<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.0.5" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: Pishing Ain&#8217;t Easy</title>
	<link>http://www.terminally-incoherent.com/blog/2008/03/04/pishing-aint-easy/</link>
	<description>Utterly random, incoherent and disjointed rants and ramblings...</description>
	<pubDate>Sat, 10 Jan 2009 02:45:19 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.0.5</generator>

	<item>
		<title>by: Luke Maciak</title>
		<link>http://www.terminally-incoherent.com/blog/2008/03/04/pishing-aint-easy/#comment-8396</link>
		<pubDate>Sun, 09 Mar 2008 18:55:59 +0000</pubDate>
		<guid>http://www.terminally-incoherent.com/blog/2008/03/04/pishing-aint-easy/#comment-8396</guid>
					<description>&lt;strong&gt;@Michael Molsner&lt;/strong&gt; - thanks for all your help. You are doing a great job keeping the interwebs safe. :)

[quote post="2324"]Do you not have a test bed apache (or Xampp) system that sits on a non-routable network block (192.168.x.x, 172.[16-31].x.x, 10.x.x.x) where you can demonstrate to your students without the risk of exposure to the big-bad-interwebbythingy.[/quote]

Nope. I'm an adjunct. I'm lucky that I get a mailbox on campus. :P

But yeah, you are right - not very smart on my part, and I totally deserved to be caught. I'm not complaining. In fact I'm totally impressed that it happened so fast. :) It's a good thing!</description>
		<content:encoded><![CDATA[<p><strong>@Michael Molsner</strong> - thanks for all your help. You are doing a great job keeping the interwebs safe. <img src="http://www.terminally-incoherent.com/blog/wp-includes/images/smilies/icon_smile.gif" alt=")" class="wp-smiley" /> </p>
<blockquote cite="http://www.terminally-incoherent.com/blog/2008/03/04/pishing-aint-easy/"><p>
Do you not have a test bed apache (or Xampp) system that sits on a non-routable network block (192.168.x.x, 172.[16-31].x.x, 10.x.x.x) where you can demonstrate to your students without the risk of exposure to the big-bad-interwebbythingy.</p>
</blockquote>
<p>Nope. I&#8217;m an adjunct. I&#8217;m lucky that I get a mailbox on campus. <img src="http://www.terminally-incoherent.com/blog/wp-includes/images/smilies/icon_razz.gif" alt="P" class="wp-smiley" /> </p>
<p>But yeah, you are right - not very smart on my part, and I totally deserved to be caught. I&#8217;m not complaining. In fact I&#8217;m totally impressed that it happened so fast. <img src="http://www.terminally-incoherent.com/blog/wp-includes/images/smilies/icon_smile.gif" alt=")" class="wp-smiley" />  It&#8217;s a good thing!
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Dougie Lawson</title>
		<link>http://www.terminally-incoherent.com/blog/2008/03/04/pishing-aint-easy/#comment-8393</link>
		<pubDate>Sun, 09 Mar 2008 12:28:18 +0000</pubDate>
		<guid>http://www.terminally-incoherent.com/blog/2008/03/04/pishing-aint-easy/#comment-8393</guid>
					<description>Why would you publish this on the public Internet? 

Do you not have a test bed apache (or Xampp) system that sits on a non-routable network block (192.168.x.x, 172.[16-31].x.x, 10.x.x.x) where you can demonstrate to your students without the risk of exposure to the big-bad-interwebbythingy. 

You were caught, you deserved to be caught - it's good to see that the anti-phishing systems work so well.</description>
		<content:encoded><![CDATA[<p>Why would you publish this on the public Internet? </p>
<p>Do you not have a test bed apache (or Xampp) system that sits on a non-routable network block (192.168.x.x, 172.[16-31].x.x, 10.x.x.x) where you can demonstrate to your students without the risk of exposure to the big-bad-interwebbythingy. </p>
<p>You were caught, you deserved to be caught - it&#8217;s good to see that the anti-phishing systems work so well.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Michael Molsner</title>
		<link>http://www.terminally-incoherent.com/blog/2008/03/04/pishing-aint-easy/#comment-8392</link>
		<pubDate>Sun, 09 Mar 2008 07:35:22 +0000</pubDate>
		<guid>http://www.terminally-incoherent.com/blog/2008/03/04/pishing-aint-easy/#comment-8392</guid>
					<description>Hello,

This is definitely an interesting project and many of such should be done in order to educate as many people as possible about phishing matters. It is always a surprise to discover "drop files" and to see how many users did input their real credentials:-/

Much to do!

