OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
[Dailydave] Interesting phish

From: Tyler Krpata (krpatasecgmail.com)
Date: Mon Feb 12 2007 - 13:16:23 CST


I had an interesting Bank of America phish pointed out to me...it gets
around the "wrong URL" problem by popping up a new window which
disables the location bar and creates a lookalike IE location bar of
its own which contains a legit URL. This is something I had actually
been thinking about and played with a bit about a year ago, so I'm not
hugely surprised to see it in the wild. (Apologies if this is not a
new tactic, but I hadn't seen it before.)

Not sure if it's kosher to post phishing URL's to the list, but I will
if anyone wants to see it.
_______________________________________________
Dailydave mailing list
Dailydavelists.immunitysec.com
http://lists.immunitysec.com/mailman/listinfo/dailydave