[18642] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

Re: US Banks: Training the next generation of phishing victims

daemon@ATHENA.MIT.EDU (Adam Shostack)
Wed Oct 12 11:04:28 2005

X-Original-To: cryptography@metzdowd.com
X-Original-To: cryptography@metzdowd.com
Date: Wed, 12 Oct 2005 10:52:07 -0400
From: Adam Shostack <adam@homeport.org>
To: Peter Gutmann <pgut001@cs.auckland.ac.nz>
Cc: cryptography@metzdowd.com
In-Reply-To: <E1EPc6c-0008TE-00@medusa01.cs.auckland.ac.nz>

On Wed, Oct 12, 2005 at 09:36:58PM +1300, Peter Gutmann wrote:
| 
| Can anyone who knows Javascript better than I do figure out what the mess of
| script on those pages is doing?  It looks like it's taking the username and
| password and posting it to an HTTPS URL, but it's rather spaghetti-ish code so
| it's a bit hard to follow what's going where.

The phishers sure can, but they don't share. 

---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com

home help back first fref pref prev next nref lref last post