Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Computer Security > How to interpret this?!

Reply
Thread Tools

How to interpret this?!

 
 
a_monk
Guest
Posts: n/a
 
      03-16-2007
Lately I received a number (phishing) mails from a bank asking for
confirmation. In the message, there was a URL:

https://www1.royalbank.com/cgi-bin/r...ntSign&LANG=EN

However, when I moved my mouse pointer to the beginning on the URL, at
the bottom of the screen, it showed the following instead.

http://163.23.70.201/http/www1.royal...tSign&LANG=EN/

First of all, the link seems not using SSL (http instead of https).
Secondly, when I pinged 163.23.70.201, there was no response.

I hesitate to click on the https:// link.

Could someone help me understand what is it all about? Any info is
much appreciated.

A Monk

 
Reply With Quote
 
 
 
 
Sebastian Gottschalk
Guest
Posts: n/a
 
      03-16-2007
a_monk wrote:

> Lately I received a number (phishing) mails from a bank asking for
> confirmation. In the message, there was a URL:
>
> https://www1.royalbank.com/cgi-bin/r...ntSign&LANG=EN
>
> However, when I moved my mouse pointer to the beginning on the URL, at
> the bottom of the screen, it showed the following instead.
>
> http://163.23.70.201/http/www1.royal...tSign&LANG=EN/
>
> First of all, the link seems not using SSL (http instead of https).
> Secondly, when I pinged 163.23.70.201, there was no response.
>
> I hesitate to click on the https:// link.
>
> Could someone help me understand what is it all about? Any info is
> much appreciated.


<a
href="http://this.is/the/real/destination.php">http://can.claim/anything/about/the/link.html</a>

Your problem obviously is that you messed up your mail client to render
HTML content. Very very bad idea.

And since you're abusing MSIE as a webbrowser, I presume your mail client
in Outlook Express or Outlook. That means you'd be even worse off, since
there a various features^W unpatched vulnerabilities which allow the
attacker to fake the displayed URL. You're lucky that this attacker didn't
try.
 
Reply With Quote
 
 
 
 
David H. Lipman
Guest
Posts: n/a
 
      03-16-2007
From: "a_monk" <>

| Lately I received a number (phishing) mails from a bank asking for
| confirmation. In the message, there was a URL:
|
| https://www1.royalbank.com/cgi-bin/r...ntSign&LANG=EN
|
| However, when I moved my mouse pointer to the beginning on the URL, at
| the bottom of the screen, it showed the following instead.
|
| http://163.23.70.201/http/www1.royal...tSign&LANG=EN/
|
| First of all, the link seems not using SSL (http instead of https).
| Secondly, when I pinged 163.23.70.201, there was no response.
|
| I hesitate to click on the https:// link.
|
| Could someone help me understand what is it all about? Any info is
| much appreciated.
|
| A Monk

What part of Phishing don't you understand ?

The screen shows; https://www1.royalbank.com but the HTML really points to;
http://163.23.70.201

http://www.dnsstuff.com/tools/whois....0.201&email=on

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm


 
Reply With Quote
 
a_monk
Guest
Posts: n/a
 
      03-16-2007
On Mar 15, 9:34 pm, "David H. Lipman" <DLipman~nosp...@Verizon.Net>
wrote:
> From: "a_monk" <dfox...@hotmail.com>
>
> | Lately I received a number (phishing) mails from a bank asking for
> | confirmation. In the message, there was a URL:
> |
> |https://www1.royalbank.com/cgi-bin/r...=1&F21=IB&F22=...
> |
> | However, when I moved my mouse pointer to the beginning on the URL, at
> | the bottom of the screen, it showed the following instead.
> |
> |http://163.23.70.201/http/www1.royal...access/F21=IB&...
> |
> | First of all, the link seems not using SSL (http instead of https).
> | Secondly, when I pinged 163.23.70.201, there was no response.
> |
> | I hesitate to click on the https:// link.
> |
> | Could someone help me understand what is it all about? Any info is
> | much appreciated.
> |
> | A Monk
>
> What part of Phishing don't you understand ?
>
> The screen shows; https://www1.royalbank.com but the HTML really points to;http://163.23.70.201
>
> http://www.dnsstuff.com/tools/whois....0.201&email=on
>
> --
> Davehttp://www.claymania.com/removal-trojan-adware.htmlhttp://www.ik-cs.com/got-a-virus.htm


What would happen if I clicked on the link?

