Results 1 to 5 of 5

Thread: New PayPal User/Pass Harvesting Scam?

  1. #1
    Just a Virtualized Geek MrLinus's Avatar
    Join Date
    Sep 2001
    Location
    Redondo Beach, CA
    Posts
    7,323

    New PayPal User/Pass Harvesting Scam?

    I just noticed this on Full Disclosure. Apparently there may be a new PayPal harvesting scam going on. The subject is "PayPal User Agreement 9". It is an html email and found inside is the "user agreement" with the following modification. (I've removed the address but there is an ADSL address in Germany that matches where the xx's and 16s are).


    PHP Code:
                    <TD class=pp_footer>Please do not reply to this e-mailMail sent to this address cannot be
     answered
    . For assistance, [url="http://www.paypal.com@xx.xx.16.16"]log in[/urlto your PayPal account
     
    and choose the "Help" link in the footer of any page.
    <
    BR class=h10>To receive email notifications in 
    plain text instead of HTML 
    ;update your preferences [url="https://www.paypal.com/PREFS-NOTI"]here[/url]. </TD></TR
    A warning and head's up for those with "gulliable" users.
    Goodbye, Mittens (1992-2008). My pillow will be cold without your purring beside my head
    Extra! Extra! Get your FREE copy of Insight Newsletter||MsMittens' HomePage

  2. #2
    AO Ancient: Team Leader
    Join Date
    Oct 2002
    Posts
    5,197
    Thanks Ms. M.

    A note will be going out to my particualar gaggle..... They'd chew down so hard on this one they'd break their teeth.....
    Don\'t SYN us.... We\'ll SYN you.....
    \"A nation that draws too broad a difference between its scholars and its warriors will have its thinking done by cowards, and its fighting done by fools.\" - Thucydides

  3. #3
    Senior Member
    Join Date
    Dec 2002
    Posts
    309
    Thanks MsMitts,

    That why I dont respond to any emails from any financial institutions.I still use the good old mail system for correspondence.Its a good legal record ,in case you need it in future.

    Dr_Evil

  4. #4
    Senior Member
    Join Date
    Jan 2003
    Posts
    1,499
    Yes,

    I recieved this in some of my users inbox's

    if you point to the link it has " www.paypal.com@"Some IP Address" "

    If these people were even remotely clever they would target individual users one at a time and get individual details.

    I mean what are they going to do with A Pile of details ?

    Write a pearl script to transfer all the £4.99 into some other account and hope no one notices.

    I wish poeple would stop doing stupid things like this and others would stop being ignorant of general internet practice and falling for it. !!!

  5. #5
    Senior Member
    Join Date
    Sep 2003
    Posts
    279
    wow, thanks, i use paypal almost daily. I have yet to run into any of those, or atleast i hope not. Thanks for the heads up though.
    AntiOnline Quick Forum Version 2b Click Here
    10010101000000110010001100111

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •