[ale] BankOne Spam Scam

Geoffrey esoteric at 3times25.net
Sat Dec 20 08:28:59 EST 2003


Kevin Krumwiede wrote:
> On 19 Dec 2003 11:07:58 -0500
> Jeff Hubbs <hbbs at comcast.net> wrote:
> 
> 
>>Boy, I just got a real convincing-looking e-mail, purportedly from
> 
> 
> I forget where I read this... if it was on this list I apologize for the
> redundance.
> 
> There are fraud emails going around that redirect you to your bank's
> real site while simultaneously popping up a login window from the
> malicious server.  I'm not very familiar with the HTTP protocol, but
> IIRC, it works by embedding HTML in a redirect response.  I'm not sure
> if that constitutes valid HTTP or if it works against all browsers, or
> only "that one"...

Actually, you can do this with a simple javascript.

-- 
Until later, Geoffrey	esoteric at 3times25.net

Building secure systems inspite of Microsoft



More information about the Ale mailing list