Phishing net FP
Michele Neylon :: Blacknight Solutions
michele at BLACKNIGHT.IE
Mon Mar 21 02:03:08 GMT 2005
Using MailScanner latest unstable
http://www.informit.com/guides/guide.asp?g=dotnet ".NET Reference Guide"
Was picked up as being a phishing attack.
Modified source code of HTML email is below:
<!-- InstanceEndRepeatEntry --><!-- InstanceBeginRepeatEntry -->
<dl>
<font size="2"><!-- InstanceBeginEditable
name="Programming_ArticleTitle" --><a
href="http://www.informit.com/guides/guide.asp?g=dotnet"><font
color="red"><b>MailScanner has detected a possible fraud attempt from
"www.informit.com" claiming to be</b></font> .NET
Reference Guide</a><!-- InstanceEndEditable --><br>
</font>
<dd><font size="2"><!-- InstanceBeginEditable
name="Programming_ArticleDescription" -->Finishing
up last week's comparison of Java and .NET, Jim
Mischel
tackles <a
href="http://www.informit.com/guides/content.asp?g=dotnet&seqNum=103"><f
ont color="red"><b>MailScanner has detected a possible fraud attempt from
"www.informit.com" claiming to be</b></font> JavaBeans,
J2EE, and their .NET counterparts</a>. <!--
InstanceEndEditable --></font></dd>
</dl>
<!-- InstanceEndRepeatEntry --><!-- InstanceEndRepeat
--></td>
</tr>
<tr>
<td class="pb02" align="right"> <p><a
href="http://www.informit.com/articles/index.asp?st=41402"></font><font
size="1" color="#999999">More Articles in Programming <img
src="http://www.informit.com/display/informit/images/newsletter/editorial/ar
row_right.gif" width="11" height="11" align="absmiddle" border="0"
hspace="3"></a></p></td>
</tr>
</table></td>
</tr>
The only explanation I can think of is that the phishing code cannot
recognise a reference to .NET as being to the software as opposed to a TLD
Mr Michele Neylon
Blacknight Internet Solutions Ltd
Hosting, co-location & domains
http://www.blacknight.ie/
Tel. +353 59 9137101
Fax. +353 59 9146970
http://www.blacknight.ie/specialoffers.html
------------------------ MailScanner list ------------------------
To unsubscribe, email jiscmail at jiscmail.ac.uk with the words:
'leave mailscanner' in the body of the email.
Before posting, read the MAQ (http://www.mailscanner.biz/maq/) and
the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html).
Support MailScanner development - buy the book off the website!
More information about the MailScanner
mailing list