Similar Searches

  • Phishing School Teaches Lessons on Secure Practices (March 11, 2009)

    The Trend Micro Content Security team discovered a phishing attack that used a software company’s website to lure victims into divulging personal information. The compromised site was that of School Website Solutions, which looks like this:Figure 1. Clean

  • Phishing Attacks on Indian Banks on the Rise (August 5, 2010)

    July 2010 was the month for phishing attacks on Indian banks. A three percent increase in phishing attacks on Indian banks from the previous month has been observed. In particular, Symantec has observed phishing websites that spoofed the Oriental Bank

  • Phishing Prepaid Debit Card Accounts (May 17, 2010)

    For the past month or so Symantec has been observing phishing websites that are spoofing a leading brand that provides prepaid debit card services to U.S. citizens. Legitimate prepaid debit cards help people to make purchases, pay bills, shop online,

  • Phishing Courier Service Brands (August 16, 2010)

    Symantec has recently observed phishing websites spoofing courier service brands. There were primarily three brands targeted and fraudsters were attempting to steal customers’ login credentials. So what’s in the login credentials of courier service brands that fraudsters can take advantage of?

  • Phishing Scam Targets Italian Bank (May 25, 2010)

    Italian bank Banca Popolare di Sondrio has become phishers’ new target with the discovery of a spammed message containing a link to the supposed bank’s Internet banking site, SCRIGNO.As

Related News

  • Phishing School Teaches Lessons on Secure Practices (March 11, 2009)

    The Trend Micro Content Security team discovered a phishing attack that used a software company’s website to lure victims into divulging personal information. The compromised site was that of School Website Solutions, which looks like this:Figure 1. Clean

  • Phishing Attacks on Indian Banks on the Rise (August 5, 2010)

    July 2010 was the month for phishing attacks on Indian banks. A three percent increase in phishing attacks on Indian banks from the previous month has been observed. In particular, Symantec has observed phishing websites that spoofed the Oriental Bank

  • Phishing Prepaid Debit Card Accounts (May 17, 2010)

    For the past month or so Symantec has been observing phishing websites that are spoofing a leading brand that provides prepaid debit card services to U.S. citizens. Legitimate prepaid debit cards help people to make purchases, pay bills, shop online,

  • Phishing Courier Service Brands (August 16, 2010)

    Symantec has recently observed phishing websites spoofing courier service brands. There were primarily three brands targeted and fraudsters were attempting to steal customers’ login credentials. So what’s in the login credentials of courier service brands that fraudsters can take advantage of?

  • Phishing Scam Targets Italian Bank (May 25, 2010)

    Italian bank Banca Popolare di Sondrio has become phishers’ new target with the discovery of a spammed message containing a link to the supposed bank’s Internet banking site, SCRIGNO.As

Phishing Pages Pose as Secure Login Pages

TrendLabs recently spotted a new phishing site spoofing CenturyLink’s secure login page from one of its anti-phishing resources.

CenturyLink, created by the merger of CenturyTel and Embarq on July 1, 2009, is a leading provider of high-quality voice, broadband, and video services through its advanced communication networks to consumers and businesses in 33 states in the United States. It is the currently the fourth largest local exchange telephone company in the United States in terms of access lines. It has more than 7 million access lines in service and more than 2 million high-speed Internet connections as well as its own 100 percent digital network, Centrex, ISDN, and advanced intelligent network.

Even though CyberLink’s real secure login page looks very similar to the spoofed one, there are still at least three major differences. First, the URL of the real login page is https://secure.centurylink.net/login.php begins with one of the first marks of a secure login page (https), followed by the company name, unlike the spoofed one, http://www.{BLOCKED}gsoo.com/g4/data/file/news/CenturyLink.net.html, which begins with http, followed by a suspicious-looking domain name before the company’s own name.

Next, a secure login page always has a padlock icon on the lower-right portion of the page while the fake page only has an exclamation

Continue reading...


Write a Comment

Copyright © 2010 The Security Blog. All rights reserved.