During a routine audit, an incident response team discovers that multiple remote employees entered their domain credentials into a web page that visually duplicated the organization's authentic single sign-on (SSO) portal. Investigation reveals that the domain name used in the attack was registered by an external third party and contained a single transposed letter relative to the official enterprise URL. Which social engineering attack vector was directly executed in this scenario?
- TyposquattingCevap
- BWatering hole attack
- CSpear phishing
- DVishing
Cevap
Typosquatting is the correct vector, as it explicitly relies on registering slight misspellings or character transpositions of legitimate domain names to trick users into visiting deceptive websites.
Typosquatting (also known as URL hijacking) occurs when an attacker registers domain names that are slight misspellings, character swaps, or variations of a legitimate domain. When users inadvertently type the wrong address or follow a link to the spoofed domain, they are presented with a fraudulent site designed to harvest sensitive information such as SSO credentials.
Adım Adım Çözüm
Anahtar Kavram
Typosquatting (URL Hijacking)