<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Phishing Scam Targeting Facebook Users</title>
	<atom:link href="http://www.techcrunch.com/2008/03/26/phishing-scam-targeting-facebook-users/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.techcrunch.com/2008/03/26/phishing-scam-targeting-facebook-users/</link>
	<description>Startup and Technology News</description>
	<pubDate>Thu, 24 Jul 2008 20:11:21 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
		<item>
		<title>By: Robert</title>
		<link>http://www.techcrunch.com/2008/03/26/phishing-scam-targeting-facebook-users/#comment-2141654</link>
		<dc:creator>Robert</dc:creator>
		<pubDate>Tue, 08 Apr 2008 00:43:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunch.com/2008/03/26/phishing-scam-targeting-facebook-users/#comment-2141654</guid>
		<description>yeah, i got the same last week and i clicked it. got hit a bit but then changed my password and deleted all applications and a lot of friends.

My msn was also being logged in from some other computer and it is no related but from a computer than had some software that recorded keystrokes.  phisfing software in another country was the origin.

these ppl make online really fun!</description>
		<content:encoded><![CDATA[<p>yeah, i got the same last week and i clicked it. got hit a bit but then changed my password and deleted all applications and a lot of friends.</p>
<p>My msn was also being logged in from some other computer and it is no related but from a computer than had some software that recorded keystrokes.  phisfing software in another country was the origin.</p>
<p>these ppl make online really fun!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jeffrey</title>
		<link>http://www.techcrunch.com/2008/03/26/phishing-scam-targeting-facebook-users/#comment-2133534</link>
		<dc:creator>Jeffrey</dc:creator>
		<pubDate>Sat, 05 Apr 2008 18:41:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunch.com/2008/03/26/phishing-scam-targeting-facebook-users/#comment-2133534</guid>
		<description>I got one of these messages on my wall last night.  It appeared to be coming from a friend.  It stated (I have removed most of the address):

lisen she's ma new friend add her up and give her a lil time as she is new here ;)

her profile is at
http://www.facebook.com. . . .

I clicked the link and was directed to a login page, at which point Firefox warned me that it was a scam to get my information.  I looked at the profile's of a few other friends of my friend who had been scammed, and saw that very similar messages had been sent to some of them.  I left warnings for a few of them about the scam.  I tried clicking on the link in IE also, and found that IE does not warn that it is a scam.  It's a good thing I was using Firefox at the time.</description>
		<content:encoded><![CDATA[<p>I got one of these messages on my wall last night.  It appeared to be coming from a friend.  It stated (I have removed most of the address):</p>
<p>lisen she&#8217;s ma new friend add her up and give her a lil time as she is new here <img src='http://www.techcrunch.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>her profile is at<br />
<a href="http://www.facebook.com" rel="nofollow">http://www.facebook.com</a>. . . .</p>
<p>I clicked the link and was directed to a login page, at which point Firefox warned me that it was a scam to get my information.  I looked at the profile&#8217;s of a few other friends of my friend who had been scammed, and saw that very similar messages had been sent to some of them.  I left warnings for a few of them about the scam.  I tried clicking on the link in IE also, and found that IE does not warn that it is a scam.  It&#8217;s a good thing I was using Firefox at the time.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SearchCap: The Day In Search, March 27, 2008</title>
		<link>http://www.techcrunch.com/2008/03/26/phishing-scam-targeting-facebook-users/#comment-2057630</link>
		<dc:creator>SearchCap: The Day In Search, March 27, 2008</dc:creator>
		<pubDate>Fri, 28 Mar 2008 00:45:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunch.com/2008/03/26/phishing-scam-targeting-facebook-users/#comment-2057630</guid>
		<description>[...] Phishing Scam Targeting Facebook Users, TechCrunch [...]</description>
		<content:encoded><![CDATA[<p>[...] Phishing Scam Targeting Facebook Users, TechCrunch [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Karen</title>
		<link>http://www.techcrunch.com/2008/03/26/phishing-scam-targeting-facebook-users/#comment-2057511</link>
		<dc:creator>Karen</dc:creator>
		<pubDate>Thu, 27 Mar 2008 23:26:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunch.com/2008/03/26/phishing-scam-targeting-facebook-users/#comment-2057511</guid>
		<description>All the information you would need to get a credit card or buy a car (maybe even get a passport) is on facebook. Full name, birthday, address... Where they work and phone numbers are just bonuses.</description>
		<content:encoded><![CDATA[<p>All the information you would need to get a credit card or buy a car (maybe even get a passport) is on facebook. Full name, birthday, address&#8230; Where they work and phone numbers are just bonuses.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jonathan Jordan</title>
		<link>http://www.techcrunch.com/2008/03/26/phishing-scam-targeting-facebook-users/#comment-2057332</link>
		<dc:creator>Jonathan Jordan</dc:creator>
		<pubDate>Thu, 27 Mar 2008 21:43:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunch.com/2008/03/26/phishing-scam-targeting-facebook-users/#comment-2057332</guid>
		<description>I think the idea too is that a lot of folks use the same password for multiple logins... so if they know your FB password, it is possible that will also be your email password or tied to other high value credentials.</description>
		<content:encoded><![CDATA[<p>I think the idea too is that a lot of folks use the same password for multiple logins&#8230; so if they know your FB password, it is possible that will also be your email password or tied to other high value credentials.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brill Pappin</title>
		<link>http://www.techcrunch.com/2008/03/26/phishing-scam-targeting-facebook-users/#comment-2057132</link>
		<dc:creator>Brill Pappin</dc:creator>
		<pubDate>Thu, 27 Mar 2008 20:11:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunch.com/2008/03/26/phishing-scam-targeting-facebook-users/#comment-2057132</guid>
		<description>@Don Jones

