Search our Spoof Library...
Another Spoof Email and Phishing Scam report by MillerSmiles.co.uk - click this image to go to our home page.

NEW FORM OF URL SPOOFING? Open now: eBay account information
15th March 2004

please forward any scams you've received to spoof@millersmiles.co.uk

 

Report Summary
Date Reported
15th March 2004
Apparent Sender
eBay
Return Address
registration@ebay.com
Subject
Open now: eBay account information
Format
HTML
Method
disguised link leads to bogus web content
Bogus Web Content?
Yes
URL of web content
New form of spoofing recognised which falsely displays a genuine secure ebay.com URL - https://arribba.cgi3.ebay.com/aw-cgi/ebayISAPI.dll
The actual location of the bogus content is on Yahoo Inc's web hosting servers
RISK LEVEL
HIGH
WARNINGS

1. Uses HTML, HTA and javascript code to replace the address bar with an image and text which appears to be an address bar with a genuine ebay secure URL. This is not the browser address bar!

 

What appears to be a new form of URL Spoofing - ADDRESS BAR SPOOFING - propogates across the net with this spoofed ebay email...

 

This spoof eBay email (see image below) is in HTML format and the link has been disguised using HTML code to look like it will lead to a genuine and secure eBay site page.

The link will open a browser window which is scripted to close and reopen with the address bar removed and at full screen. The really clever part of this bogus page is that it uses HTA, HTML and javascript to display a replacement address bar with text, and that text is a genuine URL of a secure eBay page (https://arribba.cgi3.ebay.com/aw-cgi/ebayISAPI.dll). The fake address bar is constructed with images and the URL text as mentioned, the only draw back to this approach for the perpetrators is that some of the images used to build the fake toolbar have a light grey background which only matches the Windows™ Classic desktop setting. They have even constructed a dummy 'Go' button which appears to be functional.

The bogus page is actually hosted on Yahoo Inc's servers together with the form to mail script which captures any data submitted into the form.

The nature of the bogus page and the genuine appearance of the email earns this phishing scam a HIGH risk level.

If you have received this email, please remember that it is very common for these email scams to be redistributed at a later date with only slightly different content or the same but with the fake page(s) hosted by a different provider. Also, once you have received one of these hoaxes, it is also common place to receive at least another one and usually a day or two after the first, although not necessarily from the same apparent sender.

Many thanks go to Brandon Richards of Speciality Service Systems, Inc. for reporting this email.

The Spoof Email ...

NEW FORM OF URL SPOOFING - Open now: eBay account information spoof email

 

The bogus web page (the entire address bar is built from code within the page)...

NEW FORM OF URL SPOOFING? Open now: eBay account information NEW FORM OF URL SPOOFING? Open now: eBay account information NEW FORM OF URL SPOOFING? Open now: eBay account information NEW FORM OF URL SPOOFING? Open now: eBay account information
NEW FORM OF URL SPOOFING? Open now: eBay account information NEW FORM OF URL SPOOFING? Open now: eBay account information NEW FORM OF URL SPOOFING? Open now: eBay account information NEW FORM OF URL SPOOFING? Open now: eBay account information
NEW FORM OF URL SPOOFING? Open now: eBay account information NEW FORM OF URL SPOOFING? Open now: eBay account information NEW FORM OF URL SPOOFING? Open now: eBay account information NEW FORM OF URL SPOOFING? Open now: eBay account information
NEW FORM OF URL SPOOFING? Open now: eBay account information NEW FORM OF URL SPOOFING? Open now: eBay account information NEW FORM OF URL SPOOFING? Open now: eBay account information NEW FORM OF URL SPOOFING? Open now: eBay account information
NEW FORM OF URL SPOOFING? Open now: eBay account information NEW FORM OF URL SPOOFING? Open now: eBay account information NEW FORM OF URL SPOOFING? Open now: eBay account information NEW FORM OF URL SPOOFING? Open now: eBay account information

 

Stay informed of the latest Spoof Email Phishing Scams with either of our FREE alert services...
 

Stay informed of the latest Spoof Email Phishing Scams with either of our FREE alert services...

Email Alerts
Add your email address to our email alert service...
Subscribe

Privacy Policy

RSS News Feed
Tap into our Scam Alert service using your News Reader or Aggregator (including My Yahoo!).
Scam Alert News Feed

You can even put the latest alerts on your own web site.

Click here to learn more about RSS News Feeds and our Scam Alert Service!

Resources links - use one of the links below to access more information on Spoof Email & Phishing Scams.

Library of Spoof Email Phishing Scams

Brief guide to Phishing

Full article on spoof email scams

Spoof URL Checker

Link Checker

Browser URL Spoofing Vulnerability Check

Latest browser bug aids Phishing Scams - beware!

Destinations - other resources available on the MillerSmiles.co.uk web site.

Click the arrow to return to previous page

Home

Guides...

Book Terminology

How to identify a first edition book

Auction Watcher

List of the main Auction Sites world wide