Home / Blogs

Phishing Moving to the Web Channel

Gadi Evron

Today we received one of the first phish attempts to be made as a web spam (comment spam/blog spam) attempt.

I wasn't convinced, and thought that perhaps it was a way to gather and verify RELEVANT online identities. Someone put me straight. It's phishing.

I've often in the past had run-ins with the good folks in the anti virus realm back between 1996 and 2005 who thought Trojan horses and then spyware were not part of their business. Years later the AV business people ruled it is part of their business and ran to catch up. Same with botnets.

I've often had friendly discussions with anti spam folks who said phishing isn't part of the spam problem, or interesting to them. Or that if spam is done on a medium other than email, it obviously isn't spam and needs a new name.

They were wrong. I wasn't very smart in how I approached the subject matter, though.

Today, most anti spam experts consider phishing a priority. Today, Trojan horses, bots and spyware are considered a priority with AV-ers.

Web related spam is still in the terminology and turf fighting stage, but with the increasing ROI and interest combined with the decreased success of other mediums over time, we can see the results for our selves.

Where there is ROI, the Bad Guys adapt. The Good Guys are a step behind regardless of faith, as we are inherently reactive. Still, we should stop being surprised. :)

Today, phishing makes the transition to yet another medium, which is comment spam.

Here is a quote of the phish, as it came in the comment spam earlier today:

"HEllo, i just wanted to say, after 3 years of playing neopets, i have gotten bored with it and have decided to quit. insted of letting my neopoints and items just sit there and rot, i am gonna give them away. in my years of playing i have made about 6 million neopints and have a couple million neopoints worth of items. all you need to do is send me your screenname and password so i can put the stuff in your account and a reason stating why i should give you my hard earned items."

So, we start with neopets and move on to the rest. Welcome phishing to yet another distribution channel, the world of comment spam. 

By Gadi Evron, Security Strategist. Visit the blog maintained by Gadi Evron here.

Related topics: Email, Security, Spam

WEEKLY WRAP — Get CircleID's Weekly Summary Report by Email:

Comments

Re: Phishing Moving to the Web Channel Matthew Elvey  –  Jul 23, 2006 2:18 PM PDT

An anti-abuse system that assigns a reputation to a data source is likely to be usable for any kind of spam, not just email spam.  For example, blacklists and whitelists are are already widely used to combat wiki and blog spam.  Most of what's on wikipedia's Stopping e-mail abuse page is applicable.  I've said for years, it's about internalizing the externalities that spammers exploit.

To post comments, please login or create an account.

Related Blogs

Related News

Topics

Industry Updates – Sponsored Posts

Nominum Launches 1st Comprehensive Mobile Security Solution That Protects Both Network and End User

Frontline and Nominum Deliver Integrated DNS-Based Platform to Enhance Enterprise Security

Nominum Launches Comprehensive Suite of DNS-Based Security Solutions for Russian Service Providers

Nominum Sets New Record for Network Speed and Efficiency

Implementing a Cyber-Security Code of Conduct: Real-Life Lessons From Australia (Webinar)

DDoS Attacks: Top 10 Trends and Truths (Video)

DNS on Defense, DNS on Offense

Managing Outbound Spam: A New DNS-based Approach For Stopping Abuse (Webinar)

DDoS Attacks: Top Trends and Truths (Webinar)

Internet Grows to More Than 225 Million Domain Names in the Fourth Quarter of 2011

Neustar UltraDNS Basic Launches Add-On Services for Website Monitoring and DNS Server Failover

Neustar And Arbor Networks Cloud Signaling Coalition to Stop Evolving DDoS Threat to Data Centers

Nominum Launches World's First Purpose-Built Suite of DNS‐Based Solutions for Mobile Operators

MarkMonitor Fraud Intelligence Report, Q4 2011

MarkMonitor to Exhibit at Internet Tech Policy Exhibition and Reception to be Held on Capitol Hill

Verisign to Award New Infrastructure Research Grants

Nixu SNS 2.5 Series Gives Fresh Views on DNS

Neustar Names Joe Pasqua to Head Neustar Labs

Q3 2011 Fraud Intelligence Report

The Spookiest DDoS Attacks in History

Hot Topics

Minds + Machines

Top-Level Domains

Sponsored by
Minds + Machines
dotMobi

Mobile

Sponsored by
dotMobi
Neustar UltraDNS

DNS

Sponsored by
Neustar UltraDNS
Afilias

DNS Security

Sponsored by
Afilias
Nominum

IPv6

Sponsored by
Nominum
Verisign

Security

Sponsored by
Verisign