I'm Assuming that your at least as intelligent and observant as I am :)
I used to think the same way... so you keep thinking that way, and one will eventually get you as well...

I would really love to know if there is some sort of secret ninja society hunting these guys and shutting down their servers. Sign me up!</description>
		<content:encoded><![CDATA[<p>@Don Jones</p>
<p>I&#8217;m Assuming that your at least as intelligent and observant as I am <img src='http://www.techcrunch.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
I used to think the same way&#8230; so you keep thinking that way, and one will eventually get you as well&#8230;</p>
<p>I would really love to know if there is some sort of secret ninja society hunting these guys and shutting down their servers. Sign me up!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brill Pappin</title>
		<link>http://www.techcrunch.com/2008/03/26/phishing-scam-targeting-facebook-users/#comment-2057111</link>
		<dc:creator>Brill Pappin</dc:creator>
		<pubDate>Thu, 27 Mar 2008 20:04:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunch.com/2008/03/26/phishing-scam-targeting-facebook-users/#comment-2057111</guid>
		<description>I'm ashamed to say that I was caught in this one, and I'm fairly vigilant about that sort of thing (fist time for everything).

Whats interesting was that the domain "view-facebookprofiles.com" was actually a front for another host (used an iframe) named 	join-today.net that when I search it is showing up in several different sites and has been around for at least 6 months. The actual path was join-today.net/face.

If you do a search for "join-today.net" you will find at least two or three others. The ISP that hosts join-today.net is in China and I can't speak chinese... however if someone could get on the horn with them, you might be able to recover and at least terminate that host.

I did make a small attempt to find the hackers control script but I'm just not up on that technology... that was about 10 minutes after I got nailed. The though was that its going to be writing all that data to the server and if I could get in I could save a lot of people some headache by deleting the capture file.</description>
		<content:encoded><![CDATA[<p>I&#8217;m ashamed to say that I was caught in this one, and I&#8217;m fairly vigilant about that sort of thing (fist time for everything).</p>
<p>Whats interesting was that the domain &#8220;view-facebookprofiles.com&#8221; was actually a front for another host (used an iframe) named 	join-today.net that when I search it is showing up in several different sites and has been around for at least 6 months. The actual path was join-today.net/face.</p>
<p>If you do a search for &#8220;join-today.net&#8221; you will find at least two or three others. The ISP that hosts join-today.net is in China and I can&#8217;t speak chinese&#8230; however if someone could get on the horn with them, you might be able to recover and at least terminate that host.</p>
<p>I did make a small attempt to find the hackers control script but I&#8217;m just not up on that technology&#8230; that was about 10 minutes after I got nailed. The though was that its going to be writing all that data to the server and if I could get in I could save a lot of people some headache by deleting the capture file.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sourceroot</title>
		<link>http://www.techcrunch.com/2008/03/26/phishing-scam-targeting-facebook-users/#comment-2057074</link>
		<dc:creator>sourceroot</dc:creator>
		<pubDate>Thu, 27 Mar 2008 19:50:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunch.com/2008/03/26/phishing-scam-targeting-facebook-users/#comment-2057074</guid>
		<description>I think they could fix this by monitoring the accounts that have updated the email address recently, then looking for the embedded links. 

