<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CounterMeasures -  A Security Blog » last.fm</title>
	<atom:link href="http://countermeasures.trendmicro.eu/tag/lastfm/feed/" rel="self" type="application/rss+xml" />
	<link>http://countermeasures.trendmicro.eu</link>
	<description>Trend Microâ€™s Rik Ferguson blogs about current security issues.</description>
	<lastBuildDate>Wed, 01 Feb 2012 14:48:59 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Phishing Attack Targets last.fm Users</title>
		<link>http://countermeasures.trendmicro.eu/phishing-attack-targets-lastfm-users/</link>
		<comments>http://countermeasures.trendmicro.eu/phishing-attack-targets-lastfm-users/#comments</comments>
		<pubDate>Fri, 05 Jun 2009 10:01:51 +0000</pubDate>
		<dc:creator>Rik Ferguson</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Web 2.0]]></category>
		<category><![CDATA[last.fm]]></category>
		<category><![CDATA[web]]></category>

		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=704</guid>
		<description><![CDATA[The current trend for abusing Web 2.0 sites in co-ordinated phishing attacks continues. Â  Users of the &#8220;world&#8217;s largest online music catalogue&#8221; are the latest victims. Unfortunate users receive a message in their last.fm shoutbox saying &#8220;hey &#8211; check out this blog with ur pic &#8211; http://ur.lc/[blocked]&#8221; or &#8220;hey check out this blog&#8221; again with [...]<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/phishing-attack-targets-lastfm-users/' addthis:title='Phishing Attack Targets last.fm Users '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></description>
			<content:encoded><![CDATA[<p>The current trend for abusing Web 2.0 sites in co-ordinated phishing attacks continues.</p>
<p>Â </p>
<p>Users of the &#8220;world&#8217;s largest online music catalogue&#8221; are the latest victims. Unfortunate users receive a message in their last.fm shoutbox saying &#8220;<em>hey &#8211; check out this blog with ur pic &#8211; http://ur.lc/[blocked]</em>&#8221; or &#8220;<em>hey check out this blog</em>&#8221; again with an abbreviated URL.</p>
<p><img class="alignleft size-full wp-image-705" title="spam" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2009/06/spam.png" alt="spam" width="510" height="92" /></p>
<p>Â </p>
<p>If you click the link you are redirected to a faked last.fm login screen as below, note the highlighted URL</p>
<p><img class="alignleft size-full wp-image-706" title="lastfm" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2009/06/lastfm.png" alt="lastfm" width="510" height="252" /></p>
<p>Â </p>
<p>This is a known malicious domain registered to a Chinese IP address and has been associated with several previous credential harvesting attacks.</p>
<p>Â </p>
<p>I&#8217;ve said it once, but it bears repeating, *always* check the URL in the address bar of your browser before entering any login credentials.</p>
<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/phishing-attack-targets-lastfm-users/' addthis:title='Phishing Attack Targets last.fm Users '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></content:encoded>
			<wfw:commentRss>http://countermeasures.trendmicro.eu/phishing-attack-targets-lastfm-users/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

