This is a very interesting article written by Cyrus Peikari and Seth Fogie of InformIT, I hope you take the time to read through it.
The phishing attack came in the form of an email that appeared to be from PayPal. Since the title of the email stated “Please update your billing records or your account will be suspended. Thanks!", it was clearly designed to alert the victim in a way that is bound to get their attention. Contained in the body of the email was a warning that my account would expire in 12 hours unless I updated my records. Included with the message was a helpful link to http://www.paypal.com. Unfortunately, for those not paying attention, this link actually went to http://xxxxxxxxxxx.com/awstats/cgi-bin/.
We decided to follow the link because we like to keep in the loop of what the phishers are up to incase we are called by a client who is curious as to how their identity was stolen. In addition, as we tend to discover, people who use these phishing scams sometimes make mistakes and leave a trail of information that can be helpful in stopping them.
...read the rest of the article...
Inside a PayPal Phishing Site
Moderators: Moderator, Global Moderator
Inside a PayPal Phishing Site
Last edited by Tami on Tue Feb 05, 2008 12:03 pm, edited 1 time in total.

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Inside a PayPal Phishing Site
People need to learn to look at the status bar when clicking links and the address bar when filling in credit card info etc.
Love is all a matter of timing.
It's no good meeting the right person too soon or too late.
If I'd live in another time or place...
...my story might have had a very different ending.
It's no good meeting the right person too soon or too late.
If I'd live in another time or place...
...my story might have had a very different ending.
Inside a PayPal Phishing Site
wow. thats nuts and amazing how complex the script was, the detail it went to was astonishing. im going to enjoy my uni course, ill be studying stuff like this <img src=\'http://www.killanet.net/forum3/public/s ... iggrin.gif\' class=\'bbc_emoticon\' alt=\':D\' />
oh, fav part...
oh, fav part...
bwhahaha! top notch!Finally, the phisher who is using this script is getting owned as well.



