Stuka Stunt Control Line Forum
Archive, 2000–2021 · recovered from the Internet Archive
Forums › Stuka Stunt Main Forum

A REAL PayPal scam!

Stuka Stunt Main Forum · 9 of 9 known posts recovered

cyberflyer · Jan 20, 2004 07:32 PM

#0 source
I got a piece of email today sent to the address I use for PayPal that appeared to be an 'Auction Money Request Cancelled" message from Paypal.

It referenced a transation in 2000 that I might have made with an account "jetexman" for some ten dollars or so, saying that the guy with the account was cancelling the request for the money.

Then there was a bunch of really official sounding stuff warning me never to give away my Paypal password and a link to h t t p s://PayPal.com/prq/Id=some long number, for me to log in to Paypal if I wished to check this out.

This combines some clever social engineering with some modestly clever HTTP hacking. Someone has apparently gotten hold of some out of date PayPal transaction data and is sending these messages around telling folks the request for payment has been canceled. The transaction is so old that it falls outside the range of casual memory and thus the receipient is motivated by curiosity to log into PayPal to check it out.

The link on the page is NOT a link to the PayPal home page, but rather to a clone that simply asks for your password to log into your account. DON"T log in!!! That is where your password is captured and who knows where they will send you--chances are they will remotely sent you to your account page logged in and you will NOT REALIZE your password was logged by a scam artist on the way by.

The mail headers tell you in text that they come from paypal.com's mail server but the IP address (in parens because the mail server can't verify the reverse DNS) gives away the fact that this mail came from someone at Yahoo--any one of a billion people.

If you get this email, use your mail program to expand the headers to Show All Headers and then forward the email in that state to the addresses:

[email protected]
[email protected]

leaving everything in the email intact.

This is a subtle bugger, none of the usual gif for text fakery. And the link they give you is an honest link to the paypal domain, but not to a legitimate home page. I did not bother to deduce the details but the /prq/id=somelongnumber string at the end of the link is what does the magic and the page you get to is the villian that does the actual damage.

And now back to your regularly scheduled discussion of stunt.

The Cyberflyer.

If it were easier than this, it
wouldn't be called a hack.

tperry2054 · Jan 20, 2004 08:24 PM

#1 source
Cyber

I just got one saying that they made a mistake with my fees. Checking the header info turns out it was from dingdong-1 the idiots must really think everyone is a bozo. I sent the message to [email protected]. Do they really pursue these? I am so gun-shy of the petty crooks out in cyberspace that I opened a separate bank account just for ebay/paypal and never keep much more than the minimum in it until I get a statement from ebay or I want to pay using paypal. At that time I transfer funds from my normal account. I don't want my funds tied up while the law is figuring it out.

Tom

LeagueCityRalph · Jan 20, 2004 09:45 PM

#3 source
Ebay, PayPal and your banks will NEVER ask for your passwords/PINs/etc on-line or over the phone. Even my ISP says, "NO! Don't tell me your password; just enter it!"

Any attempt to have you reveal your password or PIN should be viewed as fraudulent, and you should refuse. And you should report the attempt, although Ebay religiously refuses to pursue these reports.

They still feel (erroneously, I think) that if they don't recognize the problem, that they are not responsible. I believe someone will eventually prove them wrong, and expensively so . . .

Old Sourdough · Jan 21, 2004 05:28 AM

#7 source
LAST EDITED ON Jan-21-04 AT 05:32 AM (CDT)
 
Ralph,

My experience with eBay's persistence in running down spoof activities is at a 180° variance with yours. They chased down and found a person in Rumania (at least that's where the originating ISP was located) who somehow seized control of my account, changed the password, security question and the contact email address. and offered some desirable and very expensive merchandise for sale under that account. The listing/selling fees would have been billed to my credit card on file with eBay and I would have been liable for those fees. In addition, I highly doubt that the merchandise existed, so the eventual high bidder(s) would have paid for goods they didn't receive and I would have some major negative feed back as well as the possibility of being liable for the amounts paid by those buyers for those goods--all to the tune of over $8,000!

The online security folks were extremely helpful, although the folks who answered the toll free (voice) help line were not. I did get the situation resolved, but I am now VERY careful to sign out every time I leave the page and I guard my information extremely carefully!

The folks who mentioned that the crooks are getting smarter and more sophisticated are right on point! Guard your private information zealously! Keep your AV Software current!

Above all, if something doesn't look or feel right to you, trust that instinct! Check everything VERY carefully before entering any personal information that could lead to the compromise of your assorted user names and pass words! With PayPal and eBay, use those "spoof" email addresses. You should shortly receive a return email advising you whether and email you've received is legitimate or not. It's worth any small wait for a response to confirm that a message IS legitimate before responding to it.

