{"id":182,"date":"2006-01-19T00:42:36","date_gmt":"2006-01-18T13:42:36","guid":{"rendered":"http:\/\/www.somethinkodd.com\/oddthinking\/2006\/01\/19\/mock-phish-proposal\/"},"modified":"2006-04-13T01:29:15","modified_gmt":"2006-04-12T14:29:15","slug":"mock-phish-proposal","status":"publish","type":"post","link":"https:\/\/www.somethinkodd.com\/oddthinking\/2006\/01\/19\/mock-phish-proposal\/","title":{"rendered":"Mock-Phish Proposal"},"content":{"rendered":"<h3>Phase A: Using My Powers For Good<\/h3>\n<p>I propose that we produce a Mock-Phish web-site, which will have a goal of helping security professionals to train their co-workers, family and friends to <em>avoid<\/em> falling for phishing scams.<\/p>\n<p>One page will allow the user to nominate a naive computer user (known as the &#8216;mark&#8217;). They will enter the basic contact details of the mark (e.g. email address and perhaps name), a from address (e.g. security@<em>yourorganisation<\/em>.com, support@<em>yourbank<\/em>.com) and choose from a selection of pre-written phishing text.<\/p>\n<p>The Mock-Phish site will then forward an email (with appropriately forged headers) to the mark.<\/p>\n<p>The obfuscated URL inside the email points to a corresponding page of the Mock-Phish site, which invites the user to enter private information (e.g. corporate login name and password, or account number and PIN.) It has a submit button.<\/p>\n<p>Sounds ominous, but here&#8217;s the twist: the submit button just does a regular <code>HTTP-GET<\/code>, and does not forward the entered details. The entered details are simply discarded in the browser. The submit button simply directs the browser to another page that explains &#8220;You&#8217;ve Been Phished!&#8221; and warns about the dangers of phishing, and how to detect it. It explains that, while it still might be prudent to change your password, that your password hasn&#8217;t really been collected.  <\/p>\n<p>This explanation page would link to a technical explanation page that shows how to read the HTML enough to convince yourself that your password wasn&#8217;t really stolen. It would also link to the first page that lets you mock-phish someone else.<\/p>\n<p>I think this would be a useful tool for CIOs to tech people about the dangers of phishing by showing, rather than telling.<\/p>\n<h3>Phase B: Using My Powers For Evil<\/h3>\n<p>Once this site has been running for a while , is getting lots of hits, and has gained the trust of security professionals, Phase B comes into play.<\/p>\n<p>Randomly, the <em>first<\/em> time an IP address visits the site, it gets presented with different HTML &#8211; this time it is a genuine phishing attempt, that delivers the secret information into my clutches. It is protected so that once the submit button is pressed, Javascript runs and changes the DOM to remove all trace of itself. I haven&#8217;t worked out the technical details yet &#8211; I&#8217;ll leave that to my evil Javascripting henchmen.<\/p>\n<p>Anyone who suspects will hit &#8220;Back&#8221; and find no sign of the dodgy source, or will revisit the site and again, find no sign of the dodgy source.<\/p>\n<p>Oh well. I thought the Phase A was a good idea, until I came up with the Phase B. I should have realised more quickly that security professionals would have not trusted the site &#8211; well not if they had ever read Ken Thompson&#8217;s <a href=\"http:\/\/www.argus-systems.com\/feature\/spotm\/trustingtrust\/ReflectionsOnTrustingTrust.html\">Reflections of Trusting Trust<\/a> anyway.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I propose that we produce a Mock-Phish web-site, which will have a goal of helping security professionals to train their co-workers, family and friends to <em>avoid<\/em> falling for phishing scams.<\/p>\n<p>Once this site has been running for a while , is getting lots of hits, and has gained the trust of security professionals, Phase B comes into play.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_s2mail":"","footnotes":""},"categories":[34,27],"tags":[],"class_list":["post-182","post","type-post","status-publish","format-standard","hentry","category-software-development","category-thoughts-from-the-shower"],"_links":{"self":[{"href":"https:\/\/www.somethinkodd.com\/oddthinking\/wp-json\/wp\/v2\/posts\/182","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.somethinkodd.com\/oddthinking\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.somethinkodd.com\/oddthinking\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.somethinkodd.com\/oddthinking\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.somethinkodd.com\/oddthinking\/wp-json\/wp\/v2\/comments?post=182"}],"version-history":[{"count":0,"href":"https:\/\/www.somethinkodd.com\/oddthinking\/wp-json\/wp\/v2\/posts\/182\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.somethinkodd.com\/oddthinking\/wp-json\/wp\/v2\/media?parent=182"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.somethinkodd.com\/oddthinking\/wp-json\/wp\/v2\/categories?post=182"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.somethinkodd.com\/oddthinking\/wp-json\/wp\/v2\/tags?post=182"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}