**Freezing** yet ANOTHER PayPal Scam

Su1c1da1

Senior member
Jun 12, 2002
794
0
76
exact copy n paste from email




From : "Paypal Support" <support@paypal.com>

To : <killa_joka@hotmail.com>
Subject : System Update! Confirmation REQUIRED
Date : Sun, 28 Jul 2002 04:54:38
Dear PayPal Customer,

This email is to inform you of a recent update we made to our systems,
To avoid service Interruption we require that you confirm
your account as soon as possible.

Please take a moment to confirm your account by going to the following address:

http://www.transactionsystem.org/secureverify/accounts/accountConfirm.html

Follow these steps:

1- Log in to the link given above.
2- Your account will now be updated, you may continue using Paypal services with out any interruptions.

*** Please note: If you FAIL to update your account, it will be temporarily disabled.

We apologize for any inconvenience..
The paypal team is working hard to bring you the best services on the web.

Thank you for your business.


The Paypal Staff.



***************************************************************************************************************

Do not reply to this e-mail, for assistance contact the customer service team.

***************************************************************************************************************




 

Garet Jax

Diamond Member
Feb 21, 2000
6,369
0
71
Originally posted by: Chiboy
Thanks for the Warning... How did they send from support@paypal.com?

It is very easy to change the reply address on an email. Outlook allows it and I think express does as well. Even if that fails, it is very easy to write a java app that sends emails with any reply address whatsoever. It is so common in fact, that a lot of admins are making a filter to look at reply addresses to make sure they point to a valid email address. One company I did work for actually made sure that the domain in the email address was valid.
 

fr

Diamond Member
Oct 10, 1999
6,408
2
81
Can't any of these scammers ever do it with correct punctuation, spelling, capitalization, and grammar?
 

dew042

Platinum Member
Nov 2, 2000
2,934
0
76
Originally posted by: fr
Can't any of these scammers ever do it with correct punctuation, spelling, capitalization, and grammar?

mental note: next time i do this i need to put in better english skills....










oh, was that out loud?

dew.

 

progex

Member
Jul 20, 2002
170
0
0
Just remember,

(1)never do anything with your PayPal account if it directs to another address other than a Paypal.com/* address.
(2) If you happen to know HTML well, view the source of the webpage. You can clearly see that on: http://www.transactionsystem.org/secureverify/accounts/accountConfirm.html ... The form is a cutandpastescripts.com formmailer.
(3) Never give out your PayPal login/pass details if the webpage you're going to isn't SSL-Secure. How can you tell? If you see a lock at the bottom right of your browser and if the address starts with: https:// ... As opposed to just http:// .

Thanks for the Warning... How did they send from support@paypal.com?
Another method is using an Anonymous Mailer. Spammers often use these tools to "change" their e-mail address. However, if you view the header of the e-mail message, you can view if it's really an anonymous mailer.
 

RaWk

Senior member
Jun 20, 2001
315
0
0
not only can't they spell...but they're JS and perl scripts don't work. SO they couldnt get your password even if you entered it!
 

thortyboy

Member
May 26, 2002
88
0
0
Originally posted by: RaWk
not only can't they spell...but they're JS and perl scripts don't work. SO they couldnt get your password even if you entered it!


Rawk, you're right. hahaha, how funny
transactionsystem.org refers to 63.99.209.79-- kenosha, WI

paypal refers to 65.206.229.16 -- palo alto, CA

this guy is pretty lame, he could have at least used the some type of url like

http://www.paypal.com@65.206.229.16/secureverify/accounts/accountConfirm.html

i know that url refers back to the actual paypal, but isn't there some way to use an @
sign in a url to redirect to another site? ohwell. stupid wannabe sup3R 1337 hax0r. haha
 

GoatHerderEd

Senior member
Jan 11, 2001
498
0
0
i put in a bogus one, and it came back with:

Opps!
You email address entered into the HIDDEN tag called 'to' is incorrect



o, and if you click the protect your password link, it takes you to a window that tells you that it must say www.paypal.com!! lol. he didnt even corect that!
 

sxr7171

Diamond Member
Jun 21, 2002
5,079
40
91
Originally posted by: fr
Can't any of these scammers ever do it with correct punctuation, spelling, capitalization, and grammar?

Other than some incorrect capitalization, I can't see anything wrong with the grammar or punctuation. Please feel free to point out anything else you see.
 

iwearnosox

Lifer
Oct 26, 2000
16,018
5
0
Originally posted by: sxr7171
Originally posted by: fr
Can't any of these scammers ever do it with correct punctuation, spelling, capitalization, and grammar?

Other than some incorrect capitalization, I can't see anything wrong with the grammar or punctuation. Please feel free to point out anything else you see.
Uh, try "oops" not "opps."
 

iwearnosox

Lifer
Oct 26, 2000
16,018
5
0
The reason their script is erroring might be because of an alert site. They don't use their own forms, if you look it redirects to:

http://www.cutandpastescripts.com/cgi-bin/formprocessing/forms.pl

Posting values:

input type=hidden
name="activenumber"
value="653365185969"
name="username"
value="pp4us"

The sysops of cutandpastescripts.com probably have some good IP info on whoever is doing this. They probably got word of this scam and shut their script down, or it just plain broke.
 

skyking

Lifer
Nov 21, 2001
22,386
5,360
146
Is there any way to trace this back to the I.P., and catch these lowlifes for real? A few high-profile convictions of these slimeballs would be nice!
 

pokerstars

Junior Member
Jun 3, 2002
11
0
0
Um...just a thought here...but is it really smart for us to help these guys debug their scam site?

Just FYI - all PayPal transactions - even logins - are done from secure servers (https://...) - one more thing to watch for.

...dan
 

iwearnosox

Lifer
Oct 26, 2000
16,018
5
0
We're not helping them debug their site, it's not their site having the issue. They're being fairly simplistic in the thought that the more "layers" they place in the process of extracting emails and passwords the better. In reality it's more links in a chain that could, and did break.

Yes, they're traceable, and vunerable. Ultimately it may wind up that they're in Romania, though, and don't care about US law enforcement.
 

Apollyon

Member
Feb 7, 2002
98
0
0
So being as bored as I am, I figured I'd call their hosting company.

Wouldn't you know it, their office hours are Mon-Fri 8am-whenever, even for the sales department!

Anyways, if I don't think of it tomorrow, someone call readyhost.


Registrant:
Transaction Systems of America (UAMXAYALHD)
192 Ben Claar Road
Claysburg, PA 16625
US

Domain Name: TRANSACTIONSYSTEM.ORG

Administrative Contact:
Transaction Systems of America (UZDDWXYDFO) pp4us@hotmail.com
Transaction Systems of America
192 Ben Claar Road
Claysburg, PA 16625
US
814-942-4699
Technical Contact:
Ready Hosting Inc. (TWHBUQCCZO) sysadmin@readyhosting.com
Ready Hosting Inc.
6127 Green Bay Road
Kenosha, WI 53142
US
262-652-7640 fax: 262-652-7650

Record expires on 26-Jul-2003.
Record created on 26-Jul-2002.
Database last updated on 28-Jul-2002 17:59:44 EDT.

Domain servers in listed order:

NS5.READYHOSTING.COM 63.99.209.103
NS6.READYHOSTING.COM 63.99.209.104

 

Apollyon

Member
Feb 7, 2002
98
0
0
I forgot to include their number:

1-888-257-2052

If it wasn't toll free, I probably would not have called. I'm cheap.
 

Cattlegod

Diamond Member
May 22, 2001
8,687
1
0
no is this guy going to get off scott free with a ton of ppls money? or will the police take legal action?
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |