Notices
Non Scooby Related Anything Non-Scooby related

I don't even bank at Barclays!

Thread Tools
 
Search this Thread
 
Old 08 February 2006, 11:18 PM
  #1  
pslewis
Scooby Regular
Thread Starter
 
pslewis's Avatar
 
Join Date: Jun 2000
Location: Old Codgers Home
Posts: 32,398
Likes: 0
Received 1 Like on 1 Post
Angry I don't even bank at Barclays!

Dear Sir/Madam,
Barclays is proud to announce their new iBank upgrade.
We have updated our new iBank SSL secure servers to give our
customers a better, faster and more secure online banking
services for the year 2006.

Due to the recent update of the servers, you are requested to
update your account using the following link:

http://ibank.barclays.co.uk..............LoginMember.do


J.S. Smith
Security Advisor
Barclays Bank PLC.
Old 08 February 2006, 11:21 PM
  #2  
Scudy23
Scooby Regular
iTrader: (2)
 
Scudy23's Avatar
 
Join Date: Dec 2005
Location: South Wales
Posts: 1,262
Likes: 0
Received 0 Likes on 0 Posts
Default

If it was emailed m8 i wouldnt even bother with it..... so many tw@ts on the net trying to rip you off
Old 08 February 2006, 11:23 PM
  #3  
Moonloops
Scooby Regular
 
Moonloops's Avatar
 
Join Date: Jan 2006
Location: Gone Away
Posts: 1,711
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by Scudy23
If it was emailed m8 i wouldnt even bother with it..... so many tw@ts on the net trying to rip you off
He knows that..
Old 08 February 2006, 11:24 PM
  #4  
Richard_P
Scooby Regular
 
Richard_P's Avatar
 
Join Date: Jan 2004
Posts: 649
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by Scudy23
If it was emailed m8 i wouldnt even bother with it..... so many tw@ts on the net trying to rip you off
It's not a possibiity of a scam. It is one!
Old 08 February 2006, 11:29 PM
  #5  
Scudy23
Scooby Regular
iTrader: (2)
 
Scudy23's Avatar
 
Join Date: Dec 2005
Location: South Wales
Posts: 1,262
Likes: 0
Received 0 Likes on 0 Posts
Default

You guys were waiting for some plonker to responde first werent you ..lol.
Old 08 February 2006, 11:32 PM
  #6  
Scooby-Doo
Scooby Regular
 
Scooby-Doo's Avatar
 
Join Date: Oct 2001
Location: X5 and MCS JCW country....London :)
Posts: 2,223
Likes: 0
Received 0 Likes on 0 Posts
Default

Are you sure it was from Barclays and not Mazda trying to sell you an MG
Old 08 February 2006, 11:34 PM
  #7  
2000TLondon
Scooby Regular
 
2000TLondon's Avatar
 
Join Date: Feb 2004
Location: Texas - It's BIG!
Posts: 2,105
Likes: 0
Received 0 Likes on 0 Posts
Default

Well, it's actually written in plausible English!

I've been getting them from Chase Manhattan, usually the author has the same grasp on the English language as a three year old! A poorly educated three year old at that!
Old 09 February 2006, 01:19 AM
  #8  
fast bloke
Scooby Regular
 
fast bloke's Avatar
 
Join Date: Nov 2000
Posts: 26,619
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by Scudy23
If it was emailed m8 i wouldnt even bother with it..... so many tw@ts on the net trying to rip you off
Haven't read the link but sounds like more new labia stuff?..... people trying to rip you off?
Old 09 February 2006, 08:15 AM
  #9  
pslewis
Scooby Regular
Thread Starter
 
pslewis's Avatar
 
Join Date: Jun 2000
Location: Old Codgers Home
Posts: 32,398
Likes: 0
Received 1 Like on 1 Post
Default

Originally Posted by fast bloke
Haven't read the link but sounds like more new labia stuff?..... people trying to rip you off?
Thats right ......... people only starting ripping other people off when New Labour became the most successful government in living memory

Pete
Old 09 February 2006, 08:37 AM
  #10  
GrahamG
Scooby Regular
 
GrahamG's Avatar
 
Join Date: Sep 2005
Location: Hunting for my next Impreza!
Posts: 2,388
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by pslewis
Dear Sir/Madam,
Barclays is proud to announce their new iBank upgrade.
We have updated our new iBank SSL secure servers to give our
customers a better, faster and more secure online banking
services for the year 2006.

Due to the recent update of the servers, you are requested to
update your account using the following link:

http://ibank.barclays.co.uk..............LoginMember.do


J.S. Smith
Security Advisor
Barclays Bank PLC.
I like the way you were contacted by the Security advisor. they are taking the ****! Bloody Nigerians!!!
Old 09 February 2006, 08:51 AM
  #11  
douglasb
Scooby Regular
 
douglasb's Avatar
 
Join Date: Jun 2003
Location: use the Marauder's Map to find out.
Posts: 2,041
Likes: 0
Received 0 Likes on 0 Posts
Default

Your Alzheimers is kicking in again,Pete.. You were reminded a couple of days ago just how unsuccessful your hero Tony and his cronies are.
Old 09 February 2006, 08:55 AM
  #12  
Crapaud62
Scooby Regular
 
Crapaud62's Avatar
 
Join Date: May 2001
Posts: 4,228
Likes: 0
Received 0 Likes on 0 Posts
Default

Not sure if this is a double bluff by PSL but the link IS a genuine Barclays link.

If you actually go into the link without the ....... it takes you to the main site.

Am I missing an "in joke" here?

Now if it has been sent to a non-BArclays customer then agreed that is a security issue.

NB did I mention that I work for Barclays Compliance Dept?

Would be very interested in exact email address of sender of message to PSL and full web link given without the .......

PSL, please pm if you wish. (Unless you were just trolling and I've bitten cos it is early in the morning). I can soon find out who J S Smith is but I doubt very much he is Nigerian.
Old 09 February 2006, 09:52 AM
  #13  
Chris L
Scooby Regular
 
Chris L's Avatar
 
Join Date: May 2000
Location: MY00,MY01,RX-8, Alfa 147 & Focus ST :-)
Posts: 10,371
Likes: 0
Received 0 Likes on 0 Posts
Default

It's not genuine - they could have easily ripped the graphics and layout from the official site.

The give away is in the URL posted up. The message says they are using SSL (which is a form of secure encrypted connection), yet the URL starts 'http', when it should be 'https' ('s' as in 'secure'). Goto the official Barclays site and click 'logon' for their online banking service and you'll see what I mean.

Chris
Old 09 February 2006, 09:59 AM
  #14  
Peanuts
Scooby Regular
iTrader: (15)
 
Peanuts's Avatar
 
Join Date: Jul 2001
Location: Portsmouth
Posts: 8,606
Likes: 0
Received 0 Likes on 0 Posts
Default

must be pretty good then to catch out a Barclays employee!
Old 09 February 2006, 10:27 AM
  #15  
scooby_matt
Scooby Regular
 
scooby_matt's Avatar
 
Join Date: Jun 2005
Posts: 1,938
Likes: 0
Received 0 Likes on 0 Posts
Default

I been getting these type of emails from Barclays for months now. Just recently started getting them from the Halifax. I've never banked with either
Old 09 February 2006, 11:26 AM
  #16  
Chris L
Scooby Regular
 
Chris L's Avatar
 
Join Date: May 2000
Location: MY00,MY01,RX-8, Alfa 147 & Focus ST :-)
Posts: 10,371
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by Peanuts
must be pretty good then to catch out a Barclays employee!
We do a lot of social engineering attacks (I work for an IT security consultancy) - we've even gone as far as to do build fake websites and register similar looking domain names - you'd be amazed at how easy it is to be fooled by this stuff. 99% of people simply don't know what to look for and are far too trusting. Never let anyone tell you that IT security is a technical issue - it isn't - it's a people issue
Old 09 February 2006, 11:52 AM
  #17  
stevencotton
Scooby Regular
 
stevencotton's Avatar
 
Join Date: Jan 2001
Location: behind twin turbos
Posts: 2,710
Likes: 0
Received 1 Like on 1 Post
Default

Originally Posted by Chris L
Never let anyone tell you that IT security is a technical issue - it isn't - it's a people issue
Too right, I've even been the 'mark' of a social engineer calling me up and
asking me questions about things he shouldn't have been asking, gave a false
name and number when I asked to call him back, quite amusing
Old 09 February 2006, 12:45 PM
  #18  
Chris L
Scooby Regular
 
Chris L's Avatar
 
Join Date: May 2000
Location: MY00,MY01,RX-8, Alfa 147 & Focus ST :-)
Posts: 10,371
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by stevencotton
Too right, I've even been the 'mark' of a social engineer calling me up and
asking me questions about things he shouldn't have been asking, gave a false
name and number when I asked to call him back, quite amusing
It wasn't me honest
Old 09 February 2006, 04:38 PM
  #19  
Crapaud62
Scooby Regular
 
Crapaud62's Avatar
 
Join Date: May 2001
Posts: 4,228
Likes: 0
Received 0 Likes on 0 Posts
Default

Chris L and others

Interesting

When I cut and pasted the original link as shown on PSL's post it obviously doesn't open due to the ........

When I edited it back to just the http://ibank.barclays.co.uk and then hit enter again it then takes me to the httpS site of "Barclays". It then defaults to the Barclays site login at https://ibank.barclays.co.uk/olb/q/LoginMember.do
which appears to be the same as what PSL posted apart from it shows as https rather than http.

Now I'm confused?

Could be because:

It was early in the morning and was not fully awake or

I had the "real" Barclays sites already open on other windows on my PC, or

I'm a stupid **** who knows nothing about websites and hence I worked in Compliance and not IT

HOWEVER, if you follow the link above and click on the "online security" it opens another window. This window is "only" http but includes examples of scam emails including ones coming from J S Smith Security Advisor.

I would be very interested if the IT experts on here could explain to a non IT muppet like me how this appears to fluctuate between obviously fake sites and sites that appear, with the https prefix, to be genuine?

Why would a scammer include an example of his own scam emails???

Part of the problem is that Barclays recently changed the whole appearance of their online banking but didn't think to tell any of their customers. Consequently, they were flooded with calls asking if the new version was genuine as nobody recognised it and many people were suspicious. Barclays got fed up of telling everyone that the site had been changed and it was all OK. Obviously, some enterprising IT geek/nigerian/scammer probably realised that this was a great opportunity to take advantage of Barclays dreadful IT change management?

For a lay man, what is best way to interrogate a web site to test its validity?
The https is obvious but as noted above, this one defaulted to that prefix.
Old 09 February 2006, 05:17 PM
  #20  
Chris L
Scooby Regular
 
Chris L's Avatar
 
Join Date: May 2000
Location: MY00,MY01,RX-8, Alfa 147 & Focus ST :-)
Posts: 10,371
Likes: 0
Received 0 Likes on 0 Posts
Default

I would have to have a look through to be sure - from what you've said. Simple rule of thumb is that no financial organisation will ever send you an email request to input or change both your username and password in this way. Treat EVERY email you receive like this as dodgy and delete them.
Old 09 February 2006, 05:43 PM
  #21  
Mungo
Scooby Regular
 
Mungo's Avatar
 
Join Date: Apr 2000
Location: West Byfleet, Surrey
Posts: 1,653
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by 2000TLondon
Well, it's actually written in plausible English!

I've been getting them from Chase Manhattan, usually the author has the same grasp on the English language as a three year old! A poorly educated three year old at that!
Who haven't been known as that for about 5 years!
Old 09 February 2006, 05:55 PM
  #22  
Scooby-Doo
Scooby Regular
 
Scooby-Doo's Avatar
 
Join Date: Oct 2001
Location: X5 and MCS JCW country....London :)
Posts: 2,223
Likes: 0
Received 0 Likes on 0 Posts
Default

It is quite easy for the address in the address bar to be fake and you are actually taken to an alternative site that has no connection with the address in the address bar. Even if it says www.barclays.com you are probably going to www.givemeallyourmoney.com Never goto a financial website from a link ALWAYS type it in.
Old 10 February 2006, 12:57 AM
  #23  
Trout
Scooby Regular
iTrader: (1)
 
Trout's Avatar
 
Join Date: Jan 1999
Location: UK
Posts: 15,271
Likes: 0
Received 0 Likes on 0 Posts
Default

I have had dodgy emails that have links that 'look' right and if you cut and paste them take you to the original and genuine site. However the 'hyperlink' in the actual email takes you to the dodgy site.

It could well be that PSL cut and paste and so it is taking you to the genuine site. I had exactly the same thing when I pasted an PayPal dodgy mail on here - when people went to look it went to the PayPal site. In the email it did not

Always type the link in yourself - the PayPal clone was perfect - except it wanted just too much information.

I love to fill in details including addresses of DisneyWorld and InYourDreams as well as well chosen Celtic and Saxon words!
Old 10 February 2006, 08:37 AM
  #24  
pslewis
Scooby Regular
Thread Starter
 
pslewis's Avatar
 
Join Date: Jun 2000
Location: Old Codgers Home
Posts: 32,398
Likes: 0
Received 1 Like on 1 Post
Default

Originally Posted by Rannoch
I have had dodgy emails that have links that 'look' right and if you cut and paste them take you to the original and genuine site. However the 'hyperlink' in the actual email takes you to the dodgy site.

It could well be that PSL cut and paste and so it is taking you to the genuine site. I had exactly the same thing when I pasted an PayPal dodgy mail on here - when people went to look it went to the PayPal site. In the email it did not

Always type the link in yourself - the PayPal clone was perfect - except it wanted just too much information.

I love to fill in details including addresses of DisneyWorld and InYourDreams as well as well chosen Celtic and Saxon words!
I cut and pasted the e-mail content in full as I received it. I removed the central part of the URL only (to stop anyone clicking on it and being directed to the site - if anyone on here is like me, you will have numerous windows open - someone may have been online banking with Barclays, I didn't want them getting the wrong window and compromising themeselves)

But I certainly did not alter the URL other than deleting a central section.

Pete
Old 10 February 2006, 08:40 AM
  #25  
SJ_Skyline
Scooby Senior
 
SJ_Skyline's Avatar
 
Join Date: Apr 2002
Location: Limbo
Posts: 21,922
Likes: 0
Received 1 Like on 1 Post
Talking

Originally Posted by pslewis
if anyone on here is like me, you will have numerous windows open
I would close them now Pete, it's cold outside and we wouldn't want you catching a cold in your frail condition.
Old 10 February 2006, 09:04 AM
  #26  
ChrisB
Moderator
 
ChrisB's Avatar
 
Join Date: Dec 1998
Location: Staffs
Posts: 23,573
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by pslewis
if anyone on here is like me, you will have numerous windows open Pete
That's rife for a cross site scripting attack then.
Old 10 February 2006, 09:32 AM
  #27  
Crapaud62
Scooby Regular
 
Crapaud62's Avatar
 
Join Date: May 2001
Posts: 4,228
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by ChrisB
That's rife for a cross site scripting attack then.
Whats one of them then??

As I said I did have several other windows open including genuine Barclays online ones.

Thanks for sensible reply PSL.
Old 10 February 2006, 06:54 PM
  #28  
pslewis
Scooby Regular
Thread Starter
 
pslewis's Avatar
 
Join Date: Jun 2000
Location: Old Codgers Home
Posts: 32,398
Likes: 0
Received 1 Like on 1 Post
Default

Originally Posted by Crapaud62
Thanks for sensible reply PSL.
Normal Service

Pete
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
KAS35RSTI
Subaru
27
04 November 2021 07:12 PM
JTaylor
Non Scooby Related
202
25 December 2016 09:14 AM
FuZzBoM
Wheels, Tyres & Brakes
16
04 October 2015 09:49 PM
thunder8
General Technical
0
01 October 2015 09:13 PM
mistermexican
General Technical
2
01 October 2015 04:30 PM



Quick Reply: I don't even bank at Barclays!



All times are GMT +1. The time now is 03:47 AM.