phishing not found
mailscanner at berger.nl
mailscanner at berger.nl
Fri Jul 14 07:11:13 IST 2006
http://updates.name/signin.ebay.com is completely legal and it works. Just try the link and you find out that it works and looks very real. whitelisting all ebay is to easy and I think a lot off phishing is done using ebay. I think when a.ebay.com has a link to b.ebay.com is not a problem (they are both within the ebay.com domain). but update.ebay.com with a link to updates.name/blahblahblah seems to be phishing.
My opinion is that links are save as long as they link within the same domain.
BTW. What I forget to tell is that MailScanner did tag it with {Spam} thanks to the(Sare)rules and with {Disarmed} which seems to be working. But within the mail there is nothing changed and the links are just working.
Greetings,
Roger
Res wrote ..
> All of ebay should be whitelisted, since they always come
> as a.ebay.com <click me here z.ebay.com> they never match :)
> and it annoys the hell out of users with every ebay marked as phishing.
>
> however blah.name/signin.blah should never work as / is an illegal char
> in DNS
>
>
> On Thu, 13 Jul 2006, mailscanner at berger.nl wrote:
>
> > Hi,
> >
> > I got a phishing email today from update at ebay.com with this link:
> > http://updates.name/signin.ebay.com/ws23/eBayISAPI.htm?Sign1n&co_partner1d=2&pUser1d=&site1d=0&pageT1pe=&p41=&i1=&bsh0wgif=&Us1ngSSL=&pp=&pa42=&err4msg=&ru4name=&r4uparams=&ru4product=&s1d=&favor1tenav=&conf1rm=&ebxPageT1pe=&ex1stingEmail=&isCheck0ut=&migrateV1sitor=
> >
> > Mailscanner did not see the phishing fraud. Probably the slashes avoided
> the system.
> > Can I change this myself or is this in mailscanner?
> >
> > Thanks,
> >
> > Roger
> >
>
> --
> Cheers
> Res
> --
> MailScanner mailing list
> mailscanner at lists.mailscanner.info
> http://lists.mailscanner.info/mailman/listinfo/mailscanner
>
> Before posting, read http://wiki.mailscanner.info/posting
>
> Support MailScanner development - buy the book off the website!
More information about the MailScanner
mailing list