back to article Security researchers show how to hook phishers

Security researchers are cooking up tactics for beating phishing fraudsters at their own game. Phishers perennially set up fraudulent sites on servers they have compromised. But due to the sheer volume of sites that need to be set up to perform a successful phishing expedition, fraudsters tend to be sloppy. This allows those …


  1. Craig Edwards

    stupid phishers

    Some phishers are REALLY stupid. For example they will put an ftp link in their phish email which contains the username and password!

    From this its really easy to undo all their work.

  2. marc
    Thumb Up

    If I get sent a pishing link

    instead of typing in my banking username and password, i'll spend a few moments entering random numbers and insults. I hope it makes their life harder.

  3. Funky Dennis


    Just because some gobshite phisher has compromised a server doesn't mean that you can also enter the server (without permission).

    Although this seems more of a shortcoming in the law than anything else.

  4. I. Aproveofitspendingonspecificprojects
    Black Helicopters

    Who me? Prove it.

    Isn't the problem that lamers and people like me don't know enough to secure their PCs?

  5. George

    re: Marc's tactic

    If you do that, you might want to edit the link they send you before entering data. There's usually a code string in there that identifies your e-mail address, and you'll only invite further spam.

    But, if they get a false password from an e-mail they can't identify (or falsely identify) then you've really tossed them under the train. And, I believe many of the sensitve sites practice IP logging and will be more likely to catch on before an intrusion is made.

  6. Kurt Guntheroth

    antagonizing a criminal

    So, 'Marc' recommends hassling phishers. I can only guess that Marc still retains the belief in immortality characteristic of the very young.

    Taunting a person who you already know is (1) a criminal and (2) a hacker is just an invitation for that lamer to pay obsessive attention to giving you the very worst day possible from halfway around the planet. It's as smart as picking a fight in a biker bar. You're gonna get something kicked.

    Lots of people get older without having to learn in this particularly painful way, but some people always volunteer to serve as a warning to the rest of us.

    Of course, it's always possible that 'Marc' is a recruiter, rather than a volunteer...

  7. Jez Caudle

    Ruby Script

    I started writing a Ruby script to fill their database with crap, although the credit Card numbers would have been valid from a check digit point of view.

    I never seem to get anything done without being distracted. Biscuit any one? I'm putting the kettle on ...

  8. Brian Miller

    Finding the Phishers

    Actually, its pretty easy to hunt down phishers. Pop over to and read what they do.

