Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Spam, Scam and Phishbusters » College phishing
Search Topic:
Uniqs:
399
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
The FBI wants you to know: »
« Nice Scam attempt!  
AuthorAll Replies


nwrickert
sand groper
Premium,MVM
join:2004-09-04
Geneva, IL
·AT&T U-Verse
·AT&T Midwest

College phishing

This is an example of the new phishing that is being aimed mainly at college students.

Headers:
Message body:
--------------------------------

Dear EARLHAM.EDU Subscriber,

To verify your EARLHAM.EDU account, you must reply to this email
immediately and enter your password here (*********)

Failure to do this will immediately render your email address deactivated
from our database.

You can also confirm your email address by logging into your EARLHAM.EDU
account at https://webmail.earlham.edu/squirrel/src/login.php

Thank you for using EARLHAM.EDU !
THE EARLHAM.EDU TEAM

--------------------------------
The URL in the email is safe, and appears to be the real webmail site at Earlham College. The "Return-Path:" and "From:" headers also appear to have addresses at Earlham, though I have not tested them.

The "Reply-To:" header is the suspicious one. If somebody responds to this by email they will be sending their college network password to the phisher.

Note: I am not at Earlham. I have no idea why I was targetted for this particular message.

Judging by experience at my own campus, the stolen information is used for spamming. The spammers use the password to login to the webmail site, then do an automated spam run via that webmail.

The phish email was sent via an ISP webmail interface, and possibly that was based on an earlier email phish.

--
AT&T dsl; Westell 327w modem/router; SuSE 10.1; firefox 2.0.0.14
Forums » Up and Running » Security » Spam, Scam and PhishbustersThe FBI wants you to know: »
« Nice Scam attempt!  


Wednesday, 25-Nov 03:34:40 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [103] New AT&T Ad Campaign Hits Back At Verizon
· [85] New Bill Takes Aim At Higher Verizon ETFs
· [84] Apple Joins AT&T Verizon Snark Fest
· [39] In-Flight Internet Headed For Bumpy Landing?
· [32] Senators Want ACTA Made Public
· [30] Earthlink Suffers From Major E-mail Outage
· [30] AT&T Offers New Prepaid Wireless plans
· [28] Frontier Increases Modem Rental Fee
· [20] Despite Billions In USF Fees, U.S. Libraries Lack Bandwidth
· [16] Vivendi In Way Of Comcast's NBC Desires
Most people now reading
· Windows 7 boot manager editing questions [Microsoft Help]
· Mysterious $800 Cash Deposit? [General Questions]
· [Rant] Damn Sermons through my speakers! [Rants, Raves, and Praise]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· Is Gear Score now the new requirement to get pug invite? [World of Warcraft]
· Several MS Updates today (11/24/2009). [Security]
· [ Classes] Druid tanking: rotation and glyphs [World of Warcraft]
· [WIN7] Outlook express under Windows 7? [Microsoft Help]
· What to use while demonoid is down? [Filesharing Software]
· HOW-TO: QoS and Tomato (fixes "choppy voice") [MagicJack]