Skip to main content

Comprendre les tentatives d'hameçonnage (phishing)

Pour ne pas tomber dans le piège...

Je reçois depuis quelques jours des courriels très bien faits m'invitant à consulter mon compte Paypal ou m'indiquant qu'un colis n'a pu être délivré par UPS. Et le hasard fait que je reçois ce courriel justement le lendemain d'un achat.

Ces courriels sont faux et ne sont que des tentatives d'hameçonnage (phishing) afin de récolter des informations personnelles.

Vers où veut-on m'amener ?

En passant la souris sur les liens (SANS CLIQUER !), des détails s'affichent en bas de l'écran. Le lien nous amène vers epl.paypal-communication.com/... ou epl.ups-delirery.com/...


Alors, des vrais ou des faux ?

Les noms de dommaines sont gérés de manière internationale, en collaboration entre les pays. Tout en haut de la pyramide se trouve un organisme américain, l'ICANN.

Pour vérifier un nom de domaine, on peut recourir au service whois de l'ICANN.

Est-ce que UPS est vraiment UPS ?

Interrogeons l'ICANN...
https://whois.icann.org/en/lookup?name=ups.com

La réponse nous donne:
Contact Information

Registrant Contact
Name: Domain Administrator
Organization: United Parcel Service of America, Inc.
Mailing Address: 340 Macarthur Blvd, Mahwah NJ 07630 US
Phone: +1.2018282480
Ext:
Fax:
Fax Ext:
Email:internet@ups.com

Admin Contact
Name: Domain Administrator
Organization: United Parcel Service of America, Inc.
Mailing Address: 340 Macarthur Blvd, Mahwah NJ 07630 US
Phone: +1.2018282480
Ext:
Fax:
Fax Ext:
Email:internet@ups.com

Tech Contact
Name: Domain Administrator
Organization: United Parcel Service of America, Inc.
Mailing Address: 340 Macarthur Blvd, Mahwah NJ 07630 US
Phone: +1.2018282480
Ext:
Fax:
Fax Ext:
Email:internet@ups.com

C'est bien UPS.

Par contre, si on interroge l'ICANN au sujet de ups-delivery.com...
https://whois.icann.org/en/lookup?name=ups-delivery.com

La réponse est bien différente...

Contact Information

Registrant Contact
Name: hui liu
Organization: liuhui
Mailing Address: jinggangshan road 103,,, ji an shi jiang xi 343000 CN
Phone: +86.7968345588
Ext:
Fax: +86.7968345588
Fax Ext:
Email:285997125@qq.com

Admin Contact
Name: hui liu
Organization: liuhui
Mailing Address: jinggangshan road 103,,, ji an shi jiang xi 343000 CN
Phone: +86.7968345588
Ext:
Fax: +86.7968345588
Fax Ext:
Email:285997125@qq.com

Tech Contact
Name: hui liu
Organization: liuhui
Mailing Address: jinggangshan road 103,,, ji an shi jiang xi 343000 CN
Phone: +86.7968345588
Ext:
Fax: +86.7968345588
Fax Ext:
Email:285997125@qq.com

Ça n'a évidemment rien à voir avec UPS, ni même avec une branche chinoise d'UPS.

Et pour Paypal ?

Dans ce cas ci, la réponse en plus troublante:
https://whois.icann.org/en/lookup?name=paypal-communication.com

Contact Information

Registrant Contact
Name: Domain Administrator
Organization: PayPal Inc.
Mailing Address: 2211 North First Street,, San Jose CA 95131 US
Phone: +1.8882211161
Ext:
Fax: +1.4025375774
Fax Ext:
Email:hostmaster@paypal.com

Admin Contact
Name: Domain Administrator
Organization: PayPal Inc.
Mailing Address: 2211 North First Street,, San Jose CA 95131 US
Phone: +1.8882211161
Ext:
Fax: +1.4025375774
Fax Ext:
Email:hostmaster@paypal.com

Tech Contact
Name: Domain Administrator
Organization: PayPal Inc.
Mailing Address: 2211 North First Street,, San Jose CA 95131 US
Phone: +1.8882211161
Ext:
Fax: +1.4025375774
Fax Ext:
Email:hostmaster@paypal.com

Il s'agit bien de Paypal :-/

Dans les faits, paypal-communication.com est une branche marketing de Paypal; de toutes façons, je n'ai pas à fournir des informations autres que ce que Paypal connait déjà.

Conclusion

Ne jamais cliquer sur les liens inclus dans les courriels. Dans le doute, aller directement sur le site (Paypal, UPS, ...).

Comments

Popular posts from this blog

Drive replacement for Fostex DMT8-vl

The IDE hard drive on my Fostex DMT8-vl multitrack recorder shows signs of its imminent death; when getting hot, I could not record anymore. Must be said this drive comes from an old Sun Station, and has been replaced because I/O failures were detected by Solaris. It worked at least 5 years in my recorder: not so bad. However, time is now to replace it. The DMT8-vl is not able to handle drives bigger than 8.4 GB. Well, it is able to (the current drive is 15 GB), but only 8.4 GB will be usable. My tought was to use a 8 GB CompactFlash; having no moving parts means no noise, which is quite temptating for a music recording device. I purchased a CompactFlash-IDE adapter on the internet (8$) and I had to build a male-male IDE cable adapter (4$). Unfortunately, this doesn't work. The drive is correctly discovered by the operating system, which proposes to format it ("format IDE?"). After answering "yes", the formating runs pretty fast (faster than on a real drive), ...

Samba: Clients get "system error 1223" (or 123) after a server reboot

Facts: a Linux+Samba server shares anonymously a folder. After a reboot, Win clients could not attach the share drive anymore. C:\>net use \\mylinux\folder Enter the user name for 'mylinux': System error 1223 has occurred. The operation was canceled by the user. C:\>net view \\mylinux\ System error 123 has occurred. The filename, directory name, or volume label syntax is incorrect. The process are present, and tcpdump doesn't provide much information. What's going on? After hours of headscratching, the light came: the firewall was on and no rules for the Samba protocol! Grrr!

Issue with Soundpool MO4

I have a Atari STe with a Soundpool MO4 MIDI extension. It used to work very well, but unfortunatelly doesn't anymore: Cubase still detects it, and I can output MIDI to it but nothing is coming out from any MIDI Out. It took me a while to tackle it (lack of time, lack of tool, other items to play with), but I gave a glance last week-end. The parallel port on the Atari uses only the following signals: Pin 1 : Strobe (Atari -> MO4) Pin 2 : Data 0 (Atari -> MO4) Pin 3 : Data 1 (Atari -> MO4) Pin 4 : Data 2 (Atari -> MO4) Pin 5 : Data 3 (Atari -> MO4) Pin 6 : Data 4 (Atari -> MO4) Pin 7 : Data 5 (Atari -> MO4) Pin 8 : Data 6 (Atari -> MO4) Pin 9 : Data 7 (Atari -> MO4) Pin 11: Busy (MO4 -> Atari) The MO4 also decodes few other pins, but since the Atari doesn't, my guess is the MO4 was also targeted for PC. Inside the box, the MO4 is architectured around a CPLD (IspLSI1016 from Lattice) which contains the logi...