MICROSOFT HAS finally come up with a plan to combat those pesky 'phishing' mails that attempt to persuade gullible users to type their passwords and bank account numbers into fake websites.
The practice, which we have reported on several times, is designed to harvest passwords and access codes to online centres of money management like Paypal, E-gold, Barclay's Bank and Citibank. It is based on a little-known feature of web addresses, which allows the user name for logon to be encoded into the web address in the form
http://username@www.webaddress.com/. The 'phishers' send emails to unsuspecting netizens that include urgent entreaties to log in to a certain web site. The emails include clickable addresses in the form
http://www.trustedsite.com.bla.bla.b...@evilsite.net/ These addresses, or URLs, are difficult to distinguish at first glance from legitimate URLs actually belonging to a real bank etc.
More on this
here.