On Mon, Apr 21, 2008 at 10:26:02PM -0500, Jack Pepper wrote:
> I saw one of these in a phishing email.  I didn't know if it was  
> supposed to be that way or not, but I was quite curious.  Firefox  
> tries to connect to http://www..google.com . (click it and see)

"Firefox can't find the server at www..google.com."

Doesn't seem like a good tactic.

> Firefox will also try to connect to http://www.*.google.com .

"Firefox can't find the server at www.*.google.com."

> So as I pondered it, it seemed plausible that a phisher could create a  
> zero-length subdomain which would evade scanning by regex processors  
> (like SA) because it would not parse out as a valid URL.  But the  
> browser will still try to connect.  Is this SA evasion?  Seems quite  
> plausible.

Doesn't work.  I put "http://www..google.com"; in both text/plain and
text/html, SA finds it and parses out "google.com".

SA found "http://www.*.google.com";, domain of google.com, as a text/html href.
It doesn't find it as a parsed URL.

-- 
Randomly Selected Tagline:
 Zoidberg: So many memories, so many strange fluids gushing out 
    of patients' bodies....

Attachment: pgp9640VLETrn.pgp
Description: PGP signature

Reply via email to