North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

Re: Phishing (Was Re: WashingtonPost computer security stories)

  • From: Eric Kuhnke
  • Date: Tue Aug 17 09:03:39 2004


The mail originated from 68.77.56.130 (an ameritech.net DSL connection,
right now not pingable) and loads some images from www.citibank.com.
It links to http://61.128.198.51/Confirm/ - an IP address hosted by
Chinanet (transit to there supplied by Savvis from my point of view).
It's a 1 line rule with mod_rewrite and apache to block nonexistant or off-site http referers attempting to display GIF/JPG/PNG images... Sometimes I wonder why Citibank, Paypal and others don't do this. It would cut down on the displayed authenticity level of many basic phishes.