home archive of uk.* news reader.
 
  
OT: Ebay member's account security compromised on answering eBay's email   
Half-an-hour ago I received an official looking email from eBay.

----------------------------------------------------------------
From:     aw-confirm@ ebay.com
Date:      26 August 2005 16:18
To:         a.asghar1@ntlworld.com; [my email address]
Subject: Message ID 73000 - Message from eBay Member (eBay)

Security Service Notification: (Header) [Asterisks are mine]
eBay sent this message *on behalf of an eBay member* via My Messages.
Responses sent using email will *go to the eBay member directly* and will
include your email address. Click the Respond Now button below to send your
response via My Messages (your email address will not be included).

Security Service Notification:
Dear Customer ,
For the User Agreement, Section 9, we may immediately issue a warning,
temporarily suspend, indefinitely suspend or terminate your membership and
refuse to provide our services to you if we believe that your actions may
cause financial loss or legal liability for you, our users or us. We may
also take these actions if we are unable to verify or authenticate any
information you provide to us.
We regret to inform you that your eBay account could be suspended if you
don't re-update your account information. To resolve this problems please
use the link below and re-enter your account information. If your problems
could not be resolved your account will be suspended for a period of 24
hours, after this period your account will be terminated. .
Due to the suspension of this account, please be advised you are prohibited
from using eBay in any way. This includes the registering of a new account.
Please note that this suspension does not relieve you of your agreed-upon
obligation to pay any fees you may owe to eBay.
To update your record please click here:  Response Button

Unauthorized Account Access:
7967365480
26-Aug-05 19:32:34 EST
Thank you for using eBay!
http://www.ebay.com

----------------------------------------------------------------
Clicking the Button produced a form to fill in with blanks asking for my
account details.  There was no security warning dialogue box as one usually
comes up just before these details are requested.  I aborted the
investigation.

Please be warned.


-- 
Lin Chung
[Replace "the Water Margin" with "ntlworld" for e-mail].
Date:Fri, 26 Aug 2005 19:34:37 GMT   Author:  

Re: OT: Ebay member's account security compromised on answering eBay's email   

> Half-an-hour ago I received an official looking email from eBay.


May I ask if you`re dumb enough to read html email, and not force a 
plain text coversion so you see the true link hidden behind html ?
Date:Fri, 26 Aug 2005 20:47:39 +0100   Author:  

Re: OT: Ebay member's account security compromised on answering eBay's email   

> May I ask if you`re dumb enough to read html email, and not force a
> plain text coversion so you see the true link hidden behind html ?


If you hover over a link on OE it shows the true link at the bottom left...
Date:Fri, 26 Aug 2005 19:56:44 GMT   Author:  

Re: OT: Ebay member's account security compromised on answering eBay's email   
Paulo De Souza wrote:

> Collin Wilson wrote:
> > May I ask if you`re dumb enough to read html email, and not force a
> > plain text coversion so you see the true link hidden behind html ?
> If you hover over a link on OE it shows the true link at the bottom
> left...




Or, Ctrl + F3

Wilson has missed the point.  The last word in my message was
"investigation".

-- 
Lin Chung
[Replace "the Water Margin" with "ntlworld" for e-mail].
Date:Fri, 26 Aug 2005 20:16:37 GMT   Author:  

Re: OT: Ebay member's account security compromised on answering eBay's email   

> Wilson has missed the point.  The last word in my message was
> "investigation".


Apologies if I misinterpreted your post - but why the hell did you visit 
a non-ebay website to enter security details ?

I found an easy way around 90%+ of all my spam - I bought a domain name, 
and if I get anything to ebay at any of my other email addresses its 
shitcanned by default.

If its of use to anyone, I have free filters for Mailwasher for download 
at my site http://www.coreutilities.co.uk
Date:Fri, 26 Aug 2005 21:26:34 +0100   Author:  

Re: OT: Ebay member's account security compromised on answering eBay's email   

> I found an easy way around 90%+ of all my spam <snip>


Oh, I now get around 250-300 spam mails per day, down from ~580, of 
which the vast majority are marked for deletion without me wasting time 
seeing what they are.
Date:Fri, 26 Aug 2005 21:28:04 +0100   Author:  

Re: OT: Ebay member's account security compromised on answering eBay's email   
Colin Wilson wrote:

> > I found an easy way around 90%+ of all my spam <snip>
> Oh, I now get around 250-300 spam mails per day, down from
> ~580, of  which the vast majority are marked for deletion without
> me wasting time seeing what they are.



Actually, I don't have an eBay account, and have never used eBay.  The 'spam
filter' I use is POPFile.  The message got through to my 'not_spam' bucket.
This was one of the very rare occasion when a 'spam' was not picked up,
presumably the spammer had suceeded avoiding using all the marked key words.
There would not be a second mistake though, for the post will be marked and
'smarting up' of the POPFile will be effected.

Eversince the buying out of the 'spam king' in ?Califonia some two months
ago by, of all people, Microsoft, I have noticed the number of spam in my
in-box has dramatically reduced, from an average of 70 a day to now 20.  Now
there are very few porno looking headers appearing.  Or, maybe this was just
a temporal coincidence.

Incidentally, another quick access is Rt. click (header on the Preview pane)
 > Properties.  I normally use the keystroke combination.

-- 
Lin Chung
[Replace "the Water Margin" with "ntlworld" for e-mail].
Date:Fri, 26 Aug 2005 20:55:28 GMT   Author:  

Re: Ebay member's account security compromised on answering eBay's email   
"Lin Chung"  wrote in message 
news:h9KPe.51$n4.15@newsfe2-win.ntli.net...

> Half-an-hour ago I received an official looking email from eBay.
>


You and everyone else.  Get these sad phishing attempts on a daily basis.
Date:Fri, 26 Aug 2005 21:56:13 +0100   Author:  

Re: Ebay member's account security compromised on answering eBay's email   
Steeler wrote:

> Lin Chung wrote:
> > Half-an-hour ago I received an official looking email from eBay.
> You and everyone else.  Get these sad phishing attempts on a daily basis.



Thanks for imparting this rare insight.  This goes in some way in answering
the question: how big is phishing in spam.  Not many people would click on
the headers in the 'spam' bucket to view where the messages have come from,
much less to open the mails to read the contents.  Unless, that is, they are
in the security business.  Are you working in the IT security, Steeler?

-- 
Lin Chung
[Replace "the Water Margin" with "ntlworld" for e-mail].
Date:Sat, 27 Aug 2005 07:18:21 GMT   Author:  

Re: Ebay member's account security compromised on answering eBay's email   
"Lin Chung"  wrote in message 
news:1tUPe.165$x4.85@newsfe2-gui.ntli.net...

> Steeler wrote:
>> Lin Chung wrote:
>> > Half-an-hour ago I received an official looking email from eBay.
>> You and everyone else.  Get these sad phishing attempts on a daily basis.
>
>
> Thanks for imparting this rare insight.


Not a rare insight, but confirmation of the boredom we all suffer from when 
an arse like you comes along.

So fuck off cockrash.

Mr fucking 'I.T.' posting a pile of shite about ***shock horror*** an ebay 
phishing scam!
Is it a UK discount or bargain? no? well get to fuck you sanctimonious 
prick.

g.
Date:Sat, 27 Aug 2005 09:48:41 +0100   Author:  

Re: OT: Ebay member's account security compromised on answering eBay's email   

> Incidentally, another quick access is Rt. click (header on the Preview pane)
>  > Properties.  I normally use the keystroke combination.


Would this be for an inherently dangerous email program written by 
microsoft ? (I use a third party email program, TheBat!)
Date:Sat, 27 Aug 2005 10:15:05 +0100   Author:  

Re: OT: Ebay member's account security compromised on answering eBay's email   
Colin Wilson wrote:

> Lin Chung wrote:
> > Incidentally, another quick access is Rt. click (header on the Preview
> > pane) > Properties.  I normally use the keystroke combination.
> Would this be for an inherently dangerous email program written by
> microsoft ? (I use a third party email program, TheBat!)



I don't know of TheBat!.  Yes, I'm using none other than Outlook Express.
It may not be the greatest mail reader there is, but life is short and it
serves the purpose if I choose not to wander off the beaten track. :)

-- 
Lin Chung
[Replace "the Water Margin" with "ntlworld" for e-mail].
Date:Sat, 27 Aug 2005 09:39:17 GMT   Author:  

Re: Ebay member's account security compromised on answering eBay's email   
"Lin Chung"  wrote in message 
news:1tUPe.165$x4.85@newsfe2-gui.ntli.net...

> Steeler wrote:
>> Lin Chung wrote:
>> > Half-an-hour ago I received an official looking email from eBay.
>> You and everyone else.  Get these sad phishing attempts on a daily basis.
>
>
> Thanks for imparting this rare insight.  This goes in some way in 
> answering
> the question: how big is phishing in spam.  Not many people would click on
> the headers in the 'spam' bucket to view where the messages have come 
> from,
> much less to open the mails to read the contents.  Unless, that is, they 
> are
> in the security business.  Are you working in the IT security, Steeler?
>
> -- 


Headers?  Just hover over the link to see the scam.  Give you a clue - ebay 
does not have servers that end .ru
Date:Sat, 27 Aug 2005 12:50:43 +0100   Author: