ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Fraudulent e-commerce site proves hard to close

Rupert Goodwins ZDNet.co.uk

Published: 01 Dec 2003 17:50 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A Web site that purportedly offers cheap mobile phones is still online more than six weeks after efforts began to close it down for what is believed to be fraudulent activity.

The site, unlockedPhones-UK.com, has been discovered to be displaying fake security certificates from security companies VeriSign and TRUSTe, and is using the address of an unconnected legitimate UK mobile phone company called mPhone Ltd. UnlockedPhones-uk.com is not registered as a UK company.

MPhone said it had been aware of the fake Web site for a month and a half, but despite reporting it to the Metropolitan Police -- who said that the FBI would be informed -- and Yahoo, the company hosting the site on its $8.95 a month Premium Geocities services, it had been unable to either get the site taken down or to get in contact with the registered owner. "All the authorities are trying to track them down, and we are working very hard on it," said a source within mPhone. "We're getting so many phone calls it's not funny."

The fake site uses a succession of tricks to disguise its lack of authenticity. Clicking on the VeriSign seal brings up an apparently valid certificate registered to the non-existent company and produced by VeriSign's own computers. However, the certificate is generated by the fraudulent site itself, and the credit card checkout system is hosted on a different site with a valid certificate. Also, the Web site asks for credit card orders to be accompanied by a fax of both sides of the card.

Emails to the contact address went unanswered on Monday, and the Californian address and phone number of the registered domain administrator R. B. Nail apparently are not valid.

"They've basically ripped off our site seal and hosted it on their Web site. In normal circumstances, if they were hosting the checkout on the same site, they'd get a security error, but they're hosting it on another," said John Kerr of VeriSign UK. "Users should double-click on the yellow padlock icon on the bottom right of their browser screen when they're in the checkout, and make sure the name displayed there matches the company you're buying from."

Public speculation over the authenticity of the site began in an online forum when some potential buyers questioned whether the prices were too good to be true. Suspicion was heightened when it was discovered that the gold VeriSign seal, which e-commerce sites display to assure buyers that they have been issued a VeriSign Secure Server ID and which should give some measure of the authenticity of the site, is hosted on unlockedPhones-UK.com's own Web site. When a VeriSign seal is clicked on, it should open up a window displaying the url: https://digitalid.verisign.com. On unlockedPhones-UK.com, the page displayed by the fake Verisign seal is made to look as though it is hosted on Verisign's servers. The fake TRUSTe certificate, which would be hosted on that company's site if it were genuine, is also hosted on unlockedPhones-UK.com's site.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
53 out of 122 people found this useful


Company/Topic Alerts

Create a new alert from the list below:




Related Jobs

Project Manager, Smart Card Ticketing

Key Requirements: Extensive experience of working in transport ticketing systems Experience of tickets and fare systems Familiarisation of ITSO, HOPS ...

Lead Engineer- Linux (RHCE, SQL, PERL)

Engaging with their customers on a daily basis through phone, face to face, email and ticket contact, the Lead Engineers excel in creating great ...

Service Desk Engineer / 1st Line Support - London

Wavex currently offers a range of services from managed services to individual technical solutions such as hosting and co-location, infrastructure ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Facebook Bans Firefox 3

Ok this is the issue. Because I dared to try and access facebook with firefox 3, and all the cookies disabled, it won't let me back on there with firefox ever again, even though... More

1 comment

GoDaddy suspends travel-getaways.com d...

I'm very pleased to say that GoDaddy has suspended the travel-getaways.com domain. I blogged in June that to my surprise I had found I was the site administrator for travel-getaways.com,... More

1 comment

Hello, I知 a PC. I知 a Handheld.

Hello, I知 a PC. I知 a Handheld. Author: Eric Everson, Founder MyMobiSafe.com I have said it before and I am sure I値l say it again, mobile devices are simply replacing computers.... More

Post a comment