TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Ask HN: Tracking down fake Airbnb owner

8 pointsby asdojasdosadsaabout 5 years ago
Case: Not so technical colleague got scammed for 2 months rent. What can he do?<p>Steps: 1. He found apartment listing on immobiliare.it<p>2. Some emails were exchanged<p>3. He receives the link to the _real_ airbnb listing<p>4. He cant find it there, and the scammer sends the phishing page[1] (from @expertdesigner.eu)<p>5. Soon after he receives another email saying that the database is down from @airbnb.sa.com and he should meanwhile move the money using transferwise.com<p>6. Payment done<p>7. Scammer replies: Payment received<p>The login page was quite well made, and I think most of non technical people might get fooled<p>[1] The URL: https:&#x2F;&#x2F;airbnb.com-itinerary.app&#x2F;rooms&#x2F;762837232&#x2F;files&#x2F;login.php?id=572465&amp;locale=en&amp;sale=203&amp;<p>Thoughts?

5 comments

gus_massaabout 5 years ago
The title is slightly confusing. Note that it is a ((fake Airbnb) owner), not a (fake (Airbnb owner)).
评论 #22503748 未加载
nwsmabout 5 years ago
I don&#x27;t have any advice but I hope they are able to recover their money. Shitty people like that are why some US states like Massachusetts now require all renters to find apartments through a registered broker. Sounds nice and safe but it ended up in me paying 4 months rent to get a new apartment. (2 months rent + security deposit + broker fee which was over a month&#x27;s rent)
dfyrabout 5 years ago
There&#x27;s more to it, more php machinery, but in short:<p><i></i> Basic Info<p>- username at home dir: comitin1 - LiteSpeed server - SERVER_ADMIN=webmaster@airbnb.com-itinerary.app - English not first language<p>- Sends over location, victim ip-port pair, protocol, client, TLS encryption suite<p><i></i> Client (Victim):<p>From main.html:<p>POST &#x2F;transaction.php?id=1 --&gt; transaction.html<p>POST &#x2F;transaction-process.php --&gt; attacker no longer cares...empty response body<p><i></i> Admin<p><a href="https:&#x2F;&#x2F;airbnb.com-itinerary.app&#x2F;rooms&#x2F;762837232&#x2F;files&#x2F;management&#x2F;" rel="nofollow">https:&#x2F;&#x2F;airbnb.com-itinerary.app&#x2F;rooms&#x2F;762837232&#x2F;files&#x2F;manag...</a><p>Login with POST &#x2F;index.php with username and password<p>There is a whole interface for easy management of properties, with its own UI! It does proper client and server-side validation of inputs, uses a set of images of houses and hosters.<p>POST &#x2F;process-data.php<p>POST &#x2F;send-discount.php for a particular property id<p>POST &#x2F;edit-discount-process.php
sonicxxgabout 5 years ago
Is &quot;Not so technical&quot; euphemism for naive? This sucks, but also seems like a low effort scam.
评论 #22504117 未加载
philpemabout 5 years ago
This is gonna sound a bit granny-suck-eggs... but I hope your friend reported it to the police?
评论 #22503245 未加载