10.0.0.0/8 is a reserved lan name space, so I’d probably have ran it after confirming the headers (anything 10.x.x.x will be on your local network) but I do agree, shady and stupid af especially since IT presumably should be running their own dns and it’s trivial to implement a redirect to an internal corporate tld.
I would have assumed a beach head where they compromised a system on the internal network and then phished to extend the reach.
I figured IT of all people would have allocated some DNS and some certificate. I would have taken the lack of TLS and DNS as a consequence of an attacker not having enough access to make those things a reality, and banking on people viewing 10. as safely internal like you are inclined to suggest.
Just because it has an internal address does not mean it is safe, particularly as number of employees goes up and any one of them can get a system under their control compromised.
I never said it was safe, I said it was internal. If it’s on 10.x.x.x, sent with email headers verified against my orgs Auth, it’s beyond my or any normal user’s pay grade to deal with it and should’ve been caught far far before this point by design. Though, what you’re saying does align with defense in depth principals, I think you’ll find they cannot be expected in real life use, but perhaps you’re the type to independently verify every file you interact with via hash. Idk, some people on lemmy go hard. 🤷♂️
10.0.0.0/8 is a reserved lan name space, so I’d probably have ran it after confirming the headers (anything 10.x.x.x will be on your local network) but I do agree, shady and stupid af especially since IT presumably should be running their own dns and it’s trivial to implement a redirect to an internal corporate tld.
I would have assumed a beach head where they compromised a system on the internal network and then phished to extend the reach.
I figured IT of all people would have allocated some DNS and some certificate. I would have taken the lack of TLS and DNS as a consequence of an attacker not having enough access to make those things a reality, and banking on people viewing 10. as safely internal like you are inclined to suggest.
Just because it has an internal address does not mean it is safe, particularly as number of employees goes up and any one of them can get a system under their control compromised.
I never said it was safe, I said it was internal. If it’s on 10.x.x.x, sent with email headers verified against my orgs Auth, it’s beyond my or any normal user’s pay grade to deal with it and should’ve been caught far far before this point by design. Though, what you’re saying does align with defense in depth principals, I think you’ll find they cannot be expected in real life use, but perhaps you’re the type to independently verify every file you interact with via hash. Idk, some people on lemmy go hard. 🤷♂️