Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: domain slamming(?) |
|---|---|
| Date: | Thu, 21 Dec 2006 22:16:28 -0600 |
Edmund,
Hope this helps anyone else on the list.
Bob Jones,
Dear All,
Awhile back, I received an e-mail and fax from this guy supposedly representing this CNNIC accredited registrar stating (along the lines of an unnamed Mainland China company submitting an application to register some Internet Keywords and chinese domain name using my company's (the company that I work for) English and Chinese name. The guy even faxed a 'certificate of authorization' to me to 'prove' that his company was accredited. (This supposed certificate, which I haven't bothered verifying its authentication, looks quite 'legit-like'. (think: Photoshop))
The letter appeared very 'urgent' and required 'immediate' attention. (Reminds me of Nigerian Scams, btw). I got a few responses here but thought the better of it and ignored the guy completely. He called and I just said we weren't interested.
Well, just recently another guy from the same 'accredited' registrar called (and faxed) about another company (sister company to the first one). Again. Same M.O.
I did a search and came up with the following site:
http://www.legitiname.com/article.php3?id_article=152
The M.O. in the 'sample' letter in this site is similar to the one I received, including the wanton sprinkling of the CNNIC name in the letter.
While I doubt anyone in Europe or North America will have any troubles with this CNNIC issue(unless your company's thinking of moving into the Chinese market), it is still worth paying attention how 'time-pressure' tactics work. To be truthful, I nearly did get fooled by the initial letter; that is, until I read carefully and thought about it more.
So, the aforementioned site does makes a good suggestion. Don't Panic. Even if the letter gives the impression that it's a do-or-die situation, calm down and think.
Edmund
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: [FDE] How important is FIPS 140-2 Level 1 cert?, dan |
|---|---|
| Next by Date: | Suspicious network activity advice, infinite_uk |
| Previous by Thread: | domain slamming(?), cc |
| Next by Thread: | How important is FIPS 140-2 Level 1 cert?, Saqib Ali |
| Indexes: | [Date] [Thread] [Top] [All Lists] |