CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Anti-Phishing Toolbars
Goto page 1, 2, 3, 4, 5  Next
 
Post new topic   Reply to topic       All -> FavForums -> Phishing, Fraud and Dastardly Deeds [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
Oldfrog

Special Response Team


Joined: Jun 27, 2004
Posts: 8576
Location: Deep in the Heart of Texas
Moderators MVP Premium SRT

PostPosted: Tue Feb 22, 2005 3:17 am    Post subject: Anti-Phishing Toolbars
Reply with quote

There are a variety of products designed to work with your browser to increase online safety by warning you of suspected or known fraudulent or malevolent sites. The following are known to be reputable but provide protection through differing methodologies and databases.

FraudEliminator Toolbar
Company: FraudEliminator, LLC
Home Page: http://www.fraudeliminator.com/
Download: http://www.fraudeliminator.com/download.htm
Methodology: Database driven + ruleset
System Req: Internet Explorer 6.0|FireFox/Windows 95-XP
Review(s): Review Pending
Onsite refs:
License: Freeware

Netcraft Toolbar
Company: Netcraft, Ltd
Home Page: http://toolbar.netcraft.com/
Download: http://toolbar.netcraft.com/help/tutorials/installing.html
Methodology: Database driven + rulebased Risk Rating
System Req: Internet Explorer|FireFox/Windows 2000-XP
Review(s): CastleCops Link/r169-Netcraft_Toolbar.html
Onsite refs: CastleCops Link/t95266-Anti_Phishing_Toolbar_by_Netcraft.html CastleCops Link/article-5643-nested-0-0.html
License: Freeware

PhishGuard
Company: PhishGuard Corp.
Home Page: http://www.phishguard.com/
Download: http://www.phishguard.com/installers/PhishGuard-1-2-186.exe
Methodology: Database driven
System Req: Internet Explorer/Windows 95-XP
Review(s):
Onsite refs:
License: Freeware

SpoofGuard Toolbar
Company: Stanford University Security Lab
Home Page: http://crypto.stanford.edu/SpoofGuard/
Download: http://crypto.stanford.edu/SpoofGuard/download.html
Methodology: Rule set processing
System Req: Internet Explorer
Review(s):
Onsite refs: CastleCops Link/modules.php?name=News&file=article&sid=5408
License: Freeware

SpoofStick Toolbar/button
Company: CoreStreet, Ltd
Home Page: http://www.corestreet.com/spoofstick/index.html
Download: For Firefox, for Internet Explorer
Methodology: Displays only the "most relevant" domain information
System Req: Internet Explorer/Win2000-XP, or Firefox/Windows platform.
Review(s):
Onsite refs: CastleCops Link/t73645-SpoofStick_any_experiences_with_this_anti_spoofing_BHO.html CastleCops Link/t104972-SpoofStick_for_Firefox.html CastleCops Link/t106007-new_spoofstick_out.html
License: Freeware

TrustWatch Toolbar
Company: GeoTrust
Home Page: http://www.trustwatch.com/software/toolbar/tw-ie/index.html
Download: ftp://www.trustwatch.com/software/toolbar/tw-ie/TrustWatch_IEToolbar.exe
Methodology: SSL Certificate Verification + Database
System Req: Internet Explorer 5.01 or higher/Windows Platform
Review(s): Review Pending
Onsite refs: CastleCops Link/t104154-Trustwatch_Toolbar.html
License: Freeware



Last edited by Oldfrog on Thu Jun 02, 2005 1:59 am, edited 2 times in total
Back to top
View users profile Send private message Send email Visit posters website MSN Messenger
pdf41

Cadet
Cadet


Joined: Dec 16, 2004
Posts: 7
Location: USA

PostPosted: Mon Feb 28, 2005 2:29 am    Post subject:
Reply with quote

Hello , just got to this page . Looks like a bit of info.

Thanks again ,

pdf41

Back to top
View users profile Send private message Visit posters website
quietman7

1st Responder Mentor
1st Responder Mentor

Joined: Sep 30, 2004
Posts: 3566
Location: Virginia, USA
1st Responder Mentors 1st Responders MVP Premium Rootkit Experts Security Experts

PostPosted: Mon Feb 28, 2005 2:06 pm    Post subject:
Reply with quote

Oldfrog are your pending a review of Phishguard?
http://www.phishguard.com/

"PhishGuard is a FREE service that detects and rapidly disables Internet "phishing" or "spoofing" attacks designed to steal critical financial data."

It runs as a startup program instead of a toolbar.

image

Back to top
View users profile Send private message
Oldfrog

Special Response Team


Joined: Jun 27, 2004
Posts: 8576
Location: Deep in the Heart of Texas
Moderators MVP Premium SRT

PostPosted: Mon Feb 28, 2005 2:21 pm    Post subject:
Reply with quote

Thanks for the tip, quietman7. We will have to check that out as well.


_________________
image MS MVP Security 2006-2008
Back to top
View users profile Send private message Send email Visit posters website MSN Messenger
JJKebab

Cadet
Cadet


Joined: Mar 06, 2005
Posts: 3
Location: UK

PostPosted: Sun Mar 06, 2005 11:37 am    Post subject:
Reply with quote

Have you tried http://www.site-safe.org

It sits in the system tray and works with multiple browsers (including FireFox!!!)

Back to top
View users profile Send private message
quietman7

1st Responder Mentor
1st Responder Mentor

Joined: Sep 30, 2004
Posts: 3566
Location: Virginia, USA
1st Responder Mentors 1st Responders MVP Premium Rootkit Experts Security Experts

PostPosted: Sun Mar 06, 2005 12:39 pm    Post subject:
Reply with quote

At least they are up front about what they do!

Quote:
PRIVACY NOTICE: We collect anonymous usage information to help improve our service. Each sitesafe application installation creates a unique ID which is used to prevent abuse of the feedback facility. It is NOT used to identify a user or collect sensitive data such as email addresses, credit card details, personal information or surfing habits. We respect users' privacy.


Quote:
The sitesafe application works by checking the web pages you visit in your browser against our constantly updated database of registered websites and displays information valuable to your purchasing decision.

Does this mean they are building their master database only on good sites that register with them instead of reported bad ones? Wonder how many have signed up so far.

Back to top
View users profile Send private message
Oldfrog

Special Response Team


Joined: Jun 27, 2004
Posts: 8576
Location: Deep in the Heart of Texas
Moderators MVP Premium SRT

PostPosted: Sun Mar 06, 2005 1:17 pm    Post subject:
Reply with quote

Quote:
displays information valuable to your purchasing decision.

That makes me very wary. It goes without saying that any of the products that use any type of database will be "phoning home" to do their lookups. Still I don't like their reference to "purchasing decision".


_________________
image MS MVP Security 2006-2008
Back to top
View users profile Send private message Send email Visit posters website MSN Messenger
JJKebab

Cadet
Cadet


Joined: Mar 06, 2005
Posts: 3
Location: UK

PostPosted: Sun Mar 06, 2005 1:21 pm    Post subject:
Reply with quote

It does more than one thing:

1. It shows information about legitimate websites.
2. It identifies fraudulent websites.

It allows users to report fraudulent websites such as scam banks and phishing schemes, as well as post positive and negative feedback on legitimate retailers on line.

It has a "downloads to date" on the homepage.

Oldfrog: How would you keep an anti-phishing app up to date without consulting a central database?

Back to top
View users profile Send private message
Oldfrog

Special Response Team


Joined: Jun 27, 2004
Posts: 8576
Location: Deep in the Heart of Texas
Moderators MVP Premium SRT

PostPosted: Sun Mar 06, 2005 1:40 pm    Post subject:
Reply with quote

Quote:
How would you keep an anti-phishing app up to date without consulting a central database?

Oh, you couldn't. And, as I mentioned in my earlier post, some apps seem to be checking each URL entered or clicked against their own online database in real time.

What I find suspicious in this particular case is the language used. If they had used the phrase "valuable to your online security" instead of "valuable to your purchasing decision" I would have had no problem with it. I also used the terms "wary" and "suspicious" to indicate that I was not sure rather than rejecting it outright. I had similar suspicions about the language used in the EULA of one of the toolbars tested and the company responded to my concern and alleviated my fears. This might very well turn out the same but does need more looking into.


_________________
image MS MVP Security 2006-2008
Back to top
View users profile Send private message Send email Visit posters website MSN Messenger
quietman7

1st Responder Mentor
1st Responder Mentor

Joined: Sep 30, 2004
Posts: 3566
Location: Virginia, USA
1st Responder Mentors 1st Responders MVP Premium Rootkit Experts Security Experts

PostPosted: Sun Mar 06, 2005 1:50 pm    Post subject:
Reply with quote

Quote:
The sitesafe application works by checking the web pages you visit in your browser against our constantly updated database of registered websites

And I would also be weary of their database collection methodology. As I questioned above, are they only relying on "good" websites to register and then depending solely on them as a master database? It appears so by thier ad. And then does this mean "bad" sites and all those unregistered are lumped together as not in their database? As such will their service identify them all as "bad" simply for lack of registering?

Back to top
View users profile Send private message
JJKebab

Cadet
Cadet


Joined: Mar 06, 2005
Posts: 3
Location: UK

PostPosted: Sun Mar 06, 2005 2:07 pm    Post subject:
Reply with quote

They are not just relying on a database of "good" sites. They also have a database of "bad" websites, so bad and not registered are not bundled in together.

As far as their language is concerned, they are targeting two markets with one application: people purchasing from known "good" websites, and people wanting to avoid "bad" websites.

It is therfore not just an anti-phishing tool, but an all round purchasing-online-security application.

You may email them if you wish. I think they do have a direct email on their website.

Back to top
View users profile Send private message
quietman7

1st Responder Mentor
1st Responder Mentor

Joined: Sep 30, 2004
Posts: 3566
Location: Virginia, USA
1st Responder Mentors 1st Responders MVP Premium Rootkit Experts Security Experts

PostPosted: Mon Apr 11, 2005 4:53 pm    Post subject:
Reply with quote

Oldfrog, I finally received this reply from the folks at Phishguard after requesting more info about their program and methodology.

Quote:
Hi. We'll put some information together for you later today. Thanks.

--Steve

I will keep you posted on what they send me.

Back to top
View users profile Send private message
Oldfrog

Special Response Team


Joined: Jun 27, 2004
Posts: 8576
Location: Deep in the Heart of Texas
Moderators MVP Premium SRT

PostPosted: Mon Apr 11, 2005 5:20 pm    Post subject:
Reply with quote

Thanks, QM.

Edit: It will take some experience with the app prior to a review but at least I have it installed, working, and added to the initial post in this topic.

Back to top
View users profile Send private message Send email Visit posters website MSN Messenger
quietman7

1st Responder Mentor
1st Responder Mentor

Joined: Sep 30, 2004
Posts: 3566
Location: Virginia, USA
1st Responder Mentors 1st Responders MVP Premium Rootkit Experts Security Experts

PostPosted: Wed Apr 13, 2005 8:36 am    Post subject:
Reply with quote

Here is the info sent from Steve at Phishguard:

Quote:
PHISHGUARD OVERVIEW
- PhishGuard was launched in September 2004 and is available through many popular download sites.
- PhishGuard is a free service targeting the key chokepoint (URL navigation via Microsoft Internet Explorer browser) to intercept email and
webpage-based phishing/spoofing attacks.
- PhishGuard is a real-time system, with minimal delays between the
discovery of a new scam and the point that subscribers are immunized.
- PhishGuard utilizes an enterprise-class distributed database-driven server architecture that is highly flexible and scalable.
- Co-founders have over fifty years combined experience in development of secure, scalable, high volume database, Internet, and financial ystems.

PHISHGUARD FEATURES
- Windows 98/NT/Me/2000/XP application.
- Desktop client-server architecture. Desktop software consists of multiple
very lightweight clients (one per browser) communicating with one local
server component.
- Zero browsing impact. Threat evaluation does not delay web page loading, or otherwise change end-user perception of browser operation.
- Real-time phishing database updates. Desktop software polls the servers
for incremental changes to the phishing database.
- Phishing attack alert window. Attempts to access or submit data to a known phishing site results in a highly visible warning window. An optional
warning sound is also supported.
- Support for Internet Explorer version 4 or greater.
- Support for additional browsers. Mozilla/Firefox in process; others
planned.
- Automatic software updates. Minimum time from new software releases until widespread use. Zero end-user effort required to stay current. Application is self-healing for missing/corrupt components.
- User submissions of emails. Submission of entire phishing emails from
Outlook 97 through Outlook 2003 and Outlook Express encourages end-users to make submissions without requiring that they visit the phishing site.
- User submissions of URLs. More sophisticated end-users can submit specific URLs for potential inclusion in the phishing database.
- Submission status with scam-specific information. End-users can view the disposition (evaluation by the PhishGuard security team) of previously
submitted emails or URLs.
- End-user registration. Minimal information required to install and run
PhishGuard, and receive phishing database and software updates.

PHISHGUARD SERVERS/INFRASTRUCTURE
- Geographically distributed servers. Diverse network paths between
end-users and core PhishGuard servers ensure high availability.
- Multiple "honey pot" scam sources. Email accounts that have been "seeded" and "incubated" to increase the number of phishing scams received.
- End-user submission network. A growing population of end-users decreases the latency between the introduction of new phishing scams and their detection.
- Security Team. Security analysts are alerted to submitted threats and
rapidly classify sites/URLs. Submitted URLs (or those from "honey pot"
sources) that are determined to be phishing scams are marked for immediate distribution to polling desktop applications.

If you have any further questions, just let us know.

--Steve

I gave Steve the link to our forum and invited him to make additional comments.

Back to top
View users profile Send private message
Ikeb

Special Response Team
Forums Admin

Joined: Apr 20, 2003
Posts: 16536

Forums Admin Moderators MVP Premium SRT Team CC Committee Team F@H

PostPosted: Wed Apr 13, 2005 4:12 pm    Post subject:
Reply with quote

Looks good Steve! So when is a FireFox version going to be available?

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Phishing, Fraud and Dastardly Deeds All times are GMT
Goto page 1, 2, 3, 4, 5  Next
Page 1 of 5

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer