|
Website Hacked with AOL phishing code |
|
|
|
Wednesday, 27 February 2008 |
|
Our website was recently hacked and a "phishing" web page targeting AOL users was uploaded to our server. This bogus web page has been removed from our server and we have updated the server security to prevent the same exploit from being used against us again. We have sent all relevant information to AOL so that they can investigate those behind this attack. Many bogus emails were sent from these same hackers directing AOL users to this malicious web page. The page appeared to be an AOL login page and was used to collect AOL user names and passwords. If you logged into this bogus web page when it was still active please change your AOL password immediately as your account may be compromised. A sample email appears below (Clicking on the "My Account" link in the email would have directed the user to a URL hosted on our server, disguised by using the IP address):
Dear AOL Member,
This confirms that your AOL payment method has been updated to reflect the new information you provided. You can make payment method changes at AOL Keyword: My Account throughout your monthly billing cycle if you decide that a different payment method would better suit your needs. Please note however, that the billing method on record at 10:00 AM EST on your billing cycle date will be the one used to process your account charges.
You can access America Online`s secure, self-service Billing Center by going to AOL Keyword: My Account. Here you can review and modify your AOL account information online, anytime.
Please Remember: If your account information is not updated within 48 hours then your ability to use your AOL account will become restricted!
Sincerely, Member Services AOL, LLC.
|