Без рубрики
Proposal for “Out of Character: Use of Punycode and Homoglyph Attacks to Obfuscate URLs for Phishing” Adrian Crenshaw
Below is a project I’m doing for class. If you want to make suggestions and tell me about weird Unicode/Homoglyph security issues, please email me. If you want to play with making homographs, look at my Homoglyph Attack Generator. Introduction One of the key components users leverage to tell if a URL is part of a … Read more
How I Got Network Creds Without Even Asking: A Social Engineering Case Study Jen Fox
On a professional pen testing engagement,why is one call or phish pretext selected over another? Why does it work (or not)? This case study describes how an SE pen testing engagement used a combination of exploits – phishing, vishing, and a spoofed site to successfully gain network credentials without even asking for them. Learn why … Read more
Economics of Information Security Paper Reviews and Notes
Below are my write-ups and notes for the papers I’ve been reading in the “Economics of Information Security” class I’m enrolled in. I’m guessing most of my readers won’t get much out of them unless they have read, or plan to read, the same papers. More to come as the class continues. Week 1 This … Read more