Register Guidelines E-Books Today's Posts Search

Go Back   MobileRead Forums > E-Book General > General Discussions

Notices

Reply
 
Thread Tools Search this Thread
Old 11-04-2010, 05:33 AM   #1
Tomsk
Womble
Tomsk ought to be getting tired of karma fortunes by now.Tomsk ought to be getting tired of karma fortunes by now.Tomsk ought to be getting tired of karma fortunes by now.Tomsk ought to be getting tired of karma fortunes by now.Tomsk ought to be getting tired of karma fortunes by now.Tomsk ought to be getting tired of karma fortunes by now.Tomsk ought to be getting tired of karma fortunes by now.Tomsk ought to be getting tired of karma fortunes by now.Tomsk ought to be getting tired of karma fortunes by now.Tomsk ought to be getting tired of karma fortunes by now.Tomsk ought to be getting tired of karma fortunes by now.
 
Tomsk's Avatar
 
Posts: 120
Karma: 4505298
Join Date: Nov 2009
Location: Manchester, UK
Device: KFHDX8.9, Fujitsu S1300, Voyage, K7
mybebook.com spam/phishing/trojan email

Firstly I'm confident that this email did NOT come from mybebook.com.

It's a typical spam/phishing/trojan/virus email. The link to download the bill will download a file called 'bill.exe', which undoubtedly contains a trojan/virus of some sort.

image of email


I'm guessing that they may have found my email from this forum, so I'm posting this to alert less tech savvy ereader users to be on the lookout.
Tomsk is offline   Reply With Quote
Old 11-04-2010, 05:38 AM   #2
t-town
Connoisseur
t-town began at the beginning.
 
t-town's Avatar
 
Posts: 69
Karma: 10
Join Date: Sep 2009
Device: Kindle
Yes, I had it too.
Please do not download the bill.exe file!!!
t-town is offline   Reply With Quote
Old 11-04-2010, 07:35 AM   #3
Freeshadow
temp. out of service
Freeshadow ought to be getting tired of karma fortunes by now.Freeshadow ought to be getting tired of karma fortunes by now.Freeshadow ought to be getting tired of karma fortunes by now.Freeshadow ought to be getting tired of karma fortunes by now.Freeshadow ought to be getting tired of karma fortunes by now.Freeshadow ought to be getting tired of karma fortunes by now.Freeshadow ought to be getting tired of karma fortunes by now.Freeshadow ought to be getting tired of karma fortunes by now.Freeshadow ought to be getting tired of karma fortunes by now.Freeshadow ought to be getting tired of karma fortunes by now.Freeshadow ought to be getting tired of karma fortunes by now.
 
Posts: 2,792
Karma: 24285242
Join Date: May 2010
Location: Duisburg (DE)
Device: PB 623
I know it's a stupid question but...
have you alerted the bebook ppl about this?
Freeshadow is offline   Reply With Quote
Old 11-04-2010, 07:39 AM   #4
Nexutix
Reading and reading
Nexutix ought to be getting tired of karma fortunes by now.Nexutix ought to be getting tired of karma fortunes by now.Nexutix ought to be getting tired of karma fortunes by now.Nexutix ought to be getting tired of karma fortunes by now.Nexutix ought to be getting tired of karma fortunes by now.Nexutix ought to be getting tired of karma fortunes by now.Nexutix ought to be getting tired of karma fortunes by now.Nexutix ought to be getting tired of karma fortunes by now.Nexutix ought to be getting tired of karma fortunes by now.Nexutix ought to be getting tired of karma fortunes by now.Nexutix ought to be getting tired of karma fortunes by now.
 
Nexutix's Avatar
 
Posts: 582
Karma: 8250144
Join Date: Oct 2010
Device: Infibeam Pi, iPod Touch 4G, iPad Air 2, iPad mini 2, Oneplus One
Angry Me tooo!!!!!

Me too. I added a comment on virus total. Paste the url and see results. It is detected as malware by 16% antiviruses. How could Bebook leak emails? You also had an account at bebook?



