<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>[Scam] ebay message in ebay system that possibly exposes PW in Spam, Scam and Phishbusters</title>
<link>http://www.dslreports.com/forum/r19625660</link>
<description></description>
<language>en</language>
<pubDate>Tue, 01 Dec 2009 10:08:59 EDT</pubDate>
<lastBuildDate>Tue, 01 Dec 2009 10:08:59 EDT</lastBuildDate>

<item>
<title>Re: [Scam] ebay message in ebay system that possibly exposes PW</title>
<link>http://www.dslreports.com/forum/remark,19634192</link>
<description><![CDATA[<A HREF="/useremail/u/512414"><b>Andrew J</b></A> : Thanks. <br>Ebay doesn't care and the account that sent that is still active.<br>They haven't even sent the form letter saying they're looking into it.<br><small>--<br><A HREF="http://www.dslreports.com/forum/disco">Best Team</a>.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19634192</guid>
<pubDate>Sun, 16 Dec 2007 16:26:16 EDT</pubDate>
</item>

<item>
<title>Re: [Scam] ebay message in ebay system that possibly exposes PW</title>
<link>http://www.dslreports.com/forum/remark,19632200</link>
<description><![CDATA[<A HREF="/useremail/u/372021"><b>Doctor Olds</b></A> : <div class="bquote"><small>said by  antiphishing <A HREF="/useremail/u/1021645"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Connect to 81.20.240.65 on port 80 ... ok<br>GET /pescas/230201818845.item HTTP/1.1<br>Host: pescas.net<br>Connection: close<br>User-Agent: Web-sniffer/1.0.25 (+&raquo;web-sniffer.net/)<br>Accept-Encoding: gzip<br>Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5[CRLF]<br>Accept-Language: en-us,en;q=0.5<br>Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7<br>Referer: &raquo;web-sniffer.net/<br>Server: Apache/2.2.2 (Fedora)</div>This info isn't showing the needed Response Headers and is only showing what the Web-sniffer page is <b>sending</b> to the tested remote server with a close response and it is not showing what response is being returned from the tested server.<br><br>This is the important "Response Header" info you are leaving out.<br><pre><br>HTTP Response Header<br>Name&#9;Value&#9;Delim<br>HTTP Status Code: HTTP/1.1 200 OK<br>Date:&#9;Sun, 16 Dec 2007 12:28:20 GMT&#9;CRLF<br>Server:&#9;Apache/2.2.2 (Fedora)&#9;CRLF<br>X-Powered-By:&#9;PHP/5.1.6&#9;CRLF<br>Connection:&#9;close&#9;CRLF<br>Transfer-Encoding:&#9;chunked&#9;CRLF<br>Content-Type:&#9;text/html&#9;CRLF<br></pre><br><br>Then using the suggested Windows Tool <A HREF="http://www.grc.com/id/idserve.htm">ID Serve</a> it gives you this output.<br><br>Initiating server query ...<br>Looking up IP address for domain: pescas.net<br>The IP address for the domain is: 81.20.240.65<br>Connecting to the server on standard HTTP port: 80<br>[Connected]  Requesting the server's default page.<br>The server returned the following response headers:<br>HTTP/1.1 200 OK<br>Date: Sun, 16 Dec 2007 12:35:59 GMT<br>Server: Apache/2.2.2 (Fedora)<br>X-Powered-By: PHP/5.1.6<br>Connection: close<br>Transfer-Encoding: chunked<br>Content-Type: text/html<br>Query complete.<br><br>See the difference?<br><br><small>--<br><A HREF="http://tinyurl.com/ylb8u9">What&#146;s the point of owning a supercar if you can&#146;t scare yourself stupid from time to time?</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19632200</guid>
<pubDate>Sun, 16 Dec 2007 09:20:30 EDT</pubDate>
</item>

<item>
<title>Re: [Scam] ebay message in ebay system that possibly exposes PW</title>
<link>http://www.dslreports.com/forum/remark,19626398</link>
<description><![CDATA[<A HREF="/useremail/u/1070900"><b>nwrickert</b></A> : I retrieved that page using wget.  No problems at all.  It's a pretty standard eBay phish page.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19626398</guid>
<pubDate>Fri, 14 Dec 2007 23:54:25 EDT</pubDate>
</item>

<item>
<title>Re: [Scam] ebay message in ebay system that possibly exposes PW</title>
<link>http://www.dslreports.com/forum/remark,19625809</link>
<description><![CDATA[<A HREF="/useremail/u/1003137"><b>garys_2k</b></A> : I get bounced to &raquo;<A HREF="http://www.danapoint.com/" >www.danapoint.com/</A> where there are no forms or redirects of any kind.<br><br>Trying to retrieve that file "230201818845.item" with wget gets nothing. Are you certain that this is correct?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19625809</guid>
<pubDate>Fri, 14 Dec 2007 21:44:42 EDT</pubDate>
</item>

<item>
<title>Re: [Scam] ebay message in ebay system that possibly exposes PW</title>
<link>http://www.dslreports.com/forum/remark,19625798</link>
<description><![CDATA[<A HREF="/useremail/u/1021645"><b>antiphishing</b></A> : <div class="bquote"><small>said by  Andrew J <A HREF="/useremail/u/512414"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>This message was sent inside the ebay system. From what looks like a current user.<br>I believe the account is hijacked.<br>I believe going to the site exposes my ebay logon somehow.<br>Maybe this is not new or special but it is to me.<br><br>&raquo;<A HREF="http://pescas" >pescas</A> DOT net/pescas/230201818845.item<br> </div>canonical name  &#9;pescas.net.<br>aliases &#9;<br>addresses &#9;81.20.240.65<br> Domain Name: PESCAS.NET<br>   Registrar: NAMESECURE.COM<br>   Whois Server: whois.namesecure.com<br>   Referral URL: &raquo;<A HREF="http://www.namesecure.com" >www.namesecure.com</A><br>   Name Server: NS.CYBERMAP.PT<br>   Name Server: NS2.CYBERMAP.PT<br>   Status: clientTransferProhibited<br>   Status: clientUpdateProhibited<br>   Updated Date: 05-jun-2007<br>   Creation Date: 03-jan-2003<br>   Expiration Date: 03-jan-2010<br><br>inetnum:        81.20.240.0 - 81.20.255.255<br>netname:        TVACOREANA<br>descr:          Cabo TV Acoreana<br>descr:          Av. Antero de Quental, 9<br>descr:          Edificios dos CTT, 1 Andar - 9500 Ponta Delgada<br>country:        PT<br><br>Connect to 81.20.240.65 on port 80 ... ok<br>GET /pescas/230201818845.item HTTP/1.1<br>Host: pescas.net<br>Connection: close<br>User-Agent: Web-sniffer/1.0.25 (+&raquo;<A HREF="http://web-sniffer.net/" >web-sniffer.net/</A>)<br>Accept-Encoding: gzip<br>Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5[CRLF]<br>Accept-Language: en-us,en;q=0.5<br>Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7<br>Referer: &raquo;<A HREF="http://web-sniffer.net/" >web-sniffer.net/</A><br>Server:&#9;Apache/2.2.2 (Fedora)<br><small>--<br><b><br>Specializing in "takes downs" of phishing and advance fee scams<br>Send your Phishing/Advance fee scams to: <A HREF="mailto:phish@antihotmail.com">phish@antihotmail.com</a> <br>&raquo;<A HREF="/profile/1021645">/profile/1021645</A><br>&raquo;<A HREF="http://fraudwatchers.org/forums/" >fraudwatchers.org/forums/</A><br><b></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19625798</guid>
<pubDate>Fri, 14 Dec 2007 21:42:45 EDT</pubDate>
</item>

<item>
<title>[Scam] ebay message in ebay system that possibly exposes PW</title>
<link>http://www.dslreports.com/forum/remark,19625660</link>
<description><![CDATA[<A HREF="/useremail/u/512414"><b>Andrew J</b></A> : This message was sent inside the ebay system. From what looks like a current user.<br>I believe the account is hijacked.<br>I believe going to the site exposes my ebay logon somehow.<br>Maybe this is not new or special but it is to me.<br><br>No one on ebay is using my pics. The numbers are my auction number. So the message must be completely bogus. This is a message sent to my account inside ebay.<br>I added DOT in place of ".".<br>===============<br><br>Hello, <br><br>I am very interested in your item, but I have some doubts, as I have seen another eBay member, selling the same item as yours. I think he might have stolen your pictures and description. Please take a look and let me know what's going on. <br>You can still see the item here: &raquo;<A HREF="http://pescas" >pescas</A> DOT net/pescas/230201818845.item<br><small>--<br><A HREF="http://www.dslreports.com/forum/disco">Best Team</a>.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19625660</guid>
<pubDate>Fri, 14 Dec 2007 21:15:30 EDT</pubDate>
</item>

</channel>
</rss>
