Dailydave mailing list archives

Re: Interesting phish


From: "Tyler Krpata" <krpatasec () gmail com>
Date: Tue, 13 Feb 2007 08:41:46 -0500

Due to an overwhelming flood of requests to see the URL, here it is:
http://www.progonline.com/en/index.html (attempts to launch popup)
http://www.progonline.com/en/sys.php (direct link)

On 2/12/07, Tyler Krpata <krpatasec () gmail com> wrote:
I had an interesting Bank of America phish pointed out to me...it gets
around the "wrong URL" problem by popping up a new window which
disables the location bar and creates a lookalike IE location bar of
its own which contains a legit URL. This is something I had actually
been thinking about and played with a bit about a year ago, so I'm not
hugely surprised to see it in the wild. (Apologies if this is not a
new tactic, but I hadn't seen it before.)

Not sure if it's kosher to post phishing URL's to the list, but I will
if anyone wants to see it.

_______________________________________________
Dailydave mailing list
Dailydave () lists immunitysec com
http://lists.immunitysec.com/mailman/listinfo/dailydave


Current thread: