4.35.9: phishers of phools pheature questions

Julian Field mailscanner at ecs.soton.ac.uk
Tue Nov 2 21:39:47 GMT 2004


    [ The following text is in the "ISO-8859-1" character set. ]
    [ Your display is set for the "US-ASCII" character set.  ]
    [ Some characters may be displayed incorrectly. ]

Jeff A. Earickson wrote:

> Dear Julian Phield,
>
> I've turned on the phishing phraud pheature in 4.3.59, and I've noticed
> a couple of strange things in some emails.  One had empty quotes in
> the warning:
>
> I invite you to visit the Citizen Advocate=s for=20
> Private Philanthropy website&nbsp;<A href=3D""><font
> color=3D"red"><b>MailS=
> canner has detected a possible fraud attempt from "" claiming to
> be</b></fo=
> nt> http://www.capp.info</A>

Known bug. It's a tiny fix, but I didn't want to change the code just
before I released it.

>
> and another had a quoted URL that agreed with the real URL:
>
>   Do you Yahoo!?<BR>Check out the new Yahoo! Front Page. <A=20
>   href=3D"http://www.yahoo.com"><font color=3D"red"><b>MailScanner has
> dete=
> cted a possible fraud attempt from "www.yahoo.com" claiming to
> be</b></font=
>
>> www.yahoo.com&lt;/a</A></BLOCKQUOTE><FONT SIZE=3D3><BR>
>
It's comparing www.yahoo.com with www.yahoo.com&lt;
which are of course different.

>
> Whats going on here?  Does DNS play a role in this,

No.

--
Julian Field
www.MailScanner.info
Professional Support Services at www.MailScanner.biz
MailScanner thanks transtec Computers for their support
Buy the MailScanner book at www.MailScanner.info/store

PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654

------------------------ MailScanner list ------------------------
To unsubscribe, email jiscmail at jiscmail.ac.uk with the words:
'leave mailscanner' in the body of the email.
Before posting, read the MAQ (http://www.mailscanner.biz/maq/) and
the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html).




More information about the MailScanner mailing list