On last.fm: Radiohead - Listen free and discover!
BNET Business Network:
BNET
TechRepublic
ZDNet

October 29th, 2009

Phishing experiment sneaks through all anti-spam filters

Posted by Dancho Danchev @ 2:16 pm

Categories: Botnets, Browsers, Hackers, Phishing, Spam and Phishing

Tags: Anti-spam, LinkedIn, E-mail, Phishing, Cyberthreats, Spam, Viruses And Worms, Security, Spam And Phishing, Dancho Danchev

A recently conducted ethical phishing (New study details the dynamics of successful phishing) experiment impersonating LinkedIn by mailing invitations coming from Bill Gates, has achieved a 100% success rate in bypassing the anti-spam filters it was tested against.

The experiment emphasizes on how small-scale spear phishing campaigns are capable of bypassing anti-spam filters, and once again proves that users continue interacting with phishing emails.

More info on the methodology used:

“This scenario was an invitation from Linkedin, posing as an invitation from Bill Gates to join his network. Linkedin was selected due to availability, and the fact that it is a social network recognized by most executives. This selection of Linkedin was also based on the fact that linked-in email should be already identified by most existing email system(s), and this may have helped delivery through into the mailbox. The phishing link can be identified in the HTML source code below.

The Phishing site was based on the Linkedin sign in page. The form action was changed so that the user would be redirected to a subsequent page on our site. No usernames or passwords were collected during this assessment. All targeted users were contacted before the phishing email was sent, and were expecting a Linkedin invitation from Bill Gates.”

A similar study was conducted by ethical phishing vendor PhishMe.com in March this year, pointing out that based on the 32 phishing scenarios tested against 69,000 employees, people are less cautious when clicking on active links in emails than when they are requested for sensitive data. This behavior is not surprisingly cited by PhishCamp as a possible opportunity for the introducing of blended threats, similar to known cases where phishing and scareware sites were also serving client-side exploits.

With the average price for a thousand active Gmail, Yahoo Mail and Hotmail accounts decreasing due to the economies of scale achieved by the vendors of CAPTCHA-solving services, and the numerous tools available at the spammer’s disposal to take advantage of these accounts, in the long-term all spammers will start abusing the already established DomainKeys trust among the most popular free email service providers.

What’s the success rate of spam and phishing emails hitting your inbox? What about your corporate email? Also, do you believe that ethical phishing is most constructive way of building awareness on phishing attacks, or do you think that it drives innovation in the wrong direction by attempting to gather click-through metrics instead of advising users to avoid interacting with such emails in general?

TalkBack.

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?

