Page 1 of 1

Inside a PayPal Phishing Site

Posted: Tue Feb 05, 2008 5:14 am
by Tami
This is a very interesting article written by Cyrus Peikari and Seth Fogie of InformIT, I hope you take the time to read through it.

The phishing attack came in the form of an email that appeared to be from PayPal. Since the title of the email stated “Please update your billing records or your account will be suspended. Thanks!", it was clearly designed to alert the victim in a way that is bound to get their attention. Contained in the body of the email was a warning that my account would expire in 12 hours unless I updated my records. Included with the message was a helpful link to [url=\"http://www.paypal.com\"]http://www.paypal.com[/url]. Unfortunately, for those not paying attention, this link actually went to [url=\"http://www.google.com\"]http://xxxxxxxxxxx.com/awstats/cgi-bin/[/url].

We decided to follow the link because we like to keep in the loop of what the phishers are up to incase we are called by a client who is curious as to how their identity was stolen. In addition, as we tend to discover, people who use these phishing scams sometimes make mistakes and leave a trail of information that can be helpful in stopping them.

...[i][url=\"http://www.informit.com/guides/content.aspx?g=security&seqNum=293\"]read the rest of the article[/url][/i]...

Inside a PayPal Phishing Site

Posted: Tue Feb 05, 2008 11:14 am
by Jim
People need to learn to look at the status bar when clicking links and the address bar when filling in credit card info etc.

Inside a PayPal Phishing Site

Posted: Tue Feb 05, 2008 12:05 pm
by Vercz
wow. thats nuts and amazing how complex the script was, the detail it went to was astonishing. im going to enjoy my uni course, ill be studying stuff like this /biggrin.gif\' class=\'bbc_emoticon\' alt=\':D\' />

oh, fav part...
[quote name=\'http://www.informit.com/guides/content.aspx?g=security&seqNum=293\']Finally, the phisher who is using this script is getting owned as well.[/quote]

bwhahaha! top notch!