Soru

Zorluk: OrtaSocial Engineering Attacks and Vectors

An attacker registers a domain name that closely resembles an enterprise's official login portal by altering a single character in the domain URL. The attacker uses this fraudulent domain to host a spoofed site that captures employee credentials when users accidentally mistype the legitimate web address. Which of the following social engineering attack vectors is best illustrated in this scenario?

  1. TyposquattingCevap
  2. B
    Watering hole attack
  3. C
    Spear phishing
  4. D
    Pretexting

Cevap

Typosquatting
Typosquatting (also known as URL hijacking) occurs when an attacker registers common misspellings, character omissions, or visually similar variations of a legitimate domain name to trick users who accidentally mistype the web address into visiting a fraudulent portal.

Adım Adım Çözüm

1
Analyze the attack mechanism described in the scenario.
The adversary registered a modified domain name to capitalize on user typing mistakes.
Identifying how victims arrive at the malicious site determines the attack vector.
2
Map the technique to standard social engineering attack definitions.
Exploiting misspellings or minor character variations in domain URLs is defined as typosquatting (URL hijacking).
Typosquatting specifically targets human errors during web address entry.

Anahtar Kavram

Typosquatting (URL Hijacking)
Tahmini Süre:1m 0s
Bu soruyu puanla