14 234
editací
(založena nová stránka s textem „''Blocked by administrator due to account attack. Change your password and contact CVT UP.''</blockquote>“) |
(založena nová stránka s textem „Information technology“) značky: editace z mobilu editace z mobilního webu |
||
| (Není zobrazeno 8 mezilehlých verzí od stejného uživatele.) | |||
| Řádek 21: | Řádek 21: | ||
''Blocked by administrator due to account attack. Change your password and contact CVT UP.''</blockquote> | ''Blocked by administrator due to account attack. Change your password and contact CVT UP.''</blockquote> | ||
* In this case, the mail administrator must unblock the account manually - write a request to '''[[Helpdesk]]''' in the category [https://helpdesk.upol.cz/Ticket/New?categoryName=sitove_sluzby_%28e-mail%2C_vpn%2C_ad%29 '''Network services'''] (employees) or [https://helpdesk.upol.cz/Ticket/New?categoryName=it_a_site '''IT and networks'''] (students), enter your nationality, confirm that the password has been changed and the account has been checked, and the account will then be unblocked by the administrator. | |||
* | |||
== Check the address bar == | |||
You can often access fake dangerous websites by clicking on a link in a fake email. If you want to go to the site, it is worth opening a new browser window and rewriting the web address yourself. Even a small change in the web address can indicate whether it is a fake website. A dot may be replaced by a dash, or a single letter may be replaced by a similar one. Always check the address bar. You can check that you are on the correct page in your browser by clicking on the green lock icon. | |||
[[Soubor:Phish.png|střed|bezrámu|663x663pixelů]] | [[Soubor:Phish.png|střed|bezrámu|663x663pixelů]] | ||
== Examples of phishing attacks at UP == | |||
= | |||
This phishing email uses a real link to UPWiki. However, upon closer examination of the link, it is clear that the clickable link has the domain upol.bz, not upol.cz. Moreover, the visible text is not always identical to the link. In case you open the link, always make sure in the browser address bar that you are really on the right page or use the tooltip. | |||
[[Soubor:Phish2.png|střed|bezrámu|663x663pixelů]] | [[Soubor:Phish2.png|střed|bezrámu|663x663pixelů]] | ||
=== #2 === | === #2 === | ||
This e-mail has a ton of typos, but as it is in Czech, foreign users might get confused. There is no Information technology department at Computer center. | |||
[[Soubor:Phish3.png|střed|bezrámu|663x663pixelů]] | [[Soubor:Phish3.png|střed|bezrámu|663x663pixelů]] | ||
=== #3 === | === #3 === | ||
This phishing attack tries to convince you that CVT will deactivate your account unless you click on a link (which is not there). We will never inform you by email that we are verifying active accounts. User accounts at UP have a preset validity period - the account is deactivated 60 days after graduation or employment. After 180 days, the account is deleted. | |||
[[Soubor:Phish4.png|střed|bezrámu|663x663pixelů]] | [[Soubor:Phish4.png|střed|bezrámu|663x663pixelů]] | ||
=== #4 === | === #4 === | ||
As with the previous phishing email, the attacker tries to force you to click on a link. The email is suspicious in both its subject and sender. | |||
[[Soubor:Phish5.jpg|střed|bezrámu|663x663pixelů]] | [[Soubor:Phish5.jpg|střed|bezrámu|663x663pixelů]] | ||
=== #5 === | === #5 === | ||
Similar to the previous email, there is poor Czech and grammar here. The attacker is trying to push for quick action via a link = proven manipulation so that the person does not search and does not think much before clicking. The email and the link do not come from our domain upol.cz. | |||
[[Soubor:Phish6.jpg|střed|bezrámu|663x663pixelů]] | |||
=== #6 === | === #6 === | ||
This is a typical phishing disguised as a corporate message. It looks like a response from someone outside UP who sends a link to some "Employee Resources". The text tries to act like an internal notice from the HR department. The "copyright © 2020" does not make any sense as well as the Czech grammar is terrible. [[File:Phish7.png|center|frameless|663x663pixels]] | |||
=== #7 === | === #7 === | ||
First of all, you need to notice the nonsensical text about the "2024–2025 directory". The directory is not updated by year like a school list. It is a pure fabrication to make it sound important. Again, there is pressure and threats of losing access to the account. The aktualizace/ověření ("update/verify") link is also suspicious. Then there is bad Czech, incorrect use of upper and lower case letters. [[Soubor:Phish8.png|střed|bezrámu|663x663pixelů]] | |||
=== #8 === | === #8 === | ||
This email pretends to be a notification that your mailbox limit has been exceeded. The message is fake simply because it comes from a foreign email domain (unicamp.br), does not properly identify the university as the sender, and invites you to log in via an unverified link that is incorrectly formatted as "Kliknutím ověřte" ("Click to verify:"). This communication uses coercive language with the threat of account blocking, which is a common way to obtain access data. | |||
[[Soubor:Phish9.png|střed|bezrámu|663x663pixelů]] | |||
=== #9 === | === #9 === | ||
This is a phishing email that pretends to be an official message from the university IT administration. The attacker uses an urgent tone and a fake link to obtain the user's login details. The email contains inauthentic elements such as incomplete contact information and general wording, which indicates its fraudulent nature. The text „Aktualizovat zde (S)“ ("Update here (S)") leads to a fake page where the attacker obtains the login details. | |||
[[Soubor:Phish10.png|střed|bezrámu|663x663pixelů]] | |||
=== #10 === | === #10 === | ||
The email pretends to be a technical support message and reports an alleged problem with mailbox registration after a server update. The attacker uses an urgent tone and the threat of losing access to features to trick the user into clicking on a „KLIKNĚTE ZDE“ (“CLICK HERE”) link and performing an unauthorized action. The content of the message contains unclear wording, missing official contact information, and a generic ending, suggesting a fraudulent nature. There is also poor grammar, unusual wording, etc. | |||
[[Soubor:Phish1.png|střed|bezrámu|663x663pixelů]] | |||
[[Kategorie:Information technology|Information technology]] | |||
[[Kategorie: | |||