<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.0.4" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: PhishTank in the News: June 12, 2007</title>
	<link>http://www.phishtank.com/blog/2007/06/12/phishtank-in-the-news-june-12-2007/</link>
	<description>A blog about and from PhishTank, a collaborative clearinghouse for data about phishing.</description>
	<pubDate>Sun, 06 Jul 2008 01:58:35 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.0.4</generator>

	<item>
		<title>by: Stuart Gathman</title>
		<link>http://www.phishtank.com/blog/2007/06/12/phishtank-in-the-news-june-12-2007/#comment-35446</link>
		<pubDate>Wed, 01 Aug 2007 14:23:45 +0000</pubDate>
		<guid>http://www.phishtank.com/blog/2007/06/12/phishtank-in-the-news-june-12-2007/#comment-35446</guid>
					<description>Actually, what may be happening is that link extraction is working better since Jul 9, and my submissions are being rejected as dups.  I guess that is a consequence of having lots of people working at it.</description>
		<content:encoded><![CDATA[<p>Actually, what may be happening is that link extraction is working better since Jul 9, and my submissions are being rejected as dups.  I guess that is a consequence of having lots of people working at it.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Stuart Gathman</title>
		<link>http://www.phishtank.com/blog/2007/06/12/phishtank-in-the-news-june-12-2007/#comment-35445</link>
		<pubDate>Wed, 01 Aug 2007 14:18:10 +0000</pubDate>
		<guid>http://www.phishtank.com/blog/2007/06/12/phishtank-in-the-news-june-12-2007/#comment-35445</guid>
					<description>I have been having trouble submitting phishes via email.  I bounce them to my coded phishtank email.  Up through Jul 9, the problem was that the wrong URL (i.e. the legit URL) was extracted from the phish, not the one the user is invited to click on - this resulted in many valid phishes getting voted invalid (because the URL shown them was legit).  Since Jul 9, all my submissions are getting rejected as spam.  The last example is:

----------------
Date: Tue, 31 Jul 2007 06:58:04 -0500
From: PayPal Inc. 
Subject: your paypal account need to be updated!

    [ The following text is in the "Windows-1251" character set. ]
    [ Your display is set for the "ISO-8859-1" character set.  ]
    [ Some characters may be displayed incorrectly. ]

Dear PayPal Member,

Your account has been randomly flagged in our system as a part of our
routine security measures. This is a must to ensure that only you have
access and use of your Paypal account and to ensure a safe PayPal
experience. We require all flagged accounts to verify their information
on file with us. To verify your information at this time, please visit
our secure server webform by clicking the hyperlink below:

Click here to verify your Information
... dire warnings should you fail to click :-) ...
----------------------------

And the link goes to http://mail.yoda.com.tw/lndex.html

It is too time consuming to cut and paste phishes to submit them on the
website, so it is disappointing that email submission isn't working well.</description>
		<content:encoded><![CDATA[<p>I have been having trouble submitting phishes via email.  I bounce them to my coded phishtank email.  Up through Jul 9, the problem was that the wrong URL (i.e. the legit URL) was extracted from the phish, not the one the user is invited to click on - this resulted in many valid phishes getting voted invalid (because the URL shown them was legit).  Since Jul 9, all my submissions are getting rejected as spam.  The last example is:</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
Date: Tue, 31 Jul 2007 06:58:04 -0500<br />
From: PayPal Inc.<br />
Subject: your paypal account need to be updated!</p>
<p>    [ The following text is in the &#8220;Windows-1251&#8243; character set. ]<br />
    [ Your display is set for the &#8220;ISO-8859-1&#8243; character set.  ]<br />
    [ Some characters may be displayed incorrectly. ]</p>
<p>Dear PayPal Member,</p>
<p>Your account has been randomly flagged in our system as a part of our<br />
routine security measures. This is a must to ensure that only you have<br />
access and use of your Paypal account and to ensure a safe PayPal<br />
experience. We require all flagged accounts to verify their information<br />
on file with us. To verify your information at this time, please visit<br />
our secure server webform by clicking the hyperlink below:</p>
<p>Click here to verify your Information<br />
&#8230; dire warnings should you fail to click <img src='http://www.phishtank.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' />  &#8230;<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</p>
<p>And the link goes to <a href='http://mail.yoda.com.tw/lndex.html' rel='nofollow'>http://mail.yoda.com.tw/lndex.html</a></p>
<p>It is too time consuming to cut and paste phishes to submit them on the<br />
website, so it is disappointing that email submission isn&#8217;t working well.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Adam</title>
		<link>http://www.phishtank.com/blog/2007/06/12/phishtank-in-the-news-june-12-2007/#comment-34344</link>
		<pubDate>Thu, 26 Jul 2007 16:43:18 +0000</pubDate>
		<guid>http://www.phishtank.com/blog/2007/06/12/phishtank-in-the-news-june-12-2007/#comment-34344</guid>
					<description>http://www.phishtank.com/contact.php at the bottom of every phishtank page ;)

