All,
The phishing is getting BAD.
For those of you that do not know what phishing is here is a definition:
In computing, phishing (also known as carding and spoofing) is a form of social engineering, characterized by attempts to fraudulently acquire sensitive information, such as passwords and credit card details, by masquerading as a trustworthy person or business in an apparently official electronic communication, such as an email or an instant message. The term phishing arises from the use of increasingly sophisticated lures to "fish" for users' financial information and passwords.
Here is what happened..
Just now we received a email with the following subject line:
Subject: Question from eBay Member
In the body of the email it says:
Hello ,
please tell me more about your item ,
tell me your las price !
Thanks !
djcarlosg
It is sent from :
aw-confirm@ebay.com
And looked so real we almost clicked on it...
BUT
If you look in the headers below you will see that the email is being "Spoofed"
For those of you that do not know what "spoofing" is here is a definition:
A technique used to gain unauthorized access to computers, whereby the intruder sends messages to a computer with an IP address indicating that the message is coming from a trusted host. To engage in IP spoofing, a hacker must first use a variety of techniques to find an IP address of a trusted host and then modify the packet headers so that it appears that the packets are coming from that host.
Below is the message Real origination of the email as seen in the message headers below:
Return-Path: <pharmaco@cpanel.cygnusnet.com>
Received: from ibm13aec.bellsouth.net
for <teamaaronshara@bellsouth.net>
Mon, 5 Dec 2005 10:32:30 -0500
Received: from cpanel.cygnusnet.com ([207.44.246.52])
by ibm13aec.bellsouth.net with ESMTP
id
for <teamaaronshara@bellsouth.net>;
Mon, 5 Dec 2005 10:32:30 -0500
Received: from pharmaco by cpanel.cygnusnet.com with local (Exim 4.52)
id 1EjI96-0005mJ-Ne
for teamaaronshara@bellsouth.net; Mon, 05 Dec 2005 09:20:52 -0600
From: aw-confirm@ebay.com
Reply-To: aw-confirm@ebay.com
MIME-Version: 1.0 Content-Type: text/html\r\n
Content-Type: text/html Content-Transfer-Encoding: 8bit\r\n
Subject: Question from eBay Member
Please Be Careful out there. Your PC and all your data and whatever it is that they are looking for can be wiped out with one "click".
Aaron and Shara