<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: PhishTank Annual Report: U.S. telecoms hosting phishes; OpenDNS offering a solution</title>
	<atom:link href="http://www.phishtank.com/blog/2007/10/09/phishtank-annual-report/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.phishtank.com/blog/2007/10/09/phishtank-annual-report/</link>
	<description>A blog about and from PhishTank, a collaborative clearinghouse for data about phishing.</description>
	<lastBuildDate>Tue, 30 Jun 2009 19:58:42 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: .: GAFNO.com - Hot World News Blog :. &#187; Blog Archive &#187; Senate anti-phishing bill outlaws&#8230; what&#8217;s already illegal</title>
		<link>http://www.phishtank.com/blog/2007/10/09/phishtank-annual-report/comment-page-1/#comment-71718</link>
		<dc:creator>.: GAFNO.com - Hot World News Blog :. &#187; Blog Archive &#187; Senate anti-phishing bill outlaws&#8230; what&#8217;s already illegal</dc:creator>
		<pubDate>Wed, 27 Feb 2008 04:49:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.phishtank.com/blog/2007/10/09/phishtank-annual-report/#comment-71718</guid>
		<description>[...] To be sure, phishing is a real and serious problem. OpenDNS&#8217;s report says that one unique phishing scam is launched every two minutes. Even intelligent people can be bamboozled by email claiming to be from a bank or Paypal, and criminals have proven to be innovative and relentless. [...]</description>
		<content:encoded><![CDATA[<p>[...] To be sure, phishing is a real and serious problem. OpenDNS&#8217;s report says that one unique phishing scam is launched every two minutes. Even intelligent people can be bamboozled by email claiming to be from a bank or Paypal, and criminals have proven to be innovative and relentless. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John Nagle</title>
		<link>http://www.phishtank.com/blog/2007/10/09/phishtank-annual-report/comment-page-1/#comment-55828</link>
		<dc:creator>John Nagle</dc:creator>
		<pubDate>Mon, 26 Nov 2007 19:29:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.phishtank.com/blog/2007/10/09/phishtank-annual-report/#comment-55828</guid>
		<description>It&#039;s interesting seeing those statistics.

Did &quot;miowpurr&quot; really verify 221042 phishes?   That&#039;s one every 32 seconds for a working year.  Are they being paid? 

We now generate a report every three hours showing major domains currently exploited by phishing attacks:  

http://www.sitetruth.com/reports/phishes.html

This is based on PhishTank, DMOZ, and SiteTruth data. There are only 169 major domains (ones notable enough to be in the Open Directory, which has 1.6 million domains) hosting or redirecting to active phishes.  So solving this problem is within reach.  Most of the problem sites are either ISPs or have an open redirector; a few are clearly break-in situations.

We&#039;re seeing some problems with old phishes not being removed from PhishTank.  If you click on the &quot;PhishTank Example&quot; button for each entry in our list, you&#039;ll see a PhishTank entry marked &quot;valid and online&quot;.  But if you follow the link to the actual page, most of the time, the page will no longer be available. And, almost always, PhishTank will report &quot;No Screenshot Yet&quot;, even for entries that are months old.</description>
		<content:encoded><![CDATA[<p>It&#8217;s interesting seeing those statistics.</p>
<p>Did &#8220;miowpurr&#8221; really verify 221042 phishes?   That&#8217;s one every 32 seconds for a working year.  Are they being paid? </p>
<p>We now generate a report every three hours showing major domains currently exploited by phishing attacks:  </p>
<p><a href="http://www.sitetruth.com/reports/phishes.html" rel="nofollow">http://www.sitetruth.com/reports/phishes.html</a></p>
<p>This is based on PhishTank, DMOZ, and SiteTruth data. There are only 169 major domains (ones notable enough to be in the Open Directory, which has 1.6 million domains) hosting or redirecting to active phishes.  So solving this problem is within reach.  Most of the problem sites are either ISPs or have an open redirector; a few are clearly break-in situations.</p>
<p>We&#8217;re seeing some problems with old phishes not being removed from PhishTank.  If you click on the &#8220;PhishTank Example&#8221; button for each entry in our list, you&#8217;ll see a PhishTank entry marked &#8220;valid and online&#8221;.  But if you follow the link to the actual page, most of the time, the page will no longer be available. And, almost always, PhishTank will report &#8220;No Screenshot Yet&#8221;, even for entries that are months old.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: M M</title>
		<link>http://www.phishtank.com/blog/2007/10/09/phishtank-annual-report/comment-page-1/#comment-48914</link>
		<dc:creator>M M</dc:creator>
		<pubDate>Sun, 21 Oct 2007 13:39:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.phishtank.com/blog/2007/10/09/phishtank-annual-report/#comment-48914</guid>
		<description>The ONE ongoing issue that I want OpenDNS and PhishTank to address within their automated 
method of submission is to ensure that obfuscated URL&#039;s, in particular those utilizing the
Decimal method (ex: http://2130700433/ ) that a means for flagging that entry be made or
that it may be automatically calculated into its IP equivalent and automatically resubmitted 
so it doesn&#039;t fall through the cracks. I&#039;ve personally calculated these IP&#039;s and have submitted
several of them as separate entries through PhishTank so the phish itself can be targeted 
and resolved.

