PDA

View Full Version : Warning: Possible "PayPal" Scam


dank
09-11-2002, 11:49 PM
I haven't looked around to confirm if this is indeed a scam, a la the "PayPaI" of awhile back, but it looks very fishy. I just got an email sent to my PayPal account address saying they had a system failure today and had to take the faulty computer offline. Some data was lost, but no account balances affected (how would they know that?). Please log in and confirm everything is ok, yadda, yadda, yadda...

Where things caught my attention is the link you are taken to when clicked upon is different from the one shown in the email (it's HTML-ified). What you are shown:

https://www.paypal.com/cgi-bin/webscr/?cmd=_login-run

what the link truly is, as embedded in the email:

http://www.paypalsys.com/cgibin/webscr/?cmd=_login-run

It looks like PayPal ... but that's not really their site, is it? If it isn't, the goofballs forgot to change all the links over to their fake site... Also, the form element on the page stays on paypalsys.com:

<FORM ACTION = "?email=" METHOD = "POST">

Looks sketchy... How many account logins do you suppose they'll collect from unsuspecting folk? :( I imagine reporting this to PayPal would be a good thing, although they most likely already know about it.

Dan

Daytripper_MI6
09-12-2002, 12:35 AM
NM

the first url is on a secure server, where the other one isn't.

Andilinks
09-12-2002, 12:44 AM
I have forwarded a link to this thread to PayPal, they (pro forma) promised to reply by email.

dank
09-12-2002, 12:56 AM
NM?

I forwarded it to PayPal and got the auto-response, also.

Dan

dank
09-12-2002, 12:58 AM
Does NM stand for Never Mind, as evidenced by last edited...?

I believe any link to paypal.com automatically redirects to the secure server, for what that's worth.

Dan

Daytripper_MI6
09-12-2002, 02:11 AM
Yes, the NM was for never mind. Was doing a whois search on paypalsys.com It was just created on 10Sep2002

What you are shown:

https://www.paypal.com/cgi-bin/webscr/?cmd=_login-run

what the link truly is, as embedded in the email:

http://www.paypalsys.com/cgibin/webscr/?cmd=_login-run
So are you saying when you click on the link it takes you to the"http://www.paypalsys.com/cgibin/webscr/?cmd=_login-run" site?

dank
09-12-2002, 10:04 AM
Yep, that's what I'm saying. :)

Dan
- never did like HTML email...

Charles Capps
09-12-2002, 10:46 AM
Golly gee, the site's gone. I wonder why.

dank
09-12-2002, 10:50 AM
Boy, that was quick. 15 minutes of fame == 11 hours of online glory?

Dan

Andilinks
09-12-2002, 03:03 PM
And unfortunately may have turned an illegal profit for them if enough people were scammed in 11 hours. I will be more careful of links embedded in email...