Penetration Testing mailing list archives
New SecurityFocus article: Phishing with Rachna Dhamija
From: Erin Carroll <amoeba () amoebazone com>
Date: Mon, 19 Jun 2006 19:12:03 +0000 (UTC)
All,Generally not a pen-testing specific realm but interesting nonetheless. Has anyone ever leveraged phishing during pen-testing for human data-leakage/social engineering? Is there a viable use for it in pen-testing?
The following interview was published on SecurityFocus today: Phishing with Rachna Dhamija interview by Federico Biancuzzi 2006-06-19Federico Biancuzzi interviews Rachna Dhamija, co-author of the paper "Why Phishing Works" and creator of Dynamic Security Skins. They discuss the human factor, how easy it is to recreate a credible browser window made with images, some new anti-phishing features included in the upcoming version of some popular browsers, and the power of letting a user personalize his interface.
http://www.securityfocus.com/columnists/407 ------------------------------------------------------------------------------ This List Sponsored by: CenzicConcerned about Web Application Security? Why not go with the #1 solution - Cenzic, the only one to win the Analyst's Choice Award from eWeek. As attacks through web applications continue to rise, you need to proactively protect your applications from hackers. Cenzic has the most comprehensive solutions to meet your application security penetration testing and vulnerability management needs. You have an option to go with a managed service (Cenzic ClickToSecure) or an enterprise software (Cenzic Hailstorm). Download FREE whitepaper on how a managed service can help you: http://www.cenzic.com/news_events/wpappsec.php And, now for a limited time we can do a FREE audit for you to confirm your results from other product. Contact us at request () cenzic com for details.
------------------------------------------------------------------------------
Current thread:
- New SecurityFocus article: Phishing with Rachna Dhamija Erin Carroll (Jun 19)