PSA -------- CSRF/Phishing attack
Nov. 30th, 2011 03:36 pmJust signal boosting...
Originally posted by
markf at CSRF/Phishing attack
Originally posted by
There is currently a CSRF designed to mislead you into believing LiveJournal is requesting your username and password, when the data is actually being requested by a third party who is trying to gain access to your account.
The attack will appear as though someone has left you a comment, but an image similar to the following will appear requesting your password:

The domain used, liv i ejournal.com, is not livejournal.com, and you should not enter your password into any popup like this which appears. The domain used by the attacker could change at any time.
If you have entered your username and password into any popup like this, you should immediately change your password at https://www.livejournal.com/changepassword.bml.
If any content has been deleted from your journal by someone other than you, please submit an abuse request.
The attack will appear as though someone has left you a comment, but an image similar to the following will appear requesting your password:

The domain used, liv i ejournal.com, is not livejournal.com, and you should not enter your password into any popup like this which appears. The domain used by the attacker could change at any time.
If you have entered your username and password into any popup like this, you should immediately change your password at https://www.livejournal.com/changepassword.bml.
If any content has been deleted from your journal by someone other than you, please submit an abuse request.
no subject
Date: 2011-11-30 08:46 pm (UTC)Thanks for the signal boost. I hope no one gets caught.
*hugs*
no subject
Date: 2011-11-30 08:51 pm (UTC)I haven't seen anything yet - but man - DNW my lj hacked. :/
no subject
Date: 2011-11-30 08:47 pm (UTC)(Not that most of them don't already follow you anyway, but just in case.)
no subject
Date: 2011-11-30 08:50 pm (UTC)You can even go directly to the original post here:
http://lj-support.livejournal.com/840844.html
and click the little '+' sign and it will like back to the official post and not to mine. :)
no subject
Date: 2011-11-30 08:52 pm (UTC)D'oh! Thanks!
no subject
Date: 2011-11-30 08:54 pm (UTC)