Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Incidents
[Top] [All Lists]

Re: New Phishing Technique?

Subject: Re: New Phishing Technique?
Date: Fri, 17 Mar 2006 20:49:10 -0500
On Fri, 17 Mar 2006 14:59:39 EST, Mace.Scott@tatravelcenters.com said:
A couple of phishing emails got through our spamassasin/clamav filter here 
at work, and through to my gmail account, damn near simultaneously.  Both 
with very different text, and different urls.  Now clamav is generally 
very capable of stopping phishing attacks, so I'm surprised these made it 
through.  More interesting, is the fact one got through Gmail as well. And 
it's very obvious a phish.  Here's the text of the email (I added 11111 to 
the end of the url to guard against accidental clicking):
 Incidentally, Lotus Notes complains of an untrusted certificate when the 
email is opened.


Dear Chase account holder,

Looks like a pretty stock phish to me.  It would have helped immensely if you
had posted the original as you received it, complete with any obfuscating
Javascript/etc, so we could figure out how it managed to get through.

If you're worried about posting it to the list, forward it directly to me
(preferably as a message/rfc822 attachment with all the headers and all) and
I'll forward it to the appropriate people who are chasing down phishes.

Attachment: pgpJAMFRPHEN6.pgp
Description: PGP signature

<Prev in Thread] Current Thread [Next in Thread>