Hackers are phishing at Google's Public Service Search page

A researcher has exploited a security hole in Google Public Service Search to create an ingeniously deceptive phishing attack that looks like it's hosted on Google's domain.
http://www.google.com/u...
The fake service, Gmail Plus, which purports to be Gmail + Orkut, doesn't actually capture your user ID and password. Instead, it delivers a "You (could have) gotten served" message when you enter information into the sign-in form.
Eric Farraro discovered the exploit while adding a legitimate Google search box to a Web page at...
» Read the rest of the post
» View all photos



