<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Can You Identify Phishing? in Security</title>
<link>http://www.dslreports.com/forum/r18748749</link>
<description></description>
<language>en</language>
<pubDate>Mon, 22 Mar 2010 00:05:12 EDT</pubDate>
<lastBuildDate>Mon, 22 Mar 2010 00:05:12 EDT</lastBuildDate>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18789844</link>
<description><![CDATA[<A HREF="/useremail/u/1112464"><b>MeanPeepsSuk</b></A> : It does seem to be gone.  Wonder why?  They still have a page up about the quiz here:  &raquo;<A HREF="http://blog.siteadvisor.com/2007/07/phish_or_fake_take_our_phishin.shtml" >blog.siteadvisor.com/2007/07/phi&middot;&middot;&middot;in.shtml</A><br><br>but the links on it to the actual quiz just auto-forward to the home page with no explanation.<br><br>Kind of strange...... ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18789844</guid>
<pubDate>Wed, 01 Aug 2007 13:16:50 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18789580</link>
<description><![CDATA[<A HREF="/useremail/u/989554"><b>Blue2</b></A> : <div class="bquote"><SMALL>said by  vircotto <A HREF="/useremail/u/640181"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>The phishing quiz seems to have disappeared. I wonder why....  <br> </DIV>You mean like putting up two fake Amazon sites and two fake Chase sites and asking you to choose which one is the real one? <br><br>That sound you hear is them tripping over the tail between their legs as they head for cover.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18789580</guid>
<pubDate>Wed, 01 Aug 2007 12:34:42 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18789387</link>
<description><![CDATA[<A HREF="/useremail/u/1144666"><b>jabarnut</b></A> : Hmmm.....maybe you downloaded SiteAdvisor and it's blocking it's own quiz?  :D (j/k)<br><br>I don't see it in the original link anymore either.<br><SMALL>--<br>I had a life once.....now I have a Computer and a Modem.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18789387</guid>
<pubDate>Wed, 01 Aug 2007 12:07:57 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18789331</link>
<description><![CDATA[<A HREF="/useremail/u/640181"><b>vircotto</b></A> : The phishing quiz seems to have disappeared. I wonder why....  I can still access some of the images, but the quiz appears to be vapor.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18789331</guid>
<pubDate>Wed, 01 Aug 2007 12:00:18 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18779792</link>
<description><![CDATA[<A HREF="/useremail/u/853361"><b>Dude111</b></A> : Congrats on getting 8 right!<br><br>Im kinda sad i only got 5 :D (I thought i was IDing stuff well)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18779792</guid>
<pubDate>Mon, 30 Jul 2007 23:58:27 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18776985</link>
<description><![CDATA[<A HREF="/useremail/u/975626"><b>wolfdragon01</b></A> : YOU ANSWERED 8 OF 10 QUESTIONS CORRECTLY<br>Rating: Safety Guru<br><br>I missed the Bank of America and paypal questions 3 and 6 on their list.  Thankfully I do not not use their services. . .]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18776985</guid>
<pubDate>Mon, 30 Jul 2007 16:32:41 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18774420</link>
<description><![CDATA[<A HREF="/useremail/u/989554"><b>Blue2</b></A> : <div class="bquote"><SMALL>said by  jabarnut <A HREF="/useremail/u/1144666"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>Like I said earlier, there are a lot of different ways to scam people....some are just a lot better at it than others. ;) <br> </DIV>Well said. <br><br>"Yes, as through this world I've wandered<br>I've seen lots of funny men;<br>Some will rob you with a six-gun,<br>And some with a fountain pen."<br>PRETTY BOY FLOYD (Woody Guthrie, 1939)<br><br>Instilling insecurity is big business with a capital "B", and the unsuspecting are just as likely to fall for those licensed scams as they do for phishes. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18774420</guid>
<pubDate>Mon, 30 Jul 2007 09:43:14 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18774379</link>
<description><![CDATA[<A HREF="/useremail/u/635348"><b>rolande</b></A> : <div class="bquote"><SMALL>said by  russotto <A HREF="/useremail/u/214274"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Umm, how are you going to do that?  I could probably get a few suckers to install my root CA into their browser, but no one with any security savvy is going to do it.<br></DIV>Not difficult at all to do. All you need is a script to execute that drops the file and makes the registry update.<br><br><div class="bquote"><SMALL>said by  russotto <A HREF="/useremail/u/214274"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>If you can get a trojan in, you don't need a proxy or a root certificate or any such thing.  Your trojan can just pull the data out in the clear before encryption or after decryption, and send it wherever you like.<br> </DIV>Doesn't work that way easily if you need real-time activity recorded. Much easier and incriminating to see the traffic on the wire.<br><SMALL>--<br>Ignorance is temporary...stupidity lasts forever!<br><br>&raquo;<A HREF="http://www.thewaystation.com/" >www.thewaystation.com/</A> <br>&raquo;<A HREF="http://blog.thewaystation.com/" >blog.thewaystation.com/</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18774379</guid>
<pubDate>Mon, 30 Jul 2007 09:35:09 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18774300</link>
<description><![CDATA[<A HREF="/useremail/u/1144666"><b>jabarnut</b></A> : I still get a big kick out of the fact that even when you're an amazing "Safety Guru" who can "answer 10 out of 10 questions correctly", and have a "practically clairvoyant knowledge of the Web", that they still follow it up by telling you to not let scammers fool you.<br><br>Furthermore, SiteAdvisor can help protect your identity by warning you before you visit a risky site.<br><br>All of this amazing protection for the low, low, price of $49.99.<br><br>Of course, for someone as knowledgeable as a Safety Guru, the obvious and most logical thing to do would be to get the "3-user family pack" for a mere $19.99. <br><br>Heck, not only do you "save" an incredible $30.00, but those poor unsuspecting family members who aren't gifted enough to have that same "clairvoyant knowledge of the Web" that you do, will finally have a wonderful sense of security and piece of mind.<br><br>Like I said earlier, there are a lot of different ways to scam people....some are just a lot better at it than others. ;) <br><SMALL>--<br>I had a life once.....now I have a Computer and a Modem.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18774300</guid>
<pubDate>Mon, 30 Jul 2007 09:19:06 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18773589</link>
<description><![CDATA[<A HREF="/useremail/u/500875"><b>PeeWee</b></A> : 9/10<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap WIDTH=33%><A HREF="/r0/download/1195283~2001aa30f861d2451ca9003119bdcb6f/Doc1.zip"><IMG  align=absmiddle TITLE="download" SRC="http://i.dslr.net/silk/compress.png" border=0 width=16 height=16><IMG SRC="http://i.dslr.net/1ptrans.gif" WIDTH=10 HEIGHT=1 border=0><big>Doc1.zip</big></A> <small>19,380 bytes</small><br><small>(Doc1.docx)</small></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18773589</guid>
<pubDate>Mon, 30 Jul 2007 03:23:52 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18773422</link>
<description><![CDATA[<A HREF="/useremail/u/1447722"><b>supergirl</b></A> : I thought both Amazons were fake (the URLs looked weird) but went totally by the login screen so got 10/10.<br><br>Personally, I think PayPal itself is a scam.<br><br>Anyone sending me email with weird stuff, I delete. The Nigerian one has been around forever.<br><br>MySpace has made it difficult to check scams since everything starts with a "mslinks..." url. Their ads have all kinds of scams themselves. :uhh:<br><br>The tip: never login to a site unless you personally typed the URL yourself. I do have a personal page with all my finance links on my computer (a local webpage) so it's done for me.<br><SMALL>--<br>Saving the world keeps me busy. However, I find Earth very primitive from my home planet of Krypton.<br>-Supergirl</SMALL><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/18773422?c=1195260&ret=L2ZvcnVtL3IxODc0ODc0OS54bWw%3D"><IMG TITLE="19497 bytes" BORDER=0 WIDTH=436 HEIGHT=171 SRC="/r0/download/1195260~c3779eff1a2a01626d3fb7205069120b/security.jpg"></A><br>Security</TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18773422</guid>
<pubDate>Mon, 30 Jul 2007 02:00:44 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18770772</link>
<description><![CDATA[<A HREF="/useremail/u/356416"><b>Link Logger</b></A> : <div class="bquote"><SMALL>said by  aefstoggaflm <A HREF="/useremail/u/595148"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Which is the authentic Amazon site?<br></DIV>Both of the Amazon sites are fake and I posted the reasons earlier in the discussion.<br><br>Blake<br><SMALL>--<br>Vendor: Author of <A HREF="http://www.linklogger.com">Link Logger</A> which is a traffic analysis and firewall logging tool</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18770772</guid>
<pubDate>Sun, 29 Jul 2007 16:47:59 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18770699</link>
<description><![CDATA[<A HREF="/useremail/u/631577"><b>slash616</b></A> : <div class="bquote"><SMALL>said by twcx95 :</SMALL><BR><BR>10 out of 10.  It wasn't hard at all.  It would have been even easier if we had some context.  That is, how the user arrived at the webpage.  That is all not to mention, except for the first question, we never get to see any info regarding the url of the webpage.<br> </DIV>I think they were trying to point out that you shouldn't even rely on the URL alone.  IIRC, there have been URL encoding/XSS vulnerabilities in the past that even comes from a valid URL, but the arguments passed in the URL allow injection or worse, a retrieval of a third party site.  (10/10 btw)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18770699</guid>
<pubDate>Sun, 29 Jul 2007 16:36:27 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18770599</link>
<description><![CDATA[<A HREF="/useremail/u/836656"><b>IllIlIlllIll</b></A> : i had no problem answering the questions in less than 5 minutes.<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/18770599?c=1195025&ret=L2ZvcnVtL3IxODc0ODc0OS54bWw%3D"><IMG TITLE="76959 bytes" BORDER=0 WIDTH=482 HEIGHT=595 SRC="/r0/download/1195025~aacbd00cb0847a1101c79a94185dbf98/correct.JPG"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18770599</guid>
<pubDate>Sun, 29 Jul 2007 16:14:28 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18770333</link>
<description><![CDATA[<A HREF="/useremail/u/795407"><b>SnowyOne</b></A> : <div class="bquote"><SMALL>said by  aefstoggaflm <A HREF="/useremail/u/595148"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>Is there a way to get the right answers, without taking the test again?<br><br> </DIV> Rob <A HREF="/useremail/u/460388"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> posted this in the news<br>&raquo;<A HREF="http://cache01.ae1.net/8c985935a22567f061a12e4f14b38fcc.jpg" >cache01.ae1.net/8c985935a22567f0&middot;&middot;&middot;8fcc.jpg</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18770333</guid>
<pubDate>Sun, 29 Jul 2007 15:05:46 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18770091</link>
<description><![CDATA[<A HREF="/useremail/u/595148"><b>aefstoggaflm</b></A> : 8 out of 10 correct. :)<br><br>The ones that I got wrong were..<br><br>Which is the authentic Bank of America site?<br><br>Which is the authentic Amazon site?<br><br>----<br><br>Is there a way to get the right answers, without taking the test again?<br><br>[EDIT] I hope someone finds a way to get the McAfee SiteAdvisor Plug-in for Firefox, but from addons.mozilla.org :uhh:<br><br><SMALL>--<br>Please use the "yellow (IM) envelope" to contact me and please leave the URL intact.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18770091</guid>
<pubDate>Sun, 29 Jul 2007 14:10:14 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18769881</link>
<description><![CDATA[<A HREF="/useremail/u/655964"><b>jdong</b></A> : <div class="bquote"><SMALL>said by  russotto <A HREF="/useremail/u/214274"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br><BLOCKQUOTE>But I can just as easily create and sign my own certificate with my own Root CA and trick you into loading my Root certificate into your browser.</BLOCKQUOTE><br><br>Umm, how are you going to do that?  I could probably get a few suckers to install my root CA into their browser, but no one with any security savvy is going to do it.<br><br> </DIV>That's the point -- security savvy people don't fall for this. However, from unscientific observatons I'd be willing to say 60% or more of the "average population" will click through an invalid certificate warning without a second thought -- or thinking how the f**** do I turn off this stupid annoying alert?<br><SMALL>--<br>UbuntuForums Administrator: <A HREF="http://ubuntuforums.org">try Ubuntu Linux</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18769881</guid>
<pubDate>Sun, 29 Jul 2007 13:30:41 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18769772</link>
<description><![CDATA[<A HREF="/useremail/u/214274"><b>russotto</b></A> : <BLOCKQUOTE>But I can just as easily create and sign my own certificate with my own Root CA and trick you into loading my Root certificate into your browser.</BLOCKQUOTE><br><br>Umm, how are you going to do that?  I could probably get a few suckers to install my root CA into their browser, but no one with any security savvy is going to do it.<br><br><BLOCKQUOTE> All you need to do is drop a nice little trojan that adjusts the browser's proxy settings and adds your own Root CA certificate and with the right proxy product you can start capturing any and all SSL traffic from that client in the clear and they will not know the difference. </BLOCKQUOTE><br>If you can get a trojan in, you don't need a proxy or a root certificate or any such thing.  Your trojan can just pull the data out in the clear before encryption or after decryption, and send it wherever you like.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18769772</guid>
<pubDate>Sun, 29 Jul 2007 13:07:47 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18769226</link>
<description><![CDATA[<A HREF="/useremail/u/489959"><b>nasadude</b></A> : I never click on links in emails, even from financial institutions I do business with - I enter what I know to be the correct web address directly, then navigate where I need to go.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18769226</guid>
<pubDate>Sun, 29 Jul 2007 11:09:28 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18769205</link>
<description><![CDATA[<A HREF="/useremail/u/154148"><b>jsimmons</b></A> : 10 out of 10... Surprised myself :). I thought surely I'd miss one or two. A few were pretty tricky.<br><SMALL>--<br>"Everything should be made as simple as possible, but not one bit simpler."- Albert Einstein</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18769205</guid>
<pubDate>Sun, 29 Jul 2007 11:06:18 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18769176</link>
<description><![CDATA[<A HREF="/useremail/u/635348"><b>rolande</b></A> : <BLOCKQUOTE><SMALL><br>YOU ANSWERED 10 OF 10 QUESTIONS CORRECTLY<br>Rating: Safety Guru<br><br>Nice work! Your practically clairvoyant knowledge of the Web allows you to spot even the most realistic looking spoofed sites. We're impressed!<br></SMALL></BLOCKQUOTE><br><br>I agree with  nwrickert <A HREF="/useremail/u/1070900"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>. The information provided was of marginal value to determine site spoofing or not. In a real situation you have a lot more info available to you.<br><br>The SSL certificate question is a red herring. SSL certificates signed by a trusted Root CA that match the domain name and company name you are attempting to communicate with provide a level of trust. But I can just as easily create and sign my own certificate with my own Root CA and trick you into loading my Root certificate into your browser.<br><br>The potential for "man in the middle" attacks for SSL are scary. I can see it as the next BIG backdoor for authorities to find out what someone is doing in real-time for tracking/monitoring purposes. This capability to transparently unlock SSL has been around for just over a couple years now.<br><br>All you need to do is drop a nice little trojan that adjusts the browser's proxy settings and adds your own Root CA certificate and with the right proxy product you can start capturing any and all SSL traffic from that client in the clear and they will not know the difference. Heck, with law enforcements power, all they need to do is drop an SSL proxy transparently inline with a particular users traffic at their ISP and they have the keys to the kingdom.<br><SMALL>--<br>Ignorance is temporary...stupidity lasts forever!<br><br>&raquo;<A HREF="http://www.thewaystation.com/" >www.thewaystation.com/</A> <br>&raquo;<A HREF="http://blog.thewaystation.com/" >blog.thewaystation.com/</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18769176</guid>
<pubDate>Sun, 29 Jul 2007 11:00:01 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18769070</link>
<description><![CDATA[<A HREF="/useremail/u/537492"><b>antiserious</b></A> :  <br>"YOU ANSWERED 10 OF 10 QUESTIONS CORRECTLY<br>Rating: Safety Guru<br><br>Nice work! Your practically clairvoyant knowledge of the Web allows you to spot even the most realistic looking spoofed sites. We're impressed!"<br> <br>There was one guess in there, but some should have been obvious enough to raise flags for most everybody.<br> <br><SMALL>--<br><I>"Burn the land and boil the sea<br>You can't take the sky from me " </I><br></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18769070</guid>
<pubDate>Sun, 29 Jul 2007 10:33:28 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18768990</link>
<description><![CDATA[<A HREF="/useremail/u/534175"><b>Straphanger</b></A> : I got 9/10...screwed up on the BoA one.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18768990</guid>
<pubDate>Sun, 29 Jul 2007 10:07:26 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18768065</link>
<description><![CDATA[<A HREF="/useremail/u/553533"><b>madylarian</b></A> : I got 10 out of 10 and I don't need Site Advisor to tell me to look at the actual url in a link.<br><br>mady<br><SMALL>--<br>Honi soit qui mal y pense</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18768065</guid>
<pubDate>Sun, 29 Jul 2007 01:32:30 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18767272</link>
<description><![CDATA[<A HREF="/useremail/u/848852"><b>mvdu</b></A> : I got 8/10 correct.<br><br>Missed the PayPal question. I go there, but didn't remember the security center link. I also got the name of the other scam wrong. I can't believe I hadn't heard the name.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18767272</guid>
<pubDate>Sat, 28 Jul 2007 22:31:09 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18767245</link>
<description><![CDATA[<A HREF="/useremail/u/610684"><b>tmaertin</b></A> : 9/10 - i missed the capital one question as well - both seemed phishy to me. i find myself muttering "whats in your wallet" to no one in particular...<br><SMALL>--<br>Hike up your skirt a little more, and show your world to me.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18767245</guid>
<pubDate>Sat, 28 Jul 2007 22:24:39 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18766642</link>
<description><![CDATA[<A HREF="/useremail/u/1213174"><b>thxmed</b></A> : I got all ten answers correct too easy]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18766642</guid>
<pubDate>Sat, 28 Jul 2007 20:12:16 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18766610</link>
<description><![CDATA[<A HREF="/useremail/u/548755"><b>RoundTuit</b></A> : Lucky, I guess.<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/18766610?c=1194679&ret=L2ZvcnVtL3IxODc0ODc0OS54bWw%3D"><IMG TITLE="62578 bytes" BORDER=0 WIDTH=476 HEIGHT=208 SRC="/r0/download/1194679~d42eabf5798e584c21636fb8f65f0cbc/Phishing%20Test.jpg"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18766610</guid>
<pubDate>Sat, 28 Jul 2007 20:06:11 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18766272</link>
<description><![CDATA[<A HREF="/useremail/u/683237"><b>MrMoody</b></A> : 10/10 first try. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18766272</guid>
<pubDate>Sat, 28 Jul 2007 18:49:33 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18766198</link>
<description><![CDATA[<A HREF="/useremail/u/226651"><b>Squirrelly</b></A> : 9 out of 10<br><br>I agree the test is not a fair way to judge a fake site but I will help some people.  I have my site booked marked that I shop at so no worries there.  I think the best way to tell fake site is by the URL<br><SMALL>--<br>I bitch. People listen!!</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18766198</guid>
<pubDate>Sat, 28 Jul 2007 18:31:37 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18766154</link>
<description><![CDATA[<A HREF="/useremail/u/461572"><b>MarkAW</b></A> : Aren't these like the same questions they had a couple years ago.<br><br>YOU ANSWERED 10 OF 10 QUESTIONS CORRECTLY<br>Rating: Safety Guru]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18766154</guid>
<pubDate>Sat, 28 Jul 2007 18:21:59 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18766139</link>
<description><![CDATA[<A HREF="/useremail/u/119880"><b>schipperke</b></A> : McAfee SiteAdvisor Phishing Quiz<br>YOU ANSWERED 10 OF 10 QUESTIONS CORRECTLY<br>Rating: Safety Guru<br><br>The ones that let you see the URL are not hard, some were tricky though]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18766139</guid>
<pubDate>Sat, 28 Jul 2007 18:19:06 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18766046</link>
<description><![CDATA[<A HREF="/useremail/u/168480"><b>stevesa</b></A> : FWIW<br><br>YOU ANSWERED 10 OF 10 QUESTIONS CORRECTLY<br>Rating: Safety Guru  :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18766046</guid>
<pubDate>Sat, 28 Jul 2007 18:01:13 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18765779</link>
<description><![CDATA[<A HREF="/useremail/u/655964"><b>jdong</b></A> : <div class="bquote"><SMALL>said by Phished_out :</SMALL><br><br> - Got Six out of Ten for the test.   <br><br>   I still think SSL is pretty safe, regardless of what they want to say.  What is SSL anyway?   Super safety locks?   Oh, wait - Secure Socket Layer.   It's meant to prevent people from listening in on the data transfer you're using.   Thought I'd double check SSL in case I was wrong, but :<br><br> - &raquo;<A HREF="http://en.wikipedia.org/wiki/Transport_Layer_Security" >en.wikipedia.org/wiki/Transport_&middot;&middot;&middot;Security</A><br> </DIV>The point the test was trying to make, is, I can register a site like "www.amazon.com.haha.this.is.fake.com", and buy a signed certificate for this site, and when you visit it, you'll get SSL and a padlock that shows this site is verified....<br><br>Signed SSL means<br> (1) Your transmission is secure (err let's save that argument for another day) from you to the server and back.<br> (2) The server you are visiting is certified by a trustworthy authority to be the one it claims to be.<br><br>It doesn't say anything like "this is an authentic bank" or those things. You still have to check the URL for validity, and so on.<br><SMALL>--<br>UbuntuForums Administrator: <A HREF="http://ubuntuforums.org">try Ubuntu Linux</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18765779</guid>
<pubDate>Sat, 28 Jul 2007 17:07:07 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18765765</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> :  - Got Six out of Ten for the test.   <br><br>   I still think SSL is pretty safe, regardless of what they want to say.  What is SSL anyway?   Super safety locks?   Oh, wait - Secure Socket Layer.   It's meant to prevent people from listening in on the data transfer you're using.   Thought I'd double check SSL in case I was wrong, but :<br><br> - &raquo;<A HREF="http://en.wikipedia.org/wiki/Transport_Layer_Security" >en.wikipedia.org/wiki/Transport_&middot;&middot;&middot;Security</A><br><br>   I have never visted any of the websites (Myspace, Capitol 1, etc. etc.) except Amazon and the first rule of thumb for checking emails is to see who the sender is (before you open it).   Though the point of phishing scams is to trick you into giving your info away, I felt this test was pointed in such a way as to make you fail a few questions.  I'm not paranoid enough to pass them all, I guess.<br><br>   Do you open emails that aren't from anyone/institution you don't know or frequently use?   You should be ashamed of yourself, then.<br>   I don't have a paypal account.   Why would I receive an email from them asking me to verify my account details? <br>  <br>   Felt like a scare tactic.   Thought it would have been a useful test to help me discover new methods of diverting phishing scams.<br><br>   At least it was free.<br><br>Ranting done.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18765765</guid>
<pubDate>Sat, 28 Jul 2007 17:03:42 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18765569</link>
<description><![CDATA[<A HREF="/useremail/u/185683"><b>raye</b></A> : 9/10; knew the e-mail answer was probably wrong.  But I usually check the e-mail headers anyway, which show the actual domain name and IP address of sender.<br><br>Real easy to do in Outlook or any other client.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18765569</guid>
<pubDate>Sat, 28 Jul 2007 16:16:33 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18764139</link>
<description><![CDATA[<A HREF="/useremail/u/908758"><b>Improfane</b></A> : 10/10<br><br>Amazon one requires familiarity with the site itself. I am familiar with the site: Amazon ask you if you have an account or not.<br><br>The official PayPal email also has a link to the paypal website itself, the phishing email wouldn't do this since they want you to go to their page.<br><br>The MySpace is an interesting one though. People really do ignore the ending and look at the beginning.<br><br>Links on PayPal also misrendered.<br><br>The rest are littered with grammatical mistakes, making it easy.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18764139</guid>
<pubDate>Sat, 28 Jul 2007 11:14:05 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18760482</link>
<description><![CDATA[<A HREF="/useremail/u/655964"><b>jdong</b></A> : <div class="bquote"><SMALL>said by  Mele20 <A HREF="/useremail/u/403861"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>What was hard about Amazon? I got that one in a second...most of them were quick and very easy to tell and even the harder ones I just knew instinctively. I didn't even notice that there were grammar and spelling mistakes as I didn't need to pour over any of them to know which was the "bad" one.  The only one that gave me pause was the CapitalOne because I believed both to be fraudulent although my instinct told me to choose the second one, I felt it was worse than the first because at least the first wasn't asking for a SocSec number.<br> </DIV>The hard part is not paying attention to those kinds of inconsistencies. Nowadays the Internet has made people so hasty in their get-rich-e-business schemes that there is no attention paid to consistency and quality. If I were to closely nitpick each site, I'd argue that I'd think that 90% of the sites were fakes.<br><SMALL>--<br>UbuntuForums Administrator: <A HREF="http://ubuntuforums.org">try Ubuntu Linux</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18760482</guid>
<pubDate>Fri, 27 Jul 2007 18:54:58 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18760446</link>
<description><![CDATA[<A HREF="/useremail/u/403861"><b>Mele20</b></A> : What was hard about Amazon? I got that one in a second...most of them were quick and very easy to tell and even the harder ones I just knew instinctively. I didn't even notice that there were grammar and spelling mistakes as I didn't need to pour over any of them to know which was the "bad" one.  The only one that gave me pause was the CapitalOne because I believed both to be fraudulent although my instinct told me to choose the second one, I felt it was worse than the first because at least the first wasn't asking for a SocSec number.<br><SMALL>--<br>"The same ferocity that our founders devoted to protect the freedom and independence of the press is now appropriate for our defense of the freedom of the internet. The stakes are the same: the survival of our Republic". Al Gore, The Assault on Reason</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18760446</guid>
<pubDate>Fri, 27 Jul 2007 18:50:47 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18758841</link>
<description><![CDATA[<A HREF="/useremail/u/555541"><b>jofallon</b></A> : With the Amazon one, I actually opened the real Amazon page in another browser window and flipped back and forth between the images. Neither image matched the Amazon page I saw. Agreed that not seeing the URL removes the biggest clue. Is there something in the Phishers' Handbook for Fraudulent Web Sites that prevents them from using a spell-checker or a proof-reader?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18758841</guid>
<pubDate>Fri, 27 Jul 2007 15:04:43 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18758217</link>
<description><![CDATA[<A HREF="/useremail/u/655964"><b>jdong</b></A> : It's frustrating how all the evidence you have to work from are crappy incomplete screenshots -- you keep on wondering, "is that it?"<br><br>I know if they acually linked to the real sites, or provided a good Flash emulation of a web browser with an address bar or even view source / view certificate options, everyone here would've scored 10/10.<br><br>As I said before, this is nothing more than a way to market their products by fooling the user into thinking he's exceedingly inept.<br><SMALL>--<br>UbuntuForums Administrator: <A HREF="http://ubuntuforums.org">try Ubuntu Linux</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18758217</guid>
<pubDate>Fri, 27 Jul 2007 13:31:43 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18758189</link>
<description><![CDATA[<A HREF="/useremail/u/246096"><b>yock</b></A> : <div class="bquote"><SMALL>said by  EGeezer <A HREF="/useremail/u/668609"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>My personal opinion is to avoid sources of phishing links, like unsolicited emails, linking from unrelated web sites, popups or ads.</DIV>Really, this is the best advice of all.<br><SMALL>--<br>Laughter is the closest distance between two people. --Victor Borge<BR>"The opposite of war isn't peace, it's creation."</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18758189</guid>
<pubDate>Fri, 27 Jul 2007 13:28:23 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18758173</link>
<description><![CDATA[<A HREF="/useremail/u/668609"><b>EGeezer</b></A> : Well, based on the discussion and research in this post, it appears there's no really good way to "detect phishing", including using McAfee's own products. <br><br>My personal opinion is to avoid sources of phishing links, like unsolicited emails, linking from unrelated web sites, popups or ads. Type in and use the institution's own main web site. Peruse and verify the certificate information and the issuer as a legitimate one and not self-issued or issued to other than the domain you're visiting. <br><br>Marketscore's crapware is an example of a third party issuing its own certificate to the user signing into his SSL-encrypted site so marketscore can decrypt and track that user's SSL activity. <br><br>Cain & Abel is a program that provides a self-issued certificate to decrypt and capture SSL encoded passwords. You'll generally get a "unknown Issuer" message from your browser if you encounter this. <br><br>Finally, after avoiding referred links and using your own keyboard to enter URLs, if the links <I>still</I> look suspicious, back out. Use the telephone or go to the company's office where practical. <br><SMALL>--<br>Sive enim ad sapientiam perveniri potest, non paranda nobis solum ea, sed fruenda etiam est</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18758173</guid>
<pubDate>Fri, 27 Jul 2007 13:26:25 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18757986</link>
<description><![CDATA[<A HREF="/useremail/u/356416"><b>Link Logger</b></A> : <div class="bquote"><SMALL>said by Mr Anon :</SMALL><br><br>There is or was a chase question, I haven't gone back to it.  They may have removed it after I sent a complaint about it.</DIV>You should fire off a complaint about both of the Amazon screens being fake as well.<br><br>Blake  <br><SMALL>--<br>Vendor: Author of <A HREF="http://www.linklogger.com">Link Logger</A> which is a traffic analysis and firewall logging tool</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18757986</guid>
<pubDate>Fri, 27 Jul 2007 12:53:55 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18756810</link>
<description><![CDATA[<A HREF="/useremail/u/989554"><b>Blue2</b></A> : <div class="bquote"><SMALL>said by Mr Anon :</SMALL><BR><BR>There is or was a chase question, I haven't gone back to it.  They may have removed it after I sent a complaint about it. <br> </DIV>In other words, Mcafee's method of judging sites by spelling and design confused even Mcafee, so they really got only 9 of out 10 right on their own test? Ouch. Shooting yourself in the foot has got to hurt.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18756810</guid>
<pubDate>Fri, 27 Jul 2007 09:19:57 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18756740</link>
<description><![CDATA[<A HREF="/useremail/u/122916"><b>amysheehan</b></A> : <div class="bquote"><SMALL>said by Mr Anon :</SMALL><br><br>There is or was a chase question, I haven't gone back to it.  They may have removed it after I sent a complaint about it.  I have the link to the picture on there site that is still there when I posted this message.<br><br>&raquo;<A HREF="http://www.siteadvisor.com/quizzes/phishing_0707/quizzes/images/q4aLrg_answer.jpg" >www.siteadvisor.com/quizzes/phis&middot;&middot;&middot;swer.jpg</A><br><br>To find the actual chase page.<br>chase.com click mortgage under Personal Lending<br>then click Online mortgage application under Apply online.<br><br>drado.com seems to be a lending inst.  maybe they work with chase.<br> </DIV>See my post just above yours:  &raquo;<A HREF="/forum/r18756667-Re-Chase">Re:  Chase</A><br><br>:)<br><SMALL>--<br><A HREF="http://www.dslreports.com/phishtrack">DSLR Phishtracker</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18756740</guid>
<pubDate>Fri, 27 Jul 2007 09:01:52 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18756728</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : There is or was a chase question, I haven't gone back to it.  They may have removed it after I sent a complaint about it.  I have the link to the picture on there site that is still there when I posted this message.<br><br>&raquo;<A HREF="http://www.siteadvisor.com/quizzes/phishing_0707/quizzes/images/q4aLrg_answer.jpg" >www.siteadvisor.com/quizzes/phis&middot;&middot;&middot;swer.jpg</A><br><br>To find the actual chase page.<br>chase.com click mortgage under Personal Lending<br>then click Online mortgage application under Apply online.<br><br>drado.com seems to be a lending inst.  maybe they work with chase.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18756728</guid>
<pubDate>Fri, 27 Jul 2007 08:59:36 EDT</pubDate>
</item>

<item>
<title>Re:  Chase</title>
<link>http://www.dslreports.com/forum/remark,18756667</link>
<description><![CDATA[<A HREF="/useremail/u/122916"><b>amysheehan</b></A> : Mornin'  Mele20 <A HREF="/useremail/u/403861"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A><br><br>The 'quiz' has changed since I first took it.<br>DETAILS:  Question 4 of 10: One good way to protect yourself from a phishing attempt is to check the sender's name in the "From" field of an e-mail to see if it is the name of a legitimate institution.<br>---  This item WAS the location of the Chase [JP Morgan] good +/or fake web pages when I took the 'quiz'<br><br>I think the 'Chase' one was removed after this post was made: &raquo;<A HREF="/forum/r18752075-Re-Can-You-Identify-Phishing">Re: Can You Identify Phishing?</A> <br><br>:)<br><SMALL>--<br><A HREF="http://www.dslreports.com/phishtrack">DSLR Phishtracker</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18756667</guid>
<pubDate>Fri, 27 Jul 2007 08:44:07 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18756642</link>
<description><![CDATA[<A HREF="/useremail/u/403861"><b>Mele20</b></A> : I agree that one cannot remember the address for the secure page at Chase and a longer address invites typos. That's why I have it in Bookmarks and I told Chase when they first took the secure login off the main site that it was very stupid of them. CapitalOne is much better.  Chase told me everyone knows to use chaseonline. I said that is crazy because I didn't and I have banked online with them since they first started online banking so it wasn't as though I was new and ignorant when they changed the main page login to nonsecure and I tried to find the secure login. It took me 30 minutes of hunting all over their site to find it. When I did, I called their internet support number and laid into the tech and he said "you actually found a secure login page? Where? Give me the address." He wanted to be able to tell others calling and complaining that there still was a secure login page.  I also wrote Chase several secure emails about it and got only one canned reply.<br><br>Later, Chase tried to say that everyone "knew" to use the chase online page but no one did at first! And new customers probably don't know now. Chase made a mess of online banking from the beginning. They were the last of the major banks to have online banking and I was eagerly awaiting it...it was awful...two sites you had login to with a time limit on how long you could be there before you would be kicked off the site even if you were in the middle of paying your credit card bill. I exceeded the time limit many times because one of the two sites wouldn't load or would and then give a bunch of errors. It was horrible. I had to call their tech support so many times and frequently while on the phone with Chase support, I would get logged out and there was nothing I or the tech could do. I had to wait the mandatory time (15 min I think it was/is) before I could try to login again so the tech would be watching the clock, and telling me to hurry after he had given some fix for a problem, so I would get my business done before I was logged out. <br><br>In contrast, CapitalOne doesn't even have a specific tech support for online banking because they never have problems they told me. And they actually pay attention to user complaints and if they think the complaint has merit they act rapidly.  However, they were very slow to add support for Fx. But the best banks online are like my home bank which has put its ENTIRE SITE behind https.<br><br>I am still trying to figure out why everyone else in this thread says they saw Chase pages in the test, whereas, I saw CapitalOne pages. Maybe there are two tests? Maybe I saw other pages that were not like what the rest of you saw?????<br><SMALL>--<br>"The same ferocity that our founders devoted to protect the freedom and independence of the press is now appropriate for our defense of the freedom of the internet. The stakes are the same: the survival of our Republic". Al Gore, The Assault on Reason</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18756642</guid>
<pubDate>Fri, 27 Jul 2007 08:39:24 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18756468</link>
<description><![CDATA[<A HREF="/useremail/u/989554"><b>Blue2</b></A> : Yes, I posted example 11 above to demonstrate that even reputable banks make errors (on their security page no less!) so that relying on spelling or design alone is not a reliable method to judge a site's authenticity.<br><br>If one banks at Chase, how does one know that the banking login page is chaseonline.chase.com rather than www.chase.com? <br><br>Citibank's secure logon page is: &raquo;<small>https</small>://<A HREF="https://web.da-us.citibank.com/cgi-bin/citifi/scripts/login2/login.jsp">web.da-us.citibank.com/cgi-bin/c&middot;&middot;&middot;ogin.jsp</A><br><br>Obvious, right? These are just stupid corporate decisions that make phishes easier since no consumer can remember these addresses and it makes typing them in more likely to create errors.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18756468</guid>
<pubDate>Fri, 27 Jul 2007 07:45:49 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18756430</link>
<description><![CDATA[<A HREF="/useremail/u/403861"><b>Mele20</b></A> : <div class="bquote"><SMALL>said by  Blue2 <A HREF="/useremail/u/989554"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br><div class="bquote"><SMALL>said by  Mele20 <A HREF="/useremail/u/403861"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>  :</SMALL><br><br>But the quiz didn't have a Chase page. <br> </DIV>See the Chase single choice example posted above. <br></DIV>You mean your example number 11? There were only 10 tests not 11 and Chase was not one of them. <br><br>&raquo;<A HREF="http://www.chase.com" >www.chase.com</A> has a login on the main page and it is not encrypted probably for the reasons you mention. However, if you bank online at Chase, you are NOT supposed to go to www.chase.com rather you are supposed to go to &raquo;<small>https</small>://<A HREF="https://chaseonline.chase.com/online">chaseonline.chase.com/online</A> to login.<br><SMALL>--<br>"The same ferocity that our founders devoted to protect the freedom and independence of the press is now appropriate for our defense of the freedom of the internet. The stakes are the same: the survival of our Republic". Al Gore, The Assault on Reason</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18756430</guid>
<pubDate>Fri, 27 Jul 2007 07:28:38 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18756380</link>
<description><![CDATA[<A HREF="/useremail/u/989554"><b>Blue2</b></A> : <div class="bquote"><SMALL>said by  Mele20 <A HREF="/useremail/u/403861"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>But the quiz didn't have a Chase page. <br> </DIV>See the Chase single choice example posted above. <br><br><div class="bquote"><SMALL>said by  Mele20 <A HREF="/useremail/u/403861"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>No, ChaseOnline, which is their banking site, uses SSL page for logon. You are not supposed to use the general Chase.com site to do your banking. You are supposed to go to ChaseOnline instead which is secure. </DIV>I don't know about Chase but Citibank's banking site switched from SSL to a non-encrypted login page so that they could reduce the page load time for advertising.<br><br>The gap between banks and phishers is narrowing as banks make stupid decisions and phishers get smarter in duplicating the exact wording and design of banking sites.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18756380</guid>
<pubDate>Fri, 27 Jul 2007 07:10:54 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18756302</link>
<description><![CDATA[<A HREF="/useremail/u/403861"><b>Mele20</b></A> : <div class="bquote"><SMALL>said by  jdong <A HREF="/useremail/u/655964"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>There are sites like that where I'd <B>refuse</B> to use it just because it's so difficult to determine if it's actually real. Chase also presents the initial login form to their online banking unencrypted by default, which has been discussed before, which IMO is bad practice because it leaves the site vulnerable to MITM tampering before entering the form.<br> </DIV>No, ChaseOnline, which is their banking site, uses SSL page for logon. You are not supposed to use the general Chase.com site to do your banking. You are supposed to go to ChaseOnline instead which is secure.<br><br>But the quiz didn't have a Chase page. It had CapitalOne.  I thought both CapitalOne ones were fake. But I had to choose one so I chose the one that did not ask for my Social Security number (even though I knew the design was wrong) which I would not give on line EVER.  (I don't apply for new credit cards online for that reason either).<br><SMALL>--<br>"The same ferocity that our founders devoted to protect the freedom and independence of the press is now appropriate for our defense of the freedom of the internet. The stakes are the same: the survival of our Republic". Al Gore, The Assault on Reason</SMALL><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/18756302?c=1193905&ret=L2ZvcnVtL3IxODc0ODc0OS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="257083 bytes" WIDTH=600 HEIGHT=511 SRC="/r0/download/1193905.thumb600~1c8290def6bb71a7da05f6293ec8c611/ScreenShot054.png/thumb.jpg" ALT="Click for full size"></A><br>Not Chase</TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18756302</guid>
<pubDate>Fri, 27 Jul 2007 06:28:19 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18756280</link>
<description><![CDATA[<A HREF="/useremail/u/403861"><b>Mele20</b></A> : There is no Chase one. There is a CapitalOne one though. Or is there more than one version of this test?<br><br>I scored 9/10. I missed the CapitalOne one and I am a CapitalOne customer. :D I would immediately call CapitalOne technical support if I forgot my User ID (what is that - there is a User Name and a Password not a User ID) if they, or any bank, asked me for my Social Security number or tax ID number because I forgot my User Name or my Password! I have never forgotten it so I don't know what the procedure is but you are probably asked for the email address you registered with and a temporary password is sent to that address but I'm sure you get asked other stuff also but NEVER for Social Security number!  You probably also get locked out until you call if you try more than 3 times with the incorrect password.  <br><br>One time I went to ChaseOnline and went to login and was confronted with a locked account. I couldn't imagine why. I called immediately as that was my only choice given to rectify the situation. The rep said "This has never happened to you before and you have had an online account ever since we started online banking"?  He was incredulous and said I was extremely lucky as this happens frequently to most users. He explained that someone used my username and their password and couldn't get into what they thought was their account and they kept trying three times and the account was locked until I called. I had a simple user name from when Chase first started online banking and the process was so convoluted then with two different sites to navigate to use it to pay a credit card (within the time limit) that I was not concerned about the simple user name (plus I added a two digit number to the name) and I just never changed it. So, I changed it to a very complicated one and that has never happened again.<br><SMALL>--<br>"The same ferocity that our founders devoted to protect the freedom and independence of the press is now appropriate for our defense of the freedom of the internet. The stakes are the same: the survival of our Republic". Al Gore, The Assault on Reason</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18756280</guid>
<pubDate>Fri, 27 Jul 2007 06:13:40 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18756182</link>
<description><![CDATA[<A HREF="/useremail/u/666842"><b>MGD</b></A> : <div class="bquote"><SMALL>said by  Doctor Four <A HREF="/useremail/u/197199"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>There was a better example of a real vs. phished site quiz<br>posted either here or in the Scambusters forum a year or<br>two ago; I don't recall who it was created by, nor who had<br>posted it.<br> </DIV>Are you referring to the <A HREF="http://www.sonicwall.com/phishing/">Phishing IQ Test<A> listed on the Scambuster forum links by chance?. However, that test was about phishmails, and did not include hosted sites.<br><br>[att=1]<br><br>MGD<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap WIDTH=33%><A HREF="/speak/slideshow/18756182?c=1193880&ret=L2ZvcnVtL3IxODc0ODc0OS54bWw%3D"><IMG TITLE="8457 bytes" BORDER=0 WIDTH=127 HEIGHT=498 SRC="/r0/download/1193880~239046eab1c40f2ff74dd7c28172f75d/BBR_Phishlinks.png"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18756182</guid>
<pubDate>Fri, 27 Jul 2007 04:35:32 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18756147</link>
<description><![CDATA[<A HREF="/useremail/u/666842"><b>MGD</b></A> : <div class="bquote"><SMALL>said by  justin <A HREF="/useremail/u/1"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>I think the test is kind of bogus because they removed the address bar for several of the questions.<br>They can all be easily identified if your browser cannot be tricked into changing the URL in the address bar.<br> </DIV>I Agree, the majority of phishing sites are utility cloned copies of the real one, so typos and bad grammar are not that common.<br><br>They should not have hid the address bar, that is cheating :). Since a potential victim who has already clicked on the phishmail link believing that the mail is legit, are already 30%+ phished. One of the few remaining options is that they recognize that they have arrived at www.freehost.anyname.com/theirbankname/ and not www.theirbankname.com Expecting them to peruse the site and notice bad grammar or punctuation at this stage, is not in the cards. The dismal phrasing and bad grammar are more commonly contained in the phishmail itself.<br><br>That test exercise further confirms that for the average user recognizing and rejecting fraudulent emails is the primary method of combating phishing. Educating them that no reputable organization sends unsolicited email that leads to a request for their banking data, their SSN, DOB, and mother's maiden name, is ever legitimate.<br><br>MGD]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18756147</guid>
<pubDate>Fri, 27 Jul 2007 04:13:08 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18756126</link>
<description><![CDATA[<A HREF="/useremail/u/828168"><b>LeeBee</b></A> : some were real buggers!<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/18756126?c=1193870&ret=L2ZvcnVtL3IxODc0ODc0OS54bWw%3D"><IMG TITLE="11788 bytes" BORDER=0 WIDTH=438 HEIGHT=106 SRC="/r0/download/1193870~ae566253288191ce5d879e51dae1d8c3/10.jpg"></A><br>10 - Yay!</TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18756126</guid>
<pubDate>Fri, 27 Jul 2007 03:56:31 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18756105</link>
<description><![CDATA[<A HREF="/useremail/u/748935"><b>mindypin</b></A> :  :)I can't really brag, though, because I really sort of guessed at the Amazon page.  That one was tough.  I always type in the link myself when going to a website where I'm going to be doing secure transactions.  Also, I never, ever link to secure sites through email.  Thanks for posting this quiz - I emailed it to a bunch of my friends who aren't that savvy about identifying scams. :D<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/18756105?c=1193867&ret=L2ZvcnVtL3IxODc0ODc0OS54bWw%3D"><IMG TITLE="76160 bytes" BORDER=0 WIDTH=447 HEIGHT=127 SRC="/r0/download/1193867~7cef1dc789e5f68886a36e7fb9077491/Phishing%20Quiz%20Results.jpg"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18756105</guid>
<pubDate>Fri, 27 Jul 2007 03:42:06 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18755857</link>
<description><![CDATA[<A HREF="/useremail/u/356416"><b>Link Logger</b></A> : Interesting but I have a problem with #5 as both are fake in my opinion and I've attached my mark up for the so called real one.  I agree the one has the double drop down which is a give away, but the so called real is missing footer components as well which can be a give away of a lazy phisher.<br><br>Check out Amazon.com and tell me if you think they are both fake as well.<br><br>Blake<br>Edit -- I'm so tired at the moment that it seems the english language is beyond me.<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/18755857?c=1193848&ret=L2ZvcnVtL3IxODc0ODc0OS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="126534 bytes" WIDTH=600 HEIGHT=421 SRC="/r0/download/1193848.thumb600~fc970dfa1571ca56e416849ca825d0b4/Amazon_Real_really Fake.jpg/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18755857</guid>
<pubDate>Fri, 27 Jul 2007 01:53:03 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18755783</link>
<description><![CDATA[<A HREF="/useremail/u/697517"><b>koolman2</b></A> : I got all but the Myspace one correct.<br><SMALL>--<br>There's no place like ::1.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18755783</guid>
<pubDate>Fri, 27 Jul 2007 01:24:36 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18755520</link>
<description><![CDATA[<A HREF="/useremail/u/795407"><b>SnowyOne</b></A> : <div class="bquote"><SMALL>said by  RobertLudlum <A HREF="/useremail/u/1143581"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>Hmm only 2/10. I don't know how you guys can figure out which ones are phishes without looking at the url. <br> </DIV>Well, you can't. Without seeing the URL the best you can do is guess. Your 2/10 is interesting. If you're a gambling man your mine. :D]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18755520</guid>
<pubDate>Fri, 27 Jul 2007 00:21:44 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18755492</link>
<description><![CDATA[<A HREF="/useremail/u/655964"><b>jdong</b></A> : No, but many of them do use online PW verification forms regularly/randomly that ask for your account number, phone number, and another form of ID (usually SSN)...<br><SMALL>--<br>UbuntuForums Administrator: <A HREF="http://ubuntuforums.org">try Ubuntu Linux</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18755492</guid>
<pubDate>Fri, 27 Jul 2007 00:14:20 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18755408</link>
<description><![CDATA[<A HREF="/useremail/u/129458"><b>KrK</b></A> : 9 out of 10.  Missed the Amazon one.  Many were pretty obvious  but the Amazon one was pretty hard.<br><br>I based my guess upon the way it asked for the name and password, and I guessed wrong.  I didn't notice the "!"<br><br>Still, half the battle is how you got to the site in the first place.  If it's a phishing email, I'm not going to fall for it anyway.   I've gotten very realistic looking emails without grammar or spelling errors, however, I know from repeated reports and assurances that companies like Paypal or Citibank, eBay, etc etc are NEVER going to send you an email directing you to "Enter your account information so we can verify you".   <br><SMALL>--<br>"Regulatory capitalism is when companies invest in lawyers, lobbyists, and politicians, instead of plant, people, and customer service." - former FCC Chairman William Kennard (A real FCC Chairman, unlike the current Corporate Spokesperson in the job!)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18755408</guid>
<pubDate>Thu, 26 Jul 2007 23:58:43 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18754744</link>
<description><![CDATA[<A HREF="/useremail/u/1358638"><b>81399672</b></A> : 6/10]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18754744</guid>
<pubDate>Thu, 26 Jul 2007 22:13:35 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18754727</link>
<description><![CDATA[<A HREF="/useremail/u/940717"><b>neonhomer</b></A> : 9/10 for me.... I missed the Paypal one... That was a boneheaded move... and I use PayPal a lot... LOL....]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18754727</guid>
<pubDate>Thu, 26 Jul 2007 22:11:18 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18754520</link>
<description><![CDATA[<A HREF="/useremail/u/637748"><b>David</b></A> : <div class="bquote"><SMALL>said by  Portmonkey <A HREF="/useremail/u/986420"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Missed the Chase Bank and Amazon.  :)<br> </DIV>I missed the amazon, and one of the final questions, got 8/10 though. The amazon one was tough though. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18754520</guid>
<pubDate>Thu, 26 Jul 2007 21:45:16 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18754235</link>
<description><![CDATA[<A HREF="/useremail/u/1081876"><b>Dr Tweak</b></A> : 9 out of 10, I had a careless mistake.<br><br> :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18754235</guid>
<pubDate>Thu, 26 Jul 2007 21:06:21 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18754228</link>
<description><![CDATA[<A HREF="/useremail/u/655964"><b>jdong</b></A> : IMO this is a "Face it you're a dimwit, you can't tell the difference. Now give me 50 bucks to protect you" marketing ploy. The tests were pretty ridiculous and not gonna help you in the real world much.<br><SMALL>--<br>UbuntuForums Administrator: <A HREF="http://ubuntuforums.org">try Ubuntu Linux</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18754228</guid>
<pubDate>Thu, 26 Jul 2007 21:05:08 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18754112</link>
<description><![CDATA[<A HREF="/useremail/u/197199"><b>Doctor Four</b></A> : There was a better example of a real vs. phished site quiz<br>posted either here or in the Scambusters forum a year or<br>two ago; I don't recall who it was created by, nor who had<br>posted it.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18754112</guid>
<pubDate>Thu, 26 Jul 2007 20:48:14 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18753387</link>
<description><![CDATA[<A HREF="/useremail/u/162762"><b>djrobx</b></A> : I got 9/10 but I agree, this test is bogus.   Duplicating the exact page a site uses, word for word, even pixel for pixel, is not that hard to do.<br><br>One major criteria I used to know the answer was, "Is the site asking for too much information?".  No "security check" should need you to completely re-enter all of your personal information and account numbers.  <br><br>Awkward grammar is certainly something to look for, but is hardly conclusive, yet seems to be the basis of this test!<br><br>I got the Zimbabwean 404 one wrong, because I'd never heard of that particular scam before.  <br><SMALL>--<br>Laser eye surgery rocks!  I love frickin' laser beams.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18753387</guid>
<pubDate>Thu, 26 Jul 2007 19:03:09 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18753365</link>
<description><![CDATA[<A HREF="/useremail/u/655964"><b>jdong</b></A> : <div class="bquote"><SMALL>said by  RobertLudlum <A HREF="/useremail/u/1143581"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Hmm only 2/10. I don't know how you guys can figure out which ones are phishes without looking at the url. <br> </DIV>I gotta admit, mostly familiarity. I have accounts with all these sites and can tell that they are not like the ones I use... In addition, as it pointed out, there are times you can OBVIOUSLY tell the layout is different or the grammar is all botched up that is uncharacteristic of a billion-dollar company.<br><SMALL>--<br>UbuntuForums Administrator: <A HREF="http://ubuntuforums.org">try Ubuntu Linux</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18753365</guid>
<pubDate>Thu, 26 Jul 2007 18:57:00 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18753261</link>
<description><![CDATA[<A HREF="/useremail/u/1143581"><b>RobertLudlum</b></A> : Hmm only 2/10. I don't know how you guys can figure out which ones are phishes without looking at the url. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18753261</guid>
<pubDate>Thu, 26 Jul 2007 18:40:10 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18753211</link>
<description><![CDATA[<A HREF="/useremail/u/789469"><b>exocet_cm</b></A> : <div class="bquote"><SMALL>said by  jdong <A HREF="/useremail/u/655964"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br><div class="bquote"><SMALL>said by  russotto <A HREF="/useremail/u/214274"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Yep, the "fake" Chase page is real (linked from chase.com), though the real page has more stuff off to the bottom.<br><br>If I'd seen it while trying to actually fill out a mortgage I might not trust it either, as its URL is "chasemortgage.dorado.com" and not "chase.com".  But I think it is.<br> </DIV>There are sites like that where I'd <B>refuse</B> to use it just because it's so difficult to determine if it's actually real. Chase also presents the initial login form to their online banking unencrypted by default, which has been discussed before, which IMO is bad practice because it leaves the site vulnerable to MITM tampering before entering the form.<br> </DIV>I agree with ya there  jdong <A HREF="/useremail/u/655964"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> about the MITM attack possibility. A few of the folks here in the security forum need to slap the chase security gurus around a bit and clean up their act for em.<br><SMALL>--<br>"I have measured out my life with coffee spoons..." - T.S Eliot<BR> <B>Check out ma blog: &raquo;<A HREF="http://www.johndball.com" >www.johndball.com</A></B></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18753211</guid>
<pubDate>Thu, 26 Jul 2007 18:31:18 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18752899</link>
<description><![CDATA[<A HREF="/useremail/u/1157186"><b>quatrix</b></A> : <div class="bquote"><SMALL>said by  robo_mojo <A HREF="/useremail/u/1312347"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>I got to Question 3 which doesn't even show a URL, and stopped the test. I won't be arsed to determine whether a site is a phish or not if I can't even see a URL. <br><br>I realize that I'm probably supposed to be looking at the horrible misuse of the English language in one of the choices, and that is probably what they are saying is a phish. But that is hardly an appropriate way to spot a phishing site.</DIV>Couldn't have said it better myself... I also quit after two questions in a row were missing the URL.  I pick out grammar and spelling problems better than most, but it's not worth the time when the biggest/easiest clue is missing.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18752899</guid>
<pubDate>Thu, 26 Jul 2007 17:39:52 EDT</pubDate>
</item>

<item>
<title>&#x26;nbsp;</title>
<link>http://www.dslreports.com/forum/remark,18752681</link>
<description><![CDATA[<A HREF="/useremail/u/853361"><b>Dude111</b></A> : Yes i agree Matey 100%<br><br> <BLOCKQUOTE><SMALL>said by Lanik :</SMALL><HR>Same. Some of them are pretty good or I wasn't looking closely enough.<HR></BLOCKQUOTE>Yes they are all mostly VERY GOOD (Hard to spot)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18752681</guid>
<pubDate>Thu, 26 Jul 2007 17:04:13 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18752673</link>
<description><![CDATA[<A HREF="/useremail/u/1144666"><b>jabarnut</b></A> : For the heck of it, I decided to pick the 'spoofed' sites instead of the 'authentic' sites.<br><br>I did very well, actually......answered 1 of 10 questions "correctly".  :D<br><br>Although, I agree with justin that the whole thing is pretty bogus, for the reason mentioned.<br><br>(Edit) Oops...almost forgot the screenshot.<br>[att=1]<br><br>I let those dang "scammers" fool me for sure. <br>I'm going to get SiteAdvisor right away!!!  <br><br>Maybe I should even go for the "Best Value SiteAdvisor PLUS 3-User Family Pack!" :o<br><B>(Reg. $49.99, now only $19.99. I save $30.00!)</B><br><br>Hmmmm...wonder who's really doing the scamming here? <div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/18752673?c=1193660&ret=L2ZvcnVtL3IxODc0ODc0OS54bWw%3D"><IMG TITLE="46882 bytes" BORDER=0 WIDTH=451 HEIGHT=228 SRC="/r0/download/1193660~608fde298f7e4a5b4101001bcab7fa17/SiteAdvisor.jpg"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18752673</guid>
<pubDate>Thu, 26 Jul 2007 17:02:47 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18752668</link>
<description><![CDATA[<A HREF="/useremail/u/1288058"><b>psafux</b></A> : 9/10. They got me on amazon :P i dont visit amazon so im OK ! lol.<br><SMALL>--<br>Yes. the cat in my avatar is indeed mine.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18752668</guid>
<pubDate>Thu, 26 Jul 2007 17:01:41 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18752494</link>
<description><![CDATA[<A HREF="/useremail/u/1"><b>justin</b></A> : I think the test is kind of bogus because they removed the address bar for several of the questions.<br>They can all be easily identified if your browser cannot be tricked into changing the URL in the address bar.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18752494</guid>
<pubDate>Thu, 26 Jul 2007 16:35:12 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18752207</link>
<description><![CDATA[<A HREF="/useremail/u/655964"><b>jdong</b></A> : <div class="bquote"><SMALL>said by  russotto <A HREF="/useremail/u/214274"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Yep, the "fake" Chase page is real (linked from chase.com), though the real page has more stuff off to the bottom.<br><br>If I'd seen it while trying to actually fill out a mortgage I might not trust it either, as its URL is "chasemortgage.dorado.com" and not "chase.com".  But I think it is.<br> </DIV>There are sites like that where I'd <B>refuse</B> to use it just because it's so difficult to determine if it's actually real. Chase also presents the initial login form to their online banking unencrypted by default, which has been discussed before, which IMO is bad practice because it leaves the site vulnerable to MITM tampering before entering the form.<br><SMALL>--<br>UbuntuForums Administrator: <A HREF="http://ubuntuforums.org">try Ubuntu Linux</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18752207</guid>
<pubDate>Thu, 26 Jul 2007 15:56:51 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18752158</link>
<description><![CDATA[<A HREF="/useremail/u/214274"><b>russotto</b></A> : Yep, the "fake" Chase page is real (linked from chase.com), though the real page has more stuff off to the bottom.<br><br>If I'd seen it while trying to actually fill out a mortgage I might not trust it either, as its URL is "chasemortgage.dorado.com" and not "chase.com".  But I think it is.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18752158</guid>
<pubDate>Thu, 26 Jul 2007 15:48:42 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18752141</link>
<description><![CDATA[<A HREF="/useremail/u/151802"><b>jaykaykay</b></A> : I shocked the heck out of myself.  I got 7 out of 10 but really didn't think I would do even that well.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18752141</guid>
<pubDate>Thu, 26 Jul 2007 15:46:39 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18752102</link>
<description><![CDATA[<A HREF="/useremail/u/557569"><b>jcr46385</b></A> : I see i'm not the only one, Chase down 3 sofar and counting. ;)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18752102</guid>
<pubDate>Thu, 26 Jul 2007 15:39:41 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18752075</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : I've taken this up with the site I saw it on and sent a message to site advisor about it.<br><br>When I compared the actual chase page to the page they said was wrong. They seem exactly the same.<br><br>chase.com  Under Personal Lending click mortgage<br>New page: Under Apply online click online mortgage application<br><br>I compared the picture to the live site and found no difference.  Also the other possibly fake page you are presented with is on a different step in the process.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18752075</guid>
<pubDate>Thu, 26 Jul 2007 15:34:48 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18751664</link>
<description><![CDATA[<A HREF="/useremail/u/989554"><b>Blue2</b></A> : Here's example number 11. Real or fake? I'll even make it easy and tell you where to look.<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/18751664?c=1193602&ret=L2ZvcnVtL3IxODc0ODc0OS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="256307 bytes" WIDTH=600 HEIGHT=478 SRC="/r0/download/1193602.thumb600~ff26bad796f2b7fecb8c5a969cbe432c/Chase.jpg/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18751664</guid>
<pubDate>Thu, 26 Jul 2007 14:30:40 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18751658</link>
<description><![CDATA[<A HREF="/useremail/u/225019"><b>roztaylor</b></A> : <div class="bquote"><SMALL>said by  barqsdrinker <A HREF="/useremail/u/326871"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br> [snip] Even with the poor phrasing, why would one care about whether or not the site was real - you don't have an account so you know it is fake.<br> </DIV>I've been receiving email from Chase bank over the last few months.  I thought it was either phishing or spam (and treated it as such).  Turns out the credit card that I never use, changed banks.  I suppose they sent me a letter and I read it, but since I never use the card I forgot the bank change--until the new card showed up in the mail.<br><SMALL>--<br>Choose to make it a good day... don't wait for something good to happen!</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18751658</guid>
<pubDate>Thu, 26 Jul 2007 14:29:53 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18751550</link>
<description><![CDATA[<A HREF="/useremail/u/1039486"><b>alrandolph</b></A> : i got 8/10 correct. I missed the Capital One and the last one.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18751550</guid>
<pubDate>Thu, 26 Jul 2007 14:11:42 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18751504</link>
<description><![CDATA[<A HREF="/useremail/u/429566"><b>Jason Levine</b></A> : <div class="bquote">YOU ANSWERED 8 OF 10 QUESTIONS CORRECTLY<br>Rating: Safety Guru</DIV>A few of them were tough without the address bar.  I would have gotten 10 out of 10 had I had that additional information.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18751504</guid>
<pubDate>Thu, 26 Jul 2007 14:04:19 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18751420</link>
<description><![CDATA[<A HREF="/useremail/u/401000"><b>jjoshua</b></A> : I missed the Chase one.  The fake site asks for less information that the real one (ss#).<br><br>Also, the fake site looks nicer.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18751420</guid>
<pubDate>Thu, 26 Jul 2007 13:52:53 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18751335</link>
<description><![CDATA[<A HREF="/useremail/u/655964"><b>jdong</b></A> : I scored 9/10... failed the SSL question. I contemplated what they meant by this.... I interpreted as the SSL certificate being shown on the correct URL, in addition to no signature mismatch errors.<br><br>Obviously McAfee just meant "don't trust something just because it shows a padlock" which is certainly true.<br><br>I liked this test -- I think it takes some close examination to catch these tiny nuances.<br><SMALL>--<br>UbuntuForums Administrator: <A HREF="http://ubuntuforums.org">try Ubuntu Linux</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18751335</guid>
<pubDate>Thu, 26 Jul 2007 13:38:58 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18751028</link>
<description><![CDATA[<A HREF="/useremail/u/646474"><b>shearer</b></A> : I scored 8/10. Missed the Amazon & Chase ones. Am not the least bit bothered by failure to get 10/10.<br><br>In real life, I manually examine SSL certs and do netstat/lookups. Unless it's an email, I don't pay **too** much attention to words on webpages as legit sites can have "awkward phrases" and spelling typos.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18751028</guid>
<pubDate>Thu, 26 Jul 2007 12:56:56 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18750605</link>
<description><![CDATA[<A HREF="/useremail/u/197199"><b>Doctor Four</b></A> : I got 10 out of 10 right. The key to those without URLs<br>is to look for spelling and grammatical errors, as well<br>as awkward phrasing.<br><br>Those are surefire signs that the email/site isn't legit.<br><br>Another sign is incorrect logos or designs - in the case<br>of both the AOL and Capitol One examples, those were wrong.<br><SMALL>--<br>"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)<br>We are the Hacker Collective: Resistance Is Futile - All Your AACS Keys Will Be Assimilated.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18750605</guid>
<pubDate>Thu, 26 Jul 2007 11:48:43 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18750598</link>
<description><![CDATA[<A HREF="/useremail/u/668609"><b>EGeezer</b></A> : <br>I got 9 of 10 - I guessed on the last one because an examination of the SSL will reveal whether it's spoofed or not. However, McAffee must feel that examining the certificate for an untrusted issuer or self-issued cert is insufficient. <br><br>As others say, the URL and how the user was directed to the link is a quick tipoff, but lacking that information, the grammar and phrasing helped. <br><br>However, if a phish site is grammatically correct, or made using a<A HREF="http://www.youtube.com/watch?v=6NviimO64qA"><B> Rock Phish kit</B></A>, the sites may not have such errors. <br><br>I think use of site advisor and other similar tools is a good thing, but I suspect that these are based on a frequently updated list and that "zero-day" phish sites of smaller regional/local business sites might slip through the application. <br><SMALL>--<br>Sive enim ad sapientiam perveniri potest, non paranda nobis solum ea, sed fruenda etiam est</SMALL><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=2 WIDTH=66%><A HREF="/speak/slideshow/18750598?c=1193553&ret=L2ZvcnVtL3IxODc0ODc0OS54bWw%3D"><IMG TITLE="13032 bytes" BORDER=0 WIDTH=250 HEIGHT=224 SRC="/r0/download/1193553~53fc932d67f55337bac2f2719909d8ca/suspenders.jpg"></A><br>Belt and suspenders where my money and identity is concerned, thats me :D</TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18750598</guid>
<pubDate>Thu, 26 Jul 2007 11:47:39 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18750474</link>
<description><![CDATA[<A HREF="/useremail/u/1312347"><b>robo_mojo</b></A> : I got to Question 3 which doesn't even show a URL, and stopped the test. I won't be arsed to determine whether a site is a phish or not if I can't even see a URL. <br><br>I realize that I'm probably supposed to be looking at the horrible misuse of the English language in one of the choices, and that is probably what they are saying is a phish. But that is hardly an appropriate way to spot a phishing site. <br><br>It would be very silly to give a site your bank account login info only because the site had proper spelling and grammar. <br><br>But then again, this test is trying to sell a product, so it isn't a surprise that it is misleading. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18750474</guid>
<pubDate>Thu, 26 Jul 2007 11:24:08 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18750139</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : 10 out of 10.  It wasn't hard at all.  It would have been even easier if we had some context.  That is, how the user arrived at the webpage.  That is all not to mention, except for the first question, we never get to see any info regarding the url of the webpage.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18750139</guid>
<pubDate>Thu, 26 Jul 2007 10:26:24 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18750001</link>
<description><![CDATA[<A HREF="/useremail/u/789469"><b>exocet_cm</b></A> : <div class="bquote"><SMALL>said by  jcr46385 <A HREF="/useremail/u/557569"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>9/10 here, one i missed was my Bank.  :uhh:<br> </DIV>Ouch!  :p   It's ok, I missed my bank (Chase) as well. Apparently there are gramatical errors on the phishing page that I overlooked. Glad I do <I>MOST</I> of my banking in person. The only online banking I do is checking my balances, and that is it. <br><br>Edit: They need to have music playing in the background; Amadeus Mozart - Piano Concerto in E Flat, #482<br><SMALL>--<br>"I have measured out my life with coffee spoons..." - T.S Eliot<BR> <B>Check out ma blog: &raquo;<A HREF="http://www.johndball.com" >www.johndball.com</A></B></SMALL><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/18750001?c=1193526&ret=L2ZvcnVtL3IxODc0ODc0OS54bWw%3D"><IMG TITLE="65960 bytes" BORDER=0 WIDTH=454 HEIGHT=261 SRC="/r0/download/1193526~78cacb22f8e40ee3f1ba4a6e0307d1d8/Clipboard02.jpg"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18750001</guid>
<pubDate>Thu, 26 Jul 2007 10:02:20 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18749935</link>
<description><![CDATA[<A HREF="/useremail/u/1376598"><b>swhx7</b></A> : Blue2 and SnowyOne are basically right: the quiz is worthless. But it's actually worse than useless because it teaches people to judge by the wrong criteria.<br><br>The most basic thing you need to look at is the URL. It was actually *<I>missing from the picture</I>* in at least one of the questions (I quit at that point). Yes, other clues are important too, but without the URL you can't be sure.<br><br>There was another quiz like this with images of emails, asking visitors to spot the phishes. That too was worse than useless: they showed HTML-rendered displays, with all the true URLs behind the links invisible, and the headers not showing. Thus all the relatively reliable indicators of where it came from were missing, and they were effectively training people to rely on superficial appearances instead.<br><br>With the amount of effort that's been put into this slick quiz, they could easily have made a good start on teaching people the basic technical facts that would really help them.<br><br>The underlying idea seems to be that the public just can't learn anything that involves more text and thinking and less of the colorful pictures. Such idea is stupid and harmful.<br><br>'Scuze me for ranting.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18749935</guid>
<pubDate>Thu, 26 Jul 2007 09:49:12 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18749930</link>
<description><![CDATA[<A HREF="/useremail/u/557569"><b>jcr46385</b></A> : 9/10 here, one i missed was my Bank.  :uhh:]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18749930</guid>
<pubDate>Thu, 26 Jul 2007 09:47:52 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18749838</link>
<description><![CDATA[<A HREF="/useremail/u/164262"><b>Zaber</b></A> : 9 out of 10 here.  I missed the Chase bank one.  Then again who says that all professional sites are perfect in their grammar?  I was looking more at the page layout and what information they asked for.  A real test would have included more information (where the link came from, etc).<br><SMALL>--<br>Give a man a fish and he eats for a day, teach a man to fish and he will feed himself for a lifetime</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18749838</guid>
<pubDate>Thu, 26 Jul 2007 09:24:34 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18749797</link>
<description><![CDATA[<A HREF="/useremail/u/878241"><b>JohnInSJ</b></A> : YOU ANSWERED 9 OF 10 QUESTIONS CORRECTLY<br>Rating: Safety Guru<br><br>Missed the Amazon one.<br><br>However, my first thought was - ewwue, they're using IE, they must all be phishing attempts ;)<br><SMALL>--<br>My place : &raquo;<A HREF="http://www.schettino.us" >www.schettino.us</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18749797</guid>
<pubDate>Thu, 26 Jul 2007 09:15:02 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18749774</link>
<description><![CDATA[<A HREF="/useremail/u/246096"><b>yock</b></A> : 9 of 10 correct. I've never been a customer of Chase Bank and have never visited their site. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18749774</guid>
<pubDate>Thu, 26 Jul 2007 09:07:14 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18749629</link>
<description><![CDATA[<A HREF="/useremail/u/989554"><b>Blue2</b></A> : Yes, DojiStar, in the real world, no one is given two alternatives to choice between and is told that one of them is a phish. A far better test might have been to make ALL the choices phishes, thereby proving how deceiving looks can be. <br><br>It might be interesting to get times spent looking at these twenty examples as well as scores. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18749629</guid>
<pubDate>Thu, 26 Jul 2007 08:23:40 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18749507</link>
<description><![CDATA[<A HREF="/useremail/u/222339"><b>redhat1968</b></A> : YOU ANSWERED 7 OF 10 QUESTIONS CORRECTLY<br>Rating: Safety Guru ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18749507</guid>
<pubDate>Thu, 26 Jul 2007 07:47:17 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18749484</link>
<description><![CDATA[<A HREF="/useremail/u/326871"><b>barqsdrinker</b></A> : I got 8 out of 10; but like most, I didn't care for it, either.  What if you don't have an AOL, Amazon, or Capital One account??  Even with the poor phrasing, why would one care about whether or not the site was real - you don't have an account so you know it is fake.<br><SMALL>--<br>Thanks for reading! :)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18749484</guid>
<pubDate>Thu, 26 Jul 2007 07:36:35 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18749420</link>
<description><![CDATA[<A HREF="/useremail/u/154241"><b>John_W</b></A> : Well I got them all right, but with the quiz, you knew there was one that was a phish site.  So you took the extra time to go over each one.  In real life, with no comparison site, would you be able to catch all of these.<br><br>The quiz was a bit off because you could not tell the context to which the person got to the site.  Was it from an unsolicited email, mistyped website?  You also couldn't hold your mouse over links to see if they were legitimately owned by the company you were looking for.  That made the quix more difficult.<br><br>So in some cases it may be more difficult to figure it out, but in some cases finding out it is a phish site may be easier than the quiz was.<br><SMALL>--<br><B><A HREF="/forum/disco">Team Discovery</A></B>--<B><A HREF="/forum/helix">BBR Team Helix</A></B></SMALL><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/18749420?c=1193505&ret=L2ZvcnVtL3IxODc0ODc0OS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="1910454 bytes" WIDTH=600  SRC="/r0/download/1193505.thumb600~20e28b1ce8a85ec092496c80b814b12d/guru.bmp/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18749420</guid>
<pubDate>Thu, 26 Jul 2007 07:08:57 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18749403</link>
<description><![CDATA[<A HREF="/useremail/u/795407"><b>SnowyOne</b></A> : I wouldn't go as far as saying that the test is a total disservice to the internet community, but I certainly wouldn't call it a bonafide service either. The test does raise awareness of phish hosts so give it credit for that. Suggesting that visual clues are a legitimate method of determining whether a site is who it claims to be is a disservice to the internet community. The focus needs to be how on to avoid landing on a phish page. Not surprisingly it suggests using it's site advisor for maximum protection. Not surprisingly that's also a disservice to the internet community in the context of determining a sites authenticity. The poor grammar, spelling & malformed phish examples they are using on their test pages occur so infrequently in comparision to the perfectly formed phish hosts we see today that it's a disservice to make them central to the test. The best protection is simple & free. Not clicking a link in an email will provide more protection than visual clues & site advisor combined. Guaranteed.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18749403</guid>
<pubDate>Thu, 26 Jul 2007 06:59:10 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18749286</link>
<description><![CDATA[<A HREF="/useremail/u/989554"><b>Blue2</b></A> : <div class="bquote"><SMALL>said by  nwrickert <A HREF="/useremail/u/1070900"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>9/10.  However, I didn't much like it.  The information being used to distinguish is of marginal value.   </DIV>I agree. This test is a terrible way to test security knowledge.<br><br>1. "Missing Security Center" link means that it's a phish? (But when my bank changes its SSL login page to a non-SSL page I'm supposed to believe that this is the real site?)<br><br>2. "Awkward phrasing" (Hahahaha. I think my bank ONLY hires people for their awkward phrasing.)<br><br>3. "Space between end of word and punctuation"? (Yeah, sure, no programmer would ever do that?)<br><br>4. "Vague but scary warning." (Huh?)<br><br>5. "PayPal Account Department doesn't sound real." (But "PayPal Executive Escalations", a real division, does?) <br><br>6. Knowing the name of a phishing scam protects you? (Whether it's called ""Zimbabwean 404" or "Nigerian 419" means nothing. The point is to recognize WHY it is a scam, not its name.)<br><br>All this test says to me is that if I were a potential scammer, I should just copy the precise wording from the authentic site or get out my dictionary and 99% of the web users in this world are toast!<br><br>I continue to maintain that spelling is a horrible test of  authenticity, as the spelling of many of the posts on this forum alone demonstrate.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18749286</guid>
<pubDate>Thu, 26 Jul 2007 05:53:41 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18749257</link>
<description><![CDATA[<A HREF="/useremail/u/372021"><b>Doctor Olds</b></A> : First try. :-)<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/18749257?c=1193488&ret=L2ZvcnVtL3IxODc0ODc0OS54bWw%3D"><IMG TITLE="35927 bytes" BORDER=0 WIDTH=479 HEIGHT=412 SRC="/r0/download/1193488~41879b187659db4a5ef1974aaf5744a3/SafetyGuru.png"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18749257</guid>
<pubDate>Thu, 26 Jul 2007 05:24:08 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18749193</link>
<description><![CDATA[<A HREF="/useremail/u/1304319"><b>Psicop</b></A> : 7/10.<br><br>Doesn't worry me. I NEVER do any of financial & business transactions online.<br><br>I learned how dirty is the Internet with this regards several years ago from one of my ex-flatmates a sys admin at Mincom who also happened to use Knoppix.<br><br>Thnx for providing the link, dude111.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18749193</guid>
<pubDate>Thu, 26 Jul 2007 04:10:52 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18749157</link>
<description><![CDATA[<A HREF="/useremail/u/693202"><b>Owlbet</b></A> : I got 8 out of 10 correct.  If I would have taken the time to completely read both pictures, I would have found the grammatical errors on #4 & the logo error on #8.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18749157</guid>
<pubDate>Thu, 26 Jul 2007 03:46:12 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18749054</link>
<description><![CDATA[<A HREF="/useremail/u/986420"><b>Portmonkey</b></A> : Missed the Chase Bank and Amazon.  :)<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/18749054?c=1193459&ret=L2ZvcnVtL3IxODc0ODc0OS54bWw%3D"><IMG TITLE="20985 bytes" BORDER=0 WIDTH=430 HEIGHT=104 SRC="/r0/download/1193459~7808d3263a09692cb21781e3ee3a5760/Capture1zillion%20and%205.JPG"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18749054</guid>
<pubDate>Thu, 26 Jul 2007 02:56:39 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18749044</link>
<description><![CDATA[<A HREF="/useremail/u/103090"><b>tempnexus</b></A> : I got 9/10 right...just missed the SSL wrong...but maybe because I actually read the certificate fully and not just look at the picture.<br><br>&raquo;<A HREF="http://www.siteadvisor.com/quizzes/phishing_0707/#quiztop" >www.siteadvisor.com/quizzes/phis&middot;&middot;&middot;#quiztop</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18749044</guid>
<pubDate>Thu, 26 Jul 2007 02:52:53 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18748982</link>
<description><![CDATA[<A HREF="/useremail/u/1070900"><b>nwrickert</b></A> : 9/10.  However, I didn't much like it.  The information being used to distinguish is of marginal value.  Some phish sites are very good and cannot be distinguished in this manner.  And even real sites can make grammatical errors on their web pages.<br><br>In practice you have other information available that is more reliable - the email headers, the hostname of the web page are examples.<br><SMALL>--<br>AT&T dsl; Westell 2200 modem/router; SuSE 10.1; firefox 2.0.0.4</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18748982</guid>
<pubDate>Thu, 26 Jul 2007 02:29:56 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18748841</link>
<description><![CDATA[<A HREF="/useremail/u/122916"><b>amysheehan</b></A> : <div class="bquote"><SMALL>said by  Dude111 <A HREF="/useremail/u/853361"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br><B>Can you tell a real site from a phony one?<br>Try this test and learn:</B><br>&raquo;<A HREF="http://www.mcafee.com/phishing_quiz" >www.mcafee.com/phishing_quiz</A><br><br>I got 5/10 right :)<br> </DIV>Got 9/10 correct - missed the URL redirect for myspace  -  never been there and looked more at the layout and missed the obvious.<br><br>:)<br><SMALL>--<br><A HREF="http://www.dslreports.com/phishtrack">DSLR Phishtracker</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18748841</guid>
<pubDate>Thu, 26 Jul 2007 01:38:28 EDT</pubDate>
</item>

<item>
<title>Re: Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18748790</link>
<description><![CDATA[<A HREF="/useremail/u/418397"><b>Lanik</b></A> : <div class="bquote"><SMALL>said by  Dude111 <A HREF="/useremail/u/853361"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>I got 5/10 right :)<br> </DIV>Same.  Some of them are pretty good or I wasn't looking closely enough. ;)<br><SMALL>--<br>"If it ain't broke don't fix it."</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18748790</guid>
<pubDate>Thu, 26 Jul 2007 01:21:03 EDT</pubDate>
</item>

<item>
<title>Can You Identify Phishing?</title>
<link>http://www.dslreports.com/forum/remark,18748749</link>
<description><![CDATA[<A HREF="/useremail/u/853361"><b>Dude111</b></A> : <B>Can you tell a real site from a phony one?<br>Try this test and learn:</B><br>&raquo;<A HREF="http://www.mcafee.com/phishing_quiz" >www.mcafee.com/phishing_quiz</A><br><br>I got 5/10 right :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18748749</guid>
<pubDate>Thu, 26 Jul 2007 01:03:21 EDT</pubDate>
</item>

</channel>
</rss>
