<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re: [Serious] Certapay Scam in Canadian Chat</title>
<link>http://www.dslreports.com/forum/r15802152</link>
<description></description>
<language>en</language>
<pubDate>Sun, 29 Nov 2009 07:18:44 EDT</pubDate>
<lastBuildDate>Sun, 29 Nov 2009 07:18:44 EDT</lastBuildDate>

<item>
<title>Re: [Serious] Certapay Scam</title>
<link>http://www.dslreports.com/forum/remark,15806190</link>
<description><![CDATA[<A HREF="/useremail/u/960947"><b>Kringle</b></A> : <A HREF="http://www.cibc.com/ca/legal/fraud-example1.html#example19">CIBC e-mail fraud alerts</A> included this precise messsage since Friday (31MAR06). It's a REALLY well done fraudulent e-mail!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15806190</guid>
<pubDate>Sat, 01 Apr 2006 12:35:41 EDT</pubDate>
</item>

<item>
<title>Re: [Serious] Certapay Scam</title>
<link>http://www.dslreports.com/forum/remark,15805848</link>
<description><![CDATA[<A HREF="/useremail/u/911204"><b>Devanchya</b></A> : Problem with contacting the hosting company is 9 times out of 10, this is on a Kiddie-scripted hacked machine.  Bascily some bozzo has a website with a user "web" and password "123456" and this script gets in.<br><br>Depending on the level of the server setup, the next step is usally the instalation of a PHP script with Shell Access, and then using local access exploits to gain root to the box and setup an IRC network connection to publish phishing scams.<br><br>Now the larger groups will go ahead and buy .com .net .org names with a spelling error and point it to this location.  Domain cost $1.99 in some of the cheaper locations, and a single "successful capture" of personal data is worth about $3000 min.  Add Online banking access, or a CC number and that raises the stakes.<br><br>Now, Most phishing scams use "HTML" emails to hide the actual address and will instead redirect to something like rbonline.fasf.com/online or something stupid like that.  IF that machine is hosted in a certain locations, you can get them shutdown/notified in a few days.  Other countries good luck they don't give a fig.<br><br>In my case, there was a yahoo lottery scam that was going around and 3 of the attacks were from a twiki exploit, 1 from a weak password, and another 2 from a and [very old] old sendmail exploit.  Took about 4-5 hours each just to investigate them and in some cases removal wasn't an option at all and we had to block access to the server locations at the router.  <br><br>Each one of these cost at least $500 to even begin to repair, and after loss of confidence, support issues, reinstall steps etc, most likely will costs close to $2-3000 on the server side.<br><br>This is just KILLER for anyone who is running a small-medium hosting company.<br><br>Don't even get me started on the pure ammount of BANDWIDTH some of these attacks can take due to spam/bot inclusion attacks etc can take over.<br><br>Makes me sick in a way.<br><SMALL>--<br>&raquo;<A HREF="http://www.codecipher.com" >www.codecipher.com</A> - Marking the way to tomorrow's solutions</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15805848</guid>
<pubDate>Sat, 01 Apr 2006 11:35:16 EDT</pubDate>
</item>

<item>
<title>Re: [Serious] Certapay Scam</title>
<link>http://www.dslreports.com/forum/remark,15805729</link>
<description><![CDATA[<A HREF="/useremail/u/356677"><b>Deadpool</b></A> : <div class="bquote"><SMALL>said by  Devanchya <A HREF="/useremail/u/911204"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Actually Deadpool, they are taking the necessary steps.<br><br>Over the last week I have been sub-contracted to remove 3 differnt Spoofing scams on web servers that had a user with weak passwords<br><br>In this case, the "real" company just needs to prove to the .com commity.  Takes 24-72 hours in most cases.<br> </DIV>Sorry, I was taking what they said literally. They said 'block', and in my books that means block. If what you're saying is true, then they're not even having the site removed either, just the actual .com removed. Which doesn't really help since the HTML link can be spoofed to display whatever.com, but actually points to the IP.<br><br>What they should do is contact the hosting company and have them removed.<br><SMALL>--<br>Sens 7 (40 GF) - Leafs 0 (14 GF) **** Final Round: April 15, 2006</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15805729</guid>
<pubDate>Sat, 01 Apr 2006 11:10:14 EDT</pubDate>
</item>

<item>
<title>Re: [Serious] Certapay Scam</title>
<link>http://www.dslreports.com/forum/remark,15803409</link>
<description><![CDATA[<A HREF="/useremail/u/659656"><b>yupislyr</b></A> : If you don't notice the fake website first, just look at the email headers you pasted. No research required.<br><br><BLOCKQUOTE><br>Received: <B>from adsl-flat-basic-216.84-47-52.telecom.sk</B> ([84.47.52.216]) by toip6.bellnexxia.net with SMTP; 31 Mar 2006 16:10:29 -0500<br></BLOCKQUOTE><br><br>Would a legit email from certapay originate from a slovak dsl address? Nope.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15803409</guid>
<pubDate>Fri, 31 Mar 2006 23:18:12 EDT</pubDate>
</item>

<item>
<title>Re: [Serious] Certapay Scam</title>
<link>http://www.dslreports.com/forum/remark,15802107</link>
<description><![CDATA[<A HREF="/useremail/u/1334843"><b>delenn13</b></A> : Sorry for the dup..Just learning the ropes around here and found out what it means to be "queued".<br><br>I just wasn't sure when Certpay would reply to me and I didn't want anyone to get scammed. I had gottten many a fake email from ebay, banks and credit cards but they were obvious..this one wasn't. Had to do research in google.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15802107</guid>
<pubDate>Fri, 31 Mar 2006 21:24:53 EDT</pubDate>
</item>

<item>
<title>Re: [Serious] Certapay Scam</title>
<link>http://www.dslreports.com/forum/remark,15802563</link>
<description><![CDATA[<A HREF="/useremail/u/911204"><b>Devanchya</b></A> : Actually Deadpool, they are taking the necessary steps.<br><br>Over the last week I have been sub-contracted to remove 3 differnt Spoofing scams on web servers that had a user with weak passwords<br><br>In this case, the "real" company just needs to prove to the .com commity.  Takes 24-72 hours in most cases.<br><SMALL>--<br>&raquo;<A HREF="http://www.codecipher.com" >www.codecipher.com</A> - Marking the way to tomorrow's solutions</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15802563</guid>
<pubDate>Fri, 31 Mar 2006 21:15:06 EDT</pubDate>
</item>

<item>
<title>Re: [Serious] Certapay Scam</title>
<link>http://www.dslreports.com/forum/remark,15802504</link>
<description><![CDATA[<A HREF="/useremail/u/356677"><b>Deadpool</b></A> : It's funny how they said they took the necessary action to block the website when they're not an ISP, nor do they manage the backbones of the Internet. LOL<br><SMALL>--<br>Sens 7 (40 GF) - Leafs 0 (14 GF) **** Final Round: April 15, 2006</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15802504</guid>
<pubDate>Fri, 31 Mar 2006 21:06:43 EDT</pubDate>
</item>

<item>
<title>Re: [Serious] Certapay Scam</title>
<link>http://www.dslreports.com/forum/remark,15802287</link>
<description><![CDATA[<A HREF="/useremail/u/592593"><b>mr weather</b></A> : The scammers are getting more sophisticated.  Keep your guard up folks!<br><SMALL>--<br>"It's all coming down!!" - Mike Holmes</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15802287</guid>
<pubDate>Fri, 31 Mar 2006 20:37:53 EDT</pubDate>
</item>

<item>
<title>Re: [Serious] Certapay Scam</title>
<link>http://www.dslreports.com/forum/remark,15802228</link>
<description><![CDATA[<A HREF="/useremail/u/818722"><b>andyb</b></A> : After clicking on the bank link for scotia i can see that it reads open third party..... in the status bar.Then i proceded to open the actual scotia site where my banking is done.https on my banks site none on the link posted above.Damn good job really if you call copying and redirecting links to more fake pages a job.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15802228</guid>
<pubDate>Fri, 31 Mar 2006 20:28:57 EDT</pubDate>
</item>

<item>
<title>Re: [Serious] Certapay Scam</title>
<link>http://www.dslreports.com/forum/remark,15802167</link>
<description><![CDATA[<A HREF="/useremail/u/1334843"><b>delenn13</b></A> : I just got an email from Certapay...<br><br>ITS FAKE>>>LOL>>><br><br>Thank-you for taking the time to notify CertaPay regarding the unsolicited email which you received.<br><br>Please do not respond to it. Just delete it.<br><br>We are aware of the issue and our technical department already took the necessary action to block the website. CertaPay has taken steps to shut-down the source of the distribution and are working closely with law enforcement on this issue.<br><br>We thank you for your patience and look forward to resolve this issue.<br><br>*Registered trademark of Interac Inc. Used under license.<br><br>Sincerely,<br>Therese<br><br>The CertaPay Support Team<br>Email: info@certapay.com<br>Phone: 1-888-238-6433<br>(Monday-Friday, 9a-5p ET).<br><br>Website: &raquo;<A HREF="http://www.certapay.com" >www.certapay.com</A><br><br>CertaPay, a division of Acxsys Corporation<br><SMALL>--<br>"Dismissed. That's a Starfleet expression for 'Get out.'"    Captain Kathryn Janeway</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15802167</guid>
<pubDate>Fri, 31 Mar 2006 20:24:06 EDT</pubDate>
</item>

<item>
<title>Re: [Serious] Certapay Scam</title>
<link>http://www.dslreports.com/forum/remark,15802153</link>
<description><![CDATA[<A HREF="/useremail/u/706206"><b>jojadi76</b></A> : Report that email to certapay.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15802153</guid>
<pubDate>Fri, 31 Mar 2006 20:18:08 EDT</pubDate>
</item>

<item>
<title>Re: [Serious] Certapay Scam</title>
<link>http://www.dslreports.com/forum/remark,15802152</link>
<description><![CDATA[<A HREF="/useremail/u/818722"><b>andyb</b></A> : easy to tell its fake.at least for me since its not https.the certa pay help site is legit thou as far as i have looked but the link they want you to go to is not.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15802152</guid>
<pubDate>Fri, 31 Mar 2006 20:17:58 EDT</pubDate>
</item>

<item>
<title>Re: [Serious] Certapay Scam</title>
<link>http://www.dslreports.com/forum/remark,15802138</link>
<description><![CDATA[<A HREF="/useremail/u/248514"><b>mlerner</b></A> : <div class="bquote"><SMALL>said by  corster <A HREF="/useremail/u/590325"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>actually, it's fake, but a pretty damn good one.<br> </DIV>uhh, yes it is. <br><br>   Domain Name: SSL-CERTAPAY.COM<br>   Registrar: ONLINE SAS<br>   Whois Server: whois.bookmyname.com<br>   Referral URL: &raquo;<A HREF="http://www.bookmyname.com" >www.bookmyname.com</A><br>   Name Server: NS1.NATURALNC.NET<br>   Name Server: NS2.NATURALNC.NET<br>   Status: ACTIVE<br>   Updated Date: 31-mar-2006<br>   Creation Date: 31-mar-2006<br>   Expiration Date: 31-mar-2007<br><br>   Domain Name: CERTAPAY.COM<br>   Registrar: NETWORK SOLUTIONS, LLC.<br>   Whois Server: whois.networksolutions.com<br>   Referral URL: &raquo;<A HREF="http://www.networksolutions.com" >www.networksolutions.com</A><br>   Name Server: NS1-AUTH.Q9.COM<br>   Name Server: NS2-AUTH.Q9.COM<br>   Status: REGISTRAR-LOCK<br>   Updated Date: 19-jun-2003<br>   Creation Date: 27-apr-2000<br>   Expiration Date: 27-apr-2010]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15802138</guid>
<pubDate>Fri, 31 Mar 2006 20:15:54 EDT</pubDate>
</item>

<item>
<title>Re: [Serious] Certapay Scam</title>
<link>http://www.dslreports.com/forum/remark,15802123</link>
<description><![CDATA[<A HREF="/useremail/u/590325"><b>corster</b></A> : <div class="bquote"><SMALL>said by  noelstrom <A HREF="/useremail/u/796173"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Looks legit, but I don't think it is.  That's almost word for word the email I get when I get $$ from my gf.  The ONLY difference is the web address.  I get &raquo;<A HREF="http://gateway.certapay.com" >gateway.certapay.com</A>, not the gateway.ssl-certapay.com you get.  Also, my GF's name is always in the email as the sender.  Sounds fishy to me<br> </DIV>actually, this is a pretty good fake, but yes, its fake.<br><br>Try clicking a bank. they actually faked all the bank sites too.<br><SMALL>--<br><B>"Ladies and Gentlemen, the next Prime Minister of Canada, Mr. Stephen Harper"</B><BR><A HREF="http://www.conservative.ca">Conservative Party of Canada</A><BR></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15802123</guid>
<pubDate>Fri, 31 Mar 2006 20:14:03 EDT</pubDate>
</item>

<item>
<title>Re: [Serious] Certapay Scam</title>
<link>http://www.dslreports.com/forum/remark,15802116</link>
<description><![CDATA[<A HREF="/useremail/u/796173"><b>noelstrom</b></A> : Looks legit, but I don't think it is.  That's almost word for word the email I get when I get $$ from my gf.  The ONLY difference is the web address.  I get &raquo;<A HREF="http://gateway.certapay.com" >gateway.certapay.com</A>, not the gateway.ssl-certapay.com you get.  Also, my GF's name is always in the email as the sender.  Sounds fishy to me<br><SMALL>--<br><B>My name is noelstrom, and I approve this message.</B>  www.myspace.com/noelstrom</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15802116</guid>
<pubDate>Fri, 31 Mar 2006 20:12:43 EDT</pubDate>
</item>

<item>
<title>Re: [Serious] Certapay Scam</title>
<link>http://www.dslreports.com/forum/remark,15802083</link>
<description><![CDATA[<A HREF="/useremail/u/590325"><b>corster</b></A> : actually, it's fake, but a pretty damn good one.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15802083</guid>
<pubDate>Fri, 31 Mar 2006 20:08:01 EDT</pubDate>
</item>

<item>
<title>[Serious] Certapay Scam</title>
<link>http://www.dslreports.com/forum/remark,15802046</link>
<description><![CDATA[<A HREF="/useremail/u/1334843"><b>delenn13</b></A> : I am including a copy of the email I just got from my Sympatico account which ironically is the last day I can use it since I am now with Cogeco(so yes it has my email addy but is in the process of being closed). I have already forwarded this to Certapay..which is a legit company( I guess you could call it the Canadian answer to PayPal) endorsed by the 5 major banks and am waiting a reply but I don't know this person who is supposedly sending me this money or why anyone would be sending this money to me so I am betting dollars to donuts this is a scam.<br><br>Not to mention I googled it and I found several sites like this :&raquo;<A HREF="http://www.antionline.com/history/topic.php/267658-1.html" >www.antionline.com/history/topic&middot;&middot;&middot;8-1.html</A><br><br>Here's the email:<br><br>From :   <br>Sent :  March 31, 2006 10:10:26 AM <br>To :   <br>Subject :  INTERAC: Email Money Transfer <br>  <br>  |  |  | Inbox <br> <br>MIME-Version: 1.0 <br>Received: from tomts30-srv.bellnexxia.net ([209.226.175.104]) by bay0-pamc1-f13.bay0.hotmail.com with Microsoft SMTPSVC(6.0.3790.1830); Fri, 31 Mar 2006 13:10:33 -0800 <br>Received: from toip6.bellnexxia.net ([209.226.175.174]) by tomts30-srv.bellnexxia.net (InterMail vM.5.01.06.13 201-253-122-130-113-20050324) with ESMTP id  for ; Fri, 31 Mar 2006 16:10:33 -0500 <br>Received: from adsl-flat-basic-216.84-47-52.telecom.sk ([84.47.52.216]) by toip6.bellnexxia.net with SMTP; 31 Mar 2006 16:10:29 -0500 <br>Received: (qmail 6834 by uid 541); Fri, 31 Mar 2006 11:10:26 +0100 <br>X-Message-Info: moY6YVwXQ471ThT30mzjxfBlTT4BlunI3jzvUgxDt4o= <br>Return-Path: delenn_5@shaw.ca <br>X-OriginalArrivalTime: 31 Mar 2006 21:10:34.0067 (UTC) FILETIME=[8CB87A30:01C65507] <br>Dear delenn@sympatico.ca,<br><br>INTERAC Email Money Transfer.<br><br>Amount: $140.00 (CAD)<br><br>Sender's Message: how it's going?<br><br>Expiry Date: 28 Apr 2006<br><br>Action Required:<br>To deposit your money, click here:<br>&raquo;<A HREF="http://gateway.ssl-certapay.com/RP.do/?pID=I82sHMZ91zg%3D" >gateway.ssl-certapay.com/RP.do/?&middot;&middot;&middot;Z91zg%3D</A><br><br>Trouble with the link? Copy the link and paste it into your web <br>browser address bar. Please make sure all the characters after the <br>"pID=" are present.<br><br>Need help?<br>&raquo;<small>https</small>://<A HREF="https://www.certapay.com/ca/oon/en/help">www.certapay.com/ca/oon/en/help</A><br><br>---------------------------------------------------------<br>What is an INTERAC Email Money Transfer?<br>If you have an email address and online banking password at a <br>participating bank, you can send and receive money quickly and easily.<br>Email carries the notice while the banks securely transfer the money <br>using existing payment networks. If your bank does not yet offer <br>INTERAC Email Money Transfers, you can still deposit transfers to any <br>bank account in Canada. Click <br>&raquo;<small>https</small>://<A HREF="https://www.certapay.com/en/personalPayments/FAQs.html">www.certapay.com/en/personalPaym&middot;&middot;&middot;AQs.html</A> for details.<br><br>Pour voir les details du virement en fran&sect;ais, cliquez sur le lien <br>ci-dessous : <br>&raquo;<A HREF="http://gateway.ssl-certapay.com/RP.do?pID=I82sHMZ91zg%3D?=fr" >gateway.ssl-certapay.com/RP.do?p&middot;&middot;&middot;g%3D?=fr</A>.<br><br>I did go to the sites to check it out and it does a good pretty good impression of the real site. So guys be careful if you use the real Certapay. I could use the 140.00 but I am NOT that greedy. Just seemed to surreal to be true.<br> <br><SMALL>--<br>"Dismissed. That's a Starfleet expression for 'Get out.'"    Captain Kathryn Janeway</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15802046</guid>
<pubDate>Fri, 31 Mar 2006 20:02:35 EDT</pubDate>
</item>

</channel>
</rss>
