Beng Hacks: Devious Phishing

Monday, May 30, 2005

Devious Phishing

Everyone knows about phishing, the concept of receiving email that looks like legitimate eg a banking or online shopping website. Everyone knows not to click on these URLs rite?

Well, for some people it's easier to avoid since they are really paranoid about receiving such email. However, it seems there is another way to trick stupid people into believing that that phishing email is legitimate. Observe the following:



This is an incorrect interpretation of the CRLF coding between Unix and Windows. Surprisingly this causes an IE browser URL bar to display fakeurl when in actual fact you have visited the hacker's url (myurl).

This is spooky shit. To counter this, obey several rules: do not click on urls in email; receive plain text email; view the source of suspicious html email.

0 Comments:

Post a Comment

<< Home