funsec mailing list archives

Re: Is it phish, or is it Amex?


From: "Rob, grandpa of Ryan, Trevor, Devon & Hannah" <rmslade () shaw ca>
Date: Wed, 4 Nov 2009 21:15:02 -0800

Date sent:              Wed, 04 Nov 2009 16:32:34 -0500
From:                   Rich Kulawiec <rsk () gsp org>

They don't send from replyable addresses.

Ah, yes.  I did try to send them my rant.  The "From" address bounced.

Fortunately, they had also populated the "Reply to" field, with a different address.

It also bounced.

What level of cluelessness would inspire such behaviour?

Instead of sending from a subdomain, they sometimes register another
domain just for email.

That too.  The two aforementioned addresses came from different domains: 
service.americanexpress.com and welcome.aexp.com


======================  (quote inserted randomly by Pegasus Mailer)
rslade () vcn bc ca     slade () victoria tc ca     rslade () computercrime org
         Justify my text?  I'm sorry but it has no excuse.
victoria.tc.ca/techrev/rms.htm blog.isc2.org/isc2_blog/slade/index.html
http://blogs.securiteam.com/index.php/archives/author/p1/
http://twitter.com/NoticeBored http://twitter.com/rslade
_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: