<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Web Admin Blog &#187; Phishing</title>
	<atom:link href="http://www.webadminblog.com/index.php/category/security/phishing/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.webadminblog.com</link>
	<description>Real Web Admins.  Real World Experience.</description>
	<lastBuildDate>Wed, 25 May 2011 03:02:28 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Spear Phishing &#8211; Breaking Into Wall Street &amp; Critical Infrastructure</title>
		<link>http://www.webadminblog.com/index.php/2009/03/23/spear-phishing-breaking-into-wall-street-critical-infrastructure/</link>
		<comments>http://www.webadminblog.com/index.php/2009/03/23/spear-phishing-breaking-into-wall-street-critical-infrastructure/#comments</comments>
		<pubDate>Mon, 23 Mar 2009 18:45:19 +0000</pubDate>
		<dc:creator>Josh</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[TRISC 2009]]></category>

		<guid isPermaLink="false">http://www.webadminblog.com/?p=218</guid>
		<description><![CDATA[For my first breakout session of the TRISC 2009 Conference, I decided to check out Rohyt Belani's presentation on Spear Phishing.  Rohyt is the CEO of Intrepidus Group and has spoken at a variety of conferences from BlackHat to OWASP to MISTI to Hack in the Box.  I had heard from several other conference attendees [...]]]></description>
			<content:encoded><![CDATA[<p>For my first breakout session of the TRISC 2009 Conference, I decided to check out Rohyt Belani's presentation on Spear Phishing.  Rohyt is the CEO of Intrepidus Group and has spoken at a variety of conferences from BlackHat to OWASP to MISTI to Hack in the Box.  I had heard from several other conference attendees that he was a pretty good speaker and the topic seemed interesting enough so I went and wasn't at all disappointed.  My notes (while not very long) from the presentation are below and the actual presentation can be found <a href="http://trisc.org/presentations/Big_Game_Phishing_Rohyt_Belani.pdf" target="_blank">here</a>:</p>
<ul>
<li><!--[if !supportLists]-->CEO of Intrepidus Group</li>
<li><!--[if !supportLists]--><span style="font-family: Symbol;"><span></span></span><!--[endif]-->Adjunct Professor at Carnegie Mellon University</li>
<li><!--[if !supportLists]--><span style="font-family: Symbol;"><span></span></span><!--[endif]-->Frequent speaker at BlackHat, OWASP, MISTI, Hack in the Box</li>
<li><!--[if !supportLists]--><span style="font-family: Symbol;"><span></span></span><!--[endif]-->Phishing: The act of electronically luring a user into surrendering private information that will be used for identity theft or conducting an act that will compromise the victim’s computer system.</li>
<li><!--[if !supportLists]--><span style="font-family: Symbol;"><span></span></span><!--[endif]-->Example of spear fishing used for pump-and-dump scam</li>
<li><!--[if !supportLists]--><span style="font-family: Symbol;"><span></span></span><!--[endif]-->Example of spear fishing used to download a Trojan, crack the admin password, and create domain administrator accounts on a windows server.</li>
<li><!--[if !supportLists]--><span style="font-family: Symbol;"><span></span></span><!--[endif]-->Have a service called fishme.com that is used to run mock attacks against companies.</li>
<li><!--[if !supportLists]--><span style="font-family: Symbol;"><span></span></span><!--[endif]-->23% +/- 3% are susceptible to phishing attacks based on surveying on fishme.com</li>
<li><!--[if !supportLists]--><span style="font-family: Symbol;"><span></span></span><!--[endif]-->Convincing people to click via authority works better than reward</li>
<li><!--[if !supportLists]--><span style="font-family: Symbol;"><span></span></span><!--[endif]-->People are more “click happy” on a Friday afternoon</li>
<li><!--[if !supportLists]--><span style="font-family: Symbol;"><span></span></span><!--[endif]-->Use an existing website that’s vulnerable to XSS or create a fake SSL certificate</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.webadminblog.com/index.php/2009/03/23/spear-phishing-breaking-into-wall-street-critical-infrastructure/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

