7 ms·
I recently failed a suspicious email / phishing test for the first time, and I am also one of those people who never thought it would happen to me... The email
by samfriedman 7y ago
I recently failed a suspicious email / phishing test for the first time, and I am also one of those people who never thought it would happen to me...
The email was a newsletter I didn't care about, and the unsubscribe link was (fake) malicious. That one impressed me because it preyed on what is now a pure reflex to click the unsubscribe link.
- mason55 7y agoDid the link take you to a site that auto-ran malware? Or did it take you to some kind of page that said "login to unsubscribe"? The latter is why password managers can be so valuable. I never type my passwords in so if my auto-fill doesn't activate I immediately become suspicious. If it's the former, it seems like your company must be using an insecure browser or the site was running some kind of 0-day? I never think twice about clicking links.
- deleted 7y ago[deleted]
- inetknght 7y ago> I never think twice about clicking links. I hope you don't work for any sensitive position.
- Dylan16807 7y agoThat's not very fair. Browser exploits are a lot rarer than phishing.
- acdha 7y agoI don't think background noise of broad, low-effort phishing emails can be directly compared to a more focused attack. If you work somewhere with interesting data the odds of a good phishing attack leading to an exploit could be much higher because you're being specifically targeted and they're not going to send the message until they have a current exploit ready (probably hoping to get it in before your IT department's change window, too).
- michaelt 7y agoIf someone had a working browser exploit, wouldn't they just deliver it to their targets via an ad network? AFAIK most enterprises don't mandate ad blocking or noscript.
- acdha 7y ago> If someone had a working browser exploit, wouldn't they just deliver it to their targets via an ad network? I've heard more people at enterprises using ad blockers for security so I wouldn't rule that out but in general this is hitting that the broad vs. targeted distinction I mentioned: each time you use an exploit you're risking discovery, which will lead to it being patched & AV signatures going out. Using an ad network increases the number of people who are not your target getting the payload, not to mention any scanning the network does, and since ad networks require payment there's another trail pointing back to you which might not otherwise be the case if you are hosting things on compromised servers.
- mason55 7y agoIt's a valid comment, but if you're in a position where you are worried about 0-days from random web browsing then you should be using the internet on a fully segregated machine. If Firefox or Chrome has an RCE + privilege escalation in it that can be triggered just from browsing to a page then, congrats, you got me.
- web007 7y agoThe recent CPU-level vulnerabilities have exploits that can run in the browser. See https://www.zdnet.com/article/intel-cpus-impacted-by-new-zombieload-side-channel-attack/ https://www.zdnet.com/article/intel-cpus-impacted-by-new-zom... for pointers to video evidence. They're not zero-day attacks once they're made public, just the same as Meltdown and Spectre. Go download the PoC code, switch calc.exe to something useful, and phish away. https://news.ycombinator.com/item?id=20028108 https://news.ycombinator.com/item?id=20028108 from earlier this week shows that just loading a page can lead to network information disclosure or other compromise / attack vectors. It's not a zero-day, it's a feature.
- 0xffff2 7y agoWhen my organization does these, the link just goes to a static page that says "you could have been phished". The fact that in fact no serious attempt at phishing has yet taken place and that my work machine is far too insecure if they're worried about browser 0-days seems totally lost on them.
- kaffeemitsahne 7y agoFrom this and other comments in this thread it seems you have failed these phishing tests as soon as you click a link. Is the assumption here that you are completely pwned as soon as you visit an url controlled by an attacker? I can't imagine myself compromising company data/funds via a website where I ended up through a newsletter unsubscribe link so this seems quite unfair on the part of the phish-testers.
- Consultant32452 7y agoThis is exactly the case. If you click on a link in the fake phishing email you've failed the test. It does not require you to install anything, open an attachment, etc.
- Scoundreller 7y agoI was once at a place where the company homepage was owned. Fun times. Just starting your web-browser would exécuté some Java vuln and scareware you.
- fragmede 7y agoIf you think visiting a webpage in Chrome, or any other browser, even inside a VM, is totally safe, especially against a nation-state level actor, I have some bad news for you.
- agurk 7y agoWith that logic just having your mail client/web mail parse a malicious mail from a nation-state level actor is enough to compromise your machine.
- whenchamenia 7y agoIt happens all the time. https://thecoinshark.net/microsoft-email-clients-was-hacked-to-steal-cryptocurrency/ https://thecoinshark.net/microsoft-email-clients-was-hacked-...
- deleted 7y ago[deleted]
- inetknght 7y ago> a pure reflex to click the unsubscribe link. That's a learned trait. I don't click unsubscribe links; I click "report spam" and "report phishing" button. If only Gmail would let me create filters to automatically mark entire domains as spam though. That would be nice...
- ghaff 7y agoI'm sure this [reporting spam rather than unsubscribing] happens all the time but it's sort of obnoxious if the email is legit and, especially, if it's a list you requested to get put on at some point.
- inetknght 7y agoIf you got my email address from a third party, then I do not want to be marketed to. If you got my email address because I applied for a job, then I do not want to be marketed to. If you got my email address because I signed up for a service, then I do not want to be marketed to. If you got my email address because I purchased something, then I do not want to be marketed to. If you got my email address because someone else "legitimately" entered my email address into your field, then I do not want to be marketed to. In short: your definition of "legit" likely does not meet my definition of legit. The only email that I deem to be legit is an email that: 1) is @from a domain name that I recognize (walk like a junk, talk like a junk, it's junk) 2) is @from the same domain name as the correspondent (no third party bulk email or proxies; eg mailchimp et al) 3) does not have a no-reply@ as the reply-to address (I must be able to talk to a human) 4) does not hyperlink to third party domains (from@domain must match hyperlinked domain text) Any legitimate email outside of those parameters are specially treated with liberal amounts of filtering.
- perl4ever 7y agoYour attitude doesn't account for the possibility that since you do business with somebody, you need or want to receive some of their emails. This is the nature of any relationship. You can't be ruthless in eliminating aspects you don't like, if you don't want to end it entirely because it's net positive.
- Scoundreller 7y agoIf that’s the bar, the org should just strip out all external links. Voilà. That way they’ll also protect themselves against an external vendor that gets used to spearphish you.