<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>munkinarts.com: the blog &#187; phishing</title>
	<atom:link href="http://munkinarts.com/blog/tag/phishing/feed/" rel="self" type="application/rss+xml" />
	<link>http://munkinarts.com/blog</link>
	<description>Ravings of a loon</description>
	<lastBuildDate>Fri, 23 Dec 2011 04:47:59 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
		<item>
		<title>Hmm, I wonder why the secrecy?</title>
		<link>http://munkinarts.com/blog/2010/08/30/hmm-i-wonder-why-the-secrecy/</link>
		<comments>http://munkinarts.com/blog/2010/08/30/hmm-i-wonder-why-the-secrecy/#comments</comments>
		<pubDate>Mon, 30 Aug 2010 23:11:19 +0000</pubDate>
		<dc:creator>owner</dc:creator>
				<category><![CDATA[looney]]></category>
		<category><![CDATA[bitch!]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[George Hansen]]></category>
		<category><![CDATA[Gonna be rich]]></category>
		<category><![CDATA[phishing]]></category>

		<guid isPermaLink="false">http://munkinarts.com/blog/?p=964</guid>
		<description><![CDATA[I got this today from George Hansen (mr.georgehanson@hotmail.com).  It was nice of him to invite me, but I don&#8217;t know him. Nor do I care. Or even think it&#8217;s a real offer. Feel free to use his address as you &#8230; <a href="http://munkinarts.com/blog/2010/08/30/hmm-i-wonder-why-the-secrecy/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>I got this today from George Hansen (mr.georgehanson@hotmail.com).  It was nice of him to invite me, but I don&#8217;t know him.</p>
<p>Nor do I care.</p>
<p>Or even think it&#8217;s a real offer.</p>
<p>Feel free to use his address as you see fit.</p>
<blockquote><p>From: Mr.George Hanson</p>
<p>Dear Sir,</p>
<p>Compliments of the season to you.</p>
<p>I am a Civil Lawyer. I have a client that wishes to invest her<br />
financial estate in your Country. Can you be of Assistance as a<br />
Partner? I will give details when you reply. This transaction demands<br />
Absolute Secrecy from You.</p>
<p>Yours truly,</p>
<p>George Hanson.</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://munkinarts.com/blog/2010/08/30/hmm-i-wonder-why-the-secrecy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New phishing attempt</title>
		<link>http://munkinarts.com/blog/2010/08/06/new-phishing-attempt/</link>
		<comments>http://munkinarts.com/blog/2010/08/06/new-phishing-attempt/#comments</comments>
		<pubDate>Fri, 06 Aug 2010 14:23:38 +0000</pubDate>
		<dc:creator>owner</dc:creator>
				<category><![CDATA[random]]></category>
		<category><![CDATA[viruses]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[scammers]]></category>

		<guid isPermaLink="false">http://munkinarts.com/blog/?p=958</guid>
		<description><![CDATA[Here&#8217;s a new one, for me at least.    I received an email that theoretically looked like it came from target.com.   My mailing program blocked the remote images, but I&#8217;m assuming the scammer took the time to make it &#8230; <a href="http://munkinarts.com/blog/2010/08/06/new-phishing-attempt/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Here&#8217;s a new one, for me at least.    I received an email that theoretically looked like it came from target.com.   My mailing program blocked the remote images, but I&#8217;m assuming the scammer took the time to make it look right.</p>
<p>The email made it look like I had ordered something and this was a confirmation message.   There were three problems with this, however:</p>
<ul>
<li>I didn&#8217;t order anything</li>
<li>I don&#8217;t use this email address for shopping</li>
<li>I know enough to mouse over the links and saw they weren&#8217;t going to Target.com</li>
</ul>
<p>Nice try though, there were even links to other similar items, but again, the links didn&#8217;t go to Target.com&#8217;s site.</p>
]]></content:encoded>
			<wfw:commentRss>http://munkinarts.com/blog/2010/08/06/new-phishing-attempt/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Just a little PSA from Munkin Arts LLC</title>
		<link>http://munkinarts.com/blog/2010/06/21/just-a-little-psa-from-munkin-arts-llc/</link>
		<comments>http://munkinarts.com/blog/2010/06/21/just-a-little-psa-from-munkin-arts-llc/#comments</comments>
		<pubDate>Mon, 21 Jun 2010 13:40:54 +0000</pubDate>
		<dc:creator>owner</dc:creator>
				<category><![CDATA[computers]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[PSA]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[Tom loves you]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://munkinarts.com/blog/?p=896</guid>
		<description><![CDATA[Hi folks! Do you love email? Sure, we all do. But it&#8217;s important to use email safely.  That&#8217;s why we here at Munkin Arts LLC wanted to share this important message with you, our earnest readers. Recently a new exploit &#8230; <a href="http://munkinarts.com/blog/2010/06/21/just-a-little-psa-from-munkin-arts-llc/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Hi folks!</p>
<p>Do you love email? Sure, we all do.</p>
<p>But it&#8217;s important to use email safely.  That&#8217;s why we here at Munkin Arts LLC wanted to share this important message with you, our earnest readers.</p>
<p>Recently a new exploit has cropped up in the ever expanding attempt to infect your computer with viruses.</p>
<p>Email messages are coming in saying that you need to complete an order at bluemountain.com, an online virtual greeting card company.   Or in another example, I received this message saying  my account was set up, but I need to log in to complete the process.</p>
<blockquote><p>Thank you for becoming a member on our site</p>
<p>You have entered your email address and screen name:</p>
<p>Email: tom@[REDACTED]<br />
Screen name: boosas05</p>
<p>Please login with the password you created.</p>
<p>In order to complete the free membership process, you must click on the         attached link to activate your account:</p>
<p>You will have 30 days to confirm your registration or you will need to re-register on the site.</p></blockquote>
<p>There are a few problems with this.</p>
<ul>
<li>I never use my home address to sign for web sites</li>
<li>There&#8217;s no mention of <em>what</em> site it&#8217;s actually for.   The email came from boosas05@raschella.com, which you&#8217;ll notice happens to also be the password they sent.</li>
<li>I&#8217;d never do any business that emails a username and password combination in one email.</li>
</ul>
<p>Being a smart user, I saved the login.html attachment locally, scanned it with the virus software, then opened it in notepad to have a look.</p>
<p>The html is a mess, but it takes you to some URL no one has ever heard of or would have construct on their own.</p>
<p>So in conclusion, if it looks suspicious, don&#8217;t double click it.</p>
<p>Have a great day!</p>
]]></content:encoded>
			<wfw:commentRss>http://munkinarts.com/blog/2010/06/21/just-a-little-psa-from-munkin-arts-llc/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A new, and almost clever scam</title>
		<link>http://munkinarts.com/blog/2010/03/23/a-new-and-almost-clever-scam/</link>
		<comments>http://munkinarts.com/blog/2010/03/23/a-new-and-almost-clever-scam/#comments</comments>
		<pubDate>Tue, 23 Mar 2010 13:29:25 +0000</pubDate>
		<dc:creator>owner</dc:creator>
				<category><![CDATA[looney]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[scam]]></category>
		<category><![CDATA[Yahoo!]]></category>

		<guid isPermaLink="false">http://munkinarts.com/blog/?p=747</guid>
		<description><![CDATA[I got this in my Yahoo! mail today.   I recognized how ridiculous it sounded and how poorly executed it was, but if someone you love that may not have their wits about them uses this mail service, give them &#8230; <a href="http://munkinarts.com/blog/2010/03/23/a-new-and-almost-clever-scam/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>I got this in my Yahoo! mail today.   I recognized how ridiculous it sounded and how poorly executed it was, but if someone you love that may not have their wits about them uses this mail service, give them a gentle tip off.</p>
<p>The brilliance of this one is that it goes to?  A Yahoo.com address.  So maybe it is from corporate, right?   No. I have a yahoo.com address I use as a spam trap, but I certainly don&#8217;t work there.</p>
<div id="attachment_748" class="wp-caption aligncenter" style="width: 298px"><a href="http://munkinarts.com/blog/wp-content/uploads/2010/03/brilliant.jpg"><img class="size-medium wp-image-748" title="brilliant" src="http://munkinarts.com/blog/wp-content/uploads/2010/03/brilliant-288x300.jpg" alt="Nice try!" width="288" height="300" /></a><p class="wp-caption-text">Nice try!</p></div>
]]></content:encoded>
			<wfw:commentRss>http://munkinarts.com/blog/2010/03/23/a-new-and-almost-clever-scam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Dear Phishermen</title>
		<link>http://munkinarts.com/blog/2010/02/03/dear-phishermen/</link>
		<comments>http://munkinarts.com/blog/2010/02/03/dear-phishermen/#comments</comments>
		<pubDate>Wed, 03 Feb 2010 04:42:37 +0000</pubDate>
		<dc:creator>owner</dc:creator>
				<category><![CDATA[looney]]></category>
		<category><![CDATA[Bank of America]]></category>
		<category><![CDATA[bit.ly]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[stupid]]></category>

		<guid isPermaLink="false">http://munkinarts.com/blog/?p=656</guid>
		<description><![CDATA[If you&#8217;re going to take the time to rip off Bank of America&#8217;s graphics and email template, and even figure out how to place a Registration mark in an odd place, at least have the good sense to buy a &#8230; <a href="http://munkinarts.com/blog/2010/02/03/dear-phishermen/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>If you&#8217;re going to take the time to rip off Bank of America&#8217;s graphics and email template, and even figure out how to place a Registration mark in an odd place, at least have the good sense to buy a cheap domain that *might* fool someone into clicking your log in link.</p>
<p>Here&#8217;s one example from a message in my spam trap:</p>
<p>http://chavdaphotographers.com/gallery/online.bankofamerica.com/</p>
<p>online.bankofamerica.com/ccss-rva.bankofamerica.com/ccss/102%26target=<br />
acctOverview%26acid=1%26os/SSOEntrypageid=102%26target=<br />
acctOverview%26acid=/onlineid-sessionload/signon.do/</p>
<p>Three free bits of advice, take them for what you will:</p>
<ol>
<li>Don&#8217;t ever click a log-in link from an email.  Go to the site in question and log in correctly.</li>
<li>In many cases, if you move your mouse over a link you can see the destination in the browser&#8217;s status bar.  At best it should direct you to the actual site you think it&#8217;s heading towards.   Just be wary of bankoffamerica.com or bankofameirca.com   Two misspellings that look so similar to the real thing you might be fooled.</li>
<li>Be wary of bit.ly and other types of shortened links in email.  You can&#8217;t see the destination of where they&#8217;ll take you, it&#8217;s best just not to click on them.</li>
</ol>
<ol></ol>
]]></content:encoded>
			<wfw:commentRss>http://munkinarts.com/blog/2010/02/03/dear-phishermen/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

