CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

In Praise of Phish Fighters: CastleCops/Washington Post
Goto page Previous  1, 2
 
Post new topic   Reply to topic       All -> FavForums -> Happy Events [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
Tim_aka_Red_Barren
Currently banned

Premium Member


Joined: Aug 28, 2005
Posts: 1046

Blue Security Premium

PostPosted: Tue Feb 13, 2007 1:58 am    Post subject:
Reply with quote

Save_the_Gnome wrote:
Hey, Ikeb & Paul! (I doubt that Red is constructively involved here.)

I had set that FifthThird Bank phishing on my block/bounce/delete actions. One problem is that they come everyday; do you want me to report each one?

Another problem is that I can't copy the text.

I did use Frontpage, and came up with a totally different message:

<html>

<head>
<meta name="GENERATOR" content="Microsoft FrontPage 5.0">
<meta name="ProgId" content="FrontPage.Editor.Document">
<meta http-equiv="Content-Type" content="text/html; charset=windows-1252">
<title>New Page 1</title>
</head>

<body>

<p>
<a title="http://www.53.com.bankingportal.id43613720638.ezbsite.info/conf" href="http://www.53.com.bankingportal.id43613720638.ezbsite.info/conf">
<img title="http://www.53.com.bankingportal.id43613720638.ezbsite.info/conf" src="file:///C:/Documents%20and%20Settings/Ann/Local%20Settings/Application%20Data/IM/Runtime/Message/{921466CA-A25B-416A-85A6-F6890EE069D4}/Show/bauxite1.gif" border="0" width="608" height="386"></a>
</p>
<p>&nbsp;</p>
<p><font color="#fffff2">He examined it and was not much surprised to find it
was envy. conservation corruption Morphose and Morphose Complex.</font></p>
<p><font color="#fffff4">Two more of those on top of the ones you took half an
hour ago may drop you into a coma and then kill you, he thought, and a second
voice answered at once: Fine with me. He had never realized how many n's there
were in an average line of type. &quot;YOU CAN'T BURN MISERY, YOU COCKADOODIE BRAT,
YOU CAN'T BURN MISERY! &quot;Now Paul,;she said, in the prim voice he knew so well.
&quot;&quot;What was it about? Writing may be masturbatory, but God forbid it should be an
act off autocannibalism. I doan know if it be true, but the Bourkas, dey say
even when you get behin;her, the goddess, she seem to be lookin;at you.
bookplate</font></p>
<p><br>
<br>

What should I do?


Pray I don't read this? That web site has been shut down, at least that's the way it is now. Tomorrow the criminal will have a different site.

I'd listen to Paul and Robin. Not so much Ike. Wink Hoov for sure. Smile

Back to top
View users profile Send private message
Ikeb

Special Response Team
Forums Admin

Joined: Apr 20, 2003
Posts: 16536

Forums Admin Moderators MVP Premium SRT Team CC Committee Team F@H

PostPosted: Tue Feb 13, 2007 4:17 am    Post subject:
Reply with quote

Save_the_Gnome wrote:
Hey, Ikeb & Paul! (I doubt that Red is constructively involved here.)

I had set that FifthThird Bank phishing on my block/bounce/delete actions. One problem is that they come everyday; do you want me to report each one?

Another problem is that I can't copy the text.

I did use Frontpage, and came up with a totally different message:

<html>

<head>
<meta name="GENERATOR" content="Microsoft FrontPage 5.0">
<meta name="ProgId" content="FrontPage.Editor.Document">
<meta http-equiv="Content-Type" content="text/html; charset=windows-1252">
<title>New Page 1</title>
</head>

<body>

<p>
<a title="http://www.53.com.bankingportal.id43613720638.ezbsite.info/conf" href="http://www.53.com.bankingportal.id43613720638.ezbsite.info/conf">
<img title="http://www.53.com.bankingportal.id43613720638.ezbsite.info/conf" src="file:///C:/Documents%20and%20Settings/Ann/Local%20Settings/Application%20Data/IM/Runtime/Message/{921466CA-A25B-416A-85A6-F6890EE069D4}/Show/bauxite1.gif" border="0" width="608" height="386"></a>
</p>
<p>&nbsp;</p>
<p><font color="#fffff2">He examined it and was not much surprised to find it
was envy. conservation corruption Morphose and Morphose Complex.</font></p>
<p><font color="#fffff4">Two more of those on top of the ones you took half an
hour ago may drop you into a coma and then kill you, he thought, and a second
voice answered at once: Fine with me. He had never realized how many n's there
were in an average line of type. &quot;YOU CAN'T BURN MISERY, YOU COCKADOODIE BRAT,
YOU CAN'T BURN MISERY! &quot;Now Paul,;she said, in the prim voice he knew so well.
&quot;&quot;What was it about? Writing may be masturbatory, but God forbid it should be an
act off autocannibalism. I doan know if it be true, but the Bourkas, dey say
even when you get behin;her, the goddess, she seem to be lookin;at you.
bookplate</font></p>
<p><br>
<br>

What should I do?

Actually what you captured above could be pasted to PIRT. Just FYI, the picture you mention (green) is buried in the link to the phish site (blue). I marked the actual hyperlink that would take you to the phish site (constructively marked in red ... no relationship to ol' baldy of course ... he's useless in this context Wink ) Note that if you break down the URL, it turns out that the site is domain ezbsite.info. The PIRT handlers trace such sites down as to who owns it and who hosts it with the aim of getting it shut down.

