1.1 Compare and contrast different types of social engineering techniques Flashcards
What is Phishing?
Phishing is a broad term used to describe the fraudulent acquisition of information, often focused on credentials like usernames and passwords, as well as sensitive personal information like credit card numbers and related data.
Phishing is most often done via email.
What is Smishing?
Smishing is phishing via SMS (text) messages.
What is Vishing?
Vishing is phishing via telephone
What is Spam?
Unwanted emails or junk mail
Spam sometimes called unsolicited or junk e-mail, may not immediately seem like a social engineering technique, but spam often employs social engineering techniques to attempt to get recipients to open the message or to click on links inside of it.
What is SPIM?
Spam over instant messaging is instant messaging spam
Unwanted text messages
What is Spear Phishing?
Spear phishing targets specific individuals or groups in an organization in an attempt to gather desired information or access.
What is Dumpster Diving?
Dumpster diving is retrieving potential sensitive information from a dumpster.
What is Shoulder Surfing?
Shoulder surfing is the process of looking over a person’s shoulder to capture information like passwords or other data.
What is Pharming?
Pharming attacks redirect traffic away from legitimate websites to malicious versions.
Pharming typically requires a successful technical attack that can change DNS entries on a local PC or on a trusted local DNS server, allowing the traffic to be redirected
What is Tailgating?
Tailgating is a physical entry attack that requires simply following someone who has authorized access to an area so that as they open secured doors you can pass through as well.
What is Eliciting Information?
Eliciting information, often called elicitation, is a technique used to gather information without targets realizing they are providing it.
Techniques like flattery, false ignorance, or even acting as a counselor or sounding board are all common elements of an elicitation effort
What is Whaling?
Whaling, much like Spear phishing, targets specific people, but whaling is aimed at senior employees like CEOs and CFOs “big fish” in the company.
What is Prepending?
Prepending can mean one of three things:
- Adding an expression or phrase, such as adding “SAFE” to a set of email headers to attempt to fool a user into thinking it has passed an anti spam tool
- Adding information as part of another attack to manipulate the outcome
- Suggesting topics via a social engineering conversation to lead a target toward related information the social engineer is looking for
What is Identity Fraud?
Identity fraud, or identity theft, is the use of someone else’s identity.
What is Invoice scams?
Invoice scams, which involve sending fake invoices to organizations in hopes of receiving payment.