What I want to know is, why the even let you change the challenge question?</description>
		<content:encoded><![CDATA[<p>I think they could fix this by monitoring the accounts that have updated the email address recently, then looking for the embedded links. </p>
<p>What I want to know is, why the even let you change the challenge question?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adam O'Donnell</title>
		<link>http://www.techcrunch.com/2008/03/26/phishing-scam-targeting-facebook-users/#comment-2057001</link>
		<dc:creator>Adam O'Donnell</dc:creator>
		<pubDate>Thu, 27 Mar 2008 19:22:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunch.com/2008/03/26/phishing-scam-targeting-facebook-users/#comment-2057001</guid>
		<description>Like it or not, anything that is valued by an individual can be valued by an attacker.  There are plenty of reasons to phish a social network account beyond retrieving the end-user e-mail account.  Individuals a high value on their online presence, and will likely even pay money to retrieve a compromised account.  Another use of the account is to generate spam and phishing targeted at the compromised account's friends to further propagate the attack.</description>
		<content:encoded><![CDATA[<p>Like it or not, anything that is valued by an individual can be valued by an attacker.  There are plenty of reasons to phish a social network account beyond retrieving the end-user e-mail account.  Individuals a high value on their online presence, and will likely even pay money to retrieve a compromised account.  Another use of the account is to generate spam and phishing targeted at the compromised account&#8217;s friends to further propagate the attack.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BEFORE i FORGET &#187; FACEBOOK USERS BEWARE written by Simon Jones</title>
		<link>http://www.techcrunch.com/2008/03/26/phishing-scam-targeting-facebook-users/#comment-2056961</link>
		<dc:creator>BEFORE i FORGET &#187; FACEBOOK USERS BEWARE written by Simon Jones</dc:creator>
		<pubDate>Thu, 27 Mar 2008 19:09:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunch.com/2008/03/26/phishing-scam-targeting-facebook-users/#comment-2056961</guid>
		<description>[...] TechCrunch are reporting the strange facebook scam which involves users being directed to a bogus facebook page and asked for their account details. The scam involves a notice appearing on the wall of user profiles as a message from a friend, saying &#8220;Hey, I got a new facebook account. Im going to delete this one, so add my new profile&#8221; then with a link that appears to be a link to the new profile. The actual link goes to a URL on view-facebookprofiles.com, a domain registered (and whois protected) on Namecheap and hosted at Softlayer that looks identical to the Facebook login page: [...]</description>
		<content:encoded><![CDATA[<p>[...] TechCrunch are reporting the strange facebook scam which involves users being directed to a bogus facebook page and asked for their account details. The scam involves a notice appearing on the wall of user profiles as a message from a friend, saying &#8220;Hey, I got a new facebook account. Im going to delete this one, so add my new profile&#8221; then with a link that appears to be a link to the new profile. The actual link goes to a URL on view-facebookprofiles.com, a domain registered (and whois protected) on Namecheap and hosted at Softlayer that looks identical to the Facebook login page: [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: AW</title>
		<link>http://www.techcrunch.com/2008/03/26/phishing-scam-targeting-facebook-users/#comment-2056917</link>
		<dc:creator>AW</dc:creator>
		<pubDate>Thu, 27 Mar 2008 18:54:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunch.com/2008/03/26/phishing-scam-targeting-facebook-users/#comment-2056917</guid>
		<description>I wouldn't have fallen for this...

...because Firefox's Phishing Alert immediately goes off when you visit the page.

Do people turn that feature off, or are most of the people being phish'd not using Firefox?</description>
		<content:encoded><![CDATA[<p>I wouldn&#8217;t have fallen for this&#8230;</p>
<p>&#8230;because Firefox&#8217;s Phishing Alert immediately goes off when you visit the page.</p>
<p>Do people turn that feature off, or are most of the people being phish&#8217;d not using Firefox?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Simon Jones</title>
		<link>http://www.techcrunch.com/2008/03/26/phishing-scam-targeting-facebook-users/#comment-2056753</link>
		<dc:creator>Simon Jones</dc:creator>
		<pubDate>Thu, 27 Mar 2008 17:58:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunch.com/2008/03/26/phishing-scam-targeting-facebook-users/#comment-2056753</guid>
		<description>Agreed, DOS is NEVER EVER appropriate or legitimate.</description>
		<content:encoded><![CDATA[<p>Agreed, DOS is NEVER EVER appropriate or legitimate.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: I Am Not Posting To Spam My Blog</title>
		<link>http://www.techcrunch.com/2008/03/26/phishing-scam-targeting-facebook-users/#comment-2055631</link>
		<dc:creator>I Am Not Posting To Spam My Blog</dc:creator>
		<pubDate>Thu, 27 Mar 2008 10:56:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunch.com/2008/03/26/phishing-scam-targeting-facebook-users/#comment-2055631</guid>
		<description>The problem is that thanks to Facebook's cackhanded attempt at turning us into unwilling PR slaves, plus the prevalence of application span, you'd be hard pressed to distinguish spam from a compromised account than something your real "friends" might send you.

As to the point of gaining access to a Facebook account, well, Jaymon wins the prize. Since a lot of people use the same passwords for their Facebook and email account, and your email address is also your Facebook login, you've got a free pass to go into their email account and start rooting around for bank details and password reminders.</description>
		<content:encoded><![CDATA[<p>The problem is that thanks to Facebook&#8217;s cackhanded attempt at turning us into unwilling PR slaves, plus the prevalence of application span, you&#8217;d be hard pressed to distinguish spam from a compromised account than something your real &#8220;friends&#8221; might send you.</p>
<p>As to the point of gaining access to a Facebook account, well, Jaymon wins the prize. Since a lot of people use the same passwords for their Facebook and email account, and your email address is also your Facebook login, you&#8217;ve got a free pass to go into their email account and start rooting around for bank details and password reminders.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mapro Chang</title>
		<link>http://www.techcrunch.com/2008/03/26/phishing-scam-targeting-facebook-users/#comment-2055413</link>
		<dc:creator>Mapro Chang</dc:creator>
		<pubDate>Thu, 27 Mar 2008 09:37:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunch.com/2008/03/26/phishing-scam-targeting-facebook-users/#comment-2055413</guid>
		<description>Yeah, it's exact the same as facebook. When first time I visit the site, I think it is the facebook. Thank you for warning. Whatever, facebook now is so popular that a lot of guys wanna make money from it. But how facebook make money except the ads.? I don't see it....</description>
		<content:encoded><![CDATA[<p>Yeah, it&#8217;s exact the same as facebook. When first time I visit the site, I think it is the facebook. Thank you for warning. Whatever, facebook now is so popular that a lot of guys wanna make money from it. But how facebook make money except the ads.? I don&#8217;t see it&#8230;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark</title>
		<link>http://www.techcrunch.com/2008/03/26/phishing-scam-targeting-facebook-users/#comment-2055402</link>
		<dc:creator>Mark</dc:creator>
		<pubDate>Thu, 27 Mar 2008 09:35:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunch.com/2008/03/26/phishing-scam-targeting-facebook-users/#comment-2055402</guid>
		<description>DOS is never legit, fool. The site may be hosted on a shared ISP.
Personally I dont give a damn because Facebook is the hipster thing of the net, claiming to be something cool while it is actually more mainstream than anything.</description>
		<content:encoded><![CDATA[<p>DOS is never legit, fool. The site may be hosted on a shared ISP.<br />
Personally I dont give a damn because Facebook is the hipster thing of the net, claiming to be something cool while it is actually more mainstream than anything.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Josh</title>
		<link>http://www.techcrunch.com/2008/03/26/phishing-scam-targeting-facebook-users/#comment-2055207</link>
		<dc:creator>Josh</dc:creator>
		<pubDate>Thu, 27 Mar 2008 08:11:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunch.com/2008/03/26/phishing-scam-targeting-facebook-users/#comment-2055207</guid>
		<description>The website doing the actual harvesting is &lt;a href="http://www.who.is/whois-net/ip-address/join-today.net/" rel="nofollow"&gt;join-today.net&lt;/a&gt; registered to a company in China. view-facebookprofiles.com is just an external frame.</description>
		<content:encoded><![CDATA[<p>The website doing the actual harvesting is <a href="http://www.who.is/whois-net/ip-address/join-today.net/" rel="nofollow" onclick="javascript:pageTracker._trackPageview ('/outbound/www.who.is');">join-today.net</a> registered to a company in China. view-facebookprofiles.com is just an external frame.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Patty</title>
		<link>http://www.techcrunch.com/2008/03/26/phishing-scam-targeting-facebook-users/#comment-2055062</link>
		<dc:creator>Patty</dc:creator>
		<pubDate>Thu, 27 Mar 2008 07:11:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunch.com/2008/03/26/phishing-scam-targeting-facebook-users/#comment-2055062</guid>
		<description>Thanks for the warning...this looks like a great site for tech info!</description>
		<content:encoded><![CDATA[<p>Thanks for the warning&#8230;this looks like a great site for tech info!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DOS is legitimate</title>
		<link>http://www.techcrunch.com/2008/03/26/phishing-scam-targeting-facebook-users/#comment-2054911</link>
		<dc:creator>DOS is legitimate</dc:creator>
		<pubDate>Thu, 27 Mar 2008 05:52:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunch.com/2008/03/26/phishing-scam-targeting-facebook-users/#comment-2054911</guid>
		<description>In this instance, it's appropriate to DOS the phishing site to ensure users won't be able to get to the site.  Maintain the DOS so that it will hurt the phishing site financially.  At which time the host provider will have to get into the picture to take the site down and notify the owner.  And of course the owner is not in the U.S. =) Must be from India or China. hahaha =)</description>
		<content:encoded><![CDATA[<p>In this instance, it&#8217;s appropriate to DOS the phishing site to ensure users won&#8217;t be able to get to the site.  Maintain the DOS so that it will hurt the phishing site financially.  At which time the host provider will have to get into the picture to take the site down and notify the owner.  And of course the owner is not in the U.S. =) Must be from India or China. hahaha =)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dave Johnston</title>
		<link>http://www.techcrunch.com/2008/03/26/phishing-scam-targeting-facebook-users/#comment-2054853</link>
		<dc:creator>Dave Johnston</dc:creator>
		<pubDate>Thu, 27 Mar 2008 05:13:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunch.com/2008/03/26/phishing-scam-targeting-facebook-users/#comment-2054853</guid>
		<description>Facebook is awful.  Can we just admit that already?  I went through all this before with Myspace in 2005.  Learn how to build your own site.  Write some clever code, it takes a couple of hours to learn.</description>
		<content:encoded><![CDATA[<p>Facebook is awful.  Can we just admit that already?  I went through all this before with Myspace in 2005.  Learn how to build your own site.  Write some clever code, it takes a couple of hours to learn.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Warren Benedetto</title>
		<link>http://www.techcrunch.com/2008/03/26/phishing-scam-targeting-facebook-users/#comment-2054851</link>
		<dc:creator>Warren Benedetto</dc:creator>
		<pubDate>Thu, 27 Mar 2008 05:12:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunch.com/2008/03/26/phishing-scam-targeting-facebook-users/#comment-2054851</guid>
		<description>Don't forget that plenty of people put a TON of personal info in their Facebook account: email addresses, cell phone numbers, home addresses, plus all that juicy demographic stuff like gender, relationship status, etc. 

