Raymond.CC Blog










Go Back   Raymond.CC Forum > Computer Related Forum > Spyware/Viruses


Reply
 
Thread Tools Display Modes
  #1 (permalink)  
Old 10-07-2009
No Avatar
ripper ripper is offline
Tech Wiz
 
Join Date: Jun 2009
Posts: 541
Email phishing attack spreads to Gmail and Yahoo

Read More

Last edited by ripper; 10-30-2009 at 03:18 AM..
Reply With Quote
Alt Today
Advertising
Google Adsense
 
Standard Sponsored Links
  #2 (permalink)  
Old 10-07-2009
ceyfer's Avatar
ceyfer ceyfer is offline
Star
 
Join Date: May 2007
Location: 13°15'N - 123°41'E
Posts: 2,380
read and practice the steps below !

Quote:
Q: What should people do if they think they have received a phishing e-mail?
Quote:
A: If you think you may have received a phishing e-mail, you should take three steps: (1) take some time to check up on it and do not click on a link or give out your personal information, (2) make sure you have created a strong password for your account and (3) report the phishing scam.
  • The most important thing to remember is do not click on the link or give out your personal information. It is possible for your computer to become infected with malicious software simply by visiting a phishing site – without you even realizing it. If you receive a questionable e-mail, take some time and check up on the information. Often sites like snopes.com list common e-mail scams. Go to that website of the company you received the e-mail from and contact their customer service reps via phone or online to verify the validity of the e-mail.
  • Another thing you should do is create a strong password for your e-mail account by using more than 7 characters and having a combination of upper and lower case characters, numbers, and special characters, like the @ or # symbols. It's also a good idea to change your password on a regular basis. The next time you change your Hotmail password, you can check “make my password expire every 72 days” to remind you to change it.
  • Finally, help us identify new scams. If you use Hotmail and received a phishing e-mail, you can select the dropdown next to "Junk,” and select "Report phishing scam.” Whatever you do, do not reply back to the sender. You should also report phishing scams to the Anti-Phishing Working Group by e-mailing them at reportphishing@antiphishing.org.
__________________
Всегда верный
Reply With Quote
  #3 (permalink)  
Old 10-07-2009
noaccount's Avatar
noaccount noaccount is offline
Tech God
 
Join Date: Sep 2009
Posts: 905
Quote:
Gmail is dealing with its share of the stolen accounts by forcing password resets, and a spokesperson at Google said there was no breach in Gmail security. This comes right on the heels of a possibly-related Hotmail-only phishing attack that hit 10,000 accounts earlier this week. To be safe, make sure you use a different password for each service you sign up for (the BBC says 40% of Internet users have the same password for everything), and if you click on a link in your email, make sure you're on a legitimate website before you sign in.
Source

No strange IPs or mails here... but if your life is in google one word of advice: change your password (better safe than sorry).

Last edited by noaccount; 10-07-2009 at 08:01 AM..
Reply With Quote
  #4 (permalink)  
Old 10-07-2009
kavinraja's Avatar
kavinraja kavinraja is offline
Star
 
Join Date: Jun 2009
Location: India
Posts: 1,464
Send a message via Yahoo to kavinraja
I receive lot of phishing mails in my yahoo, but havent got any such in gmail...

Most of them tend to attract us by promising us a huge amount to be obtained through a reward...
__________________
Reply With Quote
  #5 (permalink)  
Old 10-07-2009
luffy's Avatar
luffy luffy is offline
Tech God
 
Join Date: Jun 2009
Posts: 872
Quote:
Q: What should people do if they think they have received a phishing e-mail?
A: An email that have $$ in it. And it asks for your name, address and shipping fee to send the money. Don't open it just click on the SPAM. Create a new account also.
__________________
Only Death Can Cure Stupidity.

