<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Byung Kyu Park&#039;s Personal Website &#187; phishing</title>
	<atom:link href="http://bkpark.com/tag/phishing/feed/" rel="self" type="application/rss+xml" />
	<link>http://bkpark.com</link>
	<description>Everything about Byung Kyu Park</description>
	<lastBuildDate>Tue, 07 Feb 2012 16:59:37 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Yet another CalMail phishing attempt</title>
		<link>http://bkpark.com/2010/02/20/yet-another-calmail-phishing-attempt/</link>
		<comments>http://bkpark.com/2010/02/20/yet-another-calmail-phishing-attempt/#comments</comments>
		<pubDate>Sun, 21 Feb 2010 06:23:18 +0000</pubDate>
		<dc:creator>bkpark</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[calmail]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[phishing]]></category>

		<guid isPermaLink="false">http://bkpark.com/?p=515</guid>
		<description><![CDATA[Still fairly obvious, but it looks like phishers are getting better. Below is the email with full-headers (headers revealing my secret email server setup redacted): Return-path: <span class="mh-email">xxxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=fX7_gdcqtST-0KpRghBpSr9XI4Y_Tuoo3LwMIlfJmO4=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=fX7_gdcqtST-0KpRghBpSr9XI4Y_Tuoo3LwMIlfJmO4=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span> Envelope-to: <span class="mh-email">xxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=Wm5m0_v9EqnOMa3R--MEQJHXh0VdMVkcAeIBAzSL0UY=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=Wm5m0_v9EqnOMa3R--MEQJHXh0VdMVkcAeIBAzSL0UY=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@xxxxxx.xxx</span> Delivery-date: Sat, 20 Feb 2010 21:19:26 -0800 Received: from xxxxxxxx.berkeley.edu ([128.32.xxx.xxx]) by xxxxx.xxxxxxxxxxxx.xxx with esmtps (TLS1.0:RSA_AES_256_CBC_SHA1:32) (Exim 4.69) (envelope-from &#60;<span class="mh-email">xxxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=fX7_gdcqtST-0KpRghBpSr9XI4Y_Tuoo3LwMIlfJmO4=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=fX7_gdcqtST-0KpRghBpSr9XI4Y_Tuoo3LwMIlfJmO4=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span>&#62;) id 1Nj4E2-0003HR-Mg for <span class="mh-email">xxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=Wm5m0_v9EqnOMa3R--MEQJHXh0VdMVkcAeIBAzSL0UY=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=Wm5m0_v9EqnOMa3R--MEQJHXh0VdMVkcAeIBAzSL0UY=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@xxxxxx.xxx</span>; Sat, 20 [...]]]></description>
			<content:encoded><![CDATA[<p>Still fairly obvious, but it looks like phishers are getting better. Below is the email with full-headers (headers revealing my secret email server setup redacted):</p>
<pre>
Return-path: <span class="mh-email">xxxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=HrlVOPk__MUtIJuG2xh1qI7bfAQjdGssJUyLOdr3Ctg=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=HrlVOPk__MUtIJuG2xh1qI7bfAQjdGssJUyLOdr3Ctg=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span>
Envelope-to: <span class="mh-email">xxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=Cmh-O_mcqcU-BOPxOIMc_UUzu6IhYUQPm6Ud-UFchuY=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=Cmh-O_mcqcU-BOPxOIMc_UUzu6IhYUQPm6Ud-UFchuY=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@xxxxxx.xxx</span>
Delivery-date: Sat, 20 Feb 2010 21:19:26 -0800
Received: from xxxxxxxx.berkeley.edu ([128.32.xxx.xxx])
        by xxxxx.xxxxxxxxxxxx.xxx with esmtps (TLS1.0:RSA_AES_256_CBC_SHA1:32)
        (Exim 4.69)
        (envelope-from &lt;<span class="mh-email">xxxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=HrlVOPk__MUtIJuG2xh1qI7bfAQjdGssJUyLOdr3Ctg=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=HrlVOPk__MUtIJuG2xh1qI7bfAQjdGssJUyLOdr3Ctg=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span>&gt;)
        id 1Nj4E2-0003HR-Mg
        for <span class="mh-email">xxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=Cmh-O_mcqcU-BOPxOIMc_UUzu6IhYUQPm6Ud-UFchuY=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=Cmh-O_mcqcU-BOPxOIMc_UUzu6IhYUQPm6Ud-UFchuY=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@xxxxxx.xxx</span>; Sat, 20 Feb 2010 21:19:26 -0800
Received: from xxxxxxx by xxxxxxxx.Berkeley.EDU with local (Exim 4.69)
        (envelope-from &lt;<span class="mh-email">xxxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=HrlVOPk__MUtIJuG2xh1qI7bfAQjdGssJUyLOdr3Ctg=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=HrlVOPk__MUtIJuG2xh1qI7bfAQjdGssJUyLOdr3Ctg=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span>&gt;)
        id 1Nj4E2-0004s1-Bl
        for <span class="mh-email">xxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=Cmh-O_mcqcU-BOPxOIMc_UUzu6IhYUQPm6Ud-UFchuY=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=Cmh-O_mcqcU-BOPxOIMc_UUzu6IhYUQPm6Ud-UFchuY=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@xxxxxx.xxx</span>; Sat, 20 Feb 2010 21:19:26 -0800
Received: from cm03fe.ist.berkeley.edu ([169.229.218.144])
        by xxxxxxxxx.Berkeley.EDU with esmtp (Exim 4.69)
        (envelope-from &lt;<span class="mh-email">webm<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=8kVOM8ua-pvpy26zNXEOj4o9qBHX2f2ts1Nre6AkEQQ=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=8kVOM8ua-pvpy26zNXEOj4o9qBHX2f2ts1Nre6AkEQQ=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span>&gt;)
