Loading
0x20Lesson 3 of 13

Spot phishing and social engineering

Recognize the tricks that target people instead of computers, and check where links really go.

20 min 6-question quiz 2 code exercises
By the end of this lesson you can
  • Recognize urgency, authority and secrecy pressure tactics
  • Check a link’s real destination and spot lookalike domains
  • Know why phishing-resistant sign-in and reporting matter

Many breaches start not with clever code but with a convincing message. Social engineering manipulates people into giving away access, money or information. Common forms:

  • Phishing - email that imitates a trusted sender (spear phishing targets one person using researched details).
  • Smishing / vishing - the same by text message or phone call.
  • Business email compromise - posing as an executive or supplier to redirect payments.
  • MFA fatigue - spamming sign-in approval prompts until someone taps “Approve”.

They work by triggering emotions that short-circuit careful thinking: urgency (“within 24 hours”), authority (“the CEO needs this”), fear (“your account is suspended”), curiosity or greed, and secrecy (“keep this between us”).

Try it

Red-flag hunt

Read each message like a suspicious security analyst. Click every part that’s a warning sign, then check what you found.

An account warning (1 of 3)Flags found 0/0

Click every part that looks suspicious. There are 6.

From: PayPal Security <security@paypa1-support.com> Subject: URGENT: Your account will be suspended in 24 hours Dear Customer, We noticed unusual activity on your account. To avoid permanent suspension, verify your identity immediately at: https://paypal.com.verify-account.info/login Please have your password and the 6-digit code we text you ready. Thank you, Customer Protection Team

The text of a link can say anything; what matters is the href - hover (or long-press) to see it. Then read the hostname from the right: in login.example-bank.com, the registrable domain is example-bank.com; in example-bank.com.secure-login.net, it is secure-login.net. Attackers also register lookalike domains: examp1e-bank.com, example-bank.co, or letters from other alphabets that look identical.

read_the_host.py
1from urllib.parse import urlparse
2for url in ["https://login.example-bank.com/", "https://example-bank.com.secure-login.net/"]:
3    host = urlparse(url).hostname
4    print(host, "->", ".".join(host.split(".")[-2:]))
Output
login.example-bank.com -> example-bank.com
example-bank.com.secure-login.net -> secure-login.net

Key takeaways

  • Social engineering exploits urgency, authority, fear and secrecy.

  • Check a link’s real destination and read its domain from the right.

  • Phishing-resistant MFA, out-of-band verification and easy reporting beat “just be careful”.

Lesson quiz

6 questions · pass with 5 correct · up to 50 XP

Passing this quiz completes the lesson and keeps your streak going. Questions you miss come back in review sessions later.

Practice: write Python

Write Python in the editor and run it against sample inputs. Python runs locally in your browser using a WebAssembly runtime.

Exercise 1
+25 XP

Each line is display text|href. If the display text looks like a URL (starts with http or www.), compare its hostname with the href’s hostname: print ok: HOST if they match, otherwise MISMATCH: shows A, goes to B.

If the display text isn’t a URL, print check: text link goes to HOST.

  • Four links
main.py
Loading editor…

Python runs in a sandboxed browser worker with a 60 second time limit. Its runtime loads from the Pyodide CDN; your code stays in this browser.

Exercise 2

Catch lookalike domains

+25 XP

The first line lists your trusted domains, comma-separated. Each following line is a hostname. Treat the last two labels as the registrable domain.

  • If the registrable domain is trusted, print trusted HOST.
  • Otherwise, if its first label - after mapping 0→o, 1→l, 3→e, 5→s and removing hyphens - equals a trusted domain’s first label (also without hyphens), or any label of the host equals a trusted domain’s first label, print lookalike HOST (imitates TRUSTED).
  • Otherwise print unknown HOST.
  • Mixed hosts
main.py
Loading editor…

Python runs in a sandboxed browser worker with a 60 second time limit. Its runtime loads from the Pyodide CDN; your code stays in this browser.

Questions about this lesson

Stuck? Ask. Figured something out? Share it. Explaining is one of the best ways to learn.

Loading posts…

Did you like the lesson? 😆👍
Consider a donation to support our work: