<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>Kakkoi &#187; millw0rm</title>
	<atom:link href="http://42.kaizeku.com/taxonomy/millw0rm//feed/" rel="self" type="application/rss+xml" />
	<link>http://42.kaizeku.com</link>
	<description>web development, software, windows tips and trick</description>
	<pubDate>Sat, 12 Jul 2008 15:10:01 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
	<language>en</language>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Email Phishing and Spams Trends - Be wary</title>
		<link>http://42.kaizeku.com/security/vulnerability/email-phising-and-spam-trends/</link>
		<comments>http://42.kaizeku.com/security/vulnerability/email-phising-and-spam-trends/#comments</comments>
		<pubDate>Tue, 11 Dec 2007 14:09:28 +0000</pubDate>
		<dc:creator>Avice De'veréux</dc:creator>
		
		<category><![CDATA[Gmail]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[email]]></category>

		<category><![CDATA[Exploit]]></category>

		<category><![CDATA[Google]]></category>

		<category><![CDATA[jpeg+exploit]]></category>

		<category><![CDATA[microsoft]]></category>

		<category><![CDATA[millw0rm]]></category>

		<category><![CDATA[phishing]]></category>

		<category><![CDATA[tiff+exploit]]></category>

		<category><![CDATA[vx+heavens]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/vulnerability/email-phising-and-spam-trends/</guid>
		<description><![CDATA[<p><img src='http://gmodules.com/ig/proxy?url=http://www.shareapic.net/preview2/004669852.gif' alt='Google Gmail Logo' class="fl" width="130" height="54" />Below is typical phishing email I received on <cite style="background:#ffd;color:#000;padding: 1px 3px">Dec 8, 2007</cite>. It was send to one of my active gmail accounts. </p>

<dl class="xoxo r cb" style="list-style-type:none;width:98%;margin: 18px auto;border:1px solid #eee;padding:10px">
<dd>
<h2 class="cb" style="margin-top:9px;border-bottom: 1px solid #ccc">The Email Header</h2>
	<dl id="phising-email" class="profile cf cb">
	<dt class="fl cl" style="width:50px">From</dt>
	<dd><strong style="font-weight:400">"Gmail Team" &#60;customercareteamalert4@gmail.com&#62;</strong></dd>
	<dt class="fl cl" style="width:50px">Subject</dt>
		<dd><strong style="font-weight:400">Gmail Warning!!!! Verify Your Gmail Account To Avoid Close</strong>.</dd>
	<dt class="cl" style="border-top:1px solid#ccc;padding:9px 0px;margin-top:4px">Part of the message &#8595;</dt>
	<dd><blockquote cite="http://gmail.com/">
	<p> 
	Dear member,<br/>
	This message is from gmail message center to all gmail free account owners
	and premium account owners. We are currently upgrading our data base and
	e-mail account center. We are deleting all unused gmail account to create
	more space for new accounts.
	
	 *To prevent your account from closing, you will have to verify it below so
	that we will know that it's a present used account.*
	
	* CONFIRM YOUR IDENTITY. VERIFY YOUR FREE GMAIL ACCOUNT NOW !!! [...]</p>
	</blockquote>
	</dd>
	</dl>
</dd>
</dl>]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://gmodules.com/ig/proxy?url=http://www.shareapic.net/preview2/004669852.gif' alt='Google Gmail Logo' class="fl" width="130" height="54" />Below is typical phishing email I received on <cite style="background:#ffd;color:#000;padding: 1px 3px">Dec 8, 2007</cite>. It was send to one of my active gmail accounts. </p>
<p><span id="more-78"></span></p>
<dl class="xoxo r cb" style="list-style-type:none;width:511px;margin: 18px auto;border:1px solid #eee;padding:10px">
<dd>
<h2 class="cb" style="margin-top:9px;border-bottom: 1px solid #ccc">The Email Header</h2>
<dl id="phising-email" class="profile cf cb">
<dt class="fl cl" style="width:50px">From</dt>
<dd><strong style="font-weight:400">&#8220;Gmail Team&#8221; &lt;customercareteamalert4@gmail.com&gt;</strong></dd>
<dt class="fl cl" style="width:50px">Subject</dt>
<dd><strong style="font-weight:400">Gmail Warning!!!! Verify Your Gmail Account To Avoid Close</strong>.</dd>
<dt class="cl" style="border-top:1px solid#ccc;padding:9px 0px;margin-top:4px">Part of the message &darr;</dt>
<dd>
<blockquote cite="http://gmail.com/">
<p>
Dear member,<br/><br />
This message is from gmail message center to all gmail free account owners<br />
and premium account owners. We are currently upgrading our data base and<br />
e-mail account center. We are deleting all unused gmail account to create<br />
more space for new accounts.</p>
<p> *To prevent your account from closing, you will have to verify it below so<br />
that we will know that it&#8217;s a present used account.*</p>
<p>* CONFIRM YOUR IDENTITY. VERIFY YOUR FREE GMAIL ACCOUNT NOW !!! [...]</p>
</blockquote>
</dl>
<h3 class="cb">Raw Email Content</h3>
<p>This are part of of the raw message on gmail its not download via pop3. Certain meta info is not available as its got filtered by gmail services (spam automatic removal). </p>
<pre style="460px;height:300px;overflow:auto;border:1px solid #ccc">
Delivered-To random-victims-name@gmail.com
Received: by 10.114.235.19 with SMTP id i19cs230694wah;
 Sat, 8 Dec 2007 04:27:12 -0800 (PST)
Received: by 10.141.20.7 with SMTP id x7mr3231780rvi.1197116792300;
 Sat, 08 Dec 2007 04:26:32 -0800 (PST)
Received: by 10.141.115.15 with HTTP; Sat, 8 Dec 2007 04:26:32 -0800 (PST)
Message-ID: &lt;2f83b9150712080426n4a018c86mc2af4a4ed271f223@mail.gmail.com&gt;
Date: Sat, 8 Dec 2007 13:26:32 +0100
From: &quot;Gmail Team&quot; &lt;customercareteamalert4@gmail.com&gt;
Reply-To: customercareteamalert2@gmail.com
Subject: Gmail Warning!!!! Verify Your Gmail Account To Avoid Close.
MIME-Version: 1.0
Content-Type: multipart/alternative;
	boundary=&quot;----=_Part_11145_31274162.1197116792293&quot;

------=_Part_11145_31274162.1197116792293
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

 Dear Member*,* **
 * Account Alert*
***
 *
 *VERIFY YOUR GMAIL ACCOUNT NOW TO AVOID CLOSE !!!*
***GMAI L
*Dear Member*,*
 This message is from gmail message center to all gmail free account owners
and premium account owners. We are currently upgrading our data base and
e-mail account center. We are deleting all unused gmail account to create
more space for new accounts.

 *To prevent your account from closing, you will have to verify it below so
that we will know that it's a present used account.*

* CONFIRM YOUR IDENTITY. VERIFY YOUR FREE GMAIL ACCOUNT NOW !!!

 &lt;http://amazon.com/&gt;
 Gmail! ID:.........................

 Password:........................

 Your Birthday:.................

 Your Country or Territory:...........
 Enter the Security
Characters:......... [image: Registration
Verification Code]
*

 *Warning!!! **Account owner that refuses to update his or her account
before two weeks of receiving this warning will lose his or her account
permanently. *
**
*Sincerely,*
*Gmail Team*

------=_Part_11145_31274162.1197116792293
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

&lt;table style=&quot;WIDTH: 595px; HEIGHT: 813px&quot; width=&quot;595&quot; border=&quot;0&quot;&gt;
&lt;tbody&gt;
&lt;tr bgcolor=&quot;#cccc99&quot;&gt;
&lt;td valign=&quot;center&quot; colspan=&quot;3&quot;&gt;&lt;font face=&quot;Arial,Helvetica&quot; color=&quot;#333300&quot; size=&quot;+0&quot;&gt;&lt;span style=&quot;FONT-SIZE: 13px; FONT-FAMILY: Arial&quot;&gt;Dear&amp;nbsp;&lt;font size=&quot;3&quot;&gt;Member&lt;/font&gt;&lt;strong&gt;,&lt;/strong&gt;&lt;/span&gt;&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;
&lt;td colspan=&quot;3&quot;&gt;&lt;font face=&quot;Arial,Helvetica&quot; size=&quot;-1&quot;&gt;
&lt;div align=&quot;center&quot;&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;&lt;span style=&quot;FONT-SIZE: 13px; FONT-FAMILY: Arial&quot;&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;&lt;span style=&quot;FONT-SIZE: 23px; FONT-FAMILY: Arial&quot;&gt;&lt;b&gt;&lt;font color=&quot;#dd6600&quot;&gt;
&lt;img style=&quot;WIDTH: 430px; HEIGHT: 99px&quot; height=&quot;330&quot; src=&quot;http://www.google.com/intl/en/press/images/logos/gmail.jpg&quot; width=&quot;418&quot;&gt;&lt;/font&gt;&lt;/b&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot;&gt;
&lt;div&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;&lt;span style=&quot;FONT-SIZE: 13px; FONT-FAMILY: Arial&quot;&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;&lt;span style=&quot;FONT-SIZE: 23px; FONT-FAMILY: Arial&quot;&gt;&lt;b&gt;&lt;u&gt;&lt;font color=&quot;#ff0000&quot;&gt;
&amp;nbsp;Account Alert&lt;/font&gt;&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot;&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;&lt;span style=&quot;FONT-SIZE: 13px; FONT-FAMILY: Arial&quot;&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;&lt;span style=&quot;FONT-SIZE: 23px; FONT-FAMILY: Arial&quot;&gt;&lt;strong&gt;
&lt;/strong&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;font face=&quot;Arial&quot; color=&quot;#ff0000&quot;&gt;&lt;/font&gt;&lt;/u&gt;&lt;br&gt;&amp;nbsp; &lt;/b&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot;&gt;
&lt;table cellspacing=&quot;0&quot; cellpadding=&quot;4&quot; width=&quot;585&quot; border=&quot;0&quot;&gt;
&lt;tbody&gt;
&lt;tr bgcolor=&quot;#a0b8c8&quot;&gt;
&lt;td colspan=&quot;2&quot;&gt;
&lt;div align=&quot;center&quot;&gt;&lt;font face=&quot;Arial&quot;&gt;&lt;font face=&quot;Arial Narrow&quot; size=&quot;4&quot;&gt;&lt;u&gt;&lt;strong&gt;VERIFY YOUR GMAIL ACCOUNT NOW TO AVOID CLOSE&amp;nbsp;!!!&lt;/strong&gt;&lt;/u&gt;&lt;/font&gt;&lt;/font&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot;&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;&lt;strong&gt;&lt;font size=&quot;5&quot;&gt;&lt;font face=&quot;arial&quot;&gt;&lt;/font&gt;&lt;/font&gt;&lt;/strong&gt;&lt;/font&gt;&lt;/font&gt;&lt;/font&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;
&lt;font face=&quot;Arial
 Cyr&quot; size=&quot;2&quot;&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;&lt;strong&gt;&lt;font face=&quot;Arial&quot;&gt;&lt;font size=&quot;7&quot;&gt;&lt;u&gt;&lt;font color=&quot;#0000bf&quot;&gt;G&lt;/font&gt;&lt;font color=&quot;#ff0000&quot;&gt;M&lt;/font&gt;&lt;font color=&quot;#ffff00&quot;&gt;A&lt;/font&gt;&lt;font color=&quot;#0000bf&quot;&gt;I&lt;/font&gt;&lt;font color=&quot;#007f40&quot;&gt;
 L&lt;/font&gt;&lt;/u&gt;&lt;/font&gt;&lt;/font&gt;&lt;br&gt;&lt;/strong&gt;&lt;span style=&quot;FONT-SIZE: 21px; FONT-FAMILY: Arial&quot;&gt;&lt;font color=&quot;#ff0000&quot;&gt;Dear&lt;/font&gt;&lt;font color=&quot;#ff0000&quot;&gt;&amp;nbsp;Member&lt;/font&gt;&lt;font color=&quot;#ff0000&quot;&gt;&lt;strong&gt;,&lt;/strong&gt;&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;
 &lt;/font&gt;&lt;/div&gt;&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;font face=&quot;Arial Cyr&quot; color=&quot;#124282&quot; size=&quot;2&quot;&gt;&lt;span style=&quot;FONT-SIZE: 13px; FONT-FAMILY: Arial&quot;&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span style=&quot;FONT-SIZE: 10pt; COLOR: rgb(18,66,130); FONT-FAMILY: Arial&quot;&gt;&lt;font color=&quot;#0000ff&quot;&gt;&lt;span style=&quot;FONT-SIZE: 10pt; FONT-FAMILY: Arial&quot;&gt;&lt;font color=&quot;#00007f&quot;&gt;This message is from gmail message center to all&amp;nbsp;gmail free account owners and premium account owners. We are currently upgrading our data base and e-mail account center. We are deleting all unused&amp;nbsp;gmail account to create more space for new accounts.
&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span style=&quot;FONT-SIZE: 10pt; COLOR: rgb(18,66,130); FONT-FAMILY: Arial&quot;&gt;&lt;/span&gt;&amp;nbsp;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;MARGIN: 0in 0in 0pt&quot;&gt;&lt;font face=&quot;Times

 New

 Roman&quot;&gt;&lt;strong&gt;To prevent your account from closing, you will have to&amp;nbsp;verify it&amp;nbsp;below so that we will know that it&amp;#39;s a present used account.&lt;/strong&gt;&lt;/font&gt;&lt;/div&gt;&lt;span style=&quot;FONT-SIZE: 10pt; COLOR: rgb(18,66,130)&quot;&gt;
&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span style=&quot;FONT-SIZE: 10pt; COLOR: rgb(18,66,130)&quot;&gt;&lt;/span&gt;&amp;nbsp;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;&lt;strong&gt;&lt;span style=&quot;FONT-SIZE: 10pt; COLOR: rgb(18,66,130); FONT-FAMILY: Arial&quot;&gt;
&lt;table cellspacing=&quot;0&quot; cellpadding=&quot;4&quot; width=&quot;585&quot; border=&quot;0&quot;&gt;
&lt;tbody&gt;
&lt;tr bgcolor=&quot;#a0b8c8&quot;&gt;
&lt;td colspan=&quot;2&quot;&gt;&lt;font size=&quot;4&quot;&gt;
&lt;div&gt;&lt;strong&gt;
&lt;font size=&quot;4&quot;&gt;
&lt;div&gt;&lt;strong&gt;CONFIRM YOUR IDENTITY. VERIFY YOUR FREE GMAIL ACCOUNT NOW !!!&lt;/strong&gt; &lt;/div&gt;&lt;/font&gt;&lt;/strong&gt;&lt;/div&gt;&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
&lt;div&gt;&lt;strong&gt;&lt;font size=&quot;5&quot;&gt;&lt;font face=&quot;arial&quot;&gt;&amp;nbsp;
&lt;div&gt;
&lt;div&gt;&lt;img style=&quot;WIDTH: 469px; HEIGHT: 75px&quot; height=&quot;75&quot; src=&quot;http://pics.ebaystatic.com/aw/pics/securityCenter/hdr1_649x75.gif&quot; width=&quot;649&quot;&gt;&lt;/div&gt;
&lt;div&gt;&lt;font size=&quot;2&quot;&gt;&lt;font face=&quot;Verdana&quot;&gt;&lt;strong&gt;&lt;a href=&quot;http://amazon.com/&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;&lt;span id=&quot;lw_1190759841_12&quot;&gt;&lt;font color=&quot;#003399&quot;&gt;&lt;/font&gt;&lt;/span&gt;&lt;/a&gt;&lt;/strong&gt;&lt;/font&gt;&lt;/font&gt;&amp;nbsp;&lt;/div&gt;&lt;/div&gt;&lt;/font&gt;
&lt;/font&gt;&lt;/strong&gt;&lt;/div&gt;
&lt;div&gt;&lt;strong&gt;&lt;font size=&quot;5&quot;&gt;&lt;font face=&quot;arial&quot;&gt;&lt;font face=&quot;arial narrow&quot; size=&quot;4&quot;&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;MARGIN: 0in 0in 0pt&quot;&gt;&lt;strong&gt;&lt;span style=&quot;FONT-SIZE: 13.5pt&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Gmail! ID:.........................&lt;/span&gt;&lt;/strong&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;MARGIN: 0in 0in 0pt&quot;&gt;&lt;strong&gt;&lt;span style=&quot;FONT-SIZE: 13.5pt&quot;&gt;&lt;/span&gt;&lt;/strong&gt;&amp;nbsp;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;MARGIN: 0in 0in 0pt&quot;&gt;&lt;strong&gt;&lt;span style=&quot;FONT-SIZE: 13.5pt&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Password:........................&lt;/span&gt;&lt;/strong&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;MARGIN: 0in 0in 0pt&quot;&gt;&lt;strong&gt;&lt;span style=&quot;FONT-SIZE: 13.5pt&quot;&gt;&lt;/span&gt;&lt;/strong&gt;&amp;nbsp;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;MARGIN: 0in 0in 0pt&quot;&gt;&lt;font size=&quot;4&quot;&gt;&lt;font face=&quot;arial narrow&quot;&gt;&lt;strong style=&quot;FONT-FAMILY: arial narrow&quot;&gt;&lt;span style=&quot;FONT-SIZE: 13.5pt&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Your Birthday:.................&lt;/span&gt;&lt;/strong&gt;
 &lt;/font&gt;&lt;/font&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;MARGIN: 0in 0in 0pt&quot;&gt;&lt;font size=&quot;4&quot;&gt;&lt;font face=&quot;arial
 narrow&quot;&gt;&lt;strong style=&quot;FONT-FAMILY: arial narrow&quot;&gt;&lt;span style=&quot;FONT-SIZE: 13.5pt&quot;&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/font&gt;&lt;/font&gt;&amp;nbsp;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;MARGIN: 0in 0in 0pt&quot;&gt;&lt;strong&gt;&lt;span style=&quot;FONT-SIZE: 13.5pt&quot;&gt;&lt;label for=&quot;persistent&quot;&gt;&lt;/label&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Your Country or Territory:...........&lt;/span&gt;&lt;/strong&gt; &lt;/div&gt;&lt;/font&gt;&lt;/font&gt;&lt;/font&gt;&lt;/strong&gt;
&lt;/div&gt;
&lt;div&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Enter the &lt;strong&gt;Security Characters:.........&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;img style=&quot;WIDTH: 125px; HEIGHT: 38px&quot; alt=&quot;Registration Verification Code&quot; src=&quot;https://ab.login.yahoo.com/img/LVnEpeVZFekTjDHcj06RTVxEZ3._lwVb0bZmRLXJUxldX3JOnZnejReq4nmXD_..xGmoMjBT9h9WFcSARc5o427WyZP6hQ1z1juqhTkOyV68FA04yd2HiHVj.jpg&quot; border=&quot;0&quot;&gt;
 &lt;/strong&gt;&lt;/div&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span style=&quot;FONT-SIZE: 10pt; COLOR: rgb(18,66,130); FONT-FAMILY: Arial&quot;&gt;&lt;/span&gt;&amp;nbsp;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span style=&quot;FONT-SIZE: 10pt; COLOR: rgb(18,66,130); FONT-FAMILY: Arial&quot;&gt;&lt;img style=&quot;WIDTH: 148px; HEIGHT: 53px&quot; height=&quot;139&quot; src=&quot;http://www.genbeta.com/images/2007/01/gmail%20logo%20blanco.gif&quot; width=&quot;118&quot;&gt;
 &lt;/span&gt;&lt;/div&gt;
&lt;div&gt;&lt;strong&gt;&lt;span style=&quot;FONT-SIZE: 12pt; COLOR: red; FONT-FAMILY: Arial&quot;&gt;Warning!!! &amp;nbsp;&lt;/span&gt; &lt;/strong&gt;&lt;strong&gt;&lt;span style=&quot;FONT-SIZE: 12pt; COLOR: black&quot;&gt;Account owner that refuses to update his or her account before two weeks of receiving this warning will lose his or her account permanently.
&lt;/span&gt;&lt;/strong&gt;&lt;/div&gt;
&lt;div&gt;&lt;strong&gt;&lt;span style=&quot;FONT-SIZE: 12pt; COLOR: black&quot;&gt;&lt;/span&gt;&lt;/strong&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;&lt;strong&gt;&lt;span style=&quot;FONT-SIZE: 12pt; COLOR: black&quot;&gt;Sincerely,&lt;/span&gt;&lt;/strong&gt;&lt;/div&gt;
&lt;div&gt;&lt;strong&gt;&lt;span style=&quot;FONT-SIZE: 12pt; COLOR: black&quot;&gt;Gmail Team&lt;/span&gt;&lt;/strong&gt;&lt;/div&gt;&lt;/span&gt;&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;

------=_Part_11145_31274162.1197116792293--
</pre>
<dt style="margin-bottom:10px">
They used Outlook to published this email and leeched numbers of images across different &#8220;known&#8221; web services &darr;</dt>
<dd class="title" style="border-bottom:1px dotted #ccc"><span class="fl" style="width:100px">Image</span> <span>Sources</span></dd>
<dd class="cl"><span class="fl" style="width:100px"> Gmail Logo: </span> <a href="http://www.google.com/intl/en/press/images/logos/gmail.jpg">Google Presskit logo</a></dd>
<dd class="fl"><span class="fl" style="width:100px">Captcha :</span> <a href="https://ab.login.yahoo.com/img/LVnEpeVZFekTjDHcj06RTVxEZ3._lwVb0bZmRLXJUxldX3JOnZnejReq4nmXD_..xGmoMjBT9h9WFcSARc5o427WyZP6hQ1z1juqhTkOyV68FA04yd2HiHVj.jpg">yahoo (SSL)</a></dd>
<dd class="cl"><span class="fl" style="width:100px">Gmail Logo 2:</span> <a href="http://www.genbeta.com/images/2007/01/gmail%20logo%20blanco.gif">genbeta.com</a> (might be their host)</dd>
<dd class="cl"><span class="fl" style="width:100px">Header:</span> <a href="http://pics.ebaystatic.com/aw/pics/securityCenter/hdr1_649x75.gif">EbayStatic Server</a></dd>
</dl>
<h2>Whats the motiff</h2>
<p>It may seem funny to read the message as this are pretty much a script kiddies at work. I&#8217;m sure that most savvy users will not trust this types of threat. But what most people unaware of is the &#8220;Image&#8221; portions of the message. It can play a big role for expoiting email.</p>
<p class="note" style="padding:10px;margin:10px;width:85%;border:1px solid #eee"><span style="font-weight:700">QuickInfo:</span> Spam &#8220;images&#8221; trends start around <a href="http://www.ironport.com/">june 2006</a> and earlier version of popular email client (Outlook and Thunderbird) doesn&#8217;t block images by default. </p>
<p> If you are familliar with Internet Security in general,you may notice that there is many attemp and proof of concept method in exploiting Images like &#8220;<a href="http://blog.kakkoi.net/uri/aHR0cDovL21pbHcwcm0ub3JnL2V4cGxvaXRzLzQ2MTY.curie,80,302" rel="external nofollow" title="Tiff Exploit Sources at Milw0rm">TIFF</a> &#038; <a href="http://www.google.com/search?q=microsoft+jpeg+exploit" rev="google:query" rel="external">JPEG</a>&#8220;. Both of this vulnurebilities exists in Internet Explorer Browser and various microsoft windows products. While we can only make educated guesses as there is no real working proof yet.</p>
<p><tt>My doodling scenario produce this &darr;</tt></p>
<p class="note" style="padding:10px;margin:10pxl;background-color:#f9f9f9;width:95%"> Session &#8220;hacker&#8221; create a malicious server side image &rarr; proxy tunnel send to multiple email server &rarr; the curious victim open the email &rarr; steal client informations (cookie or server session cookie) &rarr; spoof the request &rarr; send RST back to client (reset) &rarr; dump the victims data in one instance. &rarr; write signature on victim email (avoid loop) &rarr; propogate using victims session &rarr; new net-worm is born</p>
<p> Try <abbr title="search">digging</abbr> around <strong>VX Heavens</strong> &#038; <strong>milw0rm</strong> Database you&#8217;ll find something to start thinkering.</p>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/security/vulnerability/email-phising-and-spam-trends/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
