(The quickest way to register)

Forum

Dear visitor! The webpage is only available in English. We're sorry for the inconvenience.
  1. User picture
    • Raph Minus1Kidney on Wed 07 Oct 2009
    • 12:24:45 PM UTC

    Domain vs Exact URL...

    Hi,

    We got a phishing tax email with a refund_form.pdf.htm attachment, where the "Submit Form" button goes to http:www.ukxgen.biz/buk/php which then redirects the browser to http://www.hmrc.gov.uk/index.htm.

    PhishTank and in turn WOT has got the domain name http://www.ukxgen.biz and correctly shows a warning.

    However, WOT does not warn for the exact URL http://www.ukxgen.biz/buk.php .

    What can we do about this?

    Cheers
    Raph

Comments:

  1. User picture
    • Sami on Wed 07 Oct 2009
    • 12:34:00 PM UTC

    Re: Domain vs Exact URL...

    WOT does not warn for the exact URL

    It would, but the site seems to redirect you to a safe website and thus the add-on doesn't have time to show the warning. If you use blocking, the add-on stops the site from loading though.

  2. User picture
    • Havends on Wed 07 Oct 2009
    • 02:16:39 PM UTC

    If you had been using

    If you had been using Firefox 3 or later, your browser would have issued a warning:

    Reported Web Forgery!
    This web site at http://www.ukxgen.biz has been reported as a web forgery and has been blocked based on your security preferences.

    If you were using Opera (I do know that Opera doesn't have a WOT "addon"), you would have got this warning message:

    Fraud Warning
    The page you are trying to open has been reported as fraudulent. It will likely attempt to trick you into sharing personal or financial information. Opera Software strongly discourages visiting this page.

    So, I infer that you might have been using Internet Explorer. If you are really worried about your security, then you might want to consider switching to Firefox (preferred) or Opera (WOT can be used with it, but doesn't give so much relaxation to the hand ;)).

    Anyway, just as Sami told, since the URL redirects to a safe site, the add-on might not get enough time to show the warning.
    _______________________________________________

    Let's make the Internet a better place to browse.
    WeJudgeUs - Because no one can judge us better. :)

  3. User picture
    • Raph Minus1Kidney on Wed 07 Oct 2009
    • 03:55:12 PM UTC

    WOT does not warn for the exact URL in IE6...

    Hi WeJudgeUs,

    I'm happy to confirm, WOT on IE8 and FireFox 3.5.3 does block Exact URLs. So, all of my friends are protected at home.

    Additionally, for those interested, the refund_form.pdf.htm even does some validation checking on the "Credit Card Number:" in FireFox 3.5.3.

    Unfortunately, WOT on IE6 is not currently doing Exact URL blocking, which is our corporate desktop standard. The site is going to be blocked at the Proxy.

    Thanks for all of the quick responses.

    Cheers
    Raph

    • User picture
      • Sami on Wed 07 Oct 2009
      • 04:37:00 PM UTC

      Re: WOT does not warn for the exact URL in IE6...

      Works for me on IE6 too, the site is blocked no matter if I open the URL that redirects me to another site or the main page. Are you sure you have the same settings in your IE6 as you do in your other browsers? Which version of the IE add-on are you using?