Username: Save?
Password:
Home Forum Links Search Login Register*
    News: Welcome to the TechnoWorldInc! Community!
Recent Updates
[April 24, 2024, 11:48:22 AM]

[April 24, 2024, 11:48:22 AM]

[April 24, 2024, 11:48:22 AM]

[April 24, 2024, 11:48:22 AM]

[April 03, 2024, 06:11:00 PM]

[April 03, 2024, 06:11:00 PM]

[April 03, 2024, 06:11:00 PM]

[April 03, 2024, 06:11:00 PM]

[March 06, 2024, 02:45:27 PM]

[March 06, 2024, 02:45:27 PM]

[March 06, 2024, 02:45:27 PM]

[March 06, 2024, 02:45:27 PM]

[February 14, 2024, 02:00:39 PM]
Subscriptions
Get Latest Tech Updates For Free!
Resources
   Travelikers
   Funistan
   PrettyGalz
   Techlap
   FreeThemes
   Videsta
   Glamistan
   BachatMela
   GlamGalz
   Techzug
   Vidsage
   Funzug
   WorldHostInc
   Funfani
   FilmyMama
   Uploaded.Tech
   MegaPixelShop
   Netens
   Funotic
   FreeJobsInc
   FilesPark
Participate in the fastest growing Technical Encyclopedia! This website is 100% Free. Please register or login using the login box above if you have already registered. You will need to be logged in to reply, make new topics and to access all the areas. Registration is free! Click Here To Register.
+ Techno World Inc - The Best Technical Encyclopedia Online! » Forum » THE TECHNO CLUB [ TECHNOWORLDINC.COM ] » Computer / Technical Issues » Internet » Websites » Yahoo!
 Alert: Yahoo Fake Login Screen is on Yahoo's Geocities itself!
Pages: [1]   Go Down
  Print  
Author Topic: Alert: Yahoo Fake Login Screen is on Yahoo's Geocities itself!  (Read 2641 times)
Khushi
Global Moderator
Adv. Member
*****



Karma: 4
Offline Offline

Posts: 329

Hello!!


View Profile
Alert: Yahoo Fake Login Screen is on Yahoo's Geocities itself!
« Posted: January 02, 2007, 01:08:40 PM »


Few days back, I got a mail from one of my friend saying her yahoo account has been hacked! The Chinese attacker accomplished this by creating a fake-login screen! Actually there is more victims to this yahoo fake-login screen. While this type of attack isn't new, what makes people vulnerable as this one is uploaded on yahoo's geocities itself!

Posting here are ways to protect yourself...

1. Trying Wrong Password (Simple)
If you suspect the login-screen next to you is fake, then best way is to enter wrong password. While a genuine login screen will return an error such as "wrong user name or password" the fake one will redirect you to pre-configured page!


2. Checking source code... (Advance)
You can also inspect source-code of login screen...
Look for
&
tags... (or you can directly search for "action" attribute)

Now original "action" value for yahoo photo's is,

    "https://login.yahoo.com/config/login?"

Its enough to check high-level domain (as shown in red color). Creating a fake-login screen is quite simple so if hacker attacker is really naive, then this will works 99.99999% of the time! There is only one way out for attacker and it depends much more on victims foolishness as well as luck!

A fake login screen will always have different value for action attribute...
few ex:

        * https://user.yahooo.com/config/login? (note extra O in yahoo)
        * http://myserever.com/fakelogin.cgi
        * etc...

For those relying on "forget password" option then there is another bad news...
This guy is smart enough to change PIN and COUNTRY information in all his victims yahoo account so they could not get even security question to answer!!!

Logged

« Reply #1 Posted: July 17, 2007, 02:31:49 AM »
Tina
Global Moderator
Elite Member
*****



Karma: 9
Offline Offline

Posts: 806

Hi Friendz...!!


View Profile WWW
Re: Alert: Yahoo Fake Login Screen is on Yahoo's Geocities itself!
« Reply #1 Posted: July 17, 2007, 02:31:49 AM »

hey..thanks for this info.
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Copyright © 2006-2023 TechnoWorldInc.com. All Rights Reserved. Privacy Policy | Disclaimer
Page created in 0.173 seconds with 26 queries.