Search our Spoof Library...
Another Spoof Email and Phishing Scam report by MillerSmiles.co.uk - click this image to go to our home page.

PayPal Security Account Verification
5th April 2004

please forward any scams you've received to spoof@millersmiles.co.uk

 

Report Summary
Date Reported
5th April 2004
Apparent Sender
Paypal
Return Address
service@paypal.com
Subject
PayPal Security Account Verification
Format
HTML designed to look like text only
Method
disguised link leads to bogus web content
Bogus Web Content?
Yes
URL of web content
spoofed URL = http://www.paypal.com True URL = http://211.23.183.212/.,/l
RISK LEVEL
Medium
WARNINGS

1. Exploits URL Spoofing (canonicalisation) in Internet Explorer browsers - run Windows Update to ensure your browser is patched.

 

" Dear PayPal user, We recently reviewed your account ,and suspect that your PayPal account may have been accessed by an unauthorized third party."...

 

Another instance of a spoofed email with a link coded to exploit the URL Spoofing (canonicalisation) vulnerability that exists in unpatched versions of Internet Explorer browsers. Microsoft issued a patch at the beginning of February 2004, use the 'Browser URL Spooing Vulnerability Check link on the right of page to check your browser.

If you browser is vulnerable to this exploit, you will see http://www.paypal.com displayed in the address bar, but the true URL of the bogus page is http://211.23.183.212/.,/l which resolves to the Chunghwa Telecom Co.,Ltd in Taiwan (clearly nothing to do with Paypal.com).

Any information submitted is processed through a script located on the same server as the bogus content.

If you have received this email, please remember that it is very common for these email scams to be redistributed at a later date with only slightly different content or the same but with the fake page(s) hosted by a different provider. Also, once you have received one of these hoaxes, it is also common place to receive at least another one and usually a day or two after the first, although not necessarily from the same apparent sender.

 

The Spoof Email ...

Dear PayPal user,

We recently reviewed your account ,and suspect that your PayPal account may have been accessed by an unauthorized third party.Protecting the security of your account and of the PayPal network is out primary concern.Therefore ,as a preventative measure ,we have temporarily limited access to sensitive PayPal account features.

To restore your account access ,please take the following steps to ensure that your account has not been compromised:

1. Confirm your identity by completing the account verification process.

2. Click the "Submit" button at the bottom of the page.You will be taken to the Data Security and Encryption page.

3. Login to your PayPal account and review your recent account history for any unauthorized payments sent or received ,and check your account profile to make sure not changes have been made.If any unauthorized activity has taken place on your account report this to PayPal immediately.

To get started ,please click the link below.

https://www.paypal.com/cgi-bin/webscr?account-registration

We apologize for any inconvenience this may cause ,and appreciate your assistance in helping us maintain the integrity of the entire PayPal system.Thank you for your promt attention to this matter.

Sincerely ,

Thank you for using PayPal!
The PayPal Team

Please do not reply to this e-mail. Mail sent to this address cannot be answered. For assistance, log in to your PayPal account and choose the"Help" link in the header of any page.

PayPal Email ID PP315

 

The bogus web page ...

PayPal Security Account Verification forged web page.

 

Stay informed of the latest Spoof Email Phishing Scams with either of our FREE alert services...
 

Stay informed of the latest Spoof Email Phishing Scams with either of our FREE alert services...

Email Alerts
Add your email address to our email alert service...
Subscribe

Privacy Policy

RSS News Feed
Tap into our Scam Alert service using your News Reader or Aggregator (including My Yahoo!).
Scam Alert News Feed

You can even put the latest alerts on your own web site.

Click here to learn more about RSS News Feeds and our Scam Alert Service!

Resources links - use one of the links below to access more information on Spoof Email & Phishing Scams.

Library of Spoof Email Phishing Scams

Brief guide to Phishing

Full article on spoof email scams

Spoof URL Checker

Link Checker

Browser URL Spoofing Vulnerability Check

Latest browser bug aids Phishing Scams - beware!

Destinations - other resources available on the MillerSmiles.co.uk web site.

Click the arrow to return to previous page

Home

Guides...

Book Terminology

How to identify a first edition book

Auction Watcher

List of the main Auction Sites world wide