1. Advertising
    y u no do it?

    Advertising (learn more)

    Advertise virtually anything here, with CPM banner ads, CPM email ads and CPC contextual links. You can target relevant areas of the site and show ads based on geographical location of the user if you wish.

    Starts at just $1 per CPM or $0.10 per CPC.

Is it serious attempt to hack my info?

Discussion in 'General Chat' started by maverick, Mar 14, 2005.

  1. #1
    I recently received this email from

    Is it malacious attempt to hack the info, anyone else received this, and did anyone take any action?
     
    maverick, Mar 14, 2005 IP
  2. ResaleBroker

    ResaleBroker Active Member

    Messages:
    1,665
    Likes Received:
    50
    Best Answers:
    0
    Trophy Points:
    90
    #2
    I get those quite often. They are SPAM.
     
    ResaleBroker, Mar 14, 2005 IP
  3. fryman

    fryman Kiss my rep

    Messages:
    9,604
    Likes Received:
    777
    Best Answers:
    0
    Trophy Points:
    370
    #3
    They are not spam, they are illegal and you should forward them to

    Don't send it as an atachment, Ebay's personnel can't open them.
     
    fryman, Mar 14, 2005 IP
  4. maverick

    maverick Peon

    Messages:
    1,191
    Likes Received:
    24
    Best Answers:
    0
    Trophy Points:
    0
    #4
    how shall I send that then? Shall I paste in email like the way I did here?
     
    maverick, Mar 14, 2005 IP
  5. debunked

    debunked Prominent Member

    Messages:
    7,298
    Likes Received:
    416
    Best Answers:
    0
    Trophy Points:
    310
    #5
    Forward the whole e-mail to This is also known as phishing. THey try to get you to fill out your personal information and people will freely give it to the crook.
     
    debunked, Mar 14, 2005 IP
  6. fryman

    fryman Kiss my rep

    Messages:
    9,604
    Likes Received:
    777
    Best Answers:
    0
    Trophy Points:
    370
    #6
    Yup, just forward the email to them, they will track it down
     
    fryman, Mar 14, 2005 IP
  7. J.D.

    J.D. Peon

    Messages:
    1,198
    Likes Received:
    65
    Best Answers:
    0
    Trophy Points:
    0
    #7
    The domain name is ebay.com. They would have to poison your DNS cache for this to work. When you are saying that the link was pointing to this IP address, how'd you figure it out?

    J.D.
     
    J.D., Mar 14, 2005 IP
  8. Lever

    Lever Deep Thought

    Messages:
    1,823
    Likes Received:
    94
    Best Answers:
    0
    Trophy Points:
    145
    #8
    J.D. Isn't the ebay address just the anchor text in the link? That's how I've spotted paypal and ebay phishing scams... they're the only ones I look at. As for the phishing supposedly from banks I don't even belong to... :rolleyes:
     
    Lever, Mar 14, 2005 IP
  9. J.D.

    J.D. Peon

    Messages:
    1,198
    Likes Received:
    65
    Best Answers:
    0
    Trophy Points:
    0
    #9
    That's what I'm wondering about. If it's just anchor text, then it's relatively easy to spot. If the DNS cache was poisoned, one would have to check IP address registration info in order to figure out what's going on. Here's an example of what happened a few months ago with Ebay in Germany:

    http://www.theregister.co.uk/2004/09/04/ebay_domain_hijacker_arrested/

    J.D.
     
    J.D., Mar 15, 2005 IP
  10. Lever

    Lever Deep Thought

    Messages:
    1,823
    Likes Received:
    94
    Best Answers:
    0
    Trophy Points:
    145
    #10
    Despite the seriousness of the potential consequences, that's quite funny, the fact that ebay didn't lock their domains :D

    That's gotta be an extremely rare occurrence. The simple anchor text trick must fool a lot of less wary/ less savvy people though. Though since you bought the term DNS poisoning to mind, J.D., there's a lot about it on google - http://www.google.co.uk/search?hl=en&q=dns+poisoning&btnG=Google+Search&meta=
     
    Lever, Mar 15, 2005 IP
  11. Lever

    Lever Deep Thought

    Messages:
    1,823
    Likes Received:
    94
    Best Answers:
    0
    Trophy Points:
    145
    #11
    Well waddya know, just got one myself...
    <a target="_blank"    
    href="http://67.19.119.194/~doug/verify_id=ebay_fraud_alert_id_code=XXXXXXXX/index.html"   
    >http://scgi.ebay.com/verify_id=ebay fraud alert id 
    code=XXXXXXXX</a>
    Code (markup):
    Who's doug? ;)
     
    Lever, Mar 15, 2005 IP
  12. maverick

    maverick Peon

    Messages:
    1,191
    Likes Received:
    24
    Best Answers:
    0
    Trophy Points:
    0
    #12
    Its just like anchor text.. I think. They have given ebay.com's URL but pointed it to some strange IP, which does not belong to ebay.com anyway.
     
    maverick, Mar 15, 2005 IP
  13. mushroom

    mushroom Peon

    Messages:
    369
    Likes Received:
    15
    Best Answers:
    0
    Trophy Points:
    0
    #13
    "maverick" it is a phishing attempt and if you click the link it will download a file called "eBay|SAP|.dll" and note that the charators before and after SAP are pipes.

