From: Ryan Pavlik Date: 2003-10-03T13:09:42+09:00 Subject: OT: scam tricks (Was: Account Verification) On Fri, 3 Oct 2003 12:49:10 +0900 Lyle Johnson wrote: > Mark Wilson wrote: > > > Who are you? Are you really eBay? > > If they are, maybe they should check to see if anyone is auctioning off > a dictionary since they misspelled "either" at the beginning of the > second sentence ;) It's pretty obviously a scam. Always check the _actual_ URL (split for readability): https://scgi.ebay.com/ saw-cgi/eBayISAPI.dll?V erifyInform ation It's a somewhat evil trick. Actually, three going on here. Note the scgi.ebay.com:blah@69.49.246.84... a common trick to "fake" a URL, using username:password@host syntax. Combine that with printing the fake URL as the text of the link for a sense of safety, as well as some Javascript to even fake the mouseover, and you might even convice a lot of people. Like you said, the obvious misspellings don't do a lot for credibility though, and spamassassin caught some other things in the headers. -- Ryan Pavlik "Well what was it, Mr. Nightmare Pants?" - 8BT