phising – Grey Panthers Savannah https://grey-panther.net Just another WordPress site Fri, 07 Aug 2009 15:25:00 +0000 en-US hourly 1 https://wordpress.org/?v=7.1.2 206299117 Open letter to PhishTank https://grey-panther.net/2009/08/open-letter-to-phishtank.html https://grey-panther.net/2009/08/open-letter-to-phishtank.html#comments Fri, 07 Aug 2009 15:25:00 +0000 https://grey-panther.net/?p=236 3359428532_69e68ec0ef_b Dear PhishTank!

I’m writing this letter / blog post because I couldn’t find any contact addresses on your site or a user forum to voice my concern.

The idea of crowd-sourcing the phish detection great because it lets a human make judgment about threats directed at humans (which is much easier than developing and maintaining an AI system :-)). I first joined PhishTank when I received some phising emails and I wanted to “do the right thing”. However after a couple of days of “verifying” phishes I was filled with an overwhelming sense of futility because of several reasons:

  • The last blogpost on the phishtank blog is from October 2008 (more than 8 moths ago at this moment!). And the comments are closed. Just an other way you can’t give feedback
  • The rules behind the functioning of the site are somewhat mysterious. Sometimes when I’m the first to vote on a site, it goes to 100% in the “is a phish” / “is not a phish” category, other times it remains at zero (as if my vote wasn’t counted)
  • Every time I vote it says “more votes are needed to verify this site”. Does this mean that even though I’ve casted hundreds of votes, I didn’t verify a single site as being a phish? Talk about futility…
  • Many phising sites are taken down quite quickly, so it is not uncommon to only see a “this site has been taken down” message when you want to verify a URL. However there is no way (that I’ve found) to say “this might have been a phish (based on the URL for example), but it seems to be taken down”
  • There are no statistics shown about the number of submissions versus the number of verified sites. It would be nice to see if we (the volunteers) can handle the load or if we need more volunteers
  • It would be nice to offer advice on setting up a safe environment for verifying phishes. Something like: a separate instance of Firefox with Javascript entirely disabled and perhaps Tor.
  • An other idea would be (if the amount of submitted URLs is far greater than the daily verified ones) to prioritize those URLs which are not yet in the Google Safe-Browsing database. This way PhishTank could offer a very good complement to the Google data-set.

If somebody from PhishTank reads this, please fix as many of the issues as possible! It is very sad to see a good idea being hindered by technical problems. BTW, I would be happy to help out (I have considerable experience in some key areas: PHP / MySQL / computer security).

Picture taken Sandy Austin’s photostream with permission.

]]>
https://grey-panther.net/2009/08/open-letter-to-phishtank.html/feed 4 236
Interesting phish https://grey-panther.net/2008/10/interesting-phish.html https://grey-panther.net/2008/10/interesting-phish.html#comments Wed, 22 Oct 2008 06:06:00 +0000 https://grey-panther.net/?p=639 Recently I’ve received the following phish:

Return-Path <[email protected]>
Authentication-Results mta403.mail.mud.yahoo.com from=hosts.co.uk; domainkeys=neutral (no sig)
Received from 85.233.160.25 (EHLO outgoing-smtp.namesco.net) (85.233.160.25) by mta403.mail.mud.yahoo.com with SMTP; Sat, 18 Oct 2008 17:04:47 -0700
Received from [192.168.0.7] (helo=artemis.hosts.co.uk) by outgoing-smtp.namesco.net with esmtp (Exim 4.67) (envelope-from ) id 1KrKrG-0008PU-2d for [email protected]; Sun, 19 Oct 2008 00:05:20 +0100
Received from babs-education.info by artemis.hosts.co.uk with local (Exim 4.64) (envelope-from ) id 1KrKrG-0002kk-1E for [email protected]; Sun, 19 Oct 2008 00:05:18 +0100
To [email protected]
Subject
From Cosmote Romania <[email protected]>
Reply-To [email protected]
MIME-Version 1.0
Content-Type text/plain
Content-Transfer-Encoding 8bit
Message-Id <[email protected]>
Sender Site Administrator <[email protected]>
Date Sun, 19 Oct 2008 00:05:18 +0100
Content-Length 422
Acum cu Cosmote te poti bucura de -Oferta Creditului Dublu-.Trimite un ~e-mail reply~ la acest mesaj cu un cod de reincarcare valid (neutilizat) impreuna cu numarul tau de telefon Cosmote, urmand ca la un interval de maximum 30 de minute Cosmote sa iti atribuie un credit dublu fata de cel reprezentat de codul de reincarcare trimis. Oferta ramane valabila pana la data de 25 octombrie 2008.

Cosmote-Alaturi de tine !

There is nothing particularly interesting about the scam itself (it promises something in return if you buy a prepaid card and send the number to them – such scams circulate over every media – e-mail, sms, phone, etc). What I wanted to exemplify is the multitude of actors involved (which makes stopping the scam that much harder):

There is my e-mail provider (Yahoo) who managed to classify this message (correctly) as spam.

There is the account the email originated from ([email protected]). Now, as far as I can tell, the website babs-education.info is a completely legitimate site for the “British Association of Barbershop Singers”, hosted at the provider hosts.co.uk (hence the email address). My current working theory is that this account was hacked and being used to send spam. I’m not really sure who to contact (supposedly the attacker has full control over the email account, so mailing there won’t do much good – I also tried to sign up to their forum, but it requires “administrative approval” which I still didn’t get – probably the administrator gets notified through the same email account).

There is also a third actor – Gmail – who will get the reply messages. Their abuse department got notified.

It is interesting how humans calculate the utility function. Email, as a tool, is completely inadequate in situations where we have active, hostile activity. Yet we don’t try to move on to something engineered having this situation in mind. Simply because our email (kind of) works, we regard it as more useful than future systems which would work better.

Also: closed systems like Facebook messaging, which some people claim “replaces email”, won’t ever substitute it for at least two reasons: (a) they are seeing a low(er) volume of spam because they are not as ubiquitous as email (as their popularity increases, so will the volume of spam) and (b) it is a closed system, making it useless for many usecases (companies internal messaging system for example).

]]>
https://grey-panther.net/2008/10/interesting-phish.html/feed 1 639