Donation Goal
Donate Now Goal amount for this year: 799 USD, Received: 100 USD (13%)
Please donate to help support this website. The funds will be used to purchase owned license of LiteSpeed Web Server Enterprise (2-CPU). It provides superior performance in terms of raw speed, scalability and anti-DDoS capabilities.

Beware of VERIFY WHO BLOCKED YOU ON THEIR MSN CONTACT LIST Websites

Posted By Raymond In Category: Computer

Dec
22
2009

Last year there was a lot of automated MSN messages that leads you to PICS FOR MSN FRIENDS phishing website. It has now died down but here’s a new wave of MSN phishing sites. Two days ago I received an email from an old friend which we have not kept touch for a few years. The subject of the email is “hi o_O?” which doesn’t look like I should suspect anything because I know that my friend likes to use these kind of winking emotions. After opening the email, here is what it says:

hiyaaa!
Howdyy? had a damn boring day today :s
whats up at your place?
Anyway, i can bet you’re going to smile after reading this… :P
It’s Easy, Secure and Free!
Try it Now, Click Here
Thanks

Upon clicking on the link, you will see a page with the title “You’re Blocked :: MSN Messenger Block Checker – MSN Messenger Stats Checker” that allows you to verify who blocked you on their msn contact list. Bu before you can use the free service, you’ll first need to enter your MSN login and password.
VERIFY WHO BLOCKED YOU ON THEIR MSN CONTACT LIST

I know most of you probably won’t fall for this but some of you will. Most of the time people disclose their sensitive information to a phising site is because the link came from a trusted friend who also got phished in the first place. Secondly the website has a nice looking login screen where some people will automatically enter their username and password. It’s a common mistake when people are not careful enough.


I checked the HTML source code of the phishing site and found that no matter what login and password I enter, it will tell me “Wrong E-mail or Password”. Secondly, it has a javascript which does all capturing after you submit the form. For a person that is familiar with computers, he/she should know that there is no way to check who blocked you on MSN.

I am very sure that this email is not sent by my friend but rather it’s from a phisher which has already captured her MSN login and password. If you received such email, please inform your friend that her MSN login and password has been compromised. All they need to do is to change their password so that the phisher can no longer use that account to send spam emails.

To change or reset the password for your MSN account, follow these steps:
1. Go to http://login.live.com web page and then click Forgot Your Password.
2. Type in your MSN e-mail address, type the characters that appear in the Picture box, and then click Continue.
3. Click Send yourself a password reset e-mail message.
4. Click Send Message.
5. On the confirmation page, click Done.
6. Sign in to your e-mail account, and then click the link in the e-mail message to reset your password.
7. On the Confirm your e-mail address page, type your e-mail address, and then click Continue.
8. Type your new password two times, and then click Continue.
9. If you want to enter an “alternate” e-mail address, type the address two times, and then click Continue. If you do not want to enter an “alternate” e-mail address, click Skip.
10. When you receive the “You’ve changed your password” message, click Done.

I don’t think that the phisher would change your MSN password once they get your account information. It seems that the owner of the phishing site comes from China and recently I’ve gotten a lot of spam from them trying to get me to buy electronics, medicines, shoes and etc from them. So my guess is they are trying to harvest as many login as possible and then use it for spamming purposes.

Some examples of the links are the below but please DON’T enter your MSN email and password! I’m sure there are a whole lot more, so be very careful not to simple enter your MSN login details. If you got any, please leave a comment so I can add it to the list.

  • http://wbc2.great-friends-dont-block.com/?id=9r6&session=CMDUcT1EekeZlWYd-Qb8ropqFV2LzvKdrGNLkHCzbjU=
  • http://3crq.friends-circle-blocks-check.com/?id=TXg&session=9zJwltj–cQOKU6LpCLgXCig4YD0Gn0K-5S5wBjNWIA=
  • http://kspl.friends-circle-blocks-check.com/?id=8mM&session=W21H6vxwMB966Tn2XB0wzywRXlnEGl2Omz20D4zOpDU=

  • Related posts:
  • Beware of PICS FOR MSN FRIENDS Phishing Websites
  • Firefox Don’t Remember Yahoo Mail and Hotmail Password
  • BEWARE: Phishing for RapidShare Premium Accounts
  • How To Send Files when Instant Messenger File Transfer is Blocked
  • Temporary Email for avoiding SPAM
    • http://www.tmsnetwork.org whiztech

      Nice find. The Internet is getting more dangerous, especially to non-tech-savvy users.

    • robzki

      thanks for the info…

    • Shail Shah

      Nice For Computer Education!

    • Matriel

      that’s true, every month at least one of my contacts fall in some of these tricks.

      Another good thing to know about msn password, is the secret question, in Italy it only asks something you have to know, in other places such as Australia you have to know the city, the postal code, and the region. More security?

    • http://www.newpridegrafix.com/gfx Lateralus

      Lol, thanx for the info Raymond… I didn’t know people still actually used MSN, lol. Yahoo forever!

    • anil

      They don’t hack msn login details but also hack your bank details with fake bank login screen. use ful information but want to know how to stop them and how we will know that it is a fake web page.

    • kgaurav

      Thanks for informatin. Ray

    • Val

      Oh.. bloody heck! No wonder my friends have been getting strange emails from me! And I’m usually really cautious with my password! Thank you so much for the post Raymond. I changed all my electronic passwords, just in case. Once again, thanks!

    • Ahmad Saleem
    • Lee

      I have been getting them for near on 9 months.

      The passwords were posted at some site couple of

      months ago.

      I thought even lamers were wise to phishing scams.

    • dredge

      This post is extremely important for everyone who use MSN/windows live.

    • LunarWolf
    • Newbie Comp User

      Thanks Raymond!
      I knew these “who blocked me” sites were, I’ve been getting a lot of them before.

