[Dshield] Interesting change in Phishing

Mister Coffee live4java at stormcenter.net
Thu Feb 1 23:36:16 GMT 2007

Mark wrote:
> Hello,
> I received an "auto-responder" from a mail list
> informing me a mail I had purportedly sent was being
> held for moderator review. Issue is I never sent such
> an email. The email offered a link to cancel this
> post.
> This is a rather unique change as most recipients
> first reaction would be to "cancel the post" as it
> obviously didn't come from them. Joe Six-Pack is
> likely to click on it because he doesn't want some
> other Joe Six-Pack sending stuff to lists using his
> email.
> Below is the actual email with the link broken up. I
> didn't click as I have zero time to "play" with it.
> -Mark
> Your mail to 'debian-tl' with the subject
>     barberie bank
> Is being held until the list moderator can review it
> for approval.
> The reason it is being held:
>     Post by non-member to a members-only list
> Either the message will get posted to the list, or you
> will receive notification of the moderator's decision.
>  If you would like to cancel this posting, please
> visit the following URL:
> http://banwa<dot>upm<dot>edu<dot>ph/cgi-bin/mailman/confirm/debian-tl/ea8d856f2c413db8d77fc369922b9eaca8fd405d
That url is actually the right one for the debian-tl mailing list. My 
guess would be this was a legit response from the host in response to a 
spam that had your From: address spoofed.

Someone actually -on- the list could probably confirm.


More information about the list mailing list