My name is Paul Bissex, and e-scribe.com is my consulting business. I build web applications using as much open source software as possible. From September to June I teach web design and other important non-photographic professional skills to photographers. In the '90s I wrote technology commentary and reviews for magazines, newspapers, and web publications, including Wired, Salon.com, FamilyPC, the late lamented Web Review, and the Chicago Tribune. Feel free to email me.
This runs on Django, served by Apache and mod_python. The database is SQLite. The operating system is FreeBSD, on a VPS hosted at Johncompanies.com. Comment-spam protection by Akismet. Vintage topo imagery from the Maptech archive. The markup engine is Markdown.
I'm co-author of "Python Web Development with Django", an excellent guide to my favorite web framework. Published by Addison-Wesley in October 2008, it is available from Amazon and your favorite technical bookstore as well. Click on the book title above to learn more.
Akismet, del.icio.us, Django, dpaste.com, Emacs, FreeBSD, Freenode, jQuery, LaunchBar, MacPorts, Markdown, Mercurial, OS X, Postfix, Python, SQLite, Subversion, TextMate, Trac, Ubuntu Linux, wmii
At least 45602 pieces of comment spam killed since January 12th, mostly via Akismet.
A lot of eBay phishing scams take you to websites that not only mimic the look of the site they're impersonating, but actually contain live links to that site and even use images hosted there.
I just got one today: an email with the ironic subject line of "eBay Fraud Mediation Request." I always take a look at these to see if the scammers have any new tricks. I even click on the links (being a Mac user emboldens me there). This one took me to a site called www.signin-e-bay.com (I'm omitting the full link that takes you to the scam pages). The page was full of links to real eBay pages and used images hosted on eBay servers.
(Sub-rant: why does a company like eBay use a domain like ebaystatic.com? That's an actual eBay domain used for image hosting. This scam page included images hosted there. You've got to imagine that this makes eBay's anti-fraud education efforts harder. Does signin-e-bay.com look more suspcious than ebaystatic.com? Not to me. Why not static.ebay.com? When I see this kind of thing all I can think is that a company has grown so large and balkanized that it's easier for departments to register entirely new domain names than it is for them to get authorization from above to add a third-level name to the main domain. End sub-rant.)
Here are two things that eBay could be doing right now to foil this scam operation (I'm assuming they know about it; I reported it and I assume many other people have as well.) They are not rocket science. I'm not pretending to have invented anything here -- this is webservers 101. I might be missing some reason why they can't do this, but it's certainly stuff that I would do if my server were being impersonated like this. But eBay gets a little more traffic than I do.
Anyway:
Why not check referrers on all incoming page requests and redirect people who are coming from signin-e-bay.com to a page with a giant notice saying WELCOME TO EBAY! YOU HAVE ARRIVED FROM A KNOWN SCAM SITE. Admittedly the next step is more difficult, since at this point the visitor will probably be pretty suspicious of everybody and might just quit their browser and go have a beer. At least they'll be keeping out of trouble.
Why not check referrers on all image requests and return giant red "SCAM" badges when the referrer is on the (ever-evolving) scam site list? People have been doing this successfully for a long time. Again, the user may just be confused and close their browser, but at least they haven't given their login info to a malicious third party.
Maybe this is all moot, and they actually do this stuff now, and I'm just not seeing it because the whole mailing is only thirty minutes old. I'd love to be wrong here. But somehow I doubt that I am. Can anybody enlighten me as to why eBay doesn't use measures like these? What am I missing?
Richard, I'd go to eBay's Security Center to report your problem.
Hi, I have recently had a lot of buying activity on a downloadable product that hasn't really being selling. All of the buyers have an email address ending in 126.com and so far none of them have paid for the item All of the items were sold within an hour of each other on the 21st of september. I'm not quite sure how this would be a scam but it certainly smacks of one. Has anybody come accross this before or do you know what they are trying to acheive ??
Comments use Markdown syntax. Your comment will not appear until approved, which may take a few hours or more. Spammers will be torpedoed.
Programming and Ice Cream
4 comments
Back in Action
11 comments
The iPhone keyboard doesn't suck
2 comments
akahn
Programming and Ice Cream
9 days ago
Joe Brandt
Programming and Ice Cream
9 days ago
sharon fisher
Programming and Ice Cream
9 days ago
Max
Let's play a game: BASIC vs. Ruby vs. Python vs. PHP
11 days ago
mzee.richo
World's ugliest Django app
22 days ago
Banibrata Dutta
Python one-liner of the day
24 days ago
Gour
Back in Action
42 days ago
Copyright 2008
by Paul Bissex
and E-Scribe New Media
i would like to complain about a phone call i received today from a caller who wanted my e-bay acct # i have his phone # in my phone,he was very aggressive.but i need to know who to report this to.i don't want it to happen again