Phishing Attacks: Advanced Attack Techniques
暫譯: 釣魚攻擊:進階攻擊技術

Mr Christopher Atkins

  • 出版商: W. W. Norton
  • 出版日期: 2018-01-21
  • 售價: $1,570
  • 貴賓價: 9.5$1,492
  • 語言: 英文
  • 頁數: 160
  • 裝訂: Paperback
  • ISBN: 1984093975
  • ISBN-13: 9781984093974
  • 海外代購書籍(需單獨結帳)

相關主題

商品描述

Phishing is an attack technique where an attacker uses fraudulent emails or texts, or copycats websites to get a victim to share valuable personal information such as account numbers, social security numbers, or victim's login user-name and password. This technique is also used to trick the victim into running malicious code on the system, so that an attacker can control the user's system and thereby get acces to user's or organization's sensitive data. This book is an introduction for the reader in the world of Phishing attacks. The book focuses on the different kinds of Phishing attacks and provides an overview of some of the common open source tools that can be used to execute Phishing campaigns. Red teams, pentesters, attackers, etc. all use Phishing techniques to compromise a user's machine. It is necessary for Red teams and pentesters to understand the various payload delivery mechanisms used by current threat profiles. The book then delves into the common Phishing payload delivery mechanisms used by current threat profiles. It also introduces some new and uncommon payload delivery techniques that the author has used in the past to bypass and get through email filters as well as end-point detection systems.

商品描述(中文翻譯)

釣魚攻擊(Phishing)是一種攻擊技術,攻擊者利用欺詐性的電子郵件或簡訊,或仿冒網站來誘使受害者分享有價值的個人資訊,例如帳戶號碼、社會安全號碼,或受害者的登入用戶名稱和密碼。這種技術也用來欺騙受害者在系統上執行惡意程式碼,以便攻擊者能夠控制用戶的系統,從而獲取用戶或組織的敏感數據。本書是針對讀者在釣魚攻擊世界中的入門介紹。書中專注於不同類型的釣魚攻擊,並提供一些常見的開源工具概述,這些工具可用於執行釣魚活動。紅隊(Red teams)、滲透測試者(pentesters)、攻擊者等都使用釣魚技術來妥協用戶的機器。紅隊和滲透測試者有必要了解當前威脅模型所使用的各種有效載荷傳遞機制。接著,本書深入探討當前威脅模型所使用的常見釣魚有效載荷傳遞機制。它還介紹了一些作者過去使用過的新穎且不常見的有效載荷傳遞技術,以繞過電子郵件過濾器以及端點檢測系統。