Community Discussions and Support
Why does Pmail accept some phishing URLs

Michael,

Thank you for explaining so clearly what's going on!

I'm really interested in trying it out now, but I believe I'll try your suggestion about editing the CNM file. Thanks for that tip, too! (Paranoid? Who, me? [:^)] )

Dave

 

 

<p>Michael,</p><p>Thank you for explaining so clearly what's going on! </p><p>I'm really interested in trying it out now, but I believe I'll try your suggestion about editing the CNM file. Thanks for that tip, too! (Paranoid? Who, <i>me?</i> [:^)] ) </p><p>Dave</p><p> </p><p>  </p>

I got an obvious phishing Email. The HTML text contained a hyperlink where the '<a' tag's src pointed to one web site, while the readable text read 'http://twitter.com/account/.....'

I expected Pegasus (with BearHTML) to block this, but it the cursor remains a 'hand' instead of the expected 'stop' sign. Not that it fools anyone, but I'm curious why this one is not being flagged.

 

&lt;p&gt;I got an obvious phishing Email. The HTML text contained a hyperlink where the &#039;&amp;lt;a&#039; tag&#039;s src pointed to one web site, while the readable text read &#039;http://twitter.com/account/.....&#039;&lt;/p&gt;&lt;p&gt;I expected Pegasus (with BearHTML) to block this, but it the cursor remains a &#039;hand&#039; instead of the expected &#039;stop&#039; sign. Not that it fools anyone, but I&#039;m curious why this one is not being flagged.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;

Please send me a copy of one of these messages (irelam@telus.net)

Thanks

     Martin

&lt;p&gt;Please send me a copy of one of these messages (irelam@telus.net)&lt;/p&gt;&lt;p&gt;Thanks&lt;/p&gt;&lt;p&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp; Martin &lt;/p&gt;

I emailed you the CNM file as an attachment. Let me know if you didn't get it - it's bound to be snared by any spam filter that looks at it.

Eduardo

 

&lt;p&gt;I emailed you the CNM file as an attachment. Let me know if you didn&#039;t get it - it&#039;s bound to be snared by any spam filter that looks at it.&lt;/p&gt;&lt;p&gt;Eduardo&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;

No sign of it so far.  Could you just mail me the A tag without the < and >, and the text string that gets displayed please

Martin

&lt;p&gt;No sign of it so far.&amp;nbsp; Could you just mail me the A tag without the &amp;lt; and &amp;gt;, and the text string that gets displayed please&lt;/p&gt;&lt;p&gt;Martin &lt;/p&gt;

I just sent the offending HTML via email.

Eduardo

 

&lt;p&gt;I just sent the offending HTML via email.&lt;/p&gt;&lt;p&gt;Eduardo&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;

Where did you send it to?  I have seen nothing yet :-((

Where did you send it to?&amp;nbsp; I have seen nothing yet :-((

My server says it talked to your server and the email was accepted. Here's the log from my Mercury. I believe 204.209.205.52 is the MX server for telus.net Times are PDT, and are accurate.

T 20100912 183537 4c8c97e8 Begin processing job MO00009A from subelman@markmatrix.com
T 20100912 183538 4c8c97e8 Established ESMTP connection to 204.209.205.52
T 20100912 183538 4c8c97e8 MAIL FROM:<subelman@markmatrix.com> SIZE=2270
T 20100912 183538 4c8c97e8 250 Ok
T 20100912 183538 4c8c97e8 RCPT TO:<irelam@telus.net>
T 20100912 183539 4c8c97e8 250 Ok
T 20100912 183539 4c8c97e8 Connection closed normally.

The other email that never made it had a similar log entry.

&lt;p&gt;My server says it talked to your server and the email was accepted. Here&#039;s the log from my Mercury. I believe 204.209.205.52 is the MX server for telus.net Times are PDT, and are accurate. &lt;/p&gt;&lt;p&gt;T 20100912 183537 4c8c97e8 Begin processing job MO00009A from subelman@markmatrix.com T 20100912 183538 4c8c97e8 Established ESMTP connection to 204.209.205.52 T 20100912 183538 4c8c97e8 MAIL FROM:&amp;lt;subelman@markmatrix.com&amp;gt; SIZE=2270 T 20100912 183538 4c8c97e8 250 Ok T 20100912 183538 4c8c97e8 RCPT TO:&amp;lt;irelam@telus.net&amp;gt; T 20100912 183539 4c8c97e8 250 Ok T 20100912 183539 4c8c97e8 Connection closed normally. &lt;/p&gt;&lt;p&gt;The other email that never made it had a similar log entry. &lt;/p&gt;

[quote user="subelman"]I got an obvious phishing Email. The HTML text contained a hyperlink where the '<a' tag's src pointed to one web site, while the readable text read 'http://twitter.com/account/.....'

I expected Pegasus (with BearHTML) to block this, but it the cursor remains a 'hand' instead of the expected 'stop' sign. Not that it fools anyone, but I'm curious why this one is not being flagged.[/quote]

(Apologies if this has already been answered, but I didn't find it in a search.) I'm now having the above problem occur with Pegasus 4.62, Build 191, using IERenderer (which is GREAT otherwise!). My past versions of Pegasus always blocked phishing hyperlinks (which is nice reassurance that one won't make that one fatal "slip"), but I've received a number of phishing e-mails lately that don't trigger any blocking from Pegasus. Only by looking at the "raw view" or by copying/pasting the link target into Word or Wordpad can I see that the underlying link is completely different from the one displayed.

And yes, I have Tools > Options > Incoming Mail > Hyperlinks > "Check for suspicious..." selected.

Thanks.

[quote user=&quot;subelman&quot;]I got an obvious phishing Email. The HTML text contained a hyperlink where the &#039;&amp;lt;a&#039; tag&#039;s src pointed to one web site, while the readable text read &#039;http://twitter.com/account/.....&#039;&lt;p&gt;I expected Pegasus (with BearHTML) to block this, but it the cursor remains a &#039;hand&#039; instead of the expected &#039;stop&#039; sign. Not that it fools anyone, but I&#039;m curious why this one is not being flagged.[/quote]&lt;/p&gt;&lt;p&gt;(Apologies if this has already been answered, but I didn&#039;t find it in a search.) I&#039;m now having the above problem occur with Pegasus 4.62, Build 191, using IERenderer (which is GREAT otherwise!). My past versions of Pegasus always blocked phishing hyperlinks (which is nice reassurance that one won&#039;t make that one fatal &quot;slip&quot;), but I&#039;ve received a number of phishing e-mails lately that don&#039;t trigger any blocking from Pegasus. Only by looking at the &quot;raw view&quot; or by copying/pasting the link target into Word or Wordpad can I see that the underlying link is completely different from the one displayed. &lt;/p&gt;&lt;p&gt;And yes, I have Tools &amp;gt; Options &amp;gt; Incoming Mail &amp;gt; Hyperlinks &amp;gt; &quot;Check for suspicious...&quot; selected. &lt;/p&gt;&lt;p&gt;Thanks. &lt;/p&gt;

[quote user="Dave Bellerophon"](Apologies if this has already been answered, but I didn't find it in a search.) I'm now having the above problem occur with Pegasus 4.62, Build 191, using IERenderer (which is GREAT otherwise!). My past versions of Pegasus always blocked phishing hyperlinks (which is nice reassurance that one won't make that one fatal "slip"), but I've received a number of phishing e-mails lately that don't trigger any blocking from Pegasus.[/quote]

It's not "the above problem" since IERenderer works differently: It only does the check on clicking the URL since it might otherwise block further Pegasus Mail actions if just doing the check on hovering (it starts with a DNS look-up, e.g., for checking whether the target is valid at all, then proceeds with further checks): Click it and you'll most probably get what you want (if you don't dare to edit the CNM file in your new mail directory to point to a harmless website instead).

&lt;p&gt;[quote user=&quot;Dave Bellerophon&quot;](Apologies if this has already been answered, but I didn&#039;t find it in a search.) I&#039;m now having the above problem occur with Pegasus 4.62, Build 191, using IERenderer (which is GREAT otherwise!). My past versions of Pegasus always blocked phishing hyperlinks (which is nice reassurance that one won&#039;t make that one fatal &quot;slip&quot;), but I&#039;ve received a number of phishing e-mails lately that don&#039;t trigger any blocking from Pegasus.[/quote]&lt;/p&gt;&lt;p&gt;It&#039;s not &quot;the above problem&quot; since IERenderer works differently: It only does the check on clicking the URL since it might otherwise block further Pegasus Mail actions if just doing the check on hovering (it starts with a DNS look-up, e.g., for checking whether the target is valid at all, then proceeds with further checks): Click it and you&#039;ll most probably get what you want (if you don&#039;t dare to edit the CNM file in your new mail directory to point to a harmless website instead).&lt;/p&gt;
			Michael
--
IERenderer's Homepage
PGP Key ID (RSA 2048): 0xC45D831B
S/MIME Fingerprint: 94C6B471 0C623088 A5B27701 742B8666 3B7E657C
live preview
enter atleast 10 characters
WARNING: You mentioned %MENTIONS%, but they cannot see this message and will not be notified
Saving...
Saved
With selected deselect posts show selected posts
All posts under this topic will be deleted ?
Pending draft ... Click to resume editing
Discard draft