Teach an idiot to phish, and he starves.



  • Received the following email to: webmaster@wtfu.edu 

     

     This is a WebNews Email Account Update
    Please see the bottom of this mailing on this information.
    -------------------------------------------------------------------------------------------------THE
    WTFU.EDU WEBSITE WISH TO INFORM YOU THAT WE HAVE SOME PROBLEMS ABOUT EACH CUSTOMER ACCOUNT EMAIL. DUE TO ERROR CODE 334409. WE DISCOVER THAT IN SOME FEW HOURS FROM NOW EACH CUSTOMER WILL NOT BE ABLE TO ACCESS HIS OR HER EMAIL ACCOUNT SO YOU ARE REQUIRE TO SEND YOUR FULL EMAIL ADDRESS AND PASSWORD FOR A NEW ACCOUNT UPDATE.SO YOU HAVE TO SEND THIS INFORMATION IMMEDIATELY SO THAT WE WILL UPDATE YOUR ACCOUNT AND YOU WILL STOP RECEIVING SPAM EMAILS YOU ARE TO SEND US THE INFORMATION TO ENABLE US TO UPDATE YOUR ACCOUNT

    BELOW THE INFORMATION RQRUIRE FOR ACCOUT UPDATE

    1)Full Email Address:
    2)password:
    3)age/country
    4)date
    5)First name/Last name.
    ©2008 Citrix online. All Rights Reserved. Under License by wtfu.edu


    Standard bad grammar phishing, right?

     

    Except that the 'From:' was an obviously spoofed 'webmaster@wtfstate.edu' so even if I were dumb as a stump, there's no place for me to send my password to. 



  • Darwin was right - the weak (and apparrently stupid) should be culled from the herd.

     



  •  I'm sure it'll fool 80% of people.



  • @alunharford said:

     I'm sure it'll fool 80% of people.

     

    As the OP says, if they reply to it and it goes nowhere, then who cares?



  • @wk633 said:

    SO YOU HAVE TO SEND THIS INFORMATION IMMEDIATELY SO THAT WE WILL UPDATE YOUR ACCOUNT AND YOU WILL STOP RECEIVING SPAM EMAILS
     

    Legitimate businesses always threaten to spam their customers...

    Great post!

    http://consumerist.com/368374/any-joe-sixpack-can-be-a-phisher


  • @wk633 said:

    Except that the 'From:' was an obviously spoofed 'webmaster@wtfstate.edu' so even if I were dumb as a stump, there's no place for me to send my password to.

    What if there was a "Reply-to" or "Return-Path" or whatever-it's-called field?


  • @wk633 said:

    Except that the 'From:' was an obviously spoofed 'webmaster@wtfstate.edu' so even if I were dumb as a stump, there's no place for me to send my password to. 

     

     

    Are you sure there wasn't a valid "Reply-To:'?



  • So I just told my boss that I'm leaving to take another job and he's trying to keep me around with all these scary stories about the economy, etc.  But I know that even if I don't make it in my new job, I'll have a fallback grammar-checking phishing emails.  I mean, I know phishing victims are generally idiots, but at least some of them have to be able to see the red flags in an email like that.  I could make good profit either teaching these guys English or just writing their scam lines for them.



  • @wk633 said:

    Except that the 'From:' was an obviously spoofed 'webmaster@wtfstate.edu' so even if I were dumb as a stump, there's no place for me to send my password to.

    But the "to" was webmaster@wtfu.edu.  Some sort of inter-scool rivalry?



  • My Dumb.  There is a Reply-To:

     

    web.info@y7mail.com

     

    Wonder if I'll starve... 



  • The real WTF is that they didn't also ask for mother's maiden name, where you were born, favourite colour and name of first pet.



  • Anyone else [url=http://www.google.com/search?q=error+334409&ie=utf-8&oe=utf-8&aq=t&rls=org.mozilla:en-US:official&client=firefox-a]Google for Error 334409[/url]?

     



  • @medialint said:

    Anyone else Google for Error 334409?

     

    In the words of Borat: "Very Nice!"

    Regarding the phishers who buy phishing software... Do they REALLY think theres honor amongst theves? If you join a gang don't think that they won't screw you over... Hey big tony, can you store my bank account info in a safe place?



  • But the question is, what does Keyboard: latin chr doesn't work in a winform textbox have to do with any of this?



  •  @OP said:

    WTFU.EDU WEBSITE WISH TO INFORM YOU THAT WE HAVE SOME PROBLEMS ABOUT EACH CUSTOMER ACCOUNT EMAIL.

     @Kyanar said:

    But the question is, what does Keyboard: latin chr doesn't work in a winform textbox have to do with any of this?

    <sarcasm>Perhaps somebody typed ü into a winforms box and the umlaut ate their hypothetical customer table?</sarcasm>



  • @wk633 said:

    ©2008 Citrix online. All Rights Reserved. Under License by wtfu.edu
     

    This line's odd - I like Citrix (been working with their stuff a long time) and just wondered how this got in there?

    (No I don't work for Citrix)


Log in to reply