{"id":95620,"date":"2020-10-01T07:45:10","date_gmt":"2020-10-01T05:45:10","guid":{"rendered":"https:\/\/prohoster.info\/blog\/administrirovanie\/1-obuchenie-polzovatelej-osnovam-ib-borba-s-fishingom"},"modified":"2020-10-01T07:45:10","modified_gmt":"2020-10-01T05:45:10","slug":"1-obuchenie-polzovatelej-osnovam-ib-borba-s-fishingom","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/1-obuchenie-polzovatelej-osnovam-ib-borba-s-fishingom","title":{"rendered":"1. Training users in the basics of cybersecurity. Fighting phishing.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><img decoding=\"async\" alt=\"1. Training users in the basics of cybersecurity. Fighting phishing.\" src=\"\/wp-content\/uploads\/2020\/10\/75034c513ef3ce93bc27afe604afdba1.JPG\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p>Today, a network administrator or cybersecurity engineer spends a considerable amount of time and effort protecting the enterprise's network perimeter from various threats, mastering new intrusion prevention and event monitoring systems. However, even this does not guarantee complete security. Social engineering is actively utilized by criminals and can have serious consequences.<\/p>\n<p>How often have you caught yourself thinking, \"It would be good to conduct a literacy check for staff regarding cybersecurity\"? Unfortunately, these thoughts often hit a wall of misunderstanding in the form of numerous tasks or limitations of the workday. We plan to tell you about modern products and technologies in the field of automation for staff training that won't require extensive preparation for pilots or implementation, but let\u2019s go one step at a time.<\/p>\n<h2>Theoretical Foundation<\/h2>\n<p>Currently, more than 80% of malicious files are distributed via email (data taken from Check Point's reports over the past year using the Intelligence Reports service).<\/p>\n<p><img decoding=\"async\" alt=\"1. Training users in the basics of cybersecurity. Fighting phishing.\" src=\"\/wp-content\/uploads\/2020\/10\/db65c5e2a78dc046e46a006af473516a.JPG\" style=\"display:block;margin: 0 auto;\" \/>Report for the last 30 days on the vector of attacks related to malware distribution (Russia) \u2014 Check Point<\/p>\n<p>This indicates that the content in email messages is quite vulnerable to exploitation by criminals. When considering the most popular malicious file formats in attachments (EXE, RTF, DOC), it should be noted that they typically contain automatic code execution elements (scripts, macros).<\/p>\n<p><img decoding=\"async\" alt=\"1. Training users in the basics of cybersecurity. Fighting phishing.\" src=\"\/wp-content\/uploads\/2020\/10\/a6d1d2d8f374250104e156381b002ea1.JPG\" style=\"display:block;margin: 0 auto;\" \/>Annual report on file formats in received malicious messages \u2014 Check Point<\/p>\n<p>How to combat this vector of attacks? Email security involves using security tools:&nbsp;<\/p>\n<ul>\n<li>\n<p><strong>Antivirus<\/strong> \u2014 signature-based threat detection.<\/p>\n<\/li>\n<li>\n<p><strong>Emulation<\/strong> \u2014 sandboxing, allowing attachments to be opened in an isolated environment.<\/p>\n<\/li>\n<li>\n<p><strong>Content Awareness <\/strong>\u2014 extraction of active elements from documents. The user receives a cleaned document (usually in PDF format).<\/p>\n<\/li>\n<li>\n<p><strong>AntiSpam<\/strong> \u2014 checking the recipient\/sender domain for reputation.<\/p>\n<\/li>\n<\/ul>\n<p>And, theoretically, that\u2019s enough, but there\u2019s another equally valuable resource for the company \u2014 corporate and personal data of employees. In recent years, the popularity of the following type of internet fraud has been growing:<\/p>\n<p><strong><u>Phishing<\/u><\/strong> (English phishing, from fishing \u2014 catching fish, drawing out) is a form of online fraud. Its goal is to acquire users' identification data. This includes theft of passwords, credit card numbers, bank account details, and other confidential information.<\/p>\n<p><img decoding=\"async\" alt=\"1. Training users in the basics of cybersecurity. Fighting phishing.\" src=\"\/wp-content\/uploads\/2020\/10\/64ed74d70fe7a573c5e14cc03ebef33a.JPG\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p>Malefactors are improving their phishing attack methods, redirecting DNS requests from popular sites, and launching entire campaigns using social engineering to send emails.