PDA

View Full Version : eBay Phishing - warning


Roland Fricke
05-06-2005, 03:36 PM
I know a lot of Fanatici may be on eBay from time to time. Beware of "phishing" or fake emails that ask you to go to a site and enter information - I got this one from moreinfo@ebay.com (fake I'm sure)


RE: FPA NOTICE: eBay Registration Suspension - Breach of User Agreement - Section 8 - Action Required

It basically says your account was suspended for suspicious activity and if you want it reactivated visit a link that was in the mail.

It looks like an ebay page and asks for you user ID and password to get in. On the next page (I had a mental lapse and put in my user and password) it asked for credit card and SS# info which finally sent alarm bells ringing. Even though I didn't give any credit card info I had to quickly change my eBAy user ID and password.

One should always enter a web site from your favorites bar and not from links provided in mails.

[ May 06, 2005, 12:37: Message edited by: Roland Fricke ]

E_A_Lindberg
05-06-2005, 04:30 PM
Originally posted by Roland Fricke:
- I got this one from moreinfo@ebay.com (fake I'm sure)Headers show mine to have been sent from jexiste.org, though they had faked the FROM: line to look like it was from ebay.com.

I forwarded the offending e-mail to abuse@ebay.com. I should probably send something to the folks at jexiste.org, as well.

Matthew Bailey
05-09-2005, 03:24 AM
Originally posted by E_A_Lindberg:
</font><blockquote>quote:</font><hr />Originally posted by Roland Fricke:
- I got this one from moreinfo@ebay.com (fake I'm sure)Headers show mine to have been sent from jexiste.org, though they had faked the FROM: line to look like it was from ebay.com.

I forwarded the offending e-mail to abuse@ebay.com. I should probably send something to the folks at jexiste.org, as well. </font>[/QUOTE]Since I began my career with computer as a hacker back in the 1980s I have always been suspiscious of ALL email that I get. Even though my hacking experience was too early to have anything to do with phishing or stealing digital identities (No-one had a digital ID back then)... Still... I remember the first one of these I got. I thought "Why are they going against their own stated policy of not asking in email for my ID or Password?"

I forwarded it to eBay after checking the headers, and then emailed the address that was in the header to ask them when they became an employee of eBay... Then I sent a little Denial of Service attack to them...

Normally I am not a fan of creating viruses or other IT Chaos, but I HATE people who attempt to con/steal ID or money from others whether it is online or in a dark alley with a gun. At least the guy with the gun has the guts to do it without hiding behind a facade...

xeswop
05-10-2005, 10:44 PM
my rule
Ignore all messages from any vendor. If they want you they will send you note when you enter their program.

Bob