Phishing exploitation detected

May 16, 2007 14:30 GMT  ·  By

Security company Symantec discovered a new phishing threat targeting Yahoo Messenger, the famous instant messaging client provided by Yahoo. According to the company, the phishers are attempting to lure users to provide their account information and steal the Yahoo username. It seems like the entire exploitation is conducted to a page similar with Yahoo 360, all the details being stolen once the user click on the Sign in button.

"This threat is a phishing attack that encourages users to click on a URL that opens a web page that looks like a login page to the Yahoo! 360(Beta). Once at the web site, the user is encouraged to enter their Yahoo credentials. As soon as the user clicks on "Sign In" button the credentials are mailed to an external account," Symantec said.

The security company rated the flaw with a low risk level, sustaining that administrators should ensure that they have the latest antivirus definitions to detect and block the phishing attempts. However, it's very difficult to say if your security solution is able to block this phishing attempt because there are a lot of software products on the Internet but only some of them managed to be efficient.

However, you should be extremely careful when you click on Yahoo 360 and check the URL link before entering your account details.

Yahoo Messenger is the instant messaging client offered by the Sunnyvale company that is currently the most popular chat application in the Internet. Most of the users are describing it as more than a simple program because it provides numerous functions that help you communicate in several ways. As you might know, you're able to chat using the webcam support, the VoIP features or even send files to your friends straight from the interface of the application.