Flickr targetted in new-style social phish/trojan attack

, posted: 1-NOV-2006 15:05

My MSN account had a peculiar looking message in it recently:

Flikrphish

I don't have a photo on Flickr so I assumed this was some sort of "click me and get h4x3d" type of email - and indeed it was.

The link went (still goes as of writing this) to a compromised server in Norway that's hosting a copy of a Flickr page belonging to a real user on that site. When you land on the compromised site, IE7 asks if you want to allow it to run "outlook.exe". I didn't allow it to this though. :)

I'm not sure what exactly would've happened if I had allowed the site to run outlook.exe - next time I checked, the account on a server in Russia that the attacker used had been suspended, so nothing happened. Perhaps the attacker tried to plant stuff on your machine from the server in Russia, or was simply firing up Outlook to do a quick spam run. There's nothing now in the HTML on the site that shows what the intention was, although the spammer left some code pointing to a stats counter...

Either way, this could be the beginning of "social phishing", I think.






Tag(s):             


Other related posts:
Email servers strain under doubled spam load


 



Add a comment

Please note: comments that are inappropriate or promotional in nature will be deleted. E-mail addresses are not displayed, but you must enter a valid e-mail address to confirm your comments.

Are you a registered Geekzone user? Login to have the fields below automatically filled in for you and to enable links in comments. If you have (or qualify to have) a Geekzone Blog then your comment will be automatically confirmed and shown in this blog post.

Your name:

Your e-mail:

Your webpage:





Links to stories I've written:

Google News search for me
PC World New Zealand
Computerworld NZ
PC World and Computerworld Australia
PC World US
Computerworld US
Infoworld
NZ Herald
Virus Bulletin
PC World NZ Blog

Content copyright © Juha Saarinen. If you wish to use the content of my blog on your site, please contact me for details. I'm usually happy to share my stuff, as long as it's not for spamblogs and what have you. Attribution with a link back to the blog is always appreciated. If you wish to advertise on my blog, please drop me an email to discuss the details.

Comments policy
All comments posted on this blog are the copyright and responsibility of the submitters in question. Comments commercial and promotional in nature are not allowed. Please ensure that your comments are on topic and refrain from making personal remarks.




    follow me on Twitter





    Add to Netvibes



    Latest comments

    Bill Bennett on Trade Me, the behemoth on NZ’s Internet: Which begs the question, does TradeMe make more money from advertising than it m...

    juha on Trade Me, the behemoth on NZ’s Internet: @Edmund Yeah, page impressions are but one measure :)...

    Edmund Good on Trade Me, the behemoth on NZ’s Internet: All well and good to serve up that many pages - is anyone actually buying??...

    freitasm on Trade Me, the behemoth on NZ’s Internet: And with that they suck dry all the online advertising budget and no one else ge...

    lotech on Losers in the Apple iPad launch: Microsims are just smaller shaped SIMs - other than the size of the plastic it i...

    juha on Losers in the Apple iPad launch: @dacraka Vodafone NZ says it has MicroSIMs - I'd imagine Telecom has them too. C...

    dacraka on Losers in the Apple iPad launch: If NZ wants the 3G functionality, our mobile operators will need to come out wit...

    Foo on Losers in the Apple iPad launch: Great article Juha.@Jason - 60 days until release? Won't it be longer for NZ (Ju...

    Bnsofts on Losers in the Apple iPad launch: Ohh this is great thanks for sharing....

    freitasm on Losers in the Apple iPad launch: Phreek... Vodafone 3G network is 2100MHz only in the main centres. Everywhere th...



    Top Ten Techsplodings

    Telecom New Zealand's local lo...
    (28-APR-2006 17:32, 179241 views)
    Join New Zealand Internet blac...
    (16-FEB-2009 09:26, 132559 views)
    iTunes 7 bugs: doesn't Apple t...
    (14-SEP-2006 12:34, 91972 views)
    Working BIOS driver crack for ...
    (13-MAR-2007 16:14, 50968 views)
    The spoofed Telecom commercial...
    (19-MAY-2006 15:59, 45223 views)
    What did Materazzi say to Zida...
    (11-JUL-2006 08:20, 38975 views)
    Windows Vista problem solving ...
    (24-FEB-2007 18:16, 37381 views)
    Firefox 2.0 and Windows Vista ...
    (3-DEC-2006 12:23, 33810 views)
    Gutmann Reloaded and My Vista ...
    (26-JAN-2007 15:35, 32544 views)
    The Saddam Snuff Movie...
    (31-DEC-2006 11:25, 31237 views)




    Subscribe to RSS headline updates from: http://feeds.feedburner.com/Technozone
    Powered by FeedBurner



    Add to Google Subscribe in NewsGator Online Click here to add this RSS feed to Feedster Click here to add this RSS feed to My MSN Click here to add this RSS feed to AvantGo Click here to add this RSS feed to My Yahoo!

    Linkorama

    Modern Drunkard Magazine
    Centre for Citizen Media
    The Assimilated Negro
    The Raw Feed
    Object Dart
    Copyblogger
    Neil Sanderson's blog
    The Opinionated Diner
    Griffin's Gadgets
    Dion Hinchcliffe
    InternetNZ blog (Colin Jackson)
    Spareroom
    Off the record
    Rawiri Blundell
    KhooSuyinKhoo
    ReadWriteWeb
    Frankarr
    Tim Haines
    Darren Rowse - Problogger
    Daniel McKenzie
    The Hivelogic Narrative
    Fraser Talk
    Leaf Salon
    Bad Science
    Wanda Harland
    Kiwi Herald
    Mauricio Freitas
    Hard News
    The Geekzoner
    Mr Cokemaster
    Commercial Archive
    Kiwiblog
    Jama
    Chiefie's blog
    Generation X Y
    Not the South China Morning Post
    Nic often Wise
    Loosewire (Jeremy Wagstaff of WSJ)
    SunnyO
    BlackMagic NZ Film Blog
    Nigel Parker's MSDN blog