phishing net query..

Dhawal Doshy dhawal at NETMAGICSOLUTIONS.COM
Fri Apr 22 10:34:39 IST 2005


    [ The following text is in the "ISO-8859-1" character set. ]
    [ Your display is set for the "US-ASCII" character set.  ]
    [ Some characters may be displayed incorrectly. ]

Hello All,

Does the phishing net have the necessary logic to understand that
sub.domain.tld and www.domain.tld mostly have the same nameserver
maintainers, so something like the below examples ought to be considered
differently.

MailScanner has detected a possible fraud attempt from
"info.cafepress.com" claiming to be www.cafepress.com.

MailScanner has detected a possible fraud attempt from "see.sun.com"
claiming to be www.sun.com

Of course phishing.safe.sites.conf will take care of this, but can it be
done at the MS level, or am i missing it completely? If only my coding
skills were as good as my complaining skills.

- dhawal

------------------------ MailScanner list ------------------------
To unsubscribe, email jiscmail at jiscmail.ac.uk with the words:
'leave mailscanner' in the body of the email.
Before posting, read the Wiki (http://wiki.mailscanner.info/) and
the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html).

Support MailScanner development - buy the book off the website!




More information about the MailScanner mailing list