Soru

Zorluk: OrtaSocial Engineering Attacks and Vectors

An enterprise security operations center (SOC) discovers that several employees mistakenly submitted their corporate domain credentials to an external login portal. The malicious portal was hosted on `login.acme-corp.net`, whereas the legitimate enterprise single sign-on (SSO) portal is `login.acme-corp.com`. The attacker registered the alternate top-level domain to impersonate the enterprise authentication interface. Which of the following social engineering attack vectors was primarily executed by the attacker?

  1. TyposquattingCevap
  2. B
    Watering hole attack
  3. C
    Smishing
  4. D
    Whaling

Cevap

Typosquatting
Typosquatting (also known as URL hijacking) relies on registering domain names that closely resemble legitimate enterprise domain names—such as changing the top-level domain extension from `.com` to `.net` or inserting common misspellings—to trick users into delivering credentials to an attacker-controlled infrastructure.

Adım Adım Çözüm

1
Analyze the incident indicator
Identified that the attacker registered `login.acme-corp.net` to imitate the legitimate domain `login.acme-corp.com`.
Determining how the malicious destination was constructed reveals the specific vector utilized.
2
Map the technique to social engineering categories
Registering slightly modified or alternate top-level domain names to trick users into believing a fake site is authentic defines URL hijacking/typosquatting.
Typosquatting relies on user misdirection through minor textual variations or domain extension swaps.

Anahtar Kavram

Typosquatting and Domain Impersonation
Bu soruyu puanla