1/16
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Phishing is what, and how are they delivered?
Social engineering with a touch of spoofing. Often delivered via email, text, etc
If someone is trying to ‘Phish’ you, what are are the things you need to check?
Check the spelling in URL, and check spelling/fonts/graphics in webpage if you clicked on a link.
How are ‘Phishing’ attacks so successful? Give 3 examples, and explain what each one is.
Digital slight of hand: They make pages/emails/texts look very common and similar to what we would expect, typo squatting: Is a type of URL hijacking and making the URL look almost the same as the official URL, pre-texting: Basically lying to you, by creating a situation and see if they can get you to act on it
What is ‘Pharming’?
When an attacker attacks an entire group of people simultaneously.
What is the difference between Pharming and Phishing? And can these two attacks be used together.
Pharming - Harvesting large groups of people. Phishing - Collecting access credentials. Yes, normally pharming followed by phishing.
What happen if an attacker takes over a DNS server or an entire website?
Anybody who visits the DNS server or the website, will be automatically directed to the attacker’s website. This means, that even if you type in the right address in your browser, you can still end up at the attacker’s website.
How easy is it for third-party products such as anti-malware or anti-virus to recognize pharming attacks?
Very, very difficult.
What is the term for phishing done via phone or voicemail?
Vishing.
Spoofing is?
The act of disguising communication from an unknown or unauthorized source to make it look like it comes from a trusted, legitimate contact
What is happening when an attacker is vishing via call?
They are ‘spoofing’ the phone number that’s appearing on the incoming call, so it looks like its a local phone number. When in reality, they could be calling from anywhere.
‘Smishing’ is done via ? And is spoofing a problem here as well?
SMS or text messaging & yes, same as vishing.
With some of these attacks, if the objective isn’t to get an email password what else could they be after?
To get large sums of money transferred into their personal account.
What is usually the first step an attacker will take and what exactly will that entail, before actually starting to spear phish? And where do they get the information from.
Reconnaissance, gathering as much information as possible on the victim(s). They could get this information from third party websites such as social media sites.
What is the next step for an attacker wanting to spear phish a victim and how will they do this, after performing reconnaissance?
They will create a believable pre-text/fake story using information gathered from reconnaissance, information such as where you live, where you work, who you work with, who you bank with, etc
What is spear phishing, and what is concerning about this attack?
Very targeted phishing with inside information. The concerning thing about these attacks, are they are more believable since the attacker is using inside information.
What is ‘Whaling’?
Spear phishing with the possibility of a large catch, such as a CEO or CFO. Basically when they target people with a large amount of money or information.