Home U.S. Coin Forum

Uh-oh. Hope I didn't just get phished.

lordmarcovanlordmarcovan Posts: 43,893 ✭✭✭✭✭
I just had a question from an eBay member in my email. It does NOT show up on the question page in My eBay. I clicked the "Respond Now" button in the email message and was directed to an eBay logon page (though I believe I was already logged on).

The item number being questioned about leads HERE. Not my auction. I had to do a search on eBay to find it, because the link to it from the email also did not work and led to a logon page.

The email looked legit enough, but I had a strong feeling he was not asking about one of my coins because both of the auctions I have running very clearly state that I will give free shipping on these particular items to North America, including Canada. And his question regarded shipping costs to Canada.

I have a bad feeling. Think I just got hooked? I should've known better than to use the logon provided in the email.



<< <i>eBay Member jabberjock

<aw-confirm@ebay.com>
Reply-To : UseTheYellowButton@ebay.com
Sent : Friday, June 1, 2007 4:26 PM
To : rwshinnick@hotmail.com
Subject : Message from eBay Member Regarding Item #320116285683





Your registered name is included to show this message originated from eBay. Learn more.
Question about Item -- Respond Now

eBay sent this message on behalf of an eBay member through My Messages. Click the "Respond Now" button to answer the question.



Question from jabberjock
jabberjock( 12)
Positive feedback: 100%
Member since: Dec-21-05
Location: Canada
Registered on: www.ebay.ca


Item: 320116285683
This message was sent while the listing was active.
jabberjock is a potential buyer.



Hi ,

Can you please tell me how much is delivery to Canada ?

Thanks,

John
Respond to this question



Responses in My Messages will not include your email address.




Thank you,
eBay >>













Explore collections of lordmarcovan on CollecOnline, management, safe-keeping, sharing and valuation solution for art piece and collectibles.

Comments

  • goose3goose3 Posts: 11,471 ✭✭✭
    you better go and change your login NOW.
  • RussRuss Posts: 48,514 ✭✭✭
    As long as you didn't enter your login information you're fine.

    Russ, NCNE
  • fcfc Posts: 12,793 ✭✭✭
    yup. change your passwd. goto paypal change that if it is the same.
    in other words, consider that password compromised and spend the
    next hour changing wherever you use it.

    contain the issue.
  • RussRuss Posts: 48,514 ✭✭✭
    BTW, if you want to know if it's a phish as soon as you open it, change your eBay eMail preferences to text only.

    Russ, NCNE
  • tmot99tmot99 Posts: 5,238 ✭✭✭
    I get those emails all the time. I just don't click on them. Did you enter your login info? If so, you got trouble.
  • cmerlo1cmerlo1 Posts: 7,960 ✭✭✭✭✭
    Got a similar one earlier today and forwarded it on to the spoof police...then got it again later this afternoon and sent it off again. As long as you didn't enter any info, they don't have anything except your email address...

    --Christian
    You Suck! Awarded 6/2008- 1901-O Micro O Morgan, 8/2008- 1878 VAM-123 Morgan, 9/2022 1888-O VAM-1B3 H8 Morgan | Senior Regional Representative- ANACS Coin Grading. Posted opinions on coins are my own, and are not an official ANACS opinion.
  • FullStrikeFullStrike Posts: 4,353 ✭✭✭
    Ah you're going to be a fighting fish? image


    I think a real fishing scammer prefers getting a fighter once in a while - reeling in dead fish must get boring. image


    imageimage
  • lordmarcovanlordmarcovan Posts: 43,893 ✭✭✭✭✭


    << <i>As long as you didn't enter your login information you're fine. >>

    That's the problem. In a moment of inattention, I did just that. Bit down on the hook.


    Goose3 and fc- thanks, I immediately changed my eBay password, and will proceed to do the same with PayPal, which was the same. Used the same password on both sites since I started eBay in 1999, believe it or not. I suppose it was time to change anyway.

    Russ- thanks. I will change email prefs to text only.

    I think there was a hook in that worm, folks, and I bit. I hope the damage can be contained quickly. I felt funny the minute I took the bait.

    Explore collections of lordmarcovan on CollecOnline, management, safe-keeping, sharing and valuation solution for art piece and collectibles.
  • 7over87over8 Posts: 4,733 ✭✭✭
    change your pw immediately.

    never respond to ebay messages thru "email" delivery....always log on and respond on ebay....
  • storm888storm888 Posts: 11,701 ✭✭✭
    This has been the #1 phish on EBAY for the past week.

    The dimwits at T&S seem not to understand the problem.
    Their responses to the spoof-reports on this phish make
    no sense at all.

    Today, I am officially retiring as a "free-cop" for EBAY.
    Nobody is going to burn/phish me, so EBAY can save
    everybody else without ANY help from me.

    Folks Who Bite Get Bitten. Folks Who Don't Bite Get Eaten.
  • Sounds like you took the right steps right away. I hope you don't get bit!
    Exclusively collecting Capped Bust Halves in VF to AU, especially rarity 3 and up.
    image
    Joe G.
    Great BST purchases completed with commoncents123, p8nt, blu62vette and Stuart. Great coin swaps completed with rah1959, eyoung429 and Zug. Top-notch consignment experience with Russ.
  • storm888storm888 Posts: 11,701 ✭✭✭
    "....always log on and respond on ebay.... "

    ////////////////////////////////////////////////

    That is where the newest phishing is being done:

    MY MESSAGES
    Folks Who Bite Get Bitten. Folks Who Don't Bite Get Eaten.
  • GrumpyEdGrumpyEd Posts: 4,749 ✭✭✭
    You should also report it to ebay. It helps them go after the crooks.

    By now if you're paranoid about following links you can also click "security center" on the bottom of your ebay screen. Click the button for "spoof" emails.

    I had a similar phishing mail and reported it to paypal and was surprised that they replied in a few minutes and verified it was a scam and said "do not enter your info and if you did change your passwords NOW". Luckily I did not bite the hook yet.

    Report it here
    Ed
  • lordmarcovanlordmarcovan Posts: 43,893 ✭✭✭✭✭
    Well this fishie took the bait, even though on some level I shoulda known better, after advising folks never to respond to PayPal emails. image

    I automatically disregard email from PayPal but for some reason this eBay phish flew under my radar and caught me absentminded.

    Duh. imageimage

    Hopefully yours truly is a fish who realized his mistake quickly and wriggled off the hook just in time, before he got pulled onto the boat and gutted.


    Explore collections of lordmarcovan on CollecOnline, management, safe-keeping, sharing and valuation solution for art piece and collectibles.
  • RussRuss Posts: 48,514 ✭✭✭


    << <i>That is where the newest phishing is being done:

    MY MESSAGES >>



    Not this particular one. If it were, I'd get it in text. It comes in html. It's also not possible to embed a bogus login link using the messages feature through eBay that codes in the clickable buttons.

    Russ, NCNE
  • fcfc Posts: 12,793 ✭✭✭
    heck guys. i still use university of washington's mail client called
    pine. you can send me all the html you want and it still shows like
    plan text ;-). i am too lazy to install lynx.

    keep an eye out for any activity on the account(s) and be sure
    to know who to contact if you see something suspiscious in the
    next hours to day.
  • RussRuss Posts: 48,514 ✭✭✭
    If you check the expanded headers you'll see that these do not originate through eBay. Here's one I got a few minutes ago:

    Received: from apollo.hyperroll.com (apollo.hyperroll.com [212.143.92.234])
    by mx00.csee.onr.siteprotect.com (Postfix) with ESMTP id D6E88DD8056
    for <russ@compucheap.com>; Fri, 1 Jun 2007 19:33:17 -0500 (CDT)
    Received: from apollo.hyperroll.com (localhost.localdomain [127.0.0.1])
    by apollo.hyperroll.com (8.12.8/8.12.8) with ESMTP id l520bUel025494
    for <russ@compucheap.com>; Sat, 2 Jun 2007 03:37:30 +0300
    Received: (from root@localhost)
    by apollo.hyperroll.com (8.12.8/8.12.8/Submit) id l520bUaT025492;
    Sat, 2 Jun 2007 03:37:30 +0300
    Date: Sat, 2 Jun 2007 03:37:30 +0300
    Message-Id: <200706020037.l520bUaT025492@apollo.hyperroll.com>
    To: russ@compucheap.com
    Subject: Message from eBay Member regarding Item #130118081302
    From: eBay Member paradisemint <member@ebay.com>

    Russ, NCNE
  • ttownttown Posts: 4,472 ✭✭✭
    I got the same question but don't sell on Ebay. I'd change my password quick.image
  • lordmarcovanlordmarcovan Posts: 43,893 ✭✭✭✭✭
    I think for the next one of these I get, I will use the link provided in the email again, but attempt to use their phony logon with the password "kissmyarseanddieyouwannabescum". image

    Explore collections of lordmarcovan on CollecOnline, management, safe-keeping, sharing and valuation solution for art piece and collectibles.
  • LOL. But if you still have the phishing message, forward it to www.spoof@ebay.com


    image
  • storm888storm888 Posts: 11,701 ✭✭✭
    "It's also not possible to embed a bogus login link using the messages
    feature through eBay that codes in the clickable buttons."

    ///////////////////////////////////////////////////////////////////

    The ones that I have been getting in My Messages this week,
    have this feature:

    When I click the respond button, I am taken straight to the
    fake EBAY sign-in screen.
    Folks Who Bite Get Bitten. Folks Who Don't Bite Get Eaten.
  • BlackBeardBlackBeard Posts: 1,064
    One quick and easy way to tell is where it says:

    >>Your registered name is included to show this message originated from eBay. Learn more. <<<<<
    They include this to look official, but they never have had my real name up above, they use your or their ebay handle in hopes you won't notice.


    They know your email address but not your real name. I wouldn't call this foolproof, but it quickly eliminates the vast majority of them. The line below should be at the top of the body of the email.

    "eBay sent this message to ((Your real name here)) (Your ebay handle here)"


    I use Eudora Email and when I mouse over the links it will pop up a text box that warns that the destination doesn't match the address of the link. I love that feature. It either comes from Eudora or Norton, but I believe it is the email software.


    I hope they didn't get to your account. Time for a new password.
    Witty sig line currently under construction. Thank you for your patience.
  • BlackBeardBlackBeard Posts: 1,064


    << <i>"It's also not possible to embed a bogus login link using the messages
    feature through eBay that codes in the clickable buttons."

    ///////////////////////////////////////////////////////////////////

    The ones that I have been getting in My Messages this week,
    have this feature:

    When I click the respond button, I am taken straight to the
    fake EBAY sign-in screen. >>



    I would not click on any link in a suspicious email. Just going to a compromised website can infect your computer according to what I have read.
    Witty sig line currently under construction. Thank you for your patience.
  • I got the identical e-mail today. Changed all my passwords etc.

    Bruce
  • Judging from the headers and IP address that shows up, it has been re-routed through a Hotmail account. I have reported it to ebay as well.

    Bruce
  • ajiaajia Posts: 5,403 ✭✭✭
    Been ther, done that! image

    Changed everything ASAP after I hit the sign in button. image
    image
  • LongacreLongacre Posts: 16,717 ✭✭✭
    image
    Always took candy from strangers
    Didn't wanna get me no trade
    Never want to be like papa
    Working for the boss every night and day
    --"Happy", by the Rolling Stones (1972)
  • topstuftopstuf Posts: 14,803 ✭✭✭✭✭
    So we can be of more help, what did you change your password to?

    image
  • lordmarcovanlordmarcovan Posts: 43,893 ✭✭✭✭✭
    I changed it to "eye_yam_sofa_king_we_todd_did".

    Explore collections of lordmarcovan on CollecOnline, management, safe-keeping, sharing and valuation solution for art piece and collectibles.
  • itsnotjustmeitsnotjustme Posts: 8,779 ✭✭✭
    A little social engineering going on in this one. Even if 00.99% don't fall, they are happy to catch the others.

    I assume you checked everything about your account that someone might have changed.... there were no BIN auctions that posted and ended in th 5 minutes they had your password, etc.
    Give Blood (Red Bags) & Platelets (Yellow Bags)!


  • << <i>
    I would not click on any link in a suspicious email. Just going to a compromised website can infect your computer according to what I have read. >>



    I second this suggestion. They are nicknamed drive-by trojans, because a malicious website may try known (and new, unknown) exploits in your web browser to attempt to silently install all kinds of bad software on your computer, such as software that record all your keystrokes and silently transmit them to a malicious hacker. So just "driving-by" a bad website can cause you grief.
  • lordmarcovanlordmarcovan Posts: 43,893 ✭✭✭✭✭


    << <i>A little social engineering going on in this one. Even if 00.99% don't fall, they are happy to catch the others.

    I assume you checked everything about your account that someone might have changed.... there were no BIN auctions that posted and ended in th 5 minutes they had your password, etc. >>

    I think I acted in time. Hopefully. (Crosses fingers)




    << <i> would not click on any link in a suspicious email. Just going to a compromised website can infect your computer according to what I have read. >>

    Common sense, and something I pretty much knew better on, but for a momentary lapse of judgement. I suppose a momentary slip is all the thieves need in this cyber age. As to an infected computer, maybe some Trojan horses and viruses would improve the operation of my home PC- it is already buggy as hell. image

    Explore collections of lordmarcovan on CollecOnline, management, safe-keeping, sharing and valuation solution for art piece and collectibles.

Leave a Comment

BoldItalicStrikethroughOrdered listUnordered list
Emoji
Image
Align leftAlign centerAlign rightToggle HTML viewToggle full pageToggle lights
Drop image/file