WARNING: Hotfile Phishing

Status
Not open for further replies.

Flash

Active Member
1,463
2008
191
0
WARNING: Hotfile Phishing with c o . c c domains

Listen up webmasters, of there has been a lot of phishing going around especially with Rapidshare and now Hotfile is the new target in this scheme. Thank you to El_j for covering this I am merely posting this since he didn't have the time to do so.

Phishing Example:

Code:
http://hotfilecom.c o.c c/119.9/dl/765673/53b5edf/UD07_electrician.avi.html
Screen Shot:




Notice I have not downloaded anything from hotfile yet I receive this message. :S


How can I avoid this on my forum?

The answer is simple. Just censor the c o. c c words in your forum.


How do I censor these words?

vBulletin: http://www.vbulletin.com/docs/html/vboptions_group_censor

Phpbb: http://www.phpbb.com/support/documentation/3.0/adminguide/acp_posting.php (scroll down 3/4 of the page)

IPB: go to acp/looks & feel/bad word filters (at the left side at the bottom)
And for Ipb 2.3.x you have to go to acp/management/Word & Ban Filters/manage bad word filters (again in the left corner below)

SMF
: http://www.mambodemo.com/smf/censored_words.html




General Phishing Tips:

Whenever visiting any site that has anything valuable to you make sure you are logging in to the correct URL and NOT a phished one. Keep in mind there is such a thing as url masking that is a clever way that people use to trick you into logging in to your account using a phished URL.


Example:


https://login.yahoo.com/ <----That is a masked linked, how can you tell before clicking it?
If you are using firefox on the bottom left there is a bar next to the word Done and when you scroll over any link it shows the correct URL.

Screen:



Now that comes in handy a lot of times.
 
8 comments
Thanks flash for making the thread.

Sadly, only censoring .co.cc will not be enough as I'm sure phishers will find other ways. Please keep an eye on your websites, we haven't seen any phishing attempts other than RS until now.

Hotfile is becoming more popular as we all know, so keep your website clean and your users safe, thank you.
 
I had mybb before and you could cover protected links with word choices by knowing the servers they come from like on Warezbb like this:
http://~ Due To The Increase In Phishing We Now Disallow Protected URL's
I have IPB3 and am looking for a way to do that . I do not think it is possible without writing a filter for that is it? and if so then how?
 
Status
Not open for further replies.
Back
Top