Discussion:
Analysis: Postbank.nl Phishing Scam
(too old to reply)
Vincent van Scherpenseel
2005-06-06 13:48:21 UTC
Permalink
Hi there,

I've just finished writing a technical analysis on the Postbank.nl phishing
scam hitting Dutch e-bankers as from last Saturday. This was fortunately
really big in the Dutch media so the amount of victims may have been limited.

I found some interesting things in the scam: the victim was redirected 4 times
(including through Google and MSN) before arriving at his/her final location,
the use of URL obfuscating to social engineer the user into clicking 'the
link below' and the inclusion of a stylesheet over a HTTPs connection to
resemble an authentic bank to Joe Average.

You can read the analysis at: http://www.syn-ack.org/papers/postbank.html .

I would love to receive any feedback on it, either positive or negative, as
long as arguments are supplied.

- Vincent 'rastakid' van Scherpenseel
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Moritz Naumann
2005-06-06 18:39:05 UTC
Permalink
Post by Vincent van Scherpenseel
You can read the analysis at: http://www.syn-ack.org/papers/postbank.html .
I would love to receive any feedback on it, either positive or negative, as
long as arguments are supplied.
Unfortunately I wasn't able to determine what 'RCVD_IN_LSORBS' means.
A Google and a Google Groups session yielded zero results.
I'm not sure whether this is a common SpamAssassin rule (I simply didn't
check). I also do no know what the 'L' in 'LSORBS' stands for. However,
the rest clearly means that the downmost 'Received' email header line
contained an IP address which is listed in the SORBS ("Spam and Open
Relay Blocking System") DNS blacklist <http://www.sorbs.net/>.

Moritz Naumann
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Loading...