logo elektroda
logo elektroda
X
logo elektroda

Suspicious WP Mailbox Page: Redirect to Nowapoczta.wp.pl - Potential Spoof Mail & Data Security

ignacy15 26040 16
ADVERTISEMENT
Treść została przetłumaczona polish » english Zobacz oryginalną wersję tematu
  • #1 16450002
    ignacy15
    Level 14  
    Hello!
    For some time I have noticed that when he logs in to the WP mail account (profil.wp.pl/login) it is automatically redirected to the page named: nowapoczta.wp.pl, which seems to me to be an imperfect spoof mail. Is it possible that someone has caught my data and by logging into this page, someone has access to my e-mails? I will add that they are logging in to another account, there is no problem. I join screen to illustrate the situation,
    I am asking for an answer, thank you in advance! Suspicious WP Mailbox Page: Redirect to Nowapoczta.wp.pl - Potential Spoof Mail & Data Security
  • ADVERTISEMENT
  • #2 16450078
    A.Gieronimo
    Level 35  
    The leased IP address 193.222.135.131 (nowapoczta.wp.pl) is the institution
    organization: ORG-OA19-RIPE
    org-name: o2 Sp. Zoo
    org-type: OTHER
    address: o2 Sp. Zoo
    address: ul. Jutrzenki 177
    address: 02-231 Warsaw

    Some pilot project, even Google does not know this address.
    However, it stinks a bit.
    When I enter the correct data> moves to mail wp
    When not correct> does not report an error only moves to the standard wp login panel.
    To make it even more interesting, after entering the wrong address but with @ wp.pl, I logged in via the last remembered correct address.
    Strange is little said.
    :crazyeyes: :crazyeyes:

    There is also an address in the ripe database
    https://nowy.tlen.pl/
    After entering it, I logged in to an o2 account saved in my browser.
    The stick knows what it is and what it is. :D
  • ADVERTISEMENT
  • #3 16450123
    ignacy15
    Level 14  
    It is worth reporting this incident to the police?
  • ADVERTISEMENT
  • #4 16450135
    Kolobos
    IT specialist
    What do you want to report? Probably something change on wp and this does not apply to all users, therefore, in one account, a new mail is included, and not on others.

    Since this is a subdomain * .wp.pl it's all ok
  • #5 16450185
    ignacy15
    Level 14  
    The problem is that this page does not load correctly and you can not change even the password
  • #6 16450188
    A.Gieronimo
    Level 35  
    Delete the cache in the browser.
    Delete cookies.
    Check the correctness of the DNS server on the computer.
    That's all.
    Nothing happens.
  • #8 16450220
    A.Gieronimo
    Level 35  
    Scanning with the antivirus + MalwareBytes will not hurt.
    Now every third program has a shit stitched up ;) (not necessarily dangerous, but if there will be 20 and one will hit a hole), let's give a toolbar, and the problem is ready.
  • #9 16450226
    ignacy15
    Level 14  
    I wrote to the Polish Army, there is no answer yet. I have scanned the computer, reinstalled the browser and even did the format, but it is the same. It's the same on mobile devices and other computers. Transfer only one account to another page
  • #10 16450232
    A.Gieronimo
    Level 35  
    Probably you've come to the pilot program,
    Which internet provider?
    What router?
    Check DNSs just in case, in the computer and in the router.
  • #11 16450239
    ignacy15
    Level 14  
    But this is not only happening in the router's network. This also happens in other networks on different devices. Only this one wp e-mail account redirects to some suspicious site where you can not even change the password and which is not a very good copy of the original e-mail page. For now, I have changed my e-mail address and on Thursday I go to the command.
  • #12 16450245
    A.Gieronimo
    Level 35  
    NO :) Anyway, go as you like.
    There was something wrong with them in the system.
    What address did you write to?

    The hacker could not:
    - have access to different computers
    - various provajders
    - different networks

    The only option is that the WP itself has something chopped.

    Have you tried to log in from your phone over the GSM network, setting the browser to computer mode? If he moves you too, you have an answer - they are broken up.
  • #13 16450262
    ignacy15
    Level 14  
    I logged on to the site: poczta.wp.pl as always. On this page I log in and the rest of the family. Everyone has a normal access and after logging in they have a standard address: profil.wp.pl and when I log in, it automatically moves me to the page: nowapoczta.wp.pl with a different logo and a different page layout, but similar to the standard wp account. And it does not matter if you log on your computer at home or on the phone in the other part of the city. I noticed this a month ago, but I was concerned about the lack of password change and a link from other users after logging in

    Added after 4 [minutes]:

    If the hacker could not do it, why is it so loudly repeated to pay attention to whether there is any suspicious change in the bank or postal link.
  • #14 16450271
    A.Gieronimo
    Level 35  
    Yes, replacing DNS on your computer or installing fake firmware on the router.
    I said check on the phone via GSM network and not your private WiFi.
  • ADVERTISEMENT
  • #15 16450280
    ignacy15
    Level 14  
    I checked through the GSM network. It's the same. That is, all accounts log in normally and my redirects to the nowapoczta.wp.pl website
  • #16 16478175
    joyl
    Level 2  
    I checked, on one account I log in to newpap. In two other cases, other addresses on the same computer log in normally.
  • #17 16478702
    stanislaw1954
    Level 43  
    I also reported to them several times, among other things, that I mean unwanted "spam" messages, and then in a few days I receive an unwanted message from the same sender. Of course, no response from the novelties.

Topic summary

The discussion revolves around a user experiencing automatic redirection from the WP mail login page (profil.wp.pl/login) to a suspicious site (nowapoczta.wp.pl), raising concerns about potential data security and spoofing. Various responses suggest checking for issues such as DNS settings, browser cache, and cookies. Some users recommend scanning for malware and contacting WP support for assistance. The user reports that the issue persists across different devices and networks, indicating a possible account-specific problem rather than a broader system issue. The conversation highlights the importance of vigilance regarding email security and potential phishing attempts.
Summary generated by the language model.
ADVERTISEMENT