Roy Johnson has asked for the wisdom of the Perl Monks concerning the following question:

Whenever I get a phishing email, I like to go to the site and fill in the form with some bogus and insulting values. Turning off Javascript in the browser usually makes it accept anything you care to fill in. Has anybody written an automated version of this with WWW::Mechanize? I'm not looking to mount a DOS attack, but I'd like to have it submit junk every few seconds for a hundred submissions or so. I figure it would help obscure the valid information that any suckers might have entered. (Yes, I do report the sites to appropriate authorities, as well.)

If it hasn't been written and I write it, would it be worthwhile to post it here?


Caution: Contents may have been coded under pressure.

Replies are listed 'Best First'.
Re: Automatic phish form filler
by chromatic (Archbishop) on May 07, 2005 at 20:46 UTC

    Is that any more legal or ethical than phishing?

    If you want to write and post something, I suggest that you write something that can notify the hosting provider -- with human oversight.

      It's sort of like beating up the neighbourhood drug dealers in an attempt to pursuade them to stop selling drugs. It's not legal, although they're unlikely to turn you in to the cops, it's only ethical if you think that the ends justifies the means, and, most likely, all you'll end up doing is getting them to move on to new victims making them someone else's problem.

      But, for those with a mildly violent streak, it'll feel good while you're doing it ;-)

        Without getting in to a legal debate since I'm not in any respects a lawyer, how on earth is giving random information to a random webpage on the internet illegal? Does that mean everytime you sign up for one of those ridiculous "phpbb" scripts and you aren't 100% truthful, you're breaking the law? I could see how falsifying information to legal entity, such as the government or an actual bank you're trying to sign a contract with would be illegal, but I don't see phishers falling in to that category.
      Of course it's "more legal" than phishing. There are laws against phishing, and there are no laws against giving phishers false information. And since there's no attempt to harm or defraud anyone, it's more ethical, too.

      Do you want to try to suppport your suggestion that it's illegal and/or unethical?


      Caution: Contents may have been coded under pressure.

        Is there an effective difference between distributing a program that submits random information to an alleged phishing site a thousand times and distributing a DoS client, besides "Oh, but I don't like those people?"

        Do all phishing sites live on their own boxes with their own IP addresses, leased lines, and networks, or is there a possibility that there are innocent bystanders nearby?

Re: Automatic phish form filler
by chas (Priest) on May 07, 2005 at 23:47 UTC
    I considered doing something of that sort recently. However, I worried about the fact that I might just be adding to the volume of web traffic (and perhaps even more than I intended if the phishers used some scripts to act on the bogus info.)
    In addition, I've heard that there are laws against "interfering with an electronic system" (and that could very well be the case even if the system interfered with was used to phish.)
    I may be incorrect in my thinking...I really don't know...I just had a bad feeling about it even though the phishing scams are extremely annoying. Just my 1.5 cents worth...
    chas