Security issues with unpatched computers is likely one of the causes. The Society is
noticing more and more mail and ftp servers becoming compromised, especially in the
last six months or so. These scum won&#039;t stop, and we shouldn&#039;t either! Let&#039;s keep the
heat on the phishes until they&#039;re well done and ready for eating.

MM of the London Antiphishing Society (near Arkansas Nuclear One)
now in Little Rock.</description>
		<content:encoded><![CDATA[<p>The ONE ongoing issue that I want OpenDNS and PhishTank to address within their automated<br />
method of submission is to ensure that obfuscated URL&#8217;s, in particular those utilizing the<br />
Decimal method (ex: <a href="http://2130700433/" rel="nofollow">http://2130700433/</a> ) that a means for flagging that entry be made or<br />
that it may be automatically calculated into its IP equivalent and automatically resubmitted<br />
so it doesn&#8217;t fall through the cracks. I&#8217;ve personally calculated these IP&#8217;s and have submitted<br />
several of them as separate entries through PhishTank so the phish itself can be targeted<br />
and resolved.</p>
<p>Security issues with unpatched computers is likely one of the causes. The Society is<br />
noticing more and more mail and ftp servers becoming compromised, especially in the<br />
last six months or so. These scum won&#8217;t stop, and we shouldn&#8217;t either! Let&#8217;s keep the<br />
heat on the phishes until they&#8217;re well done and ready for eating.</p>
<p>MM of the London Antiphishing Society (near Arkansas Nuclear One)<br />
now in Little Rock.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ilgaz Öcal</title>
		<link>http://www.phishtank.com/blog/2007/10/09/phishtank-annual-report/comment-page-1/#comment-47817</link>
		<dc:creator>Ilgaz Öcal</dc:creator>
		<pubDate>Sun, 14 Oct 2007 04:46:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.phishtank.com/blog/2007/10/09/phishtank-annual-report/#comment-47817</guid>
		<description>I am hoping the banks, financial organisations are using the FREE DATA we (you and community) using.
Seeing some phishing sites stay up for 3 days, I have serious questions about it.</description>
		<content:encoded><![CDATA[<p>I am hoping the banks, financial organisations are using the FREE DATA we (you and community) using.<br />
Seeing some phishing sites stay up for 3 days, I have serious questions about it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Primer informe anual sobre phishing elaborado por PhishTank</title>
		<link>http://www.phishtank.com/blog/2007/10/09/phishtank-annual-report/comment-page-1/#comment-47491</link>
		<dc:creator>Primer informe anual sobre phishing elaborado por PhishTank</dc:creator>
		<pubDate>Fri, 12 Oct 2007 05:24:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.phishtank.com/blog/2007/10/09/phishtank-annual-report/#comment-47491</guid>
		<description>[...] PhishTank Annual Report: U.S. telecoms hosting phishes http://www.phishtank.com/blog/2007/10/09/phishtank-annual-report/ [...]</description>
		<content:encoded><![CDATA[<p>[...] PhishTank Annual Report: U.S. telecoms hosting phishes <a href="http://www.phishtank.com/blog/2007/10/09/phishtank-annual-report/" rel="nofollow">http://www.phishtank.com/blog/2007/10/09/phishtank-annual-report/</a> [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
