The blog has been moved. The one at this address will no longer be updated.

Please update your bookmarks

» this way to the new blog «

Tuesday, August 16, 2005

<< Home

Fake-eBay fraud

The e-mail is one of the most useful services the Internet provides, but sometimes it can be really dangerous, either because it allows viruses and trojans to spread quickly or even for frauds. A basic rule would be to read ``carefully'' all the content of the mail, including the headers if the mail contains or requests sensitive data as reply. People who are not familiar with Internet technologies are the best target for cheaters, that's why people need to be deeply aware about these pretty new technologies.
I've just received a mail with ``service@ebay.com'' as sender. The mail informs me that recently several attempts to log into my eBay account have been made, and, for my own security, they request me to change my password logging into a web link provided in the mail. Here's the text:

Dear eBay User,


To protect the security of your account, eBay © employs some of the most advanced security systems in the world and our anti-fraud teams regularly screen the eBay system for unusual activity.

We recently have determined that different computers have logged onto your eBay account, and multiple password failures were present. We now need you to re-confirm your account information to us. If this is not completed we will be forced to suspend your account , as it may have been used for fraudulent purposes. We thank you for your cooperation in this manner.
If the account information is not updated to current information within 5 days then, your access to bid or buy on eBay will be restricted.
go to this link below:

https://www.ebay.com/acounts/memb/avncenter/?dll87443%2213

Thank you for your prompt attention to this matter. Please understand that this is a security measure meant to help protect you and your account.

We apologize for any inconvenience.

If you choose to ignore our request, you leave us no choise but to temporaly suspend your account.



Thank you ,
eBay © Accounts Managent



As outlined in our User Agreement, eBay will periodically send you information about site changes and enhancements. Visit our Privacy Policy and User Agreement if you have any questions.


The mail is not in plain text, it's in html. This language allows you to write fancy, colored emails, but also allows you to ``hide'' something. For example, you can redirect somebody to a web page creating a link whose label can be different from the actual page you're redirected. This is the case of this email. The link is apparently a web page on ebay.com but actually it sends you on a just alike page hosted on a different server, controlled by non-ebay people. If somebody trusts this email and gives them his/her password, then these guys can obtain his actual ebay password but also they can request him/her to reconfirm his/her credit card number, becoming able to get money.
The mail I received wanted to send me on a page on the machine at the IP address 202.150.101.22. A quick lookup of this address reveals
$ whois 202.150.101.22
inetnum: 202.150.96.0 - 202.150.127.255
netname: CONCEPTNET
descr: Internet Service Provider
descr: Auckland New Zealand
country: NZ
admin-c: CS20-AP
tech-c: CS20-AP
status: ALLOCATED PORTABLE
mnt-by: APNIC-HM
mnt-lower: MAINT-NZ-CONCEPTNET
remarks: -+-+-+-+-+-+-+-+-+-+-+-++-+-+-+-+-+-+-+-+-+-+-+-+-+-+
remarks: This object can only be updated by APNIC hostmasters.
remarks: To update this object, please contact APNIC
remarks: hostmasters and include your organisation's account
remarks: name in the subject line.
remarks: -+-+-+-+-+-+-+-+-+-+-+-++-+-+-+-+-+-+-+-+-+-+-+-+-+-+
changed: hm-changed@apnic.net 20040623
changed: hm-changed@apnic.net 20050318
source: APNIC

person: CRAIG SPIERS
nic-hdl: CS20-AP
e-mail: craig@concept.net.nz
address: PO Box 302288
address: NorthHarbour, 1330
address: Auckland
address: New Zealand
phone: +64-9414-4297
fax-no: +64-9915-2559
country: NZ
changed: craig@concept.net.nz 20031203
mnt-by: MAINT-NEW
source: APNIC

while eBay.com has address
$ host ebay.com
ebay.com has address 66.135.192.87

and a lookup on this address says
$ whois 66.135.192.87
OrgName: eBay, Inc
OrgID: EBAY
Address: 2145 Hamilton Ave
City: San Jose
StateProv: CA
PostalCode: 95008
Country: US

NetRange: 66.135.192.0 - 66.135.223.255
CIDR: 66.135.192.0/19
NetName: EBAY-1
NetHandle: NET-66-135-192-0-1
Parent: NET-66-0-0-0-0
NetType: Direct Assignment
NameServer: SJC-DNS1.EBAYDNS.COM
NameServer: SJC-DNS2.EBAYDNS.COM
NameServer: SMF-DNS1.EBAYDNS.COM
Comment:
RegDate: 2001-07-13
Updated: 2003-02-20

OrgTechHandle: EBAYN-ARIN
OrgTechName: eBay Network
OrgTechPhone: +1-408-376-7400
OrgTechEmail: network@ebay.com


This fraud can be very dangerous, and it can be made not only faking ebay, but bank institutes as well, that could be even more dangerous.
Read carefully every single email you receive before doing anything about it.

1 terrible lies

posted by Anonymous Anonymous @ 8/23/2005 4:55 PM

Still a non-geek can not repel this fraud...

 

Does this blog need a title?

Linux inside