An Innovative Phishing Style
51–60 of 83 posts
Re: An Innovative Phishing Style
#52Earlier quoted context omitted.
Unthemed Windows & Mac OS will be convincing to a lot, Linux will be pretty hard. Then again those who tinker with their computers are unlikely to fall into this trap.
This specific phishing website mimics an ingame website for Counter-Strike Global Offensive, a shooter game with the vast majority of players using Windows. Linux isn't supported at all and while the game technically runs on a Mac most people don't (or play it with Bootcamp). I would not be surprised if 99% of the audience for this website is using Windows, the vast majority with default themes (and the ones without…
Re: An Innovative Phishing Style
#53Earlier quoted context omitted.
It's a common sales technique. People are willing to give their CC details for a free plan since they are not charging anyway. But by the time your site grows, this takes away the friction of switching to a paid plan. Mailgun does the same.
Maybe it's a cultural thing? I've never come across a situation where anyone would give their CC number for a free service. That gives a really shady impression. Or expose myself to that risk.
Re: An Innovative Phishing Style
#54Earlier quoted context omitted.
Well, first, phishing is not calling someone, but at our bank we train our employees monthly about phishing by testing them, and if they fail they must take a class. Serial failures could result up to termination. So, how much you wanna bet?
> So, how much you wanna bet? You're not resigned enough to be on an infosec team, and if you're not on an infosec team you probably don't know the true percentage of how many employees are failing over and over (it's a ton, it's always a ton). I'd go big :)
I mean, other than the attempts to foster a relationship between bank staff and the tech people through things like days of letting tech people hang out and try and be helpful at branches in order to "see what real difference they could make" - and that laegely ending up being a fairly regular educational exercise for everyone involved theres two problems I see:
1. All the phone calls into branches are monitored (you may have noticed so many "we will record this call and it may be monitored" messages - they arent kidding) and if certain key words, or even key tones of voice are picked up someone from a relevant team silently dials onto the call to listen in. 2. The general process for anyone not in it interacting with any IT system is to click a button on their screen which generates a 6 digit pin and if you cant match that pin with the person talking to you and dont confirm success then alerts go out immediately.
And given the hit rate on the "generate pin" api, tellers are definitely using it properly.
So i'd be inclined to go pretty small if I where to bet at all.
Not sure why the assumption that you can social engineer your way onto any half way competent institution still persists,but nowadays, as far as I know, you have to pick the really low hanging fruit for someone to let you in so easily.
Re: An Innovative Phishing Style
#55In this case it looks like the 3rd party service required deep integration with Steam so it was probably unavoidable, but many sites use OAuth as a crutch because they don’t want to bother butlding their own sign-in system.
I’ve stopped using services if they don’t provide an option to create a site-specific username and password. Facebook login the only way to sign up for your site? How about no.
Re: An Innovative Phishing Style
#56Wanna bet that if I call anybody working in a bank, telling them I am from the IT department and I want them to check the new login page (done the way described in this article), they will enter there their login & password?
Well, first, phishing is not calling someone, but at our bank we train our employees monthly about phishing by testing them, and if they fail they must take a class. Serial failures could result up to termination. So, how much you wanna bet?
tbh, i'm surprised they don't have bank accounts emptied out regularly, but they're sort of small(limited to grocery store employees), so maybe its just nobody has seen it.
Re: An Innovative Phishing Style
#57Earlier quoted context omitted.
> So, how much you wanna bet? You're not resigned enough to be on an infosec team, and if you're not on an infosec team you probably don't know the true percentage of how many employees are failing over and over (it's a ton, it's always a ton). I'd go big :)
Personally I'd be pretty sure that, at least at the bank I currently work at, this would rarely ever work. I mean, other than the attempts to foster a relationship between bank staff and the tech people through things like days of letting tech people hang out and try and be helpful at branches in order to "see what real difference they could make" - and that laegely ending up being a fairly regular educational exerci…
At which attackers shift their targets from a bank to a mobile phone provider... :(
Re: An Innovative Phishing Style
#58Re: An Innovative Phishing Style
#59a phising attemp that emulates a OS window in html is lame and should have been spoted a mile away. real popups open as tabs to begin with.
Re: An Innovative Phishing Style
#60Earlier quoted context omitted.
It's a common sales technique. People are willing to give their CC details for a free plan since they are not charging anyway. But by the time your site grows, this takes away the friction of switching to a paid plan. Mailgun does the same.
Maybe it's a cultural thing? I've never come across a situation where anyone would give their CC number for a free service. That gives a really shady impression. Or expose myself to that risk.