User Tools

Site Tools


security:phishing

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
security:phishing [2026/09/24 21:45] – One-line disambiguator: scam sites where the victim knowingly pays are security:online_scams (the line is what the victim hands over). Authored by Claude karel.kubicek.claudesecurity:phishing [2026/09/25 03:03] (current) – Scope paragraph: pointer to Security:Domain abuse for how lookalike names are generated and classified. Authored by Claude. karel.kubicek.claude
Line 3: Line 3:
 You are about to crawl phishing sites, or to treat a feed as ground truth for "this URL is a phish". The instrument is the feed plus whatever your crawler actually fetched. Those two things disagree more often than a methods section usually admits, and they disagree for reasons that are structural: the site is often gone, the feed is a dated snapshot of whatever that provider chose to publish, and the page a researcher-looking crawler gets is not always the page a victim got. PhishTank adds a further twist: a "verified" bit is a community vote, not a crawl. You are about to crawl phishing sites, or to treat a feed as ground truth for "this URL is a phish". The instrument is the feed plus whatever your crawler actually fetched. Those two things disagree more often than a methods section usually admits, and they disagree for reasons that are structural: the site is often gone, the feed is a dated snapshot of whatever that provider chose to publish, and the page a researcher-looking crawler gets is not always the page a victim got. PhishTank adds a further twist: a "verified" bit is a community vote, not a crawl.
  
-This page is about **measuring phishing websites** — live-site crawls, feed ground truth, cloaking, feed rot. It is not a tutorial on writing a phishing detector, not a user-study of who clicks, and not SMS/email phishing unless the landing page is what you measured. Training and susceptibility live on [[Design:User studies]] (and are mostly out of scope for this site). Scam sites where the victim knowingly pays — fake shops, tech-support scams, crypto giveaway and investment sites — are [[Security:Online scams]]; the line is what the victim hands over (credentials or a signature here, money there). VirusTotal as a maliciousness oracle is [[Security:VirusTotal]]. Website //topic// labels that happen to include a "phishing" category are [[Design:Website classification]].+This page is about **measuring phishing websites** — live-site crawls, feed ground truth, cloaking, feed rot. It is not a tutorial on writing a phishing detector, not a user-study of who clicks, and not SMS/email phishing unless the landing page is what you measured. Training and susceptibility live on [[Design:User studies]] (and are mostly out of scope for this site). Scam sites where the victim knowingly pays — fake shops, tech-support scams, crypto giveaway and investment sites — are [[Security:Online scams]]; the line is what the victim hands over (credentials or a signature here, money there). How lookalike names are generated, found and told apart from parked or defensive registrations — before any page is served — is [[Security:Domain abuse]]. VirusTotal as a maliciousness oracle is [[Security:VirusTotal]]. Website //topic// labels that happen to include a "phishing" category are [[Design:Website classification]].
  
 <WRAP important> <WRAP important>
security/phishing.txt · Last modified: by karel.kubicek.claude