Live data from Hacker News

Want to piss off your IT department? Are the links not malicious looking enough?

phishyurl.com

151–160 of 335 posts

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#151

Around 2001 I worked for one of the big dot com news outlets. In our reception we had a PC with a browser set up where people could "use the internet" while they waited. One day the receptionist asked me to fix the PC as it wasn't connected to the internet and no one from IT was available. So I messed around a bit (think in the end I just reset the DCHP lease) and to test I opened the browser to surf the net. Of cour…

Thank you for that anecdote, it lightened my breakfast Pause :)

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#152

Ah no need, corporate IT already make all URLs malicious looking through some microsoft "secure link" service, and constantly shows everyone shady looking prompts that constantly change and have cmd.exe windows flash in at random. A phone call from Microsoft about my Norton anti-virus subscription putting me into debt that can only be settled with Nintendo gift cards bought in cash across 16 specific gas stations see…

All that anti-phishing training that taught us to look closely at the URL and now it's all just safelinks.protection.outlook.com

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#153

All of this reminds me of a hilarious situation at a previous employer. As is standard corporate practice, they used to tell people to inspect links by hovering over them to confirm that they lead to the official website of the sender. People kept falling for phishing links though, so they got a Trend Micro device to scan emails, which also rewrote every link in it to point to their URL scanning service, which means…

I had the opposite problem at my last company. When you hover over a link Apple's Mail app opens a preview of the page. So if you try to see the URL then you automatically visit the link and get sent for more training.

I learnt that all those emails were sent through some relay. I blacklisted the relay. And then, some real training email notifications were sent through the same relay. But that relay is used for phising, so I just refuse to open the training email. Win-win.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#154

Ah no need, corporate IT already make all URLs malicious looking through some microsoft "secure link" service, and constantly shows everyone shady looking prompts that constantly change and have cmd.exe windows flash in at random. A phone call from Microsoft about my Norton anti-virus subscription putting me into debt that can only be settled with Nintendo gift cards bought in cash across 16 specific gas stations see…

All that anti-phishing training that taught us to look closely at the URL and now it's all just safelinks.protection.outlook.com

I find it very difficult to inspect the email headers in Outlook, I think for the iOS app it's not even possible. It's almost like they want to make it less transparent and secure

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#155
post #120

Earlier quoted context omitted.

The company I used to work for had the same thing - everything was a rewritten URL (this was a Microsoft shop so it was rewritten to something like "safe.protected.outlook.com/?random_spew". From what I remember, yo)u couldn't even see the original URL in that (or it might have just been long enough random arguments to be completely impossible to find). Nothing raises my suspicions quite like something calling itself…

> Nothing raises my suspicions quite like something calling itself "safe". Ah yes, it's like a country having "democratic republic" in it's name - if you have to say it, it's probably not true.

Or any US law that says "PROTECT" or "FREEEDOM"

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#156

Ah no need, corporate IT already make all URLs malicious looking through some microsoft "secure link" service, and constantly shows everyone shady looking prompts that constantly change and have cmd.exe windows flash in at random. A phone call from Microsoft about my Norton anti-virus subscription putting me into debt that can only be settled with Nintendo gift cards bought in cash across 16 specific gas stations see…

All that anti-phishing training that taught us to look closely at the URL and now it's all just safelinks.protection.outlook.com

In Europe there are legitimate and extremely established services that require you to input your bank login details into something other than your bank's website. It's madness.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#157
Very funny, but this could be used for both intentional and unintentional Black-hat SEO. My theory goes:

    1. Create dodgy looking URL
    2. AI in Gmail spots link, blocks it.
    3. Blocked link is spidered for more information automatically
    4. Link resolves to website
    5. Website black-listed
So I'm not going to use it!

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#158

Earlier quoted context omitted.

All that anti-phishing training that taught us to look closely at the URL and now it's all just safelinks.protection.outlook.com

In Europe there are legitimate and extremely established services that require you to input your bank login details into something other than your bank's website. It's madness.

Multiple US hospitals and insurance companies use genuine links like doctor-services-for-u.biz - infuriating.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#159

Earlier quoted context omitted.

All that anti-phishing training that taught us to look closely at the URL and now it's all just safelinks.protection.outlook.com

In Europe there are legitimate and extremely established services that require you to input your bank login details into something other than your bank's website. It's madness.

There's no legitimate case for that since PSD2 (mandatory since 2020). Are you not confused by that? PSD2 doesn't share your credentials.

I'm an European and have never needed to use nor encountered those services.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#160

Earlier quoted context omitted.

> Nothing raises my suspicions quite like something calling itself "safe". Ah yes, it's like a country having "democratic republic" in it's name - if you have to say it, it's probably not true.

Or any US law that says "PROTECT" or "FREEEDOM"

Oh, come on. Freedom of Information Act sounds kinda nice!
Post reply on HN