Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Phishing scam


  • Please log in to reply

#1
NotAQuitter

NotAQuitter

    Member

  • Member
  • PipPip
  • 10 posts
Okay, I'm attaching a screenshot (in a .doc).

It shows a website I'm investigating.

I created a fake identity and signed up for their newsletter. The next screen has a form for you to fill out so you can "tell your friends about us."

They also give you the option to save time by simply giving them "your Hotmail, Gmail, Yahoo, or AOL password...and we'll fill out the form for you."

I get it that they are using the "tell your friends about us" part to catch phish.

But how does the "give us your password" part work?

Anyone?

Attached Files


  • 0

Advertisements


#2
sari

sari

    GeekU Admin

  • Community Leader
  • 21,806 posts
  • MVP
Isn't it obvious? The point of any phishing scam is to gain login information. Give them your email password and they have your login info. They can then use your account to send spam, and you'd be the one to get your account shut down.
  • 0

#3
NotAQuitter

NotAQuitter

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts
I guess that is obvious. :)

I'm so suspicious that it didn't even occur to me that the people they're targeting probably only have one email address and/or use the same password for everything.

Sheesh. Good 'nuff to bust them anyway.

Thanks,
NAQ
  • 0

#4
Mike

Mike

    Malware Monger

  • Retired Staff
  • 2,745 posts
If you find phishing sites, report em http://www.castlecops.com/pirt

Edit, by the way - what exactly does the site want to send to your 'friends'?

Edited by Mike, 09 August 2008 - 03:11 PM.

  • 0

#5
NotAQuitter

NotAQuitter

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts
Thanks for the link. I was wondering where to send my report.

What you're supposed to get is a "free ebook" and of course, your friends will get the same wonderful offer.

The site is

Next stop for me:http://www.castlecops.com/pirt

Thanks very much,
NAQ

Edited by Johanna, 09 August 2008 - 08:53 PM.
we don't put bad links on the board

  • 0

#6
NotAQuitter

NotAQuitter

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts
http://www.castlecops.com/pirt link doesn't work
  • 0

#7
Major Payne

Major Payne

    Retired Staff

  • Retired Staff
  • 5,307 posts
Comes up on Google search, but site doesn't load from any of the Google links for me. Got this on querying the server:

Initiating server query ...
Looking up IP address for domain: www.castlecops.com
The IP address for the domain is: 204.152.184.144
Connecting to the server on standard HTTP port: 80
[Connected] Requesting the server's default page.
The server's response did not contain the expected 'Server:' header to identify itself. Therefore, server's identity can not be determined.
Query complete.


Ron
  • 0

#8
Mike

Mike

    Malware Monger

  • Retired Staff
  • 2,745 posts
http://wiki.castlecops.com/PIRT

Take a look under "Submit Phish"

Edited by Mike, 10 August 2008 - 04:49 AM.

  • 0

#9
NotAQuitter

NotAQuitter

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts
I accessed it via www.castlecops.com but not via the link you gave, i.e. http://wiki.castlecops.com/PIRT. It 'timed out' finally
  • 0

#10
jt1990

jt1990

    Member 1K

  • Member
  • PipPipPipPip
  • 1,519 posts
Interesting...They both work for me...
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP