Wednesday, December 21, 2005

Note to Ebay: You're not Helping

I've been doing some of my Xmas shopping on Ebay, despite the fact that I'm involved in anti-phishing and counter-fraud. Today, I got an HTML message from Ebay about some update to my User Agreement.

Ebay/Paypal is the number one target for phishing by a huge margin; just look at FraudWatch International's statistics. Yet despite this, all the links in this real message come in the format of:

http://click3.ebay.com/4381902.85438.0.0.http%3A%2F
%2Fpages.ebay.com%2Fhelp%2Fpolicies%2Fprivacy-policy.html

Phishers, of course, now have a template for inserting a redirect using Ebay's own site:

http://click3.ebay.com/1.2.0.0.http%3A%2F
%2Fwww.planb-security.net%2f

So, Ebay, just so you know: You're not helping by handing over a perfectly useful page redirector to phishers who are targeting your OWN brand.

0 Comments:

Post a Comment

Links to this post:

Create a Link

<< Home