3 ms·
If you are looking for a straightforward way to protect users from phishing, consider rewriting the URLS in their messages and check their clicks in real time a
by bks 8y ago
If you are looking for a straightforward way to protect users from phishing, consider rewriting the URLS in their messages and check their clicks in real time against databases of phishing feeds.
You can check against - Google Safe Browser, Phishtank and other free phishing feeds if you don't have the money for real-time databases or proactive site scrapers.
This is one of the ways that we protect the end user from Phishing at https://www.phishprotection.com https://www.phishprotection.com - part of the magic is to do a bunch of sanitization before accepting the message including strict SPF, DKIM, DMARC validation / virus protection at the edge / and watching the registration of SSL certificates for commonly exploited domains https://blog.0day.rocks/catching-phishing-using-certstream-97177f0d499a https://blog.0day.rocks/catching-phishing-using-certstream-9...
If anyone is interested we rewrite URLs to match your domain name - something like linkcheck.yourdomain.com (protected by LetsEncrypt) and if you ever decide to leave you can export out the re-written URLs and redirect your domain to your own servers.
If you'd like to give it a try, feel free to let me know.
- dmbaggett 8y agoLike phishing awareness training, this is a good practice. We actually offer URL rewriting to our customers, but there are some UX downsides to it so not everyone wants it. One big issue with GSB, Phishtank, OpenPhish, etc. as "the solution" is that, again, it's trivial for attackers to thwart these threat feeds. Using the same approach spammers have been implementing for 20 years now, the attacker just needs to randomize the URL in each sent email. Then when you report the phishing link in your copy, it helps no one else. One could imagine a system that reverses the patterns used by the URL generation scripts -- we actually do this for DGAs ("domain generation algorithms") -- but even trying to be clever like this just puts you back in an arms race with the attackers. So I don't think URL "whack-a-mole" is the right answer either. I believe you need the software to straight-up identify fraudulent emails from first principles. (Not saying it's easy.)
- marmot777 8y agoYes, spammers learned to switch IP addresses very quickly. The email filters became more sophisticated ways of identifying your spam from a different IP addresss and even from a different domain name. Spammers could run but not hide. I think I see a LOT less spam that actually gets to my inbox than in years past. Hats off to those who worked hard on making an incredible amount of progress on hard provlems, and continue to plow ahead.