Blog Phishing

On July 17, 2009, in Blog Spam, by catalin

Imagine what would happen if you would receive the following email from your blog:

A new comment on the post #123 “Post Name Title” is waiting for your approval

http://blog.yourdomain.com/?p=123

Author : ZuperJohn (IP: 1.2.3.4 , 1.2.3.4)
E-mail : random_email@gmail.com
URL : http://www.google.com
Whois : whatever
Comment:
random interesting text here
random interesting text here
random interesting text here
random interesting text here
random interesting text here

Approve it: http://blog.yourdomain.com/wp-admin/comment.php?blablabla
Delete it: http://blog.yourdomain.com/wp-admin/comment.php?blablabla
Spam it: http://blog.yourdomain.com/wp-admin/comment.php?blablabla

Currently 2 comments are waiting for approval. Please visit the moderation panel:

http://blog.yourdomain.com/wp-admin/moderation.php

And the URLs would point to a fake log-in page (similar to the one your blog uses).
[of course, after you log-in, you will automatically be redirected to your own blog]

Would this be blog phishing?
Would it actually work?

For all you bloggers out there, beware on what you click!!!!! :)

Tagged with: