{"id":9303,"date":"2021-02-09T14:44:50","date_gmt":"2021-02-09T11:44:50","guid":{"rendered":"https:\/\/www.kaspersky.com.tr\/blog\/?p=9303"},"modified":"2021-02-09T14:44:50","modified_gmt":"2021-02-09T11:44:50","slug":"the-hunt-for-mailing-lists","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/the-hunt-for-mailing-lists\/9303\/","title":{"rendered":"E-posta listelerini avlamak"},"content":{"rendered":"<p>T\u00fcketicilerin siber su\u00e7lular\u0131n ilgisini \u00e7ekecek kadar \u00f6nemli olmad\u0131klar\u0131n\u0131 d\u00fc\u015f\u00fcnmesi ne kadar tehlikeli de olsa, ayn\u0131s\u0131n\u0131 KOB\u0130 sahiplerinden duymak ger\u00e7ekten \u00e7ok daha k\u00f6t\u00fcd\u00fcr. Temel korumay\u0131 ihmal etmek, siber su\u00e7lular\u0131n en i\u015fine gelen \u015feydir, ki hedeflerindeki ki\u015filer her zaman tahmin etti\u011finiz gruplar olmayabilir. Yak\u0131n zamanda e-posta kapan\u0131m\u0131za tak\u0131lan bir \u00f6rnek, bunun i\u00e7in bi\u00e7ilmi\u015f kaftan: Posta listeleri i\u00e7in bir e-posta servis sa\u011flay\u0131c\u0131s\u0131 (ESP) hesab\u0131n\u0131 ele ge\u00e7irmeyi ama\u00e7layan kimlik av\u0131.<\/p>\n<h2>E-posta hizmetinde kimlik av\u0131 nas\u0131l yap\u0131l\u0131r?<\/h2>\n<p>Sahtekarl\u0131k bir \u015firket \u00e7al\u0131\u015fan\u0131n\u0131n, bir ESP aboneli\u011fine ait \u00f6deme onay\u0131n\u0131 i\u00e7eren bir mesaj almas\u0131yla ba\u015flar. Mesajdaki ba\u011flant\u0131n\u0131n amac\u0131, al\u0131c\u0131ya yap\u0131lan sat\u0131n alma i\u015fleminin kan\u0131t\u0131n\u0131 sunmakt\u0131r. Al\u0131c\u0131 da ger\u00e7ekten bir ESP m\u00fc\u015fterisiyse (ve kimlik av\u0131 ger\u00e7ek m\u00fc\u015fterileri hedefliyorsa), bu anormal \u00f6demeyi kontrol etme umuduyla b\u00fcy\u00fck olas\u0131l\u0131kla bu ba\u011flant\u0131ya t\u0131klar.<\/p>\n<p>Ba\u011flant\u0131 bir ESP sayfas\u0131na y\u00f6nlendiriyor gibi g\u00f6r\u00fcnse de, asl\u0131nda bamba\u015fka bir yere \u00e7\u0131kar. T\u0131klama sonucu kurbanlar, gayet makul ve resmi g\u00f6r\u00fcnen bir oturum a\u00e7ma sayfas\u0131na y\u00f6nlendirilirler.<\/p>\n<div id=\"attachment_9305\" style=\"width: 1034px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-9305\" class=\"wp-image-9305 size-large\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2021\/02\/09143844\/the-hunt-for-mailing-lists-letter-en-1024x541.png\" alt=\"\" width=\"1024\" height=\"541\"><p id=\"caption-attachment-9305\" class=\"wp-caption-text\">\u0130ki oturum a\u00e7ma ekran\u0131. Sahte olan sayfa soldaki.<\/p><\/div>\n<p>\u00a0<\/p>\n<p>Bu noktada sahte oturum a\u00e7ma sayfas\u0131na girilen herhangi bir verinin, bu sahtekarl\u0131\u011f\u0131n arkas\u0131ndaki siber su\u00e7lulara gitti\u011fini \u00f6\u011frenmek sizi \u015fa\u015f\u0131rtmamal\u0131. Ayr\u0131ca yap\u0131lan bilin\u00e7li y\u00f6nlendirmeye ek olarak, bu sahte sitenin toplad\u0131\u011f\u0131 verileri korumas\u0131z bir kanal \u00fczerinden iletti\u011fini de unutmay\u0131n. Sald\u0131rganlar g\u00f6nderdikleri postaya bunu i\u00e7in bir \u00f6rnek eklemelerine ra\u011fmen, sahte siteye CAPTCHA kodu ekleme zahmetine bile girmemi\u015fler. Sa\u011f alt k\u00f6\u015fede de bir bayrak eksik. Ancak \u00e7o\u011fu kullan\u0131c\u0131n\u0131n bu tutars\u0131zl\u0131klar\u0131 fark etmesi pek olas\u0131 de\u011fil.<\/p>\n<p>\u00a0<\/p>\n<h2>ESP hesab\u0131na eri\u015fimi kaybetmek neden tehlikelidir?<\/h2>\n<p>Olas\u0131 en iyi senaryoda, herhangi bir ESP hesab\u0131n\u0131 ele ge\u00e7iren sald\u0131rganlar, hesab\u0131n e-posta adres listesini kullanarak istenmeyen postalar g\u00f6nderecektir. Sekt\u00f6r baz\u0131nda olu\u015fturulan posta listeleri karaborsada, rastgele toparlanm\u0131\u015f e-posta adreslerinden olu\u015fan basit listelerden daha pahal\u0131ya sat\u0131l\u0131r. Kald\u0131 ki, bir \u015firketin \u00e7al\u0131\u015fma alan\u0131n\u0131 bilmek de siber su\u00e7lular\u0131n spam\u2019lerini en uygun \u015fekilde uyarlamalar\u0131na yard\u0131mc\u0131 olur.<\/p>\n<p>Siber su\u00e7lular\u0131n kimlik av\u0131 uzmanl\u0131\u011f\u0131 g\u00f6z \u00f6n\u00fcne al\u0131nd\u0131\u011f\u0131nda, \u00e7al\u0131nan listelerdeki herkesin \u015firketten gelmi\u015f gibi g\u00f6r\u00fcnen bir kimlik av\u0131 e-postas\u0131 almas\u0131 muhtemeldir. Bu noktada, al\u0131c\u0131 ister bir haber b\u00fcltenine abone olsun ister asl\u0131nda bir m\u00fc\u015fteri olsun, muhtemelen bu mesaj\u0131 a\u00e7ar, okur ve hatta i\u00e7indeki ba\u011flant\u0131ya da t\u0131klar. \u00c7\u00fcnk\u00fc g\u00f6nderen \u015f\u00fcpheli g\u00f6r\u00fcnmez.<\/p>\n<h2>Maskeleme y\u00f6ntemleri<\/h2>\n<p>Kimlik av\u0131 e-postas\u0131n\u0131 ayr\u0131nt\u0131l\u0131 olarak inceledi\u011fimizde, bir posta hizmetiyle, ancak farkl\u0131 bir hizmetle (s\u00f6zde ESP\u2019nin bir rakibinden gelmi\u015f gibi) g\u00f6nderildi\u011fini g\u00f6rd\u00fck. Bu karar\u0131n arkas\u0131ndaki mant\u0131\u011f\u0131 anlamak i\u00e7in \u201c<a href=\"https:\/\/www.kaspersky.com.tr\/blog\/phishing-via-esp\/8994\/\" target=\"_blank\" rel=\"noopener\">E-posta pazarlama hizmetleri arac\u0131l\u0131\u011f\u0131yla kimlik av\u0131<\/a>\u201d g\u00f6nderimize bakabilirsiniz. \u0130lgin\u00e7 bir \u015fekilde, eylemlerinin \u00f6mr\u00fcn\u00fc uzatmak i\u00e7in siber su\u00e7lular kendi \u201cpazarlama firmalar\u0131\u201d i\u00e7in bir ini\u015f sayfas\u0131 bile yap\u0131yorlar. Bize kal\u0131rsa \u201cSimple House Template\u201d ad\u0131ndaki sayfa ba\u015fl\u0131\u011f\u0131 pek de ikna edici de\u011fil\u2026<\/p>\n<div id=\"attachment_9306\" style=\"width: 1034px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-9306\" class=\"wp-image-9306 size-large\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2021\/02\/09144002\/the-hunt-for-mailing-lists-landing-en-1024x814.png\" alt=\"\" width=\"1024\" height=\"814\"><p id=\"caption-attachment-9306\" class=\"wp-caption-text\">Sahte \u201cpazarlama \u015firketi\u201d i\u00e7in bir ini\u015f sayfas\u0131.<\/p><\/div>\n<p>\u00a0<\/p>\n<p>Yukar\u0131dakiler, sald\u0131rganlar\u0131n \u00e7e\u015fitli posta hizmetlerinin mekanizmalar\u0131 hakk\u0131nda ayr\u0131nt\u0131l\u0131 bilgiye sahip olabilece\u011fini ve di\u011fer ESP\u2019lerin istemcilerine de sald\u0131rabileceklerini g\u00f6steriyor.<\/p>\n<h2>Kimlik av\u0131ndan nas\u0131l korunursunuz?<\/h2>\n<p>Tuza\u011fa d\u00fc\u015fmekten ka\u00e7\u0131nmak i\u00e7in a\u015fa\u011f\u0131daki basit ipu\u00e7lar\u0131n\u0131 uygulayabilirsiniz:<\/p>\n<ul>\n<li>Beklenmedik mesajlardaki ba\u011flant\u0131lara, \u00f6zellikle de bir hizmete giri\u015f yapman\u0131z\u0131 isteyen herhangi bir ba\u011flant\u0131ya t\u0131klamaktan ka\u00e7\u0131n\u0131n. Mesaj makul g\u00f6r\u00fcnse bile, taray\u0131c\u0131n\u0131zda yeni bir sayfa a\u00e7\u0131n ve sitenin ad\u0131n\u0131 s\u0131f\u0131rdan yaz\u0131n.<\/li>\n<li>Sitenin g\u00fcvenli\u011fini kontrol edin. Taray\u0131c\u0131n\u0131z bir siteyi g\u00fcvenli olarak tan\u0131mazsa, birileri kullan\u0131c\u0131 ad\u0131n\u0131z\u0131 ve \u015fifrenizi ele ge\u00e7irebilir.<\/li>\n<li>Standart kimlik av\u0131 belirtilerini nas\u0131l tespit edece\u011finizi \u00f6\u011frenin ve ard\u0131ndan t\u00fcm personelinize ayn\u0131s\u0131n\u0131 nas\u0131l yapacaklar\u0131n\u0131 \u00f6\u011fretin. Kendi e\u011fitimlerinizi olu\u015fturman\u0131za da gerek yok; <a href=\"https:\/\/k-asap.com\/tr\/?icid=tr_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder_______&amp;utm_source=kdaily&amp;utm_medium=blog&amp;utm_campaign=tr_wpplaceholder_nv0092&amp;utm_content=link&amp;utm_term=tr_kdaily_organic_avmwswubv8qh92b\" target=\"_blank\" rel=\"noopener\">\u00e7evrimi\u00e7i e\u011fitim platformlar\u0131<\/a> bu ama\u00e7la kullan\u0131labilir.