Sunday, April 28, 2024

Facebook’s New Tool to Detect and Alert Website Owners About Phishing Attacks

Phishing is one of the most common problems for Internet Users, hackers find a new innovative method to create believable URL’s to trick users.

Attackers launch innovative phishing attacks to trick the users and to steal sensitive data such as their passwords, credit card numbers, or other sensitive information. It is hard to detect as they use a number of techniques to resemble it like a legitimate domain.

Facebook phishing detection tool developed two years ago and now they expanded the capabilities of the tool to alert users when new certificate issued for phishing domains.

When a new certificate appears in the public Certificate Transparency Log the Facebook phishing detection tool analyzes the domains for possible phishing attempts.

Facebook phishing detection tool

If the tool suspects it is a phishing domain then it notifies the subscribers of the legitimate domain by sending email, push, or on-site notifications based on the subscriber preference.

To enable and domain monitoring service and manage your subscriptions visit facebook developers, Developers need to specify the domain name and the alerts they need to specify.

Certificate alerts: Alerts when the new certificate enrolled for the subscribed domain name.

Phishing Alerts: Notifies when the enrolled new certificate seems to be impersonating the
subscribed domain name.

Certificate Transparency aims to remedy these certificate-based threats by making the issuance and existence of SSL certificates open to scrutiny by domain owners, CA, and domain users. The ultimate goal of CT is to defend mis-issuance of certificates.

Facebook phishing detection tool

Open source tools like Phishing catcher also helps in detection of misissued certificates, malicious certificates, and rogue CAs.

We are also extending our Webhook API to help developers easily integrate this new phishing detection feature into their external systems.” reads facebook statement.

If a domain owner receives a notification that a CA issued a certificate for their domain without an explicit request, they will likely want to contact the CA, check that their identity isn’t compromised and take into account revoking the certificate.

Website

Latest articles

NETGEAR buffer Overflow Vulnerability Let Attackers Bypass Authentication

Some router models have identified a security vulnerability that allows attackers to bypass authentication.To...

5000+ CrushFTP Servers Hacked Using Zero-Day Exploit

Hackers often target CrushFTP servers as they contain sensitive data and are used for...

13,142,840 DDoS Attacks Targeted Organization Around The Globe

DDoS attacks are a significant and growing risk that can overpower websites, crash servers,...

Hackers Exploit Old Microsoft Office 0-day to Deliver Cobalt Strike

Hackers have leveraged an old Microsoft Office vulnerability, CVE-2017-8570, to deploy the notorious Cobalt...

Microsoft Publicly Releases MS-DOS 4.0 Source Code

In a historic move, Microsoft has made the source code for MS-DOS 4.0, one...

New SSLoad Malware Combined With Tools Hijacking Entire Network Domain

A new attack campaign has been discovered to be employed by the FROZEN#SHADOW, which...

Palo Alto Networks Shares Remediation Advice for Hacked Firewalls

Palo Alto Networks has issued urgent remediation advice after discovering a critical vulnerability, designated...
Guru baran
Guru baranhttps://gbhackers.com
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

WAAP/WAF ROI Analysis

Mastering WAAP/WAF ROI Analysis

As the importance of compliance and safeguarding critical websites and APIs grows, Web Application and API Protection (WAAP) solutions play an integral role.
Key takeaways include:

  • Pricing models
  • Cost Estimation
  • ROI Calculation

Related Articles