  • Talkback
  • Most Recent of 123 Talkback(s)
@ waleroy: i have a solution for the problem of spam mails
I agree with you in nearly every point. In the past, approximately 8 of 10 mails, delivered to my bussines email-account, were just spam ? it was really annoying. btw .. I' ve never cared about some s... (Read the rest)
Posted by: tom_001 Posted on: 11/30/09 You are currently: a Guest | | Terms of Use
Not mine.  Grayson Peddie | 10/29/09
Does deleting something or marking it as spam count as "interaction"?  AzuMao | 10/29/09
Nope.  Grayson Peddie | 10/29/09
yeah ... and mine isn't known by them either ...  TG2 | 10/30/09
Two words: Private e-mail.  Grayson Peddie | 10/30/09
Two words ain't enough..  JCitizen | 10/30/09
I don't fall for phishing scams.  Grayson Peddie | 11/01/09
Just keep in mind..  AzuMao | 11/01/09
White Listing doesn't work for salesmen  codeguy007 | 11/02/09
Hotmail & spam  john.foggitt@... | 11/05/09
I make sure...  JCitizen | 11/05/09
If you're emails are important to you at all..  AzuMao | 11/06/09
I can't believe how awesome you are  tikigawd | 10/30/09
And stupid  cne@... | 11/02/09
I can;t believe it either!  AzuMao | 11/02/09
Barracuda?  dgrainge | 10/31/09
WOW! How shocking.  Horus418 | 11/02/09
Have fun with that!! Grayson  Horus418 | 11/02/09
and what egzactly did that experiment achieve?  ljenux-23043766007667558234416105604265 | 10/30/09
What indeed?  dmgroves | 10/30/09
"Throw down" email addresses are usefull ....  kd5auq | 10/30/09
USPS & junk snail mail  TG2 | 10/30/09
USPS is broke  dano-z | 10/30/09
Let me make sure I understood that right;  AzuMao | 11/02/09
RE: Let me make sure I understood that right  HistoryPhil | 11/04/09
Who, exactly, are they selling lists of our e-mail addresses to?  AzuMao | 11/04/09
unwanted mail  herblock | 11/02/09
That's very strange indeed then.  AzuMao | 11/02/09
Multiple email addresses  john.foggitt@... | 11/05/09
RE: Phishing experiment sneaks through all anti-spam filters  cne@... | 10/30/09
prewarned  bobzaguy | 10/30/09
I was thinking the same thing...A LOT of malware  ItsTheBottomLine | 10/30/09
The clue is in the title.  teuchter | 10/30/09
Thank you @teuchter - glad not to be the only one  TG2 | 10/30/09
And it's not stupidity  compudog | 11/02/09
If they were smart, they would learn how to safely use something BEFORE  AzuMao | 11/02/09
consider-  John N. | 11/03/09
And it's not stupidity???  John N. | 11/03/09
Touchay  Horus418 | 11/02/09
Amen  John N. | 11/04/09
So...  The 'G-Man.' | 10/30/09
Education  davidr69 | 10/30/09
Why create devices and rules? Simple ...  TG2 | 10/30/09
Education  compudog | 11/02/09
I wish that was true.  Horus418 | 11/02/09
RE: Phishing experiment sneaks through all anti-spam filters  william_tr | 10/30/09
Bogus test setup  RodPayne | 10/30/09
Just a little Novocaine  kdjkdj@... | 10/30/09
testing FILTERS - FILTERS - FILTERS  tangentjohn@... | 10/30/09
The test was of filters not intelligence.  clareJ | 10/30/09
RE: Phishing experiment sneaks through all anti-spam filters  clap_clap@... | 10/30/09
FROM e mail address  bfilipiak@... | 10/30/09
Laws  Narg | 10/30/09
RE: laws  bfilipiak@... | 10/30/09
Dying is too good for them...  phatkat | 10/30/09
Yes; anyone who falls for these things should just die.  AzuMao | 10/30/09
Geeze Az...  JCitizen | 11/05/09
I'm not.  AzuMao | 11/06/09
Well, the death camps were full of the retarded...  JCitizen | 11/06/09
Laws  compudog | 11/02/09
What a ridiculous article.  johnengel | 10/30/09
RE: Phishing experiment sneaks through all anti-spam filters  shanedr | 10/30/09
Great idea!  compudog | 11/02/09
Weren't those "older people" around since before the Internet even existed?  AzuMao | 11/02/09
RE: Phishing experiment sneaks through all anti-spam filters  jimnall | 10/30/09
Huhhhh...??????  thebeans | 10/30/09
How about Steve Jobs?  icreate@... | 10/30/09
jobs? never  gabrielbear@... | 10/30/09
Hey, they wanted to invite Ballmer instead of Jobs  Wintel BSOD | 10/30/09
They can have them both.  AzuMao | 11/04/09
RE: Phishing experiment sneaks through all anti-spam filters  mike@... | 10/30/09
RE: Phishing experiment sneaks through all anti-spam filters  surfyngirl | 10/30/09
I don't know if you were kidding or not,  compudog | 11/02/09
I Do Not Believe The Test Results  NameRedacted | 10/30/09
RE: Phishing experiment sneaks through all anti-spam filters  gabrielbear@... | 10/30/09
Great "algorhythm"  compudog | 11/02/09
Algorhythm...  JCitizen | 11/02/09
Brilliant.  Horus418 | 11/02/09
Phishing Experiment.  Jaytmoon | 10/30/09
RE: Phishing experiment sneaks through all anti-spam filters  jonesgang | 10/31/09
Re: Phishing experiment  flboffin | 10/31/09
how likely is this?  dgrainge | 10/31/09
Sheesh...  DNSB | 10/31/09
Anyone want to read the frickin article before replying?  AzuMao | 11/01/09
Did you?  n.ang | 11/02/09
Do YOU want to read the article before embarrassing yourself?  compudog | 11/02/09
Just in case  compudog | 11/02/09
You must be replying to the wrong article.  AzuMao | 11/02/09
It's like talking to a drunk.  compudog | 11/02/09
Right..  AzuMao | 11/02/09
Of course the phishing experiment got thru...  cdwillems | 11/02/09
It won't sneak through MailVICE  docjackson@... | 11/02/09
Chrome OS  cpt_slog@... | 11/02/09
Not helpful to use the word "immune"  compudog | 11/02/09
And your reasoning for that statement is.. what, exactly?  AzuMao | 11/02/09
My reasoning is simple:  compudog | 11/02/09
Repeating your conclusion is not an alternative to real premises.  AzuMao | 11/02/09
Personally, I think this kind of stuff should be implemented by ISPs  AzuMao | 11/02/09
spam  herblock | 11/02/09
Entire Study is a Phish  NameRedacted | 11/02/09
Email in crisis.  cpt_slog@... | 11/02/09
FUD Panic  NameRedacted | 11/02/09
Gabrielbear answered your question!  compudog | 11/02/09
RE: Phishing experiment sneaks through all anti-spam filters  cowen80194 | 11/02/09
No one is 100% immune to being decieved  pwood57@... | 11/02/09
What you described is called "pharming", and is much more advanced than  AzuMao | 11/02/09
pharming  pwood57@... | 11/02/09
RE: Phishing experiment sneaks through all anti-spam filters  cowen80194 | 11/02/09
Agreed.  AzuMao | 11/02/09
Totally stunned.  Horus418 | 11/02/09
Pretty much, ya.  AzuMao | 11/02/09
RE: Phishing experiment sneaks through all anti-spam filters  codeguy007 | 11/02/09
Not an idiot for getting caught.  AzuMao | 11/04/09
RE: Phishing experiment sneaks through all anti-spam filters  vilppuu@... | 11/03/09
No  AzuMao | 11/03/09
RE: Phishing experiment sneaks through all anti-spam filters  waleroy | 11/03/09
@ waleroy: i have a solution for the problem of spam mails  tom_001 | 11/30/09
Err..  John N. | 11/03/09
Illegal, exploitative and aggressive behaviour saps our resources  ozzie_tech | 11/03/09
That's what makes us human though.  AzuMao | 11/03/09
LOL - sounds like ad targeting SPAMmers  wellduh | 11/05/09
Solving active links exploit - easy  wellduh | 11/05/09
Yes, it's that easy.  AzuMao | 11/06/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here