//flex table opened by JP

Click to See Complete Forum and Search --> : URGENT: AOL security alert


Gomer
10-17-2000, 10:50 PM
my mother received this mail....

X-AOL-DATE: Tue, 17 Oct 2000 9:53:55 PM Eastern Daylight Time
Return-Path: <AOLNetMailCenter@aol.com>
Received: from rly-yc01.mx.aol.com (rly-yc01.mail.aol.com [172.18.149.33])
by air-yc02.mail.aol.com (v76_r1.8) with ESMTP; Tue, 17 Oct 2000 21:53:55
-0400
Received: from falcon.prod.itd.earthlink.net (falcon.prod.itd.earthlink.net
[207.217.120.74]) by rly-yc01.mx.aol.com (v76_r1.19) with ESMTP; Tue, 17 Oct
2000 21:53:15 -0400
Received: from aol.com (dialup-209.244.181.216.NewYork2.Level3.net
[209.244.181.216])
by falcon.prod.itd.earthlink.net (EL-8_9_3_3/8.9.3) with SMTP id
SAA15252;
Tue, 17 Oct 2000 18:52:53 -0700 (PDT)
Date: Tue, 17 Oct 2000 18:52:53 -0700 (PDT)
From: AOLNetMailCenter@aol.com
Message-Id: <200010180152.SAA15252@falcon.prod.itd.earthlink.n et>
subject: You now currently have important unread message in your Inbox.

Dear Member,

I would like to inform you that you have important unread message in your
Secure - <a href="http://aol.netmail.cl.secure.login.20m.com/login.html">AOL
MailBox</a>. Many times messages are sent to AOL Mail due to confidentiality,
privacy, or urgency. *Please check and read that message, it is about your CL
status. If the message is not read within the next the next 24 hours, it will
be automatically deleted.

Please check your AOL NetMail: <a
href="http://aol.netmail.cl.secure.login.20m.com/login.html">AOL NetMail
2.0</a>

AOL NetMail 2.0 Features:

· Access AOL NetMail from work or school
· Access AOL NetMail while traveling
· Read and send NetMail easily from the Web
· Wide compatibility
· Benefits of "AOL Anywhere"
· Secure encrypted login

Thank You,
Community Netmail Team.
AOL NetMail 2.0
America Online, Inc.


DO NOT ENTER ANY INFO INTO THE LINK IN THE BODY OF THE MAIL IF YOU USE AOL AND RECEIVE IT!!!
http://aol.netmail.cl.secure.login.20m.com/login.html DO NOT ENTER ANY INFO

this site is a mirror image of the site http://aolmail.aol.com

what the rogue site does is logs your username and password. It then goes through http://aolmail.aol.com and actually logs you into your aol mail account. The unsuspecting person has no idea of what just went down. It is a very smooth operation. If you dont enter a user name or password it redirects you to aol's terms of service page. This differs from the real aol mail page as the real page will give you an error message.

again http://aol.netmail.cl.secure.login.20m.com/login.html is bogus
http://aolmail.aol.com is legit

Take a look at both sites but if you are an aol member do not enter info into the first site. I am really impressed and imagine that many who get this mail will be taken by it. Surf Safely

Gomer

Mntsnow
10-17-2000, 11:11 PM
LOL

It's supposed to be secure access but the site you are going to is a standard http site instead of a https site.

Also just look at all the headers in the email

Gomer
10-17-2000, 11:21 PM
I know better.... my ma, and many other users do not. Luckily my ma IM'ed me and asked me what I thought of it. I told her not to do anything with it and she told me it listed her mail for her. I told her to immediately change her password and relog so we should be fine. The actual address of the rogue site looks almost legitimate. Many naive users will be taken. I didn't expect aol users here to be taken but I am sure they have friends on aol who possibly could. I was impressed by the thiefs ingenuity.

Beemers
10-18-2000, 05:52 PM
You know! I just looked over my addressbook and I don't associate with any AOL users according to the addresses.

If you guys & gals out there have any contacts that use aol mail, send them this thread.

Cheers!

danb4
10-19-2000, 12:17 AM
Wow...you're right Gomer...that's pretty slick. The goal obviously isn't to outwit the cleverest person out there...it's just to outwit an AOL user...(hehe...couldn't resist).

Seriously though....I am impressed. I suspect that whoever came up with that one is going to have a bunch of AOL user account passwords.