FacebookTwitter
Hatrack River Forum   
my profile login | search | faq | forum home

  next oldest topic   next newest topic
» Hatrack River Forum » Active Forums » Books, Films, Food and Culture » Is this a scam?

   
Author Topic: Is this a scam?
A Rat Named Dog
Member
Member # 699

 - posted      Profile for A Rat Named Dog   Email A Rat Named Dog         Edit/Delete Post 
I got an e-mail purporting to be from PayPal about a problem with my account. Of course, the real problem is that I don't remember ever setting up a PayPal account [Smile]

I poked around with the links, and it sent me to this site:

http://www.paypal.com.198992.2smjb04.com/cmd-confirm/webscr/login.php?login&login_email=geoffcard@aol.com&ref=pp_as_3

I note that the actual domain name isn't really PayPal, but some random combination of characters. Should I assume that this is a scam, and an attempt to steal my password (were such a thing to exist)?

Posts: 1907 | Registered: Feb 2000  |  IP: Logged | Report this post to a Moderator
Mucus
Member
Member # 9735

 - posted      Profile for Mucus           Edit/Delete Post 
Assume yes.
If you're really concerned go to the PayPal site on your own and check it out.

Posts: 7593 | Registered: Sep 2006  |  IP: Logged | Report this post to a Moderator
Tstorm
Member
Member # 1871

 - posted      Profile for Tstorm   Email Tstorm         Edit/Delete Post 
Yes. It is a scam.

Especially if you don't have a PayPal account. [Wink]

Posts: 1813 | Registered: Apr 2001  |  IP: Logged | Report this post to a Moderator
rivka
Member
Member # 4859

 - posted      Profile for rivka   Email rivka         Edit/Delete Post 
YES.

From the horse's mouth.

Posts: 32919 | Registered: Mar 2003  |  IP: Logged | Report this post to a Moderator
cmc
Member
Member # 9549

 - posted      Profile for cmc   Email cmc         Edit/Delete Post 
It's a scam... I get those emails to my yahoo account probably once a week!!
Posts: 1355 | Registered: Jul 2006  |  IP: Logged | Report this post to a Moderator
Survivor
Member
Member # 233

 - posted      Profile for Survivor   Email Survivor         Edit/Delete Post 
Forward it to spoof@paypal.com They'll tell you if it was an actual message from them. Which it certainly isn't. The sooner you forward it to them, the better chance they have of shutting down the perps before they actually manage to dupe anyone.

The same holds true for most other reputable sites, "spoof@" and "abuse@" are almost universal ("spoof@" is currently prefered, but go ahead and forward to both if you don't know for sure which is right) addresses for reporting these kinds of fake messages from a business domain.

Posts: 763 | Registered: Aug 1999  |  IP: Logged | Report this post to a Moderator
James Tiberius Kirk
Member
Member # 2832

 - posted      Profile for James Tiberius Kirk           Edit/Delete Post 
From the page:
quote:
Secure Log In
Oh, that's rich, that is.

--j_k

Posts: 3617 | Registered: Dec 2001  |  IP: Logged | Report this post to a Moderator
RunningBear
Member
Member # 8477

 - posted      Profile for RunningBear           Edit/Delete Post 
Whenever you login it should say https:// before the website.

the s, after http is important. it certifies it is actually a secure hookup.

It still might be fake, but if it has no s, then you can be almost certain.

Posts: 883 | Registered: Aug 2005  |  IP: Logged | Report this post to a Moderator
fugu13
Member
Member # 2859

 - posted      Profile for fugu13   Email fugu13         Edit/Delete Post 
An https connection does not necessarily mean any encryption; one of the negotiated levels of security (that a server could have set as the only level it supports) is as follows:

quote:
No encryption, MD5 message authentication only. This cipher suite uses MD5 message authentication to detect tampering. It is typically supported in case a client and server have none of the other ciphers in common.


This cipher suite is supported by SSL 3.0 but not by SSL 2.0.

http://docs.sun.com/source/816-6156-10/contents.htm

Don't base your trust on the use of https. Demand sites that you have decided to trust use https, but don't rely on it at all.

Posts: 15770 | Registered: Dec 2001  |  IP: Logged | Report this post to a Moderator
The Pixiest
Member
Member # 1863

 - posted      Profile for The Pixiest   Email The Pixiest         Edit/Delete Post 
You probably have a keylogger now. NEVER follow these phishing emails. Scan your system with a virus scanner *and* a spyware scanner ASAP
Posts: 7085 | Registered: Apr 2001  |  IP: Logged | Report this post to a Moderator
Lyrhawn
Member
Member # 7039

 - posted      Profile for Lyrhawn   Email Lyrhawn         Edit/Delete Post 
I had the same thing happen to me recently, and I didn't respond to them, but contacted PayPal first to find it was in fact a hoax.

I almost never trust anything I get in my email box anymore.

Posts: 21898 | Registered: Nov 2004  |  IP: Logged | Report this post to a Moderator
theCrowsWife
Member
Member # 8302

 - posted      Profile for theCrowsWife   Email theCrowsWife         Edit/Delete Post 
quote:
Originally posted by The Pixiest:
You probably have a keylogger now. NEVER follow these phishing emails. Scan your system with a virus scanner *and* a spyware scanner ASAP

Yes. This happened to my sister-in-law. Fortunately, the worst that happened was that she lost control of her yahoo email account, but it could have been a lot worse. She could have compromised banking information, instead of just losing all the emails that her boyfriend (now husband) sent her when he was stationed in Iraq.

--Mel

Posts: 1269 | Registered: Jun 2005  |  IP: Logged | Report this post to a Moderator
Chris Bridges
Member
Member # 1138

 - posted      Profile for Chris Bridges   Email Chris Bridges         Edit/Delete Post 
Never, ever, ever click on a link from an e-mail like that. If you get one about an account you actually have, such as paypal or ebay or whatever, go to the site yourself and check your messages.

PayPal does not send links in their e-mails, ever, for just this reason.

Posts: 7790 | Registered: Aug 2000  |  IP: Logged | Report this post to a Moderator
Tatiana
Member
Member # 6776

 - posted      Profile for Tatiana   Email Tatiana         Edit/Delete Post 
I got a disturbing new type of spam the other day. It said "regarding your loan request". I sincerely hope it was the loan request they hope I was going to make, rather than one they think I have already made, but I decided it would be foolish to open it so I deleted it. Anyone else get one like that yet?
Posts: 6246 | Registered: Aug 2004  |  IP: Logged | Report this post to a Moderator
jlt
Member
Member # 10088

 - posted      Profile for jlt   Email jlt         Edit/Delete Post 
I went to the link withmy Norton fraud monitoring on and it called the site a fraud, so I'd say definitely a scam.
Posts: 130 | Registered: Jan 2007  |  IP: Logged | Report this post to a Moderator
rivka
Member
Member # 4859

 - posted      Profile for rivka   Email rivka         Edit/Delete Post 
Tatiana, lots of 'em.
Posts: 32919 | Registered: Mar 2003  |  IP: Logged | Report this post to a Moderator
Mike
Member
Member # 55

 - posted      Profile for Mike   Email Mike         Edit/Delete Post 
quote:
Originally posted by The Pixiest:
You probably have a keylogger now. NEVER follow these phishing emails. Scan your system with a virus scanner *and* a spyware scanner ASAP

You can't get a keylogger from a website unless there's a security hole in your browser (possible, but fairly rare), or you download an executable file from an unreliable source and run it (much, much more common). Just saying.

Virus and spyware scanners are pretty much a necessity if you're running Windows, whether you go to this kind of url or not.

Posts: 1810 | Registered: Jan 1999  |  IP: Logged | Report this post to a Moderator
brojack17
Member
Member # 9189

 - posted      Profile for brojack17   Email brojack17         Edit/Delete Post 
Yes. Report this to the actual PayPal. They do a good job of taking down these scammers.
Posts: 1766 | Registered: Feb 2006  |  IP: Logged | Report this post to a Moderator
Lisa
Member
Member # 8384

 - posted      Profile for Lisa   Email Lisa         Edit/Delete Post 
quote:
Originally posted by A Rat Named Dog:
I got an e-mail purporting to be from PayPal about a problem with my account. Of course, the real problem is that I don't remember ever setting up a PayPal account [Smile]

I poked around with the links, and it sent me to this site:

http://www.paypal.com.198992.2smjb04.com/cmd-confirm/webscr/login.php?login&login_email=geoffcard@aol.com&ref=pp_as_3

I note that the actual domain name isn't really PayPal, but some random combination of characters. Should I assume that this is a scam, and an attempt to steal my password (were such a thing to exist)?

Never go to links like that. They can put all sorts of garbage on your computer. I suggest that you run a heavy-duty spyware checker now to clean off the crud they put on your computer.
Posts: 12266 | Registered: Jul 2005  |  IP: Logged | Report this post to a Moderator
Lisa
Member
Member # 8384

 - posted      Profile for Lisa   Email Lisa         Edit/Delete Post 
quote:
Originally posted by RunningBear:
Whenever you login it should say https:// before the website.

the s, after http is important. it certifies it is actually a secure hookup.

It still might be fake, but if it has no s, then you can be almost certain.

A secure hookup to a domain that clearly is not Paypal is no indication of anything.
Posts: 12266 | Registered: Jul 2005  |  IP: Logged | Report this post to a Moderator
The Pixiest
Member
Member # 1863

 - posted      Profile for The Pixiest   Email The Pixiest         Edit/Delete Post 
Mike: If one keeps their browser up to date, yeah, they're pretty safe. But how many people don't even bother with automatic updates?

I don't think anyone would at work if we weren't on to them all the time about it. I know my husband wouldn't even have a virus scanner much less automatic updates if I didn't do it for him.

Keyloggers are VERY common and it's easy to get them from a website. Exploits are well known, especially between the time Microsoft announces the fix and when people get around to rebooting their computer after the update.

Always keep your browser (automatic with IE) up to date. Always keep your computer up to date. Have a virus/spyware scanner and keep it up to date. And you're prolly safe.

Posts: 7085 | Registered: Apr 2001  |  IP: Logged | Report this post to a Moderator
   

   Close Topic   Feature Topic   Move Topic   Delete Topic next oldest topic   next newest topic
 - Printer-friendly view of this topic
Hop To:


Contact Us | Hatrack River Home Page

Copyright © 2008 Hatrack River Enterprises Inc. All rights reserved.
Reproduction in whole or in part without permission is prohibited.


Powered by Infopop Corporation
UBB.classic™ 6.7.2