« The Simpsons: The Map of Springfield | Main | More thoughts around Code Generation and... »

Phishing...for EVIL!

Posted 2004-06-07 11:09 PM in Musings.

Just happened to get this in my evening email.  It's obviously a standard Phishing scam.  If you look at the source (as I usually do to most suspicious looking HTML email) you can see that the links point to urls like: http://www.scgi3-ebay-saw-cgi-ebayisapi-dll-registerenterinfo.xx.com.  Note that the first part of the URL is really just a very long subdomain, pointing to the evil person's actual domain (xx.com in this example.)  Additionally that domain's WHOIS record points to a fake person, blah blah.  Their domain points to freeservers.com which does roaming DNS which points to a webserver on their personal computer lord knows where.  When you submit your Credit Card it goes via an unencrypted Form POST right to their computer.  Evil!

What I found particularly interesting was what is revealed in this screen shot from my Outlook.  What's interesting...do you see it? 

The scrollbar is on the LEFT.  Further digging shows that the HTML body for this message was created with FrontPage and they've explicitly set the encoding to Windows-1252 and attempted to switch all the tags to dir="ltr."  However, Microsoft FrontPage when running in Right-To-Left Locales (Arabic, Hebrew, etc.) will default the HTML root tag as <html dir="rtl">.  As every OTHER tag in the document is explicitly marked dir="ltr" the document elements look OK, but since they missed the root tag, Outlook moves the scrollbar to the left, thus making their chicanery even more obvious.  Additionally it makes me wonder what country these folks are phishing from.



Monday, June 07, 2004 10:42:59 PM (Pacific Standard Time, UTC-08:00)
well spotted!

Tuesday, June 08, 2004 8:31:47 AM (Pacific Standard Time, UTC-08:00)
Damn it! And I thought you wouldn't figure it out. I'll have to try again. ;)
Comments are closed.

Contact

Sponsors

Hosting By

Hot Topics

Tags

Calendar

<November 2009>
SunMonTueWedThuFriSat
25262728293031
1234567
891011121314
15161718192021
22232425262728
293012345

Archives

November, 2009 (2)
October, 2009 (19)
September, 2009 (11)
August, 2009 (12)
July, 2009 (21)
June, 2009 (26)
May, 2009 (16)
April, 2009 (13)
March, 2009 (17)
February, 2009 (17)
January, 2009 (18)
December, 2008 (32)
November, 2008 (17)
October, 2008 (22)
September, 2008 (16)
August, 2008 (14)
July, 2008 (25)
June, 2008 (19)
May, 2008 (17)
April, 2008 (17)
March, 2008 (26)
February, 2008 (21)
January, 2008 (28)
December, 2007 (19)
November, 2007 (17)
October, 2007 (31)
September, 2007 (39)
August, 2007 (37)
July, 2007 (43)
June, 2007 (37)
May, 2007 (32)
April, 2007 (38)
March, 2007 (29)
February, 2007 (46)
January, 2007 (31)
December, 2006 (27)
November, 2006 (31)
October, 2006 (32)
September, 2006 (39)
August, 2006 (34)
July, 2006 (40)
June, 2006 (18)
May, 2006 (31)
April, 2006 (34)
March, 2006 (30)
February, 2006 (38)
January, 2006 (44)
December, 2005 (19)
November, 2005 (34)
October, 2005 (24)
September, 2005 (37)
August, 2005 (20)
July, 2005 (24)
June, 2005 (33)
May, 2005 (16)
April, 2005 (22)
March, 2005 (34)
February, 2005 (15)
January, 2005 (37)
December, 2004 (28)
November, 2004 (30)
October, 2004 (34)
September, 2004 (22)
August, 2004 (34)
July, 2004 (18)
June, 2004 (64)
May, 2004 (49)
April, 2004 (21)
March, 2004 (29)
February, 2004 (29)
January, 2004 (36)
December, 2003 (25)
November, 2003 (24)
October, 2003 (59)
September, 2003 (42)
August, 2003 (24)
July, 2003 (44)
June, 2003 (29)
May, 2003 (21)
April, 2003 (30)
March, 2003 (27)
February, 2003 (47)
January, 2003 (50)
December, 2002 (31)
November, 2002 (38)
October, 2002 (44)
September, 2002 (15)
May, 2002 (2)
April, 2002 (4)

Google Ads