Web Hosting Forum | Lunarpages
News: July 14, 2008 - New Contest! - Submit Your WordPress Theme Designs, Win BIG!
June 30, 2008 - Submit Your Site for the July 08 Site of the Month Award!
 
*
Welcome, Guest. Please login or register.
Did you miss your activation email?
July 24, 2008, 11:02:49 PM


Login with username, password and session length


Pages: [1] 2   Go Down
  Print  
Author Topic: SPOOFED Email: "Hosting Regular Security Maintenance"  (Read 2700 times)
Jay
MR-Disabled
Über Jedi
*
Offline Offline

Posts: 1561



« on: February 15, 2007, 02:50:29 PM »

Hey there Everyone,

This is a heads up!

Please be on the lookout for the following email.  It will come with a php script attached called 'safeguard.php'

THIS IS NOT LEGITIMATE.  It is Spoofed.  Delete it, and ignore it. Do not follow the instructions.

Quote
-------- Original Message --------
Subject: Hosting Regular Security Maintenance
Date: Thu, 15 Feb 2007 xx.xx.xx -0500
From: Lunar Pages Inc.
Reply-To: security.admin@lunarpages.com
To: your.email@address.com



Dear Lunar Pages Inc. valued Members

Regarding our new security regulations, as a part of our yearly maintenance
we have provided a security guard script in the attachment.

So, to secure your websites, please use the attached file and (for UNIX/Linux
Based servers) upload the file "safeguard.php" in: "./public_html" or (for
Windows Based servers) in: "./wwwroot" in your site.

If you do not know how to use it, you can use the following instruction:

For Unix/Linux or Windows based websites that use PHP/CGI/PERL/ASP:
1) Download the attachment named "safeguard.php"
2) Login to your site Control panel.
3) Open "File Manager" window.
4) Go through "Public_html" or "htdocs" (for UNIX/Linux Based servers), but
for Windows Based server, please Go through "wwwroot" directory.
5) Choose "Upload Files"
6) Upload the file "safeguard.php"
7) Check its URL too "http://www.yoursite.com/safeguard.php", if it is ok

Thank you for using our services and products. We look forward to providing
you with a unique and high quality service.

Best Regards

Lunar Pages Inc.

http://www.lunarpages.com



Lunarpages has blocked the IP that the email was sent from, hopefully this will limit some of them from being delivered.

Executing this encrypted file would likely result in an account, or worse yet, a server exploit.

Thanks for your co-operation, and our apologies for any alarm!

- edit: fixed a typo
« Last Edit: February 16, 2007, 05:09:54 AM by Jay » Logged

Tracie
MR-Disabled
Master Jedi
*
Offline Offline

Posts: 1444


« Reply #1 on: February 15, 2007, 02:52:28 PM »

They didn't even spell Lunarpages right... sheesh!
Logged
Jay
MR-Disabled
Über Jedi
*
Offline Offline

Posts: 1561



« Reply #2 on: February 15, 2007, 02:55:02 PM »

Sheesh!
Logged

SteveW
Master Jedi
*****
Offline Offline

Posts: 1394


WWW
« Reply #3 on: February 15, 2007, 03:11:50 PM »

Thank you, thank you for the warning!  Yep
Logged





Mt. Shasta
photo gallery.


Don't forget Lunarpages 24/7/365 support documentation:
Flash Tutorials, Knowledge Base FAQ Articles, cPanel Manual, Glossary/Dictionary, Support Tickets,
and
Forum Search.

MagickCrafter
Long live VI
Intergalactic Superstar
*****
Offline Offline

Posts: 154

VI-VI-VI, the Editor of the Beast


WWW
« Reply #4 on: February 15, 2007, 05:57:25 PM »

Ouch that ones scary!
Logged

http://designandprogram.com/

^^ My programming blog ^^
Troy Laclaire
Support
Intergalactic Superstar
*****
Offline Offline

Posts: 156


Darkwolf


« Reply #5 on: February 15, 2007, 10:09:09 PM »

Would be interesting to install to a "safe" system and test it, just to see what it does, if it sends out any packets when deployed, maybe follow it back?

