{"id":9351,"date":"2021-02-19T11:24:20","date_gmt":"2021-02-19T08:24:20","guid":{"rendered":"https:\/\/www.kaspersky.com.tr\/blog\/?p=9351"},"modified":"2021-02-19T11:24:20","modified_gmt":"2021-02-19T08:24:20","slug":"hosting-provider-phishing-web-page","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/hosting-provider-phishing-web-page\/9351\/","title":{"rendered":"Hosting (Yer sa\u011flay\u0131c\u0131s\u0131) kimlik av\u0131"},"content":{"rendered":"<p>Bug\u00fcn, sizlerle yak\u0131n say\u0131labilecek bir tarihte bir yer sa\u011flay\u0131c\u0131n\u0131n sitesindeki bir ki\u015fisel hesab\u0131n ele ge\u00e7irilmesini payla\u015faca\u011f\u0131z. Bu t\u00fcr bir hesap, <a href=\"https:\/\/www.kaspersky.com.tr\/blog\/the-hunt-for-mailing-lists\/9303\/\" target=\"_blank\" rel=\"noopener\">siber su\u00e7lular i\u00e7in olduk\u00e7a ilgi \u00e7ekicidir<\/a>. Gelin, tek bir sald\u0131r\u0131n\u0131n nas\u0131l i\u015fe yarad\u0131\u011f\u0131na ve benzer bir ihlalin ne kadar ileri gidebilece\u011fine bakal\u0131m.<\/p>\n<h2>Kimlik av\u0131 plan\u0131<\/h2>\n<p>Sald\u0131r\u0131, klasik bir kimlik av\u0131 ile ba\u015flad\u0131. Su\u00e7lular bu defa bir siber sald\u0131r\u0131 ba\u015flatarak al\u0131c\u0131y\u0131 h\u0131zla eyleme ge\u00e7irmek i\u00e7in korkutmaya \u00e7al\u0131\u015ft\u0131lar \u2014 hosting sa\u011flay\u0131c\u0131s\u0131 gibi davranan doland\u0131r\u0131c\u0131lar, al\u0131c\u0131n\u0131n hesab\u0131 \u00fczerinden \u015f\u00fcpheli bir alan sat\u0131n alma giri\u015fiminde bulunmak i\u00e7in hesab\u0131 ge\u00e7ici olarak engellediklerini iddia ettiler. Hesab\u0131n\u0131n kontrol\u00fcn\u00fc geri almak i\u00e7in, al\u0131c\u0131n\u0131n ba\u011flant\u0131ya t\u0131klamas\u0131 ve ki\u015fisel hesab\u0131na giri\u015f yapmas\u0131 gerekiyordu.<\/p>\n<div id=\"attachment_9352\" style=\"width: 1034px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-9352\" class=\"wp-image-9352 size-large\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2021\/02\/19111147\/hosting-provider-phishing-email-1024x658.jpg\" alt=\"\" width=\"1024\" height=\"658\"><p id=\"caption-attachment-9352\" class=\"wp-caption-text\">Bir yer sa\u011flay\u0131c\u0131s\u0131 gibi davranan siber su\u00e7lular\u0131n g\u00f6nderdi\u011fi kimlik av\u0131 e-postas\u0131<\/p><\/div>\n<p>\u00a0<\/p>\n<p>\u0130leti metni tehlike \u00e7anlar\u0131 \u00e7al\u0131yor! \u0130letide farkl\u0131 yer sa\u011flay\u0131c\u0131lar\u0131n\u0131n m\u00fc\u015fterileri i\u00e7in ortak bir \u015fablon kulland\u0131\u011f\u0131n\u0131 g\u00f6steren yer sa\u011flay\u0131c\u0131n\u0131n ad\u0131 ya da logosu bile yer alm\u0131yor. Ad, sadece bir kere g\u00f6nderenin ad\u0131 b\u00f6l\u00fcm\u00fcnde ge\u00e7iyor. Dahas\u0131, bu ad ile e-posta adresinin alan ad\u0131 e\u015fle\u015fmiyor: \u015f\u00fcpheli bir duruma y\u00f6nelik bariz bir i\u015faret.<\/p>\n<p>Ba\u011flant\u0131 ise inand\u0131r\u0131c\u0131 olmayan bir giri\u015f sayfas\u0131na y\u00f6nlendiriyor. Renk tasla\u011f\u0131 bile kapal\u0131. Burada umulan \u015fey; kullan\u0131c\u0131n\u0131n panik i\u00e7inde hareket etmesi ve durumu fark etmemesi.<\/p>\n<div id=\"attachment_9353\" style=\"width: 1034px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-9353\" class=\"wp-image-9353 size-large\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2021\/02\/19111249\/hosting-provider-phishing-web-page-1024x391.jpg\" alt=\"\" width=\"1024\" height=\"391\"><p id=\"caption-attachment-9353\" class=\"wp-caption-text\">Sahte internet sitesi sayfalar\u0131<\/p><\/div>\n<p>\u00a0<\/p>\n<p>Her kimlik av\u0131 sald\u0131r\u0131s\u0131nda oldu\u011fu gibi, bu sayfaya kimlik bilgilerinizi girmeniz kontrol\u00fc siber su\u00e7lulara vermekle e\u015fde\u011ferdir. Ancak bu sald\u0131r\u0131da, bu bilgileri girmek kurumsal internet sitesi anahtarlar\u0131n\u0131 teslim etmek anlam\u0131na geliyor. Garip bir \u015fekilde, doland\u0131r\u0131c\u0131lar baz\u0131 finansal bilgileri de soruyor; nedeni belli de\u011fil.