Worst Phisher Ever
I get the feeling this scammer doesn't quite understand how phishing is supposed to work. I almost feel sorry for him.
Update:
Holy Crap! I guess this phisher is way more clever than I gave him credit for. When viewed in Firefox, the text below is completely scrambled. In IE, it appears normal. I'm not sure why that is, but looking at the HTML it looks like its exploiting some flaw in IE. It even makes it all the way through Bloglines (my RSS aggregator) like that: scrambled in Firefox, normal in IE.
Update 2:
This appears to be a new exploit, and quite clever too. Ned has written a detailed analysis. That's the last time I almost feel sorry for a scammer.
Dera Bcralays Merebm,
Tsih eamil was setn by the Balcrays svreer to virefy yruo
eamil adsserd. You mtsu comelpte tsih procses by cilcking
on
the lkni bwole and entegnir in the samll wiwodn yruo
Balcrays Mbmeership nebmur, paedocss and mbaromele wrod.
Tsih
is deno for yuor protcetion - baceuse semo of our membres
no lregno hvae aseccs to tehir eliam asserddes and
we
mtsu veryfi it. To vefiry yruo eliam arddess and accsse yruo bakn acocunt , clkci on the lkni belwo:
http://www.barclays.com/?Mb2TvaN32E5_JA7oxSaOmBrBq3TBeLqHTRluSoDl_Wn_K_oZFTuQHFZIXGI5x8NTGos5qlp
Posted April 8, 2005 2:22 PM
Comments
If that's for real, wow. And here I thought that phishing was getting more and more sophisticated *stunned*.
I just wish I got ones as interesting as that ;)
Eric Burnett
Eric Burnett, April 9, 2005 12:56 AM
It's for real. I was just as surprised as you, but I guess I shouldn't be, using a computer doesn't make criminals any smarter. I picture a guy somewhere feeling smug that his phishing scam is able to get past the spam filters, and is eagerly awaiting all the stolen passwords that must be on their way.
Damien, April 9, 2005 10:02 AM
They're doing some very sophisticated stuff to get past spam blockers!
Unicode has "characters" that specify right-to-left or left-to-right rendering. His text switches directions every few characters so that IE will display it properly, but spam filters, even those which know to ignore non-printing Unicode characters, will see gibberish. Looks like Mozilla doesn't properly interpret the directional controls.
Very impressive....
Ned Batchelder, April 9, 2005 1:36 PM
I've put more details on my blog: http://www.nedbatchelder.com/blog/20050409T155246.html
Ned Batchelder, April 9, 2005 4:56 PM
Well, fooled me. thats a neat trick though...gotta love it how all the best things are created by people trying to screw you over. But such is the way of the internet, I guess.
Eric Burnett, April 10, 2005 9:25 PM
Not to mention that it links to a possible IE exploited URL:
http://%09%6e0%68fr2%6d%2e%09%64%[1.%72%55/
That actually looks like this to IE when unencoded:
http:// n0hfr2m. d%[1.rU/
Even though it looks like a legit URL (except for the mumbo jumbo in the query string - the stuff after the question mark).
etM, June 10, 2005 11:01 AM
i come from best search engine http://www.google.com
search engine, July 14, 2005 2:59 AM
Post a comment