Rocksolid Light

Welcome to RetroBBS

mail  files  register  newsreader  groups  login

Message-ID:  

Elegance and truth are inversely related. -- Becker's Razor


computers / comp.mail.eudora.ms-windows / Related:: Why are these phishing addesses not valid?

SubjectAuthor
* Related:: Why are these phishing addesses not valid?micky
`* Re: Related:: Why are these phishing addesses not valid?Piet
 `- Re: Related:: Why are these phishing addesses not valid?micky

1
Related:: Why are these phishing addesses not valid?

<2ieiogd0o80rd9l85l0qpmiub5a2tl3fco@4ax.com>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=277&group=comp.mail.eudora.ms-windows#277

  copy link   Newsgroups: comp.mail.eudora.ms-windows
Path: i2pn2.org!i2pn.org!weretis.net!feeder6.news.weretis.net!4.us.feeder.erje.net!2.eu.feeder.erje.net!feeder.erje.net!feeder1.feed.usenet.farm!feed.usenet.farm!newsfeed.xs4all.nl!newsfeed7.news.xs4all.nl!news-out.netnews.com!news.alt.net!fdc2.netnews.com!peer03.ams1!peer.ams1.xlned.com!news.xlned.com!feeder.cambriumusenet.nl!feed.tweaknews.nl!posting.tweaknews.nl!fx13.ams1.POSTED!not-for-mail
From: NONONOmisc07@fmguy.com (micky)
Newsgroups: comp.mail.eudora.ms-windows
Subject: Related:: Why are these phishing addesses not valid?
Message-ID: <2ieiogd0o80rd9l85l0qpmiub5a2tl3fco@4ax.com>
X-Newsreader: Forte Agent 1.93/32.576 English (American)
MIME-Version: 1.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 8bit
Lines: 41
X-Complaints-To: abuse@tweaknews.nl
NNTP-Posting-Date: Mon, 08 Nov 2021 15:06:34 UTC
Organization: Tweaknews
Date: Mon, 08 Nov 2021 10:06:34 -0500
X-Received-Bytes: 1909
 by: micky - Mon, 8 Nov 2021 15:06 UTC

Related to email but not a specifically Eudora question:

Just got this email, the most recent of several from Peru that claims to
be in charge of my USA email account.

What gets me is the link they want me to use, http:/mail.rcn.commmm. I
put in 3 extra m's so no one would accidentally click on it.

So they left out a slash, was that on purpose?

But the question is..I thought if the middle node, rcn, was a a real
one, changing the first node to mail would still give a link that
belongs to www.rcn.com, which is the URL of one of my mail servers.

Also the To: line looks like it has a valid domain. ???

Would correcting and clicking on the zimbra link install a virus, or is
it just phishing?

From: "?© +RCN Telecom Services" <a20214996@pucp.edu.pe> [Peru!!!]
Date: Mon, 8 Nov 2021 19:00:45 +0530
Subject: Re: Very Important Information Regards Your RCN
To: cskrnc@rcn.commmm

Your incoming mails and documents have been placed on hold due to the
recent spam activities on our server.

we need you to verify your account before you can view the new emails
and documents. to verify kindly click on URL below and login.

http:/mail.rcn.commmm/zimbra

© 2021 RCN Telecom Services, LLC. All Rights Reserved.

Re: Related:: Why are these phishing addesses not valid?

<smhdvd$11a4$1@gioia.aioe.org>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=292&group=comp.mail.eudora.ms-windows#292

  copy link   Newsgroups: comp.mail.eudora.ms-windows
Path: i2pn2.org!i2pn.org!aioe.org!1PrD99jtqwebgL6o7l6uoA.user.46.165.242.75.POSTED!not-for-mail
From: www.godfatherof.nl/@opt-in.invalid (Piet)
Newsgroups: comp.mail.eudora.ms-windows
Subject: Re: Related:: Why are these phishing addesses not valid?
Date: Wed, 10 Nov 2021 22:35:42 +0100
Organization: Aioe.org NNTP Server
Message-ID: <smhdvd$11a4$1@gioia.aioe.org>
References: <2ieiogd0o80rd9l85l0qpmiub5a2tl3fco@4ax.com>
Mime-Version: 1.0
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: 7bit
Injection-Info: gioia.aioe.org; logging-data="34116"; posting-host="1PrD99jtqwebgL6o7l6uoA.user.gioia.aioe.org"; mail-complaints-to="abuse@aioe.org";
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:45.0) Gecko/20100101
Thunderbird/45.8.0
X-Notice: Filtered by postfilter v. 0.9.2
 by: Piet - Wed, 10 Nov 2021 21:35 UTC

micky wrote:
> Related to email but not a specifically Eudora question:
> Just got this email, the most recent of several from Peru that claims
> to be in charge of my USA email account.

Let them claim heaven and hell, and dump them into trash. Or make
a filter that does that for you before you even have a chance to
look at the message.

> What gets me is the link they want me to use, http:/mail.rcn.commmm.
> I put in 3 extra m's so no one would accidentally click on it.

You're a bit shortsighted. Had you hovered the cursor over that
would-be-url, you'd have noticed right away the real underlying
url *does* have two slashes. It's a very common way to lure people
to malware sites, but it's also commonly used by trusted companies
hide a url ("difficult" for the computer-ignorant) in the way it's
done on webpages.

> So they left out a slash, was that on purpose?

You bet! It draws attention, and out of curiosity people will click
on the "incorrect" link.

> Would correcting and clicking on the zimbra link install a virus,
> or is it just phishing?

Just click on it and you may be lost already.

-p

Re: Related:: Why are these phishing addesses not valid?

<25fqogdutuqmekd6v707io47ldfinr7reo@4ax.com>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=294&group=comp.mail.eudora.ms-windows#294

  copy link   Newsgroups: comp.mail.eudora.ms-windows
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!newsreader4.netcologne.de!news.netcologne.de!peer03.ams1!peer.ams1.xlned.com!news.xlned.com!feeder.cambriumusenet.nl!feed.tweaknews.nl!posting.tweaknews.nl!fx12.ams1.POSTED!not-for-mail
From: NONONOmisc07@fmguy.com (micky)
Newsgroups: comp.mail.eudora.ms-windows
Subject: Re: Related:: Why are these phishing addesses not valid?
Message-ID: <25fqogdutuqmekd6v707io47ldfinr7reo@4ax.com>
References: <2ieiogd0o80rd9l85l0qpmiub5a2tl3fco@4ax.com> <smhdvd$11a4$1@gioia.aioe.org>
X-Newsreader: Forte Agent 1.93/32.576 English (American)
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Lines: 42
X-Complaints-To: abuse@tweaknews.nl
NNTP-Posting-Date: Thu, 11 Nov 2021 16:12:15 UTC
Organization: Tweaknews
Date: Thu, 11 Nov 2021 11:12:15 -0500
X-Received-Bytes: 2188
 by: micky - Thu, 11 Nov 2021 16:12 UTC

In comp.mail.eudora.ms-windows, on Wed, 10 Nov 2021 22:35:42 +0100, Piet
<www.godfatherof.nl/@opt-in.invalid> wrote:

>micky wrote:
>> Related to email but not a specifically Eudora question:
>> Just got this email, the most recent of several from Peru that claims
>> to be in charge of my USA email account.
>
>Let them claim heaven and hell, and dump them into trash. Or make
>a filter that does that for you before you even have a chance to
>look at the message.
>
>> What gets me is the link they want me to use, http:/mail.rcn.commmm.
>> I put in 3 extra m's so no one would accidentally click on it.
>
>You're a bit shortsighted. Had you hovered the cursor over that
>would-be-url, you'd have noticed right away the real underlying

Ugh. I don't know why I didn't do that. I know about it. I'm trying
to find the email again in my inbox trash but can't find it yet.

>url *does* have two slashes. It's a very common way to lure people
>to malware sites, but it's also commonly used by trusted companies
>hide a url ("difficult" for the computer-ignorant) in the way it's
>done on webpages.
>
>> So they left out a slash, was that on purpose?
>
>You bet! It draws attention, and out of curiosity people will click
>on the "incorrect" link.

Aha.

>> Would correcting and clicking on the zimbra link install a virus,
>> or is it just phishing?
>
>Just click on it and you may be lost already.

Oh, no!

>-p

1
server_pubkey.txt

rocksolid light 0.9.8
clearnet tor