1

ShmooCon 2008: Unauthorized Phishing Awareness Exercise

http://www.hackaday.com

Filed under: [Syn Phishus] presented a pretty interesting talk. At $former_company he prepared and executed a rogue internal exercise designed to heighten awareness of phishing scams. (That is, attempts to gather personal information from users with trickery.) After noting a certain lack of effort on the part of security policy implementation, he put together an official looking email, set up a simple phishing site that didn't actually store any collected information and set loose the dogs of war. OK, he actually sent it to a select group within the company without warning anyone else ahead of time. He purposely didn't store any of the results to protect the foolish, but he estimates that maybe 10% of the recipients fell for it.Permalink | Email this | Linking Blogs | Comments

Read »
Created by Ian Created 45 weeks 4 days ago
Category: Mods   Tags:
  • Anonymous