phishing not found

mailscanner at berger.nl mailscanner at berger.nl
Fri Jul 14 07:11:13 IST 2006


http://updates.name/signin.ebay.com is completely legal and it works. Just try the link and you find out that it works and looks very real.  whitelisting all ebay is to easy and I think a lot off phishing is done using ebay. I think when a.ebay.com has a link to b.ebay.com is not a problem (they are both within the ebay.com domain). but update.ebay.com with a link to updates.name/blahblahblah seems to be phishing.
My opinion is that links are save as long as they link within the same domain.
BTW. What I forget to tell is that MailScanner did tag it with {Spam} thanks to the(Sare)rules and with {Disarmed} which seems to be working. But within the mail there is nothing changed and the links are just working.

Greetings,

Roger

Res wrote ..
> All of ebay should be whitelisted, since they always come
> as a.ebay.com <click me here z.ebay.com> they never match :)
> and it annoys the hell out of users with every ebay marked as phishing.
> 
> however blah.name/signin.blah  should never work as / is an illegal char
> in DNS
> 
> 
> On Thu, 13 Jul 2006, mailscanner at berger.nl wrote:
> 
> > Hi,
> >
> > I got a phishing email today from update at ebay.com with this link:
> > http://updates.name/signin.ebay.com/ws23/eBayISAPI.htm?Sign1n&co_partner1d=2&pUser1d=&site1d=0&pageT1pe=&p41=&i1=&bsh0wgif=&Us1ngSSL=&pp=&pa42=&err4msg=&ru4name=&r4uparams=&ru4product=&s1d=&favor1tenav=&conf1rm=&ebxPageT1pe=&ex1stingEmail=&isCheck0ut=&migrateV1sitor=
> >
> > Mailscanner did not see the phishing fraud. Probably the slashes avoided
> the system.
> > Can I change this myself or is this in mailscanner?
> >
> > Thanks,
> >
> > Roger
> >
> 
> -- 
> Cheers
> Res
> -- 
> MailScanner mailing list
> mailscanner at lists.mailscanner.info
> http://lists.mailscanner.info/mailman/listinfo/mailscanner
> 
> Before posting, read http://wiki.mailscanner.info/posting
> 
> Support MailScanner development - buy the book off the website! 


More information about the MailScanner mailing list