官术网_书友最值得收藏!

Water holing

This is a social engineering attack that takes advantage of the amount of trust that users give to websites they regularly visit, such as interactive chat forums and exchange boards. Users on these websites are more likely to act in abnormally careless manners. Even the most careful people, who avoid clicking links in emails, will not hesitate to click on links provided on these types of website. These websites are referred to as watering holes because hackers trap their victims there just as predators wait to catch their prey at watering holes. Here, hackers exploit any vulnerabilities on the website, attack them, take charge, and then inject code that infects visitors with malware or that leads clicks to malicious pages. Due to the nature of the planning done by the attackers that choose this method, these attacks are normally tailored to a specific target and specific devices, operating systems, or applications that they use. It is used against some of the most IT-knowledgeable people, such as system administrators. An example of water holing is the exploitation of vulnerabilities in a site such as StackOverflow.com, which is often frequented by IT personnel. If the site is bugged, a hacker could inject malware into the computers of the visiting IT staff.

主站蜘蛛池模板: 巢湖市| 容城县| 桑植县| 永登县| 玉山县| 游戏| 遂宁市| 乐安县| 聂荣县| 霍林郭勒市| 会同县| 祁门县| 金门县| 临武县| 凤台县| 松原市| 白山市| 泗洪县| 鄂托克旗| 同仁县| 德保县| 东宁县| 保德县| 桐乡市| 寻甸| 治县。| 金山区| 连南| 乳山市| 彰武县| 新源县| 祁东县| 东光县| 九龙县| 集安市| 罗田县| 中西区| 三台县| 蒙阴县| 林芝县| 平阴县|