<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://www.eggxpert.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>The cleverness of email phishers</title><link>http://www.eggxpert.com/blogs/capt_insane/archive/2009/01/12/the-cleverness-of-email-phishers.aspx</link><description>I've been noticing lately a big increase in spam in one of my Gmail accounts. It's understandable since I use this address for things that would probably garner high volumes of spam (use your imagination). When I go to delete my junk email folder, I skim</description><dc:language>en</dc:language><generator>CommunityServer 2.1 SP2 (Build: 61120.2)</generator><item><title>The Cleverness of Email Phishers</title><link>http://www.eggxpert.com/blogs/capt_insane/archive/2009/01/12/the-cleverness-of-email-phishers.aspx#461663</link><pubDate>Tue, 13 Jan 2009 23:32:56 GMT</pubDate><guid isPermaLink="false">e96c5591-d47d-4b8d-80c4-18d6411a9236:461663</guid><dc:creator>Blog Picks</dc:creator><description>&lt;p&gt;The Cleverness of Email Phishers Read all about one of our members thoughts about Email phishers. Created&lt;/p&gt;
</description></item><item><title>re: The cleverness of email phishers</title><link>http://www.eggxpert.com/blogs/capt_insane/archive/2009/01/12/the-cleverness-of-email-phishers.aspx#462141</link><pubDate>Wed, 14 Jan 2009 22:10:20 GMT</pubDate><guid isPermaLink="false">e96c5591-d47d-4b8d-80c4-18d6411a9236:462141</guid><dc:creator>Drinksabit</dc:creator><description>&lt;p&gt;One could start with their states' Atty. Gen., not that they are likely to do anything. &amp;nbsp;But, hey, it's a place for someone to start. It is my opinion that if they get enough complaints from their own state, they just might look into it... mabye not. &amp;nbsp;Of course a large campaign contribution ... oh, I'm not going to finish that thought.&lt;/p&gt;
</description></item><item><title>re: The cleverness of email phishers</title><link>http://www.eggxpert.com/blogs/capt_insane/archive/2009/01/12/the-cleverness-of-email-phishers.aspx#462607</link><pubDate>Thu, 15 Jan 2009 20:13:14 GMT</pubDate><guid isPermaLink="false">e96c5591-d47d-4b8d-80c4-18d6411a9236:462607</guid><dc:creator>Gametech</dc:creator><description>&lt;p&gt;Well part of the issue is that American Law (and most others for that matter) requires a lot of time to adapt itself to new circumstances. Most of the systems setup in our country have been in place for at least a hundred years. There have been police and courthouses since there were towns in America thus we have a system that works decently (as in your example). The internet has gone from non-exsistant to a world-wide phenomenon in like what? 25 years? less?&lt;/p&gt;
&lt;p&gt;Not to say this is an excuse but it definitly serves as evidence that our lawmakers and enforcers are simply running to catch up to the problems found in cyber space today. The internet is much like an undiscovered country right now, all kinds of people are exploring and exploiting it for different reasons but there's nothing to keep them from being attacked, or attacking someone else without recourse.&lt;/p&gt;
&lt;p&gt;I will say that I believe the first course of action from the authorities would be to have a better way of monitoring the internet. Currently, there's nothing they really can do to tell if you've been hacked other than what you tell them, that's like you saying someone stole your thoughts, there's not really any way they can monitor what was taken vs. what may not have been there in the first place. Thus without evidence many of our current law enforcement measures don't hold up.&lt;/p&gt;
&lt;p&gt;Like you said if you had backed up the data, maybe something could be done, but again I compare it to settlers colonizing a new world, most internet users are like pilgims in a canoe, no protection, no tools or knowledge of what's out there. Sure some of us have knowledge and tools but still get raided by indians...the point is without a governing authority in this new world whomever has the sharpest wit will prevale.&lt;/p&gt;
</description></item><item><title>re: The cleverness of email phishers</title><link>http://www.eggxpert.com/blogs/capt_insane/archive/2009/01/12/the-cleverness-of-email-phishers.aspx#463041</link><pubDate>Fri, 16 Jan 2009 14:14:38 GMT</pubDate><guid isPermaLink="false">e96c5591-d47d-4b8d-80c4-18d6411a9236:463041</guid><dc:creator>daniel88c</dc:creator><description>&lt;p&gt;Personally, I think that it will and continue to happen.&lt;/p&gt;
&lt;p&gt;That's almost like saying the police is going to stop organized crime. Ha!&lt;/p&gt;
</description></item><item><title>re: The cleverness of email phishers</title><link>http://www.eggxpert.com/blogs/capt_insane/archive/2009/01/12/the-cleverness-of-email-phishers.aspx#470545</link><pubDate>Thu, 29 Jan 2009 18:52:33 GMT</pubDate><guid isPermaLink="false">e96c5591-d47d-4b8d-80c4-18d6411a9236:470545</guid><dc:creator>Rangertech724</dc:creator><description>&lt;p&gt; Not sure how familar you all are with forensic tools on the computer, but I can tell if somthing was there and when it was taken. I can even tell if you tried to delete somthing and find it in the hard drive after you think you have deleted it. One of the simple tools used is FTK. Google it you will be surprised what is there when most people think somthing is gone. As for real time monitoring this is impossible, simple too much traffic and too many packets to sift through for real time who is doing what type of information. &lt;/p&gt;
&lt;p&gt; &amp;nbsp;To some extent you can also tell what information was on a drive, but that can be tweaked with by an experienced intruder with good tech skills.&lt;/p&gt;
</description></item><item><title>re: The cleverness of email phishers</title><link>http://www.eggxpert.com/blogs/capt_insane/archive/2009/01/12/the-cleverness-of-email-phishers.aspx#471612</link><pubDate>Sat, 31 Jan 2009 23:00:19 GMT</pubDate><guid isPermaLink="false">e96c5591-d47d-4b8d-80c4-18d6411a9236:471612</guid><dc:creator>PapaHomer</dc:creator><description>&lt;p&gt;Hey Capt&lt;/p&gt;
&lt;p&gt;&amp;quot;I feel your pain&amp;quot;. &amp;nbsp;I have a Yahoo and a Gmail acct. &amp;nbsp;I seem to get more spam/phishing emails on Yahoo...but their spam filter is pretty good. &amp;nbsp;I'm thinking that they probably prevent a lot more. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;At one time I would forward emails with headers to the spammer's ISP, attorney general, uce@ftc.gov, etc. &amp;nbsp; However, that worked well...&amp;quot;not so much&amp;quot;. &amp;nbsp;I think I actually started getting more.&lt;/p&gt;
&lt;p&gt;Lately I have noticed more of the phishing and less of the spam. &amp;nbsp;The phishing emails have all of the graphics and the look of something official. &amp;nbsp; Two tips that I would give to anybody are:&lt;/p&gt;
&lt;p&gt;1) If it seems suspicious and/or unsolicited, trust your gut.&lt;/p&gt;
&lt;p&gt;2) If you mouse over (do not click) the links in the email and the real URL that shows up is some IP address or any address other than the company you have proof.&lt;/p&gt;
&lt;p&gt;I have forwarded the phishing emails to the banks and financial institutions they were posing as. &amp;nbsp; Most legitimate sites have addresses where you can report phishing to.&lt;/p&gt;
&lt;p&gt;abuse@chase, etc&lt;/p&gt;
&lt;p&gt;Peace...PH&lt;/p&gt;
</description></item><item><title>re: The cleverness of email phishers</title><link>http://www.eggxpert.com/blogs/capt_insane/archive/2009/01/12/the-cleverness-of-email-phishers.aspx#477620</link><pubDate>Tue, 10 Feb 2009 13:39:50 GMT</pubDate><guid isPermaLink="false">e96c5591-d47d-4b8d-80c4-18d6411a9236:477620</guid><dc:creator>Fizzter</dc:creator><description>&lt;p&gt;Your thoughts are on the right track. &amp;nbsp;I have worked in the email security space and seen the millions of emails that get sent to companies and some of the ever-evolving tactics.&lt;/p&gt;
&lt;p&gt;One of my particular favorites from back in the day was a money making attempt based on stocks. &amp;nbsp;(They're all based on money.. money drives everything). &amp;nbsp;The spammers send out millions of emails telling people to buy a certain stock. &amp;nbsp;Maybe 1% of those people bite, and this temporarily drives up the popularity and price. &amp;nbsp;The spammers sell for profit.&lt;/p&gt;
&lt;p&gt;The problem is out there, and even with ever-evolving filters and software, it isn't going away. &amp;nbsp;The AV-software paradigm is a falacy itself, doomed to failure. &amp;nbsp;The proper long-term protection should be proper education and use, perhaps in combination with behavioral technology rather than signature based. &amp;nbsp;It goes along the same lines as abstinance-only teaching in schools, but I dare not get into that shenanigan...&lt;/p&gt;
&lt;p&gt;Right now, the education isn't there, and shoddy AV products and mail filters are the best we can do. &amp;nbsp;Teaching this to kids in schools isn't going to work yet, either, because the people running those schools typically don't have the knowledge to realize they have this large gap.&lt;/p&gt;
&lt;p&gt;A general tip for email--don't click on links. &amp;nbsp;Always go directly to the site yourself. &amp;nbsp;If you're unsure whether or not the site is the &amp;quot;real deal&amp;quot;, log in with a fake username/password first. &amp;nbsp;The real site will deny it, but a fake site will take it as harvested data.&lt;/p&gt;
&lt;p&gt;The general rule is that if your AV product is catching stuff, then you aren't using the computer properly, and you're probably already infected. :)&lt;/p&gt;
&lt;p&gt;Good luck!&lt;/p&gt;
</description></item><item><title>re: The cleverness of email phishers</title><link>http://www.eggxpert.com/blogs/capt_insane/archive/2009/01/12/the-cleverness-of-email-phishers.aspx#480617</link><pubDate>Sun, 15 Feb 2009 01:02:56 GMT</pubDate><guid isPermaLink="false">e96c5591-d47d-4b8d-80c4-18d6411a9236:480617</guid><dc:creator>Allen750</dc:creator><description>&lt;p&gt;Well, I create a filter in Gmail with my own signature as the special rule and everything else goes to the crapper. &lt;/p&gt;
</description></item></channel></rss>