&nbsp;<\/p>\n<p>Thus, to protect your corporate email from phishing, it is recommended to apply two approaches, and their combined use yields the best results:<\/p>\n<ol>\n<li>\n<p><strong>Technical Protection Tools<\/strong>. As mentioned earlier, various technologies are used to verify and only forward legitimate emails.<\/p>\n<\/li>\n<li>\n<p><strong>Theoretical Staff Training<\/strong>. This involves comprehensive testing of staff to identify potential victims. Subsequently, retraining is conducted, and statistics are continually recorded.&nbsp;&nbsp;&nbsp;<\/p>\n<\/li>\n<\/ol>\n<h2>Trust but Verify<\/h2>\n<p>Today we will discuss the second approach to preventing phishing attacks, namely automated training of personnel aimed at increasing the overall security level of corporate and personal data. Why can this be so dangerous?<\/p>\n<p><strong><u>Social Engineering <\/u><\/strong>\u2014 psychological manipulation of people to perform specific actions or disclose confidential information (related to cybersecurity).<\/p>\n<p><img decoding=\"async\" alt=\"1. Training users in the basics of cybersecurity. Fighting phishing.\" src=\"\/wp-content\/uploads\/2020\/10\/97f19afc49a5101d20cebabe040073a1.JPG\" style=\"display:block;margin: 0 auto;\" \/>A Typical Phishing Attack Scenario<\/p>\n<p>Let\u2019s refer to an engaging flowchart that briefly outlines the process of conducting a phishing campaign. It includes various stages:<\/p>\n<ol>\n<li>\n<p>Collection of Primary Data.<\/p>\n<p>In the 21st century, it is hard to find a person who is not registered on any social network or various thematic forums. Naturally, many of us leave detailed information about ourselves: current workplace, group for colleagues, phone, email, etc. Add to this personalized information about a person's interests and you will have data to create a phishing template. Even if it is hard to find people with such information, there is always the company's website, from which you can gather all the information of interest (domain email, contacts, connections).<\/p>\n<\/li>\n<li>\n<p>Campaign Launch.<\/p>\n<p>Once the \"groundwork\" is prepared, you can launch your own targeted phishing campaign using free or paid tools. During the mailing process, you will accumulate statistics: delivered emails, opened emails, link clicks, credential inputs, etc.<\/p>\n<\/li>\n<\/ol>\n<h2>Products on the market<\/h2>\n<p>Phishing can be used by both attackers and company security staff to conduct continuous audits of employee behavior. What does the market for free and commercial solutions for automated employee training look like?<\/p>\n<ol>\n<li>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/getgophish.com\/\">GoPhish<\/a><\/noindex> \u2014 an open-source project that allows you to launch a phishing campaign to assess your employees' IT literacy. The advantages include ease of deployment and minimal system requirements. The drawbacks are the lack of ready-made mailing templates, tests, and training materials for staff.<\/p>\n<\/li>\n<li>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/www.knowbe4.com\/\">KnowBe4<\/a><\/noindex> \u2014 a platform with a large number of available products for testing personnel.<\/p>\n<\/li>\n<li>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/phishman.ru\/\">Phishman<\/a><\/noindex> \u2014 an automated training and testing system for employees. It has different product versions supporting from 10 to over 1000 employees. Training courses include theory and practical assignments, with the ability to identify needs based on statistics collected after the phishing campaign. The solution is commercial with trial use available.<\/p>\n<\/li>\n<li>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/www.antiphish.ru\/\">Anti-Phishing<\/a><\/noindex> \u2014 an automated training and security control system. The commercial product offers periodic training attacks, employee training, etc. As a demo version, a campaign is provided that includes deploying templates and conducting three training attacks.<\/p>\n<\/li>\n<\/ol>\n<p>The aforementioned solutions are just part of the available products in the market for automated employee training. Of course, each has its own advantages and disadvantages. Today we will get acquainted with <noindex><a rel=\"nofollow\" href=\"https:\/\/getgophish.com\/\">GoPhish<\/a><\/noindex>, simulate a phishing attack, and explore the available options. <\/p>\n<h2>GoPhish<\/h2>\n<p><img decoding=\"async\" alt=\"1. Training users in the basics of cybersecurity. Fighting phishing.\" src=\"\/wp-content\/uploads\/2020\/10\/cd95681b345ce85d131272c66032a68e.JPG\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p>So, it's time for practice. GoPhish was chosen for a reason: it is a user-friendly tool with the following features:<\/p>\n<ol>\n<li>\n<p>Simplified installation and setup.<\/p>\n<\/li>\n<li>\n<p>Support for REST API. Allows generating requests from <noindex><a rel=\"nofollow\" href=\"https:\/\/docs.getgophish.com\/api-documentation\/\">the documentation<\/a><\/noindex> and applying automated scripts.&nbsp;<\/p>\n<\/li>\n<li>\n<p>User-friendly graphical management interface.<\/p>\n<\/li>\n<li>\n<p>Cross-platform compatibility.<\/p>\n<\/li>\n<\/ol>\n<p>The development team has prepared an excellent <noindex><a rel=\"nofollow\" href=\"https:\/\/docs.getgophish.com\/user-guide\/installation\">guide<\/a><\/noindex> for deploying and configuring GoPhish. In fact, you will just need to go to <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/gophish\/gophish\">repository<\/a><\/noindex>, download the ZIP archive for the corresponding OS, run the internal binary file, after which the tool will be installed.<\/p>\n<p><u>IMPORTANT NOTE!<\/u><\/p>\n<p>Ultimately, you should receive information about the deployed portal in the terminal, as well as login credentials (this is relevant for versions later than 0.10.1). Don't forget to write down the password!<\/p>\n<pre><code class=\"bash\">msg=\"Please login with the username admin and the password \"<\/code><\/pre>\n<h2>Setting up GoPhish<\/h2>\n<p>After installation, a configuration file (config.json) will be created in the application directory. Let's describe the parameters for modification:<\/p>\n<p><strong>\u2014 some characteristic of the node (for example, a number). The key is needed to identify the element of the tree corresponding to this key. Example of a binary search tree:<\/strong><\/p>\n<p><strong>Value (default)<\/strong><\/p>\n<p><strong>Description<\/strong><\/p>\n<p><em>admin_server.listen_url<\/em><\/p>\n<p>127.0.0.1:3333<\/p>\n<p>IP address of the GoPhish server <\/p>\n<p><em>admin_server.use_tls<\/em><\/p>\n<p>false<\/p>\n<p>Is TLS used for connecting to the GoPhish server? <\/p>\n<p><em>admin_server.cert_path<\/em><\/p>\n<p>example.crt<\/p>\n<p>Path to the SSL certificate for the GoPhish administration portal<\/p>\n<p><em>admin_server.key_path<\/em><\/p>\n<p>example.key<\/p>\n<p>Path to the private SSL key<\/p>\n<p><em>phish_server.listen_url<\/em><\/p>\n<p>0.0.0.0:80<\/p>\n<p>IP address and port for hosting the phishing page (by default, hosted on the GoPhish server on port 80)<\/p>\n<p>&#8212;&gt; Go to the management portal. In our case:  <em>https:\/\/127.0.0.1:3333<\/em><\/p>\n<p>&#8212;&gt; You will be prompted to change a long password to a simpler one or vice versa.<\/p>\n<p>Creating a sender profile<\/p>\n<p>Navigate to the 'Sending Profiles' tab and enter the details of the user from whom our mailing will originate:<\/p>\n<p><img decoding=\"async\" alt=\"1. Training users in the basics of cybersecurity. Fighting phishing.\" src=\"\/wp-content\/uploads\/2020\/10\/7932413b0fd342dff9f952e4aa8a76f8.JPG\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p><strong>Where:<\/strong><\/p>\n<p><em><u>Name<\/u><\/em><\/p>\n<p>Sender Name<\/p>\n<p><em><u>From<\/u><\/em><\/p>\n<p>Sender Email<\/p>\n<p><em><u>Host<\/u><\/em><\/p>\n<p>IP address of the mail server that will listen for incoming mail.<\/p>\n<p><em><u>Username<\/u><\/em><\/p>\n<p>Username for the mail server account.<\/p>\n<p><em><u>Password<\/u><\/em><\/p>\n<p>Password for the mail server account.<\/p>\n<p>You can also send a test message to ensure successful delivery. Save the settings using the 'Save profile' button.<\/p>\n<p>Creating a recipient group<\/p>\n<p>Next, you need to create a group of recipients for the \"happy letters.\" Go to \"User &amp; Groups\" \u2192 \"New Group.\" There are two ways to add: manually or by importing a CSV file.<\/p>\n<p><img decoding=\"async\" alt=\"1. Training users in the basics of cybersecurity. Fighting phishing.\" src=\"\/wp-content\/uploads\/2020\/10\/15728f9314b0ca24e4709137595b7cda.JPG\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p>For the second method, the following fields are required:<\/p>\n<ul>\n<li>\n<p>First Name<\/p>\n<\/li>\n<li>\n<p>Last Name<\/p>\n<\/li>\n<li>\n<p>Email<\/p>\n<\/li>\n<li>\n<p>Position<\/p>\n<\/li>\n<\/ul>\n<p>As an example:<\/p>\n<pre><code>First Name,Last Name,Position,Email\nRichard,Bourne,CEO,rbourne@morningcatch.ph\nBoyd,Jenius,Systems Administrator,bjenius@morningcatch.ph\nHaiti,Moreo,Sales &amp; Marketing,hmoreo@morningcatch.ph<\/code><\/pre>\n<\/p>\n<p>Creating a phishing email template<\/p>\n<p>After identifying the imagined attacker and potential victims, it is necessary to create a template with a message. For this, go to the 'Email Templates' \u2192 'New Templates' section.<\/p>\n<p><img decoding=\"async\" alt=\"1. Training users in the basics of cybersecurity. Fighting phishing.\" src=\"\/wp-content\/uploads\/2020\/10\/1f867bbec9d2b08811ba4452bc27b7c8.JPG\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p>When creating the template, a technical and creative approach is used; the message from the service, which will be familiar to victim users or provoke a certain reaction, should be indicated. Possible options:<\/p>\n<p><em><u>Name<\/u><\/em> <\/p>\n<p>Template Name<\/p>\n<p><em><u>Subject<\/u><\/em><\/p>\n<p>Email Subject<\/p>\n<p><em><u>Text \/ HTML<\/u><\/em> <\/p>\n<p>Field for inputting text or HTML code<\/p>\n<p>Gophish supports email import; we will create our own. To do this, we will simulate a scenario: a company user receives an email offering to change the password from his corporate email. Then we will analyze his reaction and see our 'catch.'<\/p>\n<p>In the template, we will use built-in variables. More details can be found in the aforementioned <noindex><a rel=\"nofollow\" href=\"https:\/\/docs.getgophish.com\/user-guide\/installation\">guide<\/a><\/noindex> in the section <noindex><a rel=\"nofollow\" href=\"https:\/\/docs.getgophish.com\/user-guide\/template-reference\">Template Reference<\/a><\/noindex>.<\/p>\n<p><img decoding=\"async\" alt=\"1. Training users in the basics of cybersecurity. Fighting phishing.\" src=\"\/wp-content\/uploads\/2020\/10\/86973c1e490bfcb2c7b86bd775c025f5.JPG\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p>For starters, let's load the following text:<\/p>\n<pre><code>{{.FirstName}},\n\nThe password for {{.Email}} has expired. Please reset your password here.\n\nThanks,\nIT Team<\/code><\/pre>\n<p>Accordingly, the username (as per the previously specified 'New Group' item) and its email address will be automatically inserted.<\/p>\n<p>Next, we need to specify the link to our phishing resource. To do this, highlight the word \"here\" in the text and select the \"Link\" option in the control panel.<\/p>\n<p><img decoding=\"async\" alt=\"1. Training users in the basics of cybersecurity. Fighting phishing.\" src=\"\/wp-content\/uploads\/2020\/10\/ded21d192d8829c73d90169aa8e3315e.JPG\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p>As the URL, we will indicate the built-in variable {{.URL}}, which we will fill in later. It will be automatically embedded in the text of the phishing email.<\/p>\n<p>Before saving the template, don't forget to enable the \"Add Tracking Image\" option. This will add a media element sized 1&#215;1 pixel, which will track whether the email has been opened by the user.<\/p>\n<p>So, there's just a bit left, but first, let's summarize the mandatory steps after logging in to the Gophish portal:&nbsp;<\/p>\n<ol>\n<li>\n<p>Create a sender profile;<\/p>\n<\/li>\n<li>\n<p>Create a mailing group, indicating users;<\/p>\n<\/li>\n<li>\n<p>Create a phishing email template.<\/p>\n<\/li>\n<\/ol>\n<p>Agree, the setup didn't take much time, and we are almost ready to launch our campaign. We just need to add the phishing page.<\/p>\n<p>Creating the phishing page<\/p>\n<p>Go to the \"Landing Pages\" tab.<\/p>\n<p><img decoding=\"async\" alt=\"1. Training users in the basics of cybersecurity. Fighting phishing.\" src=\"\/wp-content\/uploads\/2020\/10\/1306ce51563f606801744aff82120c17.JPG\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p>We will be prompted to specify the object name. There is an option to import the source site. In our example, I tried specifying a working web portal of the mail server. Accordingly, it was imported as HTML code (albeit not completely). Next, there are interesting options for capturing the user's submitted data:<\/p>\n<ul>\n<li>\n<p>Capture Submitted Data. If the specified site page contains various input forms, all data will be recorded.<\/p>\n<\/li>\n<li>\n<p>Capture Passwords &#8212; capturing entered passwords. The data is stored in the GoPhish database without encryption as is.<\/p>\n<\/li>\n<\/ul>\n<p>Additionally, we can use the \u2018Redirect to\u2019 option, which will redirect the user to a specified page after they enter their credentials. I remind you that we set a scenario where the user is prompted to change their corporate email password. For this, they are presented with a fake email authorization portal page, after which the user can be sent to any accessible company resource.<\/p>\n<p>Don't forget to save the filled page and go to the \"New Campaign\" section.<\/p>\n<h2>Launching GoPhish Fishing<\/h2>\n<p>We have specified all the necessary data. In the \"New Campaign\" tab, we will create a new campaign.<\/p>\n<p>Launching Campaign<\/p>\n<p><img decoding=\"async\" alt=\"1. Training users in the basics of cybersecurity. Fighting phishing.\" src=\"\/wp-content\/uploads\/2020\/10\/dcb86ba80285f0663b15ffd6d2652a47.JPG\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p>Where:<\/p>\n<p><em><u>Name<\/u><\/em> <\/p>\n<p>Campaign Name<\/p>\n<p><em><u>Email Template<\/u><\/em><\/p>\n<p>Message Template<\/p>\n<p><em><u>Landing Page<\/u><\/em><\/p>\n<p>Phishing Page<\/p>\n<p><em><u>URL<\/u><\/em><\/p>\n<p>The IP of your GoPhish server (must be network-accessible from the victim host)<\/p>\n<p><em><u>Launch Date<\/u><\/em><\/p>\n<p>Campaign Start Date<\/p>\n<p><em><u>Send Emails By<\/u><\/em><\/p>\n<p>Campaign End Date (sending is distributed evenly)<\/p>\n<p><em><u>Sending Profile<\/u><\/em><\/p>\n<p>Sender Profile<\/p>\n<p><em><u>Groups<\/u><\/em><\/p>\n<p>Recipient Mailing Group<\/p>\n<\/p>\n<p>After the start, we can always check the statistics, which indicates: messages sent, messages opened, link clicks, data submitted, and move to spam.<\/p>\n<p><img decoding=\"async\" alt=\"1. Training users in the basics of cybersecurity. Fighting phishing.\" src=\"\/wp-content\/uploads\/2020\/10\/9043fc4d7358c7ff4bd5a344c772fe62.JPG\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p>From the statistics, we see that 1 message was sent; let's check the email from the recipient's side:<\/p>\n<p><img decoding=\"async\" alt=\"1. Training users in the basics of cybersecurity. Fighting phishing.\" src=\"\/wp-content\/uploads\/2020\/10\/129fbb8f438d2e19efb927747203e752.JPG\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p>Indeed, the victim successfully received the phishing email with a request to click the link to change the password for the corporate account. We execute the requested actions; it sends us to the Landing Pages, what about the statistics? <\/p>\n<p><img decoding=\"async\" alt=\"1. Training users in the basics of cybersecurity. Fighting phishing.\" src=\"\/wp-content\/uploads\/2020\/10\/f7efae1c10c1fb941ae651c93478c74e.JPG\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p>As a result, our user clicked on the phishing link, where they could potentially leave their account details. <\/p>\n<p><em>Author's Note: <\/em>The data entry process was not recorded due to the use of a test template, but such an option exists. At the same time, the content is not encrypted and is stored in the GoPhish database, keep this in mind. <\/p>\n<h2>In conclusion<\/h2>\n<p>Today, we touched on the relevant topic of conducting automated employee training to protect them from phishing attacks and to foster IT literacy. As an accessible solution, Gophish has been deployed, demonstrating good performance in terms of deployment time and results. With this tool, you can assess your employees and generate reports on their behavior. If you're interested in this product, we offer assistance in its deployment and auditing your staff.<u>sales@tssolution.ru<\/u>).<\/p>\n<p>However, we do not intend to stop at just one solution and plan to continue a series where we will discuss enterprise solutions for automating training processes and monitoring employee security. Stay with us and remain vigilant!