Penetration Testing mailing list archives

New SecurityFocus article: Phishing with Rachna Dhamija


From: Erin Carroll <amoeba () amoebazone com>
Date: Mon, 19 Jun 2006 19:12:03 +0000 (UTC)


All,

Generally not a pen-testing specific realm but interesting nonetheless. Has anyone ever leveraged phishing during pen-testing for human data-leakage/social engineering? Is there a viable use for it in pen-testing?


The following interview was published on SecurityFocus today:

Phishing with Rachna Dhamija
interview by Federico Biancuzzi
2006-06-19

Federico Biancuzzi interviews Rachna Dhamija, co-author of the paper "Why Phishing Works" and creator of Dynamic Security Skins. They discuss the human factor, how easy it is to recreate a credible browser window made with images, some new anti-phishing features included in the upcoming version of some popular browsers, and the power of letting a user personalize his interface.

http://www.securityfocus.com/columnists/407

------------------------------------------------------------------------------
This List Sponsored by: Cenzic

Concerned about Web Application Security? Why not go with the #1 solution - Cenzic, the only one to win the Analyst's Choice Award from eWeek. As attacks through web applications continue to rise, you need to proactively protect your applications from hackers. Cenzic has the most comprehensive solutions to meet your application security penetration testing and vulnerability management needs. You have an option to go with a managed service (Cenzic ClickToSecure) or an enterprise software (Cenzic Hailstorm). Download FREE whitepaper on how a managed service can help you: http://www.cenzic.com/news_events/wpappsec.php And, now for a limited time we can do a FREE audit for you to confirm your results from other product. Contact us at request () cenzic com for details.
------------------------------------------------------------------------------


Current thread: