Go Back   Wireless and Wifi Forums > News > Newsgroups > alt.computer.security
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 03-16-2007, 12:43 AM
a_monk
Guest
 
Posts: n/a
Default How to interpret this?!

Lately I received a number (phishing) mails from a bank asking for
confirmation. In the message, there was a URL:

https://www1.royalbank.com/cgi-bin/r...ntSign&LANG=EN

However, when I moved my mouse pointer to the beginning on the URL, at
the bottom of the screen, it showed the following instead.

http://163.23.70.201/http/www1.royal...tSign&LANG=EN/

First of all, the link seems not using SSL (http instead of https).
Secondly, when I pinged 163.23.70.201, there was no response.

I hesitate to click on the https:// link.

Could someone help me understand what is it all about? Any info is
much appreciated.

A Monk


Reply With Quote
  #2 (permalink)  
Old 03-16-2007, 01:34 AM
David H. Lipman
Guest
 
Posts: n/a
Default Re: How to interpret this?!

From: "a_monk" <dfox138@hotmail.com>

| Lately I received a number (phishing) mails from a bank asking for
| confirmation. In the message, there was a URL:
|
| https://www1.royalbank.com/cgi-bin/r...ntSign&LANG=EN
|
| However, when I moved my mouse pointer to the beginning on the URL, at
| the bottom of the screen, it showed the following instead.
|
| http://163.23.70.201/http/www1.royal...tSign&LANG=EN/
|
| First of all, the link seems not using SSL (http instead of https).
| Secondly, when I pinged 163.23.70.201, there was no response.
|
| I hesitate to click on the https:// link.
|
| Could someone help me understand what is it all about? Any info is
| much appreciated.
|
| A Monk

What part of Phishing don't you understand ?

The screen shows; https://www1.royalbank.com but the HTML really points to;
http://163.23.70.201

http://www.dnsstuff.com/tools/whois....0.201&email=on

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Reply With Quote
  #3 (permalink)  
Old 03-16-2007, 01:39 AM
a_monk
Guest
 
Posts: n/a
Default Re: How to interpret this?!

On Mar 15, 9:34 pm, "David H. Lipman" <DLipman~nosp...@Verizon.Net>
wrote:
> From: "a_monk" <dfox...@hotmail.com>
>
> | Lately I received a number (phishing) mails from a bank asking for
> | confirmation. In the message, there was a URL:
> |
> |https://www1.royalbank.com/cgi-bin/r...=1&F21=IB&F22=...
> |
> | However, when I moved my mouse pointer to the beginning on the URL, at
> | the bottom of the screen, it showed the following instead.
> |
> |http://163.23.70.201/http/www1.royal...access/F21=IB&...
> |
> | First of all, the link seems not using SSL (http instead of https).
> | Secondly, when I pinged 163.23.70.201, there was no response.
> |
> | I hesitate to click on the https:// link.
> |
> | Could someone help me understand what is it all about? Any info is
> | much appreciated.
> |
> | A Monk
>
> What part of Phishing don't you understand ?
>
> The screen shows; https://www1.royalbank.com but the HTML really points to;http://163.23.70.201
>
> http://www.dnsstuff.com/tools/whois....0.201&email=on
>
> --
> Davehttp://www.claymania.com/removal-trojan-adware.htmlhttp://www.ik-cs.com/got-a-virus.htm


What would happen if I clicked on the link?


Reply With Quote
  #4 (permalink)  
Old 03-16-2007, 01:44 AM
a_monk
Guest
 
Posts: n/a
Default Re: How to interpret this?!

On Mar 15, 9:39 pm, "a_monk" <dfox...@hotmail.com> wrote:
> On Mar 15, 9:34 pm, "David H. Lipman" <DLipman~nosp...@Verizon.Net>
> wrote:
>
>
>
>
>
> > From: "a_monk" <dfox...@hotmail.com>

>
> > | Lately I received a number (phishing) mails from a bank asking for
> > | confirmation. In the message, there was a URL:
> > |
> > |https://www1.royalbank.com/cgi-bin/r...=1&F21=IB&F22=...
> > |
> > | However, when I moved my mouse pointer to the beginning on the URL, at
> > | the bottom of the screen, it showed the following instead.
> > |
> > |http://163.23.70.201/http/www1.royal...access/F21=IB&...
> > |
> > | First of all, the link seems not using SSL (http instead of https).
> > | Secondly, when I pinged 163.23.70.201, there was no response.
> > |
> > | I hesitate to click on the https:// link.
> > |
> > | Could someone help me understand what is it all about? Any info is
> > | much appreciated.
> > |
> > | A Monk

>
> > What part of Phishing don't you understand ?

>
> > The screen shows; https://www1.royalbank.combut the HTML really points to;http://163.23.70.201

>
> >http://www.dnsstuff.com/tools/whois....0.201&email=on

>
> > --
> > Davehttp://www.claymania.com/removal-trojan-adware.htmlhttp://www.ik-cs.c...

>
> What would happen if I clicked on the link?- Hide quoted text -
>
> - Show quoted text -


Where could one report this crime?


Reply With Quote
  #5 (permalink)  
Old 03-16-2007, 02:07 AM
David H. Lipman
Guest
 
Posts: n/a
Default Re: How to interpret this?!

From: "a_monk" <dfox138@hotmail.com>


|
| Where could one report this crime?

http://www.antiphishing.org/report_phishing.html

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Reply With Quote
  #6 (permalink)  
Old 03-16-2007, 03:03 AM
Arthur T.
Guest
 
Posts: n/a
Default Re: How to interpret this?!

In
Message-ID:<1174005830.885994.262650@n76g2000hsh.googlegro ups.com>,
"a_monk" <dfox138@hotmail.com> wrote:

>Lately I received a number (phishing) mails from a bank asking for
>confirmation. In the message, there was a URL:

<snip>
>However, when I moved my mouse pointer to the beginning on the URL, at
>the bottom of the screen, it showed the following instead.

<snip>
>Could someone help me understand what is it all about? Any info is
>much appreciated.


This is standard HTML used for nefarious purposes.

I'll show an example, using parens instead of angle brackets
(in case you have a newsreader that renders HTML).

(a href="http://ACTUAL.URL")WHAT TO DISPLAY(/a)

In the above, an HTML-knowledgeable reader will show "WHAT TO
DISPLAY", but if you click on it, it'll take you to
"http://ACTUAL.URL". If "WHAT TO DISPLAY" *looks* like a URL,
it'll cause the confusion you experienced.

--
Arthur T. - ar23hur "at" intergate "dot" com
Looking for a z/OS (IBM mainframe) systems programmer position

Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
help me interpret MemTest86 results? David alt.comp.hardware 8 08-25-2005 04:52 PM


All times are GMT. The time now is 06:13 PM.


Powered by vBulletin® Version 3.7.1
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45