Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Spam, Scam and Phishbusters » huge myspace phishing scam
Uniqs:
2178
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
[Phishing] monster phish »
« [Phishing] E-bay phish disguised as survey  

brandon1234

@comcast.net


1 edit

from:
xmrocks See Profile

huge myspace phishing scam

at the moment there's a large phishing scam circulating around myspace

there are a lot of fake profiles setup like »www.myspace.com/118474060 that have really authentic looking login screens

the login info is sent to an external site

judging by wget | wc it looks as though nearly 700,000 people have been duped by this so far

removed
Crisis Management Squad
Premium,VIP
join:2002-02-08
Houston, TX
clubs:

Re: huge myspace phishing scam

Wow, that's an impressive list. But 700,000 isn't all that surprising considering the fact that most MySpace users are, well, idiots.

What kind of stuff are these accounts being hijacked for? There's no financial information on MySpace - nothing worth stealing, IMO.
--
irc.removed.us - #dslr | DSLR Phishtracker | Morning Glory Comics | Email: removed@dslr.net | Phone: 718-606-4100

xmrocks
Premium,MVM
join:2003-09-23
clubs:
·Comcast


1 edit

Re: huge myspace phishing scam

said by removed See Profile :

What kind of stuff are these accounts being hijacked for? There's no financial information on MySpace - nothing worth stealing, IMO.
Maybe they are stealing the "oh-so cool backgrounds" the idiots of MySpace are using these days MySpace is such an eyesore!

I guess if the MySpace user uses the same login, as brandon1234 mentioned as eBay/Paypal/their e-mail service, the e-mail address could be stolen and used to send out more phishing and/or scam e-mails that have more value to them (i.e. for banking, etc).

Or maybe it's just the pride oh saying "Yeah, I stole X amount of MySpace passwords!"

Edit: Just to prove my point (not that it needs to be or whatever), I picked a random user in that list, went to their e-mail server site, entered in their e-mail address and password and I'm now into their e-mail.

--
I don't tolerate phishing - >>phishtracker

removed
Crisis Management Squad
Premium,VIP
join:2002-02-08
Houston, TX
clubs:

Re: huge myspace phishing scam

Hmm, that's a very interesting point. Out of 700,000 harvested accounts at least 5% of them are bound to have an active PayPal account. 5% of 700,000 = lots and lots of disputed PayPal charges.

brandon1234

@comcast.net

from:
xmrocks See Profile

was wondering the same thing myself. i guess they could be hoping that some people have the same info for ebay/paypal/etc, but then again everyone on myspace is like 13 and has nothing worth taking

28482647
Premium
join:2003-05-13
England

Oh dear :| Anyone reported it or anythin?

justin
Australian
join:1999-05-28
Brooklyn, NY

Host:
IPv6
Business Connectiv..
Home/Office setup ..
Console/Handheld g..
Console Tech

Re: huge myspace phishing scam

said by 28482647 See Profile :

Oh dear :| Anyone reported it or anythin?
Yes the news has been passed to on to them.
Hopefully they will quickly write a script to take down all the fake pages and block new ones.
This isn't going to help the 700k+ people in the list whose email/password combinations are now pocketed, however.
Will MySpace grab the same archive file the phisher has already got, and inform everyone by email to change their passwords on other sites, if they share the same password?

28482647
Premium
join:2003-05-13
England

Re: huge myspace phishing scam


MySpace is a heap, I doubt they even care tbh.

It's wild how users can edit their pages so much so that it can be faked like that. :\

brandon1234

@comcast.net
amazing that those pages are STILL up now....

xmrocks
Premium,MVM
join:2003-09-23
clubs:
·Comcast

Re: huge myspace phishing scam

MySpace was never known for security. I am willing to bet that they'll still be up tommorow, too, unfortunately.

It honestly doesn't surprise me one bit. There's really no excuse for them to still have the page up, though. They were warned about it.
--
I don't tolerate phishing - >>phishtracker

icex _
Premium
join:2004-05-22
USA
clubs:

1 edit
fyi for anyone that wants to know the fake login link website is »:xxxxx
--
Team Discovery


mod edit: There isn't a good reason to post the link

exocet_cm
I am the law
Premium
join:2003-03-23
New Orleans, LA
clubs:
·Cox HSI
·Suddenlink
·Cingular Wireless
·AT&T Southeast
·Charter Pipeline


2 edits

Re: huge myspace phishing scam

said by icex _ See Profile :

fyi for anyone that wants to know the fake login link website is »:xxxxxxxxxxxxxxx
I just dug around and was about to post the same thing.
Edit: It looks like that site might also be involved in a watch scam. Google it.
--
"I have measured out my life with coffee spoons..." - T.S Eliot
I'll take "things only I know" for a thousand Alex.

M A R K
Premium
join:2001-06-15
Long Island
clubs:
How do we now what to even look for?
--
'Posthumously Young'
garys_2k

join:2004-05-07
Farmington, MI
·Future Nine Corpor..
·Vonage

Re: huge myspace phishing scam

said by M A R K See Profile :

How do we now what to even look for?
If it's a myspace login the url should be "login.myspace.com" and nothing else.
Forums » Up and Running » Security » Spam, Scam and Phishbusters[Phishing] monster phish »
« [Phishing] E-bay phish disguised as survey  


Tuesday, 08-Dec 23:48:30 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [193] Sprint Sued For Distracted Driving Death
· [81] 3G Network Test Says AT&T Is Tops
· [72] Mediacom Unveils 105 Mbps Pricing
· [62] Sprint Poised For A Turnaround?
· [50] The Future Of Wi-Fi Is Bright
· [49] WPA Cracker: Test WPA-PSK Networks In 20 Minutes
· [47] Site Leaks Yahoo, Verizon Fed Data Share Pricing
· [44] Microwaving Your Innards Is Not 'Extreme'
· [39] Verizon LTE: 5-12 Mbps Downstream
· [20] AT&T Releases Network Reporting iPhone App
Most people now reading
· Comcast refused to install 400' feet. [Comcast HSI]
· Man Downloads Child Porn "Accidentally," Faces 20 Years [Security]
· [How to] Install Asterisk on an Asus WL-520GU router [VOIP Tech Chat]
· Maximizing Rogue DPS for 3.1 [World of Warcraft]
· Windows 7 boot manager editing questions [Microsoft Help]
· Servers UP!!! [World of Warcraft]
· World of Warcraft Client Patch 3.3 (12-8-2009) [World of Warcraft]
· IMG 1.7 (IMG Updates and Discussion) [Verizon FIOS TV]
· [WIN7] Outlook express under Windows 7? [Microsoft Help]
· Adobe Flash Player version 10.0.42.34 [Security]