However, this has led to the evolution of more sophisticated anti-phishing filters that are able to recover hidden text in images.These filters use OCR (optical character recognition) to optically scan the image and filter it.An example of a phishing email, disguised as an official email from a (fictional) bank.

To avoid anti-phishing techniques that scan websites for phishing-related text, phishers have begun to use Flash-based websites (a technique known as phlashing).

Some phishing scams use Java Script commands in order to alter the address bar.

These types of attacks (known as cross-site scripting) are particularly problematic, because they direct the user to sign in at their bank or service's own web page, where everything from the web address to the security certificates appears correct.

Note the misspelling of the words received and discrepancy as recieved and discrepency.

Also note that although the URL of the bank's webpage appears to be legitimate, the hyperlink would actually be pointed at the phisher's webpage.

