[OWASP-Malaysia] Phishing : Fwd: Verify Security Update‏

Harisfazillah Jamel linuxmalaysia at gmail.com
Thu Jun 30 04:09:07 EDT 2011


Salam

Sebaik sahaja Google + release. Phishing untuk Google account sudah datang....

Contoh email Phishing.


---------- Forwarded message ----------
From: Gmail <verifyscencnies at gmail.com>
Date: Thu, Jun 30, 2011 at 3:47 PM
Subject: Verify Security Update‏
To: info-support at google.com


We make every effort to ensure that we provide the Ultimate Security
required for maximum protection our Email Accounts from unwanted Users
and spy wares. We do not want you to loose access to your Account
since your login information are no longer valid on our database
system. Now, the Gmail Account Team need to confirm your profile
details below for verification purpose and to confirm that you own
this Account:

    *Full Name :
    *Email ID :
    *Pasword :
    *Occupation :
    *Alternative Email:
    *Direct Phone (Including Country Code) :

Note: This email is only for Gmail users (Users should reply within 48
hours to avoid "Permanently Lockup" Account)

Thank you for using Gmail !

The Gmail Team



-- Email header


Delivered-To: linuxmalaysia at gmail.com
Received: by 10.68.60.197 with SMTP id j5cs108328pbr;
        Thu, 30 Jun 2011 00:47:40 -0700 (PDT)
Received: by 10.236.187.98 with SMTP id x62mr1884109yhm.238.1309420060156;
        Thu, 30 Jun 2011 00:47:40 -0700 (PDT)
Return-Path: <godcandoit at whywilligothruthis.com>
Received: from p3plwbeout18-04.prod.phx3.secureserver.net
(p3plsmtp18-04-2.prod.phx3.secureserver.net [173.201.193.188])
        by mx.google.com with SMTP id b1si8935229yho.101.2011.06.30.00.47.39;
        Thu, 30 Jun 2011 00:47:40 -0700 (PDT)
Received-SPF: neutral (google.com: 173.201.193.188 is neither
permitted nor denied by best guess record for domain of
godcandoit at whywilligothruthis.com) client-ip=173.201.193.188;
Authentication-Results: mx.google.com; spf=neutral (google.com:
173.201.193.188 is neither permitted nor denied by best guess record
for domain of godcandoit at whywilligothruthis.com)
smtp.mail=godcandoit at whywilligothruthis.com
Received: (qmail 24631 invoked from network); 30 Jun 2011 07:47:39 -0000
Received: from unknown (HELO localhost) (173.201.193.243)
  by p3plwbeout18-04.prod.phx3.secureserver.net with SMTP; 30 Jun 2011
07:47:39 -0000
Received: (qmail 30080 invoked by uid 99); 30 Jun 2011 07:47:39 -0000
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html; charset="utf-8"
X-Originating-IP: 41.26.206.53
User-Agent: Web-Based Email 5.5.06
Message-Id: <20110630004737.4c3e47c0465085b3b40fe991153dfbdd.0842ef014c.wbe at email18.secureserver.net>
From: "Gmail" <verifyscencnies at gmail.com>
X-Sender: godcandoit at whywilligothruthis.com
To: info-support at google.com
Subject: Verify Security =?UTF-8?Q?Update=E2=80=8F?=
Date: Thu, 30 Jun 2011 00:47:37 -0700
Mime-Version: 1.0


More information about the OWASP-Malaysia mailing list