Phishing Emails CS 142 Lecture Notes: Security Attacks: Phishing Slide 1 Legitimate: Extended Validation CS 142 Lecture Notes: Security Attacks: Phishing Slide 2

Download Report

Transcript Phishing Emails CS 142 Lecture Notes: Security Attacks: Phishing Slide 1 Legitimate: Extended Validation CS 142 Lecture Notes: Security Attacks: Phishing Slide 2

Phishing Emails
CS 142 Lecture Notes: Security Attacks: Phishing
Slide 1
Legitimate: Extended Validation
CS 142 Lecture Notes: Security Attacks: Phishing
Slide 2
Obviously Illegitimate
http://rusprory.mass.hc.ru/old_site/update/index.php
CS 142 Lecture Notes: Security Attacks: Phishing
Slide 3
Look-alike Characters
CS 142 Lecture Notes: Security Attacks: Phishing
Slide 4
Legitimate Partners Can Look Fishy
???
???
CS 142 Lecture Notes: Security Attacks: Phishing
Slide 5
International Character Sets
● What does this URL refer to?
www.bank.com/accounts/login.php?q=me.badguy.cn
Chinese characters that look like "/", "?", and "="
● This is a host name only!
CS 142 Lecture Notes: Security Attacks: Phishing
Slide 6
Picture in picture
CS 142 Lecture Notes: Security Attacks: Phishing
Slide 7
HTTPS Indicators
HTTP
HTTPS
Firefox 10
IE 8
Chrome 17
CS 142 Lecture Notes: Security Attacks: Phishing
Slide 8
Extended Validation Certificates
Extended
Normal HTTPS
Firefox 10
IE 8
Chrome 17
Certificate
Authority
CS 142 Lecture Notes: Security Attacks: Phishing
Slide 9
CS 142 Lecture Notes: Security Attacks: Phishing
Slide 10