    On a windows computer using IE it will rewite the address bar in your brower to say "http://ebay.com/" using javasript rather than the address you are connected to. And try and trick you in to entering passwords and other personal info.

    From what I have read only IE supports the pipe command in the address bar leaving it's users open to this form of spooffing.

    I have not seen this version of the ebay spoof before, the come on has changed a bit.

    Also anyone that has clicked on the link should check their computer for the dll quoted earlier.
     
    mushroom, Mar 15, 2005 IP
  14. Josh

    Josh Peon

    Messages:
    893
    Likes Received:
    82
    Best Answers:
    0
    Trophy Points:
    0
    #14
    There are a _lot_ of these going around today. Paypal, ebay, banks, you name it, anything that has anything to do with finances.

    Rule of thumb, if they request you to do something like that, type the site URL in manually (i.e. ebay.com) into the address bar, and never never never trust links that lead to IPs.



    Josh
     
    Josh, Mar 15, 2005 IP
  15. maverick

    maverick Peon

    Messages:
    1,191
    Likes Received:
    24
    Best Answers:
    0
    Trophy Points:
    0
    #15
    thanks mushroom for the info, I unfortunately clicked on it... just happened! Let me check for the DLL.
     
    maverick, Mar 16, 2005 IP
  16. maverick

    maverick Peon

    Messages:
    1,191
    Likes Received:
    24
    Best Answers:
    0
    Trophy Points:
    0
    #16
    eBayISAPI[1].dll ... this was the name of files which I found on my computer...
     
    maverick, Mar 16, 2005 IP
  17. mushroom

    mushroom Peon

    Messages:
    369
    Likes Received:
    15
    Best Answers:
    0
    Trophy Points:
    0
    #17
    Glad to be of assistance hope you deleted the "dll"

    I would also recomend that you do a full scan for spyware as some of those sites use the connection to download more spyware to your computer.
     
    mushroom, Mar 16, 2005 IP
  18. J.D.

    J.D. Peon

    Messages:
    1,198
    Likes Received:
    65
    Best Answers:
    0
    Trophy Points:
    0
    #18
    In the link, those are I's, not pipes. The DLL says ISAPI, which is an IIS API DLL. If this DLL returns anything but text/html, any browser would pop the question whether the user wants to download the content or not. In general, just downloading a DLL doesn't do any harm to your machine and is not practical from the phishing perspective.

    Unfortunately, the IP address is no longer accessible and I cannot verify what the DLL really does.

    I saw JS used to create a popup window that closely resembled the URL bar and was covering its area, but I don't think it is possible to actually rewrite the text in the URL bar.

    Can you point me to any related articles or just describe how can one use the pipe symbol to do what you are describing?

    J.D.
     
    J.D., Mar 16, 2005 IP
  19. mushroom

    mushroom Peon

    Messages:
    369
    Likes Received:
    15
    Best Answers:
    0
    Trophy Points:
    0
    #19
    As I do not use windows on the net only Linux, I read the info some where and forgot about it.

    Here is a copy of the dll
    <html>
    <head>
      <title>Please wait.. Redirecting to our secure servers</title>
      <meta http-equiv="content-type" content="text/html; charset=ISO-8859-1">
    
    
    
    <script language="javascript">
    var win = null;
    function NewWindow(mypage,myname,w,h,scroll){
    LeftPosition = (screen.width) ? (screen.width-w) : 0;
    TopPosition = (screen.height) ? (screen.height-h) : 0;
    settings =
    'height='+h+',width='+w+',top='+TopPosition+',left='+LeftPosition+',scrollbars='+scroll+',resizable'
    win = window.open(mypage,myname,settings)
    window.location = "http://ebay.com/"
    }
      </script>
    </head>
    <body onload="NewWindow('login.htm','name','1024','768','yes');return false">
    
    
    </body>
    </html>
    PHP:
    You tell me what that code will do.
     
    mushroom, Mar 16, 2005 IP
  20. J.D.

    J.D. Peon

    Messages:
    1,198
    Likes Received:
    65
    Best Answers:
    0
    Trophy Points:
    0
    #20
    This is low-tech. It launches a new window and points it the login form on the spoofed website, while the original window is redirected to ebay.com. I think their thinking is that the presence of ebay.com should make people think that the other window is from ebay as well. Here's an example of more sophisticated technique:

    http://news.netcraft.com/archives/2...ofing_vulnerabilities_actively_exploited.html

    J.D.
     
    J.D., Mar 16, 2005 IP