[HN Gopher] "Serverless" Phishing Campaign
       ___________________________________________________________________
        
       "Serverless" Phishing Campaign
        
       Author : kencausey
       Score  : 18 points
       Date   : 2021-05-22 14:36 UTC (1 days ago)
        
 (HTM) web link (isc.sans.edu)
 (TXT) w3m dump (isc.sans.edu)
        
       | dmbaggett wrote:
       | These are actually quite common now. They're especially
       | problematic because since the credential harvesting happens on
       | localhost, there's no bad site to take down, and no indicative
       | URL. Often the Javascript payload is heavily obfuscated.
       | 
       | This is one reason why we (INKY) sanitize HTML to normalize
       | character representations, remove JavaScript, XSS, etc. You can
       | no longer rely on client-side sanitization as you could in the
       | desktop client days (though even some of the better web services,
       | like Fastmail actually do sanitize). It's also why you have to be
       | super paranoid about HTML attachments now.
        
         | lanstin wrote:
         | I just switched back to using rmail package in emacs to read
         | mail. I made it ten years with the fancy email but the benefits
         | have stopped exceeding the costs as email itself becomes less
         | important.
        
       ___________________________________________________________________
       (page generated 2021-05-23 23:02 UTC)