Re: Phishing

"Paul D. Robertson" <[email protected]> Thu, 11 Apr 2013 05:38:07 -0400
Newsgroups gmane.comp.security.firewalls.wizards
Message-ID <[email protected]>
I've had friends tell me that they've never failed using fake LinkedIn accounts when performing pen tests- I'm not sure how valuable training is, but I'm reasonably confident it and Facebook are the top two common vectors.

Paul
--
President and Chairman, FluidIT Group
Moderator, Firewall-Wizards
http://pauldrobertson.net
http://pauldrobertson.com
@compuwar

On Apr 10, 2013, at 18:56, Dotzero <[email protected]> wrote:

> Training is useful as long as it is appropriate training that the
> enduser can reasonably implement.
> 
> As far as blocking Facebook/LinkedIn, I don't believe it is a
> particularly useful approach. I prefer to educate endusers on ways to
> mitigate risks.
> 
> An example of this is to never click on purported LinkedIn emails.
> Delete them and log into the site to check the message. Another
> example is to never accept an invitation to link from someone you
> don't know unless someone you know vouches for them. Taking these
> sorts of steps significantly reduces potential risks.
> 
> I do recommend applying SPF/DKIM/DMARC validation to inbound mail
> streams. ISPs and mailbox providers such as Gmail, Yahoo! and AOL are
> ahead of enterprises in doing this. Inbound email authentication
> validation adds a layer of protection to protect your users and
> organization. If you have a brand/domain at risk it is useful to
> implement on the sending side to help protect your customers, partners
> and vendors.
> 
> Reporting malicious URLs and redirectors that arrive in your inbox(s)
> or traps to APWG is useful as is reporting them to the abuse contact
> in whois or to the upstream provider.
> 
> A good practice is to also implement BCP38 outbound filtering. It
> protects your reputation and ultimately helps everyone else from abuse
> eminating from your network.
> 
> Just a few thoughts,
> 
> Mike
> 
> On Wed, Apr 10, 2013 at 5:52 PM, Paul D. Robertson <[email protected]> wrote:
>> Outside of constant training and blocking Facebook/LinkedIn does anyone have any good pointers or tools for phishing/spear phishing threats?
>> 
>> Paul
>> --
>> President and Chairman, FluidIT Group
>> Moderator, Firewall-Wizards
>> http://pauldrobertson.net
>> http://pauldrobertson.com
>> @compuwar
>> _______________________________________________
>> firewall-wizards mailing list
>> [email protected]
>> https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
> _______________________________________________
> firewall-wizards mailing list
> [email protected]
> https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards