[HN Gopher] "Serverless" Phishing Campaign
___________________________________________________________________
"Serverless" Phishing Campaign
Author : kencausey
Score : 18 points
Date : 2021-05-22 14:36 UTC (1 days ago)
(HTM) web link (isc.sans.edu)
(TXT) w3m dump (isc.sans.edu)
| dmbaggett wrote:
| These are actually quite common now. They're especially
| problematic because since the credential harvesting happens on
| localhost, there's no bad site to take down, and no indicative
| URL. Often the Javascript payload is heavily obfuscated.
|
| This is one reason why we (INKY) sanitize HTML to normalize
| character representations, remove JavaScript, XSS, etc. You can
| no longer rely on client-side sanitization as you could in the
| desktop client days (though even some of the better web services,
| like Fastmail actually do sanitize). It's also why you have to be
| super paranoid about HTML attachments now.
| lanstin wrote:
| I just switched back to using rmail package in emacs to read
| mail. I made it ten years with the fancy email but the benefits
| have stopped exceeding the costs as email itself becomes less
| important.
___________________________________________________________________
(page generated 2021-05-23 23:02 UTC)