Live data from Hacker News

Want to piss off your IT department? Are the links not malicious looking enough?

phishyurl.com

161–170 of 335 posts

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#162
post #46

Real evil would be a kind of reverse-psychology: 1. Make a site like this. 2. Wait for people to try it out with an URL that goes to a significant site (bank, social media, email, etc.) 3. Allow a bit of normal use, then secretly switch the link so that further visitors land on a corresponding phishing site. 4. Having just dismissed a bunch of "obviously fake" warning signs, people may be less alert when real ones ar…

Im sure in tge nect 5 years a blackhat model will exist that clone any website into a phishing site.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#163

Earlier quoted context omitted.

you may or may not add a condition for emails with X-PHISH in its headers

They block this and force it to show up in my inbox

At my company they force it to land in your inbox but if you manually run the rule afterward it catches them.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#164

I put in my own domain name, and got a link on the https://cheap-bitcoin.online domain. Then I sent the full url it gave me to VirusTotal, and one site reported it as malware! Hilarious, this is great.

There might be mpre falllout

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#165
post #18

Earlier quoted context omitted.

I think the lesson here is that any link in an email is bad. We should just block all of them.

Why not address the problem at its real source and just block emails entirely?

Go deeper, just revert humanity

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#167
post #159

Earlier quoted context omitted.

In Europe there are legitimate and extremely established services that require you to input your bank login details into something other than your bank's website. It's madness.

There's no legitimate case for that since PSD2 (mandatory since 2020). Are you not confused by that? PSD2 doesn't share your credentials. I'm an European and have never needed to use nor encountered those services.

PSD2 is just MFA, it doesn't prevent shady companies still asking your login credentials, even if you must authorize that login from your official banking app. Klarna is one of many examples - they ask me for my bank credentials on their own website so they can crawl all my finance data .

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#168
post #110
post #67

Earlier quoted context omitted.

> So, in the end, people just started giving the best possible feedback regardless of the team or manager performance. That seems to be the best possible strategy for any feedback you have to give as a captive audience? Reminds me of the feedback German companies are forced to give about their employees. It's like a formal letter of reference, but you can and will be sued if you you anything negative. Consequences ar…

> And because there has been an inflation in how complimentary these letters are, people started suing when their letter wasn't flowery enough, because that somehow could be read as an implicit criticism. You got a source for this folktale?

This is a very common practice in Germany. There were a few court cases won by employees whose recommendation letters were not positive enough, so employers now basically just write whatever you ask for.

I have written all my recommendation letters myself. The employers just put their letter head and sign it.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#169

Ah no need, corporate IT already make all URLs malicious looking through some microsoft "secure link" service, and constantly shows everyone shady looking prompts that constantly change and have cmd.exe windows flash in at random. A phone call from Microsoft about my Norton anti-virus subscription putting me into debt that can only be settled with Nintendo gift cards bought in cash across 16 specific gas stations see…

All that anti-phishing training that taught us to look closely at the URL and now it's all just safelinks.protection.outlook.com

I recently reported an email with “glint.email.microsoft” as a phishing attempt, but it turned out to be a corporate survey.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#170
post #71

Earlier quoted context omitted.

It's possible an attacker might say: "My first pet's name is random gibberish", and the person on the other end goes: "Yep, that's what it says." I'm not sure how many companies that would happen at, but it seems... just dumb enough to be plausible.

1Password’s default for secret questions is a sequence of English words, rather than random gibberish.

See https://xkcd.com/936/
Post reply on HN