MySpace data phished and leaked

56,000 login details exposed by phishing researchers.

A large quantity of MySpace user login and password data has been posted online, according to some reports by researchers into phishing techniques available on the social site.

Advertise on www.virusbtn.com

The data was apparently gathered via a spoofed login page linked to from the site, and over 56,000 sets of details made publicly available online. At least some of the details entered make it clear that some visitors spotted the phish and posted fake and even abusive login data. Various phishing filters, including Firefox, were quickly updated to warn users visting the site.

A link to the listing was later posted to the Full Disclosure security forum, claiming the 56,000 figure was still rising. Although the site hosting both the phish and the data has since been taken down, it is thought the data was exposed to numerous visitors and is still available elsewhere on the web.

The original Full Disclosure posting is here, with some commentary from bloggers at SecuritTeam here and ComputerDefense.org here.

19 January 2007

Tags:    del.icio.us  digg this! digg this


Poll

How should software and OS patching/security updates be managed?
Manually, at the user's discretion
Automatically via an optional, user-defined schedule
Automatically via a fixed, but optional schedule
Automatically via a fixed schedule, on by default with opt-out system
Automatically and silently, with no option to run unpatched

Leave a comment
View 19 comments

Jobs Career Sidebar

VB100 certification

VB100 This month's comparative review tackles the 64-bit version of Windows Server 2003 - with the platform bringing out quite a number of quirks and oddities in several of the products under test.
See full results.

Virus Bulletin currently has 165,655 registered users.