 |
 |
fake eBay sign-in scam
|
 |
|
 |
|
Mac Elite
Join Date: Jun 2004
Location: College
Status:
Offline
|
|
I got an email today that supposedly came from eBay billing department. That alone is suspicious to me. The "sign in" page it links to is not hosted by eBay... dead give away...
Heres the email:
*
[eBay logo]
Dear eBay customer,
During our regularly scheduled account maintenance and verification procedures, we have detected a slight error in your billing information.
This might be due to either of the following reasons:
1. A recent change in your personal information ( i.e.change of address).
2. Submiting invalid information during the initial sign up process.
3. An inability to accurately verify your selected option of payment due to an internal error within our processors.
Please update and verify your info rmation by clicking the link below:
https://signin.ebay.com/ws/eBayISAPI.dll?SignIn
If your account information is not updated within 48 hours then your ability to sell or bid on eBay will become restricted.
Thank you,
The eBay Billing Deptartment .
[trust-e logo]
(and all that white space is from the original email... I didn't add any of that.)
If you put the fake sign-in in one tab, and the real one in another, and swap back and forth, you ill see that they are very similar. Damn near identical. But the scary thing is that it wont take a fake sign in... Pretty realistic. It even has the little lock icon in the top corner of Safari. I'm afraid to use my real username, so I don't know what it shows on the next page..
The email came from 81.196.162.153 which, according to a quick whois query, is registered to "RIPE Network Coordination Centre" in Amsterdam. but farther down the search is mentions "Romania Data Systems"...
the fake sign-in is hosted on 203.73.53.120, which is in taipei, taiwan.
Pretty shady if you ask me. Romania? Amsterdam? Tiawan? illegal activity... oh yeah.
Just for reference, eBay's IP is 66.135.208.90... and is registered to, get this, EBAY, in San Jose, California! Not Romania.
Just thought I'd warn all you gullible dudes (and dudettes) out there.
|
|
|
| |
|
|
|
 |
|
 |
|
Posting Junkie
Join Date: Jun 2000
Location: Union County, NJ
Status:
Offline
|
|
|
|
|
|
| |
|
|
|
 |
|
 |
|
Addicted to MacNN
Join Date: Mar 2000
Location: London, UK
Status:
Offline
|
|
Uh, there have been phishing scams with eBay and PayPal for years now...
|
|
|
| |
|
|
|
 |
|
 |
|
Addicted to MacNN
Join Date: Jan 2003
Location: Great White North
Status:
Offline
|
|
When you sign in with crap it tries to install a virus
https://203.73.53.120/ also takes you to a chinese web site
|
|
Brian says (9:16 AM): I was looking at houses in Ottawa... I actually have a temptation in me to move
Jeff ******* says (9:19 AM): Eww, Ottawa is gross. It's infested with politicians, and presently, 1 Harper as well.
|
| |
|
|
|
 |
|
 |
|
Posting Junkie
Join Date: Feb 2000
Location: Washington, DC
Status:
Offline
|
|
A good rule of thumb is to never trust email.
If something looks legit, open up a blank web browser (do not click the link in the email), go to the site in question, and try to open your account.
It's always been a good rule for me.
|
|
|
| |
|
|
|
 |
|
 |
|
Addicted to MacNN
Join Date: Jan 2003
Location: Great White North
Status:
Offline
|
|
Originally Posted by mitchell_pgh
A good rule of thumb is to never trust email.
If something looks legit, open up a blank web browser (do not click the link in the email), go to the site in question, and try to open your account.
It's always been a good rule for me.
On PC's thats not always safe either, spyware and viruses can change your host file so that you end up going to the wrong site anyways even if you typed it in correct.
Best rule is to call the company when in question
|
|
Brian says (9:16 AM): I was looking at houses in Ottawa... I actually have a temptation in me to move
Jeff ******* says (9:19 AM): Eww, Ottawa is gross. It's infested with politicians, and presently, 1 Harper as well.
|
| |
|
|
|
 |
|
 |
|
Senior User
Join Date: Mar 2003
Status:
Offline
|
|
I just registered under a fake name and address via proxy server!
Youra Koksukker. 
|
|
To create a universe
You must taste
The forbidden fruit.
|
| |
|
|
|
 |
|
 |
|
Addicted to MacNN
Join Date: Jan 2001
Location: The Sar Chasm
Status:
Offline
|
|
I got one of those the other day, forwarded it to ebay fraud, then went back and logged in as username: U R Busted, password: Hello FBI
The "text" that looked like a link, was actually a gif, so I did a "view source" on the email. you can look for the link and the <a href=> tag to see where it really points you, if you're curious.
|
When a true genius appears in the world you may know him by this sign, that the dunces are all in confederacy against him. -- Jonathan Swift.
|
| |
|
|
|
 |
|
 |
|
Addicted to MacNN
Join Date: Jan 2001
Location: The Sar Chasm
Status:
Offline
|
|
Originally Posted by mitchell_pgh
A good rule of thumb is to never trust email.
If something looks legit, open up a blank web browser (do not click the link in the email), go to the site in question, and try to open your account.
It's always been a good rule for me.
I wouldn't do that. The one I got presented me with an exact replica of the ebay login window, only the hostname was all wrong. After I entered a fake name and password, it then forwarded me to ebay, after nabbing the info. Had I not been looking at the URL, I would never have known. (that, and the fact that a lot of the buttons on the fake login page didn't work at all)
|
When a true genius appears in the world you may know him by this sign, that the dunces are all in confederacy against him. -- Jonathan Swift.
|
| |
|
|
|
 |
|
 |
|
Mac Elite
Join Date: Jan 2005
Status:
Offline
|
|
I think he is saying *don't click the link* type in a new browser ebay.com or whatever and login to your account to see if anything is up...
|
|
|
| |
|
|
|
 |
|
 |
|
Mac Elite
Join Date: Jun 2004
Location: Westside Island
Status:
Offline
|
|
I get these all the time... send them to spoof@ebay.com and they'll shut the site down.
|
|
|
| |
|
|
|
 |
|
 |
|
Professional Poster
Join Date: Jun 2001
Location: Northwest Ohio
Status:
Offline
|
|
Originally Posted by zerostar
I think he is saying *don't click the link* type in a new browser ebay.com or whatever and login to your account to see if anything is up...
And hope and pray that the DNS cache hasn't been poisoned so that www.ebay.com doesn't point to the real eBay.
By the way: "Submiting invalid information?" How do you submite something?
And: "Please update and verify your info rmation."
You'd think that these people would learn to spell properly since most non-gullible people know that those types of spelling errors virtually scream "I'm a phishing scam!!!" 
|
|
|
| |
|
|
|
 |
|
 |
|
Addicted to MacNN
Join Date: Jan 2003
Location: ~/
Status:
Offline
|
|
I get this kind of crap all the time on one of my email accounts. Phishing schemes for eBay, PayPal and services I don't even have, too.
I just simply ignore them.
|
|
|
| |
|
|
|
 |
|
 |
|
Addicted to MacNN
Join Date: Mar 2000
Location: London, UK
Status:
Offline
|
|
Originally Posted by Cadaver
I get this kind of crap all the time on one of my email accounts. Phishing schemes for eBay, PayPal and services I don't even have, too.
I just simply ignore them.
Oh yes, they're always nice. All these banks I supposedly have accounts with.
|
|
|
| |
|
|
|
 |
|
 |
|
Mac Elite
Join Date: Dec 1999
Location: Utah
Status:
Offline
|
|
Did I tell you guys I could save you all a fortune on your mortgage payments? I got this mail the other day.....
|
|
Work: 2008 8x3.2 MacPro, 8800GT, 16GB ram, zillions of HDs. (video editing)
Home: 2008 24" 2.8 iMac, 2TB Int, 4GB ram.
Road: 2009 13" 2.26 Macbook Pro, 8GB ram & 640GB WD blue internal
Retired to BOINC only: My trusty never-gonna-die 12" iBook G4 1.25
|
| |
|
|
|
 |
|
 |
|
Professional Poster
Join Date: Oct 2001
Status:
Offline
|
|
If anyone wants to give this guy a taste of his own medicine, here are some things that you can fsck with:
Code:
21 (File Transfer [Control]) open.
22 (SSH Remote Login Protocol) open.
23 (Telnet) open.
80 (World Wide Web HTTP) open.
106 (3COM-TSMUX) open.
110 (Post Office Protocol - Version 3) open.
111 (SUN Remote Procedure Call) open.
143 (Internet Message Access Protocol) open.
199 (SMUX) open.
443 (HTTP protocol over TLS/SSL) open.
631 (IPP (Internet Printing Protocol)) open.
6000 (X-Windows) open.
It seems he's running some flavor of linux.
Heh... we could even arrange a coordinated DOS attack against him 
(Last edited by itistoday; Apr 16, 2005 at 02:26 PM.
(Reason:grammar))
|
|
|
| |
|
|
|
 |
|
 |
|
Professional Poster
Join Date: Feb 2000
Location: Nashville, TN
Status:
Offline
|
|
I always check with the company in question first... then eBay or PayPal fraud gets an email
|

Don't try to outweird me, I get stranger things than you free with my breakfast cereal.
|
| |
|
|
|
 |
|
 |
|
Professional Poster
Join Date: Jan 2003
Location: Teaneck, NJ
Status:
Offline
|
|
Originally Posted by itistoday
...snip...
Heh... we could even arrange a coordinated DOS attack against him
I'm up for it.
|
|
|
| |
|
|
|
 |
|
 |
|
Mac Elite
Join Date: Apr 2003
Location: Southern, NJ (near Philly YO!)
Status:
Offline
|
|
I always tell my customers that e-bay or your bank would never ask you for your personal info through an e-mal....they already have this info. Unless you change your credit card number and never told them they don't need any further info from you.
|
|
MacBook Pro 15" i7 ~ Snow Leopard ~ iPhone 4 - 16Gb
|
| |
|
|
|
 |
|
 |
|
Baninated
Join Date: Jan 2005
Status:
Offline
|
|
Pretty damn sad that someone thinks this is noteworthy. I must get 30 to 50 emails a week from various phishing scams.
|
|
|
| |
|
|
|
 |
|
 |
|
Mac Elite
Join Date: Mar 2002
Location: Seaford, Virginia
Status:
Offline
|
|
I get these too. I sent a reply to one of these guys saying that if I got another phish email, I would fly to where he lived, kill his wife and kids, his pets, his grandparents, burn his house down, and rip off his head and **** down his neck. I then typed about fifty **** YOU's after that. I have never heard from this person again. 
|
|
|
| |
|
|
|
 |
 |
|
 |
|
|
|
|
|

|
|
 |
Forum Rules
|
 |
 |
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
|
HTML code is Off
|
|
|
|
|
|
 |
 |
 |
 |
|
 |
|