Live data from Hacker News

Want to piss off your IT department? Are the links not malicious looking enough?

phishyurl.com

41–50 of 335 posts

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#41
post #18

I know it's a joke and I had a sensible chuckle, but if you want to routinely use it at work, just keep in mind that it's probably gonna make things worse. Since you can't exhaustively enumerate every good thing or every bad thing on the internet, a lot of security detection mechanisms are based on heuristics. These heuristics produce a fair number of false positives as it is. If you bring the rate up, it just increa…

I think the lesson here is that any link in an email is bad. We should just block all of them.

Come on man, don’t be so uptight. We can’t just be 100% max security all the time or no one will want to do business. A little bit of risk for clicking a link is worth the convenience.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#42
post #18

Earlier quoted context omitted.

I think the lesson here is that any link in an email is bad. We should just block all of them.

Why not address the problem at its real source and just block emails entirely?

Middle management would be very unhappy about that. That would take away another thing of making them very important (sure-sure) and desperately needed by the company (yeah-yeah) to provide the essential KPI metrics (oh-oh!) on how the company is performing. On all hands meetings of course.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#43

All of this reminds me of a hilarious situation at a previous employer. As is standard corporate practice, they used to tell people to inspect links by hovering over them to confirm that they lead to the official website of the sender. People kept falling for phishing links though, so they got a Trend Micro device to scan emails, which also rewrote every link in it to point to their URL scanning service, which means…

I had the opposite funny experience. When I worked for Global MegaCorp, they would occasionally send out phishing emails and if you clicked on a link it would be recorded and you would have to do trainings if you got fooled a couple times. Eventually everyone learned to stop clicking on links on emails. That's good. However, they sent out a yearly survey to get feedback from all the employees and no one clicked the l…

>... they had to send out follow up emails saying the original emails are legit and it's ok to click the links in them.

Sounds like something a phisher would do. Better not click.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#44
post #9

Not bad! https://carnalflicks.online/var/lib/systemd/coredump/logging...

Not going to lie, I was expecting this[1]. Maybe it's just not done on HN. 1: https://pc-helper.xyz/scanner-snatcher/session-snatcher/cred...

Fantastic link, very educational.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#46
Real evil would be a kind of reverse-psychology:

1. Make a site like this.

2. Wait for people to try it out with an URL that goes to a significant site (bank, social media, email, etc.)

3. Allow a bit of normal use, then secretly switch the link so that further visitors land on a corresponding phishing site.

4. Having just dismissed a bunch of "obviously fake" warning signs, people may be less alert when real ones arrive.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#47

All of this reminds me of a hilarious situation at a previous employer. As is standard corporate practice, they used to tell people to inspect links by hovering over them to confirm that they lead to the official website of the sender. People kept falling for phishing links though, so they got a Trend Micro device to scan emails, which also rewrote every link in it to point to their URL scanning service, which means…

I had the opposite funny experience. When I worked for Global MegaCorp, they would occasionally send out phishing emails and if you clicked on a link it would be recorded and you would have to do trainings if you got fooled a couple times. Eventually everyone learned to stop clicking on links on emails. That's good. However, they sent out a yearly survey to get feedback from all the employees and no one clicked the l…

The way they used to handle that at a FAANG I worked for was they had this app installed on each machine issued by IT, that would ask you a question daily about some aspect of your workplace.

Handles all the phishing concerns, except that participation was either low or the feedback was negative, which would lead to the leaders issuing subtle threats to the team about how they'd find out the involved folks and fire them. If you tried to uninstall it, it'd be back in a few hours through policy management software (jamf and its ilk). On the internal discussion forums, they'd nuke threads talking about how to disable that software.

So, in the end, people just started giving the best possible feedback regardless of the team or manager performance. I never really needed those threads, all I needed was tcpdump and then blocking its domain in the hosts file :)

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#49

Earlier quoted context omitted.

Not going to lie, I was expecting this[1]. Maybe it's just not done on HN. 1: https://pc-helper.xyz/scanner-snatcher/session-snatcher/cred...

Fantastic link, very educational.

I haven't clicked on either, which one's gonna do it to me? Is it 50/50 or 100%.... here we go
Post reply on HN