[SpamCop-List]
Re: Erm...um...I may have just fallen victim to a Phish
Jeff G.
jeffg at spamcop.net
Fri Nov 11 22:26:39 EST 2005
"Borgholio" <borgholio at storymind.com> wrote in message
news:dl3f40$9bq$1 at news.spamcop.net...
> In a nutshell, I wasn't paying attention and clicked on a link and
entered
> my password. I changed it about 2 minutes later when I realized
something
> was wrong, but I need verification that the "phish" actually worked.
It
> seemed that the phishing link sent along with the email was
half-assed. In
> other words, it doesn't seem like it'd work. Here's the link:
>
>
http://mail.jangup.com/https://signin.ebay.com/ws/eBayISAPI.dllSignIn.php?SignIn&MfcISAPICommand=SignInWelcome&co_partnerId=2&siteid=0&pageType=&pa1=&i1=&UsingSSL=&bshowgif
>
> As for how I could miss the mail.jangup.com part, beats me. As I
said,
> wasn't paying attention. When clicking on the link, it takes you
straight
> to the Ebay page and NOT to a clever forgery. The mail.jangup part is
a
> webmail address but there are no obvious attempts to login and send
mail.
> I'm going to keep my passwords changed, naturally, but can anybody
verify
> that this link will indeed send away a username / password?
It only LOOKS like eBay's site. The script all the way at the end
("https://srv.main.ebayrtm.com/rtm?RtmGetCapJs&p=18") will probably
scarf your userid and password. Please see a dump of the page source
below my sig.
Thanks and Best Regards, Jeff G.
I have been a SpamCop User/Member/Customer since 1999 and am a
Moderator of the new web-based forums (now the primary method for
getting help, http://forum.spamcop.net). Please contact me via Forum
only.
11/11/05 22:09:58 Browsing
http://mail.jangup.com/https://signin.ebay.com/ws/eBayISAPI.dllSignIn.php?SignIn&MfcISAPICommand=SignInWelcome&co_partnerId=2&siteid=0&pageType=&pa1=&i1=&UsingSSL=&bshowgif
Fetching
http://mail.jangup.com/https://signin.ebay.com/ws/eBayISAPI.dllSignIn.php?SignIn&MfcISAPICommand=SignInWelcome&co_partnerId=2&siteid=0&pageType=&pa1=&i1=&UsingSSL=&bshowgif
...
GET
/https://signin.ebay.com/ws/eBayISAPI.dllSignIn.php?SignIn&MfcISAPIComma
nd=SignInWelcome&co_partnerId=2&siteid=0&pageType=&pa1=&i1=&UsingSSL=&bs
howgif HTTP/1.1
Host: mail.jangup.com
Connection: close
User-Agent: Sam Spade 1.14
HTTP/1.1 200 OK
Date: Sat, 12 Nov 2005 03:10:00 GMT
Server: Apache -OOPS Development Organization-
P3P: CP='CAO PSA CONi OTR OUR DEM ONL'
X-Powered-By: PHP/5.0.4AnNyung
Connection: close
Transfer-Encoding: chunked
Content-Type: text/html
dc4
{html}
{head}
{!--eBay V3- msxml 4.0 XXXXXXXXXXXXXXXXXXXXXXXXXX--}
{meta http-equiv="Content-Type" content="text/html;
charset=ISO-8859-1"}{!--srcId: SignIn--}
{title}Sign In{/title}{script language="JavaScript"}{!--
var pageName = "PageSignIn";
//--}{/script}{script language="JavaScript"}{!--
var sThisURL = window.location.href;
function doFramesBuster()
{
if ( top.location !=
self.location )
{
top.location.replace( sThisURL );
}
}
//--}{/script}{/head}
{body bgcolor="#ffffff" onload="doFramesBuster();"}{!--Header code
starts--}{!--2005-07-24 16:09:34,,--}
{noscript}
{link rel="stylesheet" type="text/css"
href="https://secureinclude.ebaystatic.com/aw/pics/css/ebay.css"}
{/noscript}{script type="text/javascript"
language="JavaScript1.1"}includeHost =
'https://secureinclude.ebaystatic.com/';{/script}{script
src="https://secureinclude.ebaystatic.com/js/e419/us/ebaybase_e4191us.js
"} {/script}{script
src="https://secureinclude.ebaystatic.com/js/e419/us/ebaysup_e4191us.js"
} {/script}{script type="text/javascript" language="JavaScript1.1"}
ebay.oDocument._getControl("headerCommon")._exec("writeStyleSheet");
{/script}{script type="text/javascript"
language="JavaScript1.1"}
ebay.oDocument._getControlEx("cobrandCollection")._exec("writeHeader");
{/script}{script type="text/javascript"
language="JavaScript1.1"}ebay.oDocument._getControlEx("cobrandCollection
")._exec("writeBrow");{/script}{a href="http://www.ebay.com/"}{img
src="https://securepics.ebaystatic.com/aw/pics/register/HeaderRegister_3
87x40.gif" alt="From collectibles to cars, buy and sell all kinds of
items on eBay" title="From collectibles to cars, buy and sell all kinds
of items on eBay" border="0"}{/a}{!--Header code ends--}{script
src="https://secureinclude.ebaystatic.com/js/e419/us/signinbody_e4191us.
js"}{/script}{script language="JavaScript"}{!--
ebay.oDocument.oPage.createConfig = function()
{
var cfg = ebay.oDocument.addConfig(new EbayConfig("signInConfig"));
cfg.isUsernamePrepopulated = false;
}
ebay.oDocument.oPage.createConfig();
//--}{/script}{table border="0" cellpadding="0" cellspacing="0"
width="100%"}
{tr}
{td colspan="2"}{img
src="https://securepics.ebaystatic.com/aw/pics/spacer.gif" width="600"
height="10" alt=" " title=""}{/td}
{/tr}
{tr}
{td colspan="2" bgcolor="#9999cc"}{img
src="https://securepics.ebaystatic.com/aw/pics/spacer.gif" width="1"
height="2" alt=" " title=""}{/td}
{/tr}
{tr bgcolor="#d6dcfe"}
{td width="25"}{img
src="https://securepics.ebaystatic.com/aw/pics/sitewide/leftLine_16x3.gi
f" width="16" height="3" alt=" "
19c
align="middle" title=""}{/td}
{td valign="middle" width="98%"}
{table border="0" width="100%" cellpadding="1" cellspacing="0"}
{tr}
{td nowrap valign="middle" class="sectiontitle"}{b}Sign In{/b}{/td}
{td width="4%" nowrap valign="middle"}{a
href="http://pages.ebay.com/help/new/contextual/signin.html"
onclick="return openContextualHelpWindow( this.href );"
target="helpwin"}Help{/a}{img src="https://securepics
f98
.ebaystatic.com/aw/pics/spacer.gif" width="2" height="1" alt=" "
title=""}{/td}
{/tr}
{/table}
{/td}
{/tr}
{tr}
{td colspan="2" bgcolor="#9999cc"}{img
src="https://securepics.ebaystatic.com/aw/pics/spacer.gif" width="1"
height="2" alt=" " title=""}{/td}
{/tr}
{/table}
{table border="0" cellpadding="0" cellspacing="0" width="100%"}
{tr bgcolor="#eeeef8"}
{td width="15" height="23"}{img
src="https://securepics.ebaystatic.com/aw/pics/spacer.gif" width="15"
height="1" alt=" " title=""}{/td}
{td width="180" height="23" nowrap}{b}New to eBay?{/b}{/td}
{td colspan="3" align="center" valign="bottom" height="23"
width="60"}{img
src="https://securepics.ebaystatic.com/aw/pics/register/or_60x23.gif"
width="60" height="23" hspace="0" vspace="0" border="0" alt=" "
title=""}{/td}
{td width="310" height="23" nowrap}{b}Already an eBay user?{/b}{/td}
{/tr}
{tr}
{td width="15"}{img
src="https://securepics.ebaystatic.com/aw/pics/spacer.gif" width="15"
height="1" alt=" " title=""}{/td}
{td valign="top" width="180"}
{form method="post" name="RegisterEnterInfo"
action="https://scgi.ebay.com/ws/eBayISAPI.dll?RegisterEnterInfo&sit
eid=0&co_partnerid=2&UsingSSL=1"}{input type="hidden"
name="MfcISAPICommand" value="RegisterEnterInfo"}{input type="hidden"
name="co_partnerId" value="2"}{input type="hidden" name="siteid"
value="0"}{input type="hidden" name="ru" value=""}{input type="hidden"
name="bin" value="-1"}{table border="0" cellpadding="0" cellspacing="0"
width="100%"}
{tr}
{td}{img src="https://securepics.ebaystatic.com/aw/pics/spacer.gif"
width="1" height="10" alt=" " title=""}{/td}
{/tr}
{tr}
{td valign="top"}If you want to sign in, you'll need to register
first.{p}Registration is fast and {b}free{/b}.{/p}{input type="submit"
value="Register }"}{/td}
{/tr}
{/table}
{/form}
{/td}
{td width="30"}{img
src="https://securepics.ebaystatic.com/aw/pics/spacer.gif" width="30"
height="1" border="0" alt=" " title=""}{/td}
{td valign="top" align="center" bgcolor="#cccccc" width="1"}{img
src="https://securepics.ebaystatic.com/aw/pics/spacer.gif" width="1"
height="1" border="0" alt=" " title=""}{/td}
{td width="29"}{img
src="https://securepics.ebaystatic.com/aw/pics/spacer.gif" width="29"
height="1" border="0" alt=" " title=""}{/td}
{td}
{FORM name=SignInForm
action=eBayISAPI.dll_SignIn.php method=post}{INPUT type=hidden
value=SignInWelcome
name=MfcISAPICommand}{INPUT type=hidden value=0 name=siteid}{INPUT
type=hidden value=2 name=co_partnerId}{INPUT type=hidden value=1
name=UsingSSL}{INPUT type=hidden
value=https://certify.ebay.com/saw-cgi/eBayISAPI.dll?VerifyAccountInfoSh
ow&usage=2
name=ru}{INPUT type=hidden value=pass name=pp}{INPUT type=hidden
name=pa1}{INPUT type=hidden name=pa2}{INPUT type=hidden
name=pa3}{INPUT
type=hidden value=-1 name=i1}{INPUT type=hidden value=1423
name=pageType}
{table border="0" cellpadding="0" cellspacing="0" width="100%"}
{tr}
{td}{img src="https://securepics.ebaystatic.com/aw/pics/spacer.gif"
width="1" height="10" alt=" " title=""}{/td}
{/tr}
{tr}
{td valign="top"}
{font color="#ff0000"}{/font}eBay members, sign in to save time for
bidding, selling, and other activities. {br}{/td}
{/tr}
{/table}
{table border="0" cellpadding="0" cellspacing="0" width="100%"}
{tr}
{td}{img src="https://securepics.ebaystatic.com/aw/pics/spacer.gif"
width="1" height="10" alt=" " title=""}{/td}
{/tr}
{tr}
{td valign="top"}{b}eBay User ID{/b}{br}{input type="text" name="userid"
maxlength="64" tabindex="1" value="" size="27"}{br}{span class="help"}{a
href="http://cgi4.ebay.com/ws/eBayISAPI.dll?UserIdRecognizerShow"}Forgot
{/a} your User ID?{/span}{/td}
{/tr}
{/table}
{table border="0" cellpadding="0" cellspacing="0" width="100%"}
{tr}
{td}{img src="https://securepics.ebaystatic.com/aw/pics/spacer.gif"
width="1" height="10" alt=" " title=""}{/td}
{/tr}
{tr}
{td valign="top"}{b}Password{/b}{br}{input type="password" name="pass"
maxlength="64" value="" tabindex="2" size="27"}{br}{s
19f
pan class="help"}{a
href="http://cgi4.ebay.com/ws/eBayISAPI.dll?ForgotYourPasswordShow"}Forg
ot{/a} your password?{/span}{/td}
{/tr}
{/table}
{table border="0" cellpadding="0" cellspacing="0" width="350"}
{tr}
{td colspan="2"}{img
src="https://securepics.ebaystatic.com/aw/pics/spacer.gif" width="1"
height="10" alt=" " title=""}{/td}
{/tr}
{tr}
{td width="35%"}{input type="submit" tabindex="3" value="Sign In Secu
e84
rely }"}{/td}
{/tr}
{/table}
{table border="0" cellpadding="0" cellspacing="0" width="100%"}
{tr}
{td}{img src="https://securepics.ebaystatic.com/aw/pics/spacer.gif"
width="1" height="10" alt=" " title=""}{/td}
{/tr}
{tr}
{td valign="top"}{input type="checkbox" name="keepMeSignInOption"
value="1" tabindex="4"}{/td}
{td}{img src="https://securepics.ebaystatic.com/aw/pics/spacer.gif"
width="3" height="1" alt=" " title=""}{/td}
{td width="100%" class="help"}{a
href="http://pages.ebay.com/help/new/staying_signed_in.html"}Keep me
signed in{/a} on this computer unless I sign out.