And observe that everyone has recieved same Order number, plus bad grammar, non-professional lay-out. I detected it at first sight.
Attached Thumbnails
Click image for larger version

Name:	Capture.PNG
Views:	245
Size:	97.0 KB
ID:	60629  

Last edited by Nexutix; 11-04-2010 at 07:43 AM.
Nexutix is offline   Reply With Quote
Old 11-04-2010, 07:42 AM   #5
Magnesus
Connoisseur
Magnesus is on a distinguished road
 
Posts: 98
Karma: 58
Join Date: Apr 2010
Device: Bebook Neo
I hope at least the passwords were hashed in the database... I got the same e-mail. It landed in spam folder anyway.
Magnesus is offline   Reply With Quote
Old 11-04-2010, 09:51 AM   #6
Worldwalker
Curmudgeon
Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.
 
Posts: 3,085
Karma: 722357
Join Date: Feb 2010
Device: PRS-505
I use unique email addresses for everyone I do business with. Not only does it spot spammers, but it makes filtering a snap. While this might be more work than some people want to go through, you should at least consider having a few: one for family and friends, one for forums, one for business emails, etc. Buying your own domain name is trivial at this point, and you can just alias all the incoming addresses into one if you prefer it that way. That makes it possible to keep secure email addresses protected from random spammers, as well as making it obvious where the spam is coming from.

As an example, a forum leaked. A spammer got their email addresses. I know because I've gotten spam at that address warning me my account is about to be deleted from a game I've never played. Yeah, they're reaching. But I know who's spamming that and more or less why, whereas if it was showing up on a general-purpose address, I wouldn't have a clue.

As for how any given company could leak email addresses: They might not have done it at all (see the game "threats" above). They might have done it deliberately (the Southern California BBB once gave an address used only with them to a spammer I complained about -- one who was bragging about his BBB membership). Users might have put their email addresses somewhere visible from the Web. A legitimate website or entire system could have been cracked: see T.J. Maxx. Or someone could be selling addresses out the back door -- back in the day, Earthlink had someone doing that. Without knowing where they got the address, you can only take wild guesses.

That's where your second layer of defense comes in. You don't use Outlook. You don't open strange .exe files. You turn off "hide extensions for known file types" so you know if they're .exe files or not -- spammers are smart enough to send out picture.jpg.exe. You know what you expect to get, and get suspicious when something unexpected shows up. You know how to read headers. You have a virus scanner watching your email. And, of course, you let the right people know -- likely targets and the purported source. Believe it or not, there are companies who don't find out someone is phishing as them for days, because everyone says "oh, someone else probably told them" and nobody does, so by the time they find out and try to do something, the phisher is long gone.
Worldwalker is offline   Reply With Quote
Old 11-04-2010, 01:54 PM   #7
imaredr
Collector
imaredr ought to be getting tired of karma fortunes by now.imaredr ought to be getting tired of karma fortunes by now.imaredr ought to be getting tired of karma fortunes by now.imaredr ought to be getting tired of karma fortunes by now.imaredr ought to be getting tired of karma fortunes by now.imaredr ought to be getting tired of karma fortunes by now.imaredr ought to be getting tired of karma fortunes by now.imaredr ought to be getting tired of karma fortunes by now.imaredr ought to be getting tired of karma fortunes by now.imaredr ought to be getting tired of karma fortunes by now.imaredr ought to be getting tired of karma fortunes by now.
 
imaredr's Avatar
 
Posts: 440
Karma: 1002238
Join Date: May 2005
Location: Harker Heights, Texas
Device: Cybook
So I see I wasn't the only one that got this. I figured that something was wrong and deleted the email. Has Bebook responded to this problem?
imaredr is offline   Reply With Quote
Old 11-04-2010, 03:02 PM   #8
frozennorth
Evangelist
frozennorth has a certain pleonastic somethingfrozennorth has a certain pleonastic somethingfrozennorth has a certain pleonastic somethingfrozennorth has a certain pleonastic somethingfrozennorth has a certain pleonastic somethingfrozennorth has a certain pleonastic somethingfrozennorth has a certain pleonastic somethingfrozennorth has a certain pleonastic somethingfrozennorth has a certain pleonastic somethingfrozennorth has a certain pleonastic somethingfrozennorth has a certain pleonastic something
 
frozennorth's Avatar
 
Posts: 407
Karma: 18772
Join Date: Mar 2009
Location: Alberta, Canada
Device: Onyx Boox RIP, Sony PRS-T1, Kobo Libra
I got the same one and same order number. When I hovered the mouse over the download link it shows:

"http://jackecruise.fileave.com/Bill.exe"
Strange file name if it had been from bebook.
frozennorth is offline   Reply With Quote
Old 11-04-2010, 03:20 PM   #9
Worldwalker
Curmudgeon
Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.
 
Posts: 3,085
Karma: 722357
Join Date: Feb 2010
Device: PRS-505
Quote:
Originally Posted by imaredr View Post
So I see I wasn't the only one that got this. I figured that something was wrong and deleted the email. Has Bebook responded to this problem?
There's not a whole lot Bebook can do. I could send out spam appearing to be from you, for instance (it's called a "Joe job") and the most you could do would be say "no, that's not me." At least, assuming I was smart enough that it couldn't be traced to me, which the scumsuckers are. I get phishing attempts regularly that are supposedly about Aion accounts, but they're really from a random collection of zombie computers (this is why you need to learn to read headers, btw) and never went near SquareSoft. They can say "nope, not us" but as far as doing anything about it, they're no better off than I am except for being bigger. And, of course, playing Aion.
Worldwalker is offline   Reply With Quote
Old 11-04-2010, 04:53 PM   #10
pholy
Booklegger
pholy ought to be getting tired of karma fortunes by now.pholy ought to be getting tired of karma fortunes by now.pholy ought to be getting tired of karma fortunes by now.pholy ought to be getting tired of karma fortunes by now.pholy ought to be getting tired of karma fortunes by now.pholy ought to be getting tired of karma fortunes by now.pholy ought to be getting tired of karma fortunes by now.pholy ought to be getting tired of karma fortunes by now.pholy ought to be getting tired of karma fortunes by now.pholy ought to be getting tired of karma fortunes by now.pholy ought to be getting tired of karma fortunes by now.
 
pholy's Avatar
 
Posts: 1,801
Karma: 7999816
Join Date: Jun 2009
Location: Toronto, Ontario, Canada
Device: BeBook(1 & 2010), PEZ, PRS-505, Kobo BT, PRS-T1, Playbook, Kobo Touch
Actually, I got an email from BeBook shortly after I sent them a reply complaining about the security hole.

So they were at least sort of on top of it.
pholy is offline   Reply With Quote
Old 11-04-2010, 05:29 PM   #11
Magnesus
Connoisseur
Magnesus is on a distinguished road
 
Posts: 98
Karma: 58
Join Date: Apr 2010
Device: Bebook Neo
Quote:
Originally Posted by Worldwalker View Post
There's not a whole lot Bebook can do. I could send out spam appearing to be from you, for instance (it's called a "Joe job") and the most you could do would be say "no, that's not me."
Yes, but the spammer has e-mail adresses of mybebook site clients from somewhere. Only people who bought something there got the spam.
Magnesus is offline   Reply With Quote
Old 11-04-2010, 05:38 PM   #12
JSWolf
Resident Curmudgeon
JSWolf ought to be getting tired of karma fortunes by now.JSWolf ought to be getting tired of karma fortunes by now.JSWolf ought to be getting tired of karma fortunes by now.JSWolf ought to be getting tired of karma fortunes by now.JSWolf ought to be getting tired of karma fortunes by now.JSWolf ought to be getting tired of karma fortunes by now.JSWolf ought to be getting tired of karma fortunes by now.JSWolf ought to be getting tired of karma fortunes by now.JSWolf ought to be getting tired of karma fortunes by now.JSWolf ought to be getting tired of karma fortunes by now.JSWolf ought to be getting tired of karma fortunes by now.
 
JSWolf's Avatar
 
Posts: 73,983
Karma: 128903378
Join Date: Nov 2006
Location: Roslindale, Massachusetts
Device: Kobo Libra 2, Kobo Aura H2O, PRS-650, PRS-T1, nook STR, PW3
I never bought anything there. But I did register there.

Also, the threat is over.

Quote:
user Account Excceded Bandwidth

This account is not valid.
I went there to try to download bill.exe so I could see if Comodo recognized it as a trojan or virus.
JSWolf is offline   Reply With Quote
Reply


Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Seriously thoughtful new phishing tactic kindlekitten Lounge 15 07-10-2011 12:54 PM
Email Announcing Sony PRS Update OK? Phishing Vienna01 Reading and Management 2 12-30-2009 06:08 PM
mybebook.com payment methods? dcalder HanLin eBook 2 01-07-2009 07:57 PM
Yahoo begins test of email service that looks more like desktop email programs Bob Russell Lounge 2 09-18-2005 07:20 PM


All times are GMT -4. The time now is 04:34 AM.


MobileRead.com is a privately owned, operated and funded community.