官术网_书友最值得收藏!

Phone phishing (vishing)

This is a unique type of phishing where the attacker uses phone calls instead of emails. It is an advanced level of a phishing attack whereby the attacker will use an illegitimate interactive voice response system that sounds exactly like the ones used by banks, service providers, and so on. This attack is mostly used as an extension of the email phishing attack to make a target reveal secret information. A toll-free number is normally provided, which when called leads the target to the rogue interactive voice response system. The target will be prompted by the system to give out some verification information. It is normal for the system to reject input that a target gives so as to ensure that several PINs are disclosed. This is enough for the attackers to proceed and steal money from a target, be it a person or an organization. In extreme cases, a target will be forwarded to a fake customer care agent to assist with failed login attempts. The fake agent will continue questioning the target, gaining even more sensitive information.

The following diagram shows a scenario in which a hacker uses phishing to obtain the login credentials of a user:

主站蜘蛛池模板: 仁布县| 晋宁县| 通河县| 镇坪县| 金川县| 南岸区| 亚东县| 米脂县| 托里县| 赞皇县| 台中县| 靖边县| 阜宁县| 江达县| 定襄县| 靖远县| 博罗县| 太仓市| 淮安市| 紫金县| 阿拉善右旗| 永和县| 水富县| 峡江县| 乌拉特后旗| 柞水县| 扎鲁特旗| 西宁市| 太和县| 婺源县| 剑川县| 浮山县| 龙山县| 连山| 永城市| 若尔盖县| 晋州市| 光山县| 沁阳市| 九龙坡区| 秦安县|