[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [Full-disclosure] Grab a myspace credential
- To: Peter Dawson <slash.pd@xxxxxxxxx>, Steven Scheffler <steven@xxxxxxxxxxxxxxxx>, codeshepherd@xxxxxxxxx
- Subject: Re: [Full-disclosure] Grab a myspace credential
- From: Juha-Matti Laurio <juha-matti.laurio@xxxxxxxx>
- Date: Tue, 16 Jan 2007 15:10:01 +0200 (EET)
This ?Suspected Web Forgery? alert by Firefox 2.0.0.1 was generated very soon
after the disclosure process.
It appears that team(s) behind this technology are reading FD list regularly.
- Juha-Matti
Steven Scheffler <steven@xxxxxxxxxxxxxxxx> wrote:
>
> If you dig into google's cache you will see that
> http://www.marcolano.com/login/ has a spoofed myspace.com login screen
> where ppl enter their credentials. These are saved in a plain text file
> myspace.txt.
>
> Firefox2 warned me about marcolano.com is a phishing site.
>
> S
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/