Closed Thread
Results 1 to 5 of 5

Thread: HEADS UP - Latest scam - cPanel Phishing

Hybrid View

  1. #1
    Join Date
    Apr 2008
    Location
    Chasing the Holy Grail - Pacific Northwest
    Posts
    670

    Exclamation HEADS UP - Latest scam - cPanel Phishing

    I just ran across this article. I'll post part of it and leave the rest for you to read.

    Webmasters targeted in cPanel look-alike phish

    "Due to the system maintenance, we kindly ask you to take a few minutes to confirm your FTP details," the emails state.

    The emails are sent to customers of some of the world's most widely used webhosts, including GoDaddy, Hostgator, Yahoo!, and 50Webs. Although the subject lines vary, they all purport to come from the hosting service. In all, admins from at least 90 different webhosts are being targeted.

    Those who take the bait are led to a website formatted to look like a page from cPanel, the widely used website administration program. Once a website's address and FTP credentials are entered, users are directed to their host's login page.
    Article Link Here

    The bottom line here is to think twice and act cautiously. This is somewhat is line with banking scams. If you receive anything like this, and are in doubt, either post the question here in this thread, or contact your ISP - who is hopefully Bluehost - directly.

    Also, it is extremely good practice to only access your cPanel or your FTP site using secure methods (SFTP, SSH, HTTPS, etc). It's easy to build a bookmark to your cPanel using https, and use that for connecting rather than plain http which can be intercepted and read in plain text. If you use the secure encrypted connection method, the hackers will just move on to an easier target.

    You can create this shortcut from cPanel itself, or use the following format using the correct box number.
    You'll find the cPanel method up at the top under Preferences | Shortcuts.

    https://box999.bluehost.com:2083/
    Last edited by felgall; 01-02-2010 at 09:37 PM. Reason: fixed the example so it doesn't create an invalid link
    aka Barry
    In the Hyperion universe, a farcaster is an instantaneous transportation device.

    Murphy's Law - "Anything that can go wrong, will go wrong" (and at the most inopportune time)

  2. #2
    Join Date
    Apr 2008
    Posts
    407

    Default

    Just thought I'd add that in order to use SFTP or SSH you'll need to send in a copy of a government ID to Bluehost if you don't already have it enabled (this has been standard policy for a while now).

  3. #3

    Default plishing

    Yes, I got one - just looked fishy so I didn't do anything. Here it is:

    Dear Customer,


    During our regularly scheduled account maintenance and verification procedures, we have detected a slight error in your account information.

    Please update and verify your information by clicking the link below:

    http://www.bluehost.com/

    If your account information is not updated within 72 hours then your ability to access your account will become restricted.

    © 2003-2009 BlueHost.Com. All Rights Reserved

    Designated trademarks and brands are the property of their respective owners.

  4. #4
    Join Date
    Apr 2008
    Location
    Chasing the Holy Grail - Pacific Northwest
    Posts
    670

    Default

    This doesn't appear to be the same as the phishing that was mentioned in the article. If the link really does point to Bluehost, or it appears that it does, then place a call to them and ask about the request.

    One way to verify a link is to right-click and copy it, then paste it into your favorite text editor. You should be able to see immediately if it's a phony one or not.
    aka Barry
    In the Hyperion universe, a farcaster is an instantaneous transportation device.

    Murphy's Law - "Anything that can go wrong, will go wrong" (and at the most inopportune time)

  5. #5
    Join Date
    Sep 2007
    Location
    Lagos, Nigeria
    Posts
    154

    Default

    I receive numerous emails asking me to update one account details or the other. But I don't fall to such baits.

Closed Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts