Warning: PayPal Scams and other Bank Scams
Every other day or so, I receive an e-mail from someone claiming to be PayPal or another bank of some variety.
Of course, each e-mail wants me to immediately click on the link and enter my username and password to promptly verify that information is correct due to lost records on their part, or to validate a recently large sum of cash deposited into my account, or other such ridiculous reasons.
Now the scam pages are usually easy to spot.
Basically, if you click on the link, it will show you the actual URL you will be directed in the address bar. For example, this is a fake http://www.paypal.com/ link. If you clicked on the link you'd be directed to visit Oprah's poop. If I had been a nasty evil person, I could have made that webpage look exactly like PayPal's website. If you were fooled, you might enter in your PayPal username and password which I would promptly abuse for evil deeds.
Okay, so you are wise and smart to this trick? No one is going to fool you because you look at that address bar to tell if the website is a fake or the real McCoy. Not so fast wise-guy; you could still be fooled. Take a look at this fake PayPal URL from MSIE: https://www.paypal.com/. This does not go to the real PayPal website. Pretty neat trick, huh? Not if I were an evil person trying to scam you. This webpage does not include a valid PayPal forgery fortunately, but it could have very easily.
This is all due to Internationalizing Domain Names in Applications (IDNA). Basically, there are international characters that look almost exactly like the normal latin characters to which we are all familiar.
Even the writers of the RFC specification, warned that this might happen:
When systems use local character sets other than ASCII and Unicode, this specification leaves the problem of transcoding between the local character set and Unicode up to the application. If different applications (or different versions of one application) implement different transcoding rules, they could interpret the same name differently and contact different servers. This problem is not solved by security protocols like TLS that do not take local character sets into account.
Let me interpret for you:
Yadda yadda yadda... some international characters look like Latin characters... yadda yadda... it could fool people into thinking one website was anothers... yadda yadda yadda
What's the best way to make sure you are going to the right website? Type the website in yourself into the address bar, and not by cut n' paste or by clicking on a link in your e-mail. Yes, typing is a major pain, but it's highly unlikely you will type the international character by accident and be fooled by imitations.
YOU. HAVE. BEEN. WARNED.
What others are saying:
The Crazy Rants of Samantha Burns






















Comments
eBay too! I get more from eBay cammers than I do from PayPal even, threatening that my account will be closed if I don't update ALL my information immediately.
Posted by: Diane | August 2, 2005 05:06 PM
Samantha, I used to get 4 or 5 of these paypal and ebay emails a day. You can forward them to spoof@paypal.com and spoof@ebay.com ... it takes awhile but if you keep doing this they'll eventually slow down.
BTW, I'm adding you to my blogroll at http://finelineweb.com/blog/mel/
Posted by: mel | August 2, 2005 05:58 PM