Author Topic:  (Read 1063 times)

Offline aceriker

  • Trade Count: (0)
  • Corporal
  • ****
  • Posts: 78
    • View Profile
(No subject)
« on: April 23, 2004, 10:46:32 AM »
Thanks for the heads up!
« Last Edit: December 31, 1969, 05:00:00 PM by aceriker »
Never, Never, Never Give Up

               --Winston Churchill

Offline Trashcan

  • Trade Count: (0)
  • Staff Sergeant
  • *****
  • Posts: 224
    • View Profile
(No subject)
« Reply #1 on: April 23, 2004, 11:00:06 AM »
Thanks for the warning :)
« Last Edit: December 31, 1969, 05:00:00 PM by Trashcan »

Offline Paco

  • Trade Count: (0)
  • Brigadier General
  • *****
  • Posts: 1507
    • View Profile
(No subject)
« Reply #2 on: April 23, 2004, 11:09:43 AM »
I get those all the time for eBay and PayPal, but if it showed up in a browser with PayPal's actual URL, then you haven't updated your computer with the latest patches.  That explot was fixed a few months ago.  In the ones I get, it looks all official and has links to eBay's actual Terms of Service, searches, etc...  but the link they tell you to click on actually points to some anonymous *.nl site in europe that also LOOKS like eBay, but isn't.
« Last Edit: December 31, 1969, 05:00:00 PM by Paco »

Offline Harley

  • Trade Count: (0)
  • Major General
  • *****
  • Posts: 2254
    • View Profile
(No subject)
« Reply #3 on: April 23, 2004, 11:12:53 AM »
My workstation gets update every day, It still showed up.
« Last Edit: December 31, 1969, 05:00:00 PM by Harley »
\"Just because you\'re paranoid, doesn\'t mean they\'re not out to get you!\"

\"Have Gun - Will Travel\"

Offline Paco

  • Trade Count: (0)
  • Brigadier General
  • *****
  • Posts: 1507
    • View Profile
(No subject)
« Reply #4 on: April 23, 2004, 11:26:46 AM »
Here's an easy way to test it:

http://www.zapthedingbat.com/security/ex01/vun1.htm

Click on that link and use the "Test" button.  If your browser URL says that you're on http://www.microsoft.com then you're not patched for this exploit.
« Last Edit: December 31, 1969, 05:00:00 PM by Paco »

Offline Harley

  • Trade Count: (0)
  • Major General
  • *****
  • Posts: 2254
    • View Profile
(No subject)
« Reply #5 on: April 23, 2004, 11:27:45 AM »
Someone must have cracked down on them.  The spoofed url doesn't work anymore.  Just the same always be careful with emails like this.
« Last Edit: December 31, 1969, 05:00:00 PM by Harley »
\"Just because you\'re paranoid, doesn\'t mean they\'re not out to get you!\"

\"Have Gun - Will Travel\"

Offline Pheonix 797

  • Trade Count: (0)
  • Second Lieutenant
  • *****
  • Posts: 811
    • View Profile
(No subject)
« Reply #6 on: April 23, 2004, 11:36:44 AM »
Thx much John. Always good to see that some stupid mother is getting nailed for scamming.
« Last Edit: December 31, 1969, 05:00:00 PM by Pheonix 797 »

Offline Harley

  • Trade Count: (0)
  • Major General
  • *****
  • Posts: 2254
    • View Profile
(No subject)
« Reply #7 on: April 23, 2004, 11:37:29 AM »
Well it came up with this.

http://www.microsoft.com@zapthedingbat.com/security/ex01/vun2.htm

So what does that mean?  I've got every patch and update that the Microsoft update site has put out.
« Last Edit: December 31, 1969, 05:00:00 PM by Harley »
\"Just because you\'re paranoid, doesn\'t mean they\'re not out to get you!\"

\"Have Gun - Will Travel\"

Offline Paco

  • Trade Count: (0)
  • Brigadier General
  • *****
  • Posts: 1507
    • View Profile
(No subject)
« Reply #8 on: April 23, 2004, 11:44:04 AM »
That means you're fine.  If you didn't have the patch, it would have come up with the zapthedingbat.com page but the URL window in IE (on top and on bottom) would have said that you were on http://www.microsoft.com - it was a pretty *scary* bug since it could be used for a LOT of mischevious things, but it couldn't spoof the http<b>s</b> (SSL).  The easiest way with PayPal, is that you will ALWAYS be on a secure site if you're on the PayPal page.  Their entire site is SSL 128bit.
« Last Edit: December 31, 1969, 05:00:00 PM by Paco »

Offline Harley

  • Trade Count: (0)
  • Major General
  • *****
  • Posts: 2254
    • View Profile
(No subject)
« Reply #9 on: April 23, 2004, 11:57:21 AM »
Well then the one I got today was a new one apparently.
« Last Edit: December 31, 1969, 05:00:00 PM by Harley »
\"Just because you\'re paranoid, doesn\'t mean they\'re not out to get you!\"

\"Have Gun - Will Travel\"

Offline Harley

  • Trade Count: (0)
  • Major General
  • *****
  • Posts: 2254
    • View Profile
PayPal scam email
« Reply #10 on: April 23, 2004, 10:44:57 AM »
FYI to those of you who use PayPal.  I just received a bogus email that was pretty well spoofed.  I ran a test on it by clicking the enclosed link and it opened a page with PayPal's web address that they apparently spoofed.  I logged in with my email address but used a phony password and got in just as though I had used my correct one as they would expect.  This is how I discovered it was bogus.  Do not use any email links sent you by PayPal or eBay for updating your information.  Use your normal bookmarked links to do that.
« Last Edit: December 31, 1969, 05:00:00 PM by Harley »
\"Just because you\'re paranoid, doesn\'t mean they\'re not out to get you!\"

\"Have Gun - Will Travel\"