 
Reply With Quote
 
a_monk
Guest
Posts: n/a
 
      03-16-2007
On Mar 15, 9:39 pm, "a_monk" <dfox...@hotmail.com> wrote:
> On Mar 15, 9:34 pm, "David H. Lipman" <DLipman~nosp...@Verizon.Net>
> wrote:
>
>
>
>
>
> > From: "a_monk" <dfox...@hotmail.com>

>
> > | Lately I received a number (phishing) mails from a bank asking for
> > | confirmation. In the message, there was a URL:
> > |
> > |https://www1.royalbank.com/cgi-bin/r...=1&F21=IB&F22=...
> > |
> > | However, when I moved my mouse pointer to the beginning on the URL, at
> > | the bottom of the screen, it showed the following instead.
> > |
> > |http://163.23.70.201/http/www1.royal...access/F21=IB&...
> > |
> > | First of all, the link seems not using SSL (http instead of https).
> > | Secondly, when I pinged 163.23.70.201, there was no response.
> > |
> > | I hesitate to click on the https:// link.
> > |
> > | Could someone help me understand what is it all about? Any info is
> > | much appreciated.
> > |
> > | A Monk

>
> > What part of Phishing don't you understand ?

>
> > The screen shows; https://www1.royalbank.combut the HTML really points to;http://163.23.70.201

>
> >http://www.dnsstuff.com/tools/whois....0.201&email=on

>
> > --
> > Davehttp://www.claymania.com/removal-trojan-adware.htmlhttp://www.ik-cs.c...

>
> What would happen if I clicked on the link?- Hide quoted text -
>
> - Show quoted text -


Where could one report this crime?

 
Reply With Quote
 
David H. Lipman
Guest
Posts: n/a
 
      03-16-2007
From: "a_monk" <>


|
| Where could one report this crime?

http://www.antiphishing.org/report_phishing.html

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm


 
Reply With Quote
 
Arthur T.
Guest
Posts: n/a
 
      03-16-2007
In
Message-ID:< ups.com>,
"a_monk" <> wrote:

>Lately I received a number (phishing) mails from a bank asking for
>confirmation. In the message, there was a URL:

<snip>
>However, when I moved my mouse pointer to the beginning on the URL, at
>the bottom of the screen, it showed the following instead.

<snip>
>Could someone help me understand what is it all about? Any info is
>much appreciated.


This is standard HTML used for nefarious purposes.

I'll show an example, using parens instead of angle brackets
(in case you have a newsreader that renders HTML).

(a href="http://ACTUAL.URL")WHAT TO DISPLAY(/a)

In the above, an HTML-knowledgeable reader will show "WHAT TO
DISPLAY", but if you click on it, it'll take you to
"http://ACTUAL.URL". If "WHAT TO DISPLAY" *looks* like a URL,
it'll cause the confusion you experienced.

--
Arthur T. - ar23hur "at" intergate "dot" com
Looking for a z/OS (IBM mainframe) systems programmer position
 
Reply With Quote
 
Jim Watt
Guest
Posts: n/a
 
      03-16-2007
On 15 Mar 2007 17:43:50 -0700, "a_monk" <> wrote:

>Lately I received a number (phishing) mails from a bank


Then either delete them and move on or report them to
the bank.
--
Jim Watt
http://www.gibnet.com
 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Re: How include a large array? Edward A. Falk C Programming 1 04-04-2013 08:07 PM
debug arp output - please help to interpret Igor Mamuziæ Cisco 3 12-21-2004 10:50 AM
MAX+plus II error:Can't interpret indexed name Aliki VHDL 3 09-24-2004 02:50 AM
Re: How to interpret $FORM{} variable ? James Hunt Perl 0 05-19-2004 07:52 PM
Newbie: Can someone help interpret this single line ACL Doc Holliday Cisco 5 12-28-2003 07:37 PM



Advertisments
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57