Notices
Non Scooby Related Anything Non-Scooby related

Fake site ?

Thread Tools
 
Search this Thread
 
Old 11 November 2008, 02:56 PM
  #1  
Luan Pra bang
Scooby Regular
Thread Starter
 
Luan Pra bang's Avatar
 
Join Date: Jan 2004
Posts: 4,207
Likes: 0
Received 0 Likes on 0 Posts
Default Fake site ?

Can anyone tell wether or not this paypal wite is real, tryinf to work out if I am dealing with a scammer or not. https://www.paypal.com/uk/cgi-bin/we...ster-or-login&
Old 11 November 2008, 02:57 PM
  #2  
SwissTony
Scooby Regular
iTrader: (19)
 
SwissTony's Avatar
 
Join Date: Mar 2003
Location: In the Doghouse
Posts: 28,228
Received 12 Likes on 3 Posts
Default

It looks good as it has the https in it, but the proper site is always

Welcome - PayPal
Old 11 November 2008, 03:00 PM
  #3  
stevem2k
Scooby Regular
 
stevem2k's Avatar
 
Join Date: Sep 2001
Location: Kingston ( Surrey, not Jamaica )
Posts: 4,670
Likes: 0
Received 0 Likes on 0 Posts
Default

yep. FAKE

HTML/Spoofing.Gen script virus picked up by Avira
Old 11 November 2008, 03:01 PM
  #4  
Snazy
Scooby Regular
 
Snazy's Avatar
 
Join Date: Dec 2006
Location: S.E London
Posts: 13,654
Likes: 0
Received 0 Likes on 0 Posts
Default

If in doubt, log in the way you usually do.
As a rule I never follow email links. Especially when it is anything to do with money.
Old 11 November 2008, 03:05 PM
  #5  
Luan Pra bang
Scooby Regular
Thread Starter
 
Luan Pra bang's Avatar
 
Join Date: Jan 2004
Posts: 4,207
Likes: 0
Received 0 Likes on 0 Posts
Default

I don't even have a paypal account its just that some 0 feed back idiot won an item on ebay and it all seemed a bit suspect. Then this paypal link arrived and it seemed clear that it was a scam.
Old 11 November 2008, 03:06 PM
  #6  
SwissTony
Scooby Regular
iTrader: (19)
 
SwissTony's Avatar
 
Join Date: Mar 2003
Location: In the Doghouse
Posts: 28,228
Received 12 Likes on 3 Posts
Default

Also go to http://www.paypal.com click the top right to select your country and language. Now you see the main graphics and page when you get redirected. All kosher

Now compare it to the site you get directed to from your link

subtle eh ???
Old 11 November 2008, 04:39 PM
  #7  
sarasquares
Scooby Regular
iTrader: (1)
 
sarasquares's Avatar
 
Join Date: Jul 2003
Location: Selling the scoob to buy a CTR
Posts: 55,951
Received 1 Like on 1 Post
Default

Originally Posted by Luan Pra bang
Can anyone tell wether or not this paypal wite is real, tryinf to work out if I am dealing with a scammer or not. https://www.paypal.com/uk/cgi-bin/we...ster-or-login&
i was sent one a few months ago, its fake
Old 11 November 2008, 05:37 PM
  #8  
TopBanana
Scooby Regular
 
TopBanana's Avatar
 
Join Date: Jan 2001
Posts: 9,781
Likes: 0
Received 0 Likes on 0 Posts
Default

What yer all on about? The link is genuine
Old 11 November 2008, 05:40 PM
  #9  
Rex93
Scooby Regular
 
Rex93's Avatar
 
Join Date: Mar 2002
Posts: 383
Likes: 0
Received 0 Likes on 0 Posts
Default

Norton 360, showing it as authenticated?
Old 11 November 2008, 05:45 PM
  #10  
Boro
Scooby Regular
iTrader: (1)
 
Boro's Avatar
 
Join Date: Jul 2003
Location: Cornwall
Posts: 7,222
Likes: 0
Received 0 Likes on 0 Posts
Default

Interesting... how should AV show this as a fake site? Im running NOD32 and didnt get any warning.
Old 11 November 2008, 05:52 PM
  #11  
SwissTony
Scooby Regular
iTrader: (19)
 
SwissTony's Avatar
 
Join Date: Mar 2003
Location: In the Doghouse
Posts: 28,228
Received 12 Likes on 3 Posts
Default

Originally Posted by TopBanana
What yer all on about? The link is genuine
I remind the honorable gentleman that he is under the cosh for being a naughty boy.






Old 11 November 2008, 06:31 PM
  #12  
PaulC72
Scooby Regular
 
PaulC72's Avatar
 
Join Date: Sep 2006
Location: RIP Tam.
Posts: 5,108
Likes: 0
Received 0 Likes on 0 Posts
Default

it registers as a genuine verisign certificate too if it is a fake then it is a bloody good one {for a change}
Old 11 November 2008, 06:33 PM
  #13  
TopBanana
Scooby Regular
 
TopBanana's Avatar
 
Join Date: Jan 2001
Posts: 9,781
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by SwissTony
I remind the honorable gentleman that he is under the cosh for being a naughty boy.
Why I oughtta...
Old 11 November 2008, 06:38 PM
  #14  
NotoriousREV
Scooby Regular
 
NotoriousREV's Avatar
 
Join Date: Jan 2002
Posts: 11,581
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by TopBanana
What yer all on about? The link is genuine
Agreed. Certificate is genuine, link is genuine, site is genuine. Even checked the headers for any nasty redirects. There are none.
Old 11 November 2008, 06:44 PM
  #15  
Flaps
Scooby Regular
iTrader: (1)
 
Flaps's Avatar
 
Join Date: Nov 2006
Location: Yorkshire
Posts: 2,966
Likes: 0
Received 0 Likes on 0 Posts
Default

Swiss, WFT?

I'm going to stick my neck out and say it looks good to this ICT A-level teacher. The base address is the same as the official one and the HTTPS (plus the padlock symbol bottom right) is there.
Old 11 November 2008, 06:52 PM
  #16  
hodgy0_2
Scooby Regular
 
hodgy0_2's Avatar
 
Join Date: Jul 2008
Location: K
Posts: 15,633
Received 21 Likes on 18 Posts
Default

agreed the site looks genuine

the ssl cert matches the fqdn


however there has been talk of the DNS system having a security flaw which would enable a scammer, albeit a very sophisticated one, to spoof the address, which would mean that the certificate would still show itself as valid when in reality not

the only way to tell would be to know what the IP the www.paypal.com host was and compare it to the one your are looking at --- which is totally impractible
Old 11 November 2008, 06:52 PM
  #17  
Flaps
Scooby Regular
iTrader: (1)
 
Flaps's Avatar
 
Join Date: Nov 2006
Location: Yorkshire
Posts: 2,966
Likes: 0
Received 0 Likes on 0 Posts
Default

Well it let me log in
Old 11 November 2008, 06:58 PM
  #18  
NotoriousREV
Scooby Regular
 
NotoriousREV's Avatar
 
Join Date: Jan 2002
Posts: 11,581
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by hodgy0_2
agreed the site looks genuine

the ssl cert matches the fqdn


however there has been talk of the DNS system having a security flaw which would enable a scammer, albeit a very sophisticated one, to spoof the address, which would mean that the certificate would still show itself as valid when in reality not

the only way to tell would be to know what the IP the www.paypal.com host was and compare it to the one your are looking at --- which is totally impractible
And where would the scammers get a verified Verisign certificate from? Verisign wouldn't let them have one, that's for sure. They'd have to be *very* sophisticated.

And one way to check the IP is to do an nslookup to find the authoratative name servers for Paypal (and you can check it in a couple of places on the net to be certain) and check that you resolve the same ip from your local dns server. Takes a couple of mins.

Last edited by NotoriousREV; 11 November 2008 at 07:01 PM.
Old 11 November 2008, 08:54 PM
  #19  
spray1974
Scooby Regular
 
spray1974's Avatar
 
Join Date: Feb 2008
Location: Inverg
Posts: 90
Likes: 0
Received 0 Likes on 0 Posts
Default

So is this link legit or a fake?
Old 11 November 2008, 09:26 PM
  #20  
bugeyeandy
Scooby Regular
 
bugeyeandy's Avatar
 
Join Date: Oct 2005
Location: West London
Posts: 1,914
Likes: 0
Received 0 Likes on 0 Posts
Default

Looks perfectly legit to me. Firefox legitimises the link too.
Old 11 November 2008, 09:31 PM
  #22  
Boro
Scooby Regular
iTrader: (1)
 
Boro's Avatar
 
Join Date: Jul 2003
Location: Cornwall
Posts: 7,222
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by stevem2k
yep. FAKE

HTML/Spoofing.Gen script virus picked up by Avira
So, how did this happen?
Old 11 November 2008, 09:51 PM
  #23  
hodgy0_2
Scooby Regular
 
hodgy0_2's Avatar
 
Join Date: Jul 2008
Location: K
Posts: 15,633
Received 21 Likes on 18 Posts
Default

Originally Posted by NotoriousREV
And where would the scammers get a verified Verisign certificate from? Verisign wouldn't let them have one, that's for sure. They'd have to be *very* sophisticated.

And one way to check the IP is to do an nslookup to find the authoratative name servers for Paypal (and you can check it in a couple of places on the net to be certain) and check that you resolve the same ip from your local dns server. Takes a couple of mins.

not easy for the average hacker -- but remember how much money could be at stake

EV Certificate Sites Still Vulnerable to DNS Hacks | California Dreams

Common SSL Misconceptions | California Dreams
Old 12 November 2008, 07:21 AM
  #24  
drb5
Scooby Regular
iTrader: (4)
 
drb5's Avatar
 
Join Date: Jun 2003
Location: Scotchland
Posts: 9,200
Likes: 0
Received 0 Likes on 0 Posts
Default

Send the link to spoof@paypal.com
Old 12 November 2008, 07:33 AM
  #25  
NotoriousREV
Scooby Regular
 
NotoriousREV's Avatar
 
Join Date: Jan 2002
Posts: 11,581
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by drb5
Send the link to spoof@paypal.com
Why? It's a perfectly legitimate link to their own site!
Old 12 November 2008, 05:37 PM
  #26  
Dedrater
Scooby Regular
 
Dedrater's Avatar
 
Join Date: May 2008
Posts: 3,957
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by stevem2k
yep. FAKE

HTML/Spoofing.Gen script virus picked up by Avira
lol, where did you get that information from?
Old 12 November 2008, 05:44 PM
  #27  
Boro
Scooby Regular
iTrader: (1)
 
Boro's Avatar
 
Join Date: Jul 2003
Location: Cornwall
Posts: 7,222
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by Dedrater
lol, where did you get that information from?
ditto
Old 13 November 2008, 01:41 PM
  #28  
Luan Pra bang
Scooby Regular
Thread Starter
 
Luan Pra bang's Avatar
 
Join Date: Jan 2004
Posts: 4,207
Likes: 0
Received 0 Likes on 0 Posts
Default

NOw I am more confused than ever.
Old 13 November 2008, 01:49 PM
  #29  
Dedrater
Scooby Regular
 
Dedrater's Avatar
 
Join Date: May 2008
Posts: 3,957
Likes: 0
Received 0 Likes on 0 Posts
Default

It is real, I 100% guarantee that, the MD5 fingerprint matches that of Welcome - PayPal and in any event, someone going to the extreme lengths of spoofing a 168 bit encryption is not heard of.
Old 13 November 2008, 01:53 PM
  #30  
Dedrater
Scooby Regular
 
Dedrater's Avatar
 
Join Date: May 2008
Posts: 3,957
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by SwissTony
Also go to http://www.paypal.com click the top right to select your country and language. Now you see the main graphics and page when you get redirected. All kosher

Now compare it to the site you get directed to from your link

subtle eh ???
The only difference is that is the 'Logon' page and the link in the first post in the 'Logon or Register' page.


Quick Reply: Fake site ?



All times are GMT +1. The time now is 09:20 PM.