官术网_书友最值得收藏!

Phone phishing (vishing)

This is a unique type of phishing where the attacker uses phone calls instead of emails. It is an advanced level of a phishing attack whereby the attacker will use an illegitimate interactive voice response system that sounds exactly like the ones used by banks, service providers, and so on. This attack is mostly used as an extension of the email phishing attack to make a target reveal secret information. A toll-free number is normally provided, which when called leads the target to the rogue interactive voice response system. The target will be prompted by the system to give out some verification information. It is normal for the system to reject input that a target gives so as to ensure that several PINs are disclosed. This is enough for the attackers to proceed and steal money from a target, be it a person or an organization. In extreme cases, a target will be forwarded to a fake customer care agent to assist with failed login attempts. The fake agent will continue questioning the target, gaining even more sensitive information.

The following diagram shows a scenario in which a hacker uses phishing to obtain the login credentials of a user:

主站蜘蛛池模板: 石景山区| 三门县| 密云县| 怀化市| 祥云县| 石柱| 黔南| 青龙| 永和县| 泰和县| 保康县| 临邑县| 德州市| 昌乐县| 灌南县| 榆社县| 忻城县| 潜山县| 河北省| 沙田区| 布拖县| 连城县| 张家川| 鹤峰县| 元朗区| 济阳县| 沁源县| 阳山县| 中阳县| 获嘉县| 房产| 包头市| 金寨县| 揭西县| 贵德县| 平山县| 闵行区| 开江县| 陵川县| 永泰县| 林州市|