<\/li>\n<li>Kurumsal postalardan spam ve kimlik av\u0131n\u0131 filtrelemek i\u00e7in <a href=\"https:\/\/www.kaspersky.com.tr\/small-to-medium-business-security?icid=tr_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder_______\" target=\"_blank\" rel=\"noopener\">\u00f6zelle\u015ftirilmi\u015f \u00e7\u00f6z\u00fcmler<\/a> kullan\u0131n.<\/li>\n<li>T\u00fcm i\u015f cihazlar\u0131na <a href=\"https:\/\/www.kaspersky.com.tr\/small-to-medium-business-security?icid=tr_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder_______\" target=\"_blank\" rel=\"noopener\">g\u00fcvenlik \u00e7\u00f6z\u00fcmleri<\/a> kurun ve g\u00fcncelleyin, b\u00f6ylece birisi bir kimlik av\u0131 ba\u011flant\u0131s\u0131n\u0131 t\u0131klasa bile tehlikeyi \u00f6nlemi\u015f olursunuz.<\/li>\n<\/ul>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"kesb-trial-leadgen\">\n","protected":false},"excerpt":{"rendered":"<p>Siber su\u00e7lular, ESP hesaplar\u0131na eri\u015fimi ele ge\u00e7irmek i\u00e7in kimlik av\u0131 e-postalar\u0131 g\u00f6nderiyor.<\/p>\n","protected":false},"author":2598,"featured_media":9304,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1194,1727],"tags":[1921,2368,2367,1074],"class_list":{"0":"post-9303","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-business","8":"category-smb","9":"tag-e-posta","10":"tag-e-postalar","11":"tag-esp","12":"tag-kimlik-avi"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/the-hunt-for-mailing-lists\/9303\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/the-hunt-for-mailing-lists\/22474\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/the-hunt-for-mailing-lists\/17965\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/the-hunt-for-mailing-lists\/24179\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/the-hunt-for-mailing-lists\/22257\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/the-hunt-for-mailing-lists\/20971\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/the-hunt-for-mailing-lists\/24640\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/the-hunt-for-mailing-lists\/23847\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/the-hunt-for-mailing-lists\/30050\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/the-hunt-for-mailing-lists\/38632\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/the-hunt-for-mailing-lists\/16350\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/the-hunt-for-mailing-lists\/16966\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/the-hunt-for-mailing-lists\/14445\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/the-hunt-for-mailing-lists\/26174\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/the-hunt-for-mailing-lists\/29976\/"},{"hreflang":"nl","url":"https:\/\/www.kaspersky.nl\/blog\/the-hunt-for-mailing-lists\/26659\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/the-hunt-for-mailing-lists\/23510\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/the-hunt-for-mailing-lists\/28854\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/the-hunt-for-mailing-lists\/28661\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.tr\/blog\/tag\/e-posta\/","name":"e-posta"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/9303","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/2598"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=9303"}],"version-history":[{"count":2,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/9303\/revisions"}],"predecessor-version":[{"id":9308,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/9303\/revisions\/9308"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/9304"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=9303"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=9303"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=9303"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}