<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.0.4" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: PhishTank in the News: October 10, 2006</title>
	<link>http://www.phishtank.com/blog/2006/10/10/phishtank-in-the-news-october-10-2006/</link>
	<description>A blog about and from PhishTank, a collaborative clearinghouse for data about phishing.</description>
	<pubDate>Tue, 07 Oct 2008 11:42:30 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.0.4</generator>

	<item>
		<title>by: Matt</title>
		<link>http://www.phishtank.com/blog/2006/10/10/phishtank-in-the-news-october-10-2006/#comment-72</link>
		<pubDate>Tue, 10 Oct 2006 18:26:49 +0000</pubDate>
		<guid>http://www.phishtank.com/blog/2006/10/10/phishtank-in-the-news-october-10-2006/#comment-72</guid>
					<description>I agree Stuart, it is kind of tough, if they were easy to pick out, they wouldn't be effective ;).  I'm working on putting together a
program called Bobber (think long and hard about that one) that will look at the URI itself (not the content of the website) and give
odds on if that site is a phish or not.  I'm not sure how effective it will be because it's not made yet, but with the number of phishes
i've verified so far, I see a lot of very promising trends.</description>
		<content:encoded><![CDATA[<p>I agree Stuart, it is kind of tough, if they were easy to pick out, they wouldn&#8217;t be effective <img src='http://www.phishtank.com/blog/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> .  I&#8217;m working on putting together a<br />
program called Bobber (think long and hard about that one) that will look at the URI itself (not the content of the website) and give<br />
odds on if that site is a phish or not.  I&#8217;m not sure how effective it will be because it&#8217;s not made yet, but with the number of phishes<br />
i&#8217;ve verified so far, I see a lot of very promising trends.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Stuart</title>
		<link>http://www.phishtank.com/blog/2006/10/10/phishtank-in-the-news-october-10-2006/#comment-71</link>
		<pubDate>Tue, 10 Oct 2006 16:52:17 +0000</pubDate>
		<guid>http://www.phishtank.com/blog/2006/10/10/phishtank-in-the-news-october-10-2006/#comment-71</guid>
					<description>I recognize phishes by the forged or unrelated email headers, not by the URLs.  For instance, ebay is not going to send their official mail from hotmail.   The outright forgeries (10000+ per day just to me) are rejected in SMTP envelope via SPF (http://new.openspf.org) protocol and some adhoc heuristics (e.g. reject connections using my own domain in HELO, reject invalid numeric HELO like 1.2.3.4).  So I find it a little difficult to judge whether something is a phish based just on a website.</description>
		<content:encoded><![CDATA[<p>I recognize phishes by the forged or unrelated email headers, not by the URLs.  For instance, ebay is not going to send their official mail from hotmail.   The outright forgeries (10000+ per day just to me) are rejected in SMTP envelope via SPF (http://new.openspf.org) protocol and some adhoc heuristics (e.g. reject connections using my own domain in HELO, reject invalid numeric HELO like 1.2.3.4).  So I find it a little difficult to judge whether something is a phish based just on a website.
</p>
]]></content:encoded>
				</item>
</channel>
</rss>
