What is Social Engineering?
Social engineering is manipulating people into doing what you want, in much the same way that electrical engineering is manipulating electronics into doing what you want.
The classic social engineering attack is telephoning legitimate users of a system you wish to access and talking them out of their passwords.
[user] Hello?
[hacker] Hi, this is Bob from IT Security. We've had a security breach on the system and we need every user to verify their username and password.
[user] What do I need to do?
[hacker] Let's walk through a login, just to make sure everything is fine.
[user] OK
[hacker] OK, go ahead and login. What username are you coming in as?
[user] My username is "smith".
[hacker] Excellent. What password are you using?
[user] I am using the password "drowssap".
[hacker] Do you have a system prompt yet?
[user] Yes, I'm in.
[hacker] OK, there you are. I see you now. Everything is fine. We appreciate your cooperation.
[user] OK, goodnight.
[hacker] Thanks again, goodbye.
Social engineering is often the easiest way to get data or access. Humans are, for the most part, very trusting.
Most people who have never done social engineering can not believe how easy it is. Alternatively, most people who are naturally good at social engineering are not the sort of people you would want to let into your home. Social engineering is basically lying, and people who lie well tend to do it regularly.
Bookmark What is Social Engineering?
Latest Blog Posts
Copyright 2009 Tech-FAQ. All rights reserved. Privacy Policy. |
