Главная
Study mode:
on
1
Intro
2
"Phishing is the attempt to acquire sensitive information...by masquerading as a trustworthy entity in an electronic communication." - Wikipedia Phishing
3
Types of Attacks • Phishing - Usually no specific targets and for monetary gain • Spear Phishing - specific individuals or groups • Whaling - targeting executives
4
Setup and Deploy - Domain & Email • Domain Registration • Mass Mailers • Open Relays for the target domain
5
Setup and Deploy - Web • Web Server Setup • Web Site Cloning • Web Application Development
6
Responses / Post Exploitation • Credential Harvesting - testing credentials • Additional phishing attacks from trusted accounts • Malware - Connecting to botnet/shells and maintaining persistence • E…
7
Preparation User Awareness & Periodic Testing Detection & Analysis Alerts, Mail Proxies Containment, Eradication and Recovery Have a plan that is ready and tested
8
SpeedPhish Framework - SPF • Automates common tasks needed to perform a phishing exercise • Written in Python • Full/Partial automation • Can make use of external tools if available
9
Future Features • Company Profiler
Description:
Explore a comprehensive overview of phishing attacks and defense strategies in this BSides Knoxville 2015 conference talk. Delve into various types of phishing, including spear phishing and whaling, and learn about the setup and deployment of phishing campaigns through domain registration, email systems, and web server configurations. Discover techniques for credential harvesting, post-exploitation activities, and malware deployment. Gain insights into effective preparation, user awareness, detection, and response strategies to combat phishing threats. Examine the SpeedPhish Framework (SPF), an automated tool for conducting phishing exercises, and its potential future features. Enhance your understanding of this critical cybersecurity topic to better protect individuals and organizations from sophisticated phishing attempts.

Phishing - Going from Recon to Credentials

Add to list
0:00 / 0:00