FC: Scam extracts credit card numbers, bank info from eBay members

From: Declan McCullagh (declanat_private)
Date: Thu May 02 2002 - 06:57:19 PDT

  • Next message: Declan McCullagh: "FC: LA Times columnist wants it to "be harder to be anonymous" online"

    Obvious reasons this is a scam:
    1. Headers show it originated from sdn-ar-001nynyorp256.dialsprint.net
    2. The destination URL is http://64.177.3.234/, which receives connectivity
       from qwest.net, not ebay.com.
    3. There's no reason for eBay to send this message to me
    4. The site is not using a secure connection (https://) URLs for
       to protect sensitive information, which eBay almost certainly would.
    5. Replies are directed to to a yahoo.com address
    
    -Declan
    
    ----- Forwarded message from Safe Harbor <SafeHarborat_private> -----
    
    Return-Path: <SafeHarborat_private>
    Received: from get.hotwired.com (get.wired.com [204.62.131.5])
    	by cluebot.com (Postfix) with SMTP id 96A5A104FF
    	for <declanat_private>; Thu,  2 May 2002 05:47:31 -0400 (EDT)
    Received: (qmail 12535 invoked by alias); 2 May 2002 08:23:07 -0000
    Delivered-To: declanat_private
    Received: (qmail 12530 invoked from network); 2 May 2002 08:23:05 -0000
    Received: from smtp2.corp.terralycos.com (209.202.245.168)
      by get.wired.com with SMTP; 2 May 2002 08:23:05 -0000
    Received: from avocet.prod.itd.earthlink.net (avocet.mail.pas.earthlink.net [207.217.120.50])
    	by smtp2.corp.terralycos.com (Switch-2.2.2/Switch-2.2.0) with ESMTP id g428M1Q09497
    	for <declanat_private>; Thu, 2 May 2002 01:22:02 -0700 (PDT)
    Received: from sdn-ar-001nynyorp256.dialsprint.net ([168.191.122.18] helo=bkclan667)
    	by avocet.prod.itd.earthlink.net with smtp (Exim 3.33 #2)
    	id 173BUP-0004Jk-00; Thu, 02 May 2002 00:58:58 -0700
    From: Safe Harbor <SafeHarborat_private>
    To: debiejeanat_private, debjamesat_private, debkat_private,
    	deblat_private, debmatzat_private, debmittat_private,
    	debmj3rat_private, deborah.nowakowskiat_private, deborahdav16at_private,
    	deborahkat_private, deborahlynneat_private, deborahn1at_private,
    	deborahs3at_private, debperrinat_private, debraat_private,
    	debraat_private, debralee123at_private, debredz2rat_private,
    	debrocheat_private, debs454at_private, debs760at_private,
    	debskingat_private, debsother1at_private, deburdenat_private,
    	debydiat_private, decat_private, decade4130at_private, decadesat_private,
    	decadespastat_private, decastoat_private, deccard042at_private,
    	deceat_private, decentralizationat_private,
    	deciccoat_private, deckhandsat_private,
    	decksterityat_private, declanat_private, decolmtdat_private,
    	decoratingantiquesat_private, decorativedelightsat_private,
    	decoweenieat_private, DECoxPhotoat_private, dedeat_private,
    	dedejfat_private, dedempseyat_private, dedeskiat_private,
    	dedicatedat_private, dedillonat_private, dedorseyat_private,
    	dedorseyat_private
    Subject: Urgent message, from eBay Safe Harbor !
    Reply-To: cramos_02at_private
    Mime-Version: 1.0
    Content-Type: text/plain; charset=us-ascii
    Message-Id: <E173BUP-0004Jk-00at_private>
    Date: Thu, 02 May 2002 00:58:58 -0700
    
    
    
    
     Dear eBay member!
    
     Your information in our eBay file, was marked (flagged) as incorrect and/or 
    (fraudulent). To avoid any inconvenience concerning an interruption of your 
    service membership, in future. Please take just a moment and update your 
    eBay billing file. Remember to "doublecheck" all the fields for any possible
     mistakes.
      
    
    To respond and update your information , please click on the web address 
    below.  If that does not work, please cut and paste the entire web address 
    into the address field of your browser.
    
    
    http://64.177.3.234 Verify,Confirm and Update.
    
    
    Privacy is very important to us. Our privacy practices are held to high standards 
    by outside organizations such as TRUSTe. For more information on TRUSTe, 
    please go to www.truste.org. As part of the normal operation of our services we 
    collect and, in some cases, disclose information about you.
    
    
    Your information is secured! The information you supply below is used solely to 
    confirm its accuracy for verification purposes. The transfer of your information is 
    protected by secure 128-bit encrypted SSL connection. Your personal information 
    added in step 3 will not be stored by eBay Your credit rating will not be affected .
    ************************************************************************************************
    
    We use information in the file we maintain about you, and other information we 
    obtain from your current and past activities on the Site, to resolve disputes, 
    troubleshoot problems and enforce our User Agreement. At times, we may look 
    across multiple users to identify problems or resolve disputes, and in particular
     we may examine your information to identify users using multiple User IDs 
    or aliases.
    ________________________________________________________________
    
    For our latest announcements, please check:
    
    <A HREF="http://www2.ebay.com/av/announce.shtml"> latest announcements</a>.
    ________________________________________________________________
    
    In order to better serve you, we'd like to occasionally
    request feedback on our service. If you would rather
    not participate, please click on the link below and send
    us an email with the word "REMOVE" in the subject line.
    If that does not work, please send an email to the
    email address below. Your request will be processed
    within 5 days.
    
    mailto:csremoveat_private
    
    *************************************************************************************************
    800-546-2665, ATTN: Marry
    
    Regards,
    
    Henry
    eBay SafeHarbor
    Investigations Team
    ________________________________________________________________
    
    45678878978
    05/02/2002
    
    ----- End forwarded message -----
    
    
    
    -------------------------------------------------------------------------
    POLITECH -- Declan McCullagh's politics and technology mailing list
    You may redistribute this message freely if you include this notice.
    To subscribe to Politech: http://www.politechbot.com/info/subscribe.html
    This message is archived at http://www.politechbot.com/
    Declan McCullagh's photographs are at http://www.mccullagh.org/
    -------------------------------------------------------------------------
    Sign this pro-therapeutic cloning petition: http://www.franklinsociety.org
    -------------------------------------------------------------------------
    



    This archive was generated by hypermail 2b30 : Thu May 02 2002 - 05:50:14 PDT