I imagine some payloads use JavaScript to infect a device upon clicking. They probably target Chrome, or god forbid the Samsung Internet browser. If you wanted to see the payload, just open the link in a secure sandbox environment and view the source. Congratulations to them, they just allowed you to see their 0day in the wild, and it's no longer a 0day.
Smishing
11–20 of 32 posts
Re: Smishing
#12> As software capable of zero-click exploit, Pegasus requires no user interaction to operate: ... As a result of a simple click on the URL, the spyware was granted unlimited access to every information stored on the iPhone. That's a one-click exploit, no? Pegasus has demonstrated zero-click exploits (e.g. PDF embedded in GIF), but this is not one. edit: the provided CitizenLab link [0] describes two classes of attack…
But it's not super clear cut. Like, let's say you had to open up a message on your phone for the exploit to work - you clicked the message, right? idk
Re: Smishing
#13Re: Smishing
#14> As software capable of zero-click exploit, Pegasus requires no user interaction to operate: ... As a result of a simple click on the URL, the spyware was granted unlimited access to every information stored on the iPhone. That's a one-click exploit, no? Pegasus has demonstrated zero-click exploits (e.g. PDF embedded in GIF), but this is not one. edit: the provided CitizenLab link [0] describes two classes of attack…
I'm not sure it's one-click. Visiting a page isn't exactly "clicking" - I'd expect a "click" in this sense to be like a browser asking "are you sure?" and you clicking through, or "play video". But it's not super clear cut. Like, let's say you had to open up a message on your phone for the exploit to work - you clicked the message, right? idk
Re: Smishing
#15[0] https://www.fbi.gov/scams-and-safety/common-scams-and-crimes...
Re: Smishing
#16To the puzzled: 'Smishing' = 'SMS' ∩ 'phishing' > Signs that you are getting "Smished": [...] when you receive a message from bigger service providers, (f.e. banks, post offices, or delivery services) they will mostly have their company names displayed instead of their numbers The formulation in the article may lead to a very bad advice: in some areas, scammers do display a "company name", regularly. So: a numeric se…
> The formulation in the article may lead to a very bad advice: in some areas, scammers do display a "company name", regularly. So: a numeric sender string increases the chances of the SMS being a scam; an alphanumeric sender string /does not/ decrease the chances of the SMS being a scam. Just curious, which part of the text did you understand this way? If I would guess it could be with this part: > The number of the…
Well, there is a big image below, visually more impactive than the pasted paragraph, that goes "Messages from bigger services #do not# display their numbers". Yes, but neither do scammers.
You are trying to discriminate legitimate entities L from impersonators L̅ through properties P, and especially define ways to identify L̅. You state that P(L), but that says nothing of L̅. And in fact, it is P(L̅) also - logical exhaustion.
Logically the sentence works, because it implies "If messages display their numbers, they are not from bigger services". But in terms of effectiveness in communication, if put in the context of "how to recognize a scammer", the original may be misleading - because there (see the picture) you are focusing on the alphanumeric, not on the number, and the alphanumeric is not a criterion - the number is.
The intention was to state "do not trust numbers". But in that context it is important to stress "do not trust alphanumericals either".
Re: Smishing
#17It would be great if a section about BEC [0] was included. At $WORK we see a lot of "Smishes" that pretend to be our CEO/CTO that ask for the user to send them money. E.g. "Hello it's $CEO, I'm in a meeting currently and need your help. Can you send me 300 dollars in apple gift cards?" [0] https://www.fbi.gov/scams-and-safety/common-scams-and-crimes...
Re: Smishing
#18To the puzzled: 'Smishing' = 'SMS' ∩ 'phishing' > Signs that you are getting "Smished": [...] when you receive a message from bigger service providers, (f.e. banks, post offices, or delivery services) they will mostly have their company names displayed instead of their numbers The formulation in the article may lead to a very bad advice: in some areas, scammers do display a "company name", regularly. So: a numeric se…
Re: Smishing
#19It would be great if a section about BEC [0] was included. At $WORK we see a lot of "Smishes" that pretend to be our CEO/CTO that ask for the user to send them money. E.g. "Hello it's $CEO, I'm in a meeting currently and need your help. Can you send me 300 dollars in apple gift cards?" [0] https://www.fbi.gov/scams-and-safety/common-scams-and-crimes...
I know this sounds cold, but I feel like some of these scams are really just a stupidity tax. How do people operate in the outside world if they believe that the CEO would be hitting them up for gift cards?
George Carlin said "think of how stupid the average person is, then realize that half of them are stupider than that" https://www.youtube.com/watch?v=AKN1Q5SjbeI
Re: Smishing
#20To the puzzled: 'Smishing' = 'SMS' ∩ 'phishing' > Signs that you are getting "Smished": [...] when you receive a message from bigger service providers, (f.e. banks, post offices, or delivery services) they will mostly have their company names displayed instead of their numbers The formulation in the article may lead to a very bad advice: in some areas, scammers do display a "company name", regularly. So: a numeric se…
The elephant in the room here is that SMS is not a medium where integrity or authenticity of a message can be guaranteed—which is one of the big reasons it’s such a popular medium for phishing.