Question: When is a phish not a fish?
Answer: When a phisher uses a real eBay URL to bounce unsuspecting victims to a phishing site.Register published an article on just such a phishing relay that takes advantage of a redirect feature in eBay’s Web pages.
At the end of February, the
From the article:
“Phishers are exploiting a redirection script on eBay’s site to make fraudulent e-mails look more convincing. Three Register readers noticed the trick in scam e-mails they received. Alerted by The Register, e-mail security firm MessageLabs confirmed that it has detected and blocked the same trick a number of times in the last two weeks.
“We have yet to hear back from the online auction house, despite notifying
eBay of a potential problem on Wednesday (23 February) and making several
calls since then.”
Note that eBay’s been closed-lipped about this. That’s been my experience
with them, too. Never comment on something that might reflect poorly on
brand identity. Not that they didn’t have image problems before this. They’ve had a reputation of being shifty and unreachable whenever their customers are in trouble.
For example, when I reported for Computerworld in 2002 on eBay’s fraud detection system running amok and locking eBay users out of the funds in their PayPal accounts, eBay’s PR person told me, “We’re not going to let you talk to any of our executives because we don’t like what you’re writing. So don’t call us anymore.”
Now I read that eBay is doing its guerilla PR tactics again. And I have it on good authority that the right people at eBay have known about the Web application flaw for a year but chose to ignore it until now.
What eBay executives fail to take into account is that word gets around. And
the more eBay and PayPal try to keep it quiet, the more outraged users
become and the more they talk about it in blogs, postings and “I hate eBay”
and “PayPal Sucks” sites.
So I’ll leave you with this BugTraq
posting about eBay’s redirect problem, which appeared two weeks before the Register report.




