cyberflyer · Jan 20, 2004 07:32 PM
#0 sourceIt referenced a transation in 2000 that I might have made with an account "jetexman" for some ten dollars or so, saying that the guy with the account was cancelling the request for the money.
Then there was a bunch of really official sounding stuff warning me never to give away my Paypal password and a link to h t t p s://PayPal.com/prq/Id=some long number, for me to log in to Paypal if I wished to check this out.
This combines some clever social engineering with some modestly clever HTTP hacking. Someone has apparently gotten hold of some out of date PayPal transaction data and is sending these messages around telling folks the request for payment has been canceled. The transaction is so old that it falls outside the range of casual memory and thus the receipient is motivated by curiosity to log into PayPal to check it out.
The link on the page is NOT a link to the PayPal home page, but rather to a clone that simply asks for your password to log into your account. DON"T log in!!! That is where your password is captured and who knows where they will send you--chances are they will remotely sent you to your account page logged in and you will NOT REALIZE your password was logged by a scam artist on the way by.
The mail headers tell you in text that they come from paypal.com's mail server but the IP address (in parens because the mail server can't verify the reverse DNS) gives away the fact that this mail came from someone at Yahoo--any one of a billion people.
If you get this email, use your mail program to expand the headers to Show All Headers and then forward the email in that state to the addresses:
[email protected]
[email protected]
leaving everything in the email intact.
This is a subtle bugger, none of the usual gif for text fakery. And the link they give you is an honest link to the paypal domain, but not to a legitimate home page. I did not bother to deduce the details but the /prq/id=somelongnumber string at the end of the link is what does the magic and the page you get to is the villian that does the actual damage.
And now back to your regularly scheduled discussion of stunt.
The Cyberflyer.
If it were easier than this, it
wouldn't be called a hack.
the idiots must really think everyone is a bozo. I sent the message to
