Full Disclosure mailing list archives
Re: [HV-PAPER] Anti-Phishing Tips You Should Not Follow
From: Nick FitzGerald <nick () virus-l demon co uk>
Date: Sun, 02 Apr 2006 11:15:18 +1200
Marcos Agüero to Michal Zalewski:
Note to self: design my next phishing website to always display "logon failed".
8-) The phishmongers are well ahead of you there...
Just as most of the phishing sites already do.
Really? "Most"? Still? Admittedly I don't poke bogus credentials into every phishing site I see, but I do prod a lot of them and of late the only thing I've seen "fail" is a few sites doing Luhn checks on supplied CC #s and asking you to more carefully re-enter the number. The "iniitial fail" tactic was quite a popular a while back, but I don't recall having seen it at all lately... Regards, Nick FitzGerald _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- Re: [HV-PAPER] Anti-Phishing Tips You Should Not Follow Nick FitzGerald (Apr 01)
- <Possible follow-ups>
- Re: [HV-PAPER] Anti-Phishing Tips You Should Not Follow Nick FitzGerald (Apr 01)
- Re: [HV-PAPER] Anti-Phishing Tips You Should NotFollow Dave Korn (Apr 02)