this post was submitted on 22 Jul 2026
661 points (99.7% liked)

Dull Men's Club

4440 readers
611 users here now

An unofficial chapter of the popular Dull Men's Club.

https://dullmensclub.com/

1. Relevant commentary on your own dull life. Posts should be about your own dull, lived experience. This is our most important rule. Direct questions, random thoughts, comment baiting, advice seeking, many uses of "discuss" rarely comply with this rule.

2. Original, Fresh, Meaningful Content.

3. Avoid repetitive topics.

4. This is not a search engine
Use a search engine, a tradesperson, Reddit, friends, a specialist Facebook group, apps, Wikipedia, an AI chat, a reverse image search etc. to answer simple questions or identify objects. Also see rule 1, “comment baiting”.

There are a number of content specific communities with subject matter experts who can help you.

Some other communities to consider before posting:

5. Keep it dull. If it puts us to sleep, it’s on the right track. Examples of likely not dull: jokes, gross stuff (including toes), politics, religion, royalty, illness or injury, killing things for fun, or promotional content. Feel free to post these elsewhere.

6. No hate speech, sexism, or bullying No sexism, hate speech, degrading or excessively foul language, or other harmful language. No othering or dehumanizing of anyone or negativity towards any gender identity.

7. Proofread before posting. Use good grammar and punctuation. Avoid useless phrases. Some examples: - starting a post with "So" - starting a post with pointless phrases, like "I hope this is allowed" or “this is my first post” Only share good quality, cropped images. Do not share screenshots of images; share the original image.

.

founded 2 years ago
MODERATORS
 

Can’t make the wrong people look bad.

top 50 comments
sorted by: hot top controversial new old
[–] Fribbtastic@lemmy.world 18 points 16 hours ago (2 children)

That reminds me of a recent situation.

As someone working in software development, we are required to take part in the security trainings, the usual "don't open things from people you don't know" and "verify that a link is 'known' even if you get something from a person you do know", yada yada. You know the drill.

Recently, I got an email from our Boss saying something about "Here is something that you need to click on so that you are being authorised to do this stuff". Here was my thought process:

  1. This is from the boss's Email. But this cannot be trusted since it can be faked
  2. This is about something we/our software can do. But I don't know why I have to do this, since this isn't really something I am part of or even know anything about
  3. It looks like a legit email
  4. I hovered over the link, which had some weird target location that I didn't know

So, as a good boy, I opened a new Support ticket on IT with a screenshot of the link and said: "Got an email that tells me that I should open this link, but I don't know this link. What should I do?". The response was simple: Mark as Phishing and delete the Mail, done.

2 hours later, I got a message on Teams from IT which said: "Well, apparently that mail you marked as phishing was actually from us (was legit)". Great. Mail is gone now, don't know where Outlook put it, and frankly, I don't care.

If you train your people to "question everything" and not open links they don't know where they are going, then don't use some idiotic "middle man" or referer links in your official emails either. Even better, announce things before sending something out. I don't know how many emails I have gotten over the years where I would question the content and ignore it only for it to be something more important that nobody felt the need to announce first that something like this is coming our way.

[–] ryathal@sh.itjust.works 5 points 13 hours ago

I had a previous company send out a company wide announcement from a sketchy sender with a weird file attachment(apparently it's a voice mail file format), and the email was essentially listen to this attachment with no signature or anything else. They had to send out a second email explaining the suspicious email is actually real. Companies seem intent on ensuring there is minimal difference between phishing and legitimate email.

[–] Bytemeister@lemmy.world 2 points 14 hours ago

Honestly, this is preferable, and pretty funny. IT can always resend invites to tools and services. I'd rather send 1000 of those than have to lock someone out and have to talk to a human.

[–] half_built_pyramids@lemmy.world 9 points 14 hours ago
[–] brax@sh.itjust.works 20 points 1 day ago (2 children)

If IT did the phishing tests nobody would stand a chance lol

[–] zalgotext@sh.itjust.works 20 points 22 hours ago (1 children)

I'd always pass because I never look at any of my emails. Checkmate, IT department

[–] filcuk@feddit.uk 4 points 17 hours ago (1 children)

I've setup a filter based on email headers that include 'Phishing_Training' lol, can't be asked

[–] brax@sh.itjust.works 1 points 12 hours ago

Same but xphish, however these emails aren't sent like normal emails so I have to run the rule any time I come back from a holiday so I can quickly identify them quicker lol.

[–] Lucky_777@lemmy.world 9 points 1 day ago

Work in IT and my old cyber security architect would always try to get us. He did some great tricks and got a few salesmen. Never the engineers. Then they did similar tests for clients, they got hammered bad.

[–] BigBoyShuanzee@aussie.zone 21 points 1 day ago* (last edited 1 day ago) (3 children)

I already know the way to get me to click a phishing link is to send me 5 emails from the same company all 100% legit but have the unsubscribe link be the phishing link.

I would fall for that because I'm unsubscribing from companies emails all the time.

Of course now I've admitted this I'll be avoiding the unsubscribe link for a while too.

[–] MonkderVierte@lemmy.zip 4 points 17 hours ago (1 children)

Even IT people click on random unsubscribes? I've learned that the hard way in my teens, that you only get more spam then. Only unsub from sites you know you have an account on.

[–] BigBoyShuanzee@aussie.zone 2 points 15 hours ago

Random? No I think my original message misses a point.

I don't look at ads. I don't respond to messages I don't answer phone calls from anyone besides my wife.

I'm so overly cautious and uninterested I could possibly miss a call telling me my parents are dying.

I've been in IT so long that everything these days is spam to me, I'm always looking for a way to disable every notification and block every call/message.

The last time I had a real social media message that I cared about was back when MSN messenger existed.. So at least 18+ years ago

Now don't get me wrong, I'm a ridiculous human being.. I am a big fat loudmouth but even as far back as Bebo then Myspace then Facebook I've been more interested in getting attention face to face.

Now I've gone on and on.. That's because I'm in my late 30s and I hate my job and I've drank too much alcohol.

Good luck to you and I wish you well

load more comments (2 replies)
[–] altphoto@lemmy.today 1 points 14 hours ago

By the way, did you already donate for the annual November nothing day celebration? Click this 🔗 to donate, everyone is doing it!

[–] Forbo@lemmy.ml 14 points 1 day ago

Purple link, lol

[–] _lilith@lemmy.world 31 points 1 day ago (4 children)

Fun fact, those fishing emails usually share header information unique to the phishing email test service.

[–] HerbGrower@slrpnk.net 3 points 15 hours ago

We once had one that had what looked like a user ID in the URL. Checked with a coworker. The IDs appeared to be given sequentially. So I copied the URL and visited the site many times with different IDs.

A lot of people failed the phishing test that month and would deny it.

[–] njordomir@lemmy.world 7 points 1 day ago

Yeah, I used to see these when I worked at a big corp. I would do a whois search on the domains used and 9/10 times it would come back as some compliance contractor the company used. I then proceeded to roll my rolly chair up and down every aisle warning my engineers. I spent so much time rolling in that job they should have bought me a rascal scooter with a built in desk. :D

That is exactly how I phish (ha) them out as they hit my inbox!

load more comments (1 replies)
[–] Bieren@lemmy.today 7 points 1 day ago

Me and some coworkers got yelled for reporting the phishing attempt. And then still clicking on the links. The halfass made up sites it took you to were worth it. It’s wouldnt take you to some site saying you failed. It would be like a lunch menu for some made up place. It was great.

[–] EastofEdson@piefed.ca 112 points 1 day ago (7 children)

My company: Don't click on suspicious links.

Also my company: It's employee survey time, click this link to complete the survey http://surveywhale.com/haidn39fk49cmc93mx

I mark them as phishing attempts every damn time.

[–] Fleppensteijn@sh.itjust.works 3 points 19 hours ago

My company used some security software that scrambled up every url in emails.

You could've spotted their fake meeting invite if only it would have shown its true url.

[–] jj4211@lemmy.world 54 points 1 day ago* (last edited 1 day ago) (3 children)

Heh, an employee at my work got an email saying his anti-malware was failing to update, and to run http://10.3.4.2/xbejdjr.exe and that they need to click allow when the browser warns them that it is rejected, then right click, run as administrator, and they need to click allow in two other places to let it run.

So he reported as phishing, then IT contacted his manager saying he was failing to help IT run a required update, it was evidently totally legit, but just the most scammy looking way they imagined.

[–] Bytemeister@lemmy.world 3 points 14 hours ago (1 children)

If that was legitimately IT, then that whole department either need the funds to acquire some remote management software, or they all need to be axed. Only the budget will tell.

[–] jj4211@lemmy.world 1 points 13 hours ago

It's the latter. They actually get thrown all sorts of money in part because they say they need tools. The standard corporate load has at least 3 patch management software suites, two 'cybersecurity monitoring solutions', three anti-malware software products.

Sometimes their automation fails and this was one of those situations where his and at least in our department only his where their automation failed for some reason or another. So they fall back to a sketchy looking exe on some random web server they don't even bother to enable https on (they also provision root CAs, so it's not like it would be a challenge for them to have https on an internal domain).

They aren't very good, but they are doing things perfectly right; so long as the one deciding what is right is the sales reps of the software they use.

[–] Alcoholicorn@mander.xyz 24 points 1 day ago (7 children)

That is so fucking sketchy, I'd have to talk to the IT guy myself or get on a video call to make sure their email or the group chat or whatever wasn't compromised.

load more comments (7 replies)
load more comments (1 replies)
load more comments (5 replies)
[–] AeonFelis@lemmy.world 33 points 1 day ago (1 children)
load more comments (1 replies)
[–] MeowerMisfit817@lemmy.world 14 points 1 day ago (3 children)

I'm out of the loop, what happened here?

[–] stingpie@lemmy.world 41 points 1 day ago (1 children)

This email is the phishing attempt test itself. It says you are exempt from the phishing testing, but then tells you to put your account information on a random website.

load more comments (1 replies)

The email is a phishing test, and clicking the link automatically enrolls you in mandatory rudimentary cybersecurity awareness training.

[–] chortle_tortle@mander.xyz 12 points 1 day ago

I think the implication is that this is the fishing attempt they sent this to the higher ups / IT staff and got bites.

[–] daddycool@lemmy.world 157 points 1 day ago
[–] ramenshaman@lemmy.world 4 points 1 day ago (2 children)

They got me with one a few weeks ago :(

load more comments (2 replies)
[–] Blackmist@feddit.uk 37 points 1 day ago (2 children)

I got a mandatory phishing awareness course that we were signed up to by corporate, and I deleted it because it looked scammy as all fuck.

Don't whine at people for not completing your course on phishing, when you sign them up to courses using scammy looking names without telling us first.

I'm not sure who these courses were even for. I was born in the scams. Moulded by them. I didn't see a genuine banking email until I was already a man. I remember my dad forwarding pyramid schemes to his friends on paper.

load more comments (2 replies)
load more comments
view more: next ›