PDA

View Full Version : WARNING - Paypal fishing.



Captain_Rightfoot
28th September 2008, 08:11 AM
I just thought I'd post this up as this phishing scam was sent to someone on another forum that I frequent and I was impressed with it's quality. Basically, it is an example of some really good phishing (http://en.wikipedia.org/wiki/Phising) and should be a warning to everyone.

Basically they sent out some SPAM like the following. You see the link and then go there and enter your paypal username and password. You then get redirected to another screen where you enter basically all your identity details. This would give the perpetrators enough information that they could basically do what they will with you!

I encourage you to click on the link below. Enter a rubbish email and see the next screen with all the details. I have included a copy of the screen in case you don't want to go there. You may want to compare it to the real paypal screen (https://www.paypal.com/au/cgi-bin/webscr?cmd=_login-run&dispatch=5885d80a13c0db1f38432c9462fe731381a7a80e0 9148cd40fd400e193a86a7d) if you like. Just scary.

Notice that the URL is not actually paypal, but an IP address. This should serve as the first warning. Despite the quality of the fake, notice too that the buttons don't work. However if you just follow the prompts all your details can be stolen :(

WARNING DO NOT ENTER YOUR REAL PAYPAL ACCOUNT, PASSWORD, OR ANY OTHER PERSONAL DETAILS ON THE FAKE SITE.


Dear (my email address)@hotmail.com,

As part of our security measures, we regularly screen activity in the
PayPal system. During a recent screening, we noticed an issue
regarding your account.

Case ID Number: PP-401-126-812

For your protection, we have limited access to your account until
additional security measures can be completed. We apologize for any
inconvenience this may cause.

To review your account and some or all of the information that PayPal
used to make its decision to limit your account access.

Please update your billing records:
http://80.243.160.238/.us/cgi-bin/index.php

If, after reviewing your account information, you
seek further clarification regarding your account access, please
contact PayPal by visiting the Help Center and clicking "Contact Us".

We thank you for your prompt attention to this matter. Please
understand that this is a security measure intended to help protect
you and your account. We apologize for any inconvenience.

Sincerely,
PayPal Account Review Department

----------------------------------------------------------------
Copyright© 2008 PayPal Inc. All rights reserved. Designated trademarks
and brands are the property of their respective owners.

PayPal Email ID PP753

Sprint
28th September 2008, 08:48 AM
similar thing is happening with several thousand other companies and fake websites.....

one gem i recieved last week claimed to be from telstra/bigpond, looked legit and everything...... just a shame they didnt send it to the email account that bigpond sends thier usual correspondence to!

p38arover
28th September 2008, 09:02 AM
I use MailWasher. It shows the real address to which an email When there are clickable links in an email, it shows the real address to which it will take you.

dullbird
28th September 2008, 10:28 AM
i have had heaps of these over the years using ebay.

paypal always address you buy your name.. but if I EVER have paypal ask me for account details I ALWAYS ask there crime unit if the email is legit before i punch anything in. as there has been one or two that were very well done!.....but again be suspicous and your never get caught out