isn't quite ashamed enough to present

jr conlin's ink stained banana

2004-10-26

::Stating the Obvious

Hlleo,

a%S en Angineer, Eye no i d0'tn haff th3 best ski||s at riTin. i'm also willing to note that there are those in any company that do. Still, i can't believe that yesterday, four people (all of whom i respect) recieved the following type message and asked if it was legit. (Steve, you're not one of them. You were the fifth instance of the message.)

Dae?r SooBCsribEr? M?me?ber,

We m?su?t che?kc? t?ah?t y?ruo? ID was regis?eret?d by real peo?elp?. So, to he?pl? p?tnever? auto?etam?d
regi?tarts?ions, pl?ae?se cli?kc? on t?ih?s l?ni?k and com?etelp? code v?re?ification pr?sseco?:

w?w?w?.(yahoo|ebay|paypal|aol).co?m Evil Url Removed
ou

Suffice to say that no matter how evil you may find a given company, or how good you've heard the office parties are, they would NEVER send out an email that mangled. It's a little like getting a 13 year old guy showing up at your door and saying "Hilo, Me aM w|fe of you. Keys to Car may i h4ve? i live aT {your address}"

i swear, people don't just need firewalls, anti-virus, and spyware traps, they need a live in cynic.

With a cattle prod.

Apparently the core problem was that the actual message (the one that was screwing people up) was a well-crafted HTML message that used meta-characters to slip past the filter. Looking at the HTML version of the page, folks would be hard pressed to know that this was a phishing scheme.

i, on the other hand, disabled HTML and saw the confusing pile of characters simulated above, and was able to spot it as a phishing scheme right off the bat. This, i'd note, gives me yet another reason to strip HTML from my mail, regardless of however many requests i get from marketing newsletters asking me to "upgrade" my mail client.

Hey, delicious user, Save This Page
Blogs of note
personal that's my blog
(The Official Blog of the Internet)
memoirs of hydrogen guy matthew shepherd (quebec) rhapsodic.org j$ (right) Henriette's Herbal Blog fanatical apathy lynne ydw i iconophobia slumbering lungfish
geek Y!Cool Thing michael j radwin jeremy z
(The Official Website of the Internet)
dave's picks ultramookie Josh Woodward derek balling j$ (left) simon willison Yahoo! Search Blog
news ars technica search engine watch webmaster world.com
forums uh.net man-man killroy & tina

experimental

Firefox search plugins for Yahoo!

My Living Room media box config

The Official "Official" Registry of the Internet

Powered by WordPress
Hosted on Dreamhost.