IE better at stopping phishing than FF
Freeola Internet Get Dotted Domains Chat & Gaming
Freeola Gaming
Freeola Games HomeChat ForumsCheatsWalkthroughsTips & TrophiesReviewsWin Free GamesMyFreeolainvader-bob
£50,000 Domain Giveaway. Get Your FREE .info Domain Name Today!
 
Browse Chat Forums:
 Chat Forums Home View Latest Post Chat Rules Chat Safety & Tips Top Posters
  Games Homepage  Win Free Games  Latest Winners  Hall of Fame  See Who's Online  Update Your Profile
  Free Web Site  Free Domain Hosting  Emergency Internet  Broadband Offers  Broadband Speed Test
 

Did you know...?

Premium Customer Support

HTML & PHP Chat & Help

Visit our Support Pages E-mail a Support Request Contact Us

Migrate to Freeola Broadband - absolutely Free of Charge!

nothing
You Are Here Chat Home (38)   Web Development & Technical Chat  IE better at stoppin...
Just lurking around? Why not join in? You could win free games just by chatting. Choose your Nickname in MyFreeola or Sign Up Here.
 
 
 General Chat     Web and Technical Chat     Games Chat     Game Reviews   
 
IE better at stopping phishing than FF
"Are you sure?"
Moderator
on 07/10/2009 at 12:50:05PM
Edited: 7/10/09 12:59
Total Posts: 1692
Original Post:
Just thought I would test IE and FF using a dodgy phishing email I've come across.

The email was pretending to come from Natwest asking the recipient to login to read their latest online statement.

Looking at the source, the login link was actually:
DODGY PHISHING SITE:
www.justbecomplex.com/catalog/images/GOODS/Login.php 

WARNING: This is a fake site - take care if you visit it !!!

EDIT: I've had to insert a space before 'Login.php' in the address above for Freeola's forum s/w to allow me to post. Shame as I wanted to get the full correct URL in there for anyone that may search for it.


IE7 my normal everyday browser picked this up instantly as a phishing attempt:

"Internet Explorer has determined that this is a reported phishing website. Phishing websites impersonate other sites and attempt to trick you into revealing personal or financial information."

Going to the same address in FireFox (version 3.5.3 with all security options turned on) worryingly displayed the fake page without any warnings!
All the rest of the webpage looks pretty legit.

You don't have to go far to see people rubbishing Microsoft's IE often unfairly - this looks like another reason not to knock them to me!

Perhaps as the IE userbase is so big there is more chance that dodgy sites get reported.
NB. I noticed that removing the www allows IE to also display the page - so I using the phishing controls to report that version of the URL!

Also you would think Natwest in this case would stop third-party webistes 'hotlinking' to their official graphics to make things a little harder to do!


Keep 'em peeled...!
Hmmm...
View More Threads Post a Reply  
Displaying 1 - 15 of 15 Replies:
Garin
"Devil in disguise"
Regular
on 07/10/2009 at 3:01:23PM
Total Posts: 2074
:D
Hmmm...
"Are you sure?"
Moderator
on 07/10/2009 at 2:58:25PM
Total Posts: 1692
That's it I'm leaving this thread!
Hmmm...
Warhunt
"Life int a DPS race"
Staff Moderator
Send a message
on 07/10/2009 at 2:54:43PM
Total Posts: 1485
Was that needed? Stop being jealous you!
Garin
"Devil in disguise"
Regular
on 07/10/2009 at 2:46:54PM
Total Posts: 2074
Definite sexual tension between you two.
Warhunt
"Life int a DPS race"
Staff Moderator
Send a message
on 07/10/2009 at 2:40:15PM
Edited: 7/10/09 14:41
Total Posts: 1485
It's ok I didn't misunderstand. Besides I'm sure we have bantered enough to know a wee bit by now ;)

EDIT: Well i did misunderstand but I mean I didn't think anything of it.
Hmmm...
"Are you sure?"
Moderator
on 07/10/2009 at 2:33:22PM
Edited: 7/10/09 14:33
Total Posts: 1692
Warhunt - we often seem to misread each others posts!

When I said "Don't bother Warhunt!" - I was replying to ButchML.
So that was a 'don't disturb him' type comment.

I'm not sure you read it like that - sorry for any confusion!
Hmmm...
Warhunt
"Life int a DPS race"
Staff Moderator
Send a message
on 07/10/2009 at 2:16:55PM
Edited: 7/10/09 14:17
Total Posts: 1485
Wasn't going to.

I don't know why his one wasn't official anyway :D Maybe he has realised his place?
Hmmm...
"Are you sure?"
Moderator
on 07/10/2009 at 2:05:29PM
Total Posts: 1692
Thanks for that.
Please don't bother Warhunt!








Hmmm...
ButchML
"AYBABTU"
Staff Moderator
Send a message
on 07/10/2009 at 1:34:00PM
Total Posts: 862
Hmmm... wrote:
> NB. Thanks for fixing the 50 chars limit on the URL.


Not a problem.

> Any chance you could either increase this permanently or trust
> us old timers?


Unlikely, and no as I had to edit the post manually using our internal systems. Without you physically being here on our network with a login that has authorisation over the forums, it can't be done.

> Do you know why you have a limit? I can't see it's much of an
> abuse?


I assume that this limit is imposed by us to prevent people spamming random button combinations, filling the forums with horrible ugly links and not using the helpfully provided bbcode (listed below) and, probably most importantly and likely, each chat post has a width limit. Allowing character strings over 50 letters in size would result in the chat posts becoming long and stretched out ruining the page.

If you want an official answer I'll make Warhunt aware of this and try to get something out of him on it.
Garin
"Devil in disguise"
Regular
on 07/10/2009 at 1:32:15PM
Total Posts: 2074
I suspect you're right in that IE's larger userbase simply means they get reports quicker.  You could also speculate that Firefox's userbase is more web savy and thus less likely to be encountering phishing sites.
Hmmm...
"Are you sure?"
Moderator
on 07/10/2009 at 1:19:33PM
Edited: 7/10/09 13:30
Total Posts: 1692
I didn't know that - but where do Google get them from...?


EDIT:
http://code.google.com/apis/safebrowsing/firefox3_privacy.html
Garin
"Devil in disguise"
Regular
on 07/10/2009 at 1:17:57PM
Total Posts: 2074
Just to point out, FF gets its phishing data from Google.
Hmmm...
"Are you sure?"
Moderator
on 07/10/2009 at 1:16:20PM
Total Posts: 1692
FF is blocking/warning me now as well!

This email is doing the rounds today so it looks like FF must be getting phishing reports in and have taken some action.

Either that or they read the Freeola Chat Forums!


NB. Thanks for fixing the 50 chars limit on the URL.
Any chance you could either increase this permanently or trust us old timers?

Do you know why you have a limit? I can't see it's much of an abuse?



Hmmm...
ButchML
"AYBABTU"
Staff Moderator
Send a message
on 07/10/2009 at 1:04:51PM
Total Posts: 862
Hmmm... wrote:
> EDIT: I've had to insert a space before 'Login.php' in the
> address above for Freeola's forum s/w to allow me to post. Shame
> as I wanted to get the full correct URL in there for anyone that
> may search for it.

Fixed :)
motomoto
"The Killer Techie"
Staff Moderator
Send a message
on 07/10/2009 at 1:02:32PM
Edited: 7/10/09 13:05
Total Posts: 254
Just checked my own Firefox installation and a colleagues and we both get thefollowing message:

'Reported Web Forgery!

This web site at www.justbecomplex.com has been reported as a web forgery and has been blocked based on your security preferences.

Web forgeries are designed to trick you into revealing personal or financial information by imitating sources you may trust.

Entering any information on this web page may result in identity theft or other fraud.'

To view the page, you have to allow access. Firefox 3.5.3, this said, I do have some plugins installed...
Hmmm...
"Are you sure?"
Moderator
on 07/10/2009 at 12:50:05PM
Edited: 7/10/09 12:59
Total Posts: 1692
Just thought I would test IE and FF using a dodgy phishing email I've come across.

The email was pretending to come from Natwest asking the recipient to login to read their latest online statement.

Looking at the source, the login link was actually:
DODGY PHISHING SITE:
www.justbecomplex.com/catalog/images/GOODS/Login.php 

WARNING: This is a fake site - take care if you visit it !!!

EDIT: I've had to insert a space before 'Login.php' in the address above for Freeola's forum s/w to allow me to post. Shame as I wanted to get the full correct URL in there for anyone that may search for it.


IE7 my normal everyday browser picked this up instantly as a phishing attempt:

"Internet Explorer has determined that this is a reported phishing website. Phishing websites impersonate other sites and attempt to trick you into revealing personal or financial information."

Going to the same address in FireFox (version 3.5.3 with all security options turned on) worryingly displayed the fake page without any warnings!
All the rest of the webpage looks pretty legit.

You don't have to go far to see people rubbishing Microsoft's IE often unfairly - this looks like another reason not to knock them to me!

Perhaps as the IE userbase is so big there is more chance that dodgy sites get reported.
NB. I noticed that removing the www allows IE to also display the page - so I using the phishing controls to report that version of the URL!

Also you would think Natwest in this case would stop third-party webistes 'hotlinking' to their official graphics to make things a little harder to do!


Keep 'em peeled...!
Hmmm...
 
Your Details MyFreeola Internet Settings Control Panel Your Details
Login or create a free account.
Forgotten your password?
Free Account Sign-Up
 
Your Details
Search
 
 
 
Fantastic FREE Unlimited Services for every freeola internet customer in the UK!
Register Domain Names. Buy from £2.99
e.g. yourcompany.com
or just yourcompany.
MORE ABOUT DOMAIN NAMES