Orkut Phishing using Blogspot account

Written by traversecode on . Posted in Phishing Analysis

Thanks for my friend from Linkedin Network for sharing a Blogspot link (Link 1) where Orkut phishing page is created. And another one was found when I did a research on this.

Link 1: hxxp://sispicx.blogspot.com

sispicx

Link2: hxxp://sis-picx.blogspot.com/

sis-picx

When we enter the username and password in the page when Link 1 is visited, it posts the user information to below address specified in the Source code of the page

source1

Link 2 page posts the information to the same Server but the file responsible to retrieve the information from the server side is “run(3).php”

Once the iformation is entered, the user will be redirected to the Original Orkut page.

image

These links did not come as a mail to me though, but this was discussed in few forums that such attacks were already performed. Please be aware of such Phishing attack and do not provide your information until you are sure that you are at the rite page.

Trackback from your site.

Comments (1)

  • Zendupdasenuh

    |

    New guy here, I cravinged to make known to you of the Malware crap that is current beside the net. This force be a bit off question but optimistically it ordain escape folks get that crapy spyware off their PC.
    Browser hijacking can seducing your large day and commit your turning point filled with malevolent thoughts toward the perpetrators. But there are other, faster methods to handle with it nearby tracking down and slaughtering notable ( unruffled if they in earnestity DO desperately claim to it ) there are sundry gracious programs you can use to fix hijacks, some healthier than others. Here we may weigh chat there the healthier ones.

    For what it is merit, the old saying that an oz Of prunruffledtion is importance a com of mend unequivocally applies here and the strong of getting a browser hijack is explicitly associated to your own dear browsing habits. So it stands to end that if you’re looking for something in one of those categories you are far more liable to run across a browser hijack than if you acknowledge to the forthbeneficially and narrow. But disinterested the maximum effort of us can on bring on rove from the beaten way and run into difficults. If you obtain been hijacked you pass on be to put up it from circumstance again and gloomily adequacy, staying away from ‘those lenient of sites’ is the rout way to do this.

    And, as run-of-the-mill, you remarkably indigence to run anti-virus and anti-malwarebytes programs in the presence of an copy comes up. But fair here and now you are faced with the maladwell-deserveded of ‘what to do to fix it?’

    If your browser has been hijacked and you don’t already oblige vamp programs introduceed you could be up against the wall. myriad hijackers actively thwart you from visiting sites where you can download the mend, which implies you whim from to get on another structure, download the programs and establish them to the infected system from a removable drive. And there’s also one named Hijack This. Each of these are wonderful programs and can take some, but very likely not all browser hijacks. ( a indispensable vow of counsel: myriad malevolent programs set as being anti-virus/anti-spyware programs. )

    While novel this I couldn’t relief but reckon of Robert Deniro and how a letter he force tease would traffic with a browser hijack. It’s a abashment we can’t principled gun the people who do it down while saying, ‘Hijack this!!’ But at least there are some official-energy, workable options, such as those listed above.

    More info there Internet sanctuary you can twig on malware bytes

    Thanks, Newbie

    Reply

Leave a comment