Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Teaming Up to Educate and Enable Better Defense Against Phishing
Newest First  |  Oldest First  |  Threaded View
RyanSepe
100%
0%
RyanSepe,
User Rank: Ninja
5/14/2015 | 8:44:08 AM
Re: 1,500 Phish a Month
Ah ok, thanks for clarifying. I would imagine pulling sites is based on a "level of integrity" basis. This makes much more sense, thanks again for elaborating.
RetiredUser
50%
50%
RetiredUser,
User Rank: Ninja
5/14/2015 | 8:39:37 AM
Re: 1,500 Phish a Month
I don't mean to call out a single site, but I happen to like OpenDNS who developed PhishTank.  I think the value in DBs like this is based upon the fact that data does rapidly change for phishing sites.  With a model like PhishTank where you can develop your own anti-phishing apps against an OpenDNS API, you can actually rapidly log and pull sites, cross-reference and protect with fairly high accuracy.  Nothing's perfect, of course.  Like any spam filter your phishing filter will have flaws, but as the DB, the data and the apps developed to use them mature, their usefulness will become much more clear. 
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
5/14/2015 | 8:17:43 AM
Re: 1,500 Phish a Month
I'm interested in this statement, "I like projects like PhishTank where you can report suspected phishermen and slowly build a database of confirmed malicious emailers."


Could you elaborate more to the value this provides? It's very easy to change email addresses so I don't see how the database would be overly effective. The source could easily pivot and keep on going with the recipient database they have. Thanks,
RetiredUser
50%
50%
RetiredUser,
User Rank: Ninja
5/14/2015 | 2:41:02 AM
1,500 Phish a Month
Between all my email accounts, I've estimated that I get roughly 1,500 phish a month.  Mind you, this isn't junk mail - these are emails that contain verbiage and links designed to extract information, to get me to login to a site with a pretense that ideally will convince me to use credentials tied to my finances, etc.  

My way of dealing with this is simple.  I've built a dictionary that is a compilation of keywords and phrases culled from this monthly mountain of madness.  Line up with any number of individual keywords or phrases, and my filters are permanently deleting you, after logging a tick for your status as "another one of those..."

Of course, this is not what I want to do.  I'd rather respond back in kind, perhaps with a bit more venom in the response, and crush them at their own game.  Phish for my banking credentials, get hit with a virus in return.  Of course, the problem is even the most talented of InfoSec pros have a hard time tracing phish back to their home schools...

I like projects like PhishTank where you can report suspected phishermen and slowly build a database of confirmed malicious emailers.  It's not as glamorous as dropping the phisherman by sending back a shark, but it does a public service in pulling together victims of common crimes to aid others avoid being hit.

In time, these databases will be valuable and just having access to them could eventually come at a price.  Jump on them now while most are still free.


COVID-19: Latest Security News & Commentary
Dark Reading Staff 10/27/2020
Chinese Attackers' Favorite Flaws Prove Global Threats, Research Shows
Kelly Sheridan, Staff Editor, Dark Reading,  10/27/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-4782
PUBLISHED: 2020-10-28
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
CVE-2020-15278
PUBLISHED: 2020-10-28
Red Discord Bot before version 3.4.1 has an unauthorized privilege escalation exploit in the Mod module. This exploit allows Discord users with a high privilege level within the guild to bypass hierarchy checks when the application is in a specific condition that is beyond that user's control. By ab...
CVE-2020-16257
PUBLISHED: 2020-10-28
Winston 1.5.4 devices are vulnerable to command injection via the API.
CVE-2020-4767
PUBLISHED: 2020-10-28
IBM Sterling Connect Direct for Microsoft Windows 4.7, 4.8, 6.0, and 6.1 could allow a remote attacker to cause a denial of service, caused by a buffer over-read. Bysending a specially crafted request, the attacker could cause the application to crash. IBM X-Force ID: 188906.
CVE-2020-27974
PUBLISHED: 2020-10-28
NeoPost Mail Accounting Software Pro 5.0.6 allows php/Commun/FUS_SCM_BlockStart.php?code= XSS.