
Netcraft Anti-Phishing Extension
Phishing is a name derived from the notion of “fishing for information”, and “phreaking”. It is a simple concept whereby fraudsters attempt to trick would-be victims into disclosing sensitive personal details — their bank account details are often particularly attactive — so that the attacker may then exploit the information gathered to masquerade as the victim, often to access their online bank account. Netcraft first launched its anti-phishing system in 2005 which carefully validates community-reported phishing sites before blocking the attack. Well over 6.5 million unique phishing sites have been detected and blocked by Netcraft’s system to date [August 2013]. Netcraft’s phishing feed is used in all major web browsers and it is also licensed by many of the leading anti-virus, content filtering, web-hosting and domain registration companies. At least three separate third-party studies have found Netcraft’s anti-phishing blocklist to be the most comprehensive feed available.


Netcraft makes the list of phishing sites reported by the Toolbar community and validated by Netcraft available as a continuously updated feed suitable for network administrators and internet service providers.
Registrars, hosting providers and ISPs are able to provide a footprint of their IP addresses, name servers and WHOIS servers, such that when we validate a phishing report, they receive an alert if the phishing site is using any aspect of their infrastructure.
While the majority of phishing attacks run over HTTP, a significant number run on sites for which SSL certificates have been issued. In July 2012 alone, Netcraft found phishing attacks using a total of 505 unique valid SSL certificates from widely trusted issuers.
A tool for domain registrars to analyse the likelihood that new domains will be used for fraudulent activities. The service identifies domains which are deceptively similar to legitimate websites run by banks and other institutions commonly targeted by phishing attacks.
Once a phishing site has been detected, Netcraft responds with a set of actions which will significantly limit access to the site immediately, and will ultimately cause the fraudulent content to be eliminated.