Skip to main content

Hackers use Google to defeat anti-spam measures

posted onOctober 26, 2004
by hitbsecnews

Antivirus experts have discovered a phishing email that redirects users three times through Google to a fraudulent registration Web site in order to beat antispam technology. The email purports to be from Yahoo administrators and attempts to dupe users into signing up for new email accounts with the company. But using a clever combination of Yahoo and their own home-made Web sites, the hackers are claiming the accounts as their own.

"No one is going to block Google," said Alex Shipp, senior antivirus technologist for MessageLabs. "The link is a very complex string that hides their URL behind Google. It redirects three times probably to try and defeat anti-spam measures. Basically, you create email accounts for the bad guys. It's a way of ensuring that they have loads of accounts, and these could be used for [sending] spam."

The fraudsters sent emails pretending to be from Yahoo asking users to complete a registration form for an email account. The link on the email directs users to a fake Yahoo Web site, but does so pointing browsers at Google three times first. At this point a legitimate Yahoo pop-up appears explaining the registration process. When the form is completed, users are prompted to fill in a legitimate verification number, at which point the hackers can take control of the account.

Source

Tags

Spam

You May Also Like

Recent News

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th

Friday, June 7th