Cheers,
Michael
[KL Japan]</description>
		<content:encoded><![CDATA[<p>Hello,</p>
<p>This is definitely an interesting project and many of such should be done in order to educate as many people as possible about phishing matters. It is always a surprise to discover &#8220;drop files&#8221; and to see how many users did input their real credentials:-/</p>
<p>Much to do!</p>
<p>Cheers,<br />
Michael<br />
[KL Japan]
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Travis McCrea</title>
		<link>http://www.terminally-incoherent.com/blog/2008/03/04/pishing-aint-easy/#comment-8391</link>
		<pubDate>Sat, 08 Mar 2008 21:35:44 +0000</pubDate>
		<guid>http://www.terminally-incoherent.com/blog/2008/03/04/pishing-aint-easy/#comment-8391</guid>
					<description>I am actually developing a website that will counter phishing in a whole new way un seen to the internet so far, its too new (and simple) of an idea to post here on your blog, but send me an email I will tell you about it. It will decrease phishing on the internet by at least 20% (a lot of you think about it) if websites give it a chance.</description>
		<content:encoded><![CDATA[<p>I am actually developing a website that will counter phishing in a whole new way un seen to the internet so far, its too new (and simple) of an idea to post here on your blog, but send me an email I will tell you about it. It will decrease phishing on the internet by at least 20% (a lot of you think about it) if websites give it a chance.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Miloš</title>
		<link>http://www.terminally-incoherent.com/blog/2008/03/04/pishing-aint-easy/#comment-8368</link>
		<pubDate>Thu, 06 Mar 2008 20:29:01 +0000</pubDate>
		<guid>http://www.terminally-incoherent.com/blog/2008/03/04/pishing-aint-easy/#comment-8368</guid>
					<description>[quote post="2324"]Btw, Copeland emailed me about 3pm - he was very nice about it, and said I can keep it up but asked to hide it from the outside world so that we don’t get flagged. )[/quote]

 You see we have woodpeckers as well. :)</description>
		<content:encoded><![CDATA[<blockquote cite="http://www.terminally-incoherent.com/blog/2008/03/04/pishing-aint-easy/"><p>
Btw, Copeland emailed me about 3pm - he was very nice about it, and said I can keep it up but asked to hide it from the outside world so that we don’t get flagged. )</p>
</blockquote>
<p> You see we have woodpeckers as well. <img src="http://www.terminally-incoherent.com/blog/wp-includes/images/smilies/icon_smile.gif" alt=")" class="wp-smiley" />
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Luke Maciak</title>
		<link>http://www.terminally-incoherent.com/blog/2008/03/04/pishing-aint-easy/#comment-8336</link>
		<pubDate>Wed, 05 Mar 2008 15:57:18 +0000</pubDate>
		<guid>http://www.terminally-incoherent.com/blog/2008/03/04/pishing-aint-easy/#comment-8336</guid>
					<description>Sigh... I didn't even get to use it yesterday. :(

&lt;strong&gt;@jambarama&lt;/strong&gt; - I never considered that. :P Most of the stuff I do in class is pretty much straight out of the textbook. I don't remember the title/authors of the top of my head but it is semi-decent. It comes with ppt slides for each chapter which I usually modify, splice and hack into shape.

&lt;strong&gt;@coaster&lt;/strong&gt; - I don't think that would be the case - considering none of them have seen it yet. I put the site up in the wee hours of the morning and it was already flagged when I got up for work. I didn't actually show it in class.

&lt;strong&gt;@Miloš&lt;/strong&gt; - heh! Woodpecked! lol You got to give it to them - they are fast. 

Btw, Copeland emailed me about 3pm - he was very nice about it, and said I can keep it up but asked to hide it from the outside world so that we don't get flagged. :)

&lt;strong&gt;@ZeWrestler&lt;/strong&gt; - oh, I always thought it was pishing as in fishing with an f. Go figure. :P

I haven't seen Robila the whole semester. He apparently is doing "off campus research" on Tuesdays which means I don't see him at all these days. :(

Oh, and 3-30 days was what I was expecting - I thought i can put it up, early morning, show it in class the same day and then take it down without it being flagged. I did not expect it showing up on black lists mere hours after it hit the internets.

&lt;strong&gt;@Ricardo&lt;/strong&gt; - Hmmm... Let's see. I use faviconize, Fasterfox, adblock, greasemonkey, stylish, Google notebook, firebug, adsense notifier, and twitterfox</description>
		<content:encoded><![CDATA[<p>Sigh&#8230; I didn&#8217;t even get to use it yesterday. <img src="http://www.terminally-incoherent.com/blog/wp-includes/images/smilies/icon_sad.gif" alt="(" class="wp-smiley" /> </p>
<p><strong>@jambarama</strong> - I never considered that. <img src="http://www.terminally-incoherent.com/blog/wp-includes/images/smilies/icon_razz.gif" alt="P" class="wp-smiley" />  Most of the stuff I do in class is pretty much straight out of the textbook. I don&#8217;t remember the title/authors of the top of my head but it is semi-decent. It comes with ppt slides for each chapter which I usually modify, splice and hack into shape.</p>
<p><strong>@coaster</strong> - I don&#8217;t think that would be the case - considering none of them have seen it yet. I put the site up in the wee hours of the morning and it was already flagged when I got up for work. I didn&#8217;t actually show it in class.</p>
<p><strong>@Miloš</strong> - heh! Woodpecked! lol You got to give it to them - they are fast. </p>
<p>Btw, Copeland emailed me about 3pm - he was very nice about it, and said I can keep it up but asked to hide it from the outside world so that we don&#8217;t get flagged. <img src="http://www.terminally-incoherent.com/blog/wp-includes/images/smilies/icon_smile.gif" alt=")" class="wp-smiley" /> </p>
<p><strong>@ZeWrestler</strong> - oh, I always thought it was pishing as in fishing with an f. Go figure. <img src="http://www.terminally-incoherent.com/blog/wp-includes/images/smilies/icon_razz.gif" alt="P" class="wp-smiley" /> </p>
<p>I haven&#8217;t seen Robila the whole semester. He apparently is doing &#8220;off campus research&#8221; on Tuesdays which means I don&#8217;t see him at all these days. <img src="http://www.terminally-incoherent.com/blog/wp-includes/images/smilies/icon_sad.gif" alt="(" class="wp-smiley" /> </p>
<p>Oh, and 3-30 days was what I was expecting - I thought i can put it up, early morning, show it in class the same day and then take it down without it being flagged. I did not expect it showing up on black lists mere hours after it hit the internets.</p>
<p><strong>@Ricardo</strong> - Hmmm&#8230; Let&#8217;s see. I use faviconize, Fasterfox, adblock, greasemonkey, stylish, Google notebook, firebug, adsense notifier, and twitterfox
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Ricardo</title>
		<link>http://www.terminally-incoherent.com/blog/2008/03/04/pishing-aint-easy/#comment-8334</link>
		<pubDate>Wed, 05 Mar 2008 08:08:37 +0000</pubDate>
		<guid>http://www.terminally-incoherent.com/blog/2008/03/04/pishing-aint-easy/#comment-8334</guid>
					<description>Hey Luke,

I have a question out of curiosity: What are the add-ons you are using on Firefox? I can reconize the FavicognizeTab, the Fasterfox, the Gmail plugin, the Firebug, and the adblock from your print screen.

What about the others?</description>
		<content:encoded><![CDATA[<p>Hey Luke,</p>
<p>I have a question out of curiosity: What are the add-ons you are using on Firefox? I can reconize the FavicognizeTab, the Fasterfox, the Gmail plugin, the Firebug, and the adblock from your print screen.</p>
<p>What about the others?
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: ZeWrestler</title>
		<link>http://www.terminally-incoherent.com/blog/2008/03/04/pishing-aint-easy/#comment-8333</link>
		<pubDate>Tue, 04 Mar 2008 22:31:24 +0000</pubDate>
		<guid>http://www.terminally-incoherent.com/blog/2008/03/04/pishing-aint-easy/#comment-8333</guid>
					<description>Dude,

First, its &lt;strong&gt;phishing&lt;/strong&gt; not &lt;em&gt;pishing&lt;/em&gt;.

Second, have you shown this to Robila?

