iEntry 10th Anniversary Forum Rules Search
WebProWorld
Register FAQ Calendar Mark Forums Read
Internet Security Discussion Forum This forum is for the discussion of security related issues. If you find a new Phishing scheme, spyware, virus or malicious site - let us know about it. If any of the above found you... here's where you ask for help.

Share Thread: & Tags

Share Thread:

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 05-31-2004, 02:49 AM
mushroom's Avatar
WebProWorld Pro
 
Join Date: Feb 2004
Location: Queen Charlotte B. C. Canada
Posts: 287
mushroom RepRank 0
Default EBAY SPOOF

I recieved an e-mail recently which said eBay Account Suspended header said; From: aw-confirm@eBay.com it had the look and layout of ebay.
The link said /signin.ebay.com BUT went to lmillercc.com/.... Where it tried to install "eBayISPI.dll" on my computer but beening a LINUX machine I was allerted.

On viewing source I found;
Return-path: <apache@ns1.ravenorb.com>
Received: from [12.168.160.130] (helo=ns1.ravenorb.com)
and a java script ..............
<a onmouseover="window.status='http://signin.ebay.com//aw-cgi/eBayISAPI.dll?SignIn&ssPageName=h:h:sin:US';
return true" onmouseout="window.status='http://signin.ebay.com//aw
-cgi/eBayISAPI.dll?SignIn&ssPageName=h:h:sin:US'" href="http://lmillercc.com/images/eBayISAPidlldasSKJE
DFKJSdsalkepoamncjfdsjKKdsjdxcmnzkjsjeLKKLKdsjnxs/ksj
deISJJSjjISSdlldkDKJlLXcdcawerfDEurERRudsksalfkmcx XXl
kdmfldll/LKJDjedssjheflkcgieBaysadkKJEDjdfklluseridLK
SKdskdmxskjdeEEdkjas7837sdkjd/eBaylSAPl.dll"
&gt;<FONT face="Courier New"
size="2">http://signin.ebay.com//aw-
cgi/eBayISAPI.dll?
SignIn&ssPageName=h:h:sin:US</a><font face="Courier New" size="2">...............

I have conacted ebay and my local ISP with full source of the e-mail and am now telling the rest of the world.
__________________
Irony: That for most people the most "trusted" web site on the planet is for a company the has been convicted of criminal activity.

Both Security and SuSe start with "S". www.oldslides.com
Reply With Quote
  #2 (permalink)  
Old 06-03-2004, 12:05 PM
WebProWorld 1,000+ Club
 
Join Date: Aug 2003
Location: Edmonton, AB, Canada
Posts: 1,527
mikmik RepRank 2mikmik RepRank 2
Default

Look what I just came across.
Quote:
What is SpoofStick?
SpoofStick is a simple browser extension that helps users detect spoofed (fake) websites. A spoofed website is typically made to look like a well known, branded site (like ebay.com or citibank.com) with a slightly different or confusing URL. The attacker then tries to trick people into going to the spoofed site by sending out fake email messages or posting links in public places - hoping that some percentage of users won't notice the incorrect URL and give away important information. This practice is sometimes known as “phishing"
Available here: Browse freely ...
For IE and Firefox
Look at the example used!
Quote:
Spoofstick will say: "You're on ebay.com".

If you get fooled by going to a spoofed site, for example ht//tp://**signin.ebay.com@10.19.32.4/ (a "spoof" example used by ebay in their customer outreach),

Spoofstick will say: "You're on 10.19.32.4"
[I altered the 'url' with extra "//" and "**" - mikmik]

Thanks for keeping people informed, mushroom..
You do good work ;]
Reply With Quote
  #3 (permalink)  
Old 06-03-2004, 01:00 PM
mushroom's Avatar
WebProWorld Pro
 
Join Date: Feb 2004
Location: Queen Charlotte B. C. Canada
Posts: 287
mushroom RepRank 0
Default

Update
After making original post did some more digging.

Found that lmillercc.com apperered to be legit and perhaps innocent.

Sent email to abuse@lmillercc.com with full source of e-mail.

Site is now unavailable.

Hope I helped to put some one in jail
__________________
Irony: That for most people the most "trusted" web site on the planet is for a company the has been convicted of criminal activity.

Both Security and SuSe start with "S". www.oldslides.com
Reply With Quote
  #4 (permalink)  
Old 06-03-2004, 03:46 PM
wenwilder's Avatar
WebProWorld Veteran
WebProWorld MVP
 
Join Date: Jul 2003
Location: Nebraska US
Posts: 942
wenwilder RepRank 3wenwilder RepRank 3wenwilder RepRank 3
Default

There are multiple links, hints, and tips being collected and offered in this thread: http://www.webproworld.com/viewtopic.php?t=19009

There is a lot of good information and fantastic links!

And mik, weren't you going to add some more links to the list? *hint, hint* ;)
__________________
Forum Rules
"Cat washing IS a martial art."
"Remember Today IS Yesterdays Tomorrow"
Reply With Quote
  #5 (permalink)  
Old 06-03-2004, 08:25 PM
WebProWorld 1,000+ Club
 
Join Date: Aug 2003
Location: Edmonton, AB, Canada
Posts: 1,527
mikmik RepRank 2mikmik RepRank 2
Default

My new favorite security site, it has all OS's covered, easy to use, and a really nice navbar to boot LOL
http://www.securityfocus.com/

But, I get your drift, methinks ;-]
Reply With Quote
Reply

  WebProWorld > Webmaster, IT and Security Discussion > Internet Security Discussion Forum

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -4. The time now is 10:40 PM.



Search Engine Optimization by vBSEO 3.3.0