AumHa Forums

Supporting Users of Windows Desktop Systems
It is currently Wed 9/8/10 04:59 pm

All times are UTC - 8 hours [ DST ]




Post new topic Reply to topic  [ 2 posts ] 
Author Message
 Post subject: How to test for Phishing misdirection
PostPosted: Mon 1/3/05 01:10 pm 
Offline
AumHa Webmaster
AumHa Webmaster
User avatar

Joined: Thu 4/4/02 02:51 pm
Posts: 14708
Location: Los Angeles, CA
http://www.millersmiles.co.uk/identityt ... hecker.php has a very clever way to test to make sure you are on the right Web page - that is, to confirm what the underlyng URL really is. When you are on a page which you question, replace the Address bar contents with this:

javascript:alert("The true URL is:\t\t" + location.protocol + "//" + location.hostname + "/" + "\nIf this does not match the URL shown in your browser address bar, you are likely to be seeing a web page from a different web site! We recommend that you close you browser and empty your browser cache now.");

Not convenient, you say? Here's how to make it convenient: Make a Favorite in your browser using the colored text above as the URL. Call it "Phishing test" or something convenient. Then, to test a site, just click on this Favorite.

_________________
Jim Eshelman, MS-MVP (Windows Shell/User - Windows Security)
"One does not discover new lands without consenting to lose sight of the shore for a very long time." - Andre Gide
Your gifts to this site are much appreciated. http://aumha.org/donate.htm


Top
 Profile  
 
 Post subject:
PostPosted: Tue 1/4/05 02:23 pm 
Offline
Site Admin
Site Admin
User avatar

Joined: Tue 3/11/03 09:02 pm
Posts: 21226
Location: NW ChesCo, Pennsylvania, USA
Also much-discussed in security circles:
In another forum, MVP Donna Buenaventura wrote:
Another security program that is interesting to try and I think one feature that is attractive with this toolbar is... user can report a phished URL to help other people because once confirmed it is a phished URL, it will be blocked so other users will not become a victim.

Netcraft Anti-Phishing Toolbar Available for Download

"The Netcraft Toolbar uses Netcraft's enormous databases of web site information to show you all the attributes of each site you visit on the Web, including the sites' hosting location, country, longevity and popularity.

Toolbar features include:

Clear display of sites' hosting location at all times helps you validate fraudulent urls (e.g. the main online banking site of a large US bank is unlikely to be hosted in the former Soviet Union).

Once you report a phishing URL, it is blocked for other community members subsequently accessing it. The leverage of widely disseminated attacks (people constructing phishing attacks send literally millions of electronic mails in the expectation that some will reach customers of the bank) is utilized to expedite blocking of the fraud site.

Natively traps cross site scripting and other suspicious urls containing characters which have no common purpose other than to deceive.

Netcraft supervisor validation is used to contain the impact of any false reporting of urls.

Display of browser navigational controls (toolbar & address bar) in all windows, to defend against pop up windows which attempt to hide the navigational controls to disguise location.

Happily coexists with Google and other Toolbars."

Read more in http://news.netcraft.com/archives/2004/ ... nload.html

or http://toolbar.netcraft.com/

Just in case you need another IE toolbar. :twisted:

_________________
~Robear Dyer (PA Bear)
AumHa VSOP, Admin & Moderator
MS MVP-Internet Explorer, Mail, Consumer Security, Windows Desktop Experience - since 2002
Steely-eyed Missile Man, Sensei, & Mule Skinner
Errabundi Saepe, Semper Certi
:L) Your donations help keep this site going & are very much appreciated: http://aumha.org/donate.htm


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 2 posts ] 

All times are UTC - 8 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group