<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: IE7: 22 hours to catch a phish</title>
	<atom:link href="http://www.itwriting.com/blog/30-ie7-22-hours-to-catch-a-phish.html/feed" rel="self" type="application/rss+xml" />
	<link>http://www.itwriting.com/blog/30-ie7-22-hours-to-catch-a-phish.html</link>
	<description>Tech writing blog</description>
	<lastBuildDate>Sun, 12 Feb 2012 05:28:38 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Mark Zaugg</title>
		<link>http://www.itwriting.com/blog/30-ie7-22-hours-to-catch-a-phish.html/comment-page-1#comment-52</link>
		<dc:creator>Mark Zaugg</dc:creator>
		<pubDate>Mon, 30 Oct 2006 22:17:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.itwriting.com/blog/?p=30#comment-52</guid>
		<description>If nothing else, it&#039;s been enlightening and something that I need to guard against - both from a user standpoint as well as guarding my servers.

This started from me reading criticism of Firefox&#039;s &quot;weak phishing filter&quot; and the results I came across certainly weren&#039;t what I anticipated.

Nice to run across you, Tim.  Welcome to my RSS feeds.</description>
		<content:encoded><![CDATA[<p>If nothing else, it&#8217;s been enlightening and something that I need to guard against &#8211; both from a user standpoint as well as guarding my servers.</p>
<p>This started from me reading criticism of Firefox&#8217;s &#8220;weak phishing filter&#8221; and the results I came across certainly weren&#8217;t what I anticipated.</p>
<p>Nice to run across you, Tim.  Welcome to my RSS feeds.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tim</title>
		<link>http://www.itwriting.com/blog/30-ie7-22-hours-to-catch-a-phish.html/comment-page-1#comment-51</link>
		<dc:creator>Tim</dc:creator>
		<pubDate>Mon, 30 Oct 2006 21:58:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.itwriting.com/blog/?p=30#comment-51</guid>
		<description>The site is now access denied - maybe because I just reported it to the site admin. I guess the web server there was hacked.

Sorry to spoil the fun!

Tim</description>
		<content:encoded><![CDATA[<p>The site is now access denied &#8211; maybe because I just reported it to the site admin. I guess the web server there was hacked.</p>
<p>Sorry to spoil the fun!</p>
<p>Tim</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tim</title>
		<link>http://www.itwriting.com/blog/30-ie7-22-hours-to-catch-a-phish.html/comment-page-1#comment-50</link>
		<dc:creator>Tim</dc:creator>
		<pubDate>Mon, 30 Oct 2006 21:39:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.itwriting.com/blog/?p=30#comment-50</guid>
		<description>Thanks Mark. It looks like you are getting a different result than me, very strange (and suggests the IE7 phishing filter is even less useful than I thought).

I&#039;ve made the url non-clickable as I don&#039;t want an actual link on this site.

Tim</description>
		<content:encoded><![CDATA[<p>Thanks Mark. It looks like you are getting a different result than me, very strange (and suggests the IE7 phishing filter is even less useful than I thought).</p>
<p>I&#8217;ve made the url non-clickable as I don&#8217;t want an actual link on this site.</p>
<p>Tim</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark Zaugg</title>
		<link>http://www.itwriting.com/blog/30-ie7-22-hours-to-catch-a-phish.html/comment-page-1#comment-49</link>
		<dc:creator>Mark Zaugg</dc:creator>
		<pubDate>Mon, 30 Oct 2006 21:29:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.itwriting.com/blog/?p=30#comment-49</guid>
		<description>The exact link I&#039;m following is

http : //bankofamerica.com.wowtnc.com/cgi.bin/sso.login.controllernoscript=true/
sessiondid=2335454893_Secured152388884&amp;Update/

Going directly from Firefox it&#039;s reported as phishing. IE does not.

You&#039;re correct, I got to it via the directory listing. IE is not reporting the directory listing either.

Now I&#039;m thinking it&#039;s just a matter of the time between you&#039;re report and my finding it and hopefully it&#039;ll get reported as a phishing site promptly. To me, at least, this is indicating that the idea of a heuristic scan based on &quot;bank pin&quot; and &quot;account number&quot; etc. etc. might be a very useful tool.

At least until the next escalation..

- Mark</description>
		<content:encoded><![CDATA[<p>The exact link I&#8217;m following is</p>
<p>http : //bankofamerica.com.wowtnc.com/cgi.bin/sso.login.controllernoscript=true/<br />
sessiondid=2335454893_Secured152388884&#038;Update/</p>
<p>Going directly from Firefox it&#8217;s reported as phishing. IE does not.</p>
<p>You&#8217;re correct, I got to it via the directory listing. IE is not reporting the directory listing either.</p>
<p>Now I&#8217;m thinking it&#8217;s just a matter of the time between you&#8217;re report and my finding it and hopefully it&#8217;ll get reported as a phishing site promptly. To me, at least, this is indicating that the idea of a heuristic scan based on &#8220;bank pin&#8221; and &#8220;account number&#8221; etc. etc. might be a very useful tool.</p>
<p>At least until the next escalation..</p>
<p>- Mark</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tim</title>
		<link>http://www.itwriting.com/blog/30-ie7-22-hours-to-catch-a-phish.html/comment-page-1#comment-48</link>
		<dc:creator>Tim</dc:creator>
		<pubDate>Mon, 30 Oct 2006 21:16:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.itwriting.com/blog/?p=30#comment-48</guid>
		<description>Mark,

I&#039;m surprised too. I&#039;ve just been back to the site and IE7 still reports it to me as a phishing site. Maybe a temporary glitch in Microsoft&#039;s phishing check server?

No... I think I may have it. When you put in the partial url, you don&#039;t get the phishing page. You get (at the time of writing) an apache directory listing. The phishing page is listed; it has the curious name &quot;sessiondid=233545489..&quot;.

If I go to the actual page, both IE7 and FireFox report it. But if I go to the directory listing, FireFox reports it, IE7 does not. Is that the difference here?

Tim</description>
		<content:encoded><![CDATA[<p>Mark,</p>
<p>I&#8217;m surprised too. I&#8217;ve just been back to the site and IE7 still reports it to me as a phishing site. Maybe a temporary glitch in Microsoft&#8217;s phishing check server?</p>
<p>No&#8230; I think I may have it. When you put in the partial url, you don&#8217;t get the phishing page. You get (at the time of writing) an apache directory listing. The phishing page is listed; it has the curious name &#8220;sessiondid=233545489..&#8221;.</p>
<p>If I go to the actual page, both IE7 and FireFox report it. But if I go to the directory listing, FireFox reports it, IE7 does not. Is that the difference here?</p>
<p>Tim</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark Zaugg</title>
		<link>http://www.itwriting.com/blog/30-ie7-22-hours-to-catch-a-phish.html/comment-page-1#comment-46</link>
		<dc:creator>Mark Zaugg</dc:creator>
		<pubDate>Mon, 30 Oct 2006 20:59:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.itwriting.com/blog/?p=30#comment-46</guid>
		<description>I&#039;m... confused.

I&#039;m a sysadmin and I&#039;m experimenting today trying to beat my users to the punch by exploring phishing sites.

I&#039;m happy to see you&#039;ve done the heavy lifting Tim. But when re-enacting your experiment here, I took what URL was visible and entered it into the address bar for IE7 and Firefox. Now, I had to do some drilling down to get to the root webpage - please understand this is a &quot;rough and ready test&quot; while I&#039;m experimenting.

Since you&#039;d reported it, I thought it would be a sure bet to be reported as a phishing site. But IE7 let me through as your original test. Firefox / Google did report it as a phishing site.

I&#039;ve reported the page I encountered and I&#039;m also waiting for it to get reported.

I read the &lt;a href=&quot;http://blogs.msdn.com/ie/archive/2005/09/09/463204.aspx&quot; rel=&quot;nofollow&quot; rel=&quot;nofollow&quot;&gt;on phishing&lt;/a&gt; which gave me an overview but it&#039;s left me wanting more..

I&#039;m curious: Is this going to be a battle of escalation where small changes are invalidating the phishing filter? Or has the page been reported in Google and I&#039;m only half way through the life-cycle?

This isn&#039;t what I was expecting. I thought it would be universally reported as a phishing site. I&#039;ll stay in touch and keep you up to date with my findings.</description>
		<content:encoded><![CDATA[<p>I&#8217;m&#8230; confused.</p>
<p>I&#8217;m a sysadmin and I&#8217;m experimenting today trying to beat my users to the punch by exploring phishing sites.</p>
<p>I&#8217;m happy to see you&#8217;ve done the heavy lifting Tim. But when re-enacting your experiment here, I took what URL was visible and entered it into the address bar for IE7 and Firefox. Now, I had to do some drilling down to get to the root webpage &#8211; please understand this is a &#8220;rough and ready test&#8221; while I&#8217;m experimenting.</p>
<p>Since you&#8217;d reported it, I thought it would be a sure bet to be reported as a phishing site. But IE7 let me through as your original test. Firefox / Google did report it as a phishing site.</p>
<p>I&#8217;ve reported the page I encountered and I&#8217;m also waiting for it to get reported.</p>
<p>I read the <a href="http://blogs.msdn.com/ie/archive/2005/09/09/463204.aspx" rel="nofollow" rel="nofollow">on phishing</a> which gave me an overview but it&#8217;s left me wanting more..</p>
<p>I&#8217;m curious: Is this going to be a battle of escalation where small changes are invalidating the phishing filter? Or has the page been reported in Google and I&#8217;m only half way through the life-cycle?</p>
<p>This isn&#8217;t what I was expecting. I thought it would be universally reported as a phishing site. I&#8217;ll stay in touch and keep you up to date with my findings.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

