Home  >  Community  >  The eBay Outlook  >  phishy phishy


<< previous topic post new topic post reply next topic >>
 glassgrl
 
posted on April 24, 2006 05:00:09 PM new
some of this is for my own reference - I just want to make sure everyone sees it.

http://www.phishfighting.com/ Fight back and take down the Phishers

Phishers rely on the naivety of people to fall for their fake Paypal, eBay and banking websites. We can make the phisher's life miserable by submitting 100's or 1000's of realistic looking, but fake, entries. To make it easier I've automated the process. You can fight back right now by entering the actual destination URL from the phishing email. Then watch as realistic looking, fake, entries are automatically and continuously submitted to the phisher’s website. The criminal won't be able to distinguish between the ”Fake" entries and entries from real people who fall for the scam.

The Phisher's process
Phishers are criminals so their goal is to steal your personal information and then your money. Phishing really has two levels. The first level is the Phisher himself, who's goal is to aquire personal data. He then sells the data to a "Casher" who is setup to use the data for identity theft, printing credit cards or just stealing your money.

The Phishers first step is to setup a fake website that looks like the real website, Paypal® is very common. Then they send out millions of emails with subjects like "Account Suspended" or "Activate Your PayPal Account!". The emails can look very official, see samples below . The emails will contain a link that looks real, saying something like "Click here to Update your account". The link does not go to Paypal, rather it goes to a fake site. Often the URLs are IP address like "http://123.45.67.8/PaypalVerify" or some look more realistic like "http://www.paypal-account-verify.net". The sites look like the Paypal login page. Unwary victims will enter their login and password, click submit, and unknowingly wave goodbye to any money they have in the account. The Phisher or "Casher" could even use the "Add Funds" functions in paypal to draw money out of your credit cards and/or checking account. The fake site may reply with “Login failed please retry” or they will have a sub-page asking for "verification" information like your credit card number, password and pin. This information can then be sold to the "Casher". Losses can extend well beyond the funds in your Paypal account.

Best advice is to always type the url into the browser yourself, never rely on the link in an email.

*******************************************
Here was a fake Ebay notice email -



there is a clickable link in the email. It is the auction number and it takes you to a fake sign in page.

the auction number clickable link redirects you to:

http://hometown.aol.com/ketanketanketan/index.html

fake page it takes you to:

http://davidautos.netfirms.com/W0QQfromZR4QQsacatZ37974QQsocmdZListingItemListQQssPageNameZdcpAntiquesTextNonFeat/default.htm

real Ebay page:

https://signin.ebay.com/ws/eBayISAPI.dll?
SignIn&co_partnerId=2&pUserId=&siteid=0&pageT
ype=&pa1=&i1=&bshowgif=&UsingSSL=&ru=&pp=&pa2=&errmsg=&runame=&ruparams=&ruproduct=&sid=&favoritenav=&confirm=&ebxPageType=&existingEmail=&isheckout=&migrateVisitor=

********************************

how it was done.

first you need the original email.

forget the headers. all you have to do is open the email - in Outlook you right click and view source. I don't know how you do it if you have AOL etc.

then you see what it says. this one looked like this:

<HTML><HEAD>
<META content="MSHTML 6.00.2900.2180" name=GENERATOR></HEAD>
<BODY bgColor=#ffffff>
<TABLE cellSpacing=0 cellPadding=0 width=600 border=0>
<TBODY>
<TR>
<TD vAlign=top width=600>
<P><FONT size=2><FONT face=Verdana><FONT size=1><FONT color=#666666><B>eBay sent this message to ([email protected]).<BR></B>Your registered email address is included to show this message originated from eBay.</FONT></FONT>
<HR color=#d2d3d2 noShade>

<P></P>
<P></FONT></FONT><FONT size=2><FONT face=Verdana>Dear eBay Member,<BR><BR>The bid that has been entered in error for the item
( </FONT><A href="http://hometown.aol.com/ketanketanketan/index.html"><U><FONT face=Verdana>7610115840</FONT></U></A><FONT face=Verdana> )
has been cancelled.<BR><BR>Regards, <BR>eBay <BR>&nbsp;</FONT></FONT></P></TD></TR>
<TR>
<TD>
<TABLE cellSpacing=0 cellPadding=0>
<TBODY>
<TR>
<TD><FONT face=Verdana>
<HR color=#d2d3d2 noShade>
<FONT size=1><FONT color=#666666>This eBay notice was sent to </FONT><FONT color=#ff0000>[email protected]</FONT></FONT><FONT size=2> </FONT><FONT color=#666666 size=1>from eBay based on your account preferences. Your account is registered on </FONT></FONT><A href="http://www.ebay.com"><U><FONT face=Verdana color=#800080 size=1>www.ebay.com</FONT></U></A><FONT face=Verdana color=#666666 size=1>
. As outlined in our User Agreement, eBay will periodically send you information about site changes and enhancements. To unsubscribe from this notice, change your </FONT><A href="http://cgi4.ebay.com/ws/eBayISAPI.dll?OptinLoginShow"><U><FONT face=Verdana size=1>notification preferences</FONT></U></A><FONT face=Verdana color=#666666 size=1>. Please note that it may take up to 10 days to process your request. If you would like to receive this email in text format, change your </FONT>
<A href="http://cgi4.ebay.com/ws/eBayISAPI.dll?OptinLoginShow"><U><FONT face=Verdana size=1>notification preferences</FONT></U></A><FONT face=Verdana color=#666666 size=1>.</FONT> </TD></TR>
<TR><FONT face=Verdana></FONT></TR>
<TR>
<TD>
<P align=center><FONT face=Verdana><FONT color=#666666 size=2>Copyright © 2006 eBay Inc. All Rights Reserved. <BR>Designated trademarks and brands are the property of their respective owners.<BR>eBay and the eBay logo are trademarks of eBay Inc.</FONT> </FONT></P></TD></TR></TBODY></TABLE></TD></TR></TBODY></TABLE></BODY></HTML>

the bold shows where the clickable links "go to".

anybody can do this with any suspected phising email they receive. all you look for is where it says http:// and that tells you where the link goes.

Fake ebay log in page:



Real ebay log in page:



***********************************

(and NetFirms responded today and took down the website.)

http://davidautos.netfirms.com/W0QQfromZR4QQsacatZ37974QQsocmdZListingItemListQQssPageNameZdcpAntiquesTextNonFeat/

POOF!

Hello,

Thank-you for your e-mail enquiry.

Please be advised that we have disabled this site.

Netfirms provides legitimate web hosting services and has a ZERO tolerance policy towards these violations.

We apologize for the inconvenience this has caused you.

Regards,

Todd
Netfirms Inc.
www.netfirms.com


[ edited by glassgrl on Apr 24, 2006 06:03 PM ]
 
 sthoemke
 
posted on April 24, 2006 05:23:31 PM new
Keep in mind that the URL in the address bar can be faked with java script.

Even though it might read "https://signin.ebay.com", you could still be at a spoof webpage.

 
 yourbigstore
 
posted on April 24, 2006 06:54:57 PM new
Do they ever catch these ppl and throw them in jail? Im glad someone is making thier life a pain in the a$$

 
 irked
 
posted on April 24, 2006 08:26:13 PM new
I was tempted just once to go fill in a lot of bogus information but thought better of it. I did turn in one to the webmaster or what ever they are called at a hosting site. It too was taken down and I also got an appology kinda like the one here. I just don't have the tiem these phishers do in foiling their attempts. I do forward all phishing emails I get to PP or Ebay.

Lately I have been getting a lot of the same scams from someone trying to represent banks. Same applies to those never click a link in their emails.


**************

Some minds are like concrete,
thoroughly mixed up and permanently set.
 
 glassgrl
 
posted on April 25, 2006 05:51:46 AM new
nobody went and looked at the phishfighting.com website???? did you not read what they do????

"How many phishing emails did you receive today?: I receive 5-10 emails a day that are supposedly from real companies like Paypal® asking me to click their link and enter my login, password or other private information. These are fake sites created by criminals. I'm tired of the emails and offended by the fact that they are trying to steal from me. So I've decided to strike back and YOU CAN TOO.

Just enter the Phishing emails REAL url above and watch as realistic looking, fake, entries are continously sent to the Phishers fake site. The criminal will receive hundreds or thousands of fake entries and he won't be able to tell which are fake and which are real."


"How PhishFighting works

Q: Is sending false data to Phishers considered a DOS attack?

A: According to wikipedia: "A denial-of-service attack (also, DoS attack) is an attack on a computer system or network that causes ... the loss of network connectivity and services by consuming the bandwidth of the victim network or overloading the computational resources of the victim system." PhishFighting.com only submits data entries once every 20 seconds, which only works out to 180 calls an hour. Far short of the many 1000's of calls needed to create a DOS attack. It's not our goal to consume the Phisher's bandwidth, rather it is to provide so much data that the Phisher can not benefit for stolen valid data. Basically adding his needles to a haystack."

They tell you different ways to determine the "real" url.

http://www.phishfighting.com/Find_URL.aspx?anti_spyware

"There are several ways to determine the real url hidden in the email.
In Firefox: Right click on the link and select "Copy link location". Then paste (Ctrl+V) the link into the PhishFighting.com URL box on the home page.
In IE: Right click on the link and select "Copy shortcut". Then paste (Ctrl+V) the link into the PhishFighting.com URL box on the home page.
Click the link and copy the URL. (Caution: Hazardous)
View the source html of the email and locate the hidden link. (Safe method)
Hover over the link and read/copy it from the "tooltip" or the bottom of the browser window. (Safe method)"



 
 glassgrl
 
posted on April 25, 2006 06:06:25 AM new
it's pretty cool. after you enter the url it opens that webpage with false id in it and you have to click the submit button and try and log in. you have to keep doing it when the allowed 20 seconds elapse but hey if you're bored give it a whirl.



 
 
<< previous topic post new topic post reply next topic >>

Jump to

All content © 1998-2026  Vendio all rights reserved. Vendio Services, Inc.™, Simply Powerful eCommerce, Smart Services for Smart Sellers, Buy Anywhere. Sell Anywhere. Start Here.™ and The Complete Auction Management Solution™ are trademarks of Vendio. Auction slogans and artwork are copyrights © of their respective owners. Vendio accepts no liability for the views or information presented here.

The Vendio free online store builder is easy to use and includes a free shopping cart to help you can get started in minutes!