Sinisterly
Beware of Phishing Attacks - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: General (https://sinister.li/Forum-General)
+--- Forum: Announcements (https://sinister.li/Forum-Announcements)
+---- Forum: Announcements (Archived) (https://sinister.li/Forum-Announcements-Archived)
+---- Thread: Beware of Phishing Attacks (/Thread-Beware-of-Phishing-Attacks)

Pages: 1 2


Beware of Phishing Attacks - Skullmeat - 04-20-2016

A user had a rigged signature that would bring a popup asking for mybb credentials. If you see one of these popups, DO NOT enter your login details. If you have entered your login details to one of these popups, change your password as soon as possible.

[Image: VaCOBRz.jpg]


RE: Beware of Phishing Attacks - Blue - 04-20-2016

wtf.

Someone find this lil pussy bitch.

Thanks for letting us know tho @Skullmeat luckily I have yet to see this!


RE: Beware of Phishing Attacks - OnlyTheFewWillSurvive - 04-20-2016

Thanks never knew this could happen.


RE: Beware of Phishing Attacks - Inori - 04-20-2016

Didn't think inserting scripts was possible with MyCode.. Will look out for this.

On a sidenote, do you have a list of threads that this has happened in? Might be able to deduce who it is.


RE: Beware of Phishing Attacks - Oni - 04-20-2016

(04-20-2016, 11:14 PM)Inori Wrote: Didn't think inserting scripts was possible with MyCode.. Will look out for this.

On a sidenote, do you have a list of threads that this has happened in? Might be able to deduce who it is.

It's just htaccess/htpasswd. But yeah, don't be a dumbass and enter your info.


RE: Beware of Phishing Attacks - Customer - 04-20-2016

I wouldn't have anyways hah..

Thanks for the heads up!


RE: Beware of Phishing Attacks - m0dem - 04-20-2016

(04-20-2016, 11:16 PM)Oni Wrote: It's just htaccess/htpasswd. But yeah, don't be a dumbass and enter your info.

I don't really understand what you mean by htaccess/htpasswd.
But anyway, that's scary.
If someone falls for it though... idk what to say. xD


RE: Beware of Phishing Attacks - MLP - 04-20-2016

(04-20-2016, 11:42 PM)m0dem Wrote: I don't really understand what you mean by htaccess/htpasswd.
But anyway, that's scary.
If someone falls for it though... idk what to say. xD

He is basically saying that by using a HTPASSWD (http://www.colostate.edu/~ric/htpass.html)
the guy was able to lock down his image with a valid .png so therefore it bypassed the image filters,
But due to the bypass working he could throw a custom message in attempt to gain failed HTACCESS attempts storing user creds,
Its quit a smart attack actually but poorly managed and I assume not very organised by not even using a domain.


RE: Beware of Phishing Attacks - PLX-2M - 04-21-2016

...or run NoScript plugin


RE: Beware of Phishing Attacks - Shadow.walker - 04-21-2016

I've didn't get it! ..isn't this attack progressed by someone who is already at your own wife Network or maybe your own ISP which trying to Sniff/inject Your Browser Cookies with old Fake phishing kiddy script!?
I just didn't get what's this had to do with us or sinister site!!?...it's all progressed by your own network if you have seen this script running!.