Jul 24, 2008

Ebay Spoof/phishing Attacks. - fake ebay email detection.

Free Web Hosting, No Ads > CONTRIBUTE > Computers > Computer Security Issues & Exploits
Pages: 1, 2

free web hosting

Ebay Spoof/phishing Attacks. - fake ebay email detection.

sunny
Currnetly there are several jokers out there who try to send fake emails pretending to be from eBay itself.

Such emails may be used to steel personal as well as financial data is the user recieving the mail clicks on the links.

After contacting the ebay Support via email I've got following tips:

I am posting the mail I got from eBay as it is so that the users of Trap17 can also detact an fake email and maintain their privacy.

From: eBay Customer Support <spoof@ebay.com>
To: Cyber Mitra < cyber . mitra @gmail.com>

CODE

Hello,

Thank you for writing to eBay regarding the email you received.

Emails such as this, commonly referred to as "spoof" or "phished"
messages, are sent in an attempt to collect sensitive personal or
financial information from the recipients.

The email you reported was not sent by eBay. We have reported this email
to the appropriate authorities.

In the future, be very cautious of any email that asks you to submit
information such as your credit card numbers or passwords. If you are
ever concerned about an email you receive from eBay, simply follow these
steps:

1. Open a new Web browser and type www.ebay.com into your browser
address field to go directly to the eBay site.

2. On eBay, click on the "My eBay" link at the top of the page and sign
into your account.

3. Check the "My Messages" link located on the left side of the My eBay
page. If an email affects your eBay account, it's now in "My Messages."
Any email sent to your registered eBay email address from eBay or from
another eBay member via eBay's member-to-member communication system
will also appear in "My Messages."

Just remember, if you get an email regarding a problem with your account
or that is requesting personal information, and the email looks like it
is from eBay, please check My Messages first. If it's not there, it's a
fake email.

If you still have any doubt about whether an email message is from eBay,
please forward it to spoof@ebay.com immediately. Do not respond to it or
click any of the links. Do not remove the original subject line or
change the email in any way when you forward it to eBay.

If you have already entered sensitive personal information, financial
information, or your password into a Web site based on a request from a
spoofed email, you should take immediate action to protect your identity
and all of your online accounts. We have developed an eBay Help page
with valuable information regarding the steps you should take to protect
yourself.

http://pages.ebay.com/help/tp/isgw-account...-reporting.html

To review eBay's new tutorial about Spoof Emails, please see the
following Web page:

http://pages.ebay.com/education/spooftutorial/

To help you better protect yourself from fake eBay and PayPal Web sites,
we have developed a feature for the eBay Toolbar called "Account Guard."
Account Guard includes an indicator of when you are on an eBay or PayPal
Web site or a known spoof (or "phishing") site, buttons to report fake
eBay Web sites, and a password notification feature that warns you when
you may be entering your eBay password on an unverified site.

To learn more about the eBay Toolbar with Account Guard, please go to
www.ebay.com, click on "Downloads" at the bottom of the page, and then
click on the "eBay Toolbar" link.

We also recommend that you keep your browser, operating system, and
virus protection software up to date. Check for updates at the "Windows
Update" link on www.microsoft.com and scan your computer for viruses
often.

Once again, thank you for alerting us to the spoof email you received.
Your efforts help keep eBay a safe and fair place to trade.

Regards,

Ande
eBay SafeHarbor
Investigations Team
______________________________
eBay
The World's Online Marketplace! ®
*******************************************

Important: eBay will not ask you for sensitive personal information
(such as your password, credit card and bank account numbers, Social
Security numbers, etc.) in an email. Learn more account protection tips
at:

http://pages.ebay.com/help/confidence/isgw...protection.html

_____________________________________________

For our latest announcements, please check:

http://www2.ebay.com/aw/announce.shtml
_____________________________________________

In order to better serve you, we'd like to occasionally
request feedback on our service. If you would rather
not participate, please click on the link below and send
us an email with the word "REMOVE" in the subject line.
If that does not work, please send an email to the
email address below. Your request will be processed
within 5 days.

mailto:cssremove@ebay.com

 

 

 


Reply

crapoartworks
Thats good to know. wink.gif I once in my hotmail account recieved over 214 emails in my junk folder, all of the addresses were random (ebay...google...others...) and all contained the same virus infected attachment.


I hate spoof emails.

Reply

ashiezai
i always received this kinda spoof emails ... some of them are banks and some of them are ebays ... but it's very easy to detect .... firstly .. the email address is a good thing to spot a spoof ... secondly .. all of these spoofs doesnt use words ... they tend to use an image for it ... that is the whole email is an image ... wherever you click on the letter .. it will bring you to the targetted url .. so be alert when u received these kinda spoof emails ...

Reply

TripleH13
thanks man this is very good to no. i did not no to much about this so thanks for warining ppl about it

Reply

mayank
well that's right there are some people who send these kind of emails...now, either you have to be very carefull about these emails or what you can do is you can use a toolbar from Netcraft and it tells you all those websites which are fake or in other words keeps you safe from phishing smile.gif
The website's address is www.netcraft.com, I hope this tool will help Trap17 members. smile.gif

Reply

Microsoft
unsure.gif i dont really know what are spoof mails but good think i dint get some (dont know but similar descriptions above tell me a bit) i dont want to get one wink.gif

Reply

patelg
I have also recieved one email for Ebay.

Yes, it is image too.

It is regarding updating the account information or they will suspend my account.

I found by looking at from address as it is from ""eBay" <custservice_id_155002@ebay.com>"

Good, that i am using firefox. It has detected the link, when i cliked on image by mistake.

It is always good to have precautions...



Reply

patelg
QUOTE(mayank @ Sep 2 2005, 06:13 AM)
what you can do is you can use a toolbar from Netcraft and it tells you all those websites which are fake or in other words keeps you safe from phishing smile.gif
The website's address is www.netcraft.com, I hope this tool will help Trap17 members. smile.gif
*



Thanks for this toolbar. It is great way to prevent phising...

It even works with firefox too....

Cool. Thank You.

Reply

sunny
Some facts about Spaming:

CODE

AT&T WorldNet says it rejects 10 million to 12 million e-mails a day because the addresses don't match real users'--a sure sign that spammers are at work.
Newsweek - Crammed with Spam


1/2 to 3/4 of all spam email has forged reply addresses, estimating that the spam volume is now up to 1 billion messages a year.
Jeff Lawhorn, Software Design Associates  


Most ISPs estimate the extra cost due to spam as $2 to $3 per month per user, and longer connection times, which can be costly for rural users who have to dial long distance to connect to the Internet.
IDG


A recent survey found that ISPs spend millions of dollars to stop spammers, with about $2 of each subscriber's bill going toward spam prevention.
CNN


Approximately 10% of ISP overhead deals with SPAM (churn rate; lost revenue due to defection; new customer acquisition; infrastructure; personnel)
Gartner Group


The Federal Trade Commission reports that when it went after spammers earlier this year, it received 500 unsolicited e-mails in a single mailbox every day - and the commission probably didn't receive it all.
CNN


The increases in marketing messages are outpacing the growth in personal e-mail. By 2005, expect to get about one marketing e-mail for every two or three personal messages.
Industry Standard


Spending on commercial e-mail will balloon to $7.3 billion in 2005 from $164 million in 1999. In 1999, the average consumer received 40 pieces of spam. By 2005, the total is likely to soar to 1,600.
Jupiter Communications


FTC gets 4,500 spam complaints per day


The average business e-mail user receives three spam messages a day, and in three years that number will swell to 40. In 2003 we'll waste 15 hours deleting e-mail, compared to 2.2 hours in the year 2000. That will cost the average business in the future $400 per in-box, compared to $55 today.
Ferris Research


Average U.S. consumer will receive 1,600 commercial email messages in 2005, up from 40 in 1999, while non-marketing and personal correspondence will more than double from approximately 1,750 emails per year in 1999 to almost 4,000 in 2005.
Jupiter Communications, May 2000


By 2002, E-mail will grow from 9.8% to 17.3% of a company's total number of contacts with a customer.
Forrester Research




One more thing, If you got an email from ebay and you suspect that it is not from actual eBay.com. then you can report this to ebay by forwarding that mail in original form to [B}spoof@ebay.com[/B]

Your complaint will be registered and the person sending those email will be executed (hopefully).

Anyways, by doing so you can help ebay to find more about those cheaters.

 

 

 


Reply

niloc
I have received a few ebay spoof emails recently .... i forwarded them to ebay.

One way to check if they are spoof emails is to follow the link they suggest to where they want you to enter you personal details .... at this point look in the bottom right hand corner of your browser for a padlock icon .... if there isnt one then you are not on a secure site.

With to regard to ebay spoof emails .... they would never contact you by email for your details , they would send you a message to your ebay inbox if they had a problem with your account details.

Reply

Latest Entries

Brian Gillingham
QUOTE(niloc @ Oct 14 2005, 04:00 AM) *

One way to check if they are spoof emails is to follow the link they suggest to where they want you to enter you personal details .... at this point look in the bottom right hand corner of your browser for a padlock icon .... if there isnt one then you are not on a secure site.

With to regard to ebay spoof emails .... they would never contact you by email for your details , they would send you a message to your ebay inbox if they had a problem with your account details.

Yikes! Don't ever click on these e-mails to confirm.... once you've done that, they know that your e-mail address is good. They keep trying that e-mail address (and possibly spread your address around to a few phishing friends. But, niloc is correct in what he says about them never sending you e-mails about stuff like that. You can see "How to detect spoof e-mail" at e-bay: http://pages.ebay.com/education/spooftutor...=STRK:MEMM:LNLK

I think that my "feedback" e-mail address has been either scraped by bots - or simply added to a phishing list manually because my site had "Contact: mailto:x@y.com " -- easy to search for, and protect against if I had done what it takes (I think that it has something to do with editing the robots.txt file - confirm anybody?). In any case, 96% of the e-mails arriving at my feedback e-mail have all kinds of important sounding warnings about various accounts that I may or may not even have. All phishing attempts. All deleted immediately.

Reply

mcfly
Phishing is HUGE. I work for a bank and it seems each day more of my time is spent dealing with it. Everyone seems to agree, education is the key. Banks do not, will not send emails to clients asking them for sensitive personal or financial infomation.

It staggers me how many people will willingly submit their credit card info simply because they get an email directing them to a website that asks for it. Once your numbers have been sent, phishers can have a fake card coded and at an ATM within half-an-hour.

Reply



Got an Opinion! Express your Views! (no registration):-
Add your Reply/ Opinion/ Views/ Comments/ Suggestion/ Questions/ Queries etc.
Posts with decent grammar & English will be accepted and please refrain from profanities.
For asking a Question, We recommend you to sign-up (for free) so that you can track the topic easily.

Nature of your Post*: Opinion/ Reply/ Comments
Question/Query
Feedback to us.
       
Name   Email
Title/Question*

(Maximum characters: 10,000)
You have characters left.
Confirm Code:

Pages: 1, 2
Recent Queries:-
  1. how to know if you got a fake ebay email - 0.26 hr back. (1)
  2. report ebay fake emails - 64.29 hr back. (1)
  3. fake ebay screen keeps coming up - 74.28 hr back. (1)
  4. every time i go to the login page my antivirus warns me that this is a phishing site and the web page is designed to steal my credit card number, user name and password? why is this? - 80.89 hr back. (1)
  5. panda internet security 2008 has detected that this email could be spoofed take maximum precautions, as spoofed emails could be the sign of a fraud attempt. - 140.24 hr back. (1)
  6. ebay spyware myebay "social security" - 147.42 hr back. (1)
Similar Topics

Keywords : ebay, spoof, phishing, attacks, fake, ebay, email, detection

  1. Fight Spam Email
    Link to this script on your Hosting Account (0)
  2. Constructing Email Read Only Once
    how can I solve this problem? (6)
    I just want to send an email,but I want the recipient only read that email one time,then it is
    automaticlly deleted.How could I do that? Any want can help me .thanks.....
  3. Virus-spyware Protection An Detection
    (3)
    Best Online Scanners: QUOTE HouseCall http://housecall.trendmicro.com/ Panda
    http://www.pandasoftware.com/activescan/ BitDefender Online
    http://www.bitdefender.com/scan8/ie.html eTrust Antivirus Scanner
    http://www3.ca.com/securityadvisor/virusinfo/scan.aspx Jotti.org single file scanner
    http://virusscan.jotti.org/ Online malware scan Utilizes 8 major Antivirus Scans to analyze
    individual files. AV "sandbox" component provides detailed analysis. Libraries and further
    information: Symantec http://securityresponse.symantec.co...er/vinfodb.html ....
  4. Email Yahoo Free Accounts Without Pop3 Server?
    (1)
    i have friend and he ask me today why after he opened free yahoo email account with .com extension,
    dont have a pop3 server to send and receive e-mails? I have account with .es and can configure a
    free pop3 server.....
  5. Gmail Phishing Attempt
    (8)
    Thats a long message, but read the #'s where he wants personal information, bank accounts,
    address, and why is the message in all CAPS? Thats really wierd. I reported it to Gmail, but wanted
    to know if anybody got something similiar to this message. QUOTE I have a new email
    address! You can now email me at: peterwetego09@yahoo.com FROM :PETER WETEGO. ABIDJAN,IVORY
    COAST Email(peterwetego09@yahoo.com ) DEAR ONE, PERMIT ME TO INFORM YOU OF MY DESIRE OF GOING
    INTO BUSINESS RELATIONSHIP WITH YOU. I GOT YOUR NAME AND CONTACT FROM A FRIEND WHO IS MEMBER OF ....
  6. E-bay Phishing E-mail Still Out There
    Watch your privacy (3)
    This e-mail has been going around for a while now. I've recieved it about 5 times now. I
    thought e-bay would be on it like hawks but there really isn't much they can do about it. Just
    be aware of your personal information. Subject: eBay Account Verification Date: Fri, 20 Jun
    2003 07:38:39 -0700 From: "eBay" Reply-To: accounts@ebay.com To: Dear eBay member, As part
    of our continuing commitment to protect your account and to reduce the instance of fraud on our
    website, we are undertaking a period review of our member accounts. You are requested to v....
  7. Any Good Pop3 Email Clients
    Looking for some --- Help appreciated (3)
    I was wondering if any of you guys knew of any good pop email clients. I recently signed up for a
    pop client, but I was wondering what the best client was. People say Outlook is full of bugs and
    freezes constantly. I am told that open source is the way to go. I'm not familiar with any open
    source pop clients. If anyone has any suggestions, they would be greatly appreciated. I am running
    Windows XP. QUOTE Thanks, magical1492 No "sign - offs, please add it to your sig block
    via the profile manager. Thanks ....
  8. Using Your Email To Send Spam
    What exactly do they call those things? (10)
    I was happily browsing the web so I decided to check my Yahoo! email. I got like 4 emails that
    were bounced back by Mail-Daemon. Apparently, I had tried to send this spam mail to some MSN
    groups!? It was bounced back to me because I had to be a member of that group to send emails.
    (Whew!) /blink.gif" style="vertical-align:middle" emoid=":blink:" border="0" alt="blink.gif" />
    I was shocked and ran all the scans I could think of (Adware/Anti-virus) and deleted this Cydoor
    adware. I'm not sure that was what caused it, and I'm starting to freak out, beca....
  9. Is It True Or Just A Weird Email ?
    hotmail ID can be freeze ??? (26)
    Dear last night a very strange and very disgusting thing happend to me . It so happened that last
    night i tried to SIGN-IN my hotmail id using messenger , bet every time when i tried to sign-in I
    recieve a message off INVALID password . I just tried to sign-in in my Inbox but this time i
    recieved a error page that your account is temperarly unavaiable. I tried much but in vain . I just
    think that there may be some problem in my internet .I tried to sign-in with my other ID this time
    with other ID i was sucessfull . then i just tried with the previous id but i was conti....
  10. Weird Email
    (3)
    /ohmy.gif" style="vertical-align:middle" emoid=":o" border="0" alt="ohmy.gif" /> Today, I opened up
    an account in Gmail, and I finally get the immense 2 gig space. Then I open up my email and
    bam!!! An email to me from the Bank of America. The weird thing is that I don't use
    Bank of America. /ph34r.gif" style="vertical-align:middle" emoid=":ph34r:" border="0"
    alt="ph34r.gif" /> So I retraced the email adress and it said (unknown). Any comments please host.....
  11. Firefox's Answer To Ie's Phishing Filter?
    users of the sacred browser can breathe once more! (5)
    SiteAdvisor - Firefox's Answer To IE's Phishing Filter? A site-warning plugin
    for ie and firefox Name: Site Advisor Url: http://siteadvisor.com Download:
    http://www.siteadvisor.com/download/ff.html Rating: 9.75/10 Improvements: Not all sites are on
    their database but many of the popular ones are so index all webistes. SiteAdvisor is a simple and
    easy to install extension created for firefox which checks to see if the site you are on is "bad"
    from its database of urls. Once the results have reached your browser a notificatio....
  12. Beware Of Fake Fbi Email
    (23)
    i was just on shoutbox and saint michael said someone sent him an email with virus and fbi in it so
    im just letting yall kno beware of it but here is the email that is being sent QUOTE
    http://www.astahost.com/just-got-email-fbi-t9312.html the email address is Admin@fbi.gov (phoney)
    Dear Sir/Madam, we have logged your IP-address on more than 30 illegal Websites. Important: Please
    answer our questions! The list of questions are attached. Yours faithfully, Steven Allison
    *** Federal Bureau of Investigation -FBI- *** 935 Pennsylvania Avenue, NW, Room 3220....
  13. Network Based Attacks
    (1)
    hi friends, you know that there're lots of attacking methods in network security . Here's a
    collection of links for different kind of attacks : SYN packet manipulation -- SYN packet
    manipulation http://www.iss.net/security_center/advice/...ood/default.htm -- Syn Flood experiment
    http://www.niksula.cs.hut.fi/~dforsber/synflood/result.html -- SYN Cookie
    http://cr.yp.to/syncookies.html Smurf DOS -- ISS.com: Description
    http://www.iss.net/security_center/advice/...urf/default.htm -- GRC.com: DDOS Anatomy
    http://grc.com/dos/grcdos.htm IRC (I....
  14. Phishguard - Detects Spoofing Attacks
    Windows Tools - Spoofing (1)
    QUOTE PhishGuard is a FREE service that detects and rapidly disables Internet "phishing" or
    "spoofing" attacks designed to steal critical financial data. Phishing attacks use fraudulent
    websites and emails that mimic well-known organizations in order to trick unsuspecting Internet
    users. A simple login or account number entry screen becomes a sophisticated trap. By assuming you
    are dealing with a trusted party, you can reveal financial information including credit card
    numbers, bank accounts, passwords, and social security numbers to the "bad guys". This type of att....
  15. Fake Paypal Email Messages
    take a look and be aware (19)
    I have seen posts about what kind of messages are out there fooling members to give up private
    information--especially when PayPal sent you one. Oh no! No way, PayPal address cannot be faked.
    Wrong. I almost gave away my entire personal information about 3 years ago. And the fake messages
    are getting better and better. Even the site that links to looks too real. So I decided to share
    this with you, in hopes that no one from TRAP17 are suckered into giving up what is private
    information. PS I know everyone knows this but let's spread the word and see how many mor....
  16. Email Clients
    Which One Do You Trust For Security? (23)
    Many people don't care about email account security and just go for a Hotmail account because
    it's automatically MSN compatible or a Gmail account because it has lots of space. But out of
    those of you who choose your email based on safetey and security, which client do you recommend?
