Part of the problem is Internet Explorer/Outlook. It allows the email to show what appears to be a legit url, when in fact, it is not.
I use Linux and I can see the spoofed url (you can do the same by using "view message source" in Outlook.
I then do a whois (www.samspade.org) of the address and contact the admin of the hosting domain. More often then not the site that is hosting the ebay/paypal "validation page" has been hacked into and the admin is unaware.
__________________
Carpe Diem, Parabellum
|