I recently found an old document containing my username and password for the Fedora Linux forums so I tried to see if the account was still active and I used it to log in, which I was able to. Anyway, whilst logged in I noticed a news item on their forums about a potential phishing attack of their forums.
Here's the details...
It got me thinking, why would someone even attempt to steal someone's login and password for a web based forum? What possible data or financial reward could they get? Surely no one stores their personal information / bank details under their account in these web forums?
Are some people so sad that they like to do things like this?
Here's the details...
Nov 11, 2013 - 7:16 PM - by bob
Forum attack alert! We've just removed a new member posting a seemingly valid message with a link to illustrate his "problem". When members would click the link, they'd find a page that was an exact replica of the FedoraForum login page and think they'd somehow logged out. If you logged in to the phony page, the identity thief would have been given access to your username and password and been able to post garbage in your name.
Hopefully, this is the only such attack we'll have, however if you ever find yourself unexpectedly "logged out", look carefully at the full address bar to confirm that you're really at fedoraforum.org . In this case the attacker used our forums.fedoraforum.org but also his attack site: museumsalama.com..
Forum attack alert! We've just removed a new member posting a seemingly valid message with a link to illustrate his "problem". When members would click the link, they'd find a page that was an exact replica of the FedoraForum login page and think they'd somehow logged out. If you logged in to the phony page, the identity thief would have been given access to your username and password and been able to post garbage in your name.
Hopefully, this is the only such attack we'll have, however if you ever find yourself unexpectedly "logged out", look carefully at the full address bar to confirm that you're really at fedoraforum.org . In this case the attacker used our forums.fedoraforum.org but also his attack site: museumsalama.com..
Are some people so sad that they like to do things like this?
Comment