Warning: Twitter phishing attack spreads
Posted on | February 20, 2010 | No Comments
A linkĀ to a phished page of Twitter is being sent as a direct message to followers. Most probably the tweeter, who is automatically direct messaging his followers, might have typed in his username and password in the phished page himself. Using that details the attacker can send DM’s to all the followers with the hope of getting more victims.
If you look at the url, it is linked to bzpharma.
http://commonwealthcommunications.com/?rid=http://twitter.verify.bzpharma.net/login
http://cbsi.net/?rid=http://twitter.secure.bzpharma.net/login
These are actual links that I have received. Firefox 3.6 and Chrome 4.0 will warn you about this site as Reported Web Forgery. If you visit the site you will be taken to a login page and when you enter your details you will be taken to this page http://bzpharma.net/login/err.html which has a pic of Fail Whale with the message Twitter is overcapacity. After that you will be redirected to the actual twitter homepage.
Please take care about the links you click on and where you put in your login details. Use latest browsers like FireFox 3.6 and Chrome 4.0.
Comments
Leave a Reply

