1283
I'm in! (lemmy.world)
you are viewing a single comment's thread
view the rest of the comments
[-] ozymandias117@lemmy.world 55 points 2 years ago

The one they use at my work is extra silly, as it adds an extra email header saying it’s coming from a phishing campaign

[-] frickineh@lemmy.world 52 points 2 years ago

Ours do that too. It's so obvious that I'm not sure if they think we're all stupid, except then I remember that some of my coworkers actually are stupid, so it's probably aimed at them.

[-] cm0002@lemmy.world 58 points 2 years ago

except then I remember that some of my coworkers actually are stupid, so it's probably aimed at them.

I work in IT and have done these campaigns, if you're on Lemmy, you're probably not the target audience lmao

[-] LowtierComputer@lemmy.world 34 points 2 years ago

There's an older guy in my group who rants and raves about how all the new training is a waste of time. Discrimination, harassment, safety, information security, all of it. But he specifically hates the fraud and phishing training.

He's the only one in our group that has failed any of the test emails.

[-] jballs@sh.itjust.works 23 points 2 years ago

I've worked with a dude for years who I would consider smart both technically and non-technically. One time we got an email at work with an attachment that was something like "microsoft_update.exe.txt". The email said "due to a technical limitation on the email system, this file needs to be renamed to drop the .txt and executed to apply a critical to your computer."

It was, in my mind, such an obvious phishing attempt that I laughed out loud and said "who the fuck would ever fall for this?" Then my coworker popped his head over the cube wall and said "WAIT WHAT? We weren't supposed to run that?!"

Fortunately, the security team sat nearby and heard the whole thing and rushed over to quarantine his PC

[-] Emerald@lemmy.world 14 points 2 years ago

quarantine his PC

You mean shut it off and steal and the Ethernet cable? Lol

[-] groet@feddit.de 10 points 2 years ago

You DONT want to turn it off. Digital forensics work WAAAAAAY better if you have a memory dump of the system. And all the memory is lost if you turn it off. Even if the virus ran 10h ago and the program has long stoped running, there will most likely still be traces in the RAM. Like a hard drive, simply deleting something in RAM doesn't mean it is gone. As long as that specific area was not written over later it will still hold the same contenta. You can sometimes find memory that belonged to a virus days or even weeks after the infection if the system was never shut down. There is so much information in ram that is lost when the power is turned off.

You want to 1: quarantine from network (don't pull the cable at the system, but firewall it at the switch if possible) 2: take a full copy of the RAM 2.5: read out bitlocker keys if the drive is encrypted. 3: turn off and take a bitwise copy of the hard drive or just send the drive + memory dump to the forensics team. 4: get coffee

[-] Emerald@lemmy.world 7 points 2 years ago

Why would you be doing digital forensics?

[-] KISSmyOSFeddit@lemmy.world 12 points 2 years ago

To find out if nuking that one workstation is enough or if you have to take more drastic measures.

[-] Emerald@lemmy.world 4 points 2 years ago

I feel like most companies wouldn't bother with all that. They'd probably just nuke the workstation and call it a day.

[-] KISSmyOSFeddit@lemmy.world 7 points 2 years ago

And then get ransomwared a bit later.

[-] Emerald@lemmy.world 4 points 2 years ago

Oh yeah probably

[-] JasonDJ@lemmy.zip 2 points 2 years ago

Yeah no. You gotta do due diligence. Getting one system compromised isn't enough. The whole point is to pivot, elevate, repeat.

[-] Boozilla@lemmy.world 9 points 2 years ago

Even a smart person can have a bad day / moment of weakness. If you are super busy / stressed out and some email comes that looks like a bullshit request from HR or IT or whatever, it can be tempting to just try to knock it off your plate real quick so you can get back to whatever fire you were fighting.

My tactic these days is I pretty much don't click on ANYTHING in an email, so it's an ingrained habit. If it's a link to something, it's usually one I can navigate to myself using my browser. If it's an attachment, we use a file sharing system that stores these so I can just go to that and see what's in there.

It's inconvenient, and you don't always have these work-around options, but by trying to make into an automatic habit, it has saved me a couple of times.

[-] Boozilla@lemmy.world 5 points 2 years ago

That's really funny. It's like you work for Dunder-Mifflin.

[-] smort@lemmy.world 3 points 2 years ago

Lots of us do lol

[-] bl_r@lemmy.dbzer0.com 4 points 2 years ago

Lmao, the other day I had to whitelist some domains used for phishing training emails in the anti-phishing software we use just so they wouldn’t get nuked, then I had to whitelist them in another anti-phishing software so they wouldn’t have - huge red header injected on the top of the email body warning the user it was phishing.

[-] Magister@lemmy.world 3 points 2 years ago

haha same for me, the header contains the word "gophish", easy to filter it

[-] borari@lemmy.dbzer0.com 2 points 2 years ago

Damn. I’ve scripted out the entire process of verifying an owned domain in a hosted mail providers system, deploying the ec2 infrastructure, and installing and configuring gophish for a campaign, along with tearing everything down.

That header thing gophish adds is a default option that you can override by just setting that header to an empty string. Whoever runs campaigns for your employer either wants to make it easy for you to pass or doesn’t care about their job at all.

I’ve done it in the context of red team/adversary emulation campaigns before though, so the opsec needed to be a bit tighter than the mandatory phishing awareness stuff i guess.

this post was submitted on 10 May 2024
1283 points (98.6% liked)

Comic Strips

23926 readers
883 users here now

Comic Strips is a community for those who love comic stories.

Rules
  1. 😇 Be Nice!

    • Treat others with respect and dignity. Friendly banter is okay, as long as it is mutual; keyword: friendly.
  2. 🏘️ Community Standards

    • Comics should be a full story, from start to finish, in one post.
    • Posts should be safe and enjoyable by the majority of community members, both here on lemmy.world and other instances.
    • Any comic that would qualify as raunchy, lewd, or otherwise draw unwanted attention by nosy coworkers, spouses, or family members should be tagged as NSFW.
    • Moderators have final say on what and what does not qualify as appropriate. Use common sense, and if need be, err on the side of caution.
  3. 🧬 Keep it Real

    • Comics should be made and posted by real human beans, not by automated means like bots or AI. This is not the community for that sort of thing.
  4. 📽️ Credit Where Credit is Due

    • Comics should include the original attribution to the artist(s) involved, and be unmodified. Bonus points if you include a link back to their website. When in doubt, use a reverse image search to try to find the original version. Repeat offenders will have their posts removed, be temporarily banned from posting, or if all else fails, be permanently banned from posting.
    • Attributions include, but are not limited to, watermarks, links, or other text or imagery that artists add to their comics to use for identification purposes. If you find a comic without any such markings, it would be a good idea to see if you can find an original version. If one cannot be found, say so and ask the community for help!
  5. 📋 Post Formatting

    • Post an image, gallery, or link to a specific comic hosted on another site; e.g., the author's website.
    • Meta posts about the community should be tagged with [Meta] either at the beginning or the end of the post title.
    • When linking to a comic hosted on another site, ensure the link is to the comic itself and not just to the website; e.g.,
      ✅ Correct: https://xkcd.com/386/
      ❌ Incorrect: https://xkcd.com/
  6. 📬 Post Frequency/SPAM

    • Each user (regardless of instance) may post up to five (5 🖐) comics a day. This can be any combination of personal comics you have written yourself, or other author's comics. Any comics exceeding five (5 🖐) will be removed.
  7. 🏴‍☠️ Internationalization (i18n)

    • Non-English posts are welcome. Please tag the post title with the original language, and include an English translation in the body of the post; e.g.,
      Sí, por favor [Spanish/Español]
  8. 🍿 Moderation

    • We are human, just like most everybody else on Lemmy. If you feel a moderation decision was made in error, you are welcome to reach out to anybody on the moderation team for clarification. Keep in mind that moderation decisions may be final.
    • When reporting posts and/or comments, quote which rule is being broken, and why you feel it broke the rules.
Banned Artists

The following artists are banned from the community.

  1. Jago
  2. Stonetoss

It should be noted that when you make reports, it is your responsibility to provide rational reasoning why something should be removed. Saying it simply breaks community rules is not always good enough.

Web Accessibility

Note: This is not a rule, but a helpful suggestion.

When posting images, you should strive to add alt-text for screen readers to use to describe the image you're posting:

Another helpful thing to do is to provide a transcription of the text in your images, as well as brief descriptions of what's going on. (example)

Web of Links

founded 2 years ago
MODERATORS