JavaScript is required to use Bungie.net

离题

浏览大量随机讨论。
由Recon Number 54编辑: 6/24/2015 6:43:04 PM
85

PSA: Beware of a very simple and very effective social engineering ruse to break dual-verification

[url=http://thenextweb.com/insider/2015/06/19/this-social-engineering-trick-makes-breaking-into-email-accounts-scarily-easy/#][u]This social engineering trick makes breaking into email accounts scarily easy[/u][/url] [quote]The anatomy of the attack in the video is fairly simple, but surprisingly effective: *Send the victim a text from an unknown number, warning them that they’re about to receive a code to ensure their Google account is secure and asking them to reply with the code to confirm *Trigger the Gmail password reset process, which sends a message containing an unlock code to the registered phone *The user receives the code they’ve been warned about and sends it back to the attacker *Attacker logs in to Gmail account without detection[/quote] Just remember, if you get a text message that asks for a password OR a code, do NOT reply to the text. Dual-authentication is (and always should be) a "one way" conversation where your code is sent to you at YOUR request and you enter it into your own session.

发贴语言:

 

遵守游戏礼仪。发送贴子前请花点时间阅读我们的行为准则 取消 编辑 创建火力战队 贴子

查看完整话题
  • 由Frogley编辑: 6/26/2015 10:56:06 AM
    Wouldn't you have to be in contact with that person to do this? Just curious. Because it seems like only someone close to the person, or who has knowledge of the person could do this to them. Also they'd have to be gullible But then again I don't know the athuentication process very well so maybe I couldve fallen for it.

    发贴语言:

     

    遵守游戏礼仪。发送贴子前请花点时间阅读我们的行为准则 取消 编辑 创建火力战队 贴子

    1 回复
    你没有权限查看此内容。
    ;
    preload icon
    preload icon
    preload icon