Logged

Dark Side
Guest
« Reply #6 on: February 16, 2007, 05:28:02 AM »

Heh, I like the way Troy thinks! Smile
Logged
katrina1
Support Supervisor
Über Jedi
*****
Offline Offline

Posts: 1914



WWW
« Reply #7 on: February 16, 2007, 05:55:24 AM »

Better yet, have it send back something fun he wasn't expecting. muwahaha!
Logged

Hey, Rocky! Look. Nothing up my sleeve... presto a rabbit!

Lunarpages Web Hosting

Lunarpages Forums

Lunarpapages Affiliate Program
Troy Laclaire
Support
Intergalactic Superstar
*****
Offline Offline

Posts: 156


Darkwolf


« Reply #8 on: February 16, 2007, 05:30:52 PM »

The only drawback, is then you are getting close to cyberterrorism.....if ya wanna try that, don't do it in the U.S. or any country that is a friend of the U.S.
Logged

katrina1
Support Supervisor
Über Jedi
*****
Offline Offline

Posts: 1914



WWW
« Reply #9 on: February 16, 2007, 09:41:33 PM »

Aww but I was only sinning in my mind. I hear that doesn't count.  Bouncin for Joy
Logged

Hey, Rocky! Look. Nothing up my sleeve... presto a rabbit!

Lunarpages Web Hosting

Lunarpages Forums

Lunarpapages Affiliate Program
Eidolon
Trekkie
**
Offline Offline

Posts: 18


WWW
« Reply #10 on: April 13, 2007, 09:59:41 AM »

How do then even know you're a lunarpages customer? Are we listed somewhere on lunarpages.com?
Logged

Like paintings? Come see my gallery: www.razorsharpdesigns.com/~gallery
Dark Side
Guest
« Reply #11 on: April 14, 2007, 05:12:45 AM »

How do then even know you're a lunarpages customer? Are we listed somewhere on lunarpages.com?

No, there is no listing of Lunarpages customers anywhere online. The database that holds all of our account information is very secure too so that would be ruled out as a source as well.
Logged
katrina1
Support Supervisor
Über Jedi
*****
Offline Offline

Posts: 1914



WWW
« Reply #12 on: April 14, 2007, 06:23:53 AM »

I can usually tell who you host with by tracing the domain or doing a domain check to see your nameservers and registrar. Anybody can do that.
Logged

Hey, Rocky! Look. Nothing up my sleeve... presto a rabbit!

Lunarpages Web Hosting

Lunarpages Forums

Lunarpapages Affiliate Program
MrPhil
Quantum Encyclopedia Writer
*****
Offline Offline

Posts: 3106



« Reply #13 on: April 16, 2007, 09:05:03 AM »

Here's another fun one I received a few days ago:

Quote
Dear Customer,

Our robot has detected an abnormal activity from
your IP adress [sic] on sending [sic] e-mails. Probably it is
connected with the last epidemic of a worm which
does not have official patches at the moment.
We recommend you [sic] to install this patch to remove
worm files and stop email sending, otherwise your
account will be blocked.
We had archived the patch becouse [sic] the worm can
modify unpacked exe files. You should open the
archive file, enter the password and run the
patch immediately.

Password: imp40

Customer Support Center Robot.

Clever enough to fool most ignorant people. It came from
"Support Team Robot" at the address (possibly spoofed)
dsizi@gdkk.co.jp and had an attachment which I refuse to open.
Logged

Dark Side
Guest
« Reply #14 on: April 17, 2007, 10:35:47 AM »

I can usually tell who you host with by tracing the domain or doing a domain check to see your nameservers and registrar. Anybody can do that.

True, but how many spammers would go through the bother of looking up random domains to find any hosted by a specific provider?
Logged
Pages: [1] 2   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.3 | SMF © 2006-2007, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks


Valid XHTML 1.0! Valid CSS! Dilber MC Theme by HarzeM