Archive for the Security Category

I have a camera listed for sale on the Amazon Marketplace. A few days ago I had an e-mail from a potential buyer wanting more information on the camera. The details of this message is shown below;

Greetings from Amazon.co.uk.

A potential buyer has sent you the following message about an item you have for sale on Amazon.co.uk, or about your store at Amazon.co.uk. Please respond to the individual directly by replying to this e-mail. For your reference, the buyer’s e-mail address is charlesworth_04@keromail.com.

Item: Canon Digital IXUS 50 / Powershot SD400 / IXY Digital 55 Digital Camera [Electronics] [ASIN: B0007UB69W ]

Important Notice: Only dispatch to the address shown in your seller account. Do not honour buyer requests to dispatch orders to any address other than the one provided by Amazon.co.uk. Do not accept any payment method other than Amazon Payments. Payment for the sale may be withheld if these guidelines are not followed.
————– Begin message ———————
Dear Seller,

Am interesed in purcashing your item,i want to know if you still have this item in good condition and your final asking price.Kindly get back to me as soon as possible with a pic of the item and the present condition so that i can arrange for the payment through amazon as soon as possible..Thanks

Tom
————– End message ————————
Note: Amazon.co.uk may retain copies of all forwarded e-mails, and takes no responsibility and assumes no liability for the content of any messages forwarded to you.

Amazon.co.uk will never e-mail you and ask you to disclose or verify your Amazon.co.uk password, credit card or bank account details. If you receive a suspicious e-mail with a link to update your account information, do not click on the link–instead report the e-mail to Amazon.co.uk for investigation. Go to amazon.co.uk/phish to find out more.

The address this came from is commmgr-autoreply@amazon.co.uk, which for those paying attention is at the domain amazon.co.uk. The reply to address is the sellers own, but this is all standard. I did notice spelling mistakes, but in a genuine situation I allow for a few.

I replied with some more photos of the item and heard nothing for a few days. This morning I received another e-mail, supposedly from Amazon informing me the item had sold. Great I thought, until I read a little further into the e-mail below.

Dear markgilbert@gmail.com,

Congratulations! Your Amazon Marketplace item has been officially purchased.Funds in your Amazon Payments account are deposited directly into your bank account every 14 days. There is no need for you to do anything apart from post the item to the buyer. Here are the details of your completed Amazon Marketplace sale:

Order #: 20216011810391818
Item Count: 1
ASIN: B0007UB69W
Quantity: 1

You have agreed to ship the item not later than 1 to 2 business days and make sure you send us the Shipment Refrence Number as soon as you ship the item to buyer. This item will not be remove from Amazon.co.uk web-pages andthe FUNDS will not be TRANSFER into your Amazon account not until you postthe item. Here is your buyer\’s shipping address (use your own address as the return address, and enclose the packing slip in this e-mail for your buyer\’s reference):

Shipping Label
- - - - - - - - - - - - - - - - - - - - - - - - - –
PACKING SLIP:
Amazon Marketplace Item: Canon Digital IXUS 50 / Powershot SD400 / IXY Digital 55 Digital Camera [Electronics]
Quantity: 1

Shipping address:
—————————————————————–
Ship to: Mr Tunde Oluwatobi
Address Line 1: 29 Old Otta Rd Off Ekoro
Address Line 2: Abule-Egbe
City: Ipaja.
State/Province/Region:Lagos.
Zip/Postal Code: 23401
Country: Nigeria

Buyer \’s Name: Charles Tom
- - - - - - - - - - - - - - - - - -
Purchased by:
Name: Mr Charles Tom
Address: ***********
City: Merry Oak
State: Southampton
Zip Code: ***********
Country: United Kingdom
- - - - - - - - - - - - - - - - - - - - - - - - - -
Amazon Buyer\’s e-mail: charlesworth_04@keromail.com
Amazon Seller\’s email: markgilbert@gmail.com
Time of sale: 25-Aug-2008
Shipping speed: standard shipping
Buyer\’s Price: £136.09(GBP)
Amazon commission:(£9.90GBP)
Additional shipping credit: £66.00GBP
- - - - - - - - - - - - - - - - - - - - - - - - - - -
Your earnings (in your Payments account) £245.01(GBP)
Note: Amazon.co.uk is crediting you£66.00 GBP in addition to your net
sales price to help cover shipping costs. This amount is adequate to cover
standard shipment of most items. You are required to ship this item evenin cases that
the shipping credit does not fully cover your shipping costs.

ABOUT YOUR PAYMENT:
If you haven\’t already provided us with your checking account information,please do so at your earliest convenience. Amazon Payments CANNOT DISBURSE funds to you until you provide routing information for your checking account. Deposits to your bank account take at least 14 business days, excluding bank holidays. Any transfers that are returned to Amazon.co.uk from your bank will be investigated. If 14 or more business days have passed and you have not received your deposit, please contact your bank if you still have difficulties. If you didn\’t provide your bank account information when you registered, please do so now by clicking here:

http:s1.amazon.co.uk/exec/varzea/subst/your-account/seller-account-payments.html

The links above will tell you everything you need to know to become a first-rate seller on Amazon.co.uk.

Your Shipping and Refunds: Sellers agree to ship within 1 to 2 business days of purchase. Failure to ship immediately is grounds for negative seller feedback, revocation of shipping credits, and even suspension of a sellers account. If you cannot provide the item you sold, you can issue a full refund by

completingthe following Steps:

1. Go to your Seller Account.
2. Click on the Amazon Payments account and billing history link.
3. Click on the Search your Payments transactions link. When prompted,
sign in using your e-mail and password.
4. After signing in, input your search parameters and click the Searchbutton.
5. From the resulting list of transactions, click the transaction or order ID that you want to refund.
6. Scroll to the body of the Transaction Details page and click Refund link.You can include a short memo explaining the reason for the refund in the Memo to Buyer box.
7. After you enter your information, click the *Refund* button. We will
e-mail this information to the buyer as soon as the refund is processed successfully.
***************************************************************
Security and Spamming
Amazon.co.uk sends you an e-mail whenever you list or sell an item. Many ISPs and private e-mail accounts use aggressive spam filters that inadvertently block some of our e-mails before they reach your inbox. Be sure to add the domain \”Amazon.co.uk\” to your safe list in your e-mail program/spam filter.
****************************************************************
–Got more questions? You\’ll find answers about selling on Amazon.co.uk
at:www.amazon.co.uk/make-money -Cant find the answer to your question on our website? Got a suggestion for us? Contact Amazon.co.uk customer service at:(amazon.co.uk_management@consultant.com).

NB: Kindly go and make the shipment via Royal Mail to the shipping address provided for you above, failure to ship out the item within 1-2 Business Days, your Amazon account will be DE-ACTIVATEDand SUSPENDED. Mail the shipment tracking number to Amazon.co.uk customer service at(amazon.co.uk_management@consultant.com) in order for the FUNDS to be Transfer into your Amazon Account. The item will not be remove from Amazon.co.uk and the FUNDS will not be TRANSFER to your Amazon Account not until you make the shipment for the item. We wish you the best of luck selling atAmazon.co.uk.

Warnest regards,
Amazon.co.uk–Amazon Services Europe SARL Sell Your Stuff
http: www.amazon.co.uk/marketplace NOTE: (This message was sent to you by an automated e-mail system. Please dont reply to it.)

Note that the e-mail this was sent from was amazon.co.uk_management@consultant.com and the reply to address was the same. I have posted the mail verbatim with the exception of taking the UK post code and street address out, and the number of things wrong with this are numerous.

The delivery address is in Nigeria, and the e-mail mentions twice that I will not get paid until I have shipped the item out and mailed them the tracking number at their consultant.com domain e-mail address. For those who don’t know this is not standard Amazon marketplace practice, you get paid when the item sells, not on shipment. The price they say they have bought at is not the price the camera is listed at. They also say that the sale will not show on Amazon and the item will not be removed from my listings until I have posted the item out. The e-mail contains spelling mistakes, it is missing spaces in places, there are back slashes all over the place. In all honesty it stinks.

Then this next mail arrived, which really was the final nail in the coffin.

Hello Mark,

How are you doing today? thanks for your reply…well i would like to inform you now that i have made the payment via amazon today and they let me know that you are going to recieve the confirmation letter so as soon as you recieve the payment confirmation from amazon i will urge you to dispatch the item immediately Royalmail and get back to me with the shippment tracking number as soon as possible, Thanks

Regards
Tom

This mail is purporting to be direct from the buyer based in Southampton, again more spelling mistakes and not a single full stop. This all seems wrong and I can only conclude one of three theories.

First that “Tom” is a fictional buyer created by people perpetrating the scam.
Second, Tom has had his machine taken over by some kind of spyware, or his e-mail account has been hi-jacked.
Third that there really is a Tom and he is working with the scammers.

I should also add that the item is still listed by Amazon, it is still listed an hour after the item supposedly sold.

Cheers

The malicious widget, named “Secret Crush” will first popup as a request when one of their friends has started using the widget, and asks if you would like more information. On clicking the widget installs and before you are allowed to use it you must invite 5 friends.

So far this all seems fairly normal, not all that different from any other facebook widget. It is after this that things turn nasty, no information on who your secret crush is or could be has been reveled up to this point, since finding out who this person is will have been the goal of installing the widget in the first place then users will inevitably have come this far.

The user is next presented with frame asking the user to download and install software that purports to reveal who the person with the crush is, however instead it links to Zango, the spyware application.

Lovely

Yesterday Google purged it’s search index of reportedly over 40,000 links to sites containing malware. Over the last few months Sunbelt, the company that produces the Counterspy application, have been tracking the sites and the SEO techniques these sites have been using to get themselves to the top of the Google ranks.

There is some nice dissection of the malware links over at the Sunbelt blog.

The SEO side of things was done using a bot net to post thousands upon thousands of link in forums and comment systems to the dodgy sites in question, which is what nailed them the top Google ranks.

The malware at the heart of it all is called “Scam.Iwin” by Sunbelt, which turns infected PCs into zombie units to join the bot net and post all the needed links to crack the Google Page Rank algorithm.

So let this be a lesson to all of you, keep your machines patched and anti-virus software updated on a regular basis. Personally for Windows users I would have to recommend Kaspersky Internet Secuirty, it really seems like the best product going. High detection and removal rates, and I speak from experience when talking about it, I’ve used it at work on machines and it is leagues ahead of Norton or McAfee.

Cheers

Google is currently in the process of acquiring a small Silicon Valley startup called GreenBorder which helps protect users against malware.

This coupled with the fact that Google recently started a blog devoted to online security suggests Google may be looking to move into the computer security territory more commonly occupied by the likes of Symantec and McAfee.GreenBorder works by integrating with IE and Firefox and isolates web content in a Sandbox area that can have malware flushed out like temporary files or can be cleared when the browser session ends.Whether Google simply plans to extend on it’s current feature of warning users when they may be about to view a site on which malware is known to reside, or integrate it into their Google Desktop offering remains to be seen.Cheers

Bad Behavior has blocked 105 access attempts in the last 7 days.