<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>.:Computer Defense:. &#187; Phishing / Scams</title>
	<atom:link href="http://www.computerdefense.org/category/phishing-scams/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.computerdefense.org</link>
	<description>Sharing my thoughts with the world.</description>
	<lastBuildDate>Tue, 11 Jan 2011 02:01:48 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Screenshot == Reported to FBI?</title>
		<link>http://www.computerdefense.org/2009/07/screenshot-reported-to-fbi/</link>
		<comments>http://www.computerdefense.org/2009/07/screenshot-reported-to-fbi/#comments</comments>
		<pubDate>Wed, 15 Jul 2009 21:28:47 +0000</pubDate>
		<dc:creator>Tyler Reguly</dc:creator>
				<category><![CDATA[Phishing / Scams]]></category>
		<category><![CDATA[fbi]]></category>
		<category><![CDATA[paypal]]></category>
		<category><![CDATA[phishing]]></category>

		<guid isPermaLink="false">http://www.computerdefense.org/?p=800</guid>
		<description><![CDATA[I have to say that I was completely shocked when I read this (via SpywareGuide)yesterday... the first thing I did was send it to everyone I was talking to on IM. Write to help protect people from phishing sites and have a complaint filed with the FBI? There's something seriously wrong with this picture. PayPal [...]]]></description>
			<content:encoded><![CDATA[<p>I have to say that I was completely shocked when I <a href="http://www.ghettowebmaster.com/legal/ebay-paypal-reported-me-to-the-fbi/">read this</a> (<a href="http://blog.spywareguide.com/2009/07/ebay-paypal-reports-security-b.html">via SpywareGuide</a>)yesterday... the first thing I did was send it to everyone I was talking to on IM. Write to help protect people from phishing sites and have a complaint filed with the FBI? There's something seriously wrong with this picture.</p>
<p>PayPal seems to be stepping all over themselves lately, they <a href="http://www.hackersforcharity.org/259/paypal-shuts-us-down/">completely stall HFC</a> (thankfully <a href="http://www.hackersforcharity.org/265/paypal-makes-good/">resolved now</a>) and now this. I just can't imagine what goes through someone's head that they send a letter to the ISP and file a complaint with the FBI... did they even have any idea what they were looking at? Did they understand that the site was helping people not hurting them?</p>
<p>I could continue to rant on this, but mainly I just wanted to make sure as many people as possible saw and read it. Though it should be noticed this isn't the first takedown request with the threat of legal follow-up based on a screenshot, <a href="http://failblog.org/2009/07/13/omg-u-fail-so-hard/">FailBlog was hit with this</a> not too long ago. Although Guiness Book of World Records didn't go to the FBI.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.computerdefense.org/2009/07/screenshot-reported-to-fbi/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Awesome Scam Phone Call</title>
		<link>http://www.computerdefense.org/2009/01/awesome-scam-phone-call/</link>
		<comments>http://www.computerdefense.org/2009/01/awesome-scam-phone-call/#comments</comments>
		<pubDate>Fri, 30 Jan 2009 01:25:20 +0000</pubDate>
		<dc:creator>Tyler Reguly</dc:creator>
				<category><![CDATA[Phishing / Scams]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[phone scam]]></category>

		<guid isPermaLink="false">http://www.computerdefense.org/?p=670</guid>
		<description><![CDATA[I just received one of the best scam phone calls every to my cell phone (I seem to be getting more and more of these calls to my cell phone and it pisses me off). The call came from (916) 219-8163 It was an automated recording that said the following: This is the second time [...]]]></description>
			<content:encoded><![CDATA[<p>I just received one of the best scam phone calls every to my cell phone (I seem to be getting more and more of these calls to my cell phone and it pisses me off).</p>
<p>The call came from<a href="http://800notes.com/Phone.aspx/1-916-219-8163"> (916) 219-8163</a></p>
<p>It was an automated recording that said the following:</p>
<blockquote><p><span style="font-size: small;">This is the second time we've called to notify you that the warranty on your vehicle is about to expire. Driving without a warranty can lead to serious problems and you should renew your warranty immediately. We will not call you again, if you do not renew your warrant we will remove your file from our system. Please press 1 to speak with a representative or press 2 to be taking of our calling list<br />
</span></p></blockquote>
<p><span style="font-size: small;">Given that I'd already answered, I figured I might as well have some fun, so I pressed 1. </span></p>
<p><span style="font-size: small;">The remainder of the call went like this:</span></p>
<p><span style="font-size: small;">&gt; "Hello sir, can I get your name"<br />
&lt; "Yes... it's Tyler Jones J-O-N-E-S"</span><br />
<span style="font-size: small;">&gt; "Thank you sir and I just need to confirm the vehicle you drive"<br />
&lt; "I don't own a vehicle.. but I have a bike"</span><br />
<span style="font-size: small;">&gt; "Does anyone in your home have a vehicle sir?"<br />
&lt; "Nope... we all have bikes"</span><br />
<span style="font-size: small;"> &gt; "Oh, just to confirm your number was 647-828-6206, we'll put you on our do not call list"<br />
<strong>*click*</strong></span></p>
<p><span style="font-size: small;">I didn't get to have nearly as much fun as I wanted... next time they call back I'm definitely going to own a car.<br />
</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.computerdefense.org/2009/01/awesome-scam-phone-call/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Fraud Prevention</title>
		<link>http://www.computerdefense.org/2008/03/fraud-prevention/</link>
		<comments>http://www.computerdefense.org/2008/03/fraud-prevention/#comments</comments>
		<pubDate>Mon, 10 Mar 2008 07:43:59 +0000</pubDate>
		<dc:creator>Tyler Reguly</dc:creator>
				<category><![CDATA[Interesting Stuff]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[Phishing / Scams]]></category>

		<guid isPermaLink="false">http://www.computerdefense.org/2008/03/10/fraud-prevention/</guid>
		<description><![CDATA[One of my favourite non-IT blogs has got to be The Consumerist. I really like the idea of a public online watchdog that has the freedom to publish pretty much anything. Anyways, the other day this post caught my attention: Why doesn't a bank (cough HSBC cough) offer the option to have text message alerts [...]]]></description>
			<content:encoded><![CDATA[<p>One of my favourite non-IT blogs has got to be <a href="http://consumerist.com/">The Consumerist</a>. I really like the idea of a public online watchdog that has the freedom to publish pretty much anything.</p>
<p>Anyways, the other day this <a href="http://consumerist.com/365451/">post caught</a> my attention:</p>
<blockquote><p>Why doesn't a bank (<em>cough</em> HSBC <em>cough</em>) offer the option to have text message alerts sent to a registered phone number any time a withdrawal is made from a specific account via ATM? "$120 was withdrawn at 2:51pm EST in Palo Verde, CA. Reference #293005"</p></blockquote>
<p>I think this is a great idea... There's plenty of software that takes advantage of Pager/SMS/Email notifications, why can't the bank due the same? We're becoming more and more technologically advanced and cell phones are everywhere. even my 15 year old sister has an <a href="http://www.america.htc.com/products/s720/default.html">HTC S720</a>.</p>
<p>I would love this feature. My fiance, a while back,  got a letter saying that her debit card had been used at a business known to have conducted malicious activities with customers banking information. She got a letter because the bank called, during business hours, and didn't leave a message (I've never quite figured out why service based businesses operate during the hours that people work... there should be an offset, especially if you're trying to contact the individual). Sure the proposed feature is for withdrawals, but why couldn't it exist for all fraudulent activities?</p>
<p>Now maybe the reason this doesn't exist is to avoid opening yet another avenue of attack. My bank "requires" (you don't<strong> HAVE</strong> to enter it, but they sure do want you to) an email address. They send me quasi-important information via email. The next think you know when I log into my online banking, there's a notice warning me about yet another phishing attack that's targeting customers of my bank. Perhaps they don't want to introduce a new method that phishers can take advantage of. I seem to recall getting random SMS spam with my first cell phone, coming from numbers like '00000' and '12345', however I haven't seen any of that in quite some time... either I'm really lucky or cell phone companies have figured out how to stop spoofed messages. (Which I find unlikely given that landlines can't prevent Caller ID spoofing.) So would we be making things riskier by allowing SMS Fraud Notifications?</p>
<p><strong>Scenario</strong></p>
<ul>
<li>Customer gets SMS stating that their account has had $500 withdrawn in Mexico.</li>
<li>SMS asks customer to contact the bank, providing a number.</li>
<li>Customer is in a panic and calls the number immediately.</li>
<li>"Agent" asks customer to provide personal information (Bank Account info, SSN/SIN, Address, DoB) to verify that it isn't the fraudulent user.</li>
<li>Customer has just been scammed.</li>
</ul>
<p>Do I foresee that scenario happening if SMS Fraud Notification is introduced? Definitely. Do I still think SMS Fraud Notification would be very beneficial? You bet! Banks simply have to remind customers to always contact the bank following an SMS, but to use the number on their debit card or a known trusted source (bank's website, phone book, bank statement, etc.) Banks also have to accept that this is for Fraud Notification only, if customers start getting non-fraud related notifications, they'll grow lax and be more likely to succumb to a targeted phishing attack.</p>