Third, according to APWG's December report the avg lifetime of a phishing site was 3 days where the longest lived site is 31. So half of the worlds phishing sites are taken down in under 3 days of launch. 

Good to hear phishing education is continuing there, even after I'm gone.</description>
		<content:encoded><![CDATA[<p>Dude,</p>
<p>First, its <strong>phishing</strong> not <em>pishing</em>.</p>
<p>Second, have you shown this to Robila?</p>
<p>Third, according to APWG&#8217;s December report the avg lifetime of a phishing site was 3 days where the longest lived site is 31. So half of the worlds phishing sites are taken down in under 3 days of launch. </p>
<p>Good to hear phishing education is continuing there, even after I&#8217;m gone.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Miloš</title>
		<link>http://www.terminally-incoherent.com/blog/2008/03/04/pishing-aint-easy/#comment-8328</link>
		<pubDate>Tue, 04 Mar 2008 18:15:34 +0000</pubDate>
		<guid>http://www.terminally-incoherent.com/blog/2008/03/04/pishing-aint-easy/#comment-8328</guid>
					<description>You got "woodpecked"! :) Kaspersky is big into 24/7/365 development and updates which you can read about &lt;a href="http://www.eweek.com/c/a/Security/Kaspersky-Labs-Secret-Sauce-Uses-Woodpeckers/" rel="nofollow"&gt;here&lt;/a&gt;. Their business model is impressive and it is one of main reasons they keep improving and expanding every year.  

On the other hand you are almost dead on when it comes to sys admins...but I would place the cut off to 5:05 PM for most of them.</description>
		<content:encoded><![CDATA[<p>You got &#8220;woodpecked&#8221;! <img src="http://www.terminally-incoherent.com/blog/wp-includes/images/smilies/icon_smile.gif" alt=")" class="wp-smiley" />  Kaspersky is big into 24/7/365 development and updates which you can read about <a href="http://www.eweek.com/c/a/Security/Kaspersky-Labs-Secret-Sauce-Uses-Woodpeckers/" rel="nofollow">here</a>. Their business model is impressive and it is one of main reasons they keep improving and expanding every year.  </p>
<p>On the other hand you are almost dead on when it comes to sys admins&#8230;but I would place the cut off to 5:05 PM for most of them.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Matt`</title>
		<link>http://www.terminally-incoherent.com/blog/2008/03/04/pishing-aint-easy/#comment-8327</link>
		<pubDate>Tue, 04 Mar 2008 18:06:37 +0000</pubDate>
		<guid>http://www.terminally-incoherent.com/blog/2008/03/04/pishing-aint-easy/#comment-8327</guid>
					<description>Out of interest, what do you tell them in the way of how to recognise such sites?

The obvious one would be the domain not being ebay.com, although that can be hidden more cleverly using subdomains (e.g. http://signin.ebay.com.evilphishers.com, but with a slightly less obvious name than "evilphishers"). Anywhere where ebay would refer to you by name, like in their emails, will be a giveaway when the phishers just call you customer.. the links given in emails you can check the URL of too...

Obviously any mistakes in the reproduction of the real page will be a pretty big flag.

Easiest way to avoid all the crap is to always go to the homepage by typing it in yourself, instead of clicking links in emails - if there's some important account upgrade they need you to do (not that there ever really is) then it'll be available from logging into the main page.</description>
		<content:encoded><![CDATA[<p>Out of interest, what do you tell them in the way of how to recognise such sites?</p>
<p>The obvious one would be the domain not being ebay.com, although that can be hidden more cleverly using subdomains (e.g. <a href="http://signin.ebay.com.evilphishers.com," rel="nofollow">http://signin.ebay.com.evilphishers.com,</a> but with a slightly less obvious name than &#8220;evilphishers&#8221;). Anywhere where ebay would refer to you by name, like in their emails, will be a giveaway when the phishers just call you customer.. the links given in emails you can check the URL of too&#8230;</p>
<p>Obviously any mistakes in the reproduction of the real page will be a pretty big flag.</p>
<p>Easiest way to avoid all the crap is to always go to the homepage by typing it in yourself, instead of clicking links in emails - if there&#8217;s some important account upgrade they need you to do (not that there ever really is) then it&#8217;ll be available from logging into the main page.
</p>
]]></content:encoded>
				</item>
</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.679 seconds -->
