<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Phishing on Shadow Engineering</title>
    <link>https://shadow.engineering/tags/phishing/</link>
    <description>Recent content in Phishing on Shadow Engineering</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en</language>
    <copyright>© 2026 </copyright>
    <lastBuildDate>Tue, 01 Oct 2019 00:00:00 +1000</lastBuildDate><atom:link href="https://shadow.engineering/tags/phishing/index.xml" rel="self" type="application/rss+xml" />
    
    <item>
      <title>Adventures from the Other Side of Phishing</title>
      <link>https://shadow.engineering/posts/teach_a_man_to_phish/</link>
      <pubDate>Tue, 01 Oct 2019 00:00:00 +1000</pubDate>
      
      <guid>https://shadow.engineering/posts/teach_a_man_to_phish/</guid>
      <description>&lt;h2 class=&#34;relative group&#34;&gt;Background&#xA;    &lt;div id=&#34;background&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#background&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;p&gt;&lt;figure&gt;&lt;img&#xA;    class=&#34;my-0 rounded-md&#34;&#xA;    loading=&#34;lazy&#34;&#xA;    decoding=&#34;async&#34;&#xA;    fetchpriority=&#34;auto&#34;&#xA;    alt=&#34;Phish Site&#34;&#xA;    width=&#34;968&#34;&#xA;    height=&#34;530&#34;&#xA;    src=&#34;https://shadow.engineering/posts/teach_a_man_to_phish/image1_hu_1bfab189d9c752e4.png&#34;&#xA;    srcset=&#34;https://shadow.engineering/posts/teach_a_man_to_phish/image1_hu_1bfab189d9c752e4.png 800w, https://shadow.engineering/posts/teach_a_man_to_phish/image1.png 1280w&#34;&#xA;    sizes=&#34;(min-width: 768px) 50vw, 65vw&#34;&#xA;    data-zoom-src=&#34;https://shadow.engineering/posts/teach_a_man_to_phish/image1.png&#34;&gt;&lt;/figure&gt;&#xA;&lt;/p&gt;&#xA;&lt;p&gt;I know it may be hard to believe, but this poor looking website above is not the legitimate NAB website, it’s a poor mockery of a NABs internet banking portal based off a phishing kit we’ve seen. How do I know this? Because I made it.&lt;/p&gt;&#xA;&lt;p&gt;It stemmed from a weird need, we often need to showcase our phishing capability to seniors in the bank and as a good educational piece to students and employees. Depending on who we’re showcasing to we’re either demonstrating how we respond and manage the risk to customers, or educating users for simple things they can identify to determine the legitimacy. It also helps to showcase the other side of the phishers themselves; a lot of people don’t seem to realise what’s being gathered.&lt;/p&gt;</description>
      
    </item>
    
  </channel>
</rss>