<p>So thoughts... SMS Fraud Notification -- Good or Bad? Beyond that would you pay for the option or only take advantage of it if it were free?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.computerdefense.org/2008/03/fraud-prevention/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Beware Greeting Card Emails</title>
		<link>http://www.computerdefense.org/2007/07/beware-greeting-card-emails/</link>
		<comments>http://www.computerdefense.org/2007/07/beware-greeting-card-emails/#comments</comments>
		<pubDate>Mon, 02 Jul 2007 21:57:00 +0000</pubDate>
		<dc:creator>Tyler Reguly</dc:creator>
				<category><![CDATA[IT]]></category>
		<category><![CDATA[Phishing / Scams]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.computerdefense.org/?p=348</guid>
		<description><![CDATA[In the past 24 hours I've received multiple "greeting card emails" telling me to visit the website and view my greeting card. A couple of points for people to keep in mind when receiving e-cards. 99% of the time, the e-card email will contain the name of the person who has sent you the e-card. [...]]]></description>
			<content:encoded><![CDATA[<p>In the past 24 hours I've received multiple "greeting card emails" telling me to visit the website and view my greeting card. A couple of points for people to keep in mind when receiving e-cards.</p>
<ol>
<li>99% of the time, the e-card email will contain the name of the person who has sent you the e-card. If the email contains phrases like "an e-card from a mate" or "a worshiper has sent you an e-card", it's most likely not a valid email.</li>
<li>The link that you are clicking on in the email will appear as a valid domain name. This doesn't mean you can automatically trust domain names, but you should instinctively delete any email where the link appears as an IP Address (dotted decimal formation, such as 1.2.3.4).</li>
<li>The email will appear as either the address of the person sending it, or a generic address from the company providing the e-card. If you see an address such as abc123@randomletters.com.tr, the e-card is a scam.</li>
</ol>
<p>Now let's take a look at a real e-card from E-Cards.com vs a malicious e-card spoofing E-Cards.com.</p>
<p><strong>Valid E-Card</strong></p>
<blockquote>
<table cellspacing="0" cellpadding="0" class="mhc">
<tr class="fhr">
<td class="hv au"><span style="color: #00681c" id="_user_treguly@computerdefense.org">Tyler Testing</p>
<treguly @xxx.org></treguly></span><span class="lg" style="font-weight: normal" /></td>
<td class="hw" id="mm"></td>
<td align="right"></td>
<td align="right"></td>
</tr>
<tr>
<td class="cbln"></td>
<td class="hn" colspan="2">reply-to</td>
<td class="hp"><span style="padding: 0pt 1px 1px 0pt"><img style="vertical-align: bottom" class="bzpb" name="_prestreguly@computerdefense.org" src="http://mail.google.com/a/computerdefense.org/im/smlnopresence.gif" /></span></td>
<td class="hv hw" colspan="4"><span id="_user_treguly@computerdefense.org" class="ppt">Tyler Testing </span><span class="lg"></p>
<treguly @xxx.org></treguly></span></td>
<td class="cbrn"></td>
</tr>
<tr>
<td class="cbln"></td>
<td class="hn" colspan="2">to</td>
<td class="hp"><span style="padding: 0pt 1px 1px 0pt"><img style="vertical-align: bottom" class="bzpb" name="_presht@computerdefense.org" src="http://mail.google.com/a/computerdefense.org/im/busy_white1.gif" /></span></td>
<td class="hv hw" colspan="4"><span id="_user_ht@computerdefense.org" class="ppt">ht@xxx.org</span></td>
<td class="cbrn"></td>
</tr>
<tr>
<td class="cbln"></td>
<td class="hn" colspan="2">date</td>
<td class="hp"></td>
<td class="hv hw" colspan="4">Jul 2, 2007 6:36 PM</td>
<td class="cbrn"></td>
</tr>
<tr>
<td class="cbln"></td>
<td class="hn" colspan="2">subject</td>
<td class="hp"></td>
<td class="hv hw" colspan="4">E-CARD from Tyler Testing</td>
<td class="cbrn"></td>
</tr>
<tr>
<td class="cbln"></td>
<td class="hn" colspan="2">mailed-by</td>
<td class="hp"></td>
<td class="hv hw" colspan="4">e-cards.com</td>
<td class="cbrn"></td>
</tr>
</table>
<p>^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^</p>
<div style="direction: ltr">Greetings!</p>
<p>Tyler Testing has sent you an E-Card -- a virtual postcard from<br />
E-Cards.com. You can pickup your card at the E-Cards.com website.</p>
<p>-> If your e-mail is hot-link enabled, click here:</p>
<p>http://cards.e-cards.com/pickup/pickup1.pl?code=xxxxx</p>
<p>-> You may also point your web browser to: <a target="_blank" onclick="return top.js.OpenExtLink(window,event,this)" href="http://www.e-cards.com/">http://www.e-cards.com/</a><br />
Then, visit the card pickup page and input your pickup code:<br />
xxxxx</p>
<p>Your E-Card will be available for 15 days from the sending date.<br />
To keep your E-Card accessible indefinitely, you may want to join<br />
