
Yes we did meet up last night
What did I do? I refreshed myself on the phishing stuff following last weeks Cryptocard conversation. I was mostly working through the examples talked about in Marco Slot’s Beginners Guide to OpenID Phishing.
He describes 3 different ‘levels of phishing’ which openID is susceptible to. I’ve made the links available to our developers internally to make sure they are aware of thinking of these things.
I can’t help but wonder if you can get around the ‘level 2′ phishing approach via the use of some sort of referrer checking. I.e. are the images being loaded on this page being called from the correct OpenID login form. If not, display phishing warnings. Is that simple to get around? Or does it add a sufficient level of difficulty for the phishermen to not warrant the effort?
Feel free to debate below ![]()

Referrer checking on images is easily overcome by changing the image source to point to a proxy on the phishing server which loads the correct images from the identity provider by sending a fake referer header.
Does that add enough faff to the phish attempt to discourage it? Or is it dead simple ™?

Seems fairly simple. In effect the attacker is indistinguishable from a genuine user so there’s no way of preventing it from loading all the relevant content (text, images, stylesheets, scripts) from the identity provider. From that point it’s just a case of spitting it out again to the victim of the attack. It’s a tricky one.
Site Links
Related Sites
Community Apps
Here at PlusNet we're always trying to use clever open source things to make our lives easier. Sometimes we write our own and make other people's lives easier too!
About PlusNet
Winner of 9 out of 11 Categories in the 2008 USwitch survey. Winner of "Best Consumer ISP" at 2008 ISPA awards. Voted number 1 in the Broadband Choices 2008 survey.
© PlusNet plc All Rights Reserved. E&OE
Community Site News is powered by WordPress