Gmail phishing redux
Just noticed over at Commtouch Cafe that the gmail trickery is ongoing . They did a good job of comparing the real gmail site with a forgery, pointing out the obvious differences. Got me to thinking so I did a little search (using google!) and came up with several phonies. (Search criteria: intitle:”gmail: email from google” “lots of space” “mobile access” “less spam”) I don’t have the time right now, but it would be an interesting exercise to find linked pages… you’d probably find some XSS on the originating site, or an evil web proxy at the other end. Maybe a project for my next layover at the airport.

real Gmail page

Fake Gmail screencap

Leave a Reply