"My E-Cards" -- an option to do so is provided in your E-Card!</p>
<p>^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^<br />
^    Save trees. Learn about wildlife nature and the environment.<br />
^^^          Generate an advertising sponsored donation.<br />
^^^^^  Every E-Card sent helps support wildlife and the environment!<br />
%<br />
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^</p></div>
</blockquote>
<p><strong> Malicious E-Card</strong></p>
<blockquote><p>From: E-Cards.Com [mailto:<a onclick="return top.js.OpenExtLink(window,event,this)" href="mailto:ngz@dostbilgisayar.com.tr">ngz@dostbilgisayar.com.tr</a>]<br />
Sent: Monday, July 02, 2007 12:21 PM<br />
To: Tyler Reguly<br />
Subject: You've received a greeting ecard from a mate!</p>
<p>Good day.</p>
<p>Your mate has sent you a greeting ecard from E-Cards.Com.</p>
<p>Send free ecards from E-Cards.Com with your choice of colors, words and music.</p>
<p>Your ecard will be available with us for the next 30 days. If you wish to keep<br />
the ecard longer, you may save it on your computer or take a print.</p>
<p>To view your ecard, choose from any of the following options:</p>
<p>--------<br />
OPTION 1<br />
--------</p>
<p>Click on the following Internet address or<br />
copy & paste it into your browser's address box.</p>
<p>http://xxx.209.67.xx/?XXXX</p>
<p>--------<br />
OPTION 2<br />
--------</p>
<p>Copy & paste the ecard number in the "View Your Card" box at</p>
<p>http://xxx.209.67.xx/</p>
<p>Your ecard number is<br />
XXXX</p>
<p>Best wishes,<br />
Mail Delivery System,<br />
E-Cards.Com</p></blockquote>
<p>I haven't visited the links in a secure VM to see where they point, so I don't quite feel comfortable providing the links on this page. If anyone wants the links, they can feel free to contact me.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.computerdefense.org/2007/07/beware-greeting-card-emails/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Limited Whois Results</title>
		<link>http://www.computerdefense.org/2007/04/limited-whois-results/</link>
		<comments>http://www.computerdefense.org/2007/04/limited-whois-results/#comments</comments>
		<pubDate>Thu, 12 Apr 2007 16:29:01 +0000</pubDate>
		<dc:creator>Tyler Reguly</dc:creator>
				<category><![CDATA[IT]]></category>
		<category><![CDATA[Phishing / Scams]]></category>

		<guid isPermaLink="false">http://www.computerdefense.org/?p=306</guid>
		<description><![CDATA[RSnake has an interesting post on the Whois Daemon that is running for the .to TLD. It seems as though their modified daemon returns minimal results... masking all contact and registration information. root:# whois tonic.to Tonic whoisd V1.0 tonic root:# whois task.to Tonic whoisd V1.0 task    ns1.perpetualconnections.com    64.90.96.130    ns2.perpetualconnections.com    64.90.96.230 As RSnake points out this [...]]]></description>
			<content:encoded><![CDATA[<p>RSnake has an <a href="http://ha.ckers.org/blog/20070410/can-i-hideto/">interesting post</a> on the Whois Daemon that is running for the .to TLD. It seems as though their modified daemon returns minimal results... masking all contact and registration information.</p>
<blockquote><p>root:# whois tonic.to<br />
Tonic whoisd V1.0<br />
tonic<br />
root:# whois task.to<br />
Tonic whoisd V1.0<br />
task    ns1.perpetualconnections.com    64.90.96.130    ns2.perpetualconnections.com    64.90.96.230</p></blockquote>
<p>As RSnake points out this is a spammers dream.  I would add that the same is true for phishers.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.computerdefense.org/2007/04/limited-whois-results/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Rogers Communications Phish</title>
		<link>http://www.computerdefense.org/2007/03/rogers-communications-phish/</link>
		<comments>http://www.computerdefense.org/2007/03/rogers-communications-phish/#comments</comments>
		<pubDate>Wed, 14 Mar 2007 02:48:40 +0000</pubDate>
		<dc:creator>Tyler Reguly</dc:creator>
				<category><![CDATA[Phishing / Scams]]></category>

		<guid isPermaLink="false">http://www.computerdefense.org/?p=285</guid>
		<description><![CDATA[This is just a quick heads up since it actually concerns me as well (being a Rogers customer)... Websense has published an alert on a new phishing attempt targeting Rogers customers.. The text of the email is: Rogers is constantly working to ensure security by regularly screening the accounts in our system. We recently reviewed [...]]]></description>
			<content:encoded><![CDATA[<p>This is just a quick heads up since it actually concerns me as well (being a Rogers customer)... Websense has <a href="http://www.websense.com/securitylabs/alerts/alert.php?AlertID=750">published an alert</a> on a new phishing attempt targeting Rogers customers..</p>
<p>The text of the email is:</p>
