We Got Phished
21–30 of 156 posts
Re: We Got Phished
#22The beginning of the story is missing. PZ clicked on the link in the email because it was "received [...] from a familiar mailing list" . Did PZ trust a mailing list where anyone could post? Or did the attackers spoof the "from" field? The former may have been prevented by employee training, the latter by SPF or similar technologies.
Re: We Got Phished
#23The beginning of the story is missing. PZ clicked on the link in the email because it was "received [...] from a familiar mailing list" . Did PZ trust a mailing list where anyone could post? Or did the attackers spoof the "from" field? The former may have been prevented by employee training, the latter by SPF or similar technologies.
Or it could come from an already infected account, which might make the e-mail even less suspicious.
Re: We Got Phished
#24I use Lastpass and I just realized that it prevents phishing since it autocompletes my login info based on the domain.
Re: We Got Phished
#25I use Lastpass and I just realized that it prevents phishing since it autocompletes my login info based on the domain.
Re: We Got Phished
#26It's worth nothing the new user-image-before-password-input for Google is an anti-phishing feature. Of course, most people won't think that deeply when prompted with a password request and a similar UI.
How does it help? Can't the attacker make a query to Google for the user image and display it on the phishing page?
Re: We Got Phished
#27It's worth nothing the new user-image-before-password-input for Google is an anti-phishing feature. Of course, most people won't think that deeply when prompted with a password request and a similar UI.
How does it help? Can't the attacker make a query to Google for the user image and display it on the phishing page?
Re: We Got Phished
#28Re: We Got Phished
#29Google needs to add some optional intelligence to Chrome so that when it comes across a site with suspiciously similar design as key google urls by on a unrenognized url, it should warn the user.
Re: We Got Phished
#30Google needs to add some optional intelligence to Chrome so that when it comes across a site with suspiciously similar design as key google urls by on a unrenognized url, it should warn the user.