RSSTwitter: joshbyers

Phishing with Dynamite Part 2

Posted on June 15th, 2006 by Josh
No Comments »

If you click on the get verified link in the fake PayPal email you will be redirected to an Internet site that looks like the PayPal homepage. If you have gotten this far and still haven’t realized your being scammed there are even more blatant signals that something is not on the level.

page1.jpg

When the page loads it does something a little funny. It resizes it self. This is very simple for even a novice web developer to do. But why resize the page? When the page was resized it loaded itself into a special browser that was designed not to show you the web address of the page. But if you look in the upper corner of the page you will see this:

url.jpg

Notice that the original url is some weird number. That is a huge red flag. If the url doesn’t start with what you think it should it is possibly a scam.

Next you’ll notice that if no matter what link you click on the page it takes you to the same page. The page it takes you to is a familiar one that you see quite often if you use PayPal.

page3.jpg

And then from that page you are redirected to the page where it asks for your credit card and pin number information.

page2.jpg

Know that these sites will never ask you for your credit card number unless you are in the process of creating an account or if you are buying something. Also a site will never ask you for your pin number along with your credit card.

Hopefully you can recognize some of the signs the next time a phisherman is out trying to hook you.

Filed under: Interesting, Observations

Leave a Reply