These phishing sites not only get your contact info for various types of spam, but they can then offer detailed demographics to their shady penile enlargement customers, to better target spam, telemarketing, etc. 

And, of course, @kevin is right too.</description>
		<content:encoded><![CDATA[<p>Don&#8217;t forget that plenty of people put a TON of personal info in their Facebook account: email addresses, cell phone numbers, home addresses, plus all that juicy demographic stuff like gender, relationship status, etc. </p>
<p>These phishing sites not only get your contact info for various types of spam, but they can then offer detailed demographics to their shady penile enlargement customers, to better target spam, telemarketing, etc. </p>
<p>And, of course, @kevin is right too.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dan Jones</title>
		<link>http://www.techcrunch.com/2008/03/26/phishing-scam-targeting-facebook-users/#comment-2054847</link>
		<dc:creator>Dan Jones</dc:creator>
		<pubDate>Thu, 27 Mar 2008 05:12:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunch.com/2008/03/26/phishing-scam-targeting-facebook-users/#comment-2054847</guid>
		<description>Sometimes I feel like the people who fall for these things got what they had coming. If they're not smart enough to look at the address bar before submitting info, maybe they deserve to have their info stolen.

I know that's not true, though, because my bicycle got stolen while I failed to lock it up. Same principle.

Oh well, people just need to learn to be more careful, and pay attention to what's going on around them.

As a side note, whenever I see a phishing site like this, I like to give them fake information. Like an email address like youguysaredorks@geekville.us, and a password like IHopeYouGoToJail.</description>
		<content:encoded><![CDATA[<p>Sometimes I feel like the people who fall for these things got what they had coming. If they&#8217;re not smart enough to look at the address bar before submitting info, maybe they deserve to have their info stolen.</p>
<p>I know that&#8217;s not true, though, because my bicycle got stolen while I failed to lock it up. Same principle.</p>
<p>Oh well, people just need to learn to be more careful, and pay attention to what&#8217;s going on around them.</p>
<p>As a side note, whenever I see a phishing site like this, I like to give them fake information. Like an email address like <a href="mailto:youguysaredorks@geekville.us">youguysaredorks@geekville.us</a>, and a password like IHopeYouGoToJail.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sean</title>
		<link>http://www.techcrunch.com/2008/03/26/phishing-scam-targeting-facebook-users/#comment-2054834</link>
		<dc:creator>sean</dc:creator>
		<pubDate>Thu, 27 Mar 2008 05:07:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunch.com/2008/03/26/phishing-scam-targeting-facebook-users/#comment-2054834</guid>
		<description>@kevin

yep, i received a message from an acquaintance who i do not regularly talk to last night -- i thought he was just being dumb and spamming me.

here's the message with no links, but the site appears to redirect you to wherever they want you to go (originally ringtones, now pharamacy):

"i think i already told you but incase you forgot, you gotta see all the thousands of ringtones over at http://www.******.com i just got 20 free from them into my phone and i plan on getting more, they got all the songs i ever wanted and best things is, they don't rob your wallet for each song like the mobile provider does. they download right into your phone in seconds and best of all, no big nasty bill at the end of the month. be smart and save your money, hit them up now like i did at http://www.******.com"</description>
		<content:encoded><![CDATA[<p>@kevin</p>
<p>yep, i received a message from an acquaintance who i do not regularly talk to last night &#8212; i thought he was just being dumb and spamming me.</p>
<p>here&#8217;s the message with no links, but the site appears to redirect you to wherever they want you to go (originally ringtones, now pharamacy):</p>
<p>&#8220;i think i already told you but incase you forgot, you gotta see all the thousands of ringtones over at <a href="http://www" rel="nofollow">http://www</a>.******.com i just got 20 free from them into my phone and i plan on getting more, they got all the songs i ever wanted and best things is, they don&#8217;t rob your wallet for each song like the mobile provider does. they download right into your phone in seconds and best of all, no big nasty bill at the end of the month. be smart and save your money, hit them up now like i did at <a href="http://www" rel="nofollow">http://www</a>.******.com&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: kevin</title>
		<link>http://www.techcrunch.com/2008/03/26/phishing-scam-targeting-facebook-users/#comment-2054821</link>
		<dc:creator>kevin</dc:creator>
		<pubDate>Thu, 27 Mar 2008 04:59:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunch.com/2008/03/26/phishing-scam-targeting-facebook-users/#comment-2054821</guid>
		<description>Are you guys stupid?
Step 1: Phish accounts
Step 2: Create program to auto login to said account and post a 'new link'
Step 3: Have said program run down the list of the thousands of accounts, Posting stuff like "OMG I CANT BELIEVE I ACTUALLY GOT A FREE IPOD!! CLICK HERE AND DO IT !!!"

Step 4: Profit


Get ready for captchas all over the place on facebook. (At least thats how it went down on myspace)</description>
		<content:encoded><![CDATA[<p>Are you guys stupid?<br />
Step 1: Phish accounts<br />
Step 2: Create program to auto login to said account and post a &#8216;new link&#8217;<br />
Step 3: Have said program run down the list of the thousands of accounts, Posting stuff like &#8220;OMG I CANT BELIEVE I ACTUALLY GOT A FREE IPOD!! CLICK HERE AND DO IT !!!&#8221;</p>
<p>Step 4: Profit</p>
<p>Get ready for captchas all over the place on facebook. (At least thats how it went down on myspace)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gabe</title>
		<link>http://www.techcrunch.com/2008/03/26/phishing-scam-targeting-facebook-users/#comment-2054756</link>
		<dc:creator>Gabe</dc:creator>
		<pubDate>Thu, 27 Mar 2008 04:26:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunch.com/2008/03/26/phishing-scam-targeting-facebook-users/#comment-2054756</guid>
		<description>The scammers are building a massive and shadowy PokeNet.  And now you're in their sites, Duncan.  Next time you log in, there will be a MegaPoke (poke*10^6) waiting for you!</description>
		<content:encoded><![CDATA[<p>The scammers are building a massive and shadowy PokeNet.  And now you&#8217;re in their sites, Duncan.  Next time you log in, there will be a MegaPoke (poke*10^6) waiting for you!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt</title>
		<link>http://www.techcrunch.com/2008/03/26/phishing-scam-targeting-facebook-users/#comment-2054749</link>
		<dc:creator>Matt</dc:creator>
		<pubDate>Thu, 27 Mar 2008 04:21:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunch.com/2008/03/26/phishing-scam-targeting-facebook-users/#comment-2054749</guid>
		<description>facebook (and others) need to offer optional browser plugins for users... they can call them "security guards" that will establish an address bar color (?? something in the address bar) that only the user and the plugin know (facebook doesn't even need to know, lest they accidentally publish it in an RSS feed or some other confounded blunder they manage to fall face first into).  Not on the page, like the giraffe the bank shows you when log into your savings account, but in the address bar, like the security validation color we get on some browsers. I think there's value in getting it ingrained in peoples minds that the only place you can trust is the address bar... if you were just logged in and all of a sudden being asked for your credentials again, be trained to notice the address bar is no longer blue (if thats the color you pick...). This "training" will eventually become a part of human evolution and people will be born to recognize a phishy URL.</description>
		<content:encoded><![CDATA[<p>facebook (and others) need to offer optional browser plugins for users&#8230; they can call them &#8220;security guards&#8221; that will establish an address bar color (?? something in the address bar) that only the user and the plugin know (facebook doesn&#8217;t even need to know, lest they accidentally publish it in an RSS feed or some other confounded blunder they manage to fall face first into).  Not on the page, like the giraffe the bank shows you when log into your savings account, but in the address bar, like the security validation color we get on some browsers. I think there&#8217;s value in getting it ingrained in peoples minds that the only place you can trust is the address bar&#8230; if you were just logged in and all of a sudden being asked for your credentials again, be trained to notice the address bar is no longer blue (if thats the color you pick&#8230;). This &#8220;training&#8221; will eventually become a part of human evolution and people will be born to recognize a phishy URL.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.102 seconds -->
