Stephen Withers
Friday, 15 July 2011 10:16
Business IT -
Security
Got a MobileMe account? Watch out for a phishing attack!
Symantec is warning of a phishing attack on MobileMe accounts using a spoofed Public Folder login page as bait.
The phishers are spamming out emails containing a URL for a fake MobileMe Public Folder login page, typically stored on a free web-hosting site. A parameter in the URL customises the page with the username (which was derived from an email address), and the victim is asked for the password.
Whatever password is entered, the malicious page redirects to the actual MobileMe 'invalid password' page.
Symantec's assumption is that the phishers are trying to gain free use of iDisk space, but it could be worse than that. The MobileMe account could be used to send spam, and the contacts list plundered.
Furthermore, some people use their MobileMe account as their Apple ID for using the iTunes Store and the Apple Store, so there is potential for real financial loss.
So be particularly careful about looking at the actual URL associated with any links in emails before you click on them. Symantec understandably suggests the use of Norton Internet Security, which includes phishing protection.