Common Cybersecurity and Network Security Issues
One of the first steps to keeping your data secure is finding out what threatens it. Here are a couple of the more common threats to your business network!
How to Easily Generate Hundreds of Phishing Domains « Null Byte :: WonderHowTo
A convincing domain name is critical to the success of any phishing attack. With a single Python script, it's possible to find hundreds of available phishing domains and even identify phishing websites deployed by other hackers for purposes such as stealing user credentials.
Security as a systems problem: interaction between Netflix and Gmail
The dots do matter: how to scam a Gmail user
But perhaps this was not a mistake but a scam. I was almost fooled into perpetually paying for Eve’s Netflix access, and only paused because I didn’t recognize the declined card. More generally, the phishing scam here is:

1️⃣️ Hammer the Netflix signup form until you find a address which is “already registered”. Let’s say you find the victim `jameshfisher`.
2️⃣️ Create a Netflix account with address `james.hfisher`.
3️⃣️ Sign up for free trial with a throwaway card number.
4️⃣️ After Netflix applies the “active card check”, cancel the card.
5️⃣️ Wait for Netflix to bill the cancelled card. Then Netflix emails james.hfisher asking for a valid card.
6️⃣️ Hope Jim reads the email to `james.hfisher`, assumes it’s for his Netflix account backed by `jameshfisher`, then enters his card `**** 1234`.
7️⃣️ Change the email for the Netflix account to, kicking Jim’s access to this account.
8️⃣️ Use Netflix free forever with Jim’s card `**** 1234`!


Some blame lies with Netflix, but I believe the main problem lies with Gmail, and specifically Gmail’s “dots don’t matter” feature. The scam fundamentally relies on the Gmail user responding to an email with the assumption that it was sent to their canonical address, and not to some other address from their infinite address set.
The dots do matter: how to scam a Gmail user • James Fisher
Fisher got a valid email from Netflix saying it was having trouble with his credit card payment. He was going to update it - but the credit card it had didn't match his own. What gives?
<p>I finally realized that this email is to I normally use, with no dots. You might think this email should have bounced, but instead it reached my inbox, because “dots don’t matter in Gmail addresses”:

If someone accidentally adds dots to your address when emailing you, you’ll still get that email. For example, if your email is, you own all dotted versions of your address:<br /><br />

Netflix does not know about this Gmail “feature”. Externally, and are different identities, and should have their own Netflix accounts. I signed up for Netflix account N1 backed by in 2013. But in September 2017, someone, let’s call her “Eve”, created a new Netflix account N2, backed by

Eve has access to account N2 because she set its password when signing up, but I also have access to the account because I own, and so I can follow the password reset process for this account. I did so.

Eve loves her TV! She’s watched 587 titles in six months, all from her “Android Device” in Alabama. She watched three seasons of Trailer Park Boys over a single day in October. She consumed nearly every day until 22nd March, when Netflix put her account “on hold” due to payment failure. Eve had paid for these shows. She paid $13.99 every month for her Premium plan, until February when her card **** 2745 (also billed to Huntsville, Alabama) was declined.

Perhaps this was all a mistake? Perhaps Eve is actually one of the twelve James Fishers in Huntsville, AL, and perhaps he typed his email address in wrong when he signed up months ago. Netflix doesn’t do any email address verification when you sign up; you can start watching shows straight away.

But perhaps this was not a mistake but a scam. I was almost fooled into perpetually paying for Eve’s Netflix access, and only paused because I didn’t recognize the declined card.</p>

Google <a href="">is proud of this "feature"</a>, but like Fisher, I think it's a bug. I get tons of scam emails like this.