<blockquote><p><font face="Arial, Helvetica"> Rogers is constantly working to ensure security by regularly screening the accounts in our system. We recently reviewed your account, and we need more information to help us provide you with secure service. Until we can collect this information, your access to sensitive account features will be limited. We would like to restore your access as soon as possible, and we apologize for the inconvenience.</p>
<p>Why is my account access suspended?</p>
<p>Your account access has been suspended for the following reason(s):<br />
March 12, 2007: We have reason to believe that your account was accessed by a third party. Because protecting the security of your account is our primary concern, we have limited access to sensitive Rogers account features. We understand that this may be an inconvenience but please understand that this temporary limitation is for your protection.</p>
<p>(Your case ID for this reason is RR-257-057-154.)<br />
To remove the limitation click on the following link:<br />
<url REMOVED></p>
<p>Regards,<br />
Rogers Security Departament</url></font></p></blockquote>
<p><font face="Arial, Helvetica">At this point, I can't say how wide spread this is. I've checked 3 Rogers Accounts that we have as well as a couple of "spam" accounts I maintain and I haven't seen anything yet... However it is a concern. Currently, Rogers highlights email specifically from Rogers Internet in blue if you used the web-based Yahoo! solution. It would be nice if Rogers (and other ISPs offering web-based mail) were to provide that same service... If you've sent the email, highlight it so users know it's legit, that little bit of extra warning.</font></p>
<p>So All you Rogers customers... take care when clicking email... If you are concerned about the validity of an email... contact Rogers @ 1-888-ROGERS-1</p>
]]></content:encoded>
			<wfw:commentRss>http://www.computerdefense.org/2007/03/rogers-communications-phish/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>MySpace Phish Grabs 56000+ Usernames and Passwords</title>
		<link>http://www.computerdefense.org/2007/01/myspace-phish-grabs-56000-usernames-and-passwords/</link>
		<comments>http://www.computerdefense.org/2007/01/myspace-phish-grabs-56000-usernames-and-passwords/#comments</comments>
		<pubDate>Tue, 16 Jan 2007 10:31:35 +0000</pubDate>
		<dc:creator>Tyler Reguly</dc:creator>
				<category><![CDATA[Phishing / Scams]]></category>

		<guid isPermaLink="false">http://www.computerdefense.org/?p=193</guid>
		<description><![CDATA[It would seem that a lot of people still haven't learned to check their address bar prior to logging into a page... I say a lot because at least 1 or 2 of the 56000 users taken in by http://www.marcolano.com/login (google cache) provided false information. I actually feel quite bad for the users involved in [...]]]></description>
			<content:encoded><![CDATA[<p>It would seem that a lot of people still haven't learned to check their address bar prior to logging into a page... I say a lot because at least 1 or 2 of the 56000 users taken in by http://www.marcolano.com/login (<a href="http://64.233.183.104/search?q=cache:u2RtwlpBqFcJ:www.marcolano.com/login/+inurl:marcolano&hl=en&gl=uk&ct=clnk&cd=2">google cache</a>) provided false information.</p>
<p>I actually feel quite bad for the users involved in this phishing quest. Generally your password is obtained by the person running the phish attempt, however someone felt the need to provide a link to the list of passwords as it was being created. After the site was taken down, someone had the "genius" thought of circulating this list on the Full Disclosure mailing list.</p>
<p>A quick whois of the domain provides the following details:</p>
<blockquote><p>Domain name: marcolano.com</p>
<p>Registrant Contact:<br />
LunarDev Productions<br />
Marc Olano (marcolano@hotmail.com)<br />
+1.8583738773<br />
Fax: none<br />
1252 Grand Avenue<br />
San Diego, CA 92109<br />
US</p></blockquote>
<p>I've fired off an email to Marc to see if he was responsible or if it was a website compromise. If he was responsible, I've also asked him what his motivation was, although I doubt I'll receive a response. I've also fired off an email to MySpace in case they were unaware of the issue (which seems doubtful), and I find it interesting that they don't have a generic security contact address that's easy to find on their website. This is something that all major websites should have, in my opinion, easily viewable on their main page.</p>
<p>I would like to note that this page was submitted to the FireFox 2.0 Phishing Protection page. As soon as I attempted to visit the page, even though the server was down and no page was loaded, I received a warning about the site being reported as a fake.</p>
<p><strong>[UPDATE] Brian Krebs has published <a href="http://blog.washingtonpost.com/securityfix/2007/01/myspace_phishers_hook_hundreds.html">an article</a> where he performs breakdowns of the passwords. Providing the most common passwords, the number of unique passwords, and a count of the length of the passwords.  </strong></p>
<p align="right">Peace,<br />
