- Cybersecurity:Attack and Defense Strategies
- Yuri Diogenes Erdal Ozkaya
- 202字
- 2021-06-30 19:15:59
Phone phishing (vishing)
This is a unique type of phishing where the attacker uses phone calls instead of emails. It is an advanced level of a phishing attack whereby the attacker will use an illegitimate interactive voice response system that sounds exactly like the ones used by banks, service providers, and so on. This attack is mostly used as an extension of the email phishing attack to make a target reveal secret information. A toll-free number is normally provided, which when called leads the target to the rogue interactive voice response system. The target will be prompted by the system to give out some verification information. It is normal for the system to reject input that a target gives so as to ensure that several PINs are disclosed. This is enough for the attackers to proceed and steal money from a target, be it a person or an organization. In extreme cases, a target will be forwarded to a fake customer care agent to assist with failed login attempts. The fake agent will continue questioning the target, gaining even more sensitive information.
The following diagram shows a scenario in which a hacker uses phishing to obtain the login credentials of a user:

- Linux設(shè)備驅(qū)動開發(fā)詳解(第2版)
- Linux網(wǎng)絡(luò)管理與配置(第2版)
- Mastering ElasticSearch
- BPEL and Java Cookbook
- 精通Linux內(nèi)核開發(fā)
- Python基礎(chǔ)教程(第3版)
- OpenSolaris設(shè)備驅(qū)動原理與開發(fā)
- Linux基礎(chǔ)使用與案例
- Windows 7使用詳解(修訂版)
- 鴻蒙操作系統(tǒng)設(shè)計原理與架構(gòu)
- Learn SwiftUI
- Learning Continuous Integration with Jenkins(Second Edition)
- Less Web Development Essentials
- BuddyPress Theme Development
- Python機器學(xué)習(xí)系統(tǒng)構(gòu)建(原書第3版)