<\/p>\n<h2>Peki neden bir yer sa\u011flay\u0131c\u0131s\u0131?<\/h2>\n<p>Gelin, oturum a\u00e7ma sayfas\u0131na bir g\u00f6z atal\u0131m. Kimlik av\u0131 i\u00e7in kullan\u0131lan sitenin sertifikalar\u0131nda bir problem yok. Bilinirli\u011fi de normal g\u00f6r\u00fcn\u00fcyor. Kula\u011fa mant\u0131kl\u0131 geliyor; \u00e7\u00fcnk\u00fc siber su\u00e7lular bu alan\u0131 s\u0131f\u0131rdan olu\u015fturmad\u0131, b\u00fcy\u00fck olas\u0131l\u0131kla benzer bir sald\u0131r\u0131 ger\u00e7ekle\u015ftirerek alan\u0131 ele ge\u00e7irdiler.<\/p>\n<p>Bir yer sa\u011flay\u0131c\u0131n\u0131n internet sitesindeki ki\u015fisel bir hesab\u0131n kontrol\u00fcn\u00fc ele ge\u00e7iren siber su\u00e7lular\u0131n neler yapabilece\u011fi, sa\u011flay\u0131c\u0131ya ba\u011fl\u0131d\u0131r. Yapabilecekleri muhtemel \u015feylere birka\u00e7 \u00f6rnek vermek gerekirse; ba\u015fka i\u00e7eri\u011fe yeniden ba\u011flanabilir, bir Web aray\u00fcz\u00fc arac\u0131l\u0131\u011f\u0131yla site i\u00e7eri\u011fini g\u00fcncelleyebilir ve i\u00e7erik y\u00f6netimi i\u00e7in FTP parolas\u0131n\u0131 de\u011fi\u015ftirebilirler. Ba\u015fka bir deyi\u015fle, siber su\u00e7lular\u0131n yapabilece\u011fi \u00e7ok \u015fey var.<\/p>\n<p>Peki bu olas\u0131l\u0131klar \u00e7ok mu geni\u015f? Daha spesifik ihtimaller de var. Siber su\u00e7lular sitenizin kontrol\u00fcn\u00fc ele ge\u00e7irirse; sitenize bir kimlik av\u0131 sayfas\u0131 ekleyebilir, sitenizi k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131mlar\u0131n indirilebilece\u011fi bir ba\u011flant\u0131ya yer vermesi i\u00e7in kullanabilir ve hatta sitenizi m\u00fc\u015fterilerinize sald\u0131rmak i\u00e7in bile kullanabilirler. K\u0131sacas\u0131, \u015firketinizin ad\u0131n\u0131 ve bilinirli\u011fini k\u00f6t\u00fc ama\u00e7lar\u0131 i\u00e7in kullanabilirler.<\/p>\n<h2>Kimlik av\u0131 sald\u0131r\u0131lar\u0131ndan nas\u0131l korunursunuz?<\/h2>\n<p>Kimlik av\u0131 e-postalar\u0131 olduk\u00e7a ikna edici olabilir. Bu tuzaklara d\u00fc\u015fmemek i\u00e7in \u00f6ncelikle \u00e7al\u0131\u015fanlar\u0131n bilin\u00e7li olmas\u0131 gerekir. A\u015fa\u011f\u0131dakileri yapman\u0131z\u0131 \u00f6neririz:<\/p>\n<ul>\n<li>Ki\u015fisel bir hesab\u0131n ba\u011flant\u0131lar\u0131na asla t\u0131klanmamas\u0131na y\u00f6nelik bir politika uygulay\u0131n. Yer sa\u011flay\u0131c\u0131s\u0131ndan endi\u015fe verici bir ileti alan herkes, \u00f6ncelikle sa\u011flay\u0131c\u0131n\u0131n adresini taray\u0131c\u0131 adres \u00e7ubu\u011funa yazmal\u0131 ve resmi sitede oturum a\u00e7mal\u0131d\u0131r.<\/li>\n<li>Sa\u011flay\u0131c\u0131n\u0131n internet sitesindeki iki fakt\u00f6rl\u00fc kimlik do\u011frulamay\u0131 (2FA) aktif hale getirin. Sa\u011flay\u0131c\u0131 2FA se\u00e7ene\u011fini sunmuyorsa, bu \u00f6zelli\u011fi ne zaman uygulamaya almay\u0131 planlad\u0131klar\u0131n\u0131 \u00f6\u011frenin.<\/li>\n<li>Kimlik av\u0131 sald\u0131r\u0131lar\u0131n\u0131n belirgin i\u015faretlerine kar\u015f\u0131 uyan\u0131k olun (\u00f6rne\u011fin, g\u00f6nderen ad\u0131 ile e-posta alan alan\u0131 aras\u0131nda uyu\u015fmazl\u0131k olmas\u0131 veya internet sitelerindeki yanl\u0131\u015f alan adlar\u0131). \u0130deal olan, \u00e7al\u0131\u015fanlar\u0131n\u0131za kimlik av\u0131 giri\u015fimlerini tespit edebilmelerine y\u00f6nelik e\u011fitimler verin (bunun i\u00e7in bir <a href=\"https:\/\/k-asap.com\/tr\/?icid=tr_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder_______&amp;utm_source=kdaily&amp;utm_medium=blog&amp;utm_campaign=tr_wpplaceholder_nv0092&amp;utm_content=link&amp;utm_term=tr_kdaily_organic_avmwswubv8qh92b\" target=\"_blank\" rel=\"noopener\">\u00e7evrimi\u00e7i e\u011fitim platformu<\/a> kullanmay\u0131 tercih edebilirsiniz).