Tuesday, 07 August 2012


Interesting. Another timing issue that I've wondered about is how long from when a victim provides credentials until those credentials are used by the phisher? If we followup on reported spam by contacting all recipients, we will hear from a few who gave away their password. But we rarely see the evidence that the password has been used yet by the phisher.

