100 likes | 254 Views
Phishing Emails. Legitimate: Extended Validation. Obviously Illegitimate. http://rusprory.mass.hc.ru/old_site/update/index.php. Look-alike Characters. Legitimate Partners Can Look Fishy. ???. ???. International Character Sets. What does this URL refer to?
E N D
Phishing Emails CS 142 Lecture Notes: Security Attacks: Phishing
Legitimate: Extended Validation CS 142 Lecture Notes: Security Attacks: Phishing
Obviously Illegitimate http://rusprory.mass.hc.ru/old_site/update/index.php CS 142 Lecture Notes: Security Attacks: Phishing
Look-alike Characters CS 142 Lecture Notes: Security Attacks: Phishing
Legitimate Partners Can Look Fishy ??? ??? CS 142 Lecture Notes: Security Attacks: Phishing
International Character Sets • What does this URL refer to? www.bank.com/accounts/login.php?q=me.badguy.cn • This is a host name only! Chinese characters that look like "/", "?", and "=" CS 142 Lecture Notes: Security Attacks: Phishing
Picture in picture CS 142 Lecture Notes: Security Attacks: Phishing
HTTPS Indicators But, site can override image: CS 142 Lecture Notes: Security Attacks: Phishing
Extended Validation Certificates Extended Normal Certificate Special indicator ? No obviousdifferences ? CS 142 Lecture Notes: Security Attacks: Phishing