Last edited by luffy; 10-07-2009 at 10:06 AM..
Reply With Quote
  #6 (permalink)  
Old 10-07-2009
hellnoire's Avatar
hellnoire hellnoire is offline
Linux Guru
 
Join Date: Jan 2009
Posts: 5,224
What I like is that my school also got phished too... we had a lot of idiots, even in IT that fell for it, hook, line, and sinker!
Reply With Quote
  #7 (permalink)  
Old 10-07-2009
noaccount's Avatar
noaccount noaccount is offline
Tech God
 
Join Date: Sep 2009
Posts: 905
this is confusing but seems to me this is more than a phishing scam with bbc reporting
Quote:
seen two lists that detail more than 30,000 names and passwords from e-mail providers
so the risk of having your e-mail account compromised is real and although i didnt track any suspicious ip activity in my accounts i decided to change password as it takes only 5 sec... anyway this issue seems almost forgoten...
Reply With Quote
  #8 (permalink)  
Old 10-08-2009
noaccount's Avatar
noaccount noaccount is offline
Tech God
 
Join Date: Sep 2009
Posts: 905
Quote:
"The FBI and Egyptian authorities have arrested 100 people in what they're calling 'the largest international phishing case ever conducted' as part of a wide-scale investigation called Operation Phish Phry. The criminals used phishing to get access to hundreds of bank accounts, stealing $1.5 million. 'This international phishing ring had a significant impact on two banks and caused huge headaches for hundreds, perhaps thousands of bank customers,' said Acting US Attorney George S. Cardona."
FBI Cracks "Largest Phishing Case Ever"

Quote:
Come on, people. You’re probably aware of the big Hotmail scandal going on right now, what with some 30,000 account names and passwords having been leaked over the past few days. And now Gmail and Yahoo! e-mail accounts appear to have been compromised. The thing is, these leaks aren’t the result of a software glitch or anything, but the result of successful phishing attacks. I have one question: what the heck is wrong with you people?
Dear friends: Please stop falling for phishing attacks

Quote:
If you suspect that an unauthorized person has used your Windows Live ID to sign into your Windows Live Hotmail acccount, or any other Windows Live service, please read this article for further help.
What to do if you think your Hotmail account has been stolen

Last edited by noaccount; 10-08-2009 at 11:41 PM..
Reply With Quote
  #9 (permalink)  
Old 10-09-2009
ceyfer's Avatar
ceyfer ceyfer is offline
Star
 
Join Date: May 2007
Location: 13°15'N - 123°41'E
Posts: 2,380
Well I found an interesting article from Acutenix

Quote:
An anonymous user posted usernames and passwords of over 10,000 Windows Live Hotmail accounts to a web site called PasteBin. PasteBin is currently down for maintenance but I managed to get a copy of the list, and quickly generated some statistics from these passwords.
Quote:
Top 20 most common passwords:
  • 123456 - 64
  • 123456789 - 18
  • alejandra - 11
  • 111111 - 10
  • alberto - 9
  • tequiero - 9
  • alejandro - 9
  • 12345678 - 9
  • 1234567 - 8
  • estrella - 7
  • iloveyou - 7
  • daniel - 7
  • 000000 - 7
  • roberto - 7
  • 654321 - 6
  • bonita - 6
  • sebastian - 6
  • beatriz - 6
  • mariposa - 5
  • america - 5
Acutenix
Statistics from 10,000 leaked Hotmail passwords

Zeroday
Weak passwords dominate statistics for Hotmail's phishing scheme leak

fault: It was plain human error ( weak password ) and stupidity ( phising link )
Reply With Quote
  #10 (permalink)  
Old 10-09-2009
noaccount's Avatar
noaccount noaccount is offline
Tech God
 
Join Date: Sep 2009
Posts: 905

Anatomy of a Hotmail phishing attack (Neowin publishes one of the phishing emails used)

Last edited by noaccount; 10-09-2009 at 05:51 AM..
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Paypal SCAM (phishing-attack) In Action swarup1987 Chat 1 09-24-2009 04:55 AM
Rapidshare Phishing: Protect Yourself Dawnz Tutorials 3 05-13-2009 02:26 AM
Phishing Attack Uses Yahoo HotJobs XSS Vulnerability shan Spyware/Viruses 1 10-29-2008 12:54 AM
Phishing Warning! In-f3st General Forum 2 10-15-2008 12:23 PM
Problem loading www.gmail.com, mail.yahoo.com, www.orkut.com k9 General Forum 4 02-25-2008 09:13 AM


All times are GMT +8. The time now is 03:13 AM.