PDA

View Full Version : Test your online security IQ


Acadia
August 4th, 2004, 11:32 AM
Test your phishing knowledge with this link I found on msnbc. I scored 9 of 10 correct ... that is NOT good, that one time a baddie could have nailed me. :-[

http://survey.mailfrontier.com/survey/quiztest.html

Acadia

dog
August 4th, 2004, 12:05 PM
Woooooo Who! ;D

Acadia
August 4th, 2004, 12:09 PM
Yo, Dog, you're giving away the answers before any one goes to the site! :-\

Acadia

dog
August 4th, 2004, 12:10 PM
Opps I'll edit it! ;) Sorry! .... Dumb dog ;) ;D

Acadia
August 4th, 2004, 12:17 PM
Ahhhh, that's better, Good Doggie!! 8)

Acadia

ronjor
August 4th, 2004, 12:23 PM
You got 8 out of 10 correct, or 80 %

The two I missed were legitimate however. ;D

dog
August 4th, 2004, 12:26 PM
-{ Quote: "You got 8 out of 10 correct, or 80 %

The two I missed were legitimate however. ;D" }-

Better Safe than Sorry ;)

Rita
August 4th, 2004, 02:16 PM
-{ Quote: "Test your phishing knowledge with this link I found on msnbc. I scored 9 of 10 correct ... that is NOT good, that one time a baddie could have nailed me. :-[

http://survey.mailfrontier.com/survey/quiztest.html

Acadia" }-
hey Arcadia
i only got 70%--i need more knowledge thats for sure
rita

Tassie_Devils
August 5th, 2004, 12:18 AM
I got 9/10... but will admit 2 I got right were guesses as 3-4 do not apply to me at all...

Who/What on earth is an Earthlink..... ISP ????
I do not have any dealings with CitiBank/USBank/PayPal email link ? [Australia here, so if I was to get anything from one of those, it would be auto Blacklisted and Deleted. ;)

TAS

Blackspear
August 5th, 2004, 12:29 AM
You got 9 out of 10 correct, or 90 %

Missed the Earthlink one

;D 8) ;D 8) ;D

bigc73542
August 5th, 2004, 12:33 AM
I got 9 out of 10 I missed the microsoft no. 1 question I guess I just don't trust MS.

Ronin
August 5th, 2004, 11:19 AM
More important than the result is the discussion of how the test should be taken.

I presume, the test is a technical one, and not one based on social engineering. In other words, whether you decide the email is a fake depends not on the content (whether it looks fishy by asking you to do something you normally wouldn't expect ebay to do, typos, unprofessional writing etc), but on whether you are fooled by the url when you hover your mouse over it.

Because it's a technical test, what browser you are using is important.

I tried this on IE medium settings, and in most cases looking at the status bar was sufficent to defeat the test. The funny thing is they were using JS to alter your statusbar, but in most cases they did not use it to mislead you (That is they made the status bar show obviously wrong domains) . The only exception was test 6 which is the way I expect most people to do it.

The way to defeat test 6 is to disable active scripting.

Test 3, was easy unless you didn't understand domain names. Test 10 looks like the same?

The test could have being clearer on what was being tested, and they should not have disabled the link.

The interesting thing is that when testing on Firefox, using default settings, the status bar shows nothing when hovering over the url. That is a dead give away :P

chew
August 5th, 2004, 11:38 AM
Got 7/10.

I thought they were all illegitimate ... errmm ...

I don't use them so if they turn up on me ... I just think they are trying to rob me. ;D

So I just say no to all ... if in doubt ... say no.

Acadia
August 5th, 2004, 11:50 AM
-{ Quote: "So I just say no to all ... " }-

Agreed. Whenever I receive such an email, I use my bookmarked favorites to go straight to the site and work my way in from there.

Acadia