{Virus} new phishing (fwd)
Peter Peters
p.g.m.peters at utwente.nl
Wed Dec 1 13:46:56 GMT 2004
On Wed, 1 Dec 2004 12:57:54 +0100, you wrote:
>On my system too, but only antivir found a infection not f-prot.
I didn't have any virus. But I included an IP address from a phishing
spam.
|It seems phishers read or use MailScanner. Instead of <a
|href="http://x.x.x.x/s">www.your-favorite-bank.com</a> they start
|using <a href="http://x.x.x.x/s">signon</a>. And the phishing test
|doesn't recognize this one.
|
|Some people suggested inserting an ALT with something like "The host
|http://x.x.x.x/s, is a numerical IP address; most legitimate sites
|use names not addresses."
|
|Would this be possible?
I replaced the IP-address.
--
Peter Peters, senior netwerkbeheerder
Dienst Informatietechnologie, Bibliotheek en Educatie (ITBE)
Universiteit Twente, Postbus 217, 7500 AE Enschede
telefoon: 053 - 489 2301, fax: 053 - 489 2383, http://www.utwente.nl/itbe
------------------------ MailScanner list ------------------------
To unsubscribe, email jiscmail at jiscmail.ac.uk with the words:
'leave mailscanner' in the body of the email.
Before posting, read the MAQ (http://www.mailscanner.biz/maq/) and
the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html).
Support MailScanner development - buy the book off the website!
More information about the MailScanner
mailing list