Phishing In The Channel
Rick Zeman writes "A Washington Post story details the relationships between phishers, IRC, plug-and-play phishing toolkits, and phantom web sites. 'For the past few months we've started to see phishing attacks from subcontractors, people who buy and use ready-made phishing toolkits and e-mail lists,' Orad said. 'It's gotten to the point where you don't need to know anything about spamming or computer programming to pull this off.'"
So, this is nothing new and people are still naive. Hopefully, though, the more it hits peoples back-pocket then more savvy they will get.
DAMN YOU OCTODOG! DAMN YOU TO HELL!
While it has become easier for phishers (and now apparently nonphishers) to prey upon mom and pop internet surfer, it still comes down to personal security. Mom and pop internet surfer won't give their ATM pin or their credit card number to a guy on the street but for some reason, the authority of the Internet removes those safeguards.
Next time you see your parents or someone who is a likely phishing canidate, please, don't roll your eyes. Warn them and try to explain the difference.
-Teiresias
Typically a phisher takes advantage of the IE exploit to fake the URL also, so a vulnerable user thinks they are at a legit URL.
Got an email client which displays HTML email or launches a browser to handle it? I get many spoofs of paypal, ebay and various banks each day, HTML constructed to pull images from valid sources or a coopted server somewhere in the world, which look exactly like or reasonable enough to the untrained to fool you into entering account numbers, passwords, etc., which are actually intercepted and emailed to a box somewhere in the world. Phishers usually just hang around long enough to collect a few ID's and scram.
A feeling of having made the same mistake before: Deja Foobar
Bernstein warns about this. It seems like it's going to happen anyway.
Anybody know of registrars processing punycode registrations?
My God, it's Full of Source!
OUTSIDE_IP=$(dig +short my.ip @outsideip.net)
It doesn't even have to be that complicated... typically the URL in the email is "correct" but the underlying link is to another site....most lusers never look at the address in the status bar. /. puts the domain in brackets after the link.
http://www.ebay.com/
This is why
$7.95/mo, 200 GB disk, 2TBxfer, MySQL, PHP, RoR.
...as quoted from Lock, Stock and Two Smoking Barrels (1998).
you'll look like less of a punk if you cite your references.
GET YOUR WEAPONS READY! --DR.LIGHT