I recently blogged about the phishing pages that I found during a Tour of the Google Blacklist. In that posting I noted how I was surprised to find that Yahoo! was actually hosting phishing sites designed to phish Yahoo! credentials. Not surprisingly, Yahoo! quickly removed the pages that I'd pointed out. When questioned about the issue by Network World news editor Paul McNamara, Yahoo! stated that they "proactively scan hosted sites for potential phishing activity and deactivate suspicious sites" and that they "are continually improving and modifying [their] efforts to remain at the forefront of the industry". Fair enough, perhaps Yahoo! had not been aware of the Google blacklist and my blog posting had encouraged them to add monitoring the list to their "use of enhanced technologies, industry collaboration, public policy efforts, and increasing consumer awareness", which they are apparently employing to combat phishing. I therefore revisited the Google blacklist today and was disappointed to see that it still includes active phising sites hosted by Yahoo! Geocities. The good news for Yahoo! - they're far from being the worst offender.
This time around, I decided to see which hosting providers are aiding phishers by maintaining their websites - for free. To do this, I spent a couple of hours sifting through various publicly available resources including search engines, phishing archives, the Google Blacklist and the Google Hashed/Encoded Blacklist. Sadly, I found that most free hosting providers are contributing to the problem of phishing. Given that I was able to find dozens of sites with minimal effort and no special resources, it is clear to me that the hosting providers are making no effort whatsoever to combat this problem. Why? Do they lack the resources? Is the challenge too difficult? I have a different theory. I believe that they benefit from the ad revenue that these web pages provide. They choose not to combat the problem because they are profiting from it.
What can be done to change this? Hosting providers must be held responsible for the content that is hosted on their servers. Companies such as HSBC, MySpace, Microsoft (Hotmail) and eBay were among the targets of the phishing sites that I investigated. It is their clients that are paying the price for this and it is therefore time that such companies took action. MySpace has repeatedly removed content when facing legal action for copyright infringement. I suspect that the free hosting providers would try a little harder if they likewise faced legal action for their negligence when combating phishing.
Below, from least to most prolific offenders are the free hosting sites which I uncovered this evening. All were active phishing sites at the time of this posting.
FreeWebPage.org
http://mypics4u6969.freewebpage.org/mypics2.html
50 Megs
http://sgi.com.50megs.com/SWcgi3-bin0-ISAPIdll-viewtheitem-4583745438.htm
Tripod (Lycos)
http://jokaowns.tripod.com/
http://daulamoe.tripod.com/
Geocities (Yahoo!)
http://www.geocities.com/maria_bitch69/album_photo.html
http://www.geocities.com/myphotos30021/
http://www.geocities.com/sweet_aqnes/Album_Photo.html
http://www.geocities.com/you_want_my_cookies/
http://www.geocities.com/sweet_angel_eyez_of_tears/
http://www.geocities.com/lxxl_kiss_me_fool_lxxl/
http://www.geocities.com/sydneypulse/
http://www.geocities.com/ravish334/yahoophoto.htm
...and by far the worst offender (I stopped at 50+, but there's plenty where that came from)...
Angelfire (Lycos)
http://www.angelfire.com/ab7/serviceupdate/index.htm
http://www.angelfire.com/goth/login0/index.htm
http://www.angelfire.com/punk5/xxhaterxx4/
http://www.angelfire.com/blog/myspacelogin.error
http://www.angelfire.com/band2/hahheresahint/
http://www.angelfire.com/blog/myspace-login
http://www.angelfire.com/blog/myspacecom0/
http://www.angelfire.com/ultra2/cambo/
http://www.angelfire.com/funky/myspace1/
http://www.angelfire.com/funky/fakemyspace/
http://www.angelfire.com/ultra2/iocinlin/1234567890.html
http://www.angelfire.com/hiphop/rapperzz/
http://www.angelfire.com/dc2/box1/login.html
http://www.angelfire.com/ab/ljshouse/
http://www.angelfire.com/blog/myspcelogin
http://www.angelfire.com/blog/ihatemidgets619/
http://www.angelfire.com/blog/sizeofmylad-login
http://www.angelfire.com/blog/anime6idk/miespacio.htm
http://www.angelfire.com/crazy2/wowo30/ebayo.html
http://www.angelfire.com/ct3/ebaydll
http://www.angelfire.com/blog/password_recovery/login
http://www.angelfire.com/stars5/freeallstars4u/
http://www.angelfire.com/folk/x_jroc_x/haha.html
http://www.angelfire.com/me5/hawaiian/Sign_in.html
http://www.angelfire.com/oz/yahoox2/
http://www.angelfire.com/sk3/hotmail.com/
http://www.angelfire.com/tn3/cardandboardtournies/
http://www.angelfire.com/yt3/liloohaykid/
http://www.angelfire.com/magic/hawaiianstud96817/Log_in.html
http://www.angelfire.com/hiphop3/superstarz/chat.html
http://www.angelfire.com/comics/behnamshayani/Picture.html
http://www.angelfire.com/freak2/friendship0/card.html
http://www.angelfire.com/goth/account/
http://www.angelfire.com/droid/hairytick/update2.html
http://www.angelfire.com/film/tahirrizvi/hotmail.htm
http://www.angelfire.com/in/revolutionize/hotmail.html
http://www.angelfire.com/retro/hackers/java-y.htm
http://www.angelfire.com/mi4/anoop/ServiceLogin.htm
http://www.angelfire.com/crazy2/hobbix/
http://www.angelfire.com/pq/fos2/
http://www.angelfire.com/un/hotmailauthenticity/
http://www.angelfire.com/alt/aimexpress/index2.html
http://www.angelfire.com/cantina/test2/
http://www.angelfire.com/blog2/crimerecord/
http://www.angelfire.com/hi5/bot_remover/
http://www.angelfire.com/ult/dream10/
http://www.angelfire.com/in4/member/yahoomail.html
http://www.angelfire.com/blog/rahul180proof/
http://www.angelfire.com/ia3/falcon23/Yahoo_New.htm
http://www.angelfire.com/blog2/myspacepwnd/
http://www.angelfire.com/biz7/myspace_error/
http://www.angelfire.com/droid/dd3fgadsgasd554/pic.html
http://www.angelfire.com/music2/JDVONmusic/privatephotos.htm
http://www.angelfire.com/funky/andrews/
Why can't we all just get along?
- michael
Posted
02-09-2007 1:15 AM
by
erik.peterson