you over this Fund. I am not afraid of death hence I know where I am going. I want you to always remember me in your daily prayers because of my up coming Cancer Surgery.
Write back as soon as possible any delay in your reply will give me room in sourcing another person for this same purpose, hoping to read from you ASAP.
God bless you as you listing to the voice of reasoning,
The contribution of the Internet is indisputable. Even when it was the ARPANET its value was trivially obvious.
Twitter, on the other hand, is just trivial. And if it is now a source of germs as well, forget it.
I piss off bigots.
Only idiots are going to click links containing "pharma" in the title and then enter their password on the resulting page when they know they're already logged in.
I guess that means plenty of victims on Twitter.
I am not devoid of humor.
Twitter and Facebook are the AOL of the 21st century.