GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Saturday, 11-Oct-2025 04:45:19 JST da_667 da_667

    How to tell a phishing exercise domain is a phishing exercise domain: The SSL certificate specifies a Subject Alternative Names list that is a fucking novel.

    In conversation about a month ago from infosec.exchange permalink
    • prettygood likes this.
    • GreenSkyOverMe (Monika) repeated this.
    • Embed this notice
      da_667 (da_667@infosec.exchange)'s status on Saturday, 11-Oct-2025 04:46:19 JST da_667 da_667
      in reply to

      DA, you loveable scamp, how is this done?

      grab the e-mail address/domain from the suspected phishing e-mail, input it into virustotal. Click on details for the domain, and pay attention to the "Last HTTPS Certificate" section. See if the Subject Alternate Name section looks like war and peace.

      Done deal.

      Phishing exercise orgs are the only ones who do this, because bad guys just use lets encrypt.

      In conversation about a month ago permalink
      prettygood likes this.
    • Embed this notice
      da_667 (da_667@infosec.exchange)'s status on Saturday, 11-Oct-2025 04:46:20 JST da_667 da_667
      in reply to

      This is the third time I've gotten a phishing exercise e-mail, in which this has happened, and its hilarious every single time because I get to map your company's entirely list of phishing domains.

      In conversation about a month ago permalink
      prettygood likes this.

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.