Facebook used for phishing attacks..!!

priyanshuit's picture

.
Have a look at http://www.faaceb0ok.com/ . its FACEB0OK not FACEBOOK. Here O is "0" (zero).
First email message appears to come from Facebook Security, and requests that users confirm their account
Websense Security Labs has cautioned Facebook users of phishing attack after discovering the social networking site being used to display phishing pages for different services, as well as to redirect to phishing pages hosted elsewhere.

According to the release from the lab the first email message appears to come from Facebook Security, and requests that users confirm their account. This is just like other phishing attacks we see every day. The twist here is that the phishing page itself gets loaded from within the Facebook site using an iframe. This makes it look much more legitimate than a site hosted on another domain.
The second message is similar, but there's another URL towards the end. Clicking the link sends the user to Facebook site, where a script redirects the user to another Web site that contains the phishing page.

So, beware of a new phishing & fake page attack to hack facebook accounts. Have a look at http://www.faaceb0ok.com/, at first glance it looks like a normal facebook page. But just have a look again, its FACEB0OK not FACEBOOK. Here O is "0" (zero).

Both of these attacks make it harder for the user to spot the malicious content directly from the email. Both messages do point to a valid Facebook URL. In addition, the inclusion of valid Facebook URLs makes protecting users somewhat harder for anti-spam solutions and Web filtering products that rely on heavily URL filtering to classify content, the Web sense Security Labs said.

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
5 + 6 =
Solve this simple math problem and enter the result. E.g. for 1+3, enter 4.

About the Author

priyanshuit's picture

Name
priyanshu

Last Name
sahay

Gender
Male

Website / Blog
http://www.hackersonlineclub.com

About me
Myself PRIYANSHU. >> Certified Cyber Law Expert >> Certified Cyber Security Expert >> Certified Ethical Hacker >> Working on Cyber Security, Ethical Hacking, Investigation, VAPT, Web Designing. Catch Me On >> Facebook: http://www.facebook.com/priyanshu.it Twitter: http://twitter.com/priyanshu_itech Email: priyanshu@cyber-india.in

Location
Delhi

Recent comments