I’ve been had
Oh my god. I’m so stupid.
I got an email from Gmail@gmail.com
and I clicked a link that looked like a plain text URL that Gmail had turned into a link. It took me to the Gmail sign-in page (complete with ticking-over free space counter). It was only after I’d signed in that I looked at the addressbar. redscream.com != google.com. So I ran back to Gmail and changed my password as fast as I could.
Bloody hell. That’s the first time I’ve been caught out by phishing mail. I feel so stupid.
Here’s what I told Google:
I got a phishing mail from “Gmail@gmail.com” today. I’m ashamed to say I fell for it because I didn’t look at the address bar until it was too late (but I changed my password immediately so it’s okay).
It contained a link that had a Gmail URL in the content but a different URL in the href (it looked like it was a plaintext URL that Gmail had turned into a link). I suggest that you highlight such links to help people recognise phishing attempts.
I might see if I can write a Greasemonkey script to do the same thing in the meantime.
December 17th, 2005 at 16:50 EST
see your first mistake was opening anything from gmail@gmail.com….