July 25, 2023, 1:42 a.m. | /u/heyceeso

cybersecurity www.reddit.com

Most phishing sites are created by cloning a real webpage, but there's ways to harden a page against being cloned. 🧵Here are 3 steps:

1️⃣ Install beacon assets: if done properly these evade the cloning process and will call back to your server telling you the URL of any cloned page. You can use http://canarytokens.org or deploy your own implementation

2️⃣ Embed high-entropy strings: long, random strings are often overlooked by phishers but they make it extremely easy to detect …

cybersecurity detect don entropy high login page phishing random strings

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Security Compliance Strategist

@ Grab | Petaling Jaya, Malaysia

Cloud Security Architect, Lead

@ Booz Allen Hamilton | USA, VA, McLean (1500 Tysons McLean Dr)