CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 937
Comments: 25
block bottom
spacer spacer

Anti-Phishing Toolbars
Goto page Previous  1, 2, 3, 4, 5  Next
 
Post new topic   Reply to topic       All -> FavForums -> Phishing, Fraud and Dastardly Deeds [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
Oldfrog

Special Response Team


Joined: Jun 27, 2004
Posts: 8575
Location: Deep in the Heart of Texas
Moderators MVP Premium SRT

PostPosted: Wed Oct 12, 2005 11:29 pm    Post subject:
Reply with quote

In other toolbar news, I installed version 2.4.0 of FraudEliminator today. Despite the success enjoyed by others I was never able to get my previous version to work with Firefox and eventually had to uninstall it due to problems with that browser.

**Note: I am not suggesting that the toolbar was the cause of the problems only that they were alleviated by removing it. I really suspect an extension conflict between it and an existing extension.**

The new version installed easily and so far seems to be working as advertised. I was disappointed, however, to learn that the free version only receives fraud updates monthly.


_________________
image MS MVP Security 2006-2008
Back to top
View users profile Send private message Send email Visit posters website MSN Messenger
seafsee

General
General
Premium Member

Joined: Apr 02, 2004
Posts: 4906

Premium

PostPosted: Sat Nov 19, 2005 9:19 am    Post subject:
Reply with quote

Oldfrog wrote:
The search function is powered by AskJeeves
DreamingFox wrote:
Why would they use a disreputable search engine? What am I missing here?
I must have missed something during my prolonged absence from the net.

I do tend to have a certain distrust of search engines myself.

NetZero internet which we are currently using here, wants to change the default search page every time we sign on and doesn't take no for an answer. The ironic part is that nwannave already uses Yahoo search for her default, and NetZero search is now powered by Yahoo search.

Didn't I read that AskJeeves was taken over or bought out by someone else?

Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger MSN Messenger
Oldfrog

Special Response Team


Joined: Jun 27, 2004
Posts: 8575
Location: Deep in the Heart of Texas
Moderators MVP Premium SRT

PostPosted: Sat Nov 19, 2005 10:10 pm    Post subject:
Reply with quote

My disappointment stems from the fact that I think there are better SEs out there that would have made better choices. DFs comment probably stems from the fact that AskJeeves was involved in the MyWay search bar fiasco at Dell as well as several other questionable tactics.


_________________
image MS MVP Security 2006-2008
Back to top
View users profile Send private message Send email Visit posters website MSN Messenger
quietman7

1st Responder Mentor
1st Responder Mentor

Joined: Sep 30, 2004
Posts: 3564
Location: Virginia, USA
1st Responder Mentors 1st Responders MVP Premium Rootkit Experts Security Experts

PostPosted: Wed Dec 07, 2005 5:33 pm    Post subject:
Reply with quote

Microsoft® Phishing Filter Add-in for MSN® Search Toolbar 3.0.4702.0
http://addins.msn.com/phishingfilter/
http://www.microsoft.com/athome/security/online/phishing_filter.mspx


_________________
"THE BAD GUYS DON'T NEED A SEARCH WARRANT. ARE YOU PROTECTED?"

Microsoft MVP - Windows Security 2007-2008 image
Back to top
View users profile Send private message
MatanArie

Cadet
Cadet


Joined: Dec 11, 2005
Posts: 4
Location: Israel

PostPosted: Sun Dec 11, 2005 9:26 am    Post subject: CallingID
Reply with quote

Hi everyone.

I work at CallingID and I noticed that you've mentioned CallingID toolbar previously in this thread so I wanted to offer to answer any questions you might have.

Thanx.

Back to top
View users profile Send private message
Oldfrog

Special Response Team


Joined: Jun 27, 2004
Posts: 8575
Location: Deep in the Heart of Texas
Moderators MVP Premium SRT

PostPosted: Sun Dec 11, 2005 1:57 pm    Post subject:
Reply with quote

Hi, MatanArie, and welcome to Castlecops!

CallingID is one of several antiphishing toolbars that I use while investigating phish attempts and I am curious as to exactly what criteria it uses in assigning a risk rating. So far I have found that it consistently identifies legitimate sites as 'High Risk' if the owner of the domain uses a Whois privacy shield and rates malicious sites as 'Low Risk' so long as the target URL is a domain name with a listed owner.

A second question would be the sequence of events after a user invokes the "Report Site" feature. I have reported a number but the life expectancy of a phishing site is so short that I have never been able to observe any results.


_________________
image MS MVP Security 2006-2008
Back to top
View users profile Send private message Send email Visit posters website MSN Messenger
Yellowhammer

Site Moderator
Microsoft MVP

Joined: Jan 30, 2004
Posts: 18022

1st Responder Mentors MIRT Moderators MVP Premium Security Experts Team F@H

PostPosted: Sun Dec 11, 2005 3:18 pm    Post subject:
Reply with quote

MatanArie,

I removed a couple of your posts from the hijackthis forum. We do not allow spamming on this site either.


_________________
Yellowhammer
MS-MVP Security 2005/2006

How to prevent Reinfection
Back to top
View users profile Send private message
Wheelie4

Sergeant
Sergeant


Joined: May 08, 2005
Posts: 90
Location: USA

PostPosted: Wed Feb 01, 2006 4:12 pm    Post subject:
Reply with quote

So Oldfrog. Which phishing tool do you prefer? Better yet, which works with any browser? I use Maxthon Browser and just tried Trustwatch, Earthlinks Toolbar (featuring ScamBlocker) and PhishGuard and neither would work with Maxthon. Sad I like Earthlinks toolbar.

I did find plugin for Maxthon called "Spoof Bar" that works like "SpoofStick Tolbar" by showing the Name and IP# of the visited site.

Back to top
View users profile Send private message
Dragan_Glas

Team CC Chief Host
Team CC Chief Host
Chess Board Host
Chess Board Host

Joined: May 27, 2004
Posts: 2899

Premium RootKit Detection Hosts Rootkit Responders SRT Team CC Committee

PostPosted: Mon Apr 03, 2006 10:15 pm    Post subject:
Reply with quote

Greetings,

I did find another toolbar - CipherTrust's TrustedSource Toolbar - which is mentioned in a Computing article: New Way To Decipher Phishing Attacks.

Their Research Portal is a one-stop source for spam/phishing-related information.

CipherTrust also have something similar for websites.

Interestingly, the same company indicates that the US is the worst culprit with 32.1% whilst Korea is second with 15.4% (Microsoft Launches Anti-Phishing Legal Offensive).

Also, although this may not be the place for it, I found this interesting "book" - MailFrontier's "Field Guide To Phishing" - a funny, though informative, guide on how to recognise little phishes!

Given that surfers have difficulty spotting phish (Surfers Failing To Spot Phishing Sites) it could prove helpful!

There's even a link to a "Phishing IQ Test" at the end of the article.

Kindest regards,

Dragan Glas


_________________
Quote:
The only secure computer is one that's unplugged, locked in a safe, and buried 20 feet under the ground in a secret location... and I'm not even too sure about that one
Dennis Hughes, FBI
Back to top
View users profile Send private message
aquaevitae

Cadet
Cadet


Joined: Mar 31, 2006
Posts: 3
Location: UK

PostPosted: Sun Apr 09, 2006 10:49 am    Post subject:
Reply with quote

Hi Guys

I use Spybot and keep it running continuously
It currently has a d/b of 37180 bad progs and keeps this up-to-date as and when I choose (weekly)
BTW its free

Kind regards


_________________
MALCOLM J GREENAWAY, Managing Director
For and on behalf of Aquae Vitae Online Ltd
Aquae Vitae House 1a Stanley Road
Carshalton Surrey SM5 4LE
mjg@aquae-vitae-online.com
Back to top
View users profile Send private message Send email Visit posters website
Oldfrog

Special Response Team


Joined: Jun 27, 2004
Posts: 8575
Location: Deep in the Heart of Texas
Moderators MVP Premium SRT

PostPosted: Wed Apr 12, 2006 4:51 pm    Post subject:
Reply with quote

Quote:
I use Spybot and keep it running continuously
It currently has a d/b of 37180 bad progs and keeps this up-to-date as and when I choose (weekly)
BTW its free

While Spybot is a reasonably good AS application I am not aware of any features which provide any protection (read warning/blocking) against phishing exploits.


_________________
image MS MVP Security 2006-2008
Back to top
View users profile Send private message Send email Visit posters website MSN Messenger
MatanArie

Cadet
Cadet


Joined: Dec 11, 2005
Posts: 4
Location: Israel

PostPosted: Wed May 10, 2006 2:51 pm    Post subject: Reply
Reply with quote

Hi Oldfrog,
CallingID runs 54 tests on every site viewed and then makes an evaluation based on the overall scores of each test. The tests include finding the owner of the site in several external databases such as Dun and Bradstreet, certificates, the Better Business Bureau, checking whether the company or organization that owns the site is a real company located at the address it claims to be, the age of the site, is the site known as involved in problematic activity, is the site known by DNS servers, etc…

As the product is intended primarily for online consumers, the tests are generally designed to check a company or websites legitimacy. A side effect of this is that privately owned websites are often considered High Risk. What the toolbar is stating is in fact that the site may be unsafe to do business with; send confidential information to; or bank with. If the site does not ask you to do any of these things then the rating is irrelevant to the site.

We've received some questions about 'Hidden Identities' before and our opinion is this: If you are a commercial website; a website that asks for personal information; a website that asks for payment, donations or the like; hiding your identity from your viewers/shoppers/users/clients is dangerous to them. We therefore place considerable weight on the issue of 'Hidden Identities' in our assessments. Once again, if your site does not ask for confidential information, donations, payment, etc... the rating is irrelevant to you and your viewers.

As for your second question, CallingID puts a major emphasis on user ratings of sites. Once you've submitted a site you believe has been misclassified the information is sent directly to the top of a queue of sites that our panel of assessment techs views and rate 24/7.

It's true that phishing sites are so short lived that in most cases by the time you revisit the site it's been pulled down, but have you stopped to think why it's been pulled down? CallingID sends the info received from users and assessments calculated in real-time to Internet authorities with the capabilities to remove these sites. Your report on a site might lead directly to its removal.

Whenever a site is reported by a user, we evaluate the site, change the sites assessment (if appropriate) and email the user to notify him/her if the information submitted was correct and whether the assessment has been changed. As the 'Email' field is optional, many times we have no way of notifying "reporters" about the outcome of their reports.

I hope I've managed to shed some light on the issues you've brought up and I'd be happy to answer any more questions you might have.

Thank you.

Back to top
View users profile Send private message
Ocelotl1

Private
Private


Joined: Jul 09, 2004
Posts: 46


PostPosted: Sat Aug 19, 2006 5:16 am    Post subject:
Reply with quote

Its a pity no one has posted more anti-phising toolbars. I found the SpoofStick Toolbar here. I used it and loved it. Its simplicity was great. The problem is that it no longer works with the current version of firefox 1.5.0.6. I dont like the Netcraft Toolbar. It is way to invasive. I think it logs the websites that Netcraft Toolbar users have visited and has a specific ID for each downloaded toolbar. Thats ridiculously invasive. If anyone finds a nice anti phishing toolbar (for the current firefox) out there please let me know.

Back to top
View users profile Send private message Visit posters website
Dragan_Glas

Team CC Chief Host
Team CC Chief Host
Chess Board Host
Chess Board Host

Joined: May 27, 2004
Posts: 2899

Premium RootKit Detection Hosts Rootkit Responders SRT Team CC Committee

PostPosted: Sat Aug 19, 2006 2:46 pm    Post subject:
Reply with quote

Greetings,

Ocelotl1
There are a number of add-ons related to phishing, see:
https://addons.mozilla.org/search.php?q=phish&type=E&app=firefox
https://addons.mozilla.org/search.php?q=anti+phish&type=E&app=firefox

In future, you won't need an add-on...
Firefox 2.1 Beta incorporates anti-phishing

Kindest regards,

Dragan Glas


_________________
Quote:
The only secure computer is one that's unplugged, locked in a safe, and buried 20 feet under the ground in a secret location... and I'm not even too sure about that one
Dennis Hughes, FBI
Back to top
View users profile Send private message
PCBruiser

SRT Team Lead
SRT Team Lead
Forums Admin

Joined: May 11, 2005
Posts: 11723

1st Responder Mentors 1st Responders Forums Admin MIRT Moderators Premium Rootkit Experts Security Experts SRT Team CC Committee

PostPosted: Sat Aug 19, 2006 3:57 pm    Post subject:
Reply with quote

Ocelotl1 wrote:
I found the SpoofStick Toolbar here. I used it and loved it. Its simplicity was great. The problem is that it no longer works with the current version of firefox 1.5.0.6.
Yep, it does work and also in 2.0 B1 and 3.0 preA1. All you need is MRTech's Local Install and Nightly Tester Tools. Either will force compatibility and spoof stick will work. I have it running in both 1.5.0.6 and 2.0 B1. It works just fine.


_________________
Don't read? Can't learn!
Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Phishing, Fraud and Dastardly Deeds All times are GMT
Goto page Previous  1, 2, 3, 4, 5  Next
Page 4 of 5

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer