Phishing version and mailto: tag

Leonard Hermens Leonard.Hermens at POTLATCHCORP.COM
Mon Nov 29 22:44:57 GMT 2004


Hello,

I am running MailScanner version 4.35.11 and Message.pm version 1.126.2.172
(2004/11/29) on Red Hat Linux 9, Perl 5.8.0

I am still getting phishing fraud notices when the mailto: doesn't match
the URL text, for example:

Nov 29 14:24:48 lxclk0100 MailScanner[29724]: Found phishing fraud from
xxxxx.yyyyy at domain.com claiming to be mailto:xxxxx.yyyyy at domain.com in
iATMOTr29939

I seem to recall that Message.pm was patched to allow this to pass.

Do I need to run 4.36.1-1 for mailto: to check correctly with the latest
Message.pm? Or should 4.35.11 be okay? I'm just a bit versioning confused
right now. :)

-- Leonard


--
Leonard Hermens
Manager, Information Systems Security
Potlatch Corporation
805 Mill Road, Lewiston, ID 83501
Voice:  208.799.2031
Leonard.Hermens at potlatchcorp.com
http://www.potlatchcorp.com/

------------------------ MailScanner list ------------------------
To unsubscribe, email jiscmail at jiscmail.ac.uk with the words:
'leave mailscanner' in the body of the email.
Before posting, read the MAQ (http://www.mailscanner.biz/maq/) and
the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html).

Support MailScanner development - buy the book off the website!




More information about the MailScanner mailing list