      Ps. If you have Malwarebytes Full Version , it will block these msn phishing sites.

    • http://www.visualexif.com/blog M S

      Great information…

    • nivek_hcerg

      Messenger Plus Live can tell you who blocked you or who removed you from their contacts list. Should I be concerned? 0.o

    • http://www.raymond.cc/ Raymond

      Are you user Messenger Plus Live can tell who blocked you or removed you from their contact list? Would appreciate if you can point it to me where.

      I just found this on Messenger Plus Live FAQ.

      “Some features are not included in Messenger Plus! for several reasons. Privacy is the first one: no feature will ever be added that could compromise the privacy or the security of your contacts (like block detection schemes).”

    • nivek_hcerg

      Selecting Contact List Cleanup from the “Plus!” menu. It says whether the contact has you or not. I swear a few versions before in that same window I could see whether that contact has even blocked you or not

    • http://www.nic.pro.mk Јован

      The internet – The devil’s work. :D

    • amit

      raymond i got this email and then i enter my password and email in this. but after one hour i changed my password

    • http://www.cravingtech.com Michael Aulia @CravingTech

      Whatever link a stranger put on my email, I’ll never click on it.. whether it’s from Bank of America, the Nigerian Government or even the Pope!

    • emtunc

      Using browsers such as Firefox which have built in ‘web forgery/phishing’ detectors, DNS servers such as OpenDNS which also have built in phishing and malware prevention along with a bit of common sense would prevent these problems from popping up in the first place.

    • http://www.raymond.cc/ Raymond

      Thanks nivek.

      Looks good but it looks like this feature is able to tell you who has removed you from their contact list, not who blocked you on their contact list.

    • http://jobberies.com/jobs/banking Kundur

      they stil can hack the password even we always using our MSN. What technology they use to break our password. Must be inside job. I guess

    • Murugesh

      Thanks for the valuable info Raymond! I request you to put the word ‘BEWARE’ in upper case too as when I first read the headline I missed the word beware and thought you were talking about some real MSN related service.

    • kit

      hey, i didn’t fall for this trick in the past. But I remember that there was a site to check if your friend is currently online.

      Can’t remember which site and if it works or not. So if your friend blocks you, you will not see him online on ur msn. But all u needed to do was enter his hotmail into the box and it will check whether they are online or not. If they are detected online in the website, but offline on ur msn. It will mean you are blocked.

      sounds safer and makes a bit of sense provided if it works.

    • http://www.whoblocked.me Joe

      I am the owner of http://www.whoblocked.me

      I can honestly say that my site DOES NOT phish for passwords. The script only uses a password to authenticate the user, nothing is stored anywhere on my server or anywhere else.

      If anyone would like to take a look at the source code of my script to prove it, I am more than willing to show them.

    • darkplayer

      I’m always on the defense when it comes to providing info to sites wanting user/password.

      Thanks for the, “Beware Of Phishing Links”.

    • Rmsheikh

      thanks for the info…:)

    • Rmsheikh

      same email was received by my friend and he said me that there were some disgusting pics in that mail…..and i dont know that how many more contacts of mine has received this same mail with disgusting and dirty pics….
      This will influence their mind about my bad character….:(
      btw thanks for this info….let’s see what happens now

    • Nasim

      Correct me if I’m wrong, but I think that in Pidgin when you hover your mouse over a contact it shows a thumbnail of their pic, their contact name, status and then “Has you : Yes/No” and “Blocked you : Yes/No”

    • Vlad Galbin

      My friend’s account sent me the same thing and I was foolish so I “logged in” and instead of saying “wrong password” it said that some of my friends blocked me.

    • Mn3mic (Joc)

      Don’t use MSN, stick to Miranda IM so it blocks all the MSN virus/phishing links anyway ;)

    • Skye

      i was so stupid i logged into 1. as my uncle sent it i thought it my work. only now do i realise that its all fake and none of it works.

    • http://Anasahmed Anas

      Halo buay fain all

    • http://geblokkerdemsn lisa

      Hoi hoi,

      mijn msn is geblokkerd, dus ik kan niet meer in. De geheime vraag/aantwoord weet ik niet meer wat het was als ik vraag om nieuwe wachtwoord te maken. Ik heb hulp gevraagd bij Microsoft Customer Support ze kunnen/willen niet me helpen, omdat ik de geheime antwoord niet meer weet, en de vragen die ze stellen volgens hun komen niet allemaal overheen. Dat kan wel waar zijn, omdat ik dit msnacount heb zelf niet geopent dat heeft mijn neef toen gedaan, en dat was in 2000/2001 zoiets, dus wel een tijdje terug. Ik heb daar nl wel belangrijke mailtjes, ik hioop dat iemaand is die wel een weet wat moet ik doen,

      alvast bedankt!!
      lisa

    • http://geblokkerdemsn lisa

      my msn is blocked, so I can not anymore. The Secret Question / Answers I can not remember what it was when I ask for new password. I’ve asked for help with Microsoft Customer Support they could / would not help me, because I do not remember the secret answer, and the questions they ask are not under their all over. That may be true, because I do not geopent that msnacount myself, my cousin was done, and something that was in 2000/2001, so a while back. I have important mails or com, I hioop that iemaand which hold one knows what to do,

      Thanks!
      lisa

    • Maha

      hi
      the link is not able to use
      please tell me how can I know who blocked me?

    • http://whoblocked.me I doubted that site

      OK I am an IT Security Proffesional and I was unsure whether http://whoblocked.me was a phishing site or not, I contacted admin and he let me inside the server and as he stated it does not store any personal info which is good news since I know people who have used it before.

    Copyright © 2005-2012 - Raymond.CC Blog