<\/p>\n<p>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/tssolution\/blog\/521252\/\">habr.com<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041d\u0430 \u0441\u0435\u0433\u043e\u0434\u043d\u044f\u0448\u043d\u0438\u0439 \u0434\u0435\u043d\u044c \u0441\u0435\u0442\u0435\u0432\u043e\u0439 \u0430\u0434\u043c\u0438\u043d\u0438\u0441\u0442\u0440\u0430\u0442\u043e\u0440 \u0438\u043b\u0438 \u0438\u043d\u0436\u0435\u043d\u0435\u0440 \u0418\u0411 \u0442\u0440\u0430\u0442\u0438\u0442 \u0443\u0439\u043c\u0443 \u0432\u0440\u0435\u043c\u0435\u043d\u0438 \u0438 \u0441\u0438\u043b, \u0447\u0442\u043e\u0431\u044b \u0437\u0430\u0449\u0438\u0442\u0438\u0442\u044c \u043f\u0435\u0440\u0438\u043c\u0435\u0442\u0440 \u0441\u0435\u0442\u0438 \u043f\u0440\u0435\u0434\u043f\u0440\u0438\u044f\u0442\u0438\u044f \u043e\u0442 \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0445 \u0443\u0433\u0440\u043e\u0437, \u043e\u0441\u0432\u0430\u0438\u0432\u0430\u0435\u0442 \u0432\u0441\u0435 \u043d\u043e\u0432\u044b\u0435 \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u043f\u0440\u0435\u0434\u043e\u0442\u0432\u0440\u0430\u0449\u0435\u043d\u0438\u044f \u0438 \u043c\u043e\u043d\u0438\u0442\u043e\u0440\u0438\u043d\u0433\u0430 \u0441\u043e\u0431\u044b\u0442\u0438\u0439, \u043d\u043e \u0434\u0430\u0436\u0435 \u044d\u0442\u043e \u043d\u0435 \u0433\u0430\u0440\u0430\u043d\u0442\u0438\u0440\u0443\u0435\u0442 \u0435\u043c\u0443 \u043f\u043e\u043b\u043d\u043e\u0439 \u0437\u0430\u0449\u0438\u0449\u0435\u043d\u043d\u043e\u0441\u0442\u0438. \u0421\u043e\u0446\u0438\u0430\u043b\u044c\u043d\u0430\u044f \u0438\u043d\u0436\u0435\u043d\u0435\u0440\u0438\u044f \u0430\u043a\u0442\u0438\u0432\u043d\u043e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442\u0441\u044f \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u0430\u043c\u0438 \u0438 \u043c\u043e\u0436\u0435\u0442 \u043d\u0435\u0441\u0442\u0438 \u0437\u0430 \u0441\u043e\u0431\u043e\u0439 \u0441\u0435\u0440\u044c\u0435\u0437\u043d\u044b\u0435 \u043f\u043e\u0441\u043b\u0435\u0434\u0441\u0442\u0432\u0438\u044f. \u041a\u0430\u043a \u0447\u0430\u0441\u0442\u043e \u0432\u044b \u043b\u043e\u0432\u0438\u043b\u0438 \u0441\u0435\u0431\u044f \u043d\u0430 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":95621,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-95620","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/1-obuchenie-polzovatelej-osnovam-ib-borba-s-fishingom\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd471. \u041e\u0431\u0443\u0447\u0435\u043d\u0438\u0435 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u043e\u0441\u043d\u043e\u0432\u0430\u043c \u0418\u0411. \u0411\u043e\u0440\u044c\u0431\u0430 \u0441 \u0444\u0438\u0448\u0438\u043d\u0433\u043e\u043c | ProHoster\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/1-obuchenie-polzovatelej-osnovam-ib-borba-s-fishingom\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-10-01T05:45:10+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-10-01T05:45:10+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd471. Training users on the basics of information security. Combatting phishing | ProHoster","description":"","canonical_url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/1-obuchenie-polzovatelej-osnovam-ib-borba-s-fishingom","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd471. \u041e\u0431\u0443\u0447\u0435\u043d\u0438\u0435 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u043e\u0441\u043d\u043e\u0432\u0430\u043c \u0418\u0411. \u0411\u043e\u0440\u044c\u0431\u0430 \u0441 \u0444\u0438\u0448\u0438\u043d\u0433\u043e\u043c | ProHoster","og:url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/1-obuchenie-polzovatelej-osnovam-ib-borba-s-fishingom","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-10-01T05:45:10+00:00","article:modified_time":"2020-10-01T05:45:10+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"95620","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 11:02:17","updated":"2022-09-27 14:57:06","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/95620","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=95620"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/95620\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media\/95621"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=95620"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=95620"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=95620"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}