As far as that "last scanned" date....no idea, Im betting it's a typo.  Someone brought it up on the mailing list too, but dont think there was every an official response "why" hehe.</description>
		<content:encoded><![CDATA[<p><a href='http://www.phishtank.com/contact.php' rel='nofollow'>http://www.phishtank.com/contact.php</a> at the bottom of every phishtank page <img src='http://www.phishtank.com/blog/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>As far as that &#8220;last scanned&#8221; date&#8230;.no idea, Im betting it&#8217;s a typo.  Someone brought it up on the mailing list too, but dont think there was every an official response &#8220;why&#8221; hehe.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Mads Dam</title>
		<link>http://www.phishtank.com/blog/2007/06/12/phishtank-in-the-news-june-12-2007/#comment-29787</link>
		<pubDate>Sun, 24 Jun 2007 23:46:57 +0000</pubDate>
		<guid>http://www.phishtank.com/blog/2007/06/12/phishtank-in-the-news-june-12-2007/#comment-29787</guid>
					<description>I was going to take closer look at
http://ksjab.hk/?338ee7c634591933434671c16
before voting, but this text appeared insted of the screenshot:

"This phishing site is known to contain a virus or browser exploit.
In this case we recommend you base your decision on the screenshot provided by PhishTank (if available) and/or the technical details. If you wish to continue, please insure you are using the last version of your computer's operating system with all recent patches and upgrades applied, as well as the latest version available of your web browser. Last Scanned: Nov 30th 1999"

I don't doubt the first part of the text, but the end made me wonder: 
Do you really mean 1999? It does look like an error to me...

PS: How do I contact phishtank? I looked in vain for 'contact' in the menu.
This blog seems to be the only possibility, or am I wrong..?</description>
		<content:encoded><![CDATA[<p>I was going to take closer look at<br />
<a href='http://ksjab.hk/?338ee7c634591933434671c16' rel='nofollow'>http://ksjab.hk/?338ee7c634591933434671c16</a><br />
before voting, but this text appeared insted of the screenshot:</p>
<p>&#8220;This phishing site is known to contain a virus or browser exploit.<br />
In this case we recommend you base your decision on the screenshot provided by PhishTank (if available) and/or the technical details. If you wish to continue, please insure you are using the last version of your computer&#8217;s operating system with all recent patches and upgrades applied, as well as the latest version available of your web browser. Last Scanned: Nov 30th 1999&#8243;</p>
<p>I don&#8217;t doubt the first part of the text, but the end made me wonder:<br />
Do you really mean 1999? It does look like an error to me&#8230;</p>
<p>PS: How do I contact phishtank? I looked in vain for &#8216;contact&#8217; in the menu.<br />
This blog seems to be the only possibility, or am I wrong..?
</p>
]]></content:encoded>
				</item>
</channel>
</rss>
