<?xml version="1.0" encoding="utf-8" ?>

<rss version="2.0" 
   xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
   xmlns:admin="http://webns.net/mvcb/"
   xmlns:dc="http://purl.org/dc/elements/1.1/"
   xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
   xmlns:wfw="http://wellformedweb.org/CommentAPI/"
   xmlns:content="http://purl.org/rss/1.0/modules/content/"
   xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule">
<channel>
    <title>JaBbA's Hut - Phishing</title>
    <link>http://jalcorn.net/weblog/</link>
    <description>White Hat Liberal Geek Dad</description>
    <dc:language>en</dc:language>
    <generator>Serendipity 1.2.1 - http://www.s9y.org/</generator>
    <pubDate>Fri, 15 Jun 2007 17:26:17 GMT</pubDate>

    <image>
        <url>http://jalcorn.net/weblog/templates/default/img/s9y_banner_small.png</url>
        <title>RSS: JaBbA's Hut - Phishing - White Hat Liberal Geek Dad</title>
        <link>http://jalcorn.net/weblog/</link>
        <width>100</width>
        <height>21</height>
    </image>

<item>
    <title>Real risk - the Phishing Trojan</title>
    <link>http://jalcorn.net/weblog/archives/1068-Real-risk-the-Phishing-Trojan.html</link>
            <category>Phishing</category>
            <category>Security</category>
    
    <comments>http://jalcorn.net/weblog/archives/1068-Real-risk-the-Phishing-Trojan.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=1068</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=1068</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    Of course, there are real risks out there that we need to avoid.&lt;br /&gt;
&lt;br /&gt;
The targeted emails warning of IRS Audits or overdue invoices are a perfect example.   Executives receiving these quite alarming emails click on the attachments to find out what the problem is, and the bad guys now own their computers.&lt;br /&gt;
&lt;br /&gt;
I&#039;ve seen multiple examples of the IRS audit scam, all of which came to executives here at work.  Someone&#039;s been doing their homework.&lt;br /&gt;
&lt;br /&gt;
I&#039;d suggest warning all executives of your companies about these emails.&lt;br /&gt;
&lt;br /&gt;
Example, from &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url_id=24&amp;amp;entry_id=1068&quot; title=&quot;http://isc.sans.org/diary.html?storyid=2979&quot;  onmouseover=&quot;window.status=&#039;http://isc.sans.org/diary.html?storyid=2979&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot; &gt;SANS&lt;/a&gt;:&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote&gt;Proforma Invoice for &quot;Company Name&quot; (Attn: &quot;Executive Name&quot;)&lt;br /&gt;
&lt;br /&gt;
The Body of the email included this text&lt;br /&gt;
&lt;br /&gt;
&quot;Hello,&lt;br /&gt;
&lt;br /&gt;
The Proforma Invoice is attached to this message. You can find the file&lt;br /&gt;
in the attachments area of your email software.&lt;br /&gt;
&lt;br /&gt;
PS: The invoice also includes the cost for the services provided for the&lt;br /&gt;
second quarter of 2007.&lt;br /&gt;
Please read, evaluate and reply with any comments. Thanks.&quot;&lt;/blockquote&gt; 
    </content:encoded>

    <pubDate>Fri, 15 Jun 2007 13:26:17 -0400</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/1068-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>Paypal address bar hack on Firefox</title>
    <link>http://jalcorn.net/weblog/archives/1002-Paypal-address-bar-hack-on-Firefox.html</link>
            <category>Phishing</category>
    
    <comments>http://jalcorn.net/weblog/archives/1002-Paypal-address-bar-hack-on-Firefox.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=1002</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=1002</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    &lt;a href=&#039;http://jalcorn.net/weblog/uploads/paypal20060619.png&#039;&gt;&lt;img width=&quot;110&quot; height=&quot;62&quot; border=&quot;0&quot; hspace=&quot;5&quot; align=&quot;left&quot; src=&quot;http://jalcorn.net/weblog/uploads/paypal20060619.serendipityThumb.png&quot; alt=&quot;&quot;  /&gt;&lt;/a&gt;A paypal phish just came in that had some interesting features.  Using Firefox with NoScript, I connected to the site and it tried to redirect me.  With NoScript on it didn&#039;t succesfully redirect but it presented me with a &quot;Go here&quot; link.  I did so, and got the attached screen - note that it tried to replace my addressbar but failed, creating a new addressbar instead.  &lt;br /&gt;
&lt;br /&gt;
Netcraft identified the site as a Phish.&lt;br /&gt;
&lt;br /&gt;
I&#039;d like to see what this does to IE but I don&#039;t have a virtual machine right now and don&#039;t want to allow the site to hack my real machine.&lt;br /&gt;
&lt;br /&gt;
JaBbA says DON&#039;T Check it out! 
    </content:encoded>

    <pubDate>Mon, 19 Jun 2006 15:19:10 -0400</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/1002-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>APWG Meeting</title>
    <link>http://jalcorn.net/weblog/archives/982-APWG-Meeting.html</link>
            <category>Phishing</category>
    
    <comments>http://jalcorn.net/weblog/archives/982-APWG-Meeting.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=982</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=982</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5hbnRpcGhpc2hpbmcub3JnLw==&amp;amp;entry_id=982&quot; title=&quot;http://www.antiphishing.org/&quot;  onmouseover=&quot;window.status=&#039;http://www.antiphishing.org/&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;&lt;img width=&quot;102&quot; height=&quot;75&quot; border=&quot;0&quot; hspace=&quot;5&quot; align=&quot;left&quot; src=&quot;http://jalcorn.net/weblog/uploads/apwglogo.gif&quot; alt=&quot;&quot;  /&gt;&lt;/a&gt;I&#039;m in Chicago for the &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5hbnRpcGhpc2hpbmcub3JnLw==&amp;amp;entry_id=982&quot;  onmouseover=&quot;window.status=&#039;http://www.antiphishing.org/&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;  title=&quot;APWG&quot;&gt;Anti Phishing Working Group&lt;/a&gt; (APWG) Spring meeting.  I&#039;m speaking on a panel entitled &lt;i&gt;Moving Toward A Tipping Point in Email Authentication: Arbitrating the Remediation of a Global Application&lt;/i&gt;.  We&#039;ll be discussing how to get some email authentication method for anti-spam and anti-phishing to be adopted by the Internet.&lt;br /&gt;
&lt;br /&gt;
JaBbA&#039;s gone big time &lt;img src=&quot;http://jalcorn.net/weblog/templates/default/img/emoticons/smile.png&quot; alt=&quot;:-)&quot; style=&quot;display: inline; vertical-align: bottom;&quot; class=&quot;emoticon&quot; /&gt; 
    </content:encoded>

    <pubDate>Tue, 18 Apr 2006 10:23:40 -0400</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/982-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>There are still some amateurs out there...</title>
    <link>http://jalcorn.net/weblog/archives/976-There-are-still-some-amateurs-out-there....html</link>
            <category>Phishing</category>
    
    <comments>http://jalcorn.net/weblog/archives/976-There-are-still-some-amateurs-out-there....html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=976</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=976</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    &lt;a href=&#039;http://jalcorn.net/weblog/uploads/chasedatemistake.png&#039;&gt;&lt;img width=&quot;110&quot; height=&quot;82&quot; border=&quot;0&quot; hspace=&quot;5&quot; align=&quot;left&quot; src=&quot;http://jalcorn.net/weblog/uploads/chasedatemistake.serendipityThumb.png&quot; alt=&quot;&quot;  /&gt;&lt;/a&gt;And they still make some silly mistakes.  Like the following, received Mar 19,2006:&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote&gt;Your online credit card account has high-risk activity status. We are contacting you to remind that on March 27 2006 our Account Review Team identified some unusual activity in your account. In accordance with Chase Bank User Agreement and to ensure that your account has not been compromised, access your account was limited. Your account access will remain limited until this issue has been resolved. ...&lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
It gets even better - apparently they realized the mistake, changed the date to Mar 19, and resent it - to the same addresses!&lt;br /&gt;
&lt;br /&gt;
Of course, the sad thing is some people probably fell for it anyway.&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;UPDATE&lt;/strong&gt; OK, this gets even funnier.  &lt;br /&gt;
&lt;br /&gt;
At 12pm, they sent out a set that said the 27th.&lt;br /&gt;
At 3pm, they sent out a set that said the 21st.&lt;br /&gt;
At 6pm, another set that said the 27th.&lt;br /&gt;
And finally, at 9pm, the set that said the 19th.&lt;br /&gt;
&lt;br /&gt;
Someone&#039;s playing with daddy&#039;s phishing kit... 
    </content:encoded>

    <pubDate>Mon, 20 Mar 2006 14:17:13 -0500</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/976-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>The Phishers take it to the next level</title>
    <link>http://jalcorn.net/weblog/archives/975-The-Phishers-take-it-to-the-next-level.html</link>
            <category>Phishing</category>
    
    <comments>http://jalcorn.net/weblog/archives/975-The-Phishers-take-it-to-the-next-level.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=975</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=975</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    Think you can spot a phishing email by the fact that it isn&#039;t addressed to you?&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL2lzYy5zYW5zLm9yZy9kaWFyeS5waHA/biZzdG9yeWlkPTExOTQ=&amp;amp;entry_id=975&quot;  onmouseover=&quot;window.status=&#039;http://isc.sans.org/diary.php?n&amp;amp;storyid=1194&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;  title=&quot;sans.org&quot;&gt;Not any more&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
I&#039;ve seen a few of these.  I think their hit rate is low - some of the data is incorrect.  But when it&#039;s right, it&#039;s devastating.&lt;br /&gt;
&lt;br /&gt;
JaBbA says be careful out there. 
    </content:encoded>

    <pubDate>Thu, 16 Mar 2006 13:03:27 -0500</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/975-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>ARRRRGGGH</title>
    <link>http://jalcorn.net/weblog/archives/974-ARRRRGGGH.html</link>
            <category>Phishing</category>
    
    <comments>http://jalcorn.net/weblog/archives/974-ARRRRGGGH.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=974</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=974</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    &lt;a href=&#039;http://jalcorn.net/weblog/uploads/chasereplay.png&#039;&gt;&lt;img width=&quot;86&quot; height=&quot;110&quot; border=&quot;0&quot; hspace=&quot;5&quot; align=&quot;left&quot; src=&quot;http://jalcorn.net/weblog/uploads/chasereplay.serendipityThumb.png&quot; alt=&quot;&quot;  /&gt;&lt;/a&gt;I just got an email from my bank preparing me for the change to Chase.com.  Fine.  But they&#039;re setting me up for a replay:&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote&gt;&lt;br /&gt;
 You can bookmark the new site by adding it to your list of favorites, or you can enter &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL25vdGlmaWNhdGlvbnMuY2hhc2UuY29tLzEyMzQ1Njc4OS4xMTE3Ni4wLjUzNg==&amp;amp;entry_id=974&quot; title=&quot;http://notifications.chase.com/123456789.11176.0.536&quot;  onmouseover=&quot;window.status=&#039;http://notifications.chase.com/123456789.11176.0.536&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;www.Chase.com&lt;/a&gt; into your browser. In the meantime, you can &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL25vdGlmaWNhdGlvbnMuY2hhc2UuY29tLzEyMzQ1Njc4OS4xMTE3Ni4wLjgzNg==&amp;amp;entry_id=974&quot; title=&quot;http://notifications.chase.com/123456789.11176.0.836&quot;  onmouseover=&quot;window.status=&#039;http://notifications.chase.com/123456789.11176.0.836&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;preview the new site&lt;/a&gt; for more information.&lt;br /&gt;
&lt;/blockquote&gt;&lt;br /&gt;
Let&#039;s see.  They&#039;re&lt;br /&gt;
&lt;ul&gt;&lt;br /&gt;
&lt;li /&gt; Telling me to click a link in an email, while telling me not to !?!&lt;br /&gt;
&lt;li /&gt; Getting me used to link click tracking by putting a unique ID on the link&lt;br /&gt;
&lt;li /&gt; Telling me I&#039;m going to www.chase.com while sending me elsewhere&lt;br /&gt;
&lt;li /&gt; Getting me used to links with complex URLs, which Phishers just love&lt;br /&gt;
&lt;li /&gt; And even worse - there&#039;s NO WAY for me to preview the site EXCEPT through their complex URL.  Going to notifications.chase.com just redirects me to the standard Bank One site.&lt;br /&gt;
&lt;/ul&gt;&lt;br /&gt;
BankOne was doing a good job avoiding this crap.  I thought Chase was on this stuff, but their marketing department clearly hasn&#039;t gotten the memo.&lt;br /&gt;
&lt;br /&gt;
I&#039;m calling the security department at Chase and complaining - and telling them I moved from Ohio Savings to Bank one BECAUSE of OSB&#039;s lack of anti-phishing readiness.  Let&#039;s see if I can get them talking about this.&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Tue, 14 Mar 2006 10:06:25 -0500</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/974-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>Change in Tactics - and Maybe I'm Off the Island</title>
    <link>http://jalcorn.net/weblog/archives/972-Change-in-Tactics-and-Maybe-Im-Off-the-Island.html</link>
            <category>Phishing</category>
    
    <comments>http://jalcorn.net/weblog/archives/972-Change-in-Tactics-and-Maybe-Im-Off-the-Island.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=972</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=972</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    Well, I&#039;ve now gone 4 days and none of my SPAM-catchers has gotten a phishing scheme.  My eBay accounts are fine, nothing&#039;s wrong with PayPal, My Chase, Citibank and Wells Fargo accounts are all hunky-dory.  (Well, there was a Wells Fargo phish on Friday, but that&#039;s it.)  Even my wider nets have only caught a couple, mostly Comerica Bank.  I&#039;m still winning a lot of European lotteries, and having opportunities to help move money out of Africa, of course.  And Offers to enhance my sex life and lose weight. *yawn*&lt;br /&gt;
&lt;br /&gt;
So either the Phishers are taking a break, or they&#039;ve scrubbed me from their systems - that&#039;s possible, but unlikely.  But more importantly, the Phishers are apparently taking their cue from the eBay phishers and are changing tactics - &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL2lzYy5zYW5zLm9yZy9kaWFyeS5waHA/c3RvcnlpZD0xMTgz&amp;amp;entry_id=972&quot; title=&quot;http://isc.sans.org/diary.php?storyid=1183&quot;  onmouseover=&quot;window.status=&#039;http://isc.sans.org/diary.php?storyid=1183&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot; &gt;offering rewards rather that scaring victims&lt;/a&gt; with stories about their account being hacked.&lt;br /&gt;
&lt;br /&gt;
So apparently people are listening and ignoring the old phishes.  Be alert, and don&#039;t believe anything you are sent in email.   
    </content:encoded>

    <pubDate>Mon, 13 Mar 2006 10:32:48 -0500</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/972-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>Thank You</title>
    <link>http://jalcorn.net/weblog/archives/962-Thank-You.html</link>
            <category>Phishing</category>
    
    <comments>http://jalcorn.net/weblog/archives/962-Thank-You.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=962</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=962</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    To SANS Handler Tom Liston, who tells it like it is.  Today&#039;s &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL2lzYy5zYW5zLm9yZy9kaWFyeS5waHA/biZzdG9yeWlkPTExMTg=&amp;amp;entry_id=962&quot; title=&quot;http://isc.sans.org/diary.php?n&amp;amp;storyid=1118&quot;  onmouseover=&quot;window.status=&#039;http://isc.sans.org/diary.php?n&amp;amp;storyid=1118&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot; &gt;SANS Handler&#039;s Diary&lt;/a&gt; has a very important story to tell -  a story I&#039;ve been trying to say here for 2 years:&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote&gt;What is going on here?  How can this be happening?  Internet e-commerce is founded on SSL, and SSL is founded on the trust that the companies handing out SSL certificates are doing their homework and are verifying that the companies sitting behind their certs are who they say they are.&lt;br /&gt;
&lt;br /&gt;
To paraphrase one of my favorite movie lines: &quot;What we have here is a failure to authenticate...&quot;&lt;br /&gt;
&lt;br /&gt;
Finally, banks and credit unions that send our email with clickable links teach their customers incredibly dangerous habits.  Financial institutions that use multiple domain names are setting their customers up for disaster.  And, of course, any financial institution that isn&#039;t checking their referrer logs for odd and unknown sites is a time bomb waiting to explode.&lt;br /&gt;
&lt;br /&gt;
Come on folks.  It&#039;s hard enough to keep the end users from shooting themselves in the foot... don&#039;t give them a loaded gun.&lt;br /&gt;
&lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
JaBbA says &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL2lzYy5zYW5zLm9yZy9kaWFyeS5waHA/biZzdG9yeWlkPTExMTg=&amp;amp;entry_id=962&quot;  onmouseover=&quot;window.status=&#039;http://isc.sans.org/diary.php?n&amp;amp;storyid=1118&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;  title=&quot;Diary Entry, Feb 13 2006&quot;&gt;check it out&lt;/a&gt;. 
    </content:encoded>

    <pubDate>Mon, 13 Feb 2006 16:13:54 -0500</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/962-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>Nasty new eBay Phish</title>
    <link>http://jalcorn.net/weblog/archives/954-Nasty-new-eBay-Phish.html</link>
            <category>Phishing</category>
    
    <comments>http://jalcorn.net/weblog/archives/954-Nasty-new-eBay-Phish.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=954</wfw:comment>

    <slash:comments>1</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=954</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    Rather than relying on fear of authority to get you to give up your eBay password, this one tugs at your heartstrings:&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote&gt;Hello,&lt;br /&gt;
&lt;br /&gt;
I recently placed a bid on item #5590717206 being a wheelchair for me that i really need do to my age (78 years old) and it seems that i can not find the auction anymore...May i please know if you are the seller of the item above?&lt;br /&gt;
&lt;br /&gt;
Regards,&lt;br /&gt;
Gretta.&lt;br /&gt;
&lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
(misspellings are those of the original author)&lt;br /&gt;
&lt;br /&gt;
The email is formatted just like a question from a seller, and links to a server called looo.mooo.com.  You can see what it looks like (a little munged) &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL2phbGNvcm4ubmV0L3dlYmxvZy9wYWdlcy9lYmF5cGhpc2guaHRtbA==&amp;amp;entry_id=954&quot;  onmouseover=&quot;window.status=&#039;http://jalcorn.net/weblog/pages/ebayphish.html&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;  title=&quot;Link to example email&quot;&gt;Here&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
JaBbA says keep your guard up.  Remember, some of these have WMF exploits as well as Phishing schemes. 
    </content:encoded>

    <pubDate>Tue, 10 Jan 2006 12:05:14 -0500</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/954-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>Nasty New Phish</title>
    <link>http://jalcorn.net/weblog/archives/946-Nasty-New-Phish.html</link>
            <category>Phishing</category>
    
    <comments>http://jalcorn.net/weblog/archives/946-Nasty-New-Phish.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=946</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=946</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    &lt;a href=&#039;http://jalcorn.net/weblog/uploads/paypal20051130.png&#039;&gt;&lt;img width=&quot;110&quot; height=&quot;70&quot; border=&quot;0&quot; hspace=&quot;5&quot; align=&quot;left&quot; src=&quot;http://jalcorn.net/weblog/uploads/paypal20051130.serendipityThumb.png&quot; alt=&quot;&quot;  /&gt;&lt;/a&gt;This one is quite sophisticated and nasty.  The screenshot (click to enlarge) shows the page on my fully-patched XP SP2 box in IE.  The emails is sent with a google.com address and uses the google redirect to go to japan while it looks like paypal.  &lt;br /&gt;
&lt;br /&gt;
&lt;a href=&#039;http://jalcorn.net/weblog/uploads/paypal20051130-ff.png&#039;&gt;&lt;img width=&quot;110&quot; height=&quot;68&quot; border=&quot;0&quot; hspace=&quot;5&quot; align=&quot;right&quot; src=&quot;http://jalcorn.net/weblog/uploads/paypal20051130-ff.serendipityThumb.png&quot; alt=&quot;&quot;  /&gt;&lt;/a&gt;The hack works on Firefox too, but using the Netcraft toolbar, the noscript extension and other tools it was obvious that something funky was going on, and the faked address bar was removed in the end:&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Wed, 30 Nov 2005 09:47:17 -0500</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/946-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>Google Phish - No, you didn't win $400</title>
    <link>http://jalcorn.net/weblog/archives/942-Google-Phish-No,-you-didnt-win-400.html</link>
            <category>Phishing</category>
    
    <comments>http://jalcorn.net/weblog/archives/942-Google-Phish-No,-you-didnt-win-400.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=942</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=942</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    A &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy53ZWJzZW5zZXNlY3VyaXR5bGFicy5jb20vYWxlcnRzL2FsZXJ0LnBocD9BbGVydElEPTMzMg==&amp;amp;entry_id=942&quot;  onmouseover=&quot;window.status=&#039;http://www.websensesecuritylabs.com/alerts/alert.php?AlertID=332&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;  title=&quot;Websense Labs&quot;&gt;Wensense Labs Alert&lt;/a&gt; about a nasty Google phish using $400 as the lure.  Complete with screenshots.&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Thu, 10 Nov 2005 11:07:02 -0500</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/942-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>And you thought you were safe</title>
    <link>http://jalcorn.net/weblog/archives/929-And-you-thought-you-were-safe.html</link>
            <category>Phishing</category>
    
    <comments>http://jalcorn.net/weblog/archives/929-And-you-thought-you-were-safe.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=929</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=929</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    Because your bank gave you a stack of One Time Passwords?&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5vdXQtbGF3LmNvbS9wYWdlLTYyMTM=&amp;amp;entry_id=929&quot; title=&quot;http://www.out-law.com/page-6213&quot;  onmouseover=&quot;window.status=&#039;http://www.out-law.com/page-6213&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;Think again&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote&gt;Recipients were directed to several fake websites, thought to be based in South Korea, and asked not only for their account details, but also for the next password on their list of one-time passwords.&lt;br /&gt;
&lt;br /&gt;
[snip]&lt;br /&gt;
&lt;br /&gt;
According to F-Secure: âRegardless of what you entered, the site would complain about the scratch code and asked you to try the next one. In reality the bad boys were trying to collect several scratch codes for their own use.â?&lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Tue, 11 Oct 2005 14:43:53 -0400</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/929-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>Obedience to Authority</title>
    <link>http://jalcorn.net/weblog/archives/918-Obedience-to-Authority.html</link>
            <category>Phishing</category>
    
    <comments>http://jalcorn.net/weblog/archives/918-Obedience-to-Authority.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=918</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=918</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    The problem of Phishing comes down to Obedience to Authority, as in &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL2VuLndpa2lwZWRpYS5vcmcvd2lraS9NaWxncmFtX2V4cGVyaW1lbnQ=&amp;amp;entry_id=918&quot; title=&quot;http://en.wikipedia.org/wiki/Milgram_experiment&quot;  onmouseover=&quot;window.status=&#039;http://en.wikipedia.org/wiki/Milgram_experiment&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;Stanley Milgram&#039;s famous experiment&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3VzYWJsZXNlY3VyaXR5LmNvbS8yMDA1LzA3LzE5L29iZWRpZW5jZS10by1hdXRob3JpdHkv&amp;amp;entry_id=918&quot; title=&quot;http://usablesecurity.com/2005/07/19/obedience-to-authority/&quot;  onmouseover=&quot;window.status=&#039;http://usablesecurity.com/2005/07/19/obedience-to-authority/&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;Usable Security&lt;/a&gt; has a good article on the problem of conflicting authorities, in the case of a phish.&lt;br /&gt;
&lt;br /&gt;
JaBbA says check it out. 
    </content:encoded>

