Live data from Hacker News

Want to piss off your IT department? Are the links not malicious looking enough?

phishyurl.com

171–180 of 335 posts

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#171

Earlier quoted context omitted.

All that anti-phishing training that taught us to look closely at the URL and now it's all just safelinks.protection.outlook.com

In Europe there are legitimate and extremely established services that require you to input your bank login details into something other than your bank's website. It's madness.

Care to mention what these legitimate and established services are?

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#172
post #46

Real evil would be a kind of reverse-psychology: 1. Make a site like this. 2. Wait for people to try it out with an URL that goes to a significant site (bank, social media, email, etc.) 3. Allow a bit of normal use, then secretly switch the link so that further visitors land on a corresponding phishing site. 4. Having just dismissed a bunch of "obviously fake" warning signs, people may be less alert when real ones ar…

Im sure in tge nect 5 years a blackhat model will exist that clone any website into a phishing site.

You can just use SingleFile to download the login page of any website and serve it with a webserver

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#173
This was the best damn belly laugh I've had all week. Ahh. Thanks for that.

"Just fuck me up fam!"

You had me spraying coffee by that point

All the funnier trying it with links to community church services (baptist no less).

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#174

Earlier quoted context omitted.

All that anti-phishing training that taught us to look closely at the URL and now it's all just safelinks.protection.outlook.com

I recently reported an email with “glint.email.microsoft” as a phishing attempt, but it turned out to be a corporate survey.

Well it's probably hard for anyone except Microsoft to get a domain with the .microsoft TLD.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#175

Earlier quoted context omitted.

In Europe there are legitimate and extremely established services that require you to input your bank login details into something other than your bank's website. It's madness.

Care to mention what these legitimate and established services are?

[deleted]

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#176

Earlier quoted context omitted.

All that anti-phishing training that taught us to look closely at the URL and now it's all just safelinks.protection.outlook.com

In Europe there are legitimate and extremely established services that require you to input your bank login details into something other than your bank's website. It's madness.

Are you talking about the possibility to pay via your bank account directly on a checkout page? If so this is the bank page you are using.

Can you give some examples?

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#177
post #64

Earlier quoted context omitted.

You innocent young being. There are some gaping holes in your Internet lore knowledge, but it's been eons since that's been seen in the wild.

I miss the days of goatse

In my day, links were always goatse...

As I am still alive, it is still my day. Need I make myself clearer?

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#178
post #118

Earlier quoted context omitted.

The reality is that these letters are written in a kind of pseudolegalistic language, where a phrase like “the employee was punctual” means they were usually late. If they were actually punctual, you'd see something more like “the employee consistently demonstrated exceptional punctuality”. You usually need the reference letter to be reviewed by the works council or by an employment lawyer.

sighs . Seriously? Good to know though, if true.

German here. Absolutely true, and has been for many years now. Some examples:

- grade D, poor performance: "We were satisfied with his performance" - grade C, meh: "We were entirely satisfied with his performance" - true grade A+: "We were always satisfied to the utmost degree with his performance" plus highly positive and extensive in the rest of the reference letter.

- "was sociable": alcoholic - "was always striving for a good relationship with colleagues": was gossiping instead of working - "sociability was appreciated": had sex with colleague - "was very empathic": had sex with customer

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#179

All of this reminds me of a hilarious situation at a previous employer. As is standard corporate practice, they used to tell people to inspect links by hovering over them to confirm that they lead to the official website of the sender. People kept falling for phishing links though, so they got a Trend Micro device to scan emails, which also rewrote every link in it to point to their URL scanning service, which means…

I had the opposite funny experience. When I worked for Global MegaCorp, they would occasionally send out phishing emails and if you clicked on a link it would be recorded and you would have to do trainings if you got fooled a couple times. Eventually everyone learned to stop clicking on links on emails. That's good. However, they sent out a yearly survey to get feedback from all the employees and no one clicked the l…

I had a similar experience. I got pulled up for not completing my anti phishing training. It had been sent from a third party contractor with a random domain, but apparently I was supposed to know that was safe but the other external links were bad.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#180

Earlier quoted context omitted.

All that anti-phishing training that taught us to look closely at the URL and now it's all just safelinks.protection.outlook.com

In Europe there are legitimate and extremely established services that require you to input your bank login details into something other than your bank's website. It's madness.

I find this hard to believe and have never seen that ever.
Post reply on HN