<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>G to The Square &#187; phishing</title>
	<atom:link href="http://www.gtothesquare.com/tag/phishing/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gtothesquare.com</link>
	<description></description>
	<lastBuildDate>Fri, 30 Sep 2011 22:05:15 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Twitter Caught.. I mean Hacked</title>
		<link>http://www.gtothesquare.com/2009/01/06/twitter-caught-i-mean-hacked/</link>
		<comments>http://www.gtothesquare.com/2009/01/06/twitter-caught-i-mean-hacked/#comments</comments>
		<pubDate>Tue, 06 Jan 2009 00:54:24 +0000</pubDate>
		<dc:creator>Geries Handal</dc:creator>
				<category><![CDATA[Blogging]]></category>
		<category><![CDATA[Web]]></category>
		<category><![CDATA[Britney Spears]]></category>
		<category><![CDATA[Obama]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Twitter]]></category>
		<category><![CDATA[Web2.0]]></category>

		<guid isPermaLink="false">http://gtothesquare.wordpress.com/2009/01/06/twitter-caught-i-mean-hacked/</guid>
		<description><![CDATA[Earlier I posted about the reports of the phishing attacks against Twitter. Apparently high profile accounts i.e Obama, Britney where hacked. The good side is that the Hackers have a sense of humor, the bad thing is that they have been fixed.&#160; It looks like the vector of attack here some tools that where used [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.gtothesquare.com%2F2009%2F01%2F06%2Ftwitter-caught-i-mean-hacked%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.gtothesquare.com%2F2009%2F01%2F06%2Ftwitter-caught-i-mean-hacked%2F&amp;source=gtothesquare&amp;style=normal&amp;service=TinyURL.com&amp;hashtags=Britney+Spears,Obama,phishing,Security,Twitter,Web2.0&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>Earlier <a href="http://gtothesquare.com/2009/01/05/phishing-tweets/">I posted about the reports of the phishing attacks against Twitter</a>. Apparently <a href="http://www.readwriteweb.com/archives/twitter_security_collapses_oba.php">high profile accounts i.e Obama, Britney where hacked</a>. The good side is that the Hackers have a sense of humor, the bad thing is that they have been <a href="http://status.twitter.com/post/68538821/multiple-accounts-hacked-situation-stable">fixed.</a>&#160;</p>
<p>It looks like the <a href="http://status.twitter.com/post/68538821/multiple-accounts-hacked-situation-stable">vector of attack</a> here some tools that where used by support, to help users change their email. I guess that the hacker was able to change the email of the accounts, change the password and login. Makes me wonder if somebody in the support team had something to do with this? </p>
<p>I guess they should go back and but a BETA tag like most Web2.0 sites, at least that is a good excuse (Gmail is still BETA).</p>
<p>&#160;</p>
<p><a href="http://gtothesquare.files.wordpress.com/2009/01/image.png"><img title="image" style="border-right:0;border-top:0;display:inline;border-left:0;border-bottom:0;" height="351" alt="image" src="http://gtothesquare.files.wordpress.com/2009/01/image-thumb.png" width="462" border="0" /></a> </p>
<p><a href="http://gtothesquare.files.wordpress.com/2009/01/image1.png"><img title="image" style="border-right:0;border-top:0;display:inline;border-left:0;border-bottom:0;" height="272" alt="image" src="http://gtothesquare.files.wordpress.com/2009/01/image-thumb1.png" width="463" border="0" /></a> </p>
<p>Image source ReadWriteWeb</p>
]]></content:encoded>
			<wfw:commentRss>http://www.gtothesquare.com/2009/01/06/twitter-caught-i-mean-hacked/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Phishing Tweets</title>
		<link>http://www.gtothesquare.com/2009/01/05/phishing-tweets/</link>
		<comments>http://www.gtothesquare.com/2009/01/05/phishing-tweets/#comments</comments>
		<pubDate>Mon, 05 Jan 2009 17:20:47 +0000</pubDate>
		<dc:creator>Geries Handal</dc:creator>
				<category><![CDATA[Blogging]]></category>
		<category><![CDATA[Web]]></category>
		<category><![CDATA[Obama]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[Twitter]]></category>
		<category><![CDATA[Web2.0]]></category>

		<guid isPermaLink="false">http://gtothesquare.wordpress.com/2009/01/05/phishing-tweets/</guid>
		<description><![CDATA[According to the Twitter blog, phishing scams targeted at Twitter users, have appeared. If you wonder what scammers are trying to achieve with it? Well think about it, there is a lot of value in Twitter account. Maybe not on the average Joe Twitter user, however there are a lot of high profile Twitter users, [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.gtothesquare.com%2F2009%2F01%2F05%2Fphishing-tweets%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.gtothesquare.com%2F2009%2F01%2F05%2Fphishing-tweets%2F&amp;source=gtothesquare&amp;style=normal&amp;service=TinyURL.com&amp;hashtags=Obama,phishing,Twitter,Web2.0&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://gtothesquare.files.wordpress.com/2009/01/phishing1.jpg"><img style="display:inline;border-width:0;" title="phishing-1" src="http://gtothesquare.files.wordpress.com/2009/01/phishing1-thumb.jpg" border="0" alt="phishing-1" width="244" height="239" /></a></p>
<p>According to the <a href="http://blog.twitter.com/2009/01/gone-phishing.html">Twitter blog</a>, phishing scams targeted at Twitter users, have appeared. If you wonder what scammers are trying to achieve with it? Well think about it, there is a lot of value in Twitter account. Maybe not on the average Joe Twitter user, however there are a lot of high profile Twitter users, which account info may be of value. Just by having the president of the USA there, is worth trying the scam. Imagine if they could get the account of any high profile user  or with thousands of followers ? Some interesting social engineering could be done against the followers of the accounts hijacked.</p>
<p>At the end of the day, scammers may be betting on users using the same password on all their sites. Actually it makes sense, think about it, it takes some effort to come up with a new password that you can remember. And since people might think, that their Twitter account is not worth the effort of a new password, then why not use the “standard Web 2.0” password. Just shows how valuable are login information to popular Web 2.0 sites, even if the sites itself is not making money, doesn&#8217;t mean scammers can make money out of them.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.gtothesquare.com/2009/01/05/phishing-tweets/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

