|
Donation/Premium |
|
 |
|
|
|
|
|
|
|
 |
 |
| View previous topic :: View next topic |
| Author |
Message |
OJ_did_it
Major
 Premium Member
 Joined: Nov 13, 2004 Posts: 1059
|
Posted: Tue Feb 22, 2005 8:51 am Post subject: Another Washington Mutual Phish... |
|
|
| Some Con Artist wrote: |
X-Message-Status: n
X-SID-PRA: personalbanking@wamu.com
X-SID-Result: TempError
X-Message-Info: 6sSXyD95QpWaGVQUba4XWWiyhRFH+l/
d6fKQCagV+o0=
Received: from boscarino.com ([12.44.186.131]) by
MC8-F27.hotmail.com with Microsoft SMTPSVC
(6.0.3790.211);
Mon, 21 Feb 2005 15:27:48 -0800
Received: from wamu.com
(localhost.localdomain [127.0.0.1])
by boscarino.com (8.12.5/8.12.5) with ESMTP id
j1M1okuQ014881
for <XXXXXXXX@msn.com>; Mon, 21 Feb 2005 17:50:46
-0800
Date: Mon, 21 Feb 2005 17:50:46 -0800
Message-Id:
<200502220150.j1M1okuQ014881@boscarino.com>
To: XXXXXXXX@msn.com
From: personalbanking@wamu.com
Subject: Security Notice #326871 Washington
Mutual Bank Online Account Update Necesary
Content-Type: text/html; charset=ISO-8859-1
Return-Path: personalbanking@wamu.com
X-OriginalArrivalTime: 21 Feb 2005 23:27:48.0396
(UTC) FILETIME=[F44A1EC0:01C5186C]
<html>
<p align="left"><font face="Verdana"
style="font-size: 8.3pt">
Dear <b>Washington Mutual</b>
Customer,<br><br>
We recently reviewed your account, and suspect
that your
<b>Washington Mutual Internet Banking</b>
account may have been accessed by an unauthorized
third party. Protecting the security of your
account and of the <b>Washington Mutual</b>
network is our primary concern. Therefore, as a
preventative measure, we have temporarily limited
access to sensitive account features.<br><br>
To restore your account access, please take the
following steps to ensure that your account has
not been compromised:<br><br>
1. Login to your <b>Washington Mutual Internet
Banking</b> account. In case you are not enrolled
for Internet Banking, you will have to use your
Social Security Number as both your Personal ID
and Password and fill in all the required
information, including your name and account
number.<br><br>
2. Review your recent account history for any
unauthorized withdrawles or deposits, and check
your account profile to make sure not changes
have been made. If any unauthorized activity has
taken place on your account, report this to
<b>Washington Mutual</b> staff immediately.<br>
<br>
To get started, please click on the link below:
<br>
<br>
<b>
<a target="_blank"
href="http:/ /eyeball.goodwingroup.com/.wamusk/
index.php?MfcISAPICommand=SignInFPP&UsingSSL=1
&email=&userid=">
<font color="#000099">http://www.personalbanking
.wamu.com/verify/confirm.html</font></a></b><br><br>
We apologize for any inconvenience this may cause,
and appreciate your assistance in helping us
maintain the integrity of the entire
<b>Washington Mutual</b> system. Thank you for
your prompt attention to this matter.<br>
<br><br>Sincerly,<br>
<br>The <b>Washington Mutual</b> Team<br><br>
Please do not respond to this e-mail. Mail sent
to this address cannot be answered.
For Assistance, log in to your <
b>Washington Mutual</b> account and choose the
"Help" link in the header of any page.</font></p>
<table cellspacing="0" cellpadding="0"
border="0" width="100%"ID="Table2">
<font face="Verdana" style="font-size: 7pt"
color="#000000">©&Copyright
2005, Washington Mutual, Inc. All Rights.
Reserved.</font></nobr></td>
</tr>
</table>
</html>
|
|
|
| Back to top |
|
 |
OJ_did_it
Major
 Premium Member
 Joined: Nov 13, 2004 Posts: 1059
|
Posted: Tue Feb 22, 2005 9:01 am Post subject: |
|
|
RIPE WHois says IP is located in the UK, but WHOIS.sc says that its located in SPAIN.
True IP: 212.57.233.63
I have an idea: what if I were to write a batch file that endlessly pings this site with 65534 btyes of data and then pass the batch file onto others. Wouldnt that take their bandwidth to the limit???!!!
OJ _________________
"Your every move is my calculated step"
|
|
| Back to top |
|
 |
OJ_did_it
Major
 Premium Member
 Joined: Nov 13, 2004 Posts: 1059
|
Posted: Tue Feb 22, 2005 9:13 am Post subject: |
|
|
Edited
Last edited by OJ_did_it on Wed Feb 23, 2005 7:20 am, edited 1 time in total |
|
| Back to top |
|
 |
Ikeb
Special Response Team Forums Admin
 Joined: Apr 20, 2003 Posts: 16543
|
Posted: Tue Feb 22, 2005 1:11 pm Post subject: |
|
|
I'm afraid that type of action could result in legal action against you. Yes we want to put these sort of scum out of action but resorting to DOS tactics is illegal.
|
|
| Back to top |
|
 |
Oldfrog
Special Response Team
 Joined: Jun 27, 2004 Posts: 8576 Location: Deep in the Heart of Texas
|
Posted: Tue Feb 22, 2005 3:33 pm Post subject: |
|
|
Easy, OJ. Not only are DOS attacks illegal, as Ikeb pointed out, but also do not conform to the ethics that we uphold on this site. In any event, your idea will simply not work in this situation for the simple reason that the server hosting the target URL is firewalled and does not accept ICMP traffic. This means that you would not consume any of their bandwidth, would prominently place your IP address in their firewall logs, and would almost certainly trigger an "unusual activity" alarm at your own ISP which could result in the suspension of your account.
There are better ways to combat these people in an ethical, legal manner. We attempt to do so here by educating people to the risks, providing advice on threat recognition, exposing the methods used to deceive, and reporting exploit attempts to the proper authorities. Proof that these tactics work is reflected in the extremely short life spans that these phishing URL's enjoy. _________________
MS MVP Security 2006-2008
|
|
| Back to top |
|
 |
Ikeb
Special Response Team Forums Admin
 Joined: Apr 20, 2003 Posts: 16543
|
Posted: Tue Feb 22, 2005 6:43 pm Post subject: |
|
|
The downside is that these sleazebags just move their shop to another cyber location. Ultimately it falls to law enforcement officials to cuff 'em and lock 'em up. As Oldfrog points out, we can play a role by alerting both potential "marks" as well as the cops to these potential fraud crimes.
|
|
| Back to top |
|
 |
OJ_did_it
Major
 Premium Member
 Joined: Nov 13, 2004 Posts: 1059
|
Posted: Wed Feb 23, 2005 7:20 am Post subject: |
|
|
Points well taken. I've edited the post.
OJ _________________
"Your every move is my calculated step"
|
|
| Back to top |
|
 |
|
|
|
You can post new topics in this forum You can reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum You can attach files in this forum You can download files in this forum
|
Powered by phpBB © 2001 phpBB Group
|