    There are tons out there. Personally, I use GMX.net, it's a German service with extremely high
    security. They have a password meter to check your password for how easy or hard it might be to
    guess, encouraging you to use upper and lower case letters along with numbers. They veri....
  17. Wireless Intrusion Detection And Response
    (0)
    A prototype implementation of a wireless intrusion detection and active response system is
    described. An off the shelf wireless access point was modified by downloading a new Linux operating
    system with non-standard wireless access point functionality in order to implement a wireless
    intrusion detection system that has the ability to actively respond to identified threats. An
    overview of the characteristics and functionality required in a wireless intrusion detection system
    is presented along with a review and comparison of existing wireless intrusion detection systems a....
  18. Email Fraud
    Dont get tricked (18)
    I have recently recived a Email from "PayPal", and is clearly visibel that its not them, Dont get
    Folled by fake Emails, One of the Emails I Recived is: QUOTE Dear valued PayPal® Member  It
    has come to our attention that your PayPal®account information needs to be updated as part of our
    continuing commitment to protect your account and to reduce the instance of fraud on our website.
    If you could please take 5-10 minutes out of your online experience and update your personal
    records you will not run into any future problems with the online service. You mu....
  19. Ebay Scam That Could Have Happened
    if i fell for it and had ebay (1)
    Ok I dont have the email anymore but I got an email from so called ebay stating my account has
    almost been accesed 25 times in the last 3 days all with invalid password. They gave me a link and
    said, go here and refill out your account info and you'll be all set. If you don't do this
    in 3 days we'll have no other choice but to delete your accound. Finally they put This Is Not A
    Scam. Wanna know the funny thing I dont have an ebay account. Just goes to show that your ebay
    account is finally no longer safe. So if you are almost scamed I salout you for not fa....
  20. Windows Update Email Scam
    its a trojen horse (8)
    QUOTE A new scam by hackers has some people believing they are receiving an e-mail about a
    critical update to Windows when in actuality they are installing a Trojan horse, Sophos said on
    Friday. The e-mail directs victims to a fake version of the Windows Update site, where there are
    links to download the malicious "patches." "The email uses the Microsoft branding and style so to
    the casual observer it appears to be legitimate," Gregg Mastoras, Senior Security Analyst at Sophos,
    told BetaNews. If users download the "patches," they are actually installing the Troj/DS....
  21. Ebay Accounts Being Hijaked
    Please share this with other eBayers (8)
    Our son had his eBay account hijaked, yesterday. It took him almost a half day to get it sorted out.
    A heads-up buyer got suspicious of an auction for a snowmobile requiring a $1,000 deposit, so
    he found our son's phone # and called before paying. The listing did NOT belong to our son.
    Once the perp got our son's eBay password, he also hacked his email account, which used the same
    password. That took another half hour to sort out. This buyer told our son there has been a rash of
    these hijakings, lately. Obviously eBay isn't as secure as we thought. If....

    1. Looking for ebay, spoof, phishing, attacks, fake, ebay, email, detection

Searching Video's for ebay, spoof, phishing, attacks, fake, ebay, email, detection
advertisement



Ebay Spoof/phishing Attacks. - fake ebay email detection.



 

 

 

 

ADD REPLY / Got an Opinion! Remove these ADs! RAPID SEARCH! Free Web Hosting [X]
Express your Opinions, Thoughts or Contribute more info. to help others.
Ask your Doubts & Queries to get answers, So that "Together We can help others!"
Register FREE for AD-FREE forum, Create your own topics, Ask Questions, track topics, setup subscriptions & notifications and Get a Free Website w/ Email and FTP.
500MB Space *No Ads*, CPanel, FTP, PHP, MySQL, EMails - 100% FREE