Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Human Nature vs. Security
Daniel Hanson, 2004-03-29

Social engineering in the latest crop of viruses has people jumping through hoops to open malicious attachments. How do we change the pattern?

Comments Mode:
Human Nature vs. Security 2004-03-30
Anonymous
Human Nature vs. Security 2004-03-30
IT Professional (2 replies)
Human Nature vs. Security 2004-03-31
Anonymous
Human Nature vs. Security 2004-04-05
Anonymous (1 replies)
Human Nature vs. Security 2004-04-07
Anonymous
Human Nature vs. Security 2004-03-30
Mene Tekel (1 replies)
Human Nature vs. Security 2004-04-06
Anonymous (1 replies)
Human Nature vs. Security 2004-04-07
Anonymous
Human Nature vs. Security 2004-03-30
Simonis
One small error in the article:

>>
How does a user differentiate between my_vacation.jpg and my_vacation.jpg.exe if they can't see the file extension? What rule can be given?
<<

If extensions are hidden, the user would be presented with "my_vacation" and "my_vacation.jpg". Clearly, if I saw an extension on a file, when I normally do not, I would know something was unusual. In this case, it is as plain as the nose on one's face. Still, I doubt the average Internet user would notice.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/231/25643#25643
Human Nature vs. Security 2004-03-30
Anonymous
Human ignorance vs. security 2004-03-30
F. Obfusco
Human Nature vs. Security 2004-03-30
Yvan Boily (1 replies)
Human Nature vs. Security 2004-04-02
Anonymous
Human Nature vs. Security 2004-03-31
jaywalker (3 replies)
Human Nature vs. Security 2004-04-01
Brainclots (1 replies)
Human Nature vs. Security 2004-04-04
Mene Tekel
Human Nature vs. Security 2004-04-01
IT Professional (1 replies)
Human Nature vs. Security 2004-04-02
Anonymous
Human Nature vs. Security 2004-04-01
Anonymous
Human Nature vs. Security 2004-03-31
Anonymous (1 replies)
Human Nature vs. Security 2004-04-01
The Suite (1 replies)
Human Nature vs. Security 2004-04-02
Anonymous
Human Nature vs. Security 2004-04-01
Chris
Human Nature vs. Security 2004-04-01
Educational Netowrk admin
Human Nature vs. Security 2004-04-05
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus