|
|
|
|
|
by gitgud
1691 days ago
|
|
Not really a logical phishing strategy, if the first domain looks safe and the attacker controls it, why wouldn't they just use that to serve a phishing page? Instead of needlessly redirecting... A better example would be to show "google.com" and somehow redirect to "phishing.com"... but that's not really possible without control of "google.com" |
|
It seems to me that the author does not need control over the second domain, just the first and third. But the user will never see the first URL, only the second.