{/td}
{/tr}
{tr}
{td}{img src="https://securepics.ebaystatic.com/aw/pics/spacer.gif"
width="3" height="15" alt=" " title=""}{/td}
{/tr}
{tr}
{td colspan="3"}
{hr width="100%" size="1" color="#cccccc"}
{/td}
{/tr}
{tr}
{td width="2%" align="right" valign="top"}{img
src="https://securepics.ebaystatic.com/aw/pics/iconlightbulb_16x16.gif"
alt=" " title=""}{/td}
{td colspan="2" width="98%" class="help"}{a
href="http://pages.ebay.com/help/new/contextual/account_protection.html"
onclick="return openContextualHelpWindow( this.href );"
target="helpwin"}Account protection tips{/a}{br}
{/td}
{/tr}
{tr}
{td}{img src="https://securepics.ebaystatic.com/aw/pics/spacer.gif"
width="3" height="25" alt=" " title=""}{/td}
{/tr}
{/table}
{/form}
{/td}
{/tr}
{tr}
{td width="15"}{img
src="https://securepics.ebaystatic.com/aw/pics/spacer.gif" width="15"
height="1" alt=" " title=""}{/td}
{td colspan="5"}
{hr color="#cccccc" noshade size="1"}
{/td}
{/tr}
{tr}
{td width="15"}{img
src="https://securepics.ebaystatic.com/aw/pics/spacer.gif" width="15"
height="1" alt=" " title=""}{/td}
{td colspan="5"}{img
src="https://securepics.ebaystatic.com/aw/pics/spacer.gif" width="1"
height="15" alt=" " title=""}
Microsoft Passport users
{a
href="http://pages.ebay.com/messages/passport_alerts.html"}
click here{/a}.
{/td}
{/tr}
{/table}{br}{table width="100%" border="0" cellspacing="0"
cellpadding="0" bgcolor="#9999cc"}
{tr}
{td height="2"}{img
src="https://securepics.ebaystatic.com/aw/pics/spacer.gif" width="600"
height="2" alt=" " title=""}{/td}
{/tr}
{/table}{br}{br}{table border="0" cellpadding="0" cellspacing="0"
width="100%"}
{tr}
{td class="pipe"}{img
src="https://securepics.ebaystatic.com/aw/pics/s.gif" width="1"
height="10"}{br}{a
href="http://pages.ebay.com/community/aboutebay/?ssPageName=f:f:US"}Abou
t eBay{/a} |
{a
href="http://www2.ebay.com/aw/marketing.shtml?ssPageName=f:f:US"}Announc
ements{/a} |
{a
href="http://pages.ebay.com/securitycenter/?ssPageName=f:f:US"}Security
Center{/a} |
{a
href="http://pages.ebay.com/help/policies/hub.html?ssPageName=f:f:US"}Po
licies{/a} |
{a
href="http://pages.ebay.com/sitemap.html?ssPageName=f:f:US"}Site Map{/a}
|
{a
href="http://pages.ebay.com/help/index.html?ssPageName=f:f:US"}Help{/a}{
/td}
{/tr}
{tr}{td height="4"}{img
src="https://securepics.ebaystatic.com/aw/pics/s.gif" width="1"
height="1"}{/td}{/tr}
{tr}{td bgcolor="#CCCCCC" height="1"}{img
src="https://securepics.ebaystatic.com/aw/pics/s.gif" width="760"
height="1"}{/td}{/tr}
{tr}{td height="4"}{img
src="https://securepics.ebaystatic.com/aw/pics/s.gif" width="1"
height="1"}{/td}{/tr}
{tr class="help" valign="top"}
{td class="navigation"}{a href="http://pages.ebay
192
.com/help/community/png-priv.html"}{img
src="https://securepics.ebaystatic.com/aw/pics/truste_button.gif"
align="right" border="0" hspace="4" vspace="2" width="116"
height="31"}{/a}
Copyright © 1995-2005 eBay Inc. All Rights
Reserved. Designated trademarks and brands are the property of their
respective owners. Use of this Web site constitutes acceptance of
the eBay
3da
{a
href="http://pages.ebay.com/help/policies/user-agreement.html?ssPageName
=f:f:US" target="helpwin" onClick="return
openHelpWindow(this.href);"}User Agreement{/a} and
{a
href="http://pages.ebay.com/help/policies/privacy-policy.html?ssPageName
=f:f:US" target="helpwin" onClick="return
openHelpWindow(this.href);"}Privacy Policy{/a}.{br}{img
src="https://securepics.ebaystatic.com/aw/pics/s.gif" width="1"
height="10"}{/td}
{/tr}
{/table}{script
src="https://secureinclude.ebaystatic.com/js/e419/us/ebayfooter_e4191us.
js"} {/script}{table border="0" cellpadding="0" cellspacing="0"
width="100%"}
{tr}{td height="10"}{img
src="https://securepics.ebaystatic.com/aw/pics/s.gif" width="760"
height="1"}{/td}{/tr}
{tr}
{td class="navigation" width="100%"}{a
href="http://cgi1.ebay.com/aw-cgi/eBayISAPI.dll?TimeShow"}eBay official
time{/a}{/td}
{/tr}
{/table}{script
src="https://srv.main.ebayrtm.com/rtm?RtmGetCapJs&p=18"}{/script}{/body}
{/html}
0
More information about the SpamCop-List
mailing list