Don't fall for this common (and old) attempt to steal your password.

You would receive an email, IRC or other message saying something like:

You have received an InstaKiss! Get it here!

...and containing an address to a web page such as this one:

Web page: "To get the InstaKiss that someone has sent to you or to send a InstaKiss to another AOL member, enter your screen name (or account name) --- "

The user name and password you would submit would be mailed to the attacker.

The example above was designed to appear like a service operated by America Online. However, the URI reveals that the page was hosted by a free web space provider. With a little more effort, the URI could have been obfuscated using e.g. frames, numeric IP addresses, and/or redirections.

When sending sensitive information such as passwords over the WWW, it is important to ensure that one is communicating with the correct server, and that only the intended receiver can read the message. In practice, this means using the https scheme - e.g. https://example.com/ - and carefully verifying the server certificate.

www.anta.net and blog.anta.net serve information on inter­net­working, security and safety topics to a global audience. Both sites are partially funded by advertising. Third parties may there­fore offer cookies to your browser; request cookies back; and use web beacons. Google's use of the DART cookie enables Google to serve ads to you based on your visits to this and other web­sites. If you do not wish to use the DART cookie, please opt out on the privacy policy page for Google's ad‑and-content net­work. Additionally, you can usually specify your cookie pre­ferences in your browser settings.

All con­tent © 2000–2009 Thor Kottelin, unless other­wise indicated. Any trade­marks or registered trade­marks mentioned on this site belong to their respective owners. Con­tent and techniques used on this site may be available for licensing; for details, please con­tact the web­master. — Con­ventional hyper­linking to any con­tent on this site is highly wel­comed. How­ever, none of the con­tent on this site may be shown, even partly, in a con­text inferring or claiming it to be part of or sponsored by any other organization or site. Such pro­hibited techniques include (but are not limited to) frame­sets, interstitial pages, kiosk mode pop‑ups, and reverse proxies.

38.103.63.59 (none)
(none) CCBot/1.0 (+http://www.commoncrawl.org/bot.html)
/irt/phish-instakiss.shtml /irt/phish-instakiss.shtml