官术网_书友最值得收藏!

Water holing

This is a social engineering attack that takes advantage of the amount of trust that users give to websites they regularly visit, such as interactive chat forums and exchange boards. Users on these websites are more likely to act in abnormally careless manners. Even the most careful people, who avoid clicking links in emails, will not hesitate to click on links provided on these types of website. These websites are referred to as watering holes because hackers trap their victims there just as predators wait to catch their prey at watering holes. Here, hackers exploit any vulnerabilities on the website, attack them, take charge, and then inject code that infects visitors with malware or that leads clicks to malicious pages. Due to the nature of the planning done by the attackers that choose this method, these attacks are normally tailored to a specific target and specific devices, operating systems, or applications that they use. It is used against some of the most IT-knowledgeable people, such as system administrators. An example of water holing is the exploitation of vulnerabilities in a site such as StackOverflow.com, which is often frequented by IT personnel. If the site is bugged, a hacker could inject malware into the computers of the visiting IT staff.

主站蜘蛛池模板: 巫山县| 麻江县| 通州区| 韶关市| 衡水市| 万山特区| 汝阳县| 龙海市| 奈曼旗| 九龙城区| 临江市| 汾西县| 额济纳旗| 南皮县| 凉山| 宁陕县| 昌都县| 三明市| 平定县| 贵州省| 望奎县| 柘荣县| 阿荣旗| 施甸县| 康乐县| 金坛市| 林州市| 铜陵市| 武城县| 宿州市| 石渠县| 襄城县| 万安县| 武宁县| 莱阳市| 桃园市| 卢湾区| 临洮县| 乃东县| 和龙市| 霍山县|