<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.0.4" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: The Tank is bubbling</title>
	<link>http://www.phishtank.com/blog/2007/04/11/the-tank-is-bubbling/</link>
	<description>A blog about and from PhishTank, a collaborative clearinghouse for data about phishing.</description>
	<pubDate>Thu, 21 Aug 2008 06:44:54 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.0.4</generator>

	<item>
		<title>by: MASA</title>
		<link>http://www.phishtank.com/blog/2007/04/11/the-tank-is-bubbling/#comment-16542</link>
		<pubDate>Fri, 20 Apr 2007 01:01:07 +0000</pubDate>
		<guid>http://www.phishtank.com/blog/2007/04/11/the-tank-is-bubbling/#comment-16542</guid>
					<description>Why don't you detect the strings that are sent, and if one of the strings has a hostname match with one in the database, then red flag it.

Simply:

www.googlephishingsite.com/lalalalalala/dieusers/index.html is in the database

The phisher sets up another phishing site that is like:
www.googlephishingsite.com/lala2/losers/haha/index.html

User visits the second url, and it is sent to phishtank (if they use SiteChecker [:)]). PT says, hmm...it's close to this result which is a phish, and tells the software that it is a phish. The phishing site is blocked.</description>
		<content:encoded><![CDATA[<p>Why don&#8217;t you detect the strings that are sent, and if one of the strings has a hostname match with one in the database, then red flag it.</p>
<p>Simply:</p>
<p><a href='http://www.googlephishingsite.com/lalalalalala/dieusers/index.html' rel='nofollow'>www.googlephishingsite.com/lalalalalala/dieusers/index.html</a> is in the database</p>
<p>The phisher sets up another phishing site that is like:<br />
<a href='http://www.googlephishingsite.com/lala2/losers/haha/index.html' rel='nofollow'>www.googlephishingsite.com/lala2/losers/haha/index.html</a></p>
<p>User visits the second url, and it is sent to phishtank (if they use SiteChecker [:)]). PT says, hmm&#8230;it&#8217;s close to this result which is a phish, and tells the software that it is a phish. The phishing site is blocked.
</p>
]]></content:encoded>
				</item>
</channel>
</rss>
