Here’s the abbreviated text version of this blog entry for all you dial-up users and hearing impaired peeps:
Spoof MySpace log-in pages have been being used by asshats to harvest e-mail addresses and MySpace passwords for a number of different things for quite some time. They are simply one of the steps used for a variety of hustles. And, the information the asshats gain from them (e-mail addresses and MySpace passwords) can sometimes be used for stuff that’s really malicious. There have been some bulletins floating around MySpace about this issue that are a mix of truth and total BS. Well, here’s the real deal…
What in the hell is going on???
People are using spoof MySpace log-in pages to harvest e-mail addresses and passwords associated with accounts. The main thing I’ve seen this info being used for at the moment is to send-out bulletin spam from accounts. That’s why you’ve been seeing bulletins posted from your friends accounts that obviously aren’t posted by them.
Here’s how this goes down:
1. Asshats create spoof MySpace log-in pages. When a person enters in their e-mail address and passwords on these pages the asshat gets that info.
2. Through various methods the asshats are getting people to view their fake log-in pages. Before the Flash 9 upgrade this was most commonly done by using embedded flash files within bulletins and on fake myspace profiles that would auto-redirect you to them when you viewed said bulletins or profiles. So, they were just employing the same redirect method as that virus/adware fake porn site asshat. Instead of sending you to a site to get infected with some evilness, they were redirecting you to their spoof MySpace log-in pages. Now, they are using some less effective methods to get you onto the spoof pages. They are sending-out bulletins that say goofy stuff like Get 20 pics for your MySpace account and having links in there that go to said pages. And, some other lameness.
3. With your e-mail address and MySpace password they can do a number of things. Many of you use the same e-mail address and password for several different sites, including PayPal, your online banking sites, e-mail account, etc. So, these guys can also log into those accounts with your info.
Whats up with the spam bulletins?
Lots of spammers have been sending-out bulletins from all the accounts they have in their databases of phished (harvested) account info. They are not logging into each account one at a time and doing this manually. Its being done through an automated program which logs into the accounts one at a time and posts the bulletins for them. This sucks, but its not nearly as bad as the kids that are getting account info and screwing-up your pages and changing the passwords. Luckily, theres not too many of them doing that at the moment.
Examples of spam bulletins:
Title: Free Tones for the Phones Tonight Only!
Body: Special Deal for Myspace Users Free RingTones! Click Here! Hurry ends soon! CLICK HERE
Title: Check-out this dating site!!!
Body: I’ve been spending more time on this site than MySpace lately. You should all join it and come hang-out: CLICK HERE TO JOIN
Title: Awesomeness!!! I just got my FREE Laptop in!
Body: A couple days ago I found a website that supposively gives away laptops. Well, I really just got mine in the mail today! CLICK HERE TO GET YOURS
Title: OMG? 15 free ring tones! This is sweet!
Body: wow, i just got 15 sweet new ringers for my phone! all you have to do is enter your email, and you get them sent to your phone! it was that easy… I thought I’d just send it around to see if more people would like some awesome ringtones:CLICK HERE, enter your email, and choose your new ringtonez!
etc, etc, etc…
What you need to do:
1. Change your passwords on every website that you use the same e-mail address and password on.
2. If you haven’t already, upgrade to Flash 9.
3. Quit falling prey to these spoof log-in pages. MySpace is riddled with errors, but at no time have I ever been logged-out and directed to a log-in page. It just doesn’t happen.
Here are a few examples of the urls (web addresses) that you’ll see the spoof log-in pages on:
http://www.52234myspace.com/
http://625.214.65.987/
http://login-myspace-com-index-cfm.kjdhfidf.com
http://login-myspace-com.5456dsfg.com/index.cfm?fuseaction=login&Blah-Blah-Blah
http://625.214.65.987/index.cfm?fuseaction=login&Blah-Blah-Blah
As you can see, some of them look fairly legit. As a rule of thumb: NEVER enter your MySpace password anywhere unless you just finished typing-in myspace.com and pressing Enter or you accessed the site from a bookmark.
If you see a spoof log-in page anywhere please report it to MySpace via this link: Report Spoof MySpace Login Pages
/Shameless plug for retardedtshirts.com. Buy some shirts and/or add a banner to your MySpace page to help a Ninja out. All sales benefit me and a different charity every month. Click Here for Details And Banners
Print This Page
E-Mail This Page
AIM a Friend
Set as Away Message
