Enjoy unlimited access to all forum features for FREE! Optional upgrade available for extra perks.
Domain summit 2024

Sophisticated Yahoo Messenger "phishing" scheme to steal passwords (for domains, etc)

Status
Not open for further replies.

GeorgeK

Leap.com
Legacy Exclusive Member
Joined
May 17, 2002
Messages
2,248
Reaction score
64
Feedback: 3 / 0 / 0
Someone tried to "phish" my Yahoo password (trying for my domains, presumaby), but of course they failed. Very sophisticated, as they were there interactively. Here's what I wrote to Yahoo, to give folks a heads-up on what to expect:

There was a "login" form that asked you to login, in case Yahoo takes down the page. It would have sent the login info to the phisher.

---- email to Yahoo -----
Hi,

Someone was trying to steal Yahoo passwords, via Instant Messaging:

http://www.geocities.com/baby0fthenet//yahoophotos.html

has their page, that tries to steal the info. I suspected something was wrong, so I put in a fake username password.

The profiles are:

http://profiles.yahoo.com/baby0fthenet
http://profiles.yahoo.com/hottnsour69

The IMs I had with "her" are:

---- first IM --------
george__k (5:49:08 PM): Are you a bot??
hottnsour69 (5:49:23 PM): lol no im Trina but Thanx l
george__k (5:49:34 PM): Hmmm, what's 30+25 ?
hottnsour69 (5:49:52 PM): im from Toronto goin to school in florida
hottnsour69 (5:49:54 PM): 55
george__k (5:50:10 PM): hehe Ahhh, you're flesh and blood, and not a bot.
hottnsour69 (5:50:18 PM): Yea lol
george__k (5:50:21 PM): (I get a lot of spam bots)
hottnsour69 (5:50:25 PM): i hear yea
george__k (5:50:33 PM): I'm in Central Toronto.
hottnsour69 (5:50:40 PM): im born and raised in the east end (BEACHES)
george__k (5:50:42 PM): (around Bloor/Ossington) What do you study?
hottnsour69 (5:51:05 PM): Fashion at the university of central florida
hottnsour69 (5:51:17 PM): in orlando
george__k (5:51:26 PM): Very nice. Are you graduating this year?
hottnsour69 (5:51:59 PM): yep then hopefully have a job back in Toronto
hottnsour69 (5:52:07 PM): i miss home
hottnsour69 (5:52:09 PM): lol
george__k (5:52:31 PM): Awww. I wish you luck. Did you ever think of going to one of the fashion capitals of the world, London, Paris, Milan, NYC, etc?
hottnsour69 (5:53:00 PM): When i get ajob offer and a grrencard or Visa yes
george__k (5:53:22 PM): Maybe a professor can put in a good word for you.
hottnsour69 (5:53:22 PM): but ive been away from my friends and family for 4 yrs i want soime home time first
hottnsour69 (5:53:35 PM): some*
hottnsour69 (5:54:03 PM): would you care to see some of my work? in my yahoophotos portfolio
george__k (5:54:07 PM): They must miss ya.
george__k (5:54:10 PM): Sure.
george__k (5:54:46 PM): The Geocities links don't work (they give an error message).
hottnsour69 (5:54:47 PM): they sure do
hottnsour69 (5:54:52 PM): brb
george__k (5:55:17 PM): "We're sorry, but this page is currently unavailable for viewing. "
george__k (5:55:30 PM): There is "photos.yahoo.com" that let you upload your files, too.
george__k (5:56:09 PM): (you'd need to "share" albums amongst friends, if you upload them there)
hottnsour69 (5:56:24 PM): kk ty
george__k (5:56:52 PM): Do you do men and women's fashions?
george__k (5:56:58 PM): Or, focus on anything in particular?
----- end of first IM -------------------


---- second IM --------------------
george__k (6:12:19 PM): Hi again.
george__k (6:12:30 PM): Had to check first, due to the bots, etc., lol.
baby0fthenet (6:12:37 PM): my other account was mes
george__k (6:13:15 PM): Oh, I see. Are you invisible, by the way?
george__k (6:13:26 PM): (can't see ya on my buddy list, not sure if it added you)
george__k (6:13:30 PM): Ahh, there you are, thanks.
baby0fthenet (6:13:39 PM): im here
baby0fthenet (6:13:42 PM): sorry
baby0fthenet (6:14:42 PM): http://www.geocities.com/baby0fthenet//yahoophotos.html thats my portfolio
george__k (6:16:30 PM): brb
george__k (6:17:01 PM): hehehe Trying to steal my Yahoo password. Nice try.
george__k (6:17:05 PM): Blocked.
george__k (6:17:34 PM): (I put in a fake username, pass) Nice try, though.
------ end of second IM ---------------------------

You should shut their accounts, obviously.

Sincerely,

George
416-588-0269

----- end of email to Yahoo --------

The archived IMs miss the first "greeting" sentence from them. Obvious attempt to use sex appeal, to grab passwords to let one's guard down.
 

GeorgeK

Leap.com
Legacy Exclusive Member
Joined
May 17, 2002
Messages
2,248
Reaction score
64
Feedback: 3 / 0 / 0
lol Byalik, you're so right. Whoever tried to steal my passwords knows my tastes well, that I like hotties. :party:
 
Status
Not open for further replies.

The Rule #1

Do not insult any other member. Be polite and do business. Thank you!

Sedo - it.com Premiums

IT.com

Premium Members

AucDom
UKBackorder
Be a Squirrel
MariaBuy

New Threads

Our Mods' Businesses

UrlPick.com
URL Shortener

*the exceptional businesses of our esteemed moderators

Top Bottom