On Mon, Apr 21, 2008 at 10:26:02PM -0500, Jack Pepper wrote: > I saw one of these in a phishing email. I didn't know if it was > supposed to be that way or not, but I was quite curious. Firefox > tries to connect to http://www..google.com . (click it and see)
"Firefox can't find the server at www..google.com." Doesn't seem like a good tactic. > Firefox will also try to connect to http://www.*.google.com . "Firefox can't find the server at www.*.google.com." > So as I pondered it, it seemed plausible that a phisher could create a > zero-length subdomain which would evade scanning by regex processors > (like SA) because it would not parse out as a valid URL. But the > browser will still try to connect. Is this SA evasion? Seems quite > plausible. Doesn't work. I put "http://www..google.com" in both text/plain and text/html, SA finds it and parses out "google.com". SA found "http://www.*.google.com", domain of google.com, as a text/html href. It doesn't find it as a parsed URL. -- Randomly Selected Tagline: Zoidberg: So many memories, so many strange fluids gushing out of patients' bodies....
pgp9640VLETrn.pgp
Description: PGP signature
