<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: New Facebook Phishing Attempts</title>
	<atom:link href="http://www.snipe.net/2009/05/new-facebook-phishing-attempts/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.snipe.net/2009/05/new-facebook-phishing-attempts/</link>
	<description>Bitterness never tasted so sweet</description>
	<lastBuildDate>Thu, 29 Jul 2010 22:45:06 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
	<item>
		<title>By: Chris Jester-Young</title>
		<link>http://www.snipe.net/2009/05/new-facebook-phishing-attempts/comment-page-1/#comment-4674</link>
		<dc:creator>Chris Jester-Young</dc:creator>
		<pubDate>Tue, 26 May 2009 11:25:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.snipe.net/?p=1826#comment-4674</guid>
		<description>I look at the address bar to ensure that websites are what they should appear to be, but! I&#039;ve had one time where I got stung when I belatedly realised that I entered my credit card info to an http address. (It&#039;s a site I frequently use, and usually it&#039;s at their https address, but that one time....) I ended up calling up the bank, etc.

Some sites tell people to actually _type in_ the address if logging in is required. This gets around a &quot;lookalike&quot; attack where someone makes a website called facebοοk.com (or facebοok.com, or faceboοk.com; you get the idea) to phish. This sort of attack exploits IDNs (internationalised domain names), and the fact that the Greek omicron looks in most fonts exactly identical to the Latin letter o.

&lt;abbr&gt;&lt;em&gt;Last blog post: &lt;a href=&quot;http://stackoverflow.com/questions/861257/for-kernel-os-is-c-still-it/861286#861286&quot; rel=&quot;nofollow&quot;&gt;Answer by Chris Jester-Young for For kernel/OS is C still it&lt;/a&gt;&lt;/em&gt;&lt;/abbr&gt;</description>
		<content:encoded><![CDATA[<p>I look at the address bar to ensure that websites are what they should appear to be, but! I&#8217;ve had one time where I got stung when I belatedly realised that I entered my credit card info to an http address. (It&#8217;s a site I frequently use, and usually it&#8217;s at their https address, but that one time&#8230;.) I ended up calling up the bank, etc.</p>
<p>Some sites tell people to actually _type in_ the address if logging in is required. This gets around a &#8220;lookalike&#8221; attack where someone makes a website called facebοοk.com (or facebοok.com, or faceboοk.com; you get the idea) to phish. This sort of attack exploits IDNs (internationalised domain names), and the fact that the Greek omicron looks in most fonts exactly identical to the Latin letter o.</p>
<p><abbr><em>Last blog post: <a href="http://stackoverflow.com/questions/861257/for-kernel-os-is-c-still-it/861286#861286" rel="nofollow">Answer by Chris Jester-Young for For kernel/OS is C still it</a></em></abbr></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: GetWeb</title>
		<link>http://www.snipe.net/2009/05/new-facebook-phishing-attempts/comment-page-1/#comment-4666</link>
		<dc:creator>GetWeb</dc:creator>
		<pubDate>Tue, 26 May 2009 03:28:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.snipe.net/?p=1826#comment-4666</guid>
		<description>[...]      Brought to you by Feedtwitt.info      Visit the  Original Page . GETWEB holds no relation with the website.  . Please see our Privacy [...]</description>
		<content:encoded><![CDATA[<p>[...]      Brought to you by Feedtwitt.info      Visit the  Original Page . GETWEB holds no relation with the website.  . Please see our Privacy [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: snipe</title>
		<link>http://www.snipe.net/2009/05/new-facebook-phishing-attempts/comment-page-1/#comment-4663</link>
		<dc:creator>snipe</dc:creator>
		<pubDate>Mon, 25 May 2009 19:35:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.snipe.net/?p=1826#comment-4663</guid>
		<description>Neil - This is OS-agnostic. Its not installing any software, so Linux users are also vulnerable.</description>
		<content:encoded><![CDATA[<p>Neil &#8211; This is OS-agnostic. Its not installing any software, so Linux users are also vulnerable.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Neil Schneider</title>
		<link>http://www.snipe.net/2009/05/new-facebook-phishing-attempts/comment-page-1/#comment-4662</link>
		<dc:creator>Neil Schneider</dc:creator>
		<pubDate>Mon, 25 May 2009 19:33:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.snipe.net/?p=1826#comment-4662</guid>
		<description>Friends don&#039;t let friends run Windows.</description>
		<content:encoded><![CDATA[<p>Friends don&#8217;t let friends run Windows.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
