{Virus} new phishing (fwd)

Peter Peters p.g.m.peters at utwente.nl
Wed Dec 1 13:46:56 GMT 2004


On Wed, 1 Dec 2004 12:57:54 +0100, you wrote:

>On my system too, but only antivir found a infection not f-prot.

I didn't have any virus. But I included an IP address from a phishing
spam.

|It seems phishers read or use MailScanner. Instead of <a
|href="http://x.x.x.x/s">www.your-favorite-bank.com</a> they start
|using <a href="http://x.x.x.x/s">signon</a>. And the phishing test
|doesn't recognize this one.
|
|Some people suggested inserting an ALT with something like "The host
|http://x.x.x.x/s, is a numerical IP address; most legitimate sites
|use names not addresses."
|
|Would this be possible?

I replaced the IP-address.

--
Peter Peters, senior netwerkbeheerder
Dienst Informatietechnologie, Bibliotheek en Educatie (ITBE)
Universiteit Twente,  Postbus 217,  7500 AE  Enschede
telefoon: 053 - 489 2301, fax: 053 - 489 2383, http://www.utwente.nl/itbe

------------------------ MailScanner list ------------------------
To unsubscribe, email jiscmail at jiscmail.ac.uk with the words:
'leave mailscanner' in the body of the email.
Before posting, read the MAQ (http://www.mailscanner.biz/maq/) and
the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html).

Support MailScanner development - buy the book off the website!




More information about the MailScanner mailing list