Weekend of fraud

Options
jrausch
jrausch Posts: 510
edited February 28 in Clubhouse Archives
Just a heads up, I just received an e-bay spoof e-mail requesting I update my info. The link was an unsecured geocities link, what a scam!! A friend of mine was sent a spoof from someone claiming to be from Best Buy and wanted the same info. I think some severe examples need to be made to thwart off this all too easy scam. Here is the body of my message. Incomplete and misspelled words abound.

Dear eBay user,
We regret to inform you that your eBay account could be suspended if
you don't resolve your problems. To resolve this problems please
download file and login to your account in order to resolve your
account problems. Please click here to upgrade all the informations.
Because the fraud on eBay is bigger we must verify all users who are on eBay.
If you will not provide us all your registration informations for we can identify you and resolve these problems we must susspend the account because we want that our customers to have safety and trust on this site.
Per the User Agreement, Section 9, we may immediately issue a warning,temporarily suspend, indefinitely suspend or terminate your membership and refuse to provide our services to you if we believe
that your actions may cause financial loss or legal liability for you, our
users or us.
We may also take these actions if we are unable to
verify or authenticate any information you provide to us.
Due to the suspension of this account, please be advised you are prohibited from using eBay in any way. This includes the registering of a new account.
Please note that this suspension does not relieve you of your agreed-upon obligation to pay any fees you may owe to eBay.
Regards,
Safeharbor Departmen
eBay, Inc.

Do you Yahoo!?
SBC Yahoo! DSL - Now only $29.95 per month!
"The only way to get rid of a temptation is to yield to it."
Post edited by RyanC_Masimo on

Comments

  • dorokusai
    dorokusai Posts: 25,576
    edited June 2003
    Options
    It sucks that there is so much fraud on the internet, but that's what America is built on, so its the nature of the beast. Wait lemme edit myself, I am American, just making a broad statement about how I see things sometimes. Just boggles me how so many people are out there that take advantage of our free society, makes me sick.

    I normally ignore all those emails until my service is cut off, or I can't login anymore, saves me some headaches.
    CTC BBQ Amplifier, Sonic Frontiers Line3 Pre-Amplifier and Wadia 581 SACD player. Speakers? Always changing but for now, Mission Argonauts I picked up for $50 bucks, mint.
  • stevelarrison
    stevelarrison Posts: 63
    edited June 2003
    Options
    Do you mind if I ask for the URL of the Geocities site? I do research with viruses, and am interested in obtaining the file they want you to download. (Don't worry, I know how to handle things like that. I have over 8,000 viruses on one of my machines at home)

    If you don't want to post it publically, I would appreciate it you can send it to stevelarrison@hotmail.com

    Thanks
  • dthomps
    dthomps Posts: 352
    edited June 2003
    Options
    thanks for the heads up jrausch.
    Geez, look at the spelling and grammer... You would think they would at least try to sound a little bit more professional.
    Probably some 14 year old from SC...:D

    (J/K, BTW)
  • Tour2ma
    Tour2ma Posts: 10,177
    edited June 2003
    Options
    steve,
    Man, I don't even want my cursor to touch your posts... :)

    On the scam... you'd think a scanner would at least grammar check his cover message. Not trying to be racist here, but the misuse of the plural tense is very common for Asians with English as a second language.

    Then again, it's better than a good percentage of posters here... :D
    More later,
    Tour...
    Vox Copuli
    Better to remain silent and be thought a fool, than to open your mouth and remove all doubt. - Old English Proverb

    "Death doesn't come with a Uhaul." - Dennis Gardner

    "It's easy to get lost in price vs performance vs ego vs illusion." - doro
    "There is a certain entertainment value in ripping the occaisonal (sic) buttmunch..." - TroyD
  • stevelarrison
    stevelarrison Posts: 63
    edited June 2003
    Options
    If you know how to handle viruses, they are safe. If you don't, you will hose yourself. In addition to live viruses, I have a large number of virus generators, source code for various viruses, and libraries that can add some "interesting" functions to anything you want to develop yourself.

    For storage purposes, I keep them on a Linux box where they are absolutely harmless. Though occassionally I will purposely infect some of my own Windows machines.
  • jrausch
    jrausch Posts: 510
    edited June 2003
    Options
    The only thing they direct you to is a web page they created on geocities. I sent this to e-bay and it's still up. They said they would have it shut down immediately. I just wonder how fast their immediate really is. I just hate to see people get their hard earned money taken in this manner.

    http://www.geocities.com/upgrade_ebay/Question.html
    "The only way to get rid of a temptation is to yield to it."
  • stevelarrison
    stevelarrison Posts: 63
    edited June 2003
    Options
    Thanks, but it looks like I got your message a little too late. Geocities zapped the site.

    Oh well. I assume that the program they want you to install is a keystroke logger. Nothing too exciting, but the site that it sends information to could be interesting.
  • jrausch
    jrausch Posts: 510
    edited June 2003
    Options
    It was up just a few hours ago. It looks like it takes around 24 hours to knock a site down. Even if the spoofer gets 1 person to fall for it, that could be well worth the effort. There was no virus on the other side just an information gathering web page that looks semi-authentic. They almost had me going because I did need to update my information. The poor grammar is what turned the light on.
    "The only way to get rid of a temptation is to yield to it."
  • HBombToo
    HBombToo Posts: 5,256
    edited June 2003
    Options
    Originally posted by stevelarrison
    I keep them on a Linux box where they are absolutely harmless. Though occassionally I will purposely infect some of my own Windows machines.

    I bet I know some "really!", smart guys... that you could start networking with.

    Its Sunday and Toy Story has over-ridden Nascar so remember the Twin is on line.

    Hbomb
    ***WAREMTAE***
  • stevelarrison
    stevelarrison Posts: 63
    edited June 2003
    Options
    Jraush, aside from it being on a Geocities site, this line stands out - "To resolve this problems please
    download file and login to your account in order to resolve your
    account problems."

    I would be willing to bet anything that the file is a keylogging trojan.
  • stevelarrison
    stevelarrison Posts: 63
    edited June 2003
    Options
    Originally posted by HBombToo
    I bet I know some "really!", smart guys... that you could start networking with.


    I don't mean to sound rude, but I have absolutely no interest in that kind of thing. The reason I started my virus collection and research goes back to when I was working for Litton Electron Devices. I was the MIS Manager of the Tempe facility. Simply put, I got tired of losing my PC technicians to nasty viruses, so I started educating myself on the subject. My collection is only for research purposes. The only time I will use a virus on my own machine is if a friend gets hit by something that I need to experiment with so data loss can be avoided. It is easy for me to set up test environments that I don't really care about so I can find a proper approach to take care of anything tricky.
  • HBombToo
    HBombToo Posts: 5,256
    edited June 2003
    Options
    Originally posted by stevelarrison
    I don't mean to sound rude, but I have absolutely no interest in that kind of thing. The reason I started my virus collection and research goes back to when I was working for Litton Electron Devices.

    understood steve and i am also an alumni of Litton Electron Devices Williamsport division.

    good ta have ya in the club.

    HBomb
    ***WAREMTAE***
  • stevelarrison
    stevelarrison Posts: 63
    edited June 2003
    Options
    Yes, I remember. I ran into you in another thread back around January or so. What time frame did you work for Electron Devices? My original boss at Litton came from the Williamsport facility.
  • HBombToo
    HBombToo Posts: 5,256
    edited June 2003
    Options
    Originally posted by stevelarrison
    What time frame did you work for Electron Devices? My original boss at Litton came from the Williamsport facility.

    around 93 through almos 94... is that around the correct timeframe?

    HBombed
    ***WAREMTAE***
  • stevelarrison
    stevelarrison Posts: 63
    edited June 2003
    Options
    No. The person from Williamsport that I knew was there in the 80's. Around the time you worked there, Tempe was spinning off from the Electron Devices divison (headquartered in San Carlos) to form our own divsion. (Electro Optical Systems)

    I was with Litton from 1990 through 1998.
  • sgtgto
    sgtgto Posts: 310
    edited June 2003
    Options
    Originally posted by dthomps
    thanks for the heads up jrausch.
    Geez, look at the spelling and grammer... You would think they would at least try to sound a little bit more professional.
    Probably some 14 year old from SC...:D

    (J/K, BTW)

    I would say some foreigner:::::::::
  • danger boy
    danger boy Posts: 15,722
    edited June 2003
    Options
    I had someone send me a trojan horse virus on AOL once. when i downloaded it. it infected my computer. so every time i would log onto AOL, it would send them my user name and password. even if I changed it. it would relearn the new password and send it as an email to that person.

    I got kicked off AOL for a year for what he did. Luckily he could not access my account to purchase anything from AOL.
    PolkFest 2012, who's going>?
    Vancouver, Canada Sept 30th, 2012 - Madonna concert :cheesygrin:
  • stevelarrison
    stevelarrison Posts: 63
    edited June 2003
    Options
    AOL users attract more scam attempts than any other group. The problem is that the service has a reputation as being the method for computer neophytes to get on the internet. People without experience are an attractive target.