Live data from Hacker News

Want to piss off your IT department? Are the links not malicious looking enough?

phishyurl.com

261–270 of 335 posts

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#261

Earlier quoted context omitted.

All that anti-phishing training that taught us to look closely at the URL and now it's all just safelinks.protection.outlook.com

In Europe there are legitimate and extremely established services that require you to input your bank login details into something other than your bank's website. It's madness.

Name and shame: Klarna did this.

Not sure if they still do because i stay well clear of them.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#262
post #196

No need, my IT already do this by running the MimeCast email filter [1]. Links to non-whitelist sites are expressed in the format: https://url.uk.m.mimecastprotect.com/s/ ?domain= Maybe I can tell the link is from Google, but not what is likely to be in the URL. It's a complete surprise as to whether I will be looking at a web page or downloading something. [1] https://www.mimecast.com/

Now you just need a browser plugin to extract the domain name and fix it, problem solved.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#263
post #184

Earlier quoted context omitted.

Outlook has a rule filter for header content. Just saying I haven't failed a phishing test in ~10 years.

Mind sharing your filter rules? KnowBe4 uses X-PHISHTEST header and I think I saw Proofpoint using something similiar a few years back

Straight from the source: https://help.proofpoint.com/Proofpoint_Essentials/Security_A... xD

The vast majority of security controls are designed for the careless and the clueless.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#264
post #124
post #87

Earlier quoted context omitted.

> The way they used to handle that at a FAANG I worked for was they had this app installed on each machine issued by IT, that would ask you a question daily about some aspect of your workplace. I presume you're referring to "Amazon Connections"? Had to be the most-hated bit of corporate enforcedware around. Every Linux laptop user had a different hack for hobbling or removing it.

It's been years, and I still remember the infamous ticket `CONNECTIONS-3303`. A pox on everyone involved with that clusterfuck.

[deleted]

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#265

Earlier quoted context omitted.

I find this hard to believe and have never seen that ever.

Don't understand the downvotes, i never saw that too, and i am shopping online very often.

If you used the first gen "pay later" services they'd scrape you for "compliance checking" or simply mask it as a transaction which is actually just personal information scraping.

Most of the times you did not see it, as it's obfuscated as a part of the transaction.

They are also the companies complaining a lot about the "failure" of the PSD standards since it limits how much and how obfuscated they can scrape everything (and there are records).

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#267

Earlier quoted context omitted.

My It department does mandatory phishing training every year, and then for the "test" e-mails, they spoof a domain and whitelist the DMARC on their side so it goes through. So we get e-mails from @microsoft.com and it's only if you dig in the metadata that you see it failed authentication. The only tell in the e-mail is checking the URL, which doesn't tell you much because tons of regular e-mails use tracker redirect…

> heard IT pays a lot with not much work I want to live in this fantasy world! (Our IT dept is so overworked that I go out of my way to work around them purely out of empathy.)

Every industry has its bad employers and good.

I know teachers that make $50k and no pension, with others making $93k, halfways to their pension at 35yrs old, get almost 12 weeks off total a year, and work from 8am to 3pm (1 hour lunch, 1 hour for 'prep' aka Netflix) and home by 335, and no, they basically never do any work at home. She technically has students (10 year olds she sends links to for their chrome books) about 5x53 minutes a day.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#268
post #9

Not bad! https://carnalflicks.online/var/lib/systemd/coredump/logging...

Not going to lie, I was expecting this[1]. Maybe it's just not done on HN. 1: https://pc-helper.xyz/scanner-snatcher/session-snatcher/cred...

I'm sorry, what exactly is this?

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#269
post #131
post #9

Not bad! https://carnalflicks.online/var/lib/systemd/coredump/logging...

You should totally not click this one: https://match-heaven.club/trojan/malware_dropper.exe?id=0416...

Ngl I really want to
Post reply on HN