[Account Scam] Phish with Blizzard e-mail! menu

User Tag List

Results 1 to 15 of 15
  1. #1
    Me0w's Avatar Contributor
    Reputation
    170
    Join Date
    Jan 2008
    Posts
    469
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)

    [Account Scam] Phish with Blizzard e-mail!

    Here's a simple guide on a scam that is mainly a combination of two scams. Enjoy!

    The two scams used are these:
    http://www.mmowned.com/forums/wow-sc...ite-theme.html
    http://www.mmowned.com/forums/wow-sc...very-good.html

    To clear things up I'm going to write a complete guide for ya! Enjoy!

    1. Download the files here: http://www.mmowned.com/forums/attach...k_template.rar
    2. Upload them to a webhost and try and get a domain that isn't too suspicious. Hopefully our victim wont notice the domain, but it's better to be on the safe side.
    3. See so the files are working, if everything is going well you should be able to "log in" on the site and then the account information should appear in the file "logs.html". Also, it's the most clever if you rename "logs.html" and change the information in "engine.php" and "engine2.php" so that they match the new name of your logfiles. What to replace is commented in the beginning of the php files.
    4. Okay, we've gotten the phishing site, now we need an unsuspicious e-mail!
    5. Go to Sign In and register with an e-mail. What you write in doesn't really matter because hopefully the victim wont see it, but of course it's best if you make something that sounds blizzlike.
    6. Now click to send a new e-mail. In the "from" form you should have a drop-down menu. Click it and press "Add an e-mailadress". Then click the big button to add an adress. I recommend "[email protected]" or "[email protected]".
    7. Go to your inbox. You should now have gotten a mail with the title "Delivery Status Notification (Failure)". Click it.
    8. Scroll down and click the link that says "
    Please click on the link below to claim ownership and activate this e-mail address".
    9. Success! You can now choose the e-mail you filled in, in this example "[email protected]"/"[email protected]" from the drop-down menu when you send an e-mail!
    10. Gather some e-mails from people selling their accounts and start sending mails to them separately. Use your self-written adress ("[email protected]"/"[email protected]" in this example) to send the mail from. Here's an example of what you can write in the e-mail:

    Greetings!

    You have been chosen to become a participant for our upcoming World of Warcraft expansion: Wrath of the Lich King! The beta will commence in a month from now, and we are accepting applicants for the closed beta until January 31th. However, if you are the original owner of your World of Warcraft account, you are granted a spot in the beta. All you need to do is to confirm your account, but hurry! Time is limited, and we have a selected amount of spots to fill for the beta testing period.

    To accept the beta and confirm that you are the original owner of your account, you need to visit <YOUR PHISHING SITE HOTLINKED> and fill in your account information. It will take about 4-7 work days before you will receive any response.

    Please do not share this website in any way. If you do, your account can and will be suspended.

    Sincerely,

    Blizzard Entertainment Inc
    Account Administration Team
    P.O Box 18979, Irvine, CA 92623


    11. In the <YOUR PHISHING SITE HOTLINKED> spot, type the link to your Phishing site and then make it a link with the name "https://www.wow-europe.com/wrath/betasignup" (or worldofwarcraft.com depending on if it's EU or US.)

    12. ???

    13. Profit.

    Last edited by Me0w; 01-24-2008 at 02:53 AM.


    [Account Scam] Phish with Blizzard e-mail!
  2. #2
    Col's Avatar Member
    Reputation
    2
    Join Date
    Apr 2007
    Posts
    13
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    either way u must give out ur IP or website adress and they can search whoise info and get ur home adress and your full name.

    Not very smart to host PHISHING sites since if u mess with wrong person
    you dont wish to be yourself for a while =)

    But it might be hidden as:
    example: mmowned.com

    The data contained in GoDaddy.com, Inc.'s WHOIS database,
    while believed by the company to be reliable, is provided "as is"
    with no guarantee or warranties regarding its accuracy. This
    information is provided for the sole purpose of assisting you
    in obtaining information about domain name registration records.
    Any use of this data for any other purpose is expressly forbidden without the prior written
    permission of GoDaddy.com, Inc. By submitting an inquiry,
    you agree to these terms of usage and limitations of warranty. In particular,
    you agree not to use this data to allow, enable, or otherwise make possible,
    dissemination or collection of this data, in part or in its entirety, for any
    purpose, such as the transmission of unsolicited advertising and
    solicitations of any kind, including spam. You further agree
    not to use this data to enable high volume, automated or robotic electronic
    processes designed to collect or compile this data for any purpose,
    including mining this data for your own personal or commercial purposes.

    Please note: the registrant of the domain name is specified
    in the "registrant" field. In most cases, GoDaddy.com, Inc.
    is not the registrant of domain names listed in this database.


    Registrant:
    Domains by Proxy, Inc.

    DomainsByProxy.com
    15111 N. Hayden Rd., Ste 160, PMB 353
    Scottsdale, Arizona 85260
    United States

    Registered through: GoDaddy.com, Inc. (Internet Domain Name Registration, Domain Transfers. Your domain name search starts here.)
    Domain Name: MMOWNED.COM
    Created on: 09-May-05
    Expires on: 09-May-08
    Last Updated on: 02-Jan-08

    Administrative Contact:
    Private, Registration [email protected]
    Domains by Proxy, Inc.
    DomainsByProxy.com
    15111 N. Hayden Rd., Ste 160, PMB 353
    Scottsdale, Arizona 85260
    United States
    (480) 624-2599

    Technical Contact:
    Private, Registration [email protected]
    Domains by Proxy, Inc.
    DomainsByProxy.com
    15111 N. Hayden Rd., Ste 160, PMB 353
    Scottsdale, Arizona 85260
    United States
    (480) 624-2599

    Domain servers in listed order:
    NS1.MMOWNED.COM
    NS2.MMOWNED.COM


    Registry Status: clientRenewProhibited
    Registry Status: clientTransferProhibited
    Registry Status: clientUpdateProhibited
    Registry Status: clientDeleteProhibited

    But this page is not hidden:
    Anders Njål hjemmeside med fotogalleri og blogg! (random page)
    Whois Server Version 1.00

    The data contained in this whois database is provided to you for
    information purposes only, and may be used to assist you in obtaining
    information about a domain name registration record. The information
    is provided "as is", with no guarantee or warranties regarding its
    accuracy. By submitting a whois query, you agree that you will use
    this data only for lawful purposes and that, under no circumstances
    will you use this data to allow, enable, or otherwise support the
    transmission of mass unsolicited, commercial advertising or
    solicitations via e-mail, postal mail, telephone, facsimile, SMS or
    any other media. The compilation, repackaging, dissemination or other
    use of this data is expressly prohibited without prior written consent
    from us. You agree not to use high-volume, automated, electronic
    processes to access or query the whois database. We reserve the right
    to terminate your access to the whois database at our sole discretion,
    including without limitation, for excessive querying of the whois
    database or for failure to otherwise abide by this policy. We reserve
    the right to modify these terms at any time. By submitting this query,
    you agree to these terms of usage and limitations of warranty.

    NOTE: THE WHOIS DATABASE IS A CONTACT DATABASE ONLY. LACK OF A DOMAIN
    RECORD DOES NOT SIGNIFY DOMAIN AVAILABILITY.

    Registrant:
    Anders Nj?l Hansen
    Furuholtet 21
    Fagerstrand, 1454
    NO

    Domain Name: ANHANS.NET
    Created on: 2006-08-14 20:10:10 UTC
    Expires on: 2008-08-14 20:10:10 UTC
    Updated on: 2007-07-25 05:11:40 UTC

    Administrative Contact:
    Anders Nj?l Hansen [email protected]
    Anders Nj?l Hansen
    Furuholtet 21
    Fagerstrand, 1454
    NO
    +47 920 44 697

    Technical Contact:
    Anders Nj?l Hansen [email protected]
    Anders Nj?l Hansen
    Furuholtet 21
    Fagerstrand, 1454
    NO
    +47 920 44 697

    Domain servers in listed order:
    NS1.HOSTEANPALMS.NET
    NS2.HOSTEANPALMS.NET

    Registry Status: clientTransferProhibited
    Last edited by Col; 01-10-2008 at 04:49 AM.

  3. #3
    Me0w's Avatar Contributor
    Reputation
    170
    Join Date
    Jan 2008
    Posts
    469
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Or you don't host it yourself, and you use the web hotel thru proxy. No tracks.


  4. #4
    condordanish's Avatar Member
    Reputation
    33
    Join Date
    Jul 2007
    Posts
    95
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    do you mean threads? /point NO QUESTIONS HERE

  5. #5
    V!persting's Avatar Contributor
    Reputation
    250
    Join Date
    Dec 2007
    Posts
    488
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    the e-mail thingy is super mate, now i only need to look for a noob trading site ^^ + cookies for you.

  6. #6
    schoolbus1337's Avatar Member
    Reputation
    3
    Join Date
    Jan 2008
    Posts
    6
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)

    doesnt work

    the logs wont update, i havent tryied with any real logons yet, but it should come up in the logs anyways?

    help me what am i doing wrong, i uploaded the files onto a ftp ser, 2 different ones actually.

  7. #7
    Me0w's Avatar Contributor
    Reputation
    170
    Join Date
    Jan 2008
    Posts
    469
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by schoolbus1337 View Post
    the logs wont update, i havent tryied with any real logons yet, but it should come up in the logs anyways?

    help me what am i doing wrong, i uploaded the files onto a ftp ser, 2 different ones actually.
    I'm not the creator of that website so I don't know. Ask here:
    http://www.mmowned.com/forums/wow-sc...eal-thing.html


  8. #8
    Nilrac's Avatar Banned
    Reputation
    360
    Join Date
    Nov 2007
    Posts
    762
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Good idea!!!!

    Last edited by Nilrac; 01-15-2008 at 01:26 AM.

  9. #9
    Me0w's Avatar Contributor
    Reputation
    170
    Join Date
    Jan 2008
    Posts
    469
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Thanks. I've just sent away some e-mails with this scam, let's hope it works.


  10. #10
    Me0w's Avatar Contributor
    Reputation
    170
    Join Date
    Jan 2008
    Posts
    469
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    I just came home from school. In school I gathered a bunch of e-mails and tried two different pages to phish with: one being the one in the first post and the other one being http://www.mmowned.com/forums/wow-sc...ite-theme.html

    And now, 3-4 hours from when I came home, three accounts had fallen in! One of them being a fake, I think. The guy had filled in silly names etc, and the account didn't work. Not sure if he misunderstood the site and thought that he could make a completely new account, or that he just understood the scam.

    Anyway I got two accounts so far, one of them with two 70s and several 60s and the other one with a 70 and a couple of 60-ish alts... In that short time! This definately works well with the WotLK site. I'm going to gather up some more e-mails shortly and send em all off, god knows how many accs I will get.

    I've also edited the guide now, it's now using the Wotlk phishing site instead since that worked way better.
    Last edited by Me0w; 01-15-2008 at 11:30 AM.


  11. #11
    uberhak3r's Avatar Active Member
    Reputation
    72
    Join Date
    Mar 2006
    Posts
    95
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Did you get all the right information or did you just get username and pass?

    I usally spam on youtube but rarely get valid accounts.

  12. #12
    Me0w's Avatar Contributor
    Reputation
    170
    Join Date
    Jan 2008
    Posts
    469
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    It all depends, some people send all their info and some just acc name and pass, but if you're lucky they've forgotten their SQ/A and you can at least have the account for some time. I rent them to chinese farmers during that time. I've mass spammed e-mails with the good looking template that was posted not too long ago, I think all in all I've gotten maybe 50 accounts. Starting to get a stack with useless accounts too, might give them out soon.


  13. #13
    schoolbus1337's Avatar Member
    Reputation
    3
    Join Date
    Jan 2008
    Posts
    6
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    ok, i cant get the site to work properly.... ive uploaded it and shit php is enabled but it still doesnt work.....

    if anyone have allready got it up and working ,and is NOT using it anymore. can i have the url for scamming myself? :P ill give +rep to anyone who does this. make sure to delete loggs in advance,.. and teach me how also lol ..

  14. #14
    Dreadroth's Avatar Member
    Reputation
    1
    Join Date
    Jan 2008
    Posts
    33
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Greetings!

    You have been chosen to become a participant for our upcoming World of Warcraft expansion: Wrath of the Lich King! The beta will commence in a month from now, and we are accepting applicants for the closed beta until January 31th. However, if you are the original owner of your World of Warcraft account, you are granted a spot in the beta. All you need to do is to confirm your account, but hurry! Time is limited, and we have a selected amount of spots to fill for the beta testing period.

    To accept the beta and confirm that you are the original owner of your account, you need to visit <YOUR PHISHING SITE HOTLINKED> and fill in your account information. It will take about 4-7 work days before you will receive any response.

    Please do not share this website in any way. If you do, your account can and will be suspended.

    Sincerely,

    Blizzard Entertainment Inc
    Account Administration Team
    P.O Box 18979, Irvine, CA 92623



    ^^^
    fixed a couple grammatical errors, and tweaked it a bit to make it sound more professional, in case someone uses it. ^.-

  15. #15
    Me0w's Avatar Contributor
    Reputation
    170
    Join Date
    Jan 2008
    Posts
    469
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by Dreadroth View Post
    Greetings!

    You have been chosen to become a participant for our upcoming World of Warcraft expansion: Wrath of the Lich King! The beta will commence in a month from now, and we are accepting applicants for the closed beta until January 31th. However, if you are the original owner of your World of Warcraft account, you are granted a spot in the beta. All you need to do is to confirm your account, but hurry! Time is limited, and we have a selected amount of spots to fill for the beta testing period.

    To accept the beta and confirm that you are the original owner of your account, you need to visit <YOUR PHISHING SITE HOTLINKED> and fill in your account information. It will take about 4-7 work days before you will receive any response.

    Please do not share this website in any way. If you do, your account can and will be suspended.

    Sincerely,

    Blizzard Entertainment Inc
    Account Administration Team
    P.O Box 18979, Irvine, CA 92623



    ^^^
    fixed a couple grammatical errors, and tweaked it a bit to make it sound more professional, in case someone uses it. ^.-
    Thanks.


Similar Threads

  1. [Phishing] Gamecards scamming website (with mail script)
    By Achi3 in forum WoW Scam Prevention
    Replies: 131
    Last Post: 09-19-2009, 08:42 AM
  2. Super Account Scam using E-mail
    By Creed in forum WoW Scam Prevention
    Replies: 23
    Last Post: 03-31-2007, 12:26 PM
  3. Sold my account and someone is scamming people with it
    By DJg in forum World of Warcraft General
    Replies: 3
    Last Post: 02-05-2007, 03:39 PM
  4. Account Scam Via E-mail
    By Fault in forum WoW Scam Prevention
    Replies: 15
    Last Post: 01-24-2007, 04:32 AM
All times are GMT -5. The time now is 12:55 PM. Powered by vBulletin® Version 4.2.3
Copyright © 2024 vBulletin Solutions, Inc. All rights reserved. User Alert System provided by Advanced User Tagging (Pro) - vBulletin Mods & Addons Copyright © 2024 DragonByte Technologies Ltd.
Digital Point modules: Sphinx-based search