官术网_书友最值得收藏!

Phone phishing (vishing)

This is a unique type of phishing where the attacker uses phone calls instead of emails. It is an advanced level of a phishing attack whereby the attacker will use an illegitimate interactive voice response system that sounds exactly like the ones used by banks, service providers, and so on. This attack is mostly used as an extension of the email phishing attack to make a target reveal secret information. A toll-free number is normally provided, which when called leads the target to the rogue interactive voice response system. The target will be prompted by the system to give out some verification information. It is normal for the system to reject input that a target gives so as to ensure that several PINs are disclosed. This is enough for the attackers to proceed and steal money from a target, be it a person or an organization. In extreme cases, a target will be forwarded to a fake customer care agent to assist with failed login attempts. The fake agent will continue questioning the target, gaining even more sensitive information.

The following diagram shows a scenario in which a hacker uses phishing to obtain the login credentials of a user:

主站蜘蛛池模板: 远安县| 广宗县| 开远市| 青铜峡市| 赤水市| 北海市| 康平县| 温宿县| 乌什县| 林口县| 岳池县| 图们市| 天峻县| 宝应县| 五华县| 察雅县| 庆安县| 即墨市| 芦溪县| 湘乡市| 万州区| 通州区| 张家口市| 德保县| 察哈| 蚌埠市| 巴林左旗| 东阿县| 定远县| 尼木县| 丁青县| 手机| 苏尼特左旗| 大田县| 英德市| 读书| 南阳市| 彩票| 达日县| 汝南县| 同心县|