<\/li>\n<li>\u00c7al\u0131\u015fanlar\u0131n internete girmek i\u00e7in kulland\u0131\u011f\u0131 t\u00fcm <a href=\"https:\/\/www.kaspersky.com.tr\/small-to-medium-business-security?icid=tr_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder_______\" target=\"_blank\" rel=\"noopener\">sunuculara ve cihazlara<\/a> kurumsal posta g\u00fcvenli\u011fi \u00e7\u00f6z\u00fcmlerini kurun.<\/li>\n<\/ul>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"kesb-trial-leadgen\">\n<p>\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Siber su\u00e7lular, yer sa\u011flay\u0131c\u0131 sitelerdeki hesaplara nas\u0131l ve neden sald\u0131r\u0131r? <\/p>\n","protected":false},"author":2598,"featured_media":9354,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1194,1727],"tags":[2374,1921,1074,673],"class_list":{"0":"post-9351","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-business","8":"category-smb","9":"tag-barindirma","10":"tag-e-posta","11":"tag-kimlik-avi","12":"tag-web"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/hosting-provider-phishing-web-page\/9351\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/hosting-provider-phishing-web-page\/22531\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/hosting-provider-phishing-web-page\/18023\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/hosting-provider-phishing-web-page\/24246\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/hosting-provider-phishing-web-page\/22315\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/hosting-provider-phishing-web-page\/21083\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/hosting-provider-phishing-web-page\/24762\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/hosting-provider-phishing-web-page\/23974\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/hosting-provider-phishing-web-page\/30129\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/hosting-provider-phishing-web-page\/38783\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/hosting-provider-phishing-web-page\/16424\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/hosting-provider-phishing-web-page\/16976\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/hosting-provider-phishing-web-page\/14499\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/hosting-provider-phishing-web-page\/26259\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/hosting-provider-phishing-web-page\/30076\/"},{"hreflang":"nl","url":"https:\/\/www.kaspersky.nl\/blog\/hosting-provider-phishing-web-page\/26716\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/hosting-provider-phishing-web-page\/23573\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/hosting-provider-phishing-web-page\/28910\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/hosting-provider-phishing-web-page\/28718\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.tr\/blog\/tag\/kimlik-avi\/","name":"kimlik av\u0131"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/9351","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/2598"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=9351"}],"version-history":[{"count":1,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/9351\/revisions"}],"predecessor-version":[{"id":9355,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/9351\/revisions\/9355"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/9354"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=9351"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=9351"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=9351"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}