Scam
Scam

Users alerted to fake PayPal site scam

Fraudsters obtain valid SSL certificate to dupe users with fake e-wallet scheme

James Middleton

US internet monitor Internet Storm Centre (ISC) has warned web users of a fake website capitalising on the PayPal e-wallet system.

The fake site uses a valid secure sockets layer (SSL) certificate to dupe visitors into believing they are accessing a bona fide secure site.

Advertisement

It then compounds the deception by using a CGI script to redirect the user to the actual PayPal login page.

The scam, which hopes to gain information that can be used for identity or credit card fraud, makes use of a well-known technique called URL masking which uses a username and password prefix in the address to fool the unwary.

HTTP URLs can include user name and passwords for http basic authentication, which are added to the URL in the following syntax: http://username:password@www.somewebsite.com/somepage.html.

And if no authentication is required by the site, the user name and password are ignored.

The ISC said the particular URL of this fake site is https://ki54ft.worldispnetwork.com/i.CgI, and that in the spam email promoting it, the URl appears as: https://www.paypal.com:ac=alksdjflakdjflkasdjruoiwehjrlkajdf@KI54fT. WoRlDiSpNeTwOrK.CoM/i.CgI?billing@yourdomain.com

Although the ISC receives almost daily reports of fake PayPal or eBay sites it warned that, because this site appeared to be secure, it appeared more plausible and genuine.

"In most cases, these scam sites are easily spotted as they are not using SSL. Sometimes they attempt to hide this fact by increasing the browser window size to push the lower part of the browser window off the screen, so users will not see the open browser lock," said the ISC.

"However, this latest site uses a valid SSL certificate for the host site. Unless users inspect the certificate in more detail, they will not see the problem."

The fake URL is overly long to hide the actual host name, which comes after the '@' symbol. The misleading text before this is a username and password which will be ignored.

The ISC said that the web page uses a wild card certificate for 'worldispnetwork.com'.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

Microsoft thanks FBI for nabbing scammer

MSN email fraudster pleads guilty

Net credit card scam uncovered

Bogus internet transactions expose e-commerce security hole

Ebay to buy PayPal

Dotcom survivors announce merger

Police arrest two in alleged $50m net fraud

Third man on the run after FBI bust investment scam.

Related whitepapers

Related jobs

Most watched

V3.co.uk weekly debrief, 13 Nov 09

This week we discuss the inaugural V3.co.uk Summit

Summit: Salesforce.com on SaaS and information overload

How web services contribute to data headaches

Analysis and Reports

Remote access - Three steps to getting connected

3.4 million UK professionals now work from home – is your company equipped?

Cost benefits of a global collaboration network

This white paper is a must read for organisations looking for evidence of the bottom-line benefits of high-definition video and voice communications

Poll

Impact of Information Overload poll

Impact of Information Overload poll

What is the biggest problem your firm faces as a result of the data explosion?

View poll results

Advertisement

White paper library

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Spotlight

V3.co.uk weekly debrief, 13 Nov 09

This week we discuss the inaugural V3.co.uk Summit

Fingers on keyboard

New Flash vulnerability discovered

Web sites could be vulnerable to Flash attacks

Chris Adams

Summit: Microsoft Office to the rescue

Chris Adams, Office Client product manager for Microsoft UK, explains...

Illegal downloader

Industry and human rights campaigners united in opposition to "three strikes" plan

Critics says government proposals to curb illegal downloading are unworkable...

Primary Navigation