517
Checkmate (lemmy.ml)
submitted 10 months ago by yogthos@lemmy.ml to c/programmerhumor@lemmy.ml
you are viewing a single comment's thread
view the rest of the comments
[-] OneCardboardBox 114 points 10 months ago

Happened at my workplace. An phishing email went out to test how likely people were to click the link.

Anyone who clicked the link had to take phishing training. Anyone who forwarded it to our internal "hey this is a phishing email" service also had to take training... because the internal service would automatically click the link.

[-] Solarius 119 points 10 months ago

sounds like the internal phishing service should be the one needing to do training

[-] doctordevice@lemm.ee 57 points 10 months ago* (last edited 10 months ago)

Yeah, I'm very confused by this. Why do the users notifying IT have to do the training?

I've worked a help desk before, while after dozens of people sending it in we don't really need it forwarded anymore, people don't know that until we get the I'd still rather people forward it than click it. Ignore and delete is best since I guarantee someone will forward it to IT, but forwarding (even forwarding and asking) is never bad and demonstrates good awareness.

[-] jcg@halubilo.social 17 points 10 months ago

Yeah, I'm very confused by this. Why do the users notifying IT have to do the training?

The URL likely is unique per user. They forward it, IT clicks the link, it registers that that user clicked the link even though IT did it.

[-] HerbalGamer@lemm.ee 25 points 10 months ago

IT clicks the link,

stop that part then

[-] jcg@halubilo.social 7 points 10 months ago

If only I had the power

[-] railsdev@programming.dev 7 points 10 months ago* (last edited 10 months ago)

Random but what I always wonder is: what’s the point of forwarding?

Are we assuming they’re attaching the original email’s source so that the headers can be used to determine the source? Without that, the only thing useful I can think of would be any links in the email body.

Asking because I’ve owned an email address or two that got leaked in data dumps so I go crazy tracking down the sending server’s owner, any companies they’re pretending to be, any domain registrars, etc. and a lot of that requires analyzing the headers.

[-] sim642@lemm.ee 12 points 10 months ago

IT can look up the original (including all headers) based on the forwarded content. It's on the same mail server.

[-] railsdev@programming.dev 6 points 10 months ago

Oh that’s right! Wow!! Really feeling dumb for that one now.

[-] MonkderZweite@feddit.ch 3 points 10 months ago

Ah, yeah, forward as attachement of course.

[-] __init__@programming.dev 9 points 10 months ago

They got me good with this one time. It looked like a newsletter from like Seattle times or something, I was like I didn’t sign up for this shit and immediately clicked the unsubscribe link, boom enrolled in training. Well played, guys.

this post was submitted on 04 Oct 2023
517 points (93.7% liked)

Programmer Humor

31687 readers
123 users here now

Post funny things about programming here! (Or just rant about your favourite programming language.)

Rules:

founded 5 years ago
MODERATORS