An Information Security Place

Commentary on the State of Information Security
Filed under Pre-Categories

One of my users recently sent me a Paypal phishing email. It is to her credit that she sent it to me. Since she uses Paypal for many things, this email worried her. Here is a picture of the email, with a little cut off from the bottom (click on the pictures for a better view):

The user asked me if this was legit. I knew it was not, but I wanted to look at the links, knowing that they would lead to some bogus site. What threw me at first is I found that the first link actually pointed to Paypal’s actual site. See below:

My first thought was, “Can this actually be legit?” Then I looked at the next link, and I saw that it pointed to an alternate site. See below:

This link is legit:

This one is bad:

And look at this disclaimer. Very nice:

I thought this was a very interesting email. I am sure this has been done before, but I haven’t looked as closely lately at these emails. This is a seriously dangerous email, especially since I had to take a second glance. I wonder how many people are going to fall for this one?

Vet

Posted by Michael Farnum on Friday, April 21st, 2006