Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Gone Phishing

Gone Phishing

Nova Scotia Tech Tune Up 2017 Presentation

drifter666

March 13, 2017
Tweet

More Decks by drifter666

Other Decks in Technology

Transcript

  1. Audience Question Period • Phishing Campaigns • Black/White Hat •

    Kali Linux • Remote Command Execution • Privilege Escalation • DEP/ASLR
  2. Security Priorities (From Google’s Security Blog) SECURITY NON-EXPERTS • 1)

    Use Antivirus • 2) Use Strong Passwords • 3) Change Passwords Frequently • 4) Only Visit Websites They Know • 5) Don’t Share Personal Information SECURITY EXPERTS • 1) Install Software Updates • 2) Use Unique Passwords • 3) Use Two-Factor Authentication • 4) Use Strong Passwords • 5) Use a Password Manager https://security.googleblog.com/2015/07/new-research-comparing-how-security.html
  3. Phishing DEFINITION • A scam by which an e-mail user

    is duped into revealing personal or confidential information which the scammer can use illicitly source: https://www.merriam-webster.com/dictionary/phishing
  4. Phishing DEFINITION • A scam by which an e-mail user

    is duped into revealing personal or confidential information which the scammer can use illicitly source: https://www.merriam-webster.com/dictionary/phishing • A scam by which an e-mail, SMS, phone user is duped into revealing personal or confidential information which the scammer can use illicitly
  5. Victim Story 1 source: http://www.cbc.ca/news/canada/nova-scotia/criminals-phishing-banks-fraud-scotiabank-infoalerts-scene-1.4017269 SCAM • Fraudsters replicated a

    SMS message mimicking Scotiabank's InfoAlerts • Brenda and Fernando responded to the SMS message and lost $3000 • Bank insurance won’t cover it because they willingly gave their information away
  6. How to Fight Phishing • Phishing Awareness Training • Hardware

    (Firewalls, Mail Gateways, etc.) • Software (AntiVirus, AntiMalware, etc.) There is no 100% foolproof option