Due February 13th.

The assignment was about Phishing. Your assignment is:

Locate three "live" phishing sites. (I'm helping with that - I've posted 250 sites from yesterday on the class website:

http://www.cis.uab.edu/cs436/phishing/

More files will be added as the week goes on, but for now, you can start with:

feb06.2008.pm1.html Here's what to do:

  1. - take a screen shot of the phish
  2. - do WHOIS against the domain name and record all the email addresses you find there. print the WHOIS data.
  3. - do WHOIS against the IP address (use PING on the machine name to find the IP) and record all the email addresses you find there. print the WHOIS data.
  4. - if you can, find the "official contact" for the brand or bank and let them know about the phish as well.
  5. - email all of the contacts you have recorded to let them know about the phishing site, and print me the emails you send.
  6. - record any email replies you receive, even automated ones.
  7. - if you succeed in getting the phishing site "fixed" or taken down, get me a screen shot of the successful takedown. Do this three times for full credit. FOR THE WHOIS -- there are two sites that I strongly recommended to the class: whois.domaintools.com and www.completewhois.com ======================================= If you have questions, let me know. --- gar@uab.edu