• Feed

  • « | Main | »

    Spam from Microsoft Live

    By maurizio | October 7, 2007

    Today I’m too lazy to check if I’m right or wrong so let me know if I am wrong. Let me know if I’m right too…I like feedback. :-)

    Anyway the thing is that I’ve received an email from “Microsoft”

    We received your request to reset your Windows Live password

    Uhm. very suspect. A txt email from Microsoft? Why not the usual superbig html page? Let’s go on..

    If you didn’t request that your password be reset, please follow the instructions below to cancel your request.

    Phishing alert N.1! Why Microsoft should create a sequence of operations for something so dumb? If I haven’t requested it, just forget it after a while as 99.999% of other sites does. Ok, Microsoft is able to create braindead things to do, but not this time IMHO.

    IMPORTANT: Because fraudulent (“phishing”) e-mail often uses misleading links, Microsoft recommends that you do not click links in e-mail, but instead copy and paste them into your browsers, as described above.

    Nice suggestion! That could solve half of the phishing problem. Most of the phishing attempt can be solved this way because the “trick” is inside the mail, but you can have “phishing tricks” on the site too. (Check my post about Paypal spam to see what’s a “phishing email trick”). The suggestion is useless for this email because it’s plain and simple text without any kind of html or javascript on it.

    Copy the following web address:

    https://accountservices.msn.com/EmailPage.srf?emailid=50ace34168ea8a4

    This is the tricky part. I do not use Live a lot (I’m not even sure if I’m registered with the email I’ve received the spam on) but I can imagine that the problem lies on the way Microsoft want to use soo much their users.
    Microsoft is probably offering the possibility to let users send email with Urls on it. I don’t want to check, but if you have an account on Live, just look for an option that allow you to send an email with the link of the page you are watching.

    That option will probably create a long link with a unreadable url starting with a Microsoft’ server as the link I’ve copied above.

    That’s it! You have a link for a Microsoft service with a Microsoft url. Of course the page they link are just copies of the real Microsoft pages. In fact if you dare to open them, you’ll see the link below (“Privacy”, etc.) that point to some strange urls, always on live. The thing is that those pages are on Users’ Accounts! Look at them.

    I don’t think I’m wrong but I’d like to hear if other people got the same emails.

    Topics: Ramblings | 7 Comments »

    Read other related posts:

  • Akismet Spam
  • Blogger need help. Too much spam
  • Yahoo’s spam from Malaysia
  • 7 Responses to “Spam from Microsoft Live”

    1. Crazygamer Says: MyAvatars 0.2
      October 7th, 2007 at 8:11 am

      I actually got this same message when I DID request to reset my password

      I didn’t click it, of course, but I assume it isn’t of any harm

    2. maurizio Says: MyAvatars 0.2
      October 7th, 2007 at 11:20 pm

      Could you please send me a copy of it? Trust me I will just open the link without clicking anywhere. Or just check for yourself the 3-4 small links at the bottom of the page and see where they point to.

    3. Annie Says: MyAvatars 0.2
      November 17th, 2007 at 12:08 am

      Yes… I have received it and it is definitely Phishing. Watch “The Game” when Michael Douglass is tricked into calling a fake number for his Swiss Bank Account and the people on that line ask for his password while someone is sitting next to him in the car. It’s the same idea.

      If any of “your” real services want you to change your password… just let the email serve as a reminder… and then go to the website the way you would normally go to the website. Never click on or “copy/paste” any link that looks “kind of” like the one you normally go to. Some links display EXACTLY like your link because the text displayed doesn’t have to match the link that it actually sends you to.

      Anyway… the message specified in this post was a phishing message.

      :) Good luck

    4. Laura Says: MyAvatars 0.2
      January 19th, 2009 at 1:02 am

      I’ve just received this mail. Actually it’s the third time this week that I receive it. I read your posts and they confirm my idea that it’s phishing…and…I never asked for resetting my password!
      thanks guys,
      La

    5. AA Says: MyAvatars 0.2
      December 7th, 2009 at 9:42 am

      I just received the same several emails this week so this is either still going around or is fake.

      These are the two questions that come to mind.

      1. If I am logged into my email and see this email, why would I need my password reset (as I must know what it is currently)?

      2. If I can not log in and I need my password reset, then why would I be sent an email since I could never read it without being logged in?

      It’s very simple to change your password. It didn’t say that someone made a request and if you want to do this, then go here. Normally it would say if this was not you, then ignore the email as the request will not be valid after like 48 hours.

      This sounds really fishy..

      AA

    6. Aussie Pete Says: MyAvatars 0.2
      December 28th, 2009 at 8:32 am

      I’ve received repeated copies of this email over the last week. Even the link is exactly the same. I guess someones finding a way to make money off it since it’s still going!!

    7. Sergey Says: MyAvatars 0.2
      February 5th, 2010 at 10:48 pm

      The same thing, I’m still getting emails with reset request (but I actually never requested for it, like all of you). I have a different link for reset, and my reset link and cancel reset link have only 1 symbol difference. I’m currently trying to contact Microsoft and avoid any further possibilities of this “phishing” trick.

    Comments

    Subscribe without commenting