{"id":77,"date":"2007-12-17T02:44:54","date_gmt":"2007-12-17T06:44:54","guid":{"rendered":"http:\/\/patorjk.com\/blog\/2007\/12\/17\/myspace-phishing\/"},"modified":"2014-01-25T17:38:40","modified_gmt":"2014-01-25T21:38:40","slug":"myspace-phishing","status":"publish","type":"post","link":"https:\/\/patorjk.com\/blog\/2007\/12\/17\/myspace-phishing\/","title":{"rendered":"MySpace Phishing"},"content":{"rendered":"<p>I&#8217;ve come across a rather interesting MySpace phishing technique. Hijacked profiles will send you a link or post a link on your wall telling you to go look at some user&#8217;s profile (it&#8217;ll usually be done by a friend of your&#8217;s). For example, they may say Joe is dead and display the following link to his profile:<\/p>\n<p><a rel=\"\u201dnofollow\u201d\" href=\"http:\/\/profile.myspace.com\/index.cfmfuseaction=user.viewprofile=1890000\">http:\/\/profile.myspace.com\/index.cfmfuseaction=user.viewprofile= 1890000<\/a><\/p>\n<p>However, when you click the link, you&#8217;ll really be taken to a website like the following:<\/p>\n<p><a href=\"http:\/\/profile.myspace.com.fuseaction.id.user.viewprofile.1890000.cn\/\" rel=\u201dnofollow\u201d>http:\/\/profile.myspace.com.fuseaction.id.user.viewprofile. 1890000.cn\/<\/a><\/p>\n<p>Notice the &#8220;.cn&#8221; extension. That site ain&#8217;t MySpace. If you follow the above link you&#8217;ll see that it takes you to a site that looks just like the MySpace homepage, and it&#8217;ll be asking you to log in &#8211; even though you should already be logged in. MySpace is kind of crappy in that you have to log in to see certain things, and sometimes you get logged out for various reasons, so most users will gladly re-enter their information.<\/p>\n<p>After you&#8217;ve given this phishing site your log in info, it&#8217;ll save it and then use it to re-log you in to the real MySpace web site. So you&#8217;ll end up back at MySpace, but that interesting thing you were told about isn&#8217;t anywhere to be found. I&#8217;d assume most users would just shrug this off and move on &#8211; totally unaware that they&#8217;ve just given their log in information to a phisher\/spammer\/identity theif\/whatever.<\/p>\n<p>This really isn&#8217;t anything new, phishing has been around a long time. However, it actually works really well in this scenario, since MySpace used to take you to it&#8217;s home page after asking you to log in (even if you just wanted to look at someone&#8217;s pictures), and you were sent the link by one of your friends (not by some random dude you know is probably a phisher), so the environment leads to it being a pretty transparent attack. Anyway, it&#8217;s important to keep a look out for these kinds of things. A couple of my friends have had their accounts hijacked recently and they weren&#8217;t sure how it happened (I haven&#8217;t mentioned the above scenario since I just witnessed it recently). You don&#8217;t want to get your account or any accounts that may use the same password deleted because some jackass stole your log in info and then spammed a bunch of people.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I&#8217;ve come across a rather interesting MySpace phishing technique. Hijacked profiles will send you a link or post a link on your wall telling you to go look at some user&#8217;s profile (it&#8217;ll usually be done by a friend of your&#8217;s). For example, they may say Joe is dead and display the following link to &hellip; <a href=\"https:\/\/patorjk.com\/blog\/2007\/12\/17\/myspace-phishing\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">MySpace Phishing<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-77","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/patorjk.com\/blog\/wp-json\/wp\/v2\/posts\/77","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/patorjk.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/patorjk.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/patorjk.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/patorjk.com\/blog\/wp-json\/wp\/v2\/comments?post=77"}],"version-history":[{"count":1,"href":"https:\/\/patorjk.com\/blog\/wp-json\/wp\/v2\/posts\/77\/revisions"}],"predecessor-version":[{"id":2724,"href":"https:\/\/patorjk.com\/blog\/wp-json\/wp\/v2\/posts\/77\/revisions\/2724"}],"wp:attachment":[{"href":"https:\/\/patorjk.com\/blog\/wp-json\/wp\/v2\/media?parent=77"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/patorjk.com\/blog\/wp-json\/wp\/v2\/categories?post=77"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/patorjk.com\/blog\/wp-json\/wp\/v2\/tags?post=77"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}