Sigh... Another EBAY scam.

tranceport

Diamond Member
Aug 8, 2000
4,168
1
81
www.thesystemsengineer.com
Just to get the word out...

Here is the text of the message and the internet headers..

Five password bruteforcing attems were performed on your eBay account.


You must register and ID Verify certificate in order to remain in the eBay Community.
Dear eBay Community Member,
You (or someone else) has attempted to log in with your eBay ID and 5 diffrent wrong passwords.

According to our site policy you will have to confirm that you are the real owner of the eBay account by completing the following form or else your account will be suspended within 24 hours for investigations.

Establish your proof of identity with ID Verify (free of charge) - an easy way to help others trust you as their trading partner. The process takes about 5 minutes to complete and involves updating your eBay information. When you're successfully verified, you will receive an ID Verify icon in your feedback profile. Currently, the service is only available to residents of the United States and U.S. territories (Puerto Rico, US Virgin Islands and Guam.)

Confirm my account information and continue beeing a member of the eBay Online Auction Community.

Never share your eBay password to anyone!



Regards,

Accounting Department,
eBay Inc.




----


Headers. I replaced my stuff with ME@MYDOMAIN.

Microsoft Mail Internet Headers Version 2.0
Received: from ME@MYDOMAIN ([10.1.200.1]) by MYDOMAIN with Microsoft SMTPSVC(6.0.3790.0);
Sun, 30 Jan 2005 12:25:57 -0600
Received: by ME@MYDOMAIN (Postfix, from userid 100)
id CC9559E70C; Sun, 30 Jan 2005 12:25:44 -0600 (CST)
Received: from server.gatorland.com (unknown [66.195.241.170])
by ME@MYDOMAIN (Postfix) with ESMTP id 7E9229E33F
for <ME@MYDOMAIN>; Sun, 30 Jan 2005 12:24:45 -0600 (CST)
Received: from nobody by server.gatorland.com with local (Exim 4.43)
id 1CvJkY-0002Ow-BE
for ME@MYDOMAIN; Sun, 30 Jan 2005 13:24:42 -0500
To: ME@MYDOMAIN
Subject: Account Verification
From: eBay.com <aw-confirm@ebay.com>
Content-Type: text/html
Message-Id: <E1CvJkY-0002Ow-BE@server.gatorland.com>
Date: Sun, 30 Jan 2005 13:24:42 -0500
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - server.gatorland.com
X-AntiAbuse: Original Domain - rucool.no-ip.com
X-AntiAbuse: Originator/Caller UID/GID - [99 32003] / [47 12]
X-AntiAbuse: Sender Address Domain - server.gatorland.com
X-Source: /usr/local/bin/php
X-Source-Args: php -f ebay.php
X-Source-Dir:
X-Spam-Checker-Version: SpamAssassin 3.0.0 (2004-09-13) on firewall.rnd.local
X-Spam-Level: ***
X-Spam-Status: No, score=3.1 required=4.0 tests=HTML_50_60,HTML_IMAGE_ONLY_24,
HTML_MESSAGE,HTML_TAG_EXIST_TBODY,IP_LINK_PLUS,MIME_HEADER_CTYPE_ONLY,
MIME_HTML_ONLY,NORMAL_HTTP_TO_IP autolearn=no version=3.0.0
Return-Path: nobody@server.gatorland.com
X-OriginalArrivalTime: 30 Jan 2005 18:25:57.0524 (UTC) FILETIME=[2447DD40:01C506F9]




---
DO NOT ENTER INFORMATION ON THIS LINK
There is a link included... ---> http://221.143.46.125/bbs/aw-cgi/ws2/SignIn.html <--- Please do not actually enter your information...

If it's useful great. If not ignore it.
 

tami

Lifer
Nov 14, 2004
11,588
3
81
this stuff happens every day... why waste your breath on a post about it?
 

bsobel

Moderator Emeritus<br>Elite Member
Dec 9, 2001
13,346
0
0
You see someone raped.. It happens every day.. Why report it? Come on....

Nothing like a nice unrelated example to make your point.
 

her209

No Lifer
Oct 11, 2000
56,336
11
0
I don't get why these large corporations don't digitally sign their email. It would make spotting scam emails a lot easier.
 

Syringer

Lifer
Aug 2, 2001
19,333
2
71
Originally posted by: her209
I don't get why these large corporations don't digitally sign their email. It would make spotting scam emails a lot easier.

Anyone that can recognize the difference between a digitally signed e-mail and one that's not will easily recognize that e-mails like these are scams.
 

her209

No Lifer
Oct 11, 2000
56,336
11
0
Originally posted by: Syringer
Anyone that can recognize the difference between a digitally signed e-mail and one that's not will easily recognize that e-mails like these are scams.
People can be trained.