Phishing Flashcards
Phishing
Pretends to be from a trusted source
Check address, will have different URL
Something usually isn’t “quite right”
To avoid type URL of site directly into browser; don’t click from an email.
Typosquatting
Using URL that is slightly different or misspelled.
Example:
professormessor.com instead of the correct professormesser.com
Prepending
Adding an additional character to the beginning of the email to make it seem like a legitimate email.
Example:
pprofessormesser.com instead of professormesser.com
Pretexting
Lying to get information.
Acting like a well known company ie; Amazon, Netflix, Visa
Pharming
Redirects legitimate site to a bogus site.
Does this by using a poisoned server or client vulnerability.P
Pharming with Phishing
Pharming redirects users to illegitimate site from an actual site.
Phishing takes those users and collects their data.
Difficult for anti-malware to detect because original site may be legitimated.
Vishing
Using voicemail to phish.
Caller ID is spoofed appearing local.
Usually in the form of fake security checks or bank updates.
Smishing (Short Message Services of SMS Phishing)
Done by text.
Forwards links.
Asks for personal information.
Variations of Phishing
Fake check scam.
Phone verification code scam.
Boss/CEO scam
List of scams on Reddit.com/r/scams
Reconnaissance
To gather information on a victim or target.
Gather through:
- Lead generation sites.
- LinkedIn, Twitter, Facebook, Instagram, etc.
Attacker builds credible pretext:
-Where you work.
-Where you bank.
-Recent financial transactions.
-Family and friends.
Spear Phishing
Directed phishing.
Going after a specific person.
Whaling is a form where you go after a high-level person:
- CEO
-CFO