4 ms·
Probably because it was more sophisticated than a gift card.. There are some screenshots on Twitter from the hackers with all kinds of internal uber tools and a
by cyral 4y ago
Probably because it was more sophisticated than a gift card.. There are some screenshots on Twitter from the hackers with all kinds of internal uber tools and admin panels, many on non-uber domains (like uber.<third-party>.com). With all the internal email lists that employees are on for different departments in these large companies, it's not unimaginable that they click a link that appears to be some malicious site in disguise of an uber property, and enter their credentials.
- yeuxardents 4y agoThis is one of my biggest fears about companies constantly outsourcing easily deployed internal apps as SaaS and just using mycompany.saasprovider.com Normal users stand no chance, especially when there are URLs that are sketchy because oops, saasprovider already has a customer with your requested url, so you end up with mycompany0.saasprovider.com or mycompany-1.saasprovider.com Its terrible practice all around and lazy systems and services administration
- Thorrez 4y agoEven without SaaS I get weird URLs on login pages. The login page for my personal Chase account is https://secure07a.chase.com/web/auth/#/logon/logon/chaseOnline?treatment=chase&lang=en At least the etld+1 makes sense, but most people aren't going to recognize that generally the etld+1 is what you need to verify and you can ignore the rest.