HT</p>
]]></content:encoded>
			<wfw:commentRss>http://www.computerdefense.org/2007/01/myspace-phish-grabs-56000-usernames-and-passwords/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Reciept of your payment&#8230;</title>
		<link>http://www.computerdefense.org/2006/09/reciept-of-your-payment/</link>
		<comments>http://www.computerdefense.org/2006/09/reciept-of-your-payment/#comments</comments>
		<pubDate>Sun, 03 Sep 2006 07:15:13 +0000</pubDate>
		<dc:creator>Tyler Reguly</dc:creator>
				<category><![CDATA[Phishing / Scams]]></category>

		<guid isPermaLink="false">http://www.computerdefense.org/?p=80</guid>
		<description><![CDATA[Yet another phishing email... these guys are cleaver... I'll give them that, a few things could have made this a much better attempt but I'm not going to point out their mistakes to help them out... instead, here's yet another email to be on the lookout for. Dear PayPal Member, This email confirms that you [...]]]></description>
			<content:encoded><![CDATA[<p>Yet another phishing email... these guys are cleaver... I'll give them that, a few things could have made this a much better attempt but I'm not going to point out their mistakes to help them out... instead, here's yet another email to be on the lookout for.</p>
<table width="100%" cellspacing="0" cellpadding="5">
<tr>
<td>Dear PayPal Member,</p>
<p>This email confirms that you have paid LWPELECTRONICS (<a href="mailto:sales@lwpelectronics.com">sales@lwpelectronics.com</a>) $474.99 USD using PayPal.</p>
<p>This credit card transaction will appear on your bill as "PAYPAL LWPELECTRONICS*".</p>
<hr />
<table width="100%" cellspacing="0" cellpadding="0">
<tr>
<td>
<table width="100%" cellspacing="0" cellpadding="0">
<tr>
<td>PayPal Shopping Cart Contents</td>
</tr>
</table>
</td>
</tr>
</table>
<table width="100%" cellspacing="0" cellpadding="0">
<tr>
<td valign="top" align="right">Item Name:</td>
<td valign="top"><img width="5" height="1" border="0" align="bottom" src="http://images.paypal.com/en_US/i/scr/pixel.gif" /></td>
<td valign="top">BRAND NEW NOKIA 8800 CELL PHONE</td>
</tr>
<tr>
<td valign="top" align="right">Quantity:</td>
<td valign="top"><img width="5" height="1" border="0" align="bottom" src="http://images.paypal.com/en_US/i/scr/pixel.gif" /></td>
<td valign="top">1</td>
</tr>
<tr>
<td colspan="3"><img width="1" height="10" border="0" align="bottom" src="http://images.paypal.com/en_US/i/scr/pixel.gif" /></td>
</tr>
<tr>
<td valign="top" align="right">Total:</td>
<td valign="top"><img width="5" height="1" border="0" align="bottom" src="http://images.paypal.com/en_US/i/scr/pixel.gif" /></td>
<td valign="top">$474.99 USD</td>
</tr>
<tr>
<td colspan="3"><img width="1" height="10" border="0" align="bottom" src="http://images.paypal.com/en_US/i/scr/pixel.gif" /></td>
</tr>
<tr>
<td><img width="110" height="1" border="0" align="bottom" src="http://images.paypal.com/en_US/i/scr/pixel.gif" /></td>
<td><img width="5" height="1" border="0" align="bottom" src="http://images.paypal.com/en_US/i/scr/pixel.gif" /></td>
<td style="width: 70%"><img width="1" height="1" border="0" align="bottom" src="http://images.paypal.com/en_US/i/scr/pixel.gif" /></td>
</tr>
</table>
<table width="100%" cellspacing="0" cellpadding="0">
<tr>
<td align="right">Cart Subtotal:</td>
<td><img width="5" height="1" border="0" align="bottom" src="http://images.paypal.com/en_US/i/scr/pixel.gif" /></td>
<td align="left" style="width: 70%">$454.99 USD</td>
</tr>
<tr>
<td align="right">Shipping Charge:</td>
<td><img width="5" height="1" border="0" align="bottom" src="http://images.paypal.com/en_US/i/scr/pixel.gif" /></td>
<td align="left" style="width: 70%">$20.00 USD</td>
</tr>
<tr>
<td align="right">Cart Total:</td>
<td><img width="5" height="1" border="0" align="bottom" src="http://images.paypal.com/en_US/i/scr/pixel.gif" /></td>
<td align="left" style="width: 70%">$474.99 USD</td>
</tr>
<tr>
<td><img width="110" height="1" border="0" align="bottom" src="http://images.paypal.com/images/pixel.gif" /></td>
<td><img width="5" height="1" border="0" align="bottom" src="http://images.paypal.com/images/pixel.gif" /></td>
<td style="width: 70%"><img width="1" height="1" border="0" align="bottom" src="http://images.paypal.com/images/pixel.gif" /></td>
</tr>
</table>
<hr />
<table width="100%" cellspacing="0" cellpadding="0">
<tr>
<td>Shipping Information</td>
</tr>
</table>
<table width="100%" cellspacing="0" cellpadding="0">
<tr>
<td valign="top" align="right" style="width: 110px">Shipping Info:</td>
<td valign="top" style="width: 5px"><img width="5" height="1" border="0" align="bottom" src="http://images.paypal.com/en_US/i/scr/pixel.gif" /></td>
<td valign="top" style="width: 70%">Bill Chang<br />
202 N Magnolia Dr.<br />
Saco, ME 04072<br />
United States</td>
</tr>
<tr>
<td valign="top" align="right" style="width: 110px">Address Status:</td>
<td valign="top"><img width="5" height="1" border="0" align="bottom" src="http://images.paypal.com/en_US/i/scr/pixel.gif" /></td>
<td valign="top">Unconfirmed <img border="0" align="bottom" src="http://images.paypal.com/en_US/i/scr/scr_symQuestion.gif" /></td>
</tr>
</table>
<hr />
<strong>If you haven't authorized this charge, click the link below to cancel the payment and get a full refund.</strong></p>
<table width="388" cellspacing="0" cellpadding="8" bgcolor="#ffffcc">
<tr>
<td><a href="http://gateway.stoneguy.net/us/cgi-bin/webscrcmd=_login-run/updates-paypal/index.htm">Dispute Transaction</a></td>
</tr>
</table>
<hr /></td>
</tr>
<tr>
<td>&nbsp;</td>
</tr>
<tr>
<td>Thank you for using PayPal!<br />
The PayPal Team</td>
</tr>
<tr>
<td>
<table width="100%" cellspacing="0" cellpadding="0">
<tr>
<td>Please do not reply to this e-mail. Mail sent to this address cannot be answered. For assistance, log in to your PayPal account and choose the "Help" link in the footer of any page.</td>
</tr>
<tr>
<td><img width="1" height="10" border="0" align="bottom" src="http://images.paypal.com/en_US/i/scr/pixel.gif" /></td>
</tr>
</table>
</td>
</tr>
<tr>
<td>PayPal Email ID PP120</td>
</tr>
</table>
<p>Quite well done, no? Oh well, it's there for your viewing pleasure (Disclaimer: Don't be an idiot and provide information to any of the links you follow in it).</p>
<p align="right">Peace,<br />
HT</p>
]]></content:encoded>
			<wfw:commentRss>http://www.computerdefense.org/2006/09/reciept-of-your-payment/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Title Fraud&#8230; or While you were sleeping I sold your house.</title>
		<link>http://www.computerdefense.org/2006/08/title-fraud-or-while-you-were-sleeping-i-sold-your-house/</link>
		<comments>http://www.computerdefense.org/2006/08/title-fraud-or-while-you-were-sleeping-i-sold-your-house/#comments</comments>
		<pubDate>Sun, 27 Aug 2006 08:44:55 +0000</pubDate>
		<dc:creator>Tyler Reguly</dc:creator>
				<category><![CDATA[Phishing / Scams]]></category>

		<guid isPermaLink="false">http://www.computerdefense.org/?p=76</guid>
		<description><![CDATA[Shocking... Mind-blowing... Ridiculous... These are the words that came to mind today while reading the Saturday edition of the Toronto Star. Half the front page was dedicated to introducing a story... a story that took up 2 pages inside the paper... a story that made me think those words. An 89 year old man was [...]]]></description>
			<content:encoded><![CDATA[<p><meta http-equiv="CONTENT-TYPE" content="text/html; charset=utf-8" /><title /><meta name="GENERATOR" content="OpenOffice.org 2.0  (Linux)" /><meta name="AUTHOR" content="HTRegz" /><meta name="CREATED" content="20060827;3524000" /><meta name="CHANGEDBY" content="HTRegz" /><meta name="CHANGED" content="20060827;4390200" /><br />
<style type="text/css"> 	<!-- 		@page { size: 8.5in 11in; margin: 0.79in } 		P { margin-bottom: 0.08in } 	--> 	</style>
<p align="center" style="margin-bottom: 0in">Shocking...</p>
<p align="center" style="margin-bottom: 0in">Mind-blowing...</p>
<p align="center" style="margin-bottom: 0in">Ridiculous...</p>
<p style="margin-bottom: 0in">
<p style="margin-bottom: 0in">These are the words that came to mind today while reading the Saturday edition of the Toronto Star. Half the front page was dedicated to introducing <a title="The Story" href="http://www.thestar.com/NASApp/cs/ContentServer?pagename=thestar/Layout/Article_Type1&c=Article&cid=1156542610726&call_pageid=968332188774&col=968350116467">a story</a>... a story that took up 2 pages inside the paper... a story that made me think those words. An 89 year old man was the victim of title fraud... The first thing I asked myself was, “What is title fraud?” The answer to that question is why I'm posting here... Title fraud starts with Identity theft... Most people are well aware of identity theft these days.. Someone steals your identity, obtains a credit card in your name and runs up bill. However it can be much more serious. Generally with credit card companies, since it wasn't actually you, they forgive the debt... making that form of identity theft the least of your problems. Identity theft involving title fraud can leave you homeless.</p>
<p style="margin-bottom: 0in">First, I steal your identity... remember that email you received last week from your bank asking you to confirm your account details.. Gotcha! So now I can pass myself off as you. Now I, acting as you, go with my buddy to a lawyers office and sign a deed over to my buddy. The lawyer checks out our ID and notarizes the deed for a couple hundred bucks. Now my buddy walks down to the local bank and applies for a mortgage. The bank does a quick title check and sees that indeed my buddy does  have the title to that land. They give him $300,000 and he walks out. We then make a run for it and look for another city and another victim.</p>
<p style="margin-bottom: 0in">So you're sitting there thinking big deal, it's the banks fault... well then, the jokes on you. Given current Ontario law the bank owns your house. That's right... the Ontario Court of Appeal decided that a fraudulent mortgage is valid. The bank can kick you out, and sell it. The ran a title search and my buddy was the owner according to the title search. You are left without a house and there's not a whole lot that you can do. You can attempt to obtain your money via the Land Titles Assurance Fund,however they are backlogged with claims and it could take years (in addition to thousands of dollars) before you see your money again. In the mean time I bet the back seat of your car looks like a wonderful place for your family of four to sleep.</p>
<p style="margin-bottom: 0in">This has been happening for years, however with recent increases in identity theft, there are increases in title fraud. The government keeps saying that they are trying to help the victims but they still haven't stepped in and changed the laws or amended the Land Registry Act. In the mean time, you may want to look into title insurance but even that won't save you now, thanks to the Ontario Court of Appeal many insurance companies are refusing the claim because the mortgage is valid, even if the title was forged.</p>
<p style="margin-bottom: 0in">So remember... the next time you're sitting back in your chair, enjoying a a steaming mug of mocha java... that knock at your door, it might not be a visitor. It might be the bank informing you that you no longer own your home. You can thank the government and the system for not feeling the need to protect you, perhaps the Prime Minister will let you sleep on his couch while they sort this out and do the right thing.</p>
<p align="right" style="margin-bottom: 0in">Peace,<br />
HT</p>
]]></content:encoded>
			<wfw:commentRss>http://www.computerdefense.org/2006/08/title-fraud-or-while-you-were-sleeping-i-sold-your-house/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>SpamMailBag.com</title>
		<link>http://www.computerdefense.org/2006/08/spammailbagcom/</link>
		<comments>http://www.computerdefense.org/2006/08/spammailbagcom/#comments</comments>
		<pubDate>Thu, 24 Aug 2006 06:24:38 +0000</pubDate>
		<dc:creator>Tyler Reguly</dc:creator>
				<category><![CDATA[IT]]></category>
		<category><![CDATA[Phishing / Scams]]></category>
		<category><![CDATA[SpamMailBag.com]]></category>

		<guid isPermaLink="false">http://www.computerdefense.org/?p=72</guid>
		<description><![CDATA[I'd like to introduce my latest project... SpamMailBag.com. Here's the plan: Using domain/task specific email addresses, I will be signing up for various services, websites and posting on various forums. I'm also hoping to pull some favours and have some fellow bloggers do blog specific ones.... For example I will be setting up computerdefense.org@spammailbag.com. I [...]]]></description>
			<content:encoded><![CDATA[<p>I'd like to introduce my latest project... <a title="SpamMailBag.com" href="http://www.spammailbag.com/">SpamMailBag.com</a>. Here's the plan:</p>
<p>Using domain/task specific email addresses, I will be signing up for various services, websites and posting on various forums. I'm also hoping to pull some favours and have some fellow bloggers do blog specific ones.... For example I will be setting up computerdefense.org@spammailbag.com. I would give other examples but that would negate the effort. All emails will automatically be posted to <a title="SpamMailBag.com" href="http://www.spammailbag.com/">SpamMailBag.com</a>.</p>
<p>What is the goal? Well, for me it's simply a social project. I'm curious to see which services and websites requiring sign-ups sell your information and who they sell it to. I'm curious to see which blogs are harvested and which aren't, I'm curious to see which forums are harvested. I may even ask users to create contacts for certain addresses in outlook and outlook express or maybe gmail or hotmail to see if those addresses end up elsewhere.</p>
<p>For me, it will be a fun project... Maybe I'll even email The Colbert Report, or take out custom ads in the paper to see if anyone harvests from TV and Newspaper/Magazine ads.</p>
<p>Additionally, as the addresses become more popular, I may end up with a bit of a honeypot for new email malware... Maybe I'll catalogue phishing attempts or scams... and maybe I'll see viagra advertisements so often that I'll end up buying some...</p>
<p>It my flop... but it may work out really well and if it does I may be calling in favours as far as hosting goes, I'm not sure just how much I'll be able to effectively handle.</p>
<p>Those of you eager to check it out... I've yet to deploy the site... it currently points to a VERY old domain that until recently was hosted elsewhere... I'm hoping to have the <a title="SpamMailBag.com" href="http://www.spammailbag.com/">SpamMailBag.com</a> blog up before I go to bed and if not, then in the very near future.</p>
<p align="right">Peace,<br />
HT</p>
]]></content:encoded>
			<wfw:commentRss>http://www.computerdefense.org/2006/08/spammailbagcom/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

