Pages

Thursday, October 20, 2011

Phishing page hacked, turned into PSA on the dangers of phishing

Here's something you don't see very often. Someone - perhaps the recipient of the below phishing mail while having a Falling Down style day at the office - decided enough was enough and set out to hijack the phishing site they were sent to.

This is the email that started it all:

 Click to Enlarge

"You have exceeded the storage limit on your mailbox.You will not be able to send or receive new mail until you upgrade your email.


Click the below link and fill the form to upgrade your account.


System Administrator"

Clicking the link would have taken you to the below phishing form that asks for Username, Password and Email address (along with password verification).

 Click to Enlarge

Now? Well, it looks a little bit different:

 Click to Enlarge

The original boxes are gone, replaced by the following message :

"There is no such thing as a central email service update a stupid criminal created this to steal your email account I have modified it to educate you about online crime he does not like that but that is too damn bad you can submit this form to see a helpful video about phishing stop letting stupid criminals like this one hijack your account have a great day"

Hitting the submit button takes you to a warning video about Phishing scams on CNET.

Click to Enlarge

There's no indication left as to how the person now in control of the site obtained the login credentials.

Phishing the phisher, perhaps? It does happen from time to time...

Christopher Boyd (Thanks to Robert and Wendy for this one)

No comments:

Post a Comment