9 ms·
I don't doubt phishing happens. I just think this specific scenario/technique is one that is probably extremely rare. The attacker likely wouldn't put this much
by bluetidepro 3y ago
I don't doubt phishing happens. I just think this specific scenario/technique is one that is probably extremely rare. The attacker likely wouldn't put this much extra effort/thought in when their basic attacks already work, like you're describing.
- fkyoureadthedoc 3y agoSecurity at my job pumps their numbers by pretending you fell for a phish if you click the link in their obvious phishing test emails. I clicked one to see how good of a job they did at the other end of the link trying to extract whatever they want from me, but there's nothing there! So lazy.
- hk1337 3y agoI got dinged once for using curl (in a VM) on the link get the details to pass one when I reported it.
- npongratz 3y agoI once got dinged for forwarding an obvious gotcha email, without ever opening it, to our security team's phish notification address, as our employee handbook instructed. I learned my lesson.
- testudovictoria 3y agoI once got dinged for not reporting. I saw an email that was clearly an internal security campaign. I deleted it. I received an email a day or two later stating that I failed to take action on a phishing attempt. Damned if you do; damned if you don't.
- Macha 3y agoFor a while I had a thunderbird filter to automate forwarding based on our provider's email header. They disabled SMTP and the Gmail web client has no such ability to filter on arbitrary email headers.
- ohthatsnotright 3y agoYou can setup a Google app automation to do this for you. I did for e.g. knowbe4 since all their test emails have the same header information. It made it quite easy to never see any of their attempts, though I did have to check every once in a while to see if I'd been signed up for any random learning and it removed those emails as well..
- Macha 3y agoiirc, the same company had locked down the allowed oauth apps, so you would have needed an exception from security to run one. I doubt they'd have granted an exception to stop getting annoyed by their own training.
- tripdout 3y agoYeah the links from Proofpoint are unique to you, so however you visit it you still get tracked
- hk1337 3y agoIt was when I was working at HP/HPE/DXC (I don't remember what it was at the time), I don't remember what they used.
- MakeThemMoney 3y agoThank you! - Browser 0-day vendor
- planede 3y agoIt's good that I otherwise don't click on links in my browser during my day-to-day work. /s
- themoonisachees 3y agoGood thing browser aren't able to display content of random unvetted third parties in exchange for money on any website you visit too :) Adblock is a security measure at this point.
- autoexec 3y agoYou aren't wrong. I've got a heavily locked down browser on an off-network device for working with questionable websites. While the vast majority of phishing sites aren't pushing malware spearphishing is another story.
- bee_rider 3y agoIT still might not want you to follow the link. * Other users might have, instead, an incompetently secured browser that they think is locked down on their work devices. It is hard for IT to distinguish between you and them. * If the URL is personalized, it tells the attacker that the address is active. This is probably pretty limited help to the attacker. But it might tell them if your company emails follow a particular format, right?
- fkyoureadthedoc 3y ago> * If the URL is personalized, it tells the attacker that the address is active. This is probably pretty limited help to the attacker. But it might tell them if your company emails follow a particular format, right? I just asked chatgpt and it knows what email format the company I work for follows, so I'm not sure this is of particular value.
- kurnikas 3y agoI got dinged for clicking "report as phishing" as part of that process forwards it to microsoft threat intelligence in outlook and so their systems said I forwarded and therefore fell for the phishing, now I look for a particular header and put all of those messages in a "phishing" folder
- imzadi 3y agoI run my organization's phish sims, and we had a similar issue one month. A bunch of people failed for downloading attachments. When I looked into it further, all the attachments were downloaded by the same Czech IP address. With some research, I found that it was an AVG IP address. The fix is very simple. The phish sim service has a place to exclude IP ranges. Any activity from those IPs are just ignored. I'm sure all phish sim services and software have this ability.
- Finnucane 3y agoNow when I see a phish, I check to see where it is coming from. 97 percent of the time, it is a test. We're getting these tests often enough that I just assume that's what it is.
- imzadi 3y agoWhich is fine, actually. If you see it and think "oh, IT is at it again" and delete it or report it, mission accomplished, because there is still that 3/100 chance it is real.
- jrockway 3y agoWe must use the same vendor, as I heard about that happening to my coworkers. I clicked "it's phishing you idiots" in Outlook and got a gold star. I find it funny because my organization doesn't even use email, so 100% of email I get is spam or phishing. The dead giveaway on this email was that there was a Via: header that was like "phishingtestsforyourworkplace.com" or something.
- seethishat 3y agoMany phishing simulation systems are not technically correct. Microsoft, Google and other 'security vendors' may inspect links in emails. That link inspection can sometimes be blamed on the end user. "You clicked the phishing link, now you have to take remedial security training!" The only way to know for certain that a user fell for a phish, during a simulated exercise, is to make an HTML form that does a HTTP POST request and contains the user's credentials (that only they could type in). If a user enters their username and password and clicks submit, then they fell for the phish, otherwise no one can say for sure who or what software clicked that link that did a simple HTTP GET.
- w3ll_w3ll_w3ll 3y agoMicrosoft Safe Link technology does not actually inspect the link until the user clicks on the link. This is to avoid that confirmation links, used by some service to confirm registratio or as 2FA, may be triggered by the security engine without user consent.
- caddy 3y agoOur workplace outlook phishing protection does though. I was signing up to test one of our apps recently and my email was auto confirmed in 5 seconds despite me never receiving it. Turns out it was caught in the phish filter which automatically clicked the link to check it, so the above is not always true. Confirmed this with a few co-workers too.
- GrinningFool 3y agoI did that once for the same reason, and found myself sentenced to mandatory security retraining videos with no possibility of appeal.
- raptor99 3y agoMaybe it's just good to be aware.
- tomhallett 3y agoWhile I’m not saying the specific scenario will work 100% of the time, it doesn’t need to - by the email getting forwarded at all, there is some element of trust in “my manager forwarded me this email and typed ‘complete this for me’”. If this css technique increases the attackers odds, then it’s an issue. Or for your specific example, imagine the recipient is passing their manager in the hallway: “hey, can we chat about the Acme Corp email, I’ve got some questions about it”. Response: “sorry, super busy. It’s a fairly common ask, just get it done!”