Steve, Not weird. We have seen this quite frequently. Breaks some phishing detectors I believe and browsers don't care.
If you ftp you can see that it takes the classic approach of using a form with action taking advantage of an insecure mailer cgi ( http://www2.fiberbit.net/form/mailto.cgi ) tos a gmail email ([EMAIL PROTECTED]) All reported and all their base belong to us. Tom At 2:42 PM -0700 10/10/07, Steve Pirk wrote: >A new twist on an eBay phish: > >ftp://cindy:[EMAIL >PROTECTED]/_.htm?https://scgi.ebay.com/ws/eBayISAPI.dll?RegisterEnterInfo&siteid=0&co_partnerid=2&UsingSSL=1 > >ftp phish site? weird, but it works. > >The other url in the message is a host not found: >http://www.cudenka.pl/images/www.ebay.com.html >-- >Steve >Equal bytes for women. > >---------- Forwarded message ---------- >Return-Path: <[EMAIL PROTECTED]> >Received: from h1756.serverkompetenz.net (h1756.serverkompetenz.net > [81.169.154.149]) > by mail.pirk.com (8.14.1/8.12.0.Beta19) with ESMTP id l99Mu68e015988 > for <[EMAIL PROTECTED]>; Tue, 9 Oct 2007 15:56:06 -0700 >Received: from User (unknown [85.186.196.125]) > by h1756.serverkompetenz.net (Postfix) with ESMTP > id D59E334217B; Wed, 10 Oct 2007 00:11:41 +0200 (CEST) >From: "eBay" <[EMAIL PROTECTED]> >Subject: Unpaid Item Dispute #260120571043 >Date: Wed, 10 Oct 2007 01:12:10 -0700 >MIME-Version: 1.0 >Content-Type: text/html; > charset="Windows-1251" >Content-Transfer-Encoding: 7bit >X-Priority: 1 >X-MSMail-Priority: High >X-Mailer: Microsoft Outlook Express 6.00.2600.0000 >X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000 >Message-Id: <[EMAIL PROTECTED]> >To: undisclosed-recipients:; > > >eBay Unpaid Item Dispute #260120571043 - response required [eBayLogo.gif] > > >Dear member, > >eBay member uofarkscott44 (569Feedback score is 25,000 to 49,999 ) >[s.gif] Member is a PowerSeller [s.gif] Go to member's eBay Store has >that they already paid for item #260120571043 > > Review the submitted details regarding the payment. > > >Regards, >eBay International AG > > >_______________________________________________ >phishing mailing list >phishing@whitestar.linuxbox.org >http://www.whitestar.linuxbox.org/mailman/listinfo/phishing -- Tom Shaw - Chief Engineer, OITC <[EMAIL PROTECTED]>, http://www.oitc.com/ US Phone Numbers: 321-984-3714, 321-729-6258(fax), 321-258-2475(cell/voice mail,pager) Text Paging: http://www.oitc.com/Pager/sendmessage.html AIM/iChat: [EMAIL PROTECTED] Google Talk: [EMAIL PROTECTED] _______________________________________________ phishing mailing list phishing@whitestar.linuxbox.org http://www.whitestar.linuxbox.org/mailman/listinfo/phishing