New Facebook Security Phishing: Please complete this security check
In one of my Facebook information security groups a fellow member got targeted by a facebook phishing attack. The phishing account sends a single message to the facebook user. After the user clicks on the link, they start collecting information to hijjack his Facebook + E-mail and more.
I thought it would be nice if i wrote a summary about the phishing attack.
The Facebook phising message:
“WARNING : Your account is reported to have violated the policies that are considered annoying or insulting Facebook users. Until we (http://www.facebook.com/security) system will disable your account within 24 hours if you do not do the reconfirmation.
Please confirm your facebook account below:
<Phishing link> http://pleace-check-you-accounts.at.hm/ <Phishing link>
Thanks.Facebook Security “
Once you click on the first link (http://www.facebook.com/security) you will be redirected to a Facebook Security page on Facebook.
Once you click on the second link (<Phishing link> http://pleace-check-you-accounts.at.hm/ <Phishing link>) you will be redirected to the AT.hm domain.
At the moment you land on the AT.hm domain you will see a phished facebook page. The malicious facebook page contains the following question.
Please Complete This Security Check.
For the safety and privacy of your Facebook account, facebook Our team has made some improvements in security of your facebook. You must verify your email address before you can use it on facebook service.
Once you click on confirm you will be redirected to this page.

Once you click confirm you get redirected to the next page.

Here they collect your secret question.

Here they collect your e-mail credentials.

Here they collect your card number.

After receiving all your information you get redirected to the facebook security page.

Tweet
Memorial
Knowledge is suppressed because of its power to change.
Online since 30-jan-2010
Security tips #1
Donate
Donate & Help us out. Server(
cost money.
Security tips #2
Avoiding Social Engineering and Phishing Attacks
Dealing with Cyberbullies
Preventing and Responding to Identity Theft
Recognizing and Avoiding Spyware
Recovering from Viruses, Worms, and Trojan Horses
Understanding Denial-of-Service Attacks
Understanding Hidden Threats: Corrupted SoftwareFiles
Understanding Hidden Threats: Rootkits and Botnets
Who's new
- ciberprov
- michael.nguyen
- mornjinfeng
- aniketdaptardar
- hadriker
- Alanw
Security vids #1
Team Cymru Research NFP is a specialized Internet security research firm and 501(c)3 non-profit dedicated to making the Internet more secure. Team Cymru helps organizations identify and eradicate problems in their networks, providing insight that improves lives.
Team Cymru the video series 1 to 10
Team Cymru the video series 11 to 20
Team Cymru the video series 21 to 30
Team Cymru the video series 31 to 40
Team Cymru the video series 41 to 50
Team Cymru the video series 51 to 60
Who's online
Security vids #2
The Center for Education and Research in Information Assurance and Security (CERIAS) is currently viewed as one of the world’s leading centers for research and education in areas of information security that are crucial to the protection of critical computing and communication infrastructure.
CERIAS is unique among such national centers in its multidisciplinary approach to the problems, ranging from purely technical issues (e.g., intrusion detection, network security, etc) to ethical, legal, educational, communicational, linguistic, and economic issues, and the subtle interactions and dependencies among them.
CERIAS Security: Attribute-Based Access Control
CERIAS Security: Information Flow Analysis in Security Enhanced Linux
CERIAS Security: Towards Mining Syslog Data
Weapons of Mass Disruption Gallery Launch: Reitinger Remarks
Weapons of Mass Disruption: Mike McConnell on The Nightmare Scenario










Comments
Have a problem of security check.
It's attached to my chat room icon killing me
11:20am
LAST WARNING : Your account is reported to have violated the policies that are considered annoying or insulting Facebook users. Until we (http://www.facebook.com/security) system will disable your account within 24 hours if you do not do the reconfirmation.
If you still want to use Facebook, Please confirm your account below:
apps-help-center-users-inc.co.cc/
Thanks.
The Facebook Team
Post new comment