Industry guru Dave Taylor offers tech support on technical and business topics, including iPhone, iPod, Microsoft Windows, Sony PSP, cellphones, online advertising, CSS, Web design, business, Unix, Linux, SEO, Mac OS X, and shell script programming.     


What's this fake Craiglist posting confirmation all about?

I'm confused. I received a bunch of different emails from Craigslist that are posting confirmation receipts for things I actually haven't put up for sale on Craigslist. I clicked on the link to see what was going on and all I got was a "loading" message, and it wasn't even on the craigslist.com domain. What's it all mean, Dave? Is this some sneaky Craigslist phishing attack from some cybercriminals, or a script virus or what?


Dave's Answer:

Okay, we've gone through this before plenty of times. If you get an email that seems at all odd or inexplicable, you really need to make the assumption that it's a scam or hustle of some sort and not click on the links. Sometimes it's pretty obvious what's going on, like a notification of your account being suspended from an organization you aren't even associated with, like a bank.

Other times, however, it is possible, albeit not likely, that the email is legitimate. I mean, it sounds like you have listed at least one thing on Craigslist at some point in your life, so you weren't unfamiliar with the email that was sent. And that, of course, is the game that all these cybercriminals, hackers, bad guys, whatever you want to call them, are playing. It's just as easy to send 500,000 messages as 50, so if there's even a 1% chance that a recipient will find it legit, they could get hundreds or thousands of people to click on their links.

If it's a phishing attack, the resultant page will look legit and have some believable error message on it like "Please log in before proceeding..." and then if you're not paying attention, you enter your account and password. An error ensues "Validated. Please enter again to confirm" and it then switches you to the real site. You blissfully proceed, never realizing that the first of those login screens was just some PC in a basement somewhere, harvesting account credentials. Ugh.

Worse, though, are when they're script attacks because then you don't see anything particularly problematic, just a "working" or "confirmed" or similar message. Done. No worries. Right?

Wrong.

Let's dig into this particular attack and you'll see what's going on. And then regret clicking on that link and, yes, it's time to run some antivirus scanner!

First off, here's one of the many bogus Craigslist messages I've received:

Looks pretty legit, doesn't it? Even to the friendly "if you're experiencing problems" section.

I didn't, of course, actually post that I have a screwdriver set for sale. I don't even own a screwdriver set, let alone a "screwdrivers kit". Hmmm....

Moving my cursor over the link reveals what's going on:

The domain "mainart.cn" is most assuredly not a part of Craigslist, so it's very odd. Still, as a scientist, I'll go ahead and click on it anyway, to see what happens.

It takes me to a page that shows this:

The item posting ID is wrong and the name of the item listed is wrong, but that's not the issue. The issue is "what's going on while it says "please wait...?"

As a first step, I simply went to the top level http://www.mainart.cn/ site, which shows this:

It appears to be a service where they make paintings out of photographs. Okay. I'm 99.9% sure that it's a legit business and they have no idea that there's this nefarious code hanging off their site, actually.

The fact that it says "100% Safe" is just irony, I suppose.

Back to the page that the bogus email sent us to, the answer is revealed when I View Source on the page:

Ahhhh.... that is most assuredly not good. Not good at all. The script is obfuscated so it's not easily read (I chopped out about thirty lines of digits, btw) and it's doing something suspicious to any user who is daft enough to click on the link.

Probably, it's a virus being injected into the system.

So while you're waiting for the posting to "load", the page is actually pushing a virus onto your system. Yikes.

I'll say it again, gang. Do not click on links from messages that are even the slightest bit suspicious or odd. It's way too dangerous.

Oh, and you really need to scan your system for viruses. Good luck.


More Useful Computer and Internet Basics Articles:
✔   How do I blur my house on Google Maps Street View?
I was poking around on Google Maps looking at satellite views of my neighborhood and when I switched to street view, was upset...
✔   Create a custom vanity URL for Kickstarter?
I was reading some updates on Twitter and saw someone had posted a URL that would let me see what projects they'd backed...
✔   Export or Save Subscription List from Google Reader?
Just heard that Google Reader is going away this summer. That stinks! How am I supposed to read my RSS feeds? More importantly,...
✔   Shrink or Reduce a Photo File Size on Mac?
I'm trying to upload some photos to a social media site and it's complaining that they're too big. They are, as they come...
✔   Can I organize my Yahoo Mail with folders?
I've been on Yahoo Mail for years and while most of my friends are now on Gmail or their own Web-based email programs,...

Let's stay in touch!
Sign up for my weekly AskDaveTaylor Newsletter and you'll receive even more tech and gadget help right to your inbox, along with exclusive news and industry updates. It's good stuff. I promise!
    Enter your name: and your email addr:  





Categorized: Computer and Internet Basics   (Article 10431, Written by )
Tagged: bad scripts, craigslist, cybercrime, hackers, phishing, script attacks, virus attacks, viruses
Previous: Embed an audio player on a blog or web page?
Next: Reset (reformat) your Amazon Kindle prior to reselling it?




Reader Comments To Date: 3

Scott Ames said, on July 26, 2012 5:28 PM:

Thanks for the info. That's wild.

Brian H said, on July 26, 2012 7:12 PM:

I'm getting to the point where I will never, ever click on a link in an email.

Ken B said, on July 27, 2012 9:28 AM:

While trying to figure out just what the link would do, my anti-virus program (AVG) kept "getting in the way". I suppose that's a good thing the other 99.99% of the time. :-)

Even while trying to access the page from an "unprotected" VM on my system, AVG kicked in on my "real" computer. (I probably should have written down what AVG said the malware was, but I didn't think to do so at the time.)

But, your advice is spot on -- don't click. In a case like this, assuming you even have a Craigslist account, log in to the account the usual way, and then try to find the item in question.

Starbucks coffee cup I do have a lot to say, and questions of my own for that matter, but first I'd like to say thank you, Dave, for all your helpful information by buying you a cup of coffee!

I do have a comment, now that you mention it!











I will never send you any unsolicited email. Ever.






Check This Out Too...

 
Look for Answers
Need Help? Ask Dave Taylor!


Follow Me on Pinterest

Find Me on Google+
ADT on G+
© 2002 - 2013 by Dave Taylor. All Rights Reserved.

Note: This web site is for the purpose of disseminating information for educational purposes, free of charge, for the benefit of all visitors. We take great care to provide quality information. However, we do not guarantee, and accept no legal liability whatsoever arising from or connected to, the accuracy, reliability, currency or completeness of any material contained on this web site or on any linked site. Further, please note that by submitting a question or comment you're agreeing to my terms of service, which are: you relinquish any subsequent rights of ownership to your material by submitting it on this site. My lawyer says "Thanks".
"Ask Dave Taylor®" is a registered trademark of Intuitive Systems, LLC.