Phishing Emails CS 142 Lecture Notes: Security Attacks: Phishing - - PowerPoint PPT Presentation

phishing emails
SMART_READER_LITE
LIVE PREVIEW

Phishing Emails CS 142 Lecture Notes: Security Attacks: Phishing - - PowerPoint PPT Presentation

Phishing Emails CS 142 Lecture Notes: Security Attacks: Phishing Slide 1 Legitimate: Extended Validation CS 142 Lecture Notes: Security Attacks: Phishing Slide 2 Obviously Illegitimate http://rusprory.mass.hc.ru/old_site/update/index.php CS


slide-1
SLIDE 1

Slide 1

Phishing Emails

CS 142 Lecture Notes: Security Attacks: Phishing

slide-2
SLIDE 2

CS 142 Lecture Notes: Security Attacks: Phishing Slide 2

Legitimate: Extended Validation

slide-3
SLIDE 3

CS 142 Lecture Notes: Security Attacks: Phishing Slide 3

Obviously Illegitimate

http://rusprory.mass.hc.ru/old_site/update/index.php

slide-4
SLIDE 4

CS 142 Lecture Notes: Security Attacks: Phishing Slide 4

Look-alike Characters

slide-5
SLIDE 5

CS 142 Lecture Notes: Security Attacks: Phishing Slide 5

Legitimate Partners Can Look Fishy

??? ???

slide-6
SLIDE 6

CS 142 Lecture Notes: Security Attacks: Phishing Slide 6

International Character Sets

  • What does this URL refer to?

www.bank.com/accounts/login.php?q=me.badguy.cn

  • This is a host name only!

Chinese characters that look like "/", "?", and "="

slide-7
SLIDE 7

CS 142 Lecture Notes: Security Attacks: Phishing Slide 7

Picture in picture

slide-8
SLIDE 8

CS 142 Lecture Notes: Security Attacks: Phishing Slide 8

HTTPS Indicators

HTTP HTTPS Firefox 10 IE 8 Chrome 17

slide-9
SLIDE 9

CS 142 Lecture Notes: Security Attacks: Phishing Slide 9

Extended Validation Certificates

Extended Normal HTTPS Firefox 10 IE 8 Chrome 17

Certificate Authority

slide-10
SLIDE 10

CS 142 Lecture Notes: Security Attacks: Phishing Slide 10