Penetration Testing mailing list archives

Re: Outlook catching Phishing Emails


From: One2 () onetwo com
Date: 5 Sep 2006 06:12:30 -0000

Hey All,

Thanks to noone for replying! ... Just kidding! ;o)

For anyone who was actually interested, Outlook was classifying my spoofed emails as junk due to some of the wording, 
like "please login", as well as a "hidden" link - so I was wondering how I could bypass Outlook's spam/phishing filter.

Suprisingly (or really not so suprisingly), by sending the email from Outlook itself, when Outlook received the email 
it no longer classified it as junk.

I therefore grabbed the HTML from within the Outlook generated email and used it as the HTML source code for my 
phishing email (send via PHP).

This was successfully received by Outlook in the Inbox! Woohoo! Go Mickysoft!

Ciao,
One2

------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.
http://www.cenzic.com/products_services/download_hailstorm.php
------------------------------------------------------------------------


Current thread: