This morning I get a very well done phishing email in my box for PayPal. It's got a lot of hidden markup with a link that looks like it goes to http://www.paypal.com/cgi-bin/webscr?cmd=_login-run but really goes to "msjertpoortmasurncfhsyuspty.has.it".

A friend of mine is very conscientious and always reports this kind of stuff. I figure I have some time, so I'll do the same. I'm in gmail, so the first bit is easy. Under "more options" there's a "report phishing" link. I don't know why it's a little hidden or doesn't say something like "report fraud", but there it is.

The next step is to tell PayPal proper. No worries, they must have an email address I can just forward this thing to... Well, if they do it's somewhere I couldn't find. I end up fighting a cludgy online form where they want me to cut and paste the text of the mail.

The basic email text will help with a spam filter, but does little to catch the phisher. Being a good geek, I paste the entire text source of the email, complete with routing information.

Well, I can't give them the full text. Something about invalid characters. This is my message.

Having to fill out this form will prevent me from reporting more of these, which is a shame.

Also, your cut and paste did not support the original text, with all the forwarding and HTML spoofing mock up. I would think this would greatly hinder your attempts to solve the problem.

Good luck.


I'm left wondering if they even try to fight the scam they make possible. Is it more effective from their perspective to just pretend to be on top of things? My emailer good deed leaves me more concerned than comforted.

From: [identity profile] ladypeyton.livejournal.com


They do have an addfress. It's spoof at paypal dot com. I use it all the time as well as spoof at ebay dot com becuase I'm anal about reporting these things like your friend is.

From: [identity profile] loosecanon.livejournal.com


HAH! Ya beat me to it, and we are in the same room. I bet I get mileage from this /grin

Have a good day today.
ext_44932: (Default)

From: [identity profile] baavgai.livejournal.com


Curious, under security center (http://www.paypal.com/cgi-bin/webscr?cmd=_security-center-outside) I now see. I swear I missed it before.
.

Profile

baavgai: (Default)
baavgai

Links

Most Popular Tags

Powered by Dreamwidth Studios

Style Credit

Expand Cut Tags

No cut tags