Social Engineering Flashcards
What is Phishing
Persuades or tricks target into interacting with a malicious resource. traditionally over Email. Combines social engineering and spoofing.
What is Smishing
A standard scam sent via text (SMS). Used to trick target into giving valuable info.
What is Vishing
Over the phone Phishing. Scam to extract info or convince target to interact with malicious resource.
What is Spam
Unsolicited Email both malicious and mundane
What is SPIM (Spam over internet messaging)
Unsolicited messaging through internet messaging{ catch all for not email but sent over the internet}
What is Spear Phishing
Focused Phishing usually including information to add credibility. Tailored to address a specific target.
What is Dumpster Diving
Combing through garbage for files/removable media.
What is Shoulder Surfing
Observing the input of a password or information. not just physically looking over the shoulder cameras are fair game. Recorded video counts.
What is Pharming
Corrupts name resolution process in order to reroute users of legitimate websites to malicious websites passively.
What is Tailgating
Entering an area unauthorized via following closely behind someone without their knowledge or consent of malicious goals. Still count if they hold the door open but were tricked into doing so.
What is Eliciting Information
The discrete gathering of information. For example a conversation in which tricks the other party into giving useful information.
What is Whaling
Spear Phishing but aimed at somebody big like a CEO.
A focused scam using information to create legitimacy.
What is Prepending
Adds text to Hoax of Spam that looks the the email system produced to create legitimacy
What is Identity Fraud
Used specific details of someone’s identity to impersonate them. Also compromised accounts.
What is Invoice Scams
Spoofs invoice details but changes changes bank account number. You fake being the collector of a bill.