• The Forums are now open to new registrations, adverts are also being de-tuned.

"The AMG Brabus Collection" in Sturminster Newton

Engadine

Active Member
Joined
Jan 3, 2021
Messages
370
Location
London
Car
2022 C63S Brabus 600 cabrio; 2013 C63 Estate (RIP)
Surely a case of trademark infringement? These guys call themselves the AMG Brabus Collection and pop up when you search for AMG or Brabus on Pistonheads. They even use imitation logos. They currently have 5 old AMGs in stock. I have never seen a Brabus in stock there.

 
Surely a case of trademark infringement? These guys call themselves the AMG Brabus Collection and pop up when you search for AMG or Brabus on Pistonheads. They even use imitation logos. They currently have 5 old AMGs in stock. I have never seen a Brabus in stock there.

Not too switched on this dealer, contact page states Sturminster Newton in Devon???
 
Dorset according to Google maps but in the description it does say North Dorset, maybe he's lost.
 
Quite a few miles from the Devon Border so def in Dorset....its actually nearer Somerset than Devon.
 
Yes he's lost and also somehow doesn't have a landline, only two mobiles, despite having service facilities on the premises etc. I wonder if he moves to Devon if you have a complaint.
 
Maybe when he shifts one of those AMGs he'll be able to afford an SSL certificate for his website.
 
Maybe when he shifts one of those AMGs he'll be able to afford an SSL certificate for his website.
Jeeeeez, good point. They're actually free these days, no excuse for no SSL/HTTPS on a website anymore.
 
Jeeeeez, good point. They're actually free these days, no excuse for no SSL/HTTPS on a website anymore.
Yep, I'm an IT Consultant and it makes my teeth itch when I see things like this. He should have one, especially as he has a contact form and is potentially handling personal information.
 
Yep, I'm an IT Consultant and it makes my teeth itch when I see things like this. He should have one, especially as he has a contact form and is potentially handling personal information.
Ditto... I imagine then, like me, you think the same thing when you see "[email protected]" across the side of vans and shops?!
 
Ditto... I imagine then, like me, you think the same thing when you see "[email protected]" across the side of vans and shops?!
I remember Geocities and people had their default Geocities URL scrawled across their vans etc. Looked awful.
 
Jeeeeez, good point. They're actually free these days, no excuse for no SSL/HTTPS on a website anymore.
Who are doing free SSL certificates?
 
I stayed at the Plumber Manor Hotel in Sturminster Newton in June, a fabulous country retreat :)

It's very rural and there's not much else there apart from farms, where the business appears to be based. No wonder the stock is all knocking on 20 years old...
 
Zero protection from spoofing, which I think is a worry.

What we see in very significant volumes at the moment (globally, not just UK) is threat-actors using fairly basic credential phishing attacks/brute force attacks to compromise ill-defended user accounts.

An example of how this would work here would be that the threat-actor successfully compromises a user account at the AMG Brabus Collection, our research shows that within 30 seconds the account will have been accessed and searched for any financial interaction - search terms being run such as 'account', 'payment', 'invoice' and so forth are the very first actions we see in most compromised accounts.

In this case if ABC are selling cars the threat-actor would find conversations where the deposit has been paid but not the balance.

Next action the threat-actor takes is to send an email to the person buying the car spoofing the actual domain, with either a convincing look-alike (or more commonly for low value attacks) just a throw-away address in the reply-to.

This email would have the previous exchanges in the conversation pasted into it, would be put into the thread as a genuine reply, and would likely pass inspection - and would ask the buyer to send the balance to a different account (if details already provided) or would ask for the balance via bank transfer to a specific account (if not).

Buyer transfers the balance, a few days later they turn up at ABC to collect their car - but of course they've not paid for it.
 

Users who are viewing this thread

Back
Top Bottom