On mySimon: Robert Rodriguez Studded-Band Skirt
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 5 of 8:
Next »
« Previous
When will people learn...
After examining a few of these scams, one thing the phishers do is put up a page that looks like the eBay login page but proxies the information to eBay. So when the phishers get your information, they validate it with eBay on their site using your information. If eBay returns an error, it returns the error to you. If the phishers do this, how will you know the site is bogus?

Oh... and don't expect the address line to help you. If you are using an older browser or have not patched IE recently, it is possible to fake the address line shown on your browser. And forget the status line, too. That is the easiest to fake!

The key is NOT to click through any URL sent via email. I do not care what email program you use, just don't do it.

Now, if eBay would stop sending formatted emails and force everything in the clear, you would see the URL before clicking. Or what they should do is tell you to go to eBay and check out your messages in the My eBay area, then you can get it from the site directly and not worry about phishing.

Ahh... social engineering hacks... this is what keeps us security folk employed and awake at nights!
Posted by: sbarman   Posted on: 03/07/05 You are currently: a Guest | Members login | Terms of Use

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

Testing Bogus Sites  George Jay | 03/04/05
True, BUT...  gordon@... | 03/06/05
FUD!  PA-ITGuy | 03/07/05
Not true....  DarbyOhara | 03/07/05
When will people learn...  sbarman | 03/07/05
its hard to overcome  baziltron | 03/06/05
Tin Foil Hat Time!  Geo.Frank | 03/07/05
Baloney!  DarbyOhara | 03/07/05

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Meet Doc