    <pubDate>Wed, 20 Jul 2005 10:36:35 -0400</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/918-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>Simple Anti-Phishing tool</title>
    <link>http://jalcorn.net/weblog/archives/917-Simple-Anti-Phishing-tool.html</link>
            <category>Browser Wars</category>
            <category>Phishing</category>
    
    <comments>http://jalcorn.net/weblog/archives/917-Simple-Anti-Phishing-tool.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=917</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=917</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    A new firefox extension is a simple and effective addition to the Anti-Fraud arsenal.&lt;br /&gt;
&lt;br /&gt;
The &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3BldG5hbWUubW96ZGV2Lm9yZy8=&amp;amp;entry_id=917&quot; title=&quot;http://petname.mozdev.org/&quot;  onmouseover=&quot;window.status=&#039;http://petname.mozdev.org/&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;Petname Extension&lt;/a&gt; simply allows you to assign a descriptive name to any SSL-enabled website, then displays that name whenever it sees that same SSL certificate.&lt;br /&gt;
&lt;br /&gt;
Any browser tricks or redirections will become obvious when you &quot;Pet Name&quot; for the website isn&#039;t displayed.&lt;br /&gt;
&lt;br /&gt;
JaBbA recommends.&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;UPDATE&lt;/strong&gt; I probably should have pointed out - this is a very small implementation of a new idea called a &quot;Security Skin&quot;.  See&lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5zY2huZWllci5jb20vY3J5cHRvLWdyYW0tMDUwNy5odG1sIzEz&amp;amp;entry_id=917&quot; title=&quot;http://www.schneier.com/crypto-gram-0507.html#13&quot;  onmouseover=&quot;window.status=&#039;http://www.schneier.com/crypto-gram-0507.html#13&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt; Bruce Schneier&lt;/a&gt; and &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy50eWdhci5uZXQvcGFwZXJzL0JhdHRsZV9hZ2FpbnN0X3BoaXNoaW5nLnBkZg==&amp;amp;entry_id=917&quot; title=&quot;http://www.tygar.net/papers/Battle_against_phishing.pdf&quot;  onmouseover=&quot;window.status=&#039;http://www.tygar.net/papers/Battle_against_phishing.pdf&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;this paper&lt;/a&gt; (PDF). 
    </content:encoded>

    <pubDate>Fri, 15 Jul 2005 14:21:52 -0400</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/917-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>And more examples of corporate stupidity</title>
    <link>http://jalcorn.net/weblog/archives/914-And-more-examples-of-corporate-stupidity.html</link>
            <category>Phishing</category>
    
    <comments>http://jalcorn.net/weblog/archives/914-And-more-examples-of-corporate-stupidity.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=914</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=914</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    F-Secure&#039;s blog has examples of phishing-replayable emails from &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5mLXNlY3VyZS5jb20vd2VibG9nL2FyY2hpdmVzL2FyY2hpdmUtMDcyMDA1Lmh0bWwjMDAwMDA1ODY=&amp;amp;entry_id=914&quot; title=&quot;http://www.f-secure.com/weblog/archives/archive-072005.html#00000586&quot;  onmouseover=&quot;window.status=&#039;http://www.f-secure.com/weblog/archives/archive-072005.html#00000586&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;RSA&lt;/a&gt; and &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5mLXNlY3VyZS5jb20vd2VibG9nLyMwMDAwMDU4OQ==&amp;amp;entry_id=914&quot; title=&quot;http://www.f-secure.com/weblog/#00000589&quot;  onmouseover=&quot;window.status=&#039;http://www.f-secure.com/weblog/#00000589&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;CA&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
These are &lt;strong&gt;Security Companies&lt;/strong&gt; doing this!  Amazing. 
    </content:encoded>

    <pubDate>Fri, 08 Jul 2005 12:30:36 -0400</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/914-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>

</channel>
</rss>