C Fernandez wrote:
Doc Shipley wrote:
This is new to me too. I got one earlier today, but I caught it. What
made me suspect something was up, was that the email was so generic. In
addition, he asked things that were plainly stated in my auction. I did
a search for the username, and it came back as no longer a registered
user!!
Right. And on mine, the auction item number was invalid.
I just got a
phished "My Messages" eBay email from "a potential
buyer". It purported to be a question about a listed item, and the
links to the listing took me to a fake login page. It's very slick, I
wasn't paying attention and I fell for it.
Well, if you look, it wasn't actually in the message area if you logged
into "My Ebay".
Well, yeah, but that was a little late. :\
Like I said, if I had been paying attention (and if eBay wasn't
constantly "tweaking" the look and feel), it would have been fairly easy
to spot. But I wasn't.
What's
really ugly is that the phishing site actually *does* bounce
you into your own account and log you in.
I don't see how that's possible. Unless you mean that your browser
automatically fills in your username and password into a fake ebay page,
as if it were the real one. Otherwise, why would the scammer even need
to send an email to you?
No, I mean that when I clicked the "item link" in the phisher's
email, and logged into the page it took me to, it redirected me to eBay
and logged me into my real account, so that I ended up in my normal "My
Summary" interface, with my current watched items and stuff showing.
I don't know how they did it, but I'm guessing it just requires a
little PHP code on the phisher's site.
Doc