The Old Sourdough
Beer Can Cove, Alaska, US of A

cyberflyer · Jan 21, 2004 07:22 AM

RE: A real PayPal misconception#8 source
>... although Ebay religiously refuses to pursue these reports.
>

What?

Whatever your experience that leads you to make that statement is unique at the very least.

eBay knows that their business model is based on the users trusting the system and each other. It's a huge testimate to the basic good will of most humans that they got as far as they did. If word gets out you cannot trust ebay, they will lose business. So even if you are cynical, it's in their best business interest to step on transgressors.

And the anti spoofers derive just as much pleasure tracking down a spoofer as the spoofer does spoofing the civilians.

So I believe your belief in their "religion" is not a credible assertion.

Show all the headers and forward the email.

If nothing else, it will be good for your karma.

Cy,


If it were easier than this, it
wouldn't be called a hack.

cyberflyer · Jan 20, 2004 10:48 PM

#4 source
>Cy
>
> I sent the message to [email protected].
> Do they really pursue these?
>
>Tom

Yes.

But in order for them to have anything to work with you HAVE to use your mail reader/browser settings to display the full headers, which then shows a bunch of incomprehensible stuff you normally don't want to see. The message has to be in that format on your screen when you forward it, or the support guys won't have any clues to work with. They can't expand the headers of the message you forward. The exact means vary from mail reader to mail reader, but a fully expanded set of headers would look something like this:

----

From: [email protected]

Subject: Auction Money Request Cancelled

Date: January 20, 2004 12:46:01 PM MST

To: [email protected]

Return-Path: <[email protected]>

Received: from smtp-outbound.nix.paypal.com (64.4.240.67) by airspacemag.com with ESMTP (Eudora Internet Mail Server 3.2.2) for <[email protected]>; Tue, 20 Jan 2004 12:46:04 -0700

Received: from web27.sc5.paypal.com (web92.nix.paypal.com <10.192.2.92>) by smtp-outbound.nix.paypal.com (Postfix) with SMTP id 6B8FA4F5A09 for <[email protected]>; Tue, 20 Jan 2004 11:46:01 -0800 (PST)

Received: (qmail 26654 invoked by uid 99); 20 Jan 2004 19:46:01 -0000

Message-Id: <[email protected]>

Content-Type: text/plain; charset=windows-1252

---

As opposed to:

---

From: [email protected]
Subject: Auction Money Request Cancelled
Date: January 20, 2004 12:46:01 PM MST
To: [email protected]

---

Which tells the guys nothing, really, since that much can be faked by a good mail spammer program.

The other thing to remember is that the tech support guys are fighting World War III trying to deal with this kind of thing, so you will probably just get a form letter in reply, if you get anything at all. But they will be really happy to have proof of the trail of transmission and timestamps which will allow them to come close to figuring out who is sending the info.

I had a similar password extraction attempt spoofing my online banking account and had to get on the phone to the bank and harrass my way through several layers of basic brain-dead customer service until I finally got the email address of a person who was actually working the problem. The vanilla tech support guys were all for having me just paste the email into a form on the web, which would not have done any good.

If you forward an expanded header version of the mail you recieve to the proper address at the responsible organization, it WILL be useful.

And bear in mind that there are websites as useful to the spammers/script kiddies as SSWF is to us, filled with instructions on how to do this kind of thing. So when you get a similar mail the next day, don't assume the affected company does not care. Take the time to forward that mail, too, as it's more than likely a different asshole using the same recipe to stir up trouble.

And now, once again, back to your regularly scheduled discussion of stunt.

At least I hope that is still going on...

Cy

If it were easier than this, it
wouldn't be called a hack.

Randy · Jan 20, 2004 11:42 PM

#5 source
I'm, with Jerry Pournelle. Something really ugly and very permanent needs to happen to people like this to discourage further nonsense.

Randy Powell

PeterOK · Jan 20, 2004 08:56 PM

#2 source
Thanks for the alert, Cy.

I have occasion to browse the Bay so its a timely warning.

We need to be very suspicious of any emails, and their included web-links, that seek to induce us to reveal personal data... without getting paranoid, of course!

I have also had emails from banks here in Australia asking me to respond, by clicking on a web-link, and provide personal details so they can update their files with regard to my access codes, PIN numbers, etc. even when I don't have any connection with that banking establishment.

Gotta be vigilant about potential net-scams as they are becoming more sophisticated in their methods and looking more authentic in their appearance...


Peter O'Keeffe

jacobite · Jan 21, 2004 02:41 AM

To any other Aussies on here.....#6 source
There is a scam going round Oz at the moment.
You get an E-mail asking if you want a high-paying part time job selling wide-screen TV's.
All you have to do is supply your bank account details so they can pay you, etc, etc.

Dave Moffitt

Dave Moffitt