Welcome to the MacNN Forums.

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

You are here: MacNN Forums > Community > MacNN Lounge > Doh! Got suckered by phishing email...

Doh! Got suckered by phishing email...
Thread Tools
Dedicated MacNNer
Join Date: Apr 2001
Status: Offline
Reply With Quote
Jan 10, 2007, 08:49 PM
 
Being the savvy computer user I supposedly am, I looked at the email header first when I got a "Paypal account notice" email.

Return-Path: <aw-confirm@ebay.com>
X-Flags: 1001
Received: (qmail invoked by alias); 11 Jan 2007 01:51:09 -0000
Received: from pconnect.infinityhost.com (HELO ebay.com) [66.242.24.128]
by mx0.gmx.net (mx086) with SMTP; 11 Jan 2007 02:51:09 +0100
Received: (qmail 10401 invoked by alias); 11 Jan 2007 01:32:12 -0000
Date: 11 Jan 2007 01:32:12 -0000
Message-ID: <20070111013212.10368.qmail@ebay.com>
From: "service@paypal.com" <service@paypal.com>
To:
Content-Type: text/html;

Somehow, I couldn't determine the authenticity of the email, so I clicked on the the Paypal login link in the text below.

" We recently received a report of unauthorized credit card use associated with this account. As a precaution, we have limited access to your PayPal account in order to protect against future unauthorized transactions.

Case ID Number: PP-711-611-856

In accordance with PayPal's User Agreement, your account access will remain limited until the issue has been resolved. Unfortunately, if access to your account remains limited for an extended period of time, it may result in further limitations or eventual account closure. We encourage you to follow our verification procedure as soon as possible to help avoid this.

Click here to login and restore your account access"

These bastards are obviously banking on people using a very short URL field bar.
[url]www.paypal.com.711611.20inyw.com/Welcome/cmd-confirm/login.php?login&login_email=xxx@xxx.com&re f=pp_n_jan10
Do NOT click on the phishing URL above!

I saw the full address, but still managed to type in my Paypal password and click Submit, before the little lightbulb came on in my head.
(Last edited by legionare; Jan 10, 2007 at 09:04 PM. (Reason:how do I turn off auto-URL linking?))
     
zro
Mac Elite
Join Date: Nov 2003
Location: The back of the room
Status: Offline
Reply With Quote
Jan 10, 2007, 08:53 PM
 
Why the **** are you posting that link?
     
Moderator Emeritus
Join Date: Apr 2001
Location: Fort Lauderdale, FL
Status: Offline
Reply With Quote
Jan 10, 2007, 08:53 PM
 
I got a paypal email just like that the other day, I reported it. Looked pretty nice tho
ice
     
Mac Elite
Join Date: Nov 2005
Location: Seattle, WA, USA
Status: Offline
Reply With Quote
Jan 10, 2007, 08:58 PM
 
Wow, that's a pretty convincing one. The links on the page even point to the real Paypal site.

Any ramblings are entirely my own, and do not represent those of my employers, coworkers, friends, or species
     
Professional Poster
Join Date: Aug 2006
Location: The decaying ruins of Old New York
Status: Offline
Reply With Quote
Jan 10, 2007, 09:05 PM
 
Originally Posted by legionare View Post
I saw the full address, but still managed to type in my Paypal password and click Submit, before the little lightbulb came on in my head.
I am assuming here that you IMMEDIATELY reported to PayPal that your account was compromised?
For all the trash I talk, I sure own a lot of Macs...
Clamshell iBook Mod Community
     
Dedicated MacNNer
Join Date: Apr 2001
Status: Offline
Reply With Quote
Jan 10, 2007, 09:07 PM
 
I logged into paypal with the compromised password and changed it It should be good enough, no?
     
Professional Poster
Join Date: Mar 2002
Location: Smallish town in Ohio
Status: Offline
Reply With Quote
Jan 10, 2007, 09:12 PM
 
Originally Posted by legionare View Post
I logged into paypal with the compromised password and changed it It should be good enough, no?
That's what I did for my mom who was suckered into a phishing email. I told her to change the password right away and it has worked so far.
     
Mac Elite
Join Date: Feb 2006
Location: Manhattan, NY
Status: Offline
Reply With Quote
Jan 10, 2007, 09:34 PM
 
Just to be safe, I would actually close your paypal account and open a new one--but I'm paranoid. I've been getting those phishing emails myself. I got a similar bank of america notice and followed the link. All the links off the phishing page connected to the real boa site. Since I didn't have a boa account, I knew it was fake.
     
Addicted to MacNN
Join Date: Sep 2001
Location: Toronto
Status: Offline
Reply With Quote
Jan 10, 2007, 09:36 PM
 
At this day and age, how can anybody still fall for one of these? Seriously.
     
Dedicated MacNNer
Join Date: Apr 2001
Status: Offline
Reply With Quote
Jan 10, 2007, 09:45 PM
 
Hey! I am an email header reading computer geek! I had managed to remain unblemished by this infamy for years, until today!
     
Moderator Emeritus
Join Date: Apr 2001
Location: Fort Lauderdale, FL
Status: Offline
Reply With Quote
Jan 10, 2007, 10:10 PM
 
Funny, I didn't even read the header information. I just knew my account was in good shape. Fired up Safari, followed my own link to paypal, and yep: all was good, no real notices from paypal.
ice
     
Mac Elite
Join Date: Apr 2005
Location: Nashville, TN
Status: Offline
Reply With Quote
Jan 10, 2007, 10:19 PM
 
call paypal, they will lock your account down and send you a snail mail form with new password i did the same thing earlier this year
"I'm sick of following my dreams. I'm just going to ask them where they're goin', and hook up with them later"
     
Mac Elite
Join Date: May 2002
Status: Offline
Reply With Quote
Jan 11, 2007, 12:06 AM
 
Originally Posted by IceEnclosure View Post
Funny, I didn't even read the header information. I just knew my account was in good shape. Fired up Safari, followed my own link to paypal, and yep: all was good, no real notices from paypal.
That is what I did too. I just typed in the URL and checked out my account without clicking through the email. Solves all the problems.
...
     
Senior User
Join Date: Sep 2003
Status: Offline
Reply With Quote
Jan 11, 2007, 12:12 AM
 
I get an e-mail like that every few days.

PayPal recommends you never click a link to their site in an e-mail. Always type it in your browser so you know its the real site.
     
Dedicated MacNNer
Join Date: Aug 2005
Location: Beaumont Texas
Status: Offline
Reply With Quote
Jan 11, 2007, 12:44 AM
 
I get these emails too, but I dont have an e-bay or paypal account. So I just delete them.
32GB iPad 2 | 32GB iPhone 4 | 11' MacBook Air 1.6 i5, 4GB, 128GB SSD
     
Senior User
Join Date: Nov 2003
Status: Offline
Reply With Quote
Jan 12, 2007, 06:07 PM
 
time for a bigger computer screen.
     
Clinically Insane
Join Date: Jun 2001
Location: planning a comeback !
Status: Offline
Reply With Quote
Jan 13, 2007, 12:54 AM
 
I don't get these mails. SpamAssassin takes care of them all.

-t
     
Dedicated MacNNer
Join Date: Nov 2006
Location: Circa 1225, from the Old French
Status: Offline
Reply With Quote
Jan 13, 2007, 01:56 AM
 
I never click links in emails for logging in to sites.

Always use a known good bookmark or carefully-typed url.
     
   
Thread Tools
Forum Links
Forum Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Top
Privacy Policy
All times are GMT -5. The time now is 11:51 AM.
All contents of these forums © 1995-2011 MacNN. All rights reserved.
Branding + Design: www.gesamtbild.com
vBulletin v.3.8.7 © 2000-2011, Jelsoft Enterprises Ltd., Content Relevant URLs by vBSEO 3.3.2