A Rant About Phishing: It's Not the User's Fault (and Not DNS Either)
by jelizondo from SoylentNews on (#78CJM)
owl writes:
https://maurycyz.com/misc/domains/
"For safety, don't click suspicious links"
Meanwhile, most organization's login flow redirects through:
- # This is a real example, but I've changed the names to avoid pointing fingers
- https://www.[name of company].com/squawk/
- https://login.[name of company].com/
- https://login.smallcrow.com/324aa78a-03a6-66fc-23e1-4124fdsa213
- https://experience.crow-cloud.com/[name of company]/auth
- https://flock.auth.bird-security.com/authorization
- https://api-deadbeef.bird-security.com/oauth/v1/authorize?token=DeAdBeEf
- https://api2.bird-security.com/2fa
- https://www.[name of company].com/cool/bird/
- https://experience.crow-cloud.com/[name of company]/
- https://www.[name of company].com/squawk/
Neither the username, password nor 2FA prompts are hosted on the company's own domain. Combine that with token expiration triggering random authetication pop-ups, it becomes nearly impossible to notice phishing... because the real thing looks identical to a scam:
All an attacker has to do is write a website with a password box and the company logo. The URL doesn't matter because users have learned to ignore it.
Read more of this story at SoylentNews.