Google's umbrella jigsaw has published 'Phishing Quizzes' that I can test if I'm easy to catch up with phishing scams and actually used it


by rawpixel.com

Phishing fraud is a technique in which a malicious hacker impersonates a trusted e-mail, a website, or the like, and attempts to draw out information of economic value, such as user's personal information or credit card number, of fraud conducted on the Internet about. Since " jigsaw " of technology incubator, which is a company belonging to Google, released a quiz called " Phishing Quiz (fishing quiz) " which tests the ability to see such phishing scams, I actually tried it.

Phishing Quiz
https://phishingquiz.withgoogle.com/

Test your internet prowess with Google's phishing quiz
https://mashable.com/article/google-phishing-quiz/#bEk4GuJRgsqB

Anyone can challenge fishing quizzes for free. When you visit the official page, the word "Can you see the phishing scam?" Appears and it is explained that phishing scams are becoming clever beyond people's imagination. To challenge a quiz, click "Take the QUIZ".



You will then be asked to enter your name and email address, but this information does not have to be a real name or email address. It is an input form prepared just to make the test seem real, so if you do not want to enter a real name or email address, you can enter an appropriate name or email address. Information is not transmitted to the server etc regardless of whether the input information is true or false.



When you finish entering your name and email address, you will be asked a quiz at once. With the setting that the mail arrived at the fictitious mail address, it examines whether this mail is a phishing scam or not, and judges whether it is "PHISHING (phishing scam)" or "LEGITIMATE (legitimate mail)" .



In addition, in the lower part, I will explain while actually touching the contents of phishing quizzes. If you want to try a quiz without preliminary knowledge, we recommend that you first read the quiz before reading.

First check the sender of the email. It is from an unknown email address, but perhaps there may have been acquaintance at work. Judgment is pending for now.



If you click on the inverse triangle icon at the bottom of the From column and examine the mail information a little more, you do not have other acquaintances in the CC. However, the task was "2019 Departmental Budget (divisional budget for 2019)".



A file like Google Docs is attached to the e-mail, and the sender seems to want you to check the document. As soon as you move the cursor over the document ... ...



The URL of the link destination is displayed at the lower left of the screen. However, there is a feeling of strangeness in the URL of the link destination.



Take a closer look, the clickthrough URL starts with "http://drive--google.com". However, for Google Docs, the URL should start with "https://docs.google.com", for Google Drive the URL should begin with "https://drive.google.com".



This email is suspicious, click "phishing scam".



Then the word "Correct! (Correct answer!)" Was displayed. Apparently it seems I have seen a phishing scam and I am relieved. Click "SHOW ME" ......



A more detailed explanation was displayed. Since phishing fraud may lead you to a site made for fraudulent purposes and may try to enter important information, before clicking the link attached to the email, it is necessary to know whether the linked URL is not suspicious It is important to check. After reading the commentary, click "NEXT".



Next, mail arrives with the setting "Internet fax arrived", and again checks whether this email is a phishing scam or not. By solving the same problem as 8 questions, you can investigate how much you have the ability to see phishing scams.



E-mails from school old-fashioned persons and mails recommending upgrade from Dropbox of online storage service, such as e-mail quizzes that are actually not incomplete will be taken. By challenging quizzes for a few minutes, you can be conscious of how hackers use clever techniques and can increase security awareness.



When answering all 8 questions, the final result is displayed. Even if you answer all questions correctly, hackers continue to devise a clever technique every day, and even if someone truly attaches phishing scams to themselves, if you take the same way as this time Please note that it is not limited. Do not forget that if you steal information, you will receive very great damage.

in Review,   Web Service,   Security, Posted by log1h_ik