Skip to main content

Do You Know How Phishing Works?

How Phishing Works ?

Phising Attack

 

It is always safer to deal with a known devil — no matter how dangerous it is — than is to deal with an unknown demon. Just the knowledge of the devil is enough to trigger a response mechanism inside of us, which in due time help us form a strategy to defeat the devil in the battle.
I believe in this, and that is the reason why I have decided to first inform you about the workings of phishing scamsters. The mere knowledge of their working will save you more often than you can care to imagine. So let’s get started with reading mind of a phishing scamster.

How phishing works

 

The phishing net used by the scamsters consist of three things:
  1. A cooked up story enticing you to take action.
  2. A link to a website that looks similar to the one phishing email claim to be.
  3. A landing page that looks entirely like the website of the company a phishing mail claims to originate from. 

How each of the elements is used?

 

To make a phishing mail believable, a scamster designs a mail that looks identical to the mails you receive from the company which phishing scammer is pretending to be — bank, credit card websites, PayPal, etc.
Against this background, a story is weaved to make it believable to the audience, so much so that the readers click the link sent in the mail. Such mails are sent in abundance to anyone and everyone using all the possible media.
The readers are then taken to a website that looks entirely like the website they would see on the other side of the original link the scammer is mimicking, expect for one thing. The URL is not the same.
These tricks rests on the fact that not many people verify the URL, HTTPS prefix, and presence of padlock on a website before keying in their username and password. And sadly, almost all the phishing attacks succeeds in fishing critical information — typically usernames and passwords of bank accounts and other financial institutions — from lot many users.

Comments

Popular posts from this blog

Defacing Sites via HTML Injections (XSS)

Defacing Sites via HTML Injections Defacing Sites via HTML Injections What Is HTML Injection: "HTML Injection" is called as the Virtual Defacement Technique and also known as the "XSS" Cross Site Scripting. It is a very common vulnerability found when searched for most of the domains. This kind of a Vulnerability allows an "Attacker" to Inject some code into the applications affected in order to bypass access to the "Website" or to Infect any particular Page in that "Website". HTML injections = Cross Site Scripting, It is a Security Vulnerability in most of the sites, that allows an Attacker to Inject HTML Code into the Web Pages that are viewed by other users. XSS Attacks are essentially code injection attacks into the various interpreters in the browser. These attacks can be carried out using HTML, JavaScript, VBScript, ActiveX, Flash and other clinet side Languages. Well crafted Malicious Code can even hep the ...

Linux Systems Performance/Observability (BPF (bpfcc-tools), BCC Tools

  Linux System Performance/Observability Tools Linux Systems Performance/Observability (BPF (bpfcc-tools), BCC Tools Assuming you have Linux Server in place and have the required BPF aka BCC related packages installed on the system(s) for the required Linux distribution. BPF(eBPF) aka BCC Tools (bpfcc-tools) : BPF, which originally stood for Berkley Packet Filter is the dynamic tracing tools for Linux Systems.  BPF initially used for the speeding up for the tcpdump expressions and since then it has been know as the extended Berkley packet Filter (eBPF).  Its new uses are Tracing Tools where it provides programmability for the BPF Compiler Collection (BCC) and bpftrace front ends .   Example: execsnoop, biosnoop etc is a BCC Tool. When facing production performance crisis these such list of tools comes handy to trace and fix the issue. However, it requires certain KERNEL level config options to be enabled such as CONFIG_FTRACE, CONFIG_BPF. Profiling tools typically re...

EKS Cluster and Create CSI Driver to store credentials in AWS Secrets Manager via SecretProviderClass

EKS Cluster | CSI Driver | SecretProviderClass | AWS Secrets Manager Setup EKS Cluster and Manage Credentials at runtime using CSI driver using SecretProviderClass and Secrets Manager Assuming you have Configured/Installed AWS CLI, EKSCTL, KUBECTL, HELM. CSI Basic Information: CSI (Container Storage Interface) widely used as a Storage Technology. Created by Google | Mesosphere | Docker.  It has two two Plugins one runs on the Master Node (Centralized Controller Plugin) and another one on Worker Nodes (Decentralized headless Node Plugin).  CSI communication protocol is gRPC.   The communication between Container Orchestration to Controller Plugin (Master) and to Node Plugin (Worker Node) happens using gRPC .  CSI Drivers : vendor specific compiled into Kubernetes/openshift binaries. To use a CSI driver, a StorageClass needs to be assigned first.  The CSI driver is then set as the Provisioner for the Storage Class. CSI drivers provide three main service...