|
Libra38
|
I got the mails several times, first I disregard it but it keeps coming so I was convince it could be geniune and decided to fill the form online.
Guest what?' tanx to my Norton Anti-Virus who block it immediately.
Please guys! shine your eyes well well oooooooo!!!
|
|
|
|
|
|
gbengaijot (m)
|
i just checked the whois record for this particular scam website and came out with the following;
Whois Record
Registration Service Provided By: United Online, Inc. Contact: Domain name: equitorialtrustbank.com
Registrant Contact: Walcom Computer Consultants Adewale Onafuwa () Fax: 5, Igbore Street, Onike Yaba, 999 NG
Administrative Contact: Walcom - Computer Consultants Adewale Onafuwa () +1.2074731353 Fax: 8 Weymouth close Beckton, E66ZF GB
Technical Contact: Register.Com Domain Registrar () +1.9027492701 Fax: +1.9027495429 575 8th Avenue 11th Floor New York, NY 10018 US
Status: Active
Name Servers: ns19a.nameservers.net ns19b.nameservers.net Creation date: 10 Jun 2003 00:40:22 Expiration date: 10 Jun 2010 00:40:00
|
|
|
|
|
|
aeso (m)
|
e-mail phishing 101.
Never open any link that deals with electronic cash transaction from your mail box.
and I wonder why interswitch doesnt have an SSL digital certificate to verify the authenticity of their site.
|
|
|
|
|
|
lucillia90
|
what can i even say? i got thesame email and it came 4 rm interswitch website live For the past 4 months it has been telling me to update my info if not my card wouldn't work on atm and i dunno i just refused to update my info and for sum reasons the card still works, dat was hw i sensed foul play.one funny thing is dat it came from interswitch website and email, where else could it cme from?
|
|
|
|
|
|
aeso (m)
|
As a security expert, here are a few tips people should always observe: 1. No responsible financial institution will ever request you update your records over the Internet, knowing the risks involved. If in doubt contact the bank first by phone or visit a branch. 2. Always ensure the website URL begins with https (NOT http as shown in the image) when entering confidential information. HTTPS means a secure form of HTTP. 3. Always watch out for a padlock or key sign on the browser (location varies between browsers). 4. Always use the latest version of your web browser (this will have the full certificate hierarchy). Ideally no one should be using present day any browser below Firefox 3, IE 7 or Opera 9. 4. Click on the padlock or key to verify the authenticity of the site if in doubt. This will reveal the site's certificate and the issuer. If the site uses a self-issued or expired certificate, the browsers listed above will easily detect and warn the user. In fact IE7 or IE8 will not allow you access to the fraudulent page.
Having said these, it is possible to hack into legitimate sites and create links that redirect to fraudulent sites. Yes, and it can be quite easy if the website developers/administrators do not follow security guidelines when designing these sites. This can be a form of cross-site scripting.
A plain antivirus program does not protect from phishing. However most packages come as a bundle nowadays, with antivirus, firewall, antispam and antiphishing e.g. Norton 360. They will easily spot phishing attacks like this example but not more advanced ones.
Any questions feel free to ask!
|
|
|
|
|
|
exago (m)
|
@gbengaijot
Please how do I check for the Whois Record of a website, thanks.
|
|
|
|
|
|
|
|
|
|
aeso (m)
|
Not much Interswitch can do, besides advising people on safe practices, like I listed in my earlier post. The real Interswitch site would have features to help identify it, for instance, only the legit interswitch site can begin with https and have a padlock sign, except they were careless to let a crook steal their server certificate!
|
|
|
|
|
|
v3nom4eva (m)
|
NOW. . .Let's de-mystify this scamming of a thingy. . .  There's possible 3-4 things a scammer'll need to perpetrate this sorta"classy" crime 1- A c99shell, ftp server (used to upload the scampages) 2- The scampage (fake website), wif a PHP script (containing the scammer's email address) where all entries will be delivered too. . . 3- A good PHP mailer, SMTP server (used with AMS software) or other Mass Mailing softwares Last but the "BEST". . . Good leads (emails) Once he/she has all of these. . it's easy to get some "mugus" who'd just "walk the plank" witout thinking hard. . I've gotten these emails too. . .The ONLY thing your Bank will prolly send to you are your Bank Statements (IF you opted to receive them via email and that comes in either .PDF or .XLS file formats Be careful and all the best
|
|
|
|
|
|
gbengaijot (m)
|
@gbengaijot
Please how do I check for the Whois Record of a website, thanks.
simply go to www.whois.sc and type the website address into the address bar.
|
|
|
|
|
|
v3nom4eva (m)
|
NOW. . .Let's de-mystify this scamming of a thingy. . .  There's possible 3-4 things a scammer'll need to perpetrate this sorta"classy" crime 1- A c99shell, ftp server (used to upload the scampages) 2- The scampage (fake website), wif a PHP script (containing the scammer's email address) where all entries will be delivered too. . . 3- A good PHP mailer, SMTP server (used with AMS software) or other Mass Mailing softwares Last but the "BEST". . . Good leads (emails) Once he/she has all of these. . it's easy to get some "mugus" who'd just "walk the plank" witout thinking hard. . I've gotten these emails too. . .The ONLY thing your Bank will prolly send to you are your Bank Statements (IF you opted to receive them via email and that comes in either .PDF or .XLS file formats Be careful and all the best
|
|
|
|
|
|
gbengaijot (m)
|
@ seun, i noticed that while posting replied, it gives a 504 gateway timeout. This is causing everyone to make their post twice,
Is it a temporary server issue? Kindly rectify it please if you can. God bless
|
|
|
|
|
|
v3nom4eva (m)
|
NOW. . .Let's de-mystify this scamming of a thingy. . .  There's possible 3-4 things a scammer'll need to perpetrate this sorta"classy" crime 1- A c99shell, ftp server (used to upload the scampages) 2- The scampage (fake website), wif a PHP script (containing the scammer's email address) where all entries will be delivered too. . . 3- A good PHP mailer, SMTP server (used with AMS software) or other Mass Mailing softwares Last but the "BEST". . . Good leads (emails) Once he/she has all of these. . it's easy to get some "mugus" who'd just "walk the plank" witout thinking hard. . I've gotten these emails too. . .The ONLY thing your Bank will prolly send to you are your Bank Statements (IF you opted to receive them via email and that comes in either .PDF or .XLS file formats Be careful and all the best
|
|
|
|
|
|
exago (m)
|
@gbengaijot
Please how do I check for the Whois Record of a website, thanks.
|
|
|
|
|
|
lepacious
|
What makes this case pathetic is the fact that these guys are really making use of ETB's website for this. Who on earth is the webmaster of the Bank's website?
This should make ETB liable to the victims of this scam.
|
|
|
|
|
|
lannre (m)
|
Its not limited to equitorial trust bank thay picked bank at random,the content is enough to make an intellect think twice. (1) how can Bank cancel ATM transaction of Millions of their customers (2) what is the percentage of their customers that have access to the internet to get such information.
I believe the fraudster is sick and no matter the make belive of any website, I advise individual to visit the concerned Organisation for better clarification. As good as ICT there are great vices,its not limited to Nigeria. Hackers effort should be a training to experts,that is what should bring a good challenge to make ICT expert perform better
|
|
|
|
|
|
lannre (m)
|
Its not limited to equitorial trust bank thay picked bank at random,the content is enough to make an intellect think twice. (1) how can Bank cancel ATM transaction of Millions of their customers (2) what is the percentage of their customers that have access to the internet to get such information.
I believe the fraudster is sick and no matter the make belive of any website, I advise individual to visit the concerned Organisation for better clarification. As good as ICT there are great vices,its not limited to Nigeria. Hackers effort should be a training to experts,that is what should bring a good challenge to make ICT expert perform better
|
|
|
|
|
|
brein
|
@Topic. Amazing Grace, how sweet the sound. 
|
|
|
|
|
|
brein
|
@Topic. Amazing Grace, how sweet the sound. 
|
|
|
|
|
|
opensource (m)
|
How they hell , where they able to host in on the real banking website.
this should be investigated , probably the webmaster should be held.
|
|
|
|
|
|
allboyz (m)
|
even to their fellow brother and sis again? this 'em guys nor dey fear?
|
|
|
|
|
|
opensource (m)
|
How they hell , where they able to host in on the real banking website.
this should be investigated , probably the webmaster should be held.
|
|
|
|
|
|
solosimple (m)
|
eeehhh! Wahala dey!
|
|
|
|
|
|
Carlosein (m)
|
@ seun, i noticed that while posting replied, it gives a 504 gateway timeout. This is causing everyone to make their post twice,
Is it a temporary server issue? Kindly rectify it please if you can. God bless
i noticed this too. but when you post and get this, just refresh instead of going back and posting again.
|
|
|
|
|
|
exago (m)
|
first and Foremost I dont have a direct link with interswitch, it only exists' through my bank, an interswith card linked to my bank account, period. So why should I bother myself updating on a site different from my bank.
|
|
|
|
|
|
danteweb
|
From the replies i have read on this thread, its obvious that only a handfull are webmasters. This situation is a unique case. Its not the usual thing where the scammer sets up a fake website which is a clone of the original site and tries to get confidential information through that fake website. This case is the case of a bank's real website, being hijacked and used to scam people. The consequences of this are absolutely grave, ETB really need to get on top of this. As far as i'm concerned, these scammers have the power to do anything with the ETB website if they wish. The can even shut it down totally if the want. The only mysterious thing is that how did they manage to gain access onto the webspace?   ? A question only the webmasters can answer.
|
|
|
|
|
|
Seun (m)
|
This case is different. www.equitorialtrustbank.com is a legitimate website. The criminals actually created a fraudulent page on the bank's real website. (Fortunately, the page has now been removed) Please note that your bank will never ask for your ATM pin, for any reason.
|
|
|
|
|
|
webpro (m)
|
How is it possible that this criminals got into ET Bank's website control panel and created a subdomain to upload a phishing website. believe me, the person incharge of managing ET Bank's website is directly responsible for this. As someone who has grounded knowledge in Etical hacking and forency investigation, i know well, how a website is hacked into, so u wont tell me to believe that the fraudstars actually hacked into ETB's website and used it to upload a fraud page.
Please other web programmers here should know what am talking about. Its only if the bank uses a kanel shell code which is vulnerable to attacks, or any other easy web uploading scripts that this happens. Moreso, this fraudstars are not even hackers because what they do is not regarding as hacking so they would not possibly be able to go into their cpanel.
I'm open to more arguments on this
The bank should question their site admin for this! PERIOD!
|
|
|
|
|
|
Saddam
|
The Crazy Thing about The Whole things is the When u go to the Office The Old Bingo who's in charge of the IT and web Administratior Will be Busy
Sipping Tea n easting Cookies. Doing facebook
Instead of Checkin on the facilities He is been paid for to look after.
ET Bank its a Shame Just Sack the fella
|
|
|
|
|
|
trimandtrendy (f)
|
yesterday i got one from gtbank, which is the bank i use. i almost succumbed, til my firfox stopped me
|
|
|
|
|
|
nitation (m)
|
For those lamenting on the web administrator!
You should ask yourself if the bank took the proper procedure in employing the better guys to maintain their online server.
2) How much was "positively" invested in the so-called ETB online website.
3) What checks and balances was put to place on those maintaining the website and how do they respond to problems when encountered; DO this people (ETB) even consider their customer's protection/safety.
Lastly, the web admin doesn't have to give access before a less secured site can be compromised. I give kudos to aeso for sharing his thoughts here, but believe me phishing has gone way beyond how it seem.
My contribution
- nitation
|
|
|
|
|
|