Twitter Hit By BZPharma LOL Phishing Attack
An anonymous reader writes "Twitter users are being warned not to click on messages saying "'ol, this is funny,' as they can lead to their account details being stolen. A widespread attack has hit Twitter this weekend, tricking users into logging into a fake Twitter page — and thus handing their account details over to hackers. Messages include Lol. this is me?? / lol , this is funny. / ha ha, u look funny on here / Lol. this you?? followed by a link in the form of http://example/ [dot] com/?rid=http://twitter.verify.bzpharma [dot] net/login, where 'example.com' can vary. Clicking on the link redirects users to the second-half of the link, where the fake login page is hosted. In a video and blog entry, computer security firm Sophos is warning users that it is not just Twitter direct messages (DMs) that carry the poisoned links, but they are appearing on public profiles due to services such as GroupTweet which republish direct messages. Sophos also reports that the site being used for the Twitter phishing has also been constructed to steal information from users of the Bebo social network. Affected users are advised to change their passwords immediately."
twits.
this is funny.
Seriously, anyone with more than a few functional neurons is not going to type their password into a page they reached by clicking on a link from "LOL this is funny!".
We need to let people like that sink or swim. People end up being as stupid as we let them be. If we expect complete idiocy, we will *get* complete idiocy, and that harms the experience for the rest of us.
I say let these people experience the consequences of their own actions.
...I just deliberately sought out this thing so I could see what it looked like - and amazingly, whatever it does, it manages to somehow hide the "Suspected phishing site" page in Google Chrome: It briefly appears but then the page seems to reload automatically and the page disappears
So not only is this a pretty sophisticated clone of Twitter's login, they've somehow managed to force their way past the attack warning too. Any ideas how they've done that?
wolves
Shouldn't that be "wovles?" It would make more sense for "wovles" to prey on "sheeple."
When you're afraid to download music illegally in your own home, then the terrorists have won!
"Sheeples wovle but they don't fall down"
I asked her what color her panties were and she said "j00z did 9/11!"
Weirdest sex chat I've ever had that didn't involve a robe and wizard hat.
I piss off bigots.
I've always wondered why we don't see more phishing attacks with URL shortening services. Why not just tweet "Hey check out the pictures of my latest vacation at my picasaweb page"? I don't think forcing users to install yet another plugin which checks out the tinyurl link as there's more than enough companies that do shorten URLs to make this plugin be yet another one which has to have to phone home to get updates...