 garys_2k
join:2004-05-07 Farmington, MI
·Vonage
edit: July 5th, @10:43PM
| Phishtracker Manual Input Error
I just tried to use the manual form and got this:
HTTP/1.1 200 OK Date: Sun, 06 Jul 2008 02:36:47 GMT Server: Apache/1.3.39 (Unix) mod_perl/1.30 Location: »i.dslr.net/errpage.html Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=iso-8859-1 OK The document has moved here.
"here" contains a link to »i.dslr.net/errpage.html, showing some sort of error was received.
The phish is live and active, here's the code FYI:
From service@columbusbankandtrust.com Sat Jul 5 05:22:46 2008 Return-Path: Authentication-Results: mta501.mail.mud.yahoo.com from=; domainkeys=neutral (no sig) Received: from 210.75.221.246 (HELO gateway.bda.gov.cn) (210.75.221.246) by mta501.mail.mud.yahoo.com with SMTP; Sat, 05 Jul 2008 18:51:05 -0700 Received: from adsl-068-213-098-155.sip.jan.bellsouth.net (HELO user) (info@68.213.98.155) by localhost with SMTP; 5 Jul 2008 12:14:43 -0000 Reply-To: From: "service@columbusbankandtrust.com" Subject: Columbus Bank and Trust Company Survey program Date: Sat, 5 Jul 2008 07:22:46 -0500 MIME-Version: 1.0 Content-Type: text/html; charset="Windows-1251" Content-Transfer-Encoding: 7bit Content-Length: 1093 Greetings from Columbus Bank and Trust Company
Welcome to the Columbus Bank and Trust Company Survey program, the first and largest loyalty program in the world! We are proud to inform you that today. 05 July 2008 Columbus Bank and Trust Company launch a new reward program. Please take the 5 questions survey. For your effort you will be rewarded with $50
Please go to Columbus Bank and Trust Company Survey program and follow the steps.
Thank you very much for your help and your patient and hope you will enjoy the Columbus Bank and Trust Company reward program in the future
Sincerely, Columbus Bank and Trust Company Reward Department Please do not reply to this auto-answer message
The phish contained this phony uri for Columbus: hxxp://bongsan.kehc.org/bbs/images/read.html
That redirects to: hxxp://www.playwithroy.com/xoops/uploads/wordpress/www.columbusbankandtrust.com.htm
Anyhoo, let me know what I need to do differently. I copied/pasted the complete header and phish text, and inserted the uri's into the text (yahoo mail doesn't let you view the message text itself, just the html-ized version of it).
Edit to disable the links, above. |