Slashdot Log In
Fake PayPal Site
Posted by
CmdrTaco
on Fri Jul 21, 2000 09:02 AM
from the gotta-hate-when-that-happens dept.
from the gotta-hate-when-that-happens dept.
CharlieG writes: "Just a friendly warning as a followup to all the PayPal talk of yesterday. It seems that there is a scam going on based out of South Ural, Romania. They have created a site that looks exactly like Paypal, but is PayPai.com." Much more harmful than all the Slashdot typo sites (those only cause me to get dozens of flames a week for framing Slashdot: this one could actually steal your credit card!)
This discussion has been archived.
No new comments can be posted.
Fake PayPal Site
|
Log In/Create an Account
| Top
| 134 comments
(Spill at 50!) | Index Only
| Search Discussion
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
(1)
|
2
(1)
|
2

Technical info (Score:3)
Anyway, all the login info was routed through paypai.com, then it returned the paypal.com webpage. Worked essentially like a proxy, but probably logged the passwords. But the front end of the page was copied directly from paypal.com and had the paypal references changed to go to paypai.
Interesting method of attack. I wonder if this is going to become more common. Makes you wonder how you can secure against this kind of scam from the viewpoint of the website designer. Okay, admittedly, if you can get a user to give out a password, he's boned, but still.
---
Re:PayPai? (Score:3)
Slashdot Effect Saves The Day (Score:3)
effect already took care of the problem.
All we have to do is keep a quick link at
on hand to make sure they don't get back up.
By the time our loyal crowd of slashdot readers
get tired of constantly crushing...er revisiting
the deciteful paypal site they will be out of
revenue.
Registar.Cops? (Score:3)
agreement concerning domains. (The one that says they are free to do
nearly anything, include reposses your children and pets.)
Has anyone ever tried contacting the registar of a domain and report
such fraudulent abuse of a domain name. Network Solutions is fairly quick
about protect mother corporate.
Although PayPai.com uses something named EasySpace, I am sure the power
of being a domain registar has already corrupted those in charge there
and they would be more than insanely happy to be Registar cops.
Will it soon be, Registar to the rescue? Instead of going through the
proper authorities...especially when the business in question is located
in some far off land or a floating oil rig with no internet law.
Re:A simple solution.... (Score:3)
Re:/. effect (Score:3)
"They have created a site that looks exactly like Paypal"
I guess you could go to paypal.com and pretend you're getting scammed. I just did, and I'm pretty pissed off and calling my credit card company right now.
Re:Here is a mirror. (Score:3)
Some Are Still Available! (Score:3)
NetworksoIutions.com [networksoiutions.com] on the other hand is taken, though not by anything useful.
-----
Could have been worse/brighter (Score:3)
First, they used a lure that was not only false, but that could be readily verifiable by the user. Big chunk o' cash waiting? I'll go see! Hmm, not there... uh oh! Using a less-effective lure (please click here to be removed from the paypaI.com mailing list) would not have generated as many hits, but would have kept him under cover much longer.
I also think it was a bit untidy of him/her to use paypai.com as the main site. Personally, I look at the URL quite a bit. Seeing "paypai" would set me off instantly. Instead, he/she could have used something else, like "login.paypalcom.net" or even "welcome.to/paypal", and one might just assume they're expanding their service and changing server names (like Hotmail likes to do a lot).
Even better (if it's possible), after recording the login and password, it could have spat the user to a "login failed" page with a "please try again" link, or maybe "server error, please try a different server [boo.hoo], sorry for the inconvenience" page, that then redirected the user to the REAL PayPal site.
I have to admit - as illegal and unethical as this scam was, it was a fairly bright idea. Good thing for PayPal users that they didn't think it all the way through.
Abusers of Fonts (Score:4)
I happened to notice this because i use a high contrast decent-sized courier font on my machine, and i run PINE in an KDE terminal window, so it stuck out like a sore thumb.
As always the user is the weakest link in security...
Here is a mirror. (Score:5)