Home > Microsoft Exchange News > PhishTank casts its net for malicious email
Microsoft Exchange News:
EMAIL THIS

PhishTank casts its net for malicious email

By Dennis Fisher, Executive Editor
06 Oct 2006 | SearchSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

A new information clearinghouse for data on phishing attacks is up and running, and unlike similar efforts at other sites, PhishTank includes an open API that enables contributors to submit and access data through various applications.

The new site is not only an archive of suspected and confirmed phishing emails, but it also includes a feature that allows other registered users to examine submissions and verify that they are in fact malicious mailings. This collaborative format is a bit different from the work done by other groups, such as the Anti-Phishing Working Group, which focuses on compiling statistics on phishing and pharming attacks and aiding law enforcement agencies in taking down malicious sites.

PhishTank launched on Tuesday and by Thursday morning Eastern time, the site had received 752 submissions, 447 of which were verified as phish, according to the site's statistics page.

The site is backed by OpenDNS, a San Francisco-based company that provides a free DNS service designed to help companies avoid malicious Web sites and speed up their DNS queries.

The PhishTank API is a unique submission option for the site's contributors. Once a contributor registers an application with the site, he can submit suspected phishing emails via a direct SSL connection over HTTP. It is believed this method will be used mainly by ISPs and large enterprises. But individual contributors can submit emails simply by forwarding them to phish@phishtank.com.

One early application of this API is a button for Microsoft Outlook that the antispam group Project Honey Pot is developing. Once installed in the Outlook toolbar, the button will enable users to report suspected phish with one click.

Phishing and pharming -- a variation on phishing that involves DNS cache poisoning -- have been the favored attack vectors for identity thieves and online crime gangs for several years. Early phishing emails were crude and for the most part easily recognizable by their blatant spelling errors and other telltale signs. But as the financial stakes have grown, the messages and their social engineering tactics have becomes far more sophisticated and often target specific groups with small memberships, such as customers of small credit unions or community banks.

The number of attacks has continued to multiply as well. The Anti-Phishing Working Group reported more than 14,000 unique phishing campaigns in July 2005; July of this year saw more than 23,000 such attacks.

This article originally appeared on SearchSecurity.com.

Tags: IndustryPhishing and Email Fraud ProtectionVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Industry
Tackling the social messaging dilemma
Microsoft drops free migration tool for Exchange 2010
Microsoft reverses support plan for Exchange 2007 on Windows Server 2008 R2
Virtualize Exchange Server 2007 -- without losing your job
Exchange Server 2007 SP2 adds auditing, backup
Avoid these Exchange Server migration pitfalls
Microsoft readies Exchange Server 2010 release candidate
Virtualizing Exchange Server 2007 -- Where it works
Microsoft updates Exchange Server 2007 SP1
Microsoft fortifies Exchange Server with archiving

Phishing and Email Fraud Protection
Exchange 2007 out-of-office (OOF) feature adds usability and security
Microsoft Outlook and Exchange Server 2003 Email Security Guide
A Microsoft Outlook email security tutorial -- 8 tips in 8 minutes
Microsoft Office 2007's native security and antiphishing tools
New tools fight fraud and phishing
Phishing protection primer
Three ways phishers are hooking you
Phishing: A whale of a problem for enterprises
New phishing threat outpaces Netsky-P
Phishing secrets revealed

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
greylist  (SearchExchange.com)
Sender ID  (SearchExchange.com)
Vouch by Reference (VBR)  (SearchExchange.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



E-mail Security - Spam Filtering, Anti Virus, Password Management, Exchange Server Permissions
HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersIT Downloads
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2004 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts