Page 1 of 1

Received A Password Change EMail

Posted: Wed Sep 16, 2009 3:30 pm
by firstbassman
Hey Peter.

Just thought I'd let you know.
I assume it was a Phishing message.

Thanks, - Mark

Re: Received A Password Change EMail

Posted: Wed Sep 16, 2009 3:56 pm
by admin
Mark: Thanks for this information. Do you have a copy of this and if so would you mind emailing it to me at [email protected]

Re: Received A Password Change EMail

Posted: Wed Sep 16, 2009 6:38 pm
by beatlefreak
Don't forget to include the full header to the email.

Re: Received A Password Change EMail

Posted: Thu Sep 17, 2009 5:16 pm
by firstbassman
Yup, will try to do so this weekend.

I know how to get the header in Outlook.

Will have to check how to do so with Yahoo Mail.

Re: Received A Password Change EMail

Posted: Thu Sep 17, 2009 7:47 pm
by doctorwho
firstbassman wrote:Yup, will try to do so this weekend.

I know how to get the header in Outlook.

Will have to check how to do so with Yahoo Mail.
Mark, I can already tell you how you'll have to do it in Yahoo mail, as I've had to fight their system when complaining about spam.

1. Display the message.

2. Scroll to the bottom of the message. In the lower right corner, click on the user-unfriendly "Full Headers" link.
YahooSpamExample.jpg
YahooSpamExample.jpg (7.82 KiB) Viewed 1784 times
3. The e-mail will now be displayed with full headers.

3. DO NOT CLICK ON FORWARD, because, for reasons known only to Yahoo and the Dark Lord it worships, forwarding removes the full headers (and there is no way to forward a message with full headers as far as I can figure out :twisted: :?: :roll: :twisted: ).

Instead, left-click-drag from the "X-Apparently-To' in the message through the entire message and copy/paste that to Notepad or some other text editor.
YahooSpam2.jpg
4. In the message, position the cursor over the link and see whether the displayed link in the lower left of the screen matches the printed link:
YahooSpam3.jpg
If they don't match (I'm guessing they won't), it means that the spammer has fraudulently disguised the link. To copy the actual link (not just the printed text), place the cursor over the printed link, right click on it, and select Copy Link Location from the menu displayed. Go to the copied message in Notepad (or whatever text editor you used) , place the cursor below the printed link in the message (make an extra line/space if needed), and paste the actual link below it. This is important because Peter will need to know where the illegal "login" page is actually located (it probably will be different from the ISP from which the e-mail was sent).

5. In Notepad (or whatever text editor you used), copy the entire message and paste it into a PM or new e-mail to Peter.

Throw the book at them, Peter!

Re: Received A Password Change EMail

Posted: Thu Oct 15, 2009 5:27 pm
by firstbassman
Peter,

Sent to you as a PM.

- Mark

Re: Received A Password Change EMail

Posted: Fri Oct 16, 2009 7:17 am
by admin
Thanks, Mark. We will review this.