• On MovieTome: See the villain of IRON MAN 2!
October 28, 2009 3:02 PM PDT

Twitter users warned about new phishing attack

by Elinor Mills
  • Font size
  • Print
  • 10 comments

This is Twitter's spam warning.

(Credit: Twitter)

Twitter warned on Wednesday about a new phishing attack in which direct messages to users link to a fake log-in page that steals passwords.

"We've seen a few phishing attempts today; if you've received a strange (direct message), and it takes you to a Twitter log-in page, don't do it!" the Twitter spam warning says.

The direct messages say: "hi. this you on here? http://blogger.djh****.com," Sophos reports in a blog post. The full URL is obscured to prevent people from unwittingly visiting the phishing site.

Clicking on the link takes a user to a page that looks like a legitimate Twitter log-in page. When the user types in the username and password, a fake version of Twitter's "over capacity" message is displayed, with the image of the notorious "fail whale" held aloft by birds.

"When I visited the page, I was then slingshot to another Web page on Blogspot.com, claiming to belong to a blogger called NetMeg99," Sophos researcher Graham Cluley wrote. "It's not clear if NetMeg99 is involved in the phishing scam, but there is a suggestion that her Web page did also try to phish for credentials at one point."

If you have been duped by this phishing ruse, Sophos suggests that you immediately change your password at Twitter and any other sites where you used the same log-in credentials.

Elinor Mills covers Internet security and privacy. She joined CNET News in 2005 after working as a foreign correspondent for Reuters in Portugal and writing for The Industry Standard, the IDG News Service, and the Associated Press. E-mail Elinor.
Recent posts from InSecurity Complex
Cisco launches iPhone security app
Fortified rice, fuel cells among Tech Award winners
T-Mobile UK says workers sold customer data
FAQ: Recognizing phishing e-mails
Report: Countries prepping for cyberwar
Antitrust concerns linger in Google Books deal
Hackers create tools for disaster relief
Microsoft patching zero-day Windows 7 SMB hole
Add a Comment (Log in or register) (10 Comments)
  • prev
  • 1
  • next
by n3td3v October 28, 2009 3:59 PM PDT
One more reason *not* to use social media.
Reply to this comment
by SwissJay October 28, 2009 4:30 PM PDT
One more reason not to let dumb people use the Internet!! Honestly, people falling for that kind of stuff deserve their fate!
by n3td3v October 28, 2009 5:04 PM PDT
@SwissJay

Dumb people speak in 140 characters or less, they are bound to fall fate. The bad guys have got their yacht in the sun secured while we sit in our poxy 9/to/5 jobs.
by Vegaman_Dan October 28, 2009 8:29 PM PDT
"One more reason *not* to use social media."

98 characters. You qualiy for Twitter!

"Dumb people speak in 140 characters or less, they are bound to fall fate."

67 characters. Again, you qualify to post on Twit- oh, I see now. Um... oops. :)
by idaremyidea October 28, 2009 7:33 PM PDT
Are they dumb? or are they finding their way through life like the most of us? I think keeping in touch using communication allows those that can seek solutions can provide spammers a new kind of food for thought; without them how would other people be challenged in life? Everyone finds a way of doing something they think is right in life; everything else is just an observation - isn't it?
Reply to this comment
by corelogik October 28, 2009 7:37 PM PDT
Anyone that falls for a phishing scam should have to take an intelligence test to get back on the internet.
Reply to this comment
by BethJones-Sophos October 29, 2009 7:46 AM PDT
>One more reason *not* to use social media.
> Anyone that falls for a phishing scam should have to take an intelligence test to get back on the internet.

It's this attitude that actually helps the bad guys along. Everyone thinks "it only happens to someone else" which keeps the trust factor high enough that the scams work again and again. It's very much like it was in the early days where you never questioned an email with an attachment that came from a friend, yet that's exactly how Happy99 and Melissa made it so big. Even FBI Director Robert Mueller almost fell for a phish. So it's not just "dumb people" falling for scams. The phish attacks are getting more and more sophisticated and not as easy to "spot the fake" as it were.
Reply to this comment
by Harrison912 October 30, 2009 6:11 PM PDT
I've seen this before since I started using Twitter to socially market my safety and security web site. I hope they catch who ever is doing it this time. I'm all about catching the bad guys.
Reply to this comment
by albizzia November 1, 2009 7:21 PM PST
The message, "Be ever vigilant and always suspicious".
Reply to this comment
by TobyGalino November 3, 2009 7:35 AM PST
Yeah well.. how about "Knock Knock"... it would be an interesting study to see the amount that fall for that. Oh My, I have to agree with all of you and yet, I too understand how sometimes you fall victim by "pulling the trigger" prior to clarity and immediately have that nauseous feeling in your gut.

At VeriSign we note this as more reason to encrypt sites (not just financial and ecommerce) And internet users and development folks have their piece of this action to respond to, but if, for example, if SocNet's like Twitter, Facebook, were encrypted with Extended Validation SSL, it would cut down on phishing attempts that could compromise log-in credentials across multiple websites.
Reply to this comment
(10 Comments)
  • prev
  • 1
  • next
advertisement

The 411 on early-termination fees

Verizon Wireless has doubled its early-termination fees for smartphones, but what does it mean for the rest of the industry?

Google has its own plan for Netbooks

No, the search giant isn't saying it will build a Netbook. But it sure knows what it would like one running Chrome OS to resemble, and that's a little different from the Netbook of today.
• Screenshot tour of Chrome OS

About InSecurity Complex

Elinor Mills became fascinated with hacker culture when she was sent to Las Vegas to cover DefCon in 1995. Since then, script kiddies have given way to cyber criminals targeting bank passwords, and privacy risks are everywhere, from Google to Facebook and the iPhone. InSecurity Complex keeps tabs on the flaws, the foibles, and the fixes.

Add this feed to your online news reader

InSecurity Complex topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right