republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Spam, Scam and Phishbusters » [Scam] ebay message in ebay system that possibly exposes PW
Search Topic:
Uniqs:
410
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
[Scam] Car Scam? »
« Nigerian Idiots ' Phishing ' for Yahoo email accounts  
AuthorAll Replies


Andrew J
Premium
join:2001-11-09
Lancaster, PA
clubs:
·Comcast
·Vonage
·Verizon Online DSL

[Scam] ebay message in ebay system that possibly exposes PW

This message was sent inside the ebay system. From what looks like a current user.
I believe the account is hijacked.
I believe going to the site exposes my ebay logon somehow.
Maybe this is not new or special but it is to me.

No one on ebay is using my pics. The numbers are my auction number. So the message must be completely bogus. This is a message sent to my account inside ebay.
I added DOT in place of ".".
===============

Hello,

I am very interested in your item, but I have some doubts, as I have seen another eBay member, selling the same item as yours. I think he might have stolen your pictures and description. Please take a look and let me know what's going on.
You can still see the item here: »pescas DOT net/pescas/230201818845.item
--
Best Team.


antiphishing
Phishing Scam Terminator
Premium
join:2004-06-09
Wilkes Barre, PA

said by Andrew J See Profile :

This message was sent inside the ebay system. From what looks like a current user.
I believe the account is hijacked.
I believe going to the site exposes my ebay logon somehow.
Maybe this is not new or special but it is to me.

»pescas DOT net/pescas/230201818845.item
canonical name pescas.net.
aliases
addresses 81.20.240.65
Domain Name: PESCAS.NET
Registrar: NAMESECURE.COM
Whois Server: whois.namesecure.com
Referral URL: »www.namesecure.com
Name Server: NS.CYBERMAP.PT
Name Server: NS2.CYBERMAP.PT
Status: clientTransferProhibited
Status: clientUpdateProhibited
Updated Date: 05-jun-2007
Creation Date: 03-jan-2003
Expiration Date: 03-jan-2010

inetnum: 81.20.240.0 - 81.20.255.255
netname: TVACOREANA
descr: Cabo TV Acoreana
descr: Av. Antero de Quental, 9
descr: Edificios dos CTT, 1 Andar - 9500 Ponta Delgada
country: PT

Connect to 81.20.240.65 on port 80 ... ok
GET /pescas/230201818845.item HTTP/1.1
Host: pescas.net
Connection: close
User-Agent: Web-sniffer/1.0.25 (+»web-sniffer.net/)
Accept-Encoding: gzip
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5[CRLF]
Accept-Language: en-us,en;q=0.5
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Referer: »web-sniffer.net/
Server: Apache/2.2.2 (Fedora)
--

Specializing in "takes downs" of phishing and advance fee scams
Send your Phishing/Advance fee scams to: phish@antihotmail.com
»/profile/1021645
»fraudwatchers.org/forums/

garys_2k

join:2004-05-07
Farmington, MI
·Future Nine Corpor..
·Vonage

reply to Andrew J
I get bounced to »www.danapoint.com/ where there are no forms or redirects of any kind.

Trying to retrieve that file "230201818845.item" with wget gets nothing. Are you certain that this is correct?


nwrickert
sand groper
Premium,MVM
join:2004-09-04
Geneva, IL
I retrieved that page using wget. No problems at all. It's a pretty standard eBay phish page.


Doctor Olds
I Need A Remedy For What's Ailing Me.
Premium,VIP
join:2001-04-19
1970 442 W30
clubs:

reply to antiphishing
said by antiphishing See Profile :

Connect to 81.20.240.65 on port 80 ... ok
GET /pescas/230201818845.item HTTP/1.1
Host: pescas.net
Connection: close
User-Agent: Web-sniffer/1.0.25 (+»web-sniffer.net/)
Accept-Encoding: gzip
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5[CRLF]
Accept-Language: en-us,en;q=0.5
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Referer: »web-sniffer.net/
Server: Apache/2.2.2 (Fedora)
This info isn't showing the needed Response Headers and is only showing what the Web-sniffer page is sending to the tested remote server with a close response and it is not showing what response is being returned from the tested server.

This is the important "Response Header" info you are leaving out.

HTTP Response Header
Name Value Delim
HTTP Status Code: HTTP/1.1 200 OK
Date: Sun, 16 Dec 2007 12:28:20 GMT CRLF
Server: Apache/2.2.2 (Fedora) CRLF
X-Powered-By: PHP/5.1.6 CRLF
Connection: close CRLF
Transfer-Encoding: chunked CRLF
Content-Type: text/html CRLF


Then using the suggested Windows Tool ID Serve it gives you this output.

Initiating server query ...
Looking up IP address for domain: pescas.net
The IP address for the domain is: 81.20.240.65
Connecting to the server on standard HTTP port: 80
[Connected] Requesting the server's default page.
The server returned the following response headers:
HTTP/1.1 200 OK
Date: Sun, 16 Dec 2007 12:35:59 GMT
Server: Apache/2.2.2 (Fedora)
X-Powered-By: PHP/5.1.6
Connection: close
Transfer-Encoding: chunked
Content-Type: text/html
Query complete.

See the difference?

--
What’s the point of owning a supercar if you can’t scare yourself stupid from time to time?


Andrew J
Premium
join:2001-11-09
Lancaster, PA
clubs:
Thanks.
Ebay doesn't care and the account that sent that is still active.
They haven't even sent the form letter saying they're looking into it.
--
Best Team.
Forums » Up and Running » Security » Spam, Scam and Phishbusters[Scam] Car Scam? »
« Nigerian Idiots ' Phishing ' for Yahoo email accounts  


Saturday, 28-Nov 13:06:26 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [122] Time Warner Cable Fires Broadside At Broadcasters
· [112] New AT&T Ad Campaign Hits Back At Verizon
· [96] Apple Joins AT&T Verizon Snark Fest
· [87] New Bill Takes Aim At Higher Verizon ETFs
· [75] TiVo Sees Record Customer Losses
· [70] Verizon CEO: Hulu Will Be Dead Soon
· [69] In-Flight Internet Headed For Bumpy Landing?
· [62] Thanksgiving Open Thread
· [60] Weekend Open Thread
· [40] EFF Wages War On Fine Print
Most people now reading
· [Newsgroups] Newzleech down? [Filesharing Software]
· Why does it take so long? Mail question [General Questions]
· Windows 7 boot manager editing questions [Microsoft Help]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· Whats the big deal about being "Old School"....? [World of Warcraft]
· Using AirMax to provide triple play services? [Wireless Service Providers]
· DIR-655 New Beta 1.32b09 [D-Link]
· Hosts file attributes set to system and hidden [Security]
· Gizmo5 has added a Google Voice section in its members area. [VOIP Tech Chat]
· [Wireless] Linksys WMP54g v4.1 and Windows 7 x64 [Linksys]