LostStraw Posted September 20, 2006 Share Posted September 20, 2006 This is the first scam/phish topic that I've posted -- I normally wouldn't post something like this because they often suck. But this one is different, it's pretty slick. Following is a description and some screen shots. As the norm, I get an email telling me I needed to update my PayPal account, well I don't have an account -- that tipped me off right there, but I decided to follow the link anyway. Here's a screenshot showing the fake website: Here's a screenshot of the real website for comparison: Note the strange URL on the fake website. I didn't link the page because I don't know if the site contains spyware/viruses.. be careful if you decide to look at it for yourself. All the links on the fake page redirect to the official Paypal pages except the "Log In" button. The "Log In" takes you to a page asking you to fill out some information (credit cards, etc..) no matter what is typed in the email/password fields. Link to comment Share on other sites More sharing options...
Pop Posted September 20, 2006 Share Posted September 20, 2006 Uh... yeah. Always check the url. This happens with a lot of password-protected sites. I believe Myspace has had a lot of problems with this. I don't really understand why you would willingly explore the email if you knew it was malicious. It could be loaded with teh warez! Join me, and we shall make Production Beards a reality! Link to comment Share on other sites More sharing options...
Darque Posted September 20, 2006 Share Posted September 20, 2006 Thread relocated to a more appropriate forum. Link to comment Share on other sites More sharing options...
LostStraw Posted September 20, 2006 Author Share Posted September 20, 2006 As watchful as ever Darque :"> I browse with a lot of software designed to block the bad things.. I really should have done it in a VM though. I'm surprised that they made it look so good, but not quite perfect... it's like putting a lot of effort into something and then stopping near the end. Link to comment Share on other sites More sharing options...
Oerwinde Posted September 20, 2006 Share Posted September 20, 2006 When these first started going around I knew they were fake right off the bat from the bad URLs and sending the emails to the wrong email addresses and such(I got the phishing site emails in one address, while my account is registered with another) and wondered how anyone could fall for them. Then lots of people started falling for them. The area between the balls and the butt is a hotbed of terrorist activity. Link to comment Share on other sites More sharing options...
Nartwak Posted September 20, 2006 Share Posted September 20, 2006 Link to comment Share on other sites More sharing options...
Tigranes Posted September 20, 2006 Share Posted September 20, 2006 To be fair, they're very good at finding stolen credit cards. Let's Play: Icewind Dale Ironman (Complete) Let's Play: Icewind Dale II Ironman (Complete) Let's Play: Divinity II (Complete) Let's Play: Baldur's Gate Trilogy Ironman - BG1 (Complete) Let's Play: Baldur's Gate Trilogy Ironman - BG2 (In Progress) Link to comment Share on other sites More sharing options...
Diamond Posted September 20, 2006 Share Posted September 20, 2006 Hmmm, interesting. The site is in Brasil, Montevideo. It is a rooted linux server. If you go to .../icons/, directory index is available, and PHP Shell Offender is installed (php.cgi) so anyone can execute remote commands in the web shell. I think the owners of the server have to be notified that their server is owned. This statement is false. Link to comment Share on other sites More sharing options...
metadigital Posted September 20, 2006 Share Posted September 20, 2006 But ... Montevideo is the capital of Uruguay. OBSCVRVM PER OBSCVRIVS ET IGNOTVM PER IGNOTIVS OPVS ARTIFICEM PROBAT Link to comment Share on other sites More sharing options...
6 Foot Invisible Rabbit Posted September 20, 2006 Share Posted September 20, 2006 NOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOO! Not Uruguay?!?!? :'( Harvey Link to comment Share on other sites More sharing options...
Calax Posted September 20, 2006 Share Posted September 20, 2006 But ... Montevideo is the capital of Uruguay. <{POST_SNAPBACK}> It was also blown to pieces by Vandal Savage during JLA 1 million. Victor of the 5 year fan fic competition! Kevin Butler will awesome your face off. Link to comment Share on other sites More sharing options...
Diamond Posted September 20, 2006 Share Posted September 20, 2006 (edited) But ... Montevideo is the capital of Uruguay. <{POST_SNAPBACK}> OK, I've got it wrong somewhere. Edit: the site has a Brazilian domain name and IP address is registered in Brazil, but IP address registry is in Uruguay. Good news: phishing site is down, but the shell is still there. Edited September 20, 2006 by Diamond This statement is false. Link to comment Share on other sites More sharing options...
Fenghuang Posted September 21, 2006 Share Posted September 21, 2006 You didn't... RIP Link to comment Share on other sites More sharing options...
Diamond Posted September 21, 2006 Share Posted September 21, 2006 I didn't? But Montevideo is indeed in Uruguay. This statement is false. Link to comment Share on other sites More sharing options...
Fenghuang Posted September 21, 2006 Share Posted September 21, 2006 Thought you were implying you took it down though questionable means. Nevermind. RIP Link to comment Share on other sites More sharing options...
Diamond Posted September 21, 2006 Share Posted September 21, 2006 I admit, it was very tempting to do so. I'd delete the shell php file as well if I was doing that. But no, I just emailed website owners. This statement is false. Link to comment Share on other sites More sharing options...
metadigital Posted September 21, 2006 Share Posted September 21, 2006 What did you email the website owners? OBSCVRVM PER OBSCVRIVS ET IGNOTVM PER IGNOTIVS OPVS ARTIFICEM PROBAT Link to comment Share on other sites More sharing options...
Diamond Posted September 21, 2006 Share Posted September 21, 2006 Ummm... "your site has been owned"? This statement is false. Link to comment Share on other sites More sharing options...
metadigital Posted September 21, 2006 Share Posted September 21, 2006 Ah. As long as it wasn't an email bomb ... " OBSCVRVM PER OBSCVRIVS ET IGNOTVM PER IGNOTIVS OPVS ARTIFICEM PROBAT Link to comment Share on other sites More sharing options...
Fenghuang Posted September 21, 2006 Share Posted September 21, 2006 Because y'know. That wouldn't be nice. RIP Link to comment Share on other sites More sharing options...
6 Foot Invisible Rabbit Posted September 21, 2006 Share Posted September 21, 2006 Being nice to scammers? That seems so wrong. Harvey Link to comment Share on other sites More sharing options...
Diamond Posted September 21, 2006 Share Posted September 21, 2006 Actually being nice to a Brazilian government organization, if you missed that. This statement is false. Link to comment Share on other sites More sharing options...
6 Foot Invisible Rabbit Posted September 21, 2006 Share Posted September 21, 2006 Even better! DO IT! Harvey Link to comment Share on other sites More sharing options...
mkreku Posted September 21, 2006 Share Posted September 21, 2006 Russians scare me Swedes, go to: Spel2, for the latest game reviews in swedish! Link to comment Share on other sites More sharing options...
Diamond Posted September 21, 2006 Share Posted September 21, 2006 This statement is false. Link to comment Share on other sites More sharing options...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now