(July 19, 2011 at 4:23 am)FaithNoMore Wrote:Phishing is a very common form of attack, one that even I'll admit to being fooled by before. They are often very clever, exploiting numerous browser vulnerabilities, and are quite hard to detect by most users. The key to remember is to never enter your password into a site that you clicked through to get to. In other words, always type the URL or save it as a bookmark in your browser.(July 19, 2011 at 3:19 am)fr0d0 Wrote: I work in IT, and I was duped into entering my hotmail password into a web form. Luckily I quickly realised and changed my passwords quickly. I wasn't affected. Part of a good password regime is to change your passwords regularly.
You're in IT and gave away your password? Maybe a new job is in order.
Also, if you aren't logging in, or requesting a password reset, then there is (usually) no need to enter or confirm your password.