RavenBlog
Black:  ravenblack.net | me | games | books | email | wishlist | rss
Blogs:  Angryblog | As Above | MonkyBlog | Nightshade | Journals
Blimey:  SomethingAwful | Advice
Archives: Last 4 Days | June2001 | July2001 | August2001 | September2001 | October2001 | November2001 | December2001 | January2002 | February2002 | March2002 | April2002 | May2002 | June2002 | July2002 | August2002 | September2002 | October2002 | November2002 | December2002 | January2003 | February2003 | March2003 | April2003 | May2003 | June2003 | July2003 | August2003 | September2003 | October2003 | November2003 | December2003 | January2004 | February2004 | March2004 | April2004 | May2004 | June2004 | July2004 | August2004 | September2004 | October2004 | November2004 | December2004 | January2005 | February2005 | March2005 | April2005 | May2005 | June2005 | July2005 | August2005 | September2005 | October2005 | November2005 | January2006 | February2006 | March2006 | April2006 | May2006 | June2006 | July2006 | August2006 | September2006 | October2006 | November2006 | December2006 | January2007 | February2007 | March2007 | April2007 | May2007 | June2007 | July2007 | August2007 | September2007 | October2007 | November2007 | December2007 | January2008 | February2008 | March2008 | April2008 | May2008 | June2008 | July2008 | August2008 | September2008 | October2008 | November2008 | December2008 | January2009 | March2009 | April2009 | May2009 | July2009 | August2009 | September2009 | February2010 | March2010 | June2010 | July2010 | August2010 | September2010 | October2010 | November2010 | December2010 | February2011 | March2011 | April2011 | May2011 | June2011 | July2011 | August2011 | September2011 | October2011 | December2011 | March2012 | April2012 | May2012 | September2012 | December2012 | March2013 | April2013 | May2013 | June2013 | October2021


Comments on Sunday 18 April 2004:
That's the best Paypal-password-theft spam ever!
Dear (proper paypal email address),

We recently reviewed your account, and suspect that your PayPal account may have been accessed by an unauthorized third party. Protecting the security of your account and of the PayPal network is our primary concern. Therefore, as a preventative measure, we have temporarily limited access to sensitive PayPal account features.
Click below in order to regain access to your account:
https://www.paypal.com/cgi-bin/webscr?cmd=_login-run

For more information about how to protect your account, please visit PayPal's Security Center, accessible via the "Security Center" link located at the bottom of each page of the PayPal website.

We apologize for any inconvenience this may cause, and appreciate your assistance in helping us maintain the integrity of the entire PayPal system. Thank you for your prompt attention to this matter.

Sincerely,
The PayPal Team

Please do not reply to this e-mail. Mail sent to this address cannot be answered. For assistance, log in to your PayPal account and choose the "Help" link in the header of any page.

PayPal Email ID PP198
PayPal Email ID PP316
Note, the link there is safe to look at (open it in a new window, it'll go all full screen and annoying) to poke at and see what fantastic trickery is afoot, but please close the window immediately afterwards, and really really don't put your Paypal password in there. For the less technical reader, the most pertinent thing to note about the trickery is that the address bar you see is not your address bar. Also, it may be slow since the site is probably busily fooling thousands of people - the spam was only received about thirty minutes ago. [21:48]

James
It's a dead site, now. What exactly was the technical trickery?

RavenBlack
It opened itself in a new window with no address bar or status bar, then put a fake address bar at the top of the page (in a separate frame I think), editable and everything. The lack of status bar would hide the fact that the security padlock was missing, and the address bar showed "https://www.paypal.com/" etc (the proper address, anyway) while the actual page was the password-collector. It also went on, in the "confirm your account" pages, to ask for your mother's maiden name, your bank name, bank account number, sort code, credit card number and pin number. Oh the havoc.

James
I've had a couple of these appear using similar tricks; one claimed to be from Visa Security, and fed the information into a host in Germany. I forwarded all the details to Visa (the real Visa!) and received a nice pro-forma thankyou, then nothing more. The big giveaway, of course, is that it was sent to my Whois contact address ;-)

Personally, I found the username trick more convincing - and with a cheap (or trial) SSL certificate, you can get a padlock icon displayed as well.

yardenxanthe
I just took your What Flavour are You quiz and wanted to let you know that I really like it. Yep.

Gecko
Yeah, I've gottenq quite a few of those lately. One was from the "FDIC" telling me that b/c I have violated the PATRIOT act, I had to immidiatly email them back with all sorts of information about my account.
Add Comment:
Name:Comment: (max. 2048 characters)
Email:
Show Email: (if no website)
Website:
No HTML tags allowed.
(Antispam) What is 51 + 49?
Archives: Last 4 Days | June2001 | July2001 | August2001 | September2001 | October2001 | November2001 | December2001 | January2002 | February2002 | March2002 | April2002 | May2002 | June2002 | July2002 | August2002 | September2002 | October2002 | November2002 | December2002 | January2003 | February2003 | March2003 | April2003 | May2003 | June2003 | July2003 | August2003 | September2003 | October2003 | November2003 | December2003 | January2004 | February2004 | March2004 | April2004 | May2004 | June2004 | July2004 | August2004 | September2004 | October2004 | November2004 | December2004 | January2005 | February2005 | March2005 | April2005 | May2005 | June2005 | July2005 | August2005 | September2005 | October2005 | November2005 | January2006 | February2006 | March2006 | April2006 | May2006 | June2006 | July2006 | August2006 | September2006 | October2006 | November2006 | December2006 | January2007 | February2007 | March2007 | April2007 | May2007 | June2007 | July2007 | August2007 | September2007 | October2007 | November2007 | December2007 | January2008 | February2008 | March2008 | April2008 | May2008 | June2008 | July2008 | August2008 | September2008 | October2008 | November2008 | December2008 | January2009 | March2009 | April2009 | May2009 | July2009 | August2009 | September2009 | February2010 | March2010 | June2010 | July2010 | August2010 | September2010 | October2010 | November2010 | December2010 | February2011 | March2011 | April2011 | May2011 | June2011 | July2011 | August2011 | September2011 | October2011 | December2011 | March2012 | April2012 | May2012 | September2012 | December2012 | March2013 | April2013 | May2013 | June2013 | October2021