        id 1Nj4E2-0004rv-9i
        for <span class="mh-email">xxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=9hInstEEzMyl6a3FvLVaLt5DZGhvMr4XzJr8zlOSaho=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=9hInstEEzMyl6a3FvLVaLt5DZGhvMr4XzJr8zlOSaho=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@xxxxxxxxxxxx.xxx</span>; Sat, 20 Feb 2010 21:19:26 -0800
Received: from cm09be.ist.berkeley.edu ([169.229.218.182])
        by cm03fe.ist.berkeley.edu with esmtps (TLSv1:AES256-SHA:256)
        (Exim 4.69)
        (envelope-from &lt;<span class="mh-email">webm<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=8kVOM8ua-pvpy26zNXEOj4o9qBHX2f2ts1Nre6AkEQQ=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=8kVOM8ua-pvpy26zNXEOj4o9qBHX2f2ts1Nre6AkEQQ=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span>&gt;)
        id 1Nj4E1-0005NQ-Cn
        for <span class="mh-email">xxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=9hInstEEzMyl6a3FvLVaLt5DZGhvMr4XzJr8zlOSaho=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=9hInstEEzMyl6a3FvLVaLt5DZGhvMr4XzJr8zlOSaho=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@xxxxxxxxxxxx.xxx</span>; Sat, 20 Feb 2010 21:19:25 -0800
Received: from cyrus by cm09be.ist.berkeley.edu with local (Exim 4.69)
        (envelope-from &lt;<span class="mh-email">webm<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=8kVOM8ua-pvpy26zNXEOj4o9qBHX2f2ts1Nre6AkEQQ=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=8kVOM8ua-pvpy26zNXEOj4o9qBHX2f2ts1Nre6AkEQQ=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span>&gt;)
        id 1Nj4E1-0002WX-Ra
        for <span class="mh-email">xxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=9hInstEEzMyl6a3FvLVaLt5DZGhvMr4XzJr8zlOSaho=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=9hInstEEzMyl6a3FvLVaLt5DZGhvMr4XzJr8zlOSaho=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@xxxxxxxxxxxx.xxx</span>; Sat, 20 Feb 2010 21:19:25 -0800
Received: from cm01fe.ist.berkeley.edu (cm01fe.IST.Berkeley.EDU [169.229.218.142])
        by cm09ms.ist.berkeley.edu (Cyrus v2.3.13-CalMail-v2.3) with LMTPA;
        Sat, 20 Feb 2010 21:19:25 -0800
X-Sieve: CMU Sieve 2.3
Received: from persius.rz.uni-potsdam.de ([141.89.68.1])
        by cm01fe.ist.berkeley.edu with esmtp (Exim 4.69)
        (envelope-from &lt;<span class="mh-email">webm<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=8kVOM8ua-pvpy26zNXEOj4o9qBHX2f2ts1Nre6AkEQQ=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=8kVOM8ua-pvpy26zNXEOj4o9qBHX2f2ts1Nre6AkEQQ=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span>&gt;)
        id 1Nj4Dy-0007hK-52; Sat, 20 Feb 2010 21:19:24 -0800
Received: from arnim.rz.uni-potsdam.de (arnim.rz.uni-potsdam.de [141.89.68.11])
        by persius.rz.uni-potsdam.de (8.12.11/8.12.11) with ESMTP id o1L50smS001879;
        Sun, 21 Feb 2010 06:00:54 +0100 (CET)
Received: from uni-potsdam.de (localhost.localdomain [127.0.0.1])
        by arnim.rz.uni-potsdam.de (8.13.8/8.13.8) with ESMTP id o1L50qp1025812;
        Sun, 21 Feb 2010 06:00:52 +0100
Received: from 41.138.182.176 ([41.138.182.176]) by webmail.uni-potsdam.de
        (Horde MIME library) with HTTP; Sun, 21 Feb 2010 06:00:52 +0100
Message-ID: &lt;<span class="mh-email">2010<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=qyIqDwBc7N65vKMVQMscN_ksEGgbJ2_FbgM99tnQG7gHV8AypQ9sBhRBzh6IY_aPQmaKmqZHRr3sys56-Ixgsw==' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=qyIqDwBc7N65vKMVQMscN_ksEGgbJ2_FbgM99tnQG7gHV8AypQ9sBhRBzh6IY_aPQmaKmqZHRr3sys56-Ixgsw==', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@webmail.uni-potsdam.de</span>&gt;
Date: Sun, 21 Feb 2010 06:00:52 +0100
From: "Berkeley.edu Web-Administration" &lt;<span class="mh-email">webm<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=8kVOM8ua-pvpy26zNXEOj4o9qBHX2f2ts1Nre6AkEQQ=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=8kVOM8ua-pvpy26zNXEOj4o9qBHX2f2ts1Nre6AkEQQ=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span>&gt;
Reply-to: <span class="mh-email">supp<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=g0UERoJSVzHhkMRrmqix4mqOgswGuS8E5WHPgfJFLo4=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=g0UERoJSVzHhkMRrmqix4mqOgswGuS8E5WHPgfJFLo4=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@live.com</span>
To: undisclosed-recipients: ;
Subject: Alert: Update your CalMail  account
MIME-Version: 1.0
Content-Type: text/plain;
        charset=ISO-8859-1;
        DelSp="Yes";
        format="flowed"
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable
User-Agent: Internet Messaging Program (IMP) H3 (4.1.6)
X-Virus-Scanned: clamav-milter 0.95.3 at arnim.rz.uni-potsdam.de
X-Virus-Status: Clean
X-j-chkmail-Score: MSGID : 4B80BE06.000 on persius : j-chkmail score : X : 5/50 0
X-Miltered: at persius with ID 4B80BE06.000 by Joe's j-chkmail (http://j-chkmail.ensmp.fr)!
X-Ucb-Scan-Signature: 606d01dea56a423fb13a5c3f55ff5ffa3eae29a5
X-Ucb-Spam: Gauge=IIIIIII, Probability=7%, Report=''
X-Ucb-Notice: This message has been processed by a spam tagging system.
        See http://mailinfo.berkeley.edu/ for more information.

--

Dear CalMail User,

Your email account needs to be upgraded with our new F-Secure® HTK4S
anti-virus/anti-spam 2010 version.
Fill the columns below and click reply to send back or your account will be
suspended temporary from our services.

CalNet ID:
Passphrase:
Phone Number:

Berkeley.edu Web-Administration
Greg Silva

https://calmail.berkeley.edu/

----©2010, University Of California.
</pre>
<p>Note the fairly convincing From: address. A lot of the suspicious routing information will be hidden by most email clients, <em>however</em>, the Reply-to: header (which would route the email to <span class="mh-email">supp<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=g0UERoJSVzHhkMRrmqix4mqOgswGuS8E5WHPgfJFLo4=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=g0UERoJSVzHhkMRrmqix4mqOgswGuS8E5WHPgfJFLo4=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@live.com</span> and which the phishing relies on) <em>should</em> be set to visible by most email clients, which means, yet again, people who pay attention to details shouldn&#8217;t be taken in by this rather amateurish phishing attempt.</p>
<p>Not to mention one should never send passphrases over email&mdash;even if you know the recipient; email is transmitted in clear text between servers and is <em>inherently insecure</em>. </p>
]]></content:encoded>
			<wfw:commentRss>http://bkpark.com/2010/02/20/yet-another-calmail-phishing-attempt/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

