republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Spam, Scam and Phishbusters » [Phishing] ALERT!! New Vicious PAYPAL phishing
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
[Spam] Spamcop »
« [Spam] It seems i all been getting spam from one domain all this  
AuthorAll Replies

MGD
Premium,MVM
join:2002-07-31
Fort Lauderdale, FL

reply to K Patterson
Re: [Phishing] ALERT!! New Vicious PAYPAL phishing

K Patterson See Profile is spot on, that is precisely how it works. A snippet of the source code confirms it. The phishers login.php script has a line: href="ht*tps://www.paypal.com/cgi-bin/webscr?cmd=_login-run

<html>
<head>
<title>PayPal - Log In</title>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<link href="data.css" rel="stylesheet" type="text/css">
</head>

<body>
<TABLE width="620" height="68" border=0 align=center cellPadding=0 cellSpacing=0 class=main>
<TBODY>
<TR>
<TD width="200" noWrap><A><IMG
height=50 src="img/logo.gif" width=200
border=0></A></TD>
<TD>&nbsp;</TD>
<TD width="161" align=right noWrap class=pptext><A href="https://www.paypal.com/cgi-bin/webscr?cmd=_registration-run"><strong>Sign&nbsp;Up</strong></A> | <a href="https://www.paypal.com/cgi-bin/webscr?cmd=_login-run">Log&nbsp;In</a> | <A href="https://www.paypal.com/cgi-bin/webscr?cmd=_help-ext&source_page=p/gen/jobs-outside">Help</A></TD>
</TR>
<TR>
<TD height="18" noWrap>&nbsp;</TD>
<TD width="259">&nbsp;</TD>
<TD class=pptext noWrap align=right>&nbsp;</TD>
</TR>
</TBODY>
</TABLE>
<table width="100%" height="63" border="0" cellpadding="0" cellspacing="0" background="img/bg.gif">

Banning the IP would be an effective method to block this validation and retrieval process.

MGD

K Patterson
Premium,MVM
join:2006-03-12
Columbus, OH
·RoadRunner Cable

reply to tdumaine
Assuming that the Pay Pal system keeps the client database on a server different from their WWW server, that is exactly how it is set up.

The phisher does not access the database directly. It logs in to the WWW site just like any other PayPal member, using the user name and password which the yokel provides.

Until it bans the IP associated with the phisher, there is no way to separate this fake inquiry from a legitimate customer log-in.

I think it would have been better to have said "sceen scraper" in my earlier post.

tdumaine

join:2004-03-14
Redmond, WA
·Comcast

reply to MGD
Dude,

Say im runnin a paypal like service. Lets call it tompal.

Tompal has 2 servers that runs it. When you go to tompal, server #1 presents you with a login page. Server 1 checks your username/password with my server#2 wich contains all that.

Set server 2 up to not allow any connections other than from server 1.

Then the phishers in china wouldnt work cause server 2 wont auth to the outside world.

Why cant they set it up like this?
Forums » Up and Running » Security » Spam, Scam and Phishbusters[Spam] Spamcop »
« [Spam] It seems i all been getting spam from one domain all this  


Tuesday, 01-Dec 09:16:42 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [62] Baltimore To Ban Lazy Cable Installs
· [50] Broadband Killed The Game Console
· [36] Rural Carriers Quickly Embracing Fiber
· [33] AT&T Top Lobbyist Cicconi Has His Feelings Hurt
· [29] Charter Exits Chapter 11
· [22] Midcontinent Socked With Easement Lawsuit
· [4] Monday Evening Links
· [3] Monday Morning Links
· [3] ACTA: Global Three Strikes
· [2] Vivendi Agrees, Comcast/NBC Deal Soon
Most people now reading
· Windows 7 boot manager editing questions [Microsoft Help]
· [Rant] called out sick! [Rants, Raves, and Praise]
· Heating - my dad gave me this advice... [Home Repair & Improvement]
· Is Microsoft Technet ok to use for my family PC's? [Microsoft Help]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· Considering Leaving Vonage, who should I Consider? [VOIP Tech Chat]
· IMG 1.7 (IMG Updates and Discussion) [Verizon FIOS TV]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]
· A little freaky, not sure if its legit. [Spam, Scam and Phishbusters]
· Why is VoIP Better than POTS? [VOIP Tech Chat]