Back to top
View users profile Send private message
Save_the_Gnome

Captain
Captain
Premium Member

Joined: Dec 17, 2006
Posts: 435

Premium

PostPosted: Tue Feb 13, 2007 4:22 am    Post subject:
Reply with quote

Tim_aka_Red_Barren wrote:


Pray I don't read this? That web site has been shut down, at least that's the way it is now. Tomorrow the criminal will have a different site.



I'd listen to Paul and Robin. Not so much Ike. Wink Hoov for sure. Smile


Ike +Robin?

If the site is shut down, why do I continue receiving messages everyday?

I still have no idea what to do with Pictures in the phish file.


I'm sorry, Red, but I feel that I'm back to square one.


_________________
Limitations live only in our minds.

But if we use our imaginations,

Our possibilities become limitless.

- Jamie Paolinetti
Back to top
View users profile Send private message Visit posters website Yahoo Messenger
Tim_aka_Red_Barren
Currently banned

Premium Member


Joined: Aug 28, 2005
Posts: 1046

Blue Security Premium

PostPosted: Tue Feb 13, 2007 1:53 pm    Post subject:
Reply with quote

Ikeb wrote:
Tim_aka_Red_Barren wrote:
(seriously, I don't mind you calling me that. It's better than what a lot of other people call me. Wink)

Shocked ooh .... pray tell, what would that be? Curious minds need to know. Wink


If you must know, I was once walking from another building back to my office. While I was crossing the parking lot, someone yelled, "Hey, a@@hole!" I turned to see who it was and it turned out to be the president of the college.

I don't mind ol' baldy at all. Razz

Back to top
View users profile Send private message
Tim_aka_Red_Barren
Currently banned

Premium Member


Joined: Aug 28, 2005
Posts: 1046

Blue Security Premium

PostPosted: Tue Feb 13, 2007 1:56 pm    Post subject:
Reply with quote

Ikeb wrote:
(constructively marked in red ... no relationship to ol' baldy of course ... he's useless in this context Wink )


Just out of curiosity, is there a reason she can't just forward it to pirt@castlecops.com, or aren't they using that anymore?

Back to top
View users profile Send private message
Ikeb

Special Response Team
Forums Admin

Joined: Apr 20, 2003
Posts: 16536

Forums Admin Moderators MVP Premium SRT Team CC Committee Team F@H

PostPosted: Tue Feb 13, 2007 3:34 pm    Post subject:
Reply with quote

Tim_aka_Red_Barren wrote:
If you must know, I was once walking from another building back to my office. While I was crossing the parking lot, someone yelled, "Hey, a@@hole!" I turned to see who it was and it turned out to be the president of the college.

Shocked I'm shocked! Totally undeserved I'm sure. Razz

As to whether pirt AT castlecops DOT com still works; indeed it works like a charm. I send any phish that ends up in my inbox there.

Back to top
View users profile Send private message
Save_the_Gnome

Captain
Captain
Premium Member

Joined: Dec 17, 2006
Posts: 435

Premium

PostPosted: Tue Feb 13, 2007 4:51 pm    Post subject:
Reply with quote

Tim_aka_Red_Barren wrote:


Just out of curiosity, is there a reason she can't just forward it to pirt@castlecops.com, or aren't they using that anymore?


Talk about shock, you were constructive! blink


_________________
Limitations live only in our minds.

But if we use our imaginations,

Our possibilities become limitless.

- Jamie Paolinetti
Back to top
View users profile Send private message Visit posters website Yahoo Messenger
Tim_aka_Red_Barren
Currently banned

Premium Member


Joined: Aug 28, 2005
Posts: 1046

Blue Security Premium

PostPosted: Tue Feb 13, 2007 5:30 pm    Post subject:
Reply with quote

Save_the_Gnome wrote:
Talk about shock, you were constructive! blink


I'm surprised ol' bonehead didn't think of it. Razz weee

Back to top
View users profile Send private message
Tim_aka_Red_Barren
Currently banned

Premium Member


Joined: Aug 28, 2005
Posts: 1046

Blue Security Premium

PostPosted: Tue Feb 13, 2007 5:34 pm    Post subject:
Reply with quote

Ikeb wrote:
Shocked I'm shocked! Totally undeserved I'm sure. Razz


Well, not totally. He has this annoying habit of asking "What do you know?" One time I said, "Well, I know you have tickets to tonight's Bills preseason game."

Yup, he gave me the tickets. Club seats. Luxury. Very Happy

Back to top
View users profile Send private message
Save_the_Gnome

Captain
Captain
Premium Member

Joined: Dec 17, 2006
Posts: 435

Premium

PostPosted: Tue Feb 13, 2007 5:49 pm    Post subject:
Reply with quote

Tim_aka_Red_Barren wrote:

Well, not totally. He has this annoying habit of asking "What do you know?" One time I said, "Well, I know you have tickets to tonight's Bills preseason game."

Yup, he gave me the tickets. Club seats. Luxury. Very Happy


I guess you're being a cheeky bugger paid off this time. clapping


_________________
Limitations live only in our minds.

But if we use our imaginations,

Our possibilities become limitless.

- Jamie Paolinetti
Back to top
View users profile Send private message Visit posters website Yahoo Messenger
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Happy Events All times are GMT
Goto page Previous  1, 2
Page 2 of 2

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer