[ale] Fraud? [Fwd: Visa Security Update]

Frank S. Glass glass at holos.com
Fri Dec 5 14:57:39 EST 2003


It takes you to ip address 61.252.126.191, probably in another country. 
Everything before the @ sign in the url is a username.  This is a very well
crafted scam.  I've often wondered why thieves with this much skill couldn't
have made a good living plying their craft honestry.


-- 
Frank S. Glass
Holos Software, Inc.
770-496-1877


Quoting Stephen Touset <stephen at touset.org>:

> Hrm...looking around even MORE, I found out that when you go to that 
> URL, it actually takes you a VISA page. I assume, then, that the page 
> attempts to exploit a vulnerability in some browser(s) to allow the 
> theft of credit card information by you simply visiting the page and it 
> instantly redirecting you to a VISA one.
> 
> Stephen Touset wrote:
> 
> > Looking around more, I see that the link *doesn't* actually go to Visa's 
> > website, but Mozilla takes me there anyways. However, the actual URL 
> > goes to:
> > 
> >
>
http://www.visa.com%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20:UserSession%3D2f6q9uuu88312264trzzz55884495&usersoption%3DSecurityUpdate&StateLevel%3DGetFrom@61.252.126.191/verified_by_visa.html
> 
> > 
> > 
> > Also, the headers of the email show that it came from the United 
> > Kingdom. So yeah, this is a scam. Just one that doesn't work in Firebird.
> > 
> > Stephen Touset wrote:
> > 
> >> This email absolutely reeks of fraud. There are grammar mistakes, the 
> >> layout is boring, but bad, etc. However, when you click on the link, 
> >> it actually takes you to Visa's website. I'm almost certain that this 
> >> is a scam, but everything checks out so far. Has anyone else gotten 
> >> one of these, and is it legit?
> >>
> >> ------------------------------------------------------------------------
> >>
> >> Subject:
> >> Visa Security Update
> >> From:
> >> Visa International Service <security at visa-security.com>
> >> Date:
> >> Fri, 05 Dec 2003 21:54:33 -0500
> >> To:
> >> stephen at touset.org
> >>
> >>
> >>
> >> *Dear Customer,
> >>
> >> Our latest security system will help you to avoid possible fraud 
> >> actions and
> >> keep your investments in safety.
> >>
> >> Due to technical security update you have to reactivate your account
> >>
> >> Click on the link below to login to your updated Visa account.
> >>
> >> To log into your account, please visit the Visa Website at
> >>
> >> http://www.visa.com <http://www.visa.com 
> >>
>
:UserSession=2f6q9uuu88312264trzzz55884495&usersoption=SecurityUpdate&StateLevel=GetFrom at 61.252.126.191/verified_by_visa.html>
> 
> >>
> >>
> >> We respect your time and business.
> >> It's our pleasure to serve you.
> >>
> >>
> >> * Please don't reply to this email. This e-mail was generated by a 
> >> mail handling system.
> >>
> >>
> >>
> >>
> >> Copyright 1996-2003, Visa International Service Association. All 
> >> rights reserved.
> >>
> >>
> >>
> >>
> >> ------------------------------------------------------------------------
> >>
> >> _______________________________________________
> >> Ale mailing list
> >> Ale at ale.org
> >> http://www.ale.org/mailman/listinfo/ale
> > 
> > 
> > 
> > _______________________________________________
> > Ale mailing list
> > Ale at ale.org
> > http://www.ale.org/mailman/listinfo/ale
> 
> _______________________________________________
> Ale mailing list
> Ale at ale.org
> http://www.ale.org/mailman/listinfo/ale
> 
> 


-------------------------------------------------
Holos Software, Inc. http://holos.com



More information about the Ale mailing list