- Cybersecurity:Attack and Defense Strategies
- Yuri Diogenes Erdal Ozkaya
- 202字
- 2021-06-30 19:15:59
Phone phishing (vishing)
This is a unique type of phishing where the attacker uses phone calls instead of emails. It is an advanced level of a phishing attack whereby the attacker will use an illegitimate interactive voice response system that sounds exactly like the ones used by banks, service providers, and so on. This attack is mostly used as an extension of the email phishing attack to make a target reveal secret information. A toll-free number is normally provided, which when called leads the target to the rogue interactive voice response system. The target will be prompted by the system to give out some verification information. It is normal for the system to reject input that a target gives so as to ensure that several PINs are disclosed. This is enough for the attackers to proceed and steal money from a target, be it a person or an organization. In extreme cases, a target will be forwarded to a fake customer care agent to assist with failed login attempts. The fake agent will continue questioning the target, gaining even more sensitive information.
The following diagram shows a scenario in which a hacker uses phishing to obtain the login credentials of a user:

- pcDuino開發實戰
- Linux Mint Essentials
- Ansible權威指南
- Kali Linux滲透測試全流程詳解
- VMware Horizon View 6 Desktop Virtualization Cookbook
- 開源安全運維平臺OSSIM疑難解析:入門篇
- Linux網絡內核分析與開發
- 注冊表應用完全DIY
- RHCSARHCE 紅帽Linux認證學習指南(第7版)EX200 & EX300
- Social Data Visualization with HTML5 and JavaScript
- 統信UOS應用開發進階教程
- Linux內核API完全參考手冊(第2版)
- OpenVZ Essentials
- 應急指揮信息系統設計
- Linux內核修煉之道