Search our Spoof Library...
Another Spoof Email and Phishing Scam report by MillerSmiles.co.uk - click this image to go to our home page.

eBay.com Protection
23rd March 2004

please forward any scams you've received to spoof@millersmiles.co.uk

 

Report Summary
Date Reported
23rd March 2004
Apparent Sender
eBay
Return Address
support@eBay.com
Subject
eBay.com Protection
Format
HTML made to look like text only to aid in disguising the link
Method
disguised link leads to bogus web content
Bogus Web Content?
Yes
URL of web content
http://www.ebay.com.cgi3.update.information.system.users.
cgi3.ebay.com.update.base.cgi3.update.base.system.control.
cgi2.panel.ebay.com.sdffsd.com/e.html
RISK LEVEL
HIGH
WARNINGS

1. An incredibly long subdomain in the URL. It has been constructed like this to give the appearance of a genuine ebay.com URL (we have highlighted the actual domain in the link shown above)

 

Users arrive at a forged eBay page with a very convincing URL in this Phishing Scam...

 

This spoof eBay email (see below) is in HTML format (although it does look like a text only email in order add a sense of authenticity to the link text). The link has been disguised using HTML code to look like a genuine link to eBay but it will actually open a forged eBay web form titles 'For security reasons the following information must be confirmed'.

The URL (as shown in your browser address bar) of the bogus form is actually a sub domain of sdffsd.com, and the sub domain name has purposefully been constructed to be very long and contain the phrase 'www.ebay.com.cgi3' etc, (which of-course, bears absolutely no relation to where the fake page is). Sub domains like this (also called Third Level Domain names) can be considered to be an independent and unique website in themselves. Many webmasters offer their sole use as one form or another of web hosting (such as 20m.com who offer them for free) and an alternative to having to register a domain for yourself. We are seeing more of these long URLs made from long sub domain names and which are broken up with periods to give the appearance of being a genuine domain, such as www.ebay.com as in this spoof email. The URL is...

http://www.ebay.com.cgi3.update.information.system.users. cgi3.ebay.com.update.base.cgi3.update.base.system.control.
cgi2.panel.ebay.com.sdffsd.com/e.html

...and we've highlighted the deceptive part in bold red, and the true domain in bold blue. The length of the URL would also cause the genuine domain component to fall out of view in screens of low resolution such as 800x600 (one of the most popular screen resolutions in use).

If you have received this email, please remember that it is very common for these email scams to be redistributed at a later date with only slightly different content or the same but with the fake page(s) hosted by a different provider. Also, once you have received one of these hoaxes, it is also common place to receive at least another one and usually a day or two after the first, although not necessarily from the same apparent sender.

 

The Spoof Email ...

Dear eBay User,

During our regular update and verification of the accounts, we could not verify your current information. Either your information has changed or it is incomplete.

As a result, your access to bid or buy on eBay has been restricted.
According to our site policy you will have to confirm that you are the real owner of the eBay account by completing the form that will pop up or else your account will be deleted.

If you received this notice and you are not the authorized account holder, please be aware that it is in violation of eBay policy to represent oneself as another eBay user.
Such action may also be in violation of local, national, and/or international law. eBay is committed to assist law enforcement with any inquires related to attempts to
misappropriate personal information with the intent to commit fraud or theft.

We apologize in advance for any inconvenience this may cause you and we would like to thank you for your cooperation as we review this matter.

To update your eBay records click here::

http://cgi1.ebay.com/aw-cgi/ebayISAPI.dll?UPdate
eBay Update team
http://www.eBay.com


Thank you

Safeharbor Department
eBay Inc.

 

The bogus web page ...

eBay.com Protection bogus web page with form eBay.com Protection bogus web page with form eBay.com Protection bogus web page with form eBay.com Protection bogus web page with form
eBay.com Protection bogus web page with form eBay.com Protection bogus web page with form eBay.com Protection bogus web page with form eBay.com Protection bogus web page with form
eBay.com Protection bogus web page with form eBay.com Protection bogus web page with form eBay.com Protection bogus web page with form eBay.com Protection bogus web page with form
eBay.com Protection bogus web page with form eBay.com Protection bogus web page with form eBay.com Protection bogus web page with form eBay.com Protection bogus web page with form
eBay.com Protection bogus web page with form eBay.com Protection bogus web page with form eBay.com Protection bogus web page with form eBay.com Protection bogus web page with form

 

 

Stay informed of the latest Spoof Email Phishing Scams with either of our FREE alert services...
 

Stay informed of the latest Spoof Email Phishing Scams with either of our FREE alert services...

Email Alerts
Add your email address to our email alert service...
Subscribe

Privacy Policy

RSS News Feed
Tap into our Scam Alert service using your News Reader or Aggregator (including My Yahoo!).
Scam Alert News Feed

You can even put the latest alerts on your own web site.

Click here to learn more about RSS News Feeds and our Scam Alert Service!

Resources links - use one of the links below to access more information on Spoof Email & Phishing Scams.

Library of Spoof Email Phishing Scams

Brief guide to Phishing

Full article on spoof email scams

Spoof URL Checker

Link Checker

Browser URL Spoofing Vulnerability Check

Latest browser bug aids Phishing Scams - beware!

Destinations - other resources available on the MillerSmiles.co.uk web site.

Click the arrow to return to previous page

Home

Guides...

Book Terminology

How to identify a first edition book

Auction Watcher

List of the main Auction Sites world wide