image
image

Go Back   macosx.com > Community > Bob's Place

Reply
 
Thread Tools
  #1  
Old January 7th, 2004, 12:00 PM
michaelsanford's Avatar
Psycholinguist
 
Join Date: Oct 2002
Location: Ottawa/Montr้al
Posts: 2,172
Thanks: 0
Thanked 0 Times in 0 Posts
michaelsanford is on a distinguished road
One *doozy* of a PayPal scam!

I got an email from service@paypal.com to my Hotmail account and though, hey wait a second, I don't use this account with PayPal.

Then I opened the page, which had an HTML link that was different from the text link (the text link looked valid: ""). It looked kosher until the part about the ATM PIN and the part requesting online banking credentials... :P

Check this out:
http://www.paypal.com-webscr-cmd-acc...ixhosting.net/

I reported it to PayPal/eBay already...
__________________
michaelsanford.com • Blog • Twitter • Tumblr • LinkedIn
• iMac Aluminum 24" |
MacOS X 10.5-current | 3.06 GHz Intel Core Duo | 4 GB RAM | 1 TB HDD
• iBook G4 1.42 GHz | MacOS X 10.5-current | 1 GB RAM, 100 GB HDD
• AMD Athlon64 3500+ | Slackware 12 (2.6.21.5-smp) | 2 GB RAM, 2•120 GB RAID 1, 2•500 GB RAID 0
Reply With Quote
  #2  
Old January 7th, 2004, 01:25 PM
RPS's Avatar
RPS RPS is offline
Apple Guru Wannabe™
 
Join Date: Jul 2002
Location: Amsterdam, The Netherlands.
Posts: 521
Thanks: 0
Thanked 0 Times in 0 Posts
RPS is on a distinguished road
Yeah that happened to my dad also, except he got the email on his correct adress.
__________________
* iMac G4 running 10.3.4

My iChat Screenname:
zxyRobertzxy (aim)

Last edited by bobw; January 7th, 2004 at 05:36 PM.
Reply With Quote
  #3  
Old January 7th, 2004, 05:27 PM
Trip's Avatar
www.TannerSite.com
 
Join Date: Sep 2001
Location: Utah
Posts: 3,266
Thanks: 0
Thanked 0 Times in 0 Posts
Trip is on a distinguished road
Feel free to send donations to stop that scam to the following PayPal account:

Framistan@SpyMac.com

__________________
13" MacBook - 2GHz. 2 GB RAM. OS 10.4.7
12" iBook - 500 MHz. 640 MB RAM. (R.I.P.)
TannerSite.com
Reply With Quote
  #4  
Old January 7th, 2004, 06:18 PM
michaelsanford's Avatar
Psycholinguist
 
Join Date: Oct 2002
Location: Ottawa/Montr้al
Posts: 2,172
Thanks: 0
Thanked 0 Times in 0 Posts
michaelsanford is on a distinguished road
Well, for such a worthy cause sure!

=P
__________________
michaelsanford.com • Blog • Twitter • Tumblr • LinkedIn
• iMac Aluminum 24" |
MacOS X 10.5-current | 3.06 GHz Intel Core Duo | 4 GB RAM | 1 TB HDD
• iBook G4 1.42 GHz | MacOS X 10.5-current | 1 GB RAM, 100 GB HDD
• AMD Athlon64 3500+ | Slackware 12 (2.6.21.5-smp) | 2 GB RAM, 2•120 GB RAID 1, 2•500 GB RAID 0
Reply With Quote
  #5  
Old January 7th, 2004, 08:16 PM
Arden's Avatar
Don't drink and derive.
 
Join Date: Dec 2002
Location: San Francisco
Posts: 7,743
Thanks: 0
Thanked 0 Times in 0 Posts
Arden is on a distinguished road
Yes, the clincher in that URL is the %00@ part. That bit means that the URL after the symbols is the real host, and is simply passing itself off as the URl before it. IE for Windows hides everything after those symbols, so people who get those emails think it's legitimate, which it wouldn't be anyway if it's asking for your PIN number.

There was an article in the Currents (read: Tuesday Life) section of our paper yesterday about this very kind of scandal, called phishing. The guy got an email purporting to be from Citibank asking for verification of his email address. Fortunately, he was smart enough to recognize the signs of fraud, but many others aren't so lucky.
__________________
System:
• 2.5 GHz MacBook Pro Core 2 Duo, 4 GB RAM, 200 GB hard drive, runs 10.5.4
• 1.6 GHz iMac G5, 1.5 GB RAM, 250 GB hard drive, runs 10.4.11
• iPhone, 4 GB, OS X 2.0.2
Reply With Quote
  #6  
Old January 7th, 2004, 08:50 PM
mr. k's Avatar
Registered User
 
Join Date: Oct 2002
Location: mpls. mn
Posts: 1,408
Thanks: 0
Thanked 0 Times in 0 Posts
mr. k is on a distinguished road
And because internet explorer is a completely crippled browser that won't be seeing a real update until 2006 (if even) when longhorn comes out, we are stuck dealing with these scams for years. Plus IE sucks!
__________________
iMac G3 600Mhz, 256MB RAM, 40GB HD, 10.3.5
20GB iPod (Click Wheel) w/ Griffin iTrip // AIM:kjell05
Reply With Quote
  #7  
Old January 8th, 2004, 12:03 AM
michaelsanford's Avatar
Psycholinguist
 
Join Date: Oct 2002
Location: Ottawa/Montr้al
Posts: 2,172
Thanks: 0
Thanked 0 Times in 0 Posts
michaelsanford is on a distinguished road
Arden, thanks for the insight, I was trying to figure out how it had a seemingly fully qualified domain name ending in .com but not point to that server...cool.
__________________
michaelsanford.com • Blog • Twitter • Tumblr • LinkedIn
• iMac Aluminum 24" |
MacOS X 10.5-current | 3.06 GHz Intel Core Duo | 4 GB RAM | 1 TB HDD
• iBook G4 1.42 GHz | MacOS X 10.5-current | 1 GB RAM, 100 GB HDD
• AMD Athlon64 3500+ | Slackware 12 (2.6.21.5-smp) | 2 GB RAM, 2•120 GB RAID 1, 2•500 GB RAID 0
Reply With Quote
  #8  
Old January 8th, 2004, 01:04 AM
symphonix's Avatar
Scratch & Sniff Committee
 
Join Date: Jul 2001
Location: The Australian Jungles
Posts: 4,022
Thanks: 2
Thanked 2 Times in 2 Posts
symphonix is on a distinguished road
So far this "Phishing" bug only affects users of MS IE, and this has been discussed as a security issue for months, with several IT security consultancies placing pressure on MS to fix it. Still, no go.
__________________
- iMac G5 1.8GHZ 17" | SuperDrive | 160GB | 512MB | Airport Extreme | Bluetooth Keyboard & Mouse | Wacom Intuos II
- Pentax *ist DL - JVC MiniDV Camcorder - Airport Express - iPod Nano 1gb white
Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off
Forum Jump


All times are GMT -5. The time now is 04:59 PM.


Mac Support® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.1.0
Copyright 2000-2008 DigitalCrowd, Inc.