 |
Unusual new phishing technique
08-31-2021, 09:36 AM
|
#1
|
Moderator
Join Date: Feb 2010
Location: Flyover country
Posts: 23,920
|
Unusual new phishing technique
Just saw this and thought a general warning would be in order. I think most of us are used to hovering over a URL to check where it actually goes, but this trick can bypass that safeguard in a couple of ways.
Quote:
This phishing attack is using a sneaky trick to steal your passwords, warns Microsoft
Hovering over a link in an email isn't going to be enough to check if it's going to take you to a dangerous site.
|
ZDNet article
__________________
I thought growing old would take longer.
|
|
|
 |
Join the #1 Early Retirement and Financial Independence Forum Today - It's Totally Free!
Are you planning to be financially independent as early as possible so you can live life on your own terms? Discuss successful investing strategies, asset allocation models, tax strategies and other related topics in our online forum community. Our members range from young folks just starting their journey to financial independence, military retirees and even multimillionaires. No matter where you fit in you'll find that Early-Retirement.org is a great community to join. Best of all it's totally FREE!
You are currently viewing our boards as a guest so you have limited access to our community. Please take the time to register and you will gain a lot of great new features including; the ability to participate in discussions, network with our members, see fewer ads, upload photographs, create a retirement blog, send private messages and so much, much more!
|
08-31-2021, 10:04 AM
|
#2
|
Give me a museum and I'll fill it. (Picasso) Give me a forum ...
Join Date: Jan 2007
Location: Independence
Posts: 7,123
|
So what does one do to combat and be safe? Google says "not our problem - the hover to check isn't useful security anyway". Didn't notice an answer in the article.
Just be afraid, be very afraid? I've been counting on things looking bogus, not actual seriously plausible sneak attacks. my stomach hurts.
__________________
"Be kind whenever possible. It is always possible." Dalai Lama
|
|
|
08-31-2021, 10:11 AM
|
#3
|
Give me a museum and I'll fill it. (Picasso) Give me a forum ...
Join Date: May 2013
Location: ATL --> Flyover Country
Posts: 6,649
|
Quote:
Originally Posted by calmloki
So what does one do to combat and be safe? Google says "not our problem - the hover to check isn't useful security anyway". Didn't notice an answer in the article.
Just be afraid, be very afraid? I've been counting on things looking bogus, not actual seriously plausible sneak attacks. my stomach hurts.
|
I think the pop-up warning is the key.
Quote:
This particular attack relies on the email sales and marketing tool called 'open redirects', which has been abused in the past to redirect a visitor to a trustworthy destination to a malicious site. Google doesn't rate open redirects for Google URLs as a security vulnerability, but it does display a 'redirect notice' in the browser.
|
__________________
FIRE'd in 2014 @ 40 Years Old
Professional Retiree
|
|
|
08-31-2021, 11:21 AM
|
#4
|
Give me a museum and I'll fill it. (Picasso) Give me a forum ...
Join Date: Jul 2014
Location: Spending the Kids Inheritance and living in Chicago
Posts: 15,903
|
I wish the site had given an example of a redirect
__________________
Fortune favors the prepared mind. ... Louis Pasteur
|
|
|
08-31-2021, 11:23 AM
|
#5
|
Moderator
Join Date: Feb 2010
Location: Flyover country
Posts: 23,920
|
Quote:
Originally Posted by Sunset
I wish the site had given an example of a redirect
|
It can vary, but here is one example:
__________________
I thought growing old would take longer.
|
|
|
08-31-2021, 12:37 PM
|
#6
|
Give me a museum and I'll fill it. (Picasso) Give me a forum ...
Join Date: Sep 2005
Location: Northern IL
Posts: 26,281
|
Quote:
Originally Posted by calmloki
So what does one do to combat and be safe? Google says "not our problem - the hover to check isn't useful security anyway". Didn't notice an answer in the article.
Just be afraid, be very afraid? I've been counting on things looking bogus, not actual seriously plausible sneak attacks. my stomach hurts.
|
Simple - NEVER (and I'm breaking my rule of 'never say never'), but NEVER click on a link from an email. NEVER call a number regarding finances that was provided for you (email or voice message).
Go to the site directly from a known address, or call the number on your CC, bank statement etc.
-ERD50
|
|
|
08-31-2021, 12:40 PM
|
#7
|
Thinks s/he gets paid by the post
Join Date: Feb 2014
Posts: 2,850
|
I set privacy settings in Thunderbird to block remote content by default. If the email is trusted I click allow remote content.
|
|
|
08-31-2021, 02:29 PM
|
#8
|
Moderator
Join Date: Oct 2010
Posts: 10,181
|
Maybe I've got this wrong, but aren't the same people that hover over a link to see if it's legit, the same crowd that looks at the link in the browser's address bar so see if it's legit too? If you're redirected to russianbadguy.com, I probably wouldn't interact with the page, hehe!
|
|
|
08-31-2021, 05:34 PM
|
#9
|
Recycles dryer sheets
Join Date: Jun 2021
Posts: 65
|
Who ever clicks on links in emails anymore? I haven't done that in years. Just go to the site and login and find what you need. The hovering itself doesn't cause the problem, it's only the clicking. Don't trust the hover, and you'll be fine.
|
|
|
08-31-2021, 05:51 PM
|
#10
|
Thinks s/he gets paid by the post
Join Date: Oct 2010
Posts: 1,155
|
Quote:
Originally Posted by ERD50
Simple - NEVER (and I'm breaking my rule of 'never say never'), but NEVER click on a link from an email. NEVER call a number regarding finances that was provided for you (email or voice message).
Go to the site directly from a known address, or call the number on your CC, bank statement etc.
-ERD50
|
Yep, this is how you deal with it.
|
|
|
 |
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
|
|
Thread Tools |
Search this Thread |
|
|
Display Modes |
Linear Mode
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
|
» Recent Threads
|
|
|
|
|
|
|
|
|
|
|
|
|
» Quick Links
|
|
|