{"id":36,"date":"2011-08-13T23:35:16","date_gmt":"2011-08-14T04:35:16","guid":{"rendered":"https:\/\/www.falatic.com\/?p=36"},"modified":"2011-08-13T23:55:27","modified_gmt":"2011-08-14T04:55:27","slug":"new-old-twitter-password-stealer-making-the-rounds","status":"publish","type":"post","link":"https:\/\/www.falatic.com\/index.php\/36\/new-old-twitter-password-stealer-making-the-rounds","title":{"rendered":"New (old?) Twitter password stealer making the rounds&#8230;"},"content":{"rendered":"<p><strong>If you click a Twitter link and it sends you to a Twitter login page, beware&#8230; look closely at the address bar and ensure you&#8217;re actually at Twitter&#8217;s login page and not a thieving imposter&#8217;s page!<\/strong><\/p>\n<p><strong><\/strong>Recently a friend on Twitter sent a link as part of a message:<\/p>\n<p>&#8220;<em>Look! it&#8217;s you in this picture.. [along with a tinyurl link]<\/em>&#8221;<\/p>\n<p>Other variants of this exist, such as &#8220;<em>you&#8217;ll laugh when you see this pic of you<\/em>&#8230; <em> [along with a tinyurl link]<\/em>&#8220;.<\/p>\n<p>Turns out, my friend&#8217;s account had been hijacked. (Yes, it really was a friend&#8230; I&#8217;ve seen this before with Twitter and other sites but it looks identical to an attack I saw about a month ago).<\/p>\n<p><!--more-->In this case, the bogus link went to a subpage on <strong>itwittiler.com<\/strong> (IP address 220.164.140.252), a domain registered in China\u00a0&#8211; earlier today! The page <em>looks<\/em> like Twitter&#8217;s login page but it&#8217;s not. In fact, I sandboxed it and entered a bogus username\/password to see if it&#8217;d redirect to Twitter no matter what was entered. No&#8230; it redirected me to a &#8220;StalkTrak&#8221; page, clearly malformed and totally bogus. Read <a href=\"http:\/\/nakedsecurity.sophos.com\/2011\/08\/12\/twitter-finally-released-a-stalkers-app-no-its-a-phishing-scam\/\" target=\"_blank\">this Sophos security article<\/a> for more info.<\/p>\n<p>Another subpage (found via some searching online) does redirect to Twitter, but to a user who doesn&#8217;t exist. In all cases, the first page you go to looks just like the Twitter login page (there are some subtle yet sloppy differences, but next time there might not be.)<\/p>\n<p><strong>It&#8217;s quite likely the page is harvesting credentials along the way. If you get stung, go to the real Twitter homepage and reset your password pronto (after closing your browser windows).<\/strong><\/p>\n<p>More info on <strong>itwittiler.com<\/strong>, via <em>whois<\/em>:<\/p>\n<p>Domain Name: ITWITTILER.COM<br \/>\nRegistrar: JIANGSU BANGNING SCIENCE &amp; TECHNOLOGY CO. LTD<br \/>\nWhois Server: whois.55hl.com<br \/>\nReferral URL: http:\/\/www.55hl.com<br \/>\nName Server: DNS5.4CUN.COM<br \/>\nName Server: DNS6.4CUN.COM<br \/>\nStatus: ok<br \/>\nUpdated Date: 13-aug-2011<br \/>\nCreation Date: 13-aug-2011<br \/>\nExpiration Date: 13-aug-2012<\/p>\n<p><strong>Update:<\/strong> Another StalkTrak spam domain made the rounds last month: <strong>itiwitter.com<\/strong>. Surprise! It&#8217;s registered to the very same registrar! Judging by the same subpage structure I strongly suspect it&#8217;s the very same scammer using the very same site (or site structure)&#8230; while the IP address won&#8217;t resolve, it turns out <a href=\"http:\/\/www.priceofweb.com\/www.itiwitter.com\" target=\"_blank\">this site&#8217;s for sale!<\/a> And the IP address when last they checked? 220.164.140.252. Isn&#8217;t that special?<\/p>\n<p>Domain Name: ITIWITTER.COM<br \/>\nRegistrar: JIANGSU BANGNING SCIENCE &amp; TECHNOLOGY CO. LTD<br \/>\nWhois Server: whois.55hl.com<br \/>\nReferral URL: http:\/\/www.55hl.com<br \/>\nName Server: DNS5.4CUN.COM<br \/>\nName Server: DNS6.4CUN.COM<br \/>\nStatus: clientHold<br \/>\nStatus: clientTransferProhibited<br \/>\nUpdated Date: 20-jul-2011<br \/>\nCreation Date: 15-jul-2011<br \/>\nExpiration Date: 15-jul-2012<\/p>\n<p><strong>Still more information can be found <a href=\"http:\/\/stopmalvertising.com\/spam-scams\/do-not-hand-over-your-twitter-credentials-to-stalktrak.html\" target=\"_blank\">on this site<\/a><\/strong>, which talks about the same scam (back before the scammers changed domain names and came back from the &#8220;dead&#8221;).<\/p>\n<!-- wpsso rrssb get buttons: buttons on archive option not enabled -->\n","protected":false},"excerpt":{"rendered":"<p>If you click a Twitter link and it sends you to a Twitter login page, beware&#8230; look closely at the address bar and ensure you&#8217;re actually at Twitter&#8217;s login page <a href=\"https:\/\/www.falatic.com\/index.php\/36\/new-old-twitter-password-stealer-making-the-rounds\" class=\"more-link\">[&hellip;]<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"Layout":"","footnotes":"","_links_to":"","_links_to_target":""},"categories":[1],"tags":[64,65,63,62],"class_list":["entry","author-marty","has-more-link","post-36","post","type-post","status-publish","format-standard","category-uncategorized","tag-scams","tag-securiity","tag-social-networking","tag-twitter"],"_links":{"self":[{"href":"https:\/\/www.falatic.com\/index.php\/wp-json\/wp\/v2\/posts\/36","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.falatic.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.falatic.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.falatic.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.falatic.com\/index.php\/wp-json\/wp\/v2\/comments?post=36"}],"version-history":[{"count":0,"href":"https:\/\/www.falatic.com\/index.php\/wp-json\/wp\/v2\/posts\/36\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.falatic.com\/index.php\/wp-json\/wp\/v2\/media?parent=36"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.falatic.com\/index.php\/wp-json\/wp\/v2\/categories?post=36"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.falatic.com\/index.php\/wp-json\/wp\/v2\/tags?post=36"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}