<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>College phishing in Spam, Scam and Phishbusters</title>
<link>http://www.dslreports.com/forum/r20430401</link>
<description></description>
<language>en</language>
<pubDate>Sat, 26 Jul 2008 13:30:13 EDT</pubDate>
<lastBuildDate>Sat, 26 Jul 2008 13:30:13 EDT</lastBuildDate>

<item>
<title>College phishing</title>
<link>http://www.dslreports.com/forum/remark,20430401</link>
<description><![CDATA[<A HREF="/useremail/u/1070900"><b>nwrickert</b></A> : This is an example of the new phishing that is being aimed mainly at college students.<br><br>Headers:<br><textarea name="code" class="text" cols=50 rows=10>Return-Path: customercare@earlham.edu&#012;Delivery-Date: Sun, 04 May 2008 12:45:51 -0500&#012;Received: from mail.greenbaynet.com (mail.greenbaynet.com &#91;69.217.40.27&#93;)&#012;        by mp.cs.niu.edu (8.14.3/8.14.3) with ESMTP id m44HigJh008149&#012;        for &lt;munged&gt;; Sun, 4 May 2008 12:44:47 -0500 (CDT)&#012;Received: by mail.greenbaynet.com (Postfix, from userid 48)&#012;        id A9684838FC2; Sun,  4 May 2008 12:44:36 -0500 (CDT)&#012;Received: from 196.207.15.201&#012;        (SquirrelMail authenticated user bbwicker)&#012;        by mail.greenbaynet.com with HTTP;&#012;        Sun, 4 May 2008 12:44:36 -0500 (CDT)&#012;Message-ID: &lt;57493.196.207.15.201.1209923076.squirrel@mail.greenbaynet.com&gt;&#012;Date: Sun, 4 May 2008 12:44:36 -0500 (CDT)&#012;Subject: CONFIRM YOUR EARLHAM.EDU EMAIL ACCOUNT IMMEDIATELY!!!&#012;From: "EARLHAM.EDUTEAM" &lt;customercare@earlham.edu&gt;&#012;Reply-To: ccare70@gmail.com&#012;User-Agent: SquirrelMail/1.4.10a-1.fc6&#012;MIME-Version: 1.0&#012;Content-Type: text/plain;charset=iso-8859-1&#012;Content-Transfer-Encoding: 8bit&#012;X-Priority: 3 (Normal)&#012;Importance: Normal&#012;To: undisclosed-recipients:;&#012;</textarea><!--end code block-->Message body:<br>--------------------------------<br><pre><br>Dear EARLHAM.EDU Subscriber,<br> <br>To verify your EARLHAM.EDU account, you must reply to this email<br>immediately and enter your password here (*********)<br> <br>Failure to do this will immediately render your email address deactivated<br>from our database.<br> <br>You can also confirm your email address by logging into your EARLHAM.EDU<br>account at https&#58;//webmail.earlham.edu/squirrel/src/login.php<br> <br>Thank you for using EARLHAM.EDU !<br>THE EARLHAM.EDU TEAM<br></pre><br>--------------------------------<br>The URL in the email is safe, and appears to be the real webmail site at Earlham College.  The "Return-Path:" and "From:" headers also appear to have addresses at Earlham, though I have not tested them.<br><br>The "Reply-To:" header is the suspicious one.  If somebody responds to this by email they will be sending their college network password to the phisher.<br><br>Note:  I am not at Earlham.  I have no idea why I was targetted for this particular message.<br><br>Judging by experience at my own campus, the stolen information is used for spamming.  The spammers use the password to login to the webmail site, then do an automated spam run via that webmail.<br><br>The phish email was sent via an ISP webmail interface, and possibly that was based on an earlier email phish.<br><br><small>--<br>AT&T dsl; Westell 327w modem/router; SuSE 10.1; firefox 2.0.0.14</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20430401</guid>
<pubDate>Sun, 04 May 2008 14:58:48 EDT</pubDate>
</item>

</channel>
</rss>
