WebProWorld Part of WebProNews.com
Page One Link To Us Edit Profile Private Messages Archives FAQ RSS Feeds  
 

Go Back   WebProWorld > Webmaster, IT and Security Discussion > Internet Security Discussion Forum
Subscribe to the Newsletter FREE!


Register FAQ Members List Calendar Arcade Chatbox Mark Forums Read

Internet Security Discussion Forum This forum is for the discussion of security related issues. If you find a new Phishing scheme, spyware, virus or malicious site - let us know about it. If any of the above found you... here's where you ask for help.

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 05-31-2004, 01:49 AM
mushroom's Avatar
mushroom mushroom is offline
WebProWorld Veteran
 

Join Date: Feb 2004
Location: Queen Charlotte B. C. Canada
Posts: 351
mushroom RepRank 0
Default EBAY SPOOF

I recieved an e-mail recently which said eBay Account Suspended header said; From: aw-confirm@eBay.com it had the look and layout of ebay.
The link said /signin.ebay.com BUT went to lmillercc.com/.... Where it tried to install "eBayISPI.dll" on my computer but beening a LINUX machine I was allerted.

On viewing source I found;
Return-path: <apache@ns1.ravenorb.com>
Received: from [12.168.160.130] (helo=ns1.ravenorb.com)
and a java script ..............
<a onmouseover="window.status='http://signin.ebay.com//aw-cgi/eBayISAPI.dll?SignIn&ssPageName=h:h:sin:US';
return true" onmouseout="window.status='http://signin.ebay.com//aw
-cgi/eBayISAPI.dll?SignIn&ssPageName=h:h:sin:US'" href="http://lmillercc.com/images/eBayISAPidlldasSKJE
DFKJSdsalkepoamncjfdsjKKdsjdxcmnzkjsjeLKKLKdsjnxs/ksj
deISJJSjjISSdlldkDKJlLXcdcawerfDEurERRudsksalfkmcx XXl
kdmfldll/LKJDjedssjheflkcgieBaysadkKJEDjdfklluseridLK
SKdskdmxskjdeEEdkjas7837sdkjd/eBaylSAPl.dll"
&gt;<FONT face="Courier New"
size="2">http://signin.ebay.com//aw-
cgi/eBayISAPI.dll?
SignIn&ssPageName=h:h:sin:US</a><font face="Courier New" size="2">...............

I have conacted ebay and my local ISP with full source of the e-mail and am now telling the rest of the world.
__________________
Irony: That for most people the most "trusted" web site on the planet is for a company the has been convicted of criminal activity.

Both Security and SuSe start with "S". www.oldslides.com
Reply With Quote
  #2 (permalink)  
Old 06-03-2004, 11:05 AM
mikmik's Avatar
mikmik mikmik is offline
WebProWorld 1,000+ Club
 

Join Date: Aug 2003
Location: Edmonton, AB, Canada
Posts: 3,406
mikmik RepRank 1
Default

Look what I just came across.
Quote:
What is SpoofStick?
SpoofStick is a simple browser extension that helps users detect spoofed (fake) websites. A spoofed website is typically made to look like a well known, branded site (like ebay.com or citibank.com) with a slightly different or confusing URL. The attacker then tries to trick people into going to the spoofed site by sending out fake email messages or posting links in public places - hoping that some percentage of users won't notice the incorrect URL and give away important information. This practice is sometimes known as “phishing"
Available here: Browse freely ...
For IE and Firefox
Look at the example used!
Quote:
Spoofstick will say: "You're on ebay.com".

If you get fooled by going to a spoofed site, for example ht//tp://**signin.ebay.com@10.19.32.4/ (a "spoof" example used by ebay in their customer outreach),

Spoofstick will say: "You're on 10.19.32.4"
[I altered the 'url' with extra "//" and "**" - mikmik]

Thanks for keeping people informed, mushroom..
You do good work ;]
__________________
What I am is what I am, are you what you are, or what.
Eddie Brickel
Reply With Quote
  #3 (permalink)  
Old 06-03-2004, 12:00 PM
mushroom's Avatar
mushroom mushroom is offline
WebProWorld Veteran
 

Join Date: Feb 2004
Location: Queen Charlotte B. C. Canada
Posts: 351
mushroom RepRank 0
Default

Update
After making original post did some more digging.

Found that lmillercc.com apperered to be legit and perhaps innocent.

Sent email to abuse@lmillercc.com with full source of e-mail.

Site is now unavailable.

Hope I helped to put some one in jail
__________________
Irony: That for most people the most "trusted" web site on the planet is for a company the has been convicted of criminal activity.

Both Security and SuSe start with "S". www.oldslides.com
Reply With Quote
  #4 (permalink)  
Old 06-03-2004, 02:46 PM
wenwilder's Avatar
wenwilder wenwilder is offline
WebProWorld 1,000+ Club
 

Join Date: Jul 2003
Location: Nebraska US
Posts: 2,172
wenwilder RepRank 2wenwilder RepRank 2
Default

There are multiple links, hints, and tips being collected and offered in this thread: http://www.webproworld.com/viewtopic.php?t=19009

There is a lot of good information and fantastic links!

And mik, weren't you going to add some more links to the list? *hint, hint* ;)
__________________
Forum Rules
"Cat washing IS a martial art."
"Remember Today IS Yesterdays Tomorrow"
Reply With Quote
  #5 (permalink)  
Old 06-03-2004, 07:25 PM
mikmik's Avatar
mikmik mikmik is offline
WebProWorld 1,000+ Club
 

Join Date: Aug 2003
Location: Edmonton, AB, Canada
Posts: 3,406
mikmik RepRank 1
Default

My new favorite security site, it has all OS's covered, easy to use, and a really nice navbar to boot LOL
http://www.securityfocus.com/

But, I get your drift, methinks ;-]
__________________
What I am is what I am, are you what you are, or what.
Eddie Brickel
Reply With Quote
Reply

  WebProWorld > Webmaster, IT and Security Discussion > Internet Security Discussion Forum
Tags: ebay, spoof



Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



Search Engine Friendly URLs by vBSEO 3.0.0