3 ms·
> an ashtonishing 70% of the exploits are through various forms of Phishing and other attacks in the browser Credential phishing doesn’t care where your browse
by resfirestar 6y ago
> an ashtonishing 70% of the exploits are through various forms of Phishing and other attacks in the browser
Credential phishing doesn’t care where your browser is running, as I frequently have to remind IT teams who think their web proxy logs can identify 100% of victims of a phishing attack (there are almost always a few people who clicked on their phone). RBI of this type is specifically to mitigate vulnerabilities in the browser engine, the type of 0-day where you just click on the wrong thing and get owned. While these are a real threat, they are nowhere near 70%, more like less than 1% (and see my other comment about how the 70% number is just made up).
> [2] https://blogs.akamai.com/2018/01/a-death-match-of-domain-gen https://blogs.akamai.com/2018/01/a-death-match-of-domain-gen...
Domain generation algorithms are used for malware command and control, not in the browser/phishing stage of an attack. An actual reason DNS blacklists aren’t perfect for this purpose is that attackers host malware distribution and phishing pages on legitimate services like Google Docs and Sharepoint.
- ignoramous 6y agoI should have been clearer: Domain generation algorithms render solutions like Google SafeBrowsing vulnerable. Sure, these are only used by botnets today, but before we know it, it'd be put to use by adware and spyware too.
- resfirestar 6y agoDGAs aren't a solution to the "my phishing page is blocked by safebrowsing/some other blacklist" problem. You can't send someone an email with a "link" that generates URLs until one of them isn't blocked: hyperlinks aren't programmable in that sense. You can send them a link to a page that does that, sure, but that doesn't stop them from blacklisting the redirector page. How would someone running a phishing campaign actually use a DGA?