Skip to main content
GameDev.net gamedev.net
🔒 Locked

almost fell for a phishing email

Started by slicer4ever Aug 30, 2015 at 6:23 AM 20 replies 4.1k views
Original Post
slicer4ever
slicer4ever
so, today i was nearly fooled by a phishing email, and had chrome not alerted me, i would have potentially provided one of my passwords to them.

So, this is what happened and how i was tricked, because of the contest i'm currently doing alot of paypal traffic. suddenly today i get a paypal phishing email(i do find this a bit odd to be honest though). First thing is the account in question actually isn't my current active account, but I was worried at first it was talking about my active account. So i go directly to paypal, login and no warnings. check the email and see it's talking about my old account. log into that one on paypal, and no warnings there. so i change that accounts password, and go back to the email(this is not an excuse for my actions, had i better inspected the email i would have caught the fact before foolishly attempting to use their links).

This is the part that i missed, and is why i so casually made this mistake(and actually why i'm making this post), When i get an email, i always double check where the link is actually going to send me, this one was going to send me to:

paypal.com.webapp/somepage?bunchofnumbershere.

I made a grave mistake in not realizing paypal is the subdomain, and com is the domain. i just casually thought "webapp" was the page, and not the actual .com address(what is this part of an address called anyway?). anyway, it made me realize that this form of phishing is now possible, it's much easier in my opinion to pass off a fake url since now com is a legitimate domain name, something like "paypal.com.com" would have made me take a double look, but i casually glanced over the "webapp" part, and didn't give it a second thought.

After this i took a longer look at the format of the email, and realized further what a fool I was, as there were several other signs that should have tipped me off.

But anyway, i found this form of url faking as a bit scary, and now I don't think i'll make a similar mistake in the future. Hopefully reading this might save someone else in the future as well.
Alberth
Alberth
I always type urls manually, especially for sensitive sites. It's a bit more work, but at least you don't go to places you didn't enter.
Hodgman
Hodgman

it's much easier in my opinion to pass off a fake url since now com is a legitimate domain name, something like "paypal.com.com" would have made me take a double look

Your brain is actually hard-wired to filter out redundantly duplicated words.
Mistakes like "the fox jumped over the the lazy dog" are often missed because of this.
Bacterius
Bacterius

it's much easier in my opinion to pass off a fake url since now com is a legitimate domain name, something like "paypal.com.com" would have made me take a double look

Your brain is actually hard-wired to filter out redundantly duplicated words.
Mistakes like "the fox jumped over the the lazy dog" are often missed because of this.

Case in point, I didn't see the double "the" on the first read unsure.png

“If I understand the standard right it is legal and safe to do this but the resulting value could be anything.”
Endurion
Endurion

Did they even manage to get your name right? Usually my fake paypal emails will not have my name embedded.

And even if I do get suspicious of it, never use the link in the email directly.

email is another of these old protocols from old trustworthy days that would need a security overhaul. So far there is no real successor.

Fruny: Ftagn! Ia! Ia! std::time_put_byname! Mglui naflftagn std::codecvt eY'ha-nthlei!,char,mbstate_t>
ronan.thibaudau
ronan.thibaudau

Another shield should be protecting you even if you screw up and click, the SSL certificate won't be to paypal's name.

Tom Sloper
Tom Sloper
So his website is really "com.webapp" - wow, that's actually a smart phisherman!
-- Tom Sloper    --      sloperama.com
JohnnyCode
JohnnyCode




Case in point, I didn't see the double "the" on the first read unsure.png

Wow, me neither, had to read it second time to see what's up.

slicer4ever
slicer4ever

I always type urls manually, especially for sensitive sites. It's a bit more work, but at least you don't go to places you didn't enter.

this seems like it'd be quite difficult with the massive series of numbers usually associated with these emails. I generally inspect the url they are sending me to, to verify the domain is correct before moving on(which is why this happened in the first place)


it's much easier in my opinion to pass off a fake url since now com is a legitimate domain name, something like "paypal.com.com" would have made me take a double look

Your brain is actually hard-wired to filter out redundantly duplicated words.
Mistakes like "the fox jumped over the the lazy dog" are often missed because of this.


Ha, perhaps i would have still done this even if it was com.com

Did they even manage to get your name right? Usually my fake paypal emails will not have my name embedded.

And even if I do get suspicious of it, never use the link in the email directly.

email is another of these old protocols from old trustworthy days that would need a security overhaul. So far there is no real successor.

ah, this is what i meant by "After this i took a longer look at the format of the email, and realized further what a fool I was" paypal would have used my name on the account, not the email address. And it should have absolutely been my first red flag with the email. I really have no excuse for why i overlooked this fact.

Another shield should be protecting you even if you screw up and click, the SSL certificate won't be to paypal's name.

probably what chrome caught(either that, or the site is already a known phishing site to chrome).

So his website is really "com.webapp" - wow, that's actually a smart phisherman!

yea, it's the first time i've seen this tactic being used, which is why i hope this post might help tip off someone else that is ever in a similar position.
L. Spiro
L. Spiro

Look, slicer4ever, let’s end this silly game.

Just give me your PayPal account information and I will stop sending you these e-mails. You can’t hold out forever…

L. Spiro

I restore Nintendo 64 video-game OST’s into HD! https://www.youtube.com/channel/UCCtX_wedtZ5BoyQBXEhnVZw/playlists?view=1&sort=lad&flow=grid
215648
215648

Look, slicer4ever, let’s end this silly game.

Just give me your PayPal account information and I will stop sending you these e-mails. You can’t hold out forever…

L. Spiro

We will split the profits.

Dragonsoulj
Dragonsoulj




and not the actual .com address(what is this part of an address called anyway?)

I didn't see this answered for you. Top Level Domains are what the ".com", ".net" (as in GameDev.net), ".org", etc are called.

ankhd
ankhd

yep star craft II has them to they keep sending me emails to click there link because Im trying to sell wow account I dont have that account pff.

Brain
Brain

and not the actual .com address(what is this part of an address called anyway?)

I didn't see this answered for you. Top Level Domains are what the ".com", ".net" (as in GameDev.net), ".org", etc are called.

You can rent your own tld for only $10k a year.

Looks like they don't really check what you're doing either...

.paypal here we come... :)

Bacterius
Bacterius

Another shield should be protecting you even if you screw up and click, the SSL certificate won't be to paypal's name.

There's two problems with this line of thinking though, assuming you failed to recognize the phishing attempt from the URL alone:

1. if the phishing link sends you to an HTTP endpoint, and you forget to check that the green padlock is missing (if you actually check that, you probably are also checking the URL), you're fucked

2. if the adversary actually has a valid and legitimate-looking SSL certificate to his phishing website (and, yes, it can be done; turns out many CA's don't really do in-depth verification besides domain ownership), and you don't check that the certificate is actually owned by the legitimate Paypal entity (which is actually about the same amount of work as checking the URL), you're fucked

The best defense against phishing attacks, really, is to use bookmarks, and not click random links from emails, or if you must, spend a few seconds scanning the URL to verify it's actually sending you to the right place. And also, it's probably okay to ignore SSL certificate warnings from some random website you just found on google search, but you probably want to think twice if your browser is telling you your bank's certificate is invalid!

“If I understand the standard right it is legal and safe to do this but the resulting value could be anything.”
slicer4ever
slicer4ever

Look, slicer4ever, let’s end this silly game.
Just give me your PayPal account information and I will stop sending you these e-mails. You can’t hold out forever…


L. Spiro

Ah i thought so, the "L. Spiro" at the bottom of that email seemed very familar. Unfortuantly i think you'll be disappointed with my finacials though.


and not the actual .com address(what is this part of an address called anyway?)


I didn't see this answered for you. Top Level Domains are what the ".com", ".net" (as in GameDev.net), ".org", etc are called.
Ah thanks, i was always curious about what to call that part.
andy-pandy
andy-pandy

this forum has historically attracted quite smart people from the game/tech industry, so i am highly surprised to hear that the OP almost fell for phishing scammer. I personally avoid such situations by a custom google script i wrote that send all of my emails straight into the goddamn trash

d000hg
d000hg

I always type urls manually, especially for sensitive sites. It's a bit more work, but at least you don't go to places you didn't enter.

Until you mis-type and end up on a scam site like paypla.com set up for just that purpose.

Servant of the Lord
Servant of the Lord

Until you mis-type and end up on a scam site like paypla.com set up for just that purpose.

That's what the ".cm" domain name is for. smile.png

Topic Locked

This topic has been locked by a moderator. New replies are not allowed.

Sign in to reply to this topic.