You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
<divclass="alert">⚠️ This was a phishing simulation – no credentials were captured.</div>
81
+
<p>
82
+
You clicked a link and signed in because the consent screen looked familiar. This exercise demonstrates how attackers exploit <strong>trusted app names</strong> to trick users.
83
+
</p>
84
+
<h2>What happened?</h2>
85
+
<ul>
86
+
<li>The sign-in page looked legitimate because it was Microsoft’s real login page.</li>
87
+
<li>The app name shown was a well-known service (e.g., Microsoft Teams).</li>
88
+
<li>You trusted the app name without checking the <strong>redirect URL</strong> or <strong>permissions requested</strong>.</li>
89
+
</ul>
90
+
<h2>How to protect yourself:</h2>
91
+
<ul>
92
+
<li>Always verify the <strong>redirect URI</strong> before granting consent.</li>
93
+
<li>Check the <strong>permissions requested</strong> – attackers often ask for more than they need.</li>
94
+
<li>If something